Legal
Guardyx AI Terms of Service
Version 1.5
Effective May 14, 2026 · Last updated May 14, 2026
Contents
- Introduction
- Definitions
- Eligibility and Account Requirements
- Description of Services
- Customer Responsibilities
- Acceptable Use Restrictions
- AI and Automation Risks
- Approval Workflows and Human-in-the-Loop Decisions
- Customer Data Ownership and Use
- Data Processing and Privacy
- Security and Tenant Isolation
- Audit Logs and Telemetry
- Third-Party Services and Integrations
- Fees, Usage Metering, and Billing
- Subscription Term and Renewal
- Confidentiality
- Suspension Rights
- Termination
- Effect of Termination
- Service Level Agreement
- Beta Features
- Warranties and Disclaimers
- Limitation of Liability
- Indemnification
- Compliance and Export Controls
- Force Majeure
- Assignment
- Notices
- Governing Law and Dispute Resolution
- Changes to Terms
- Survival
- Miscellaneous
- Contact Information
1. Introduction
These Terms of Service (“Terms”) govern access to and use of the Guardyx AI platform, APIs, SDKs, hosted services, customer portal, integrations, websites, and related offerings (collectively, the “Services”) provided by Code Above Lab, Inc. (“Code Above Lab,” “Guardyx,” “we,” “us,” or “our”), which operates the Guardyx AI service and platform.
By clicking “I agree,” creating an account, accessing, or otherwise using the Services, you agree to be bound by these Terms.
If you are using the Services on behalf of an organization, you represent and warrant that you have authority to bind that organization, and “Customer,” “you,” and “your” refer to that organization.
If you do not agree to these Terms, you may not access or use the Services.
Section headings are provided for convenience only and do not affect interpretation. Capitalized terms have the meanings set forth in Section 2.
2. Definitions
2.1 “Acceptable Use Policy”
Guardyx’s then-current acceptable use policy governing permitted and prohibited uses of the Services, as updated from time to time.
2.2 “Affiliate”
Any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where “control” means ownership of more than fifty percent (50%) of the voting interests.
2.3 “Agents”
Software agents, workflows, automations, orchestration systems, or AI-powered systems connected to or operated through the Services.
2.4 “Authorized Users”
Employees, contractors, or other personnel that Customer authorizes to access and use the Services on Customer’s behalf.
2.5 “Beta Features”
Features, functionality, integrations, APIs, or services designated by Guardyx as alpha, beta, preview, experimental, or early access.
2.6 “Confidential Information”
Any non-public business, technical, financial, security, product, roadmap, customer, operational, or other proprietary information disclosed by one party (“Disclosing Party”) to the other party (“Receiving Party”), including Customer Data, Documentation, pricing, audit records, security information, and non-public aspects of the Services.
2.7 “Customer”
The individual or legal entity using the Services, including its Affiliates accessing the Services under Customer’s account.
2.8 “Customer Data”
Any data, prompts, agent inputs and outputs, tool requests and responses, telemetry, files, credentials, logs, metadata, or other information submitted to or processed through the Services by Customer, its Authorized Users, or its Agents. Customer Data expressly includes prompts, tool payloads, tool responses, agent telemetry, and workflow execution data processed through the Services.
2.9 “Documentation”
The official user, technical, and operational documentation made available by Guardyx for the Services, as updated from time to time.
2.10 “Order Form”
Any ordering document, online order, subscription form, or written agreement entered into between Customer and Guardyx that references these Terms and specifies the Services, fees, term, and other commercial terms applicable to Customer.
2.11 “Personal Data”
Information relating to an identified or identifiable natural person, as defined under applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and similar laws.
2.12 “Retrieval Period”
The thirty (30) day period following expiration or termination of the Services during which Customer may export Customer Data using generally available functionality described in the Documentation.
2.13 “Sensitive Actions”
Actions designated by Customer or Guardyx as requiring additional review, approval, policy enforcement, or elevated security controls, including actions configured to require human approval through the Services.
2.14 “Subprocessor”
A third-party service provider engaged by Guardyx to process Customer Data on Guardyx’s behalf in connection with the Services.
2.15 “Tools”
External APIs, connectors, systems, databases, SaaS services, plugins, models, or integrations invoked through the Services.
2.16 “Trust Center”
Guardyx’s online security and compliance resource center describing applicable security practices, certifications, subprocessors, and related materials.
3. Eligibility and Account Requirements
To access the Services, you must:
- be legally capable of entering into a binding agreement under applicable law;
- be at least the age of majority in your jurisdiction;
- provide accurate, current, and complete registration information;
- maintain and promptly update your account information;
- maintain the confidentiality and security of credentials, API keys, and authentication tokens;
- promptly notify Guardyx of any unauthorized access or suspected security incident.
Customer is responsible for all activities conducted under its accounts, tenants, API keys, and credentials, including those of its Authorized Users and Agents.
4. Description of Services
Guardyx provides infrastructure for governed AI agent operations, including:
- AI agent connectivity and orchestration support;
- tool execution gateways;
- policy enforcement and decisioning;
- approval workflows and human-in-the-loop checkpoints;
- observability, telemetry, and audit logging;
- usage metering;
- SDKs, adapters, and Documentation;
- billing and account management;
- customer portal functionality.
Guardyx may modify, improve, add to, suspend, or discontinue portions of the Services from time to time. Guardyx will use commercially reasonable efforts to provide advance notice of material adverse changes to generally available Services.
5. Customer Responsibilities
Customer is solely responsible for:
- configuring its Agents, Tools, policies, and approval workflows;
- determining appropriate access controls, roles, and permissions;
- reviewing, configuring, and acting upon approval requests and policy decisions;
- ensuring its use of the Services complies with applicable laws and contractual obligations;
- obtaining all rights, consents, and authorizations necessary for Customer Data and for Guardyx’s processing of Customer Data as contemplated by these Terms;
- validating the accuracy and appropriateness of outputs generated by Agents or AI systems;
- the acts and omissions of its Authorized Users and Agents, including any actions taken by Agents that exceed their intended scope.
Customer acknowledges that AI systems may generate inaccurate, incomplete, biased, harmful, or unexpected outputs, and that Customer must implement appropriate human review for material decisions.
Guardyx does not determine the business purpose, objectives, or substantive merits of Customer Agents, Customer workflows, or Customer business decisions, even where the Services enforce policies, approvals, or execution controls configured by Customer.
Customer is also solely responsible for the security and scope of access associated with the Services, including:
- credentials, API tokens, OAuth grants, and authentication material connected to the Services;
- the authority scope granted to Agents and Authorized Users;
- permissions configured for connected Third-Party Services;
- downstream systems, repositories, databases, infrastructure, and external environments accessed through the Services.
6. Acceptable Use Restrictions
Customer may not, and may not permit any Authorized User or Agent to:
- use the Services for any unlawful purpose;
- violate export controls, sanctions laws, or trade restrictions;
- process regulated data, including protected health information, payment card data, or other regulated categories, without required legal safeguards and any required separate agreements;
- attempt to gain unauthorized access to any systems, tenants, accounts, or Customer Data of other customers;
- interfere with or disrupt the security, integrity, or availability of the Services;
- use the Services to distribute malware, malicious code, or harmful content;
- conduct denial-of-service attacks or otherwise overload the Services;
- reverse engineer, decompile, or disassemble proprietary platform components, except to the extent expressly permitted by applicable law notwithstanding this restriction;
- use the Services to build or operate a substantially similar competing infrastructure platform through unauthorized extraction or replication of the Services, or publish misleading competitive benchmarks or performance evaluations that are not based on then-current versions of the Services and that do not include sufficient methodology to permit independent reproduction;
- use the Services to infringe or violate any third-party rights, including intellectual property, privacy, or publicity rights;
- circumvent billing, metering, quotas, rate limits, or access restrictions;
- remove or alter any proprietary notices.
Customer may not use the Services in connection with:
- unlawful surveillance, stalking, or harassment;
- unlawful discrimination;
- autonomous weapons systems;
- fully automated high-risk medical, legal, financial, or employment decision-making without qualified human oversight;
- generation of child sexual abuse material or non-consensual intimate imagery;
- activities prohibited by Guardyx’s then-current Acceptable Use Policy or applicable law.
7. AI and Automation Risks
Customer acknowledges and accepts that:
- AI agents may behave unpredictably or produce unreliable outputs;
- policy enforcement, approval workflows, and other governance features reduce but do not eliminate risk and may not prevent all unsafe behavior;
- external Tools and third-party APIs may fail, time out, or produce incorrect or inconsistent outputs;
- Guardyx provides infrastructure software and does not supervise Customer’s operations, business decisions, or end uses;
- Customer’s configuration of Agents, Tools, policies, and approvers materially affects platform behavior and outcomes.
Customer is responsible for evaluating whether Agent-generated actions are appropriate before deployment in production environments and for establishing appropriate human review and override mechanisms.
Foundation model providers and Third-Party Services may modify model behavior, safety filtering, availability, pricing, APIs, output characteristics, or usage policies without notice. Guardyx is not responsible for resulting impacts to Customer workflows, outputs, approvals, integrations, or operational outcomes.
Customer is responsible for validating and re-validating Agent behavior following changes to foundation models, Third-Party Services, prompts, workflows, integrations, or configurations.
8. Approval Workflows and Human-in-the-Loop Decisions
The Services may be configured to require human approval for certain Agent actions. Customer acknowledges that:
- Customer is solely responsible for designating approvers, configuring approval policies, and reviewing approval requests in a timely manner;
- approvals issued by Customer’s Authorized Users are deemed authorized actions of Customer;
- Guardyx does not review the substantive merits of approval requests or decisions and is not responsible for the consequences of any approved or denied action;
- expired, ignored, or auto-rejected approval requests are handled in accordance with Customer’s configured settings and the Documentation;
- Customer assumes all risk and liability arising from approval decisions made through the Services.
9. Customer Data Ownership and Use
Customer retains all rights, title, and interest in Customer Data. Guardyx does not acquire ownership rights in Customer Data.
Customer grants Guardyx a worldwide, non-exclusive, royalty-free license to host, process, transmit, store, analyze, display, and otherwise use Customer Data solely to:
- provide, maintain, and support the Services;
- secure the platform and detect or prevent fraud or abuse;
- maintain and improve operational reliability;
- comply with legal obligations or valid legal process.
Unless expressly agreed otherwise in writing:
- Guardyx will not use Customer Data to train foundation models or general-purpose AI models;
- Guardyx will not sell Customer Data;
- Guardyx will not disclose Customer Data except as described in these Terms, the applicable Data Processing Addendum, or Guardyx’s Privacy Policy.
Guardyx may collect, generate, and use aggregated and de-identified data derived from Customer’s use of the Services, which does not identify Customer, its Authorized Users, or any individual, for any lawful purpose, including improving the Services, developing new features, and producing benchmarks and analytics. Guardyx will not attempt to re-identify such data and will use commercially reasonable measures to prevent re-identification.
Guardyx will not provide aggregated or de-identified data to third parties in a form that could reasonably be used to re-identify Customer, Authorized Users, or any individual.
10. Data Processing and Privacy
Where Guardyx processes Personal Data on behalf of Customer in connection with the Services, the parties’ respective obligations are set forth in the Guardyx Data Processing Addendum (“DPA”), which is incorporated into these Terms by reference for customers processing Personal Data subject to applicable data protection laws.
Guardyx maintains a current list of Subprocessors and will provide notice of material changes in accordance with the DPA. Customer’s use of the Services is also subject to the Guardyx Privacy Policy.
11. Security and Tenant Isolation
Guardyx implements commercially reasonable administrative, technical, and organizational safeguards designed to protect Customer Data. Such safeguards may include:
- logical tenant isolation;
- encryption of Customer Data in transit and at rest;
- role-based access controls and least-privilege principles;
- audit logging and event recording;
- secrets management integrations;
- policy enforcement and approval workflow layers;
- monitoring, vulnerability management, and incident response procedures.
Additional security practices, certifications, and commitments, which may include SOC 2, ISO 27001, or similar frameworks as made available by Guardyx, may be described in the Trust Center, Security Addendum, or applicable Order Forms.
Customer is responsible for properly configuring its use of the Services, protecting its credentials, and implementing security controls within its own environment. Customer acknowledges that no system can be guaranteed to be fully secure and that unauthorized access, cyberattacks, data breaches, service interruptions, or other security incidents may occur despite reasonable safeguards.
12. Audit Logs and Telemetry
The Services generate audit logs, telemetry, and event records relating to Agent runs, Tool invocations, approvals, and policy decisions. Unless otherwise specified in an Order Form or the DPA:
- audit logs and telemetry are retained for at least ninety (90) days;
- Customer may export audit logs through the Services during the subscription term, subject to applicable rate limits and Documentation;
- following termination, audit logs and telemetry are subject to the retention and deletion procedures described in Section 19 (Effect of Termination).
Customer is responsible for retaining its own copies of audit logs and telemetry where required for its compliance obligations.
13. Third-Party Services and Integrations
The Services may interoperate with third-party tools, APIs, SaaS platforms, databases, cloud providers, and AI model providers (collectively, “Third-Party Services”). Customer authorizes Guardyx to access and process information from such Third-Party Services as directed by Customer.
Customer acknowledges that:
- Third-Party Services are provided by third parties and are not part of the Services;
- use of Third-Party Services may be subject to separate terms and pricing imposed by the third-party provider;
- Guardyx is not responsible for the availability, security practices, accuracy, performance, or acts and omissions of Third-Party Services or their providers;
- AI model providers and other Subprocessors are listed in Guardyx’s Subprocessor list as described in the DPA;
- changes to or discontinuation of Third-Party Services may affect the Services, and Guardyx is not liable for such changes.
Guardyx’s role with respect to Third-Party Services is limited to request routing, policy evaluation, approval gating, telemetry collection, audit logging, and related infrastructure functionality. Guardyx does not control or validate the substantive correctness, legality, safety, or appropriateness of Third-Party Service outputs or actions.
14. Fees, Usage Metering, and Billing
Customer agrees to pay all fees specified in the applicable Order Form or as posted for the applicable plan. Fees may be based on:
- Tool invocations or other metered usage;
- API requests or compute consumption;
- seats, users, or Agents;
- data retention or storage;
- subscription tiers or enterprise licensing terms.
Unless otherwise stated in an Order Form:
- all fees are stated and payable in U.S. dollars;
- invoices are due within thirty (30) days of invoice date (net 30);
- fees are exclusive of taxes, levies, duties, and similar governmental assessments, which are Customer’s responsibility except for taxes based on Guardyx’s net income;
- overdue amounts may accrue interest at the lesser of 1.5% per month or the maximum rate permitted by law;
- fees are non-refundable, except where the Services are terminated by Guardyx without cause or as otherwise required by law.
Customer must notify Guardyx in writing of any fee, metering, or usage dispute within thirty (30) days of the applicable invoice date. Failure to dispute an invoice within such period constitutes acceptance of the invoice. The parties will cooperate in good faith to resolve any metering or billing disputes.
Subscriptions may auto-renew on the terms set forth in the applicable Order Form. Guardyx may change fees for renewal terms with at least thirty (30) days’ prior notice. Guardyx may suspend Services for nonpayment in accordance with Section 16.
15. Subscription Term and Renewal
Unless otherwise specified in an applicable Order Form, subscriptions begin on the effective date of the applicable Order Form and continue for the subscription term stated therein.
Subscriptions automatically renew for successive renewal terms equal to the initial subscription term unless either party provides written notice of non-renewal at least thirty (30) days before the end of the then-current term.
Guardyx may modify pricing for renewal terms upon at least thirty (30) days’ prior written notice.
16. Confidentiality
Each Receiving Party agrees to use Confidential Information solely for purposes of exercising its rights and fulfilling its obligations under these Terms and to protect Confidential Information using the same degree of care it uses to protect its own similar information, but in no event less than reasonable care.
Confidential Information does not include information that the Receiving Party can demonstrate:
- is or becomes publicly available without breach of these Terms;
- was lawfully known by the Receiving Party without restriction before disclosure;
- is independently developed by the Receiving Party without use of or reference to Confidential Information;
- is lawfully obtained from a third party without confidentiality obligations.
A Receiving Party may disclose Confidential Information where required by law, regulation, subpoena, or court order, provided it gives prior notice where legally permitted and reasonably cooperates with efforts to seek protective treatment.
Upon termination or request, each party will return or destroy Confidential Information, except where retention is required by law or reasonably necessary for backup, security, audit, legal, or compliance purposes.
Customer Data shall be retained, exported, deleted, and otherwise handled in accordance with Section 19 (Effect of Termination) and the applicable DPA, notwithstanding this Section.
Confidentiality obligations continue during the term of these Terms and for five (5) years following termination or expiration, except for trade secrets, which remain protected for so long as they qualify as trade secrets under applicable law.
17. Suspension Rights
Guardyx may suspend Customer’s access to the Services, in whole or in part, immediately upon notice if:
- Customer’s use creates a security, operational, legal, or compliance risk;
- Customer violates Section 6 (Acceptable Use Restrictions);
- Customer materially degrades platform integrity, performance, or availability;
- required by law, governmental order, or regulatory authority;
- Customer fails to pay undisputed fees when due.
Where reasonably practicable, Guardyx will provide advance notice and use commercially reasonable efforts to narrow the scope and duration of any suspension.
Guardyx will restore access once the underlying issue giving rise to the suspension has been resolved to Guardyx’s reasonable satisfaction.
18. Termination
Either party may terminate an applicable Order Form or subscription for material breach if the breaching party fails to cure such breach within thirty (30) days after written notice.
Guardyx may terminate immediately upon notice if:
- Customer materially violates Section 6;
- Customer becomes insolvent or subject to bankruptcy proceedings;
- continued provision of the Services would create material legal, regulatory, or security risk.
Customer may terminate its use of the Services at any time, subject to payment obligations accrued through the effective date of termination.
Subscriptions expire at the end of the applicable subscription term unless renewed pursuant to Section 15.
If Guardyx terminates the Services or an applicable Order Form without cause and not due to Customer breach, Guardyx will refund any prepaid, unused fees covering the terminated portion of the subscription term.
If Customer terminates for Guardyx’s uncured material breach, Guardyx will refund any prepaid, unused fees for the terminated portion of the applicable subscription term.
19. Effect of Termination
Upon expiration or termination:
- Customer’s access rights to the Services terminate;
- Customer remains responsible for accrued fees and obligations;
- Customer may export Customer Data during the Retrieval Period;
- following the Retrieval Period, Guardyx will delete or render inaccessible Customer Data within ninety (90) days, unless retention is required by law, legal process, regulatory obligations, audit requirements, security incident investigation, or retention within backup systems subject to standard deletion cycles.
Termination does not relieve either party of obligations incurred prior to termination.
20. Service Level Agreement
Any service availability commitments, service credits, or response time obligations apply only to the extent expressly stated in an executed SLA or applicable Order Form.
Absent an executed SLA or Order Form provision, Guardyx does not provide any binding service level commitment.
Marketing materials, Documentation, or public statements do not create binding SLA obligations unless expressly incorporated into an Order Form or SLA.
21. Beta Features
Guardyx may offer Beta Features. Beta Features:
- may be incomplete or unstable;
- may change substantially or be discontinued without notice;
- may contain defects;
- may not be supported;
- are provided “as is” and “as available,” without warranties of any kind.
Customer’s use of Beta Features is voluntary and at Customer’s sole risk. Guardyx’s liability with respect to Beta Features is excluded to the maximum extent permitted by law.
22. Warranties and Disclaimers
Each party represents and warrants that it has the legal power and authority to enter into and perform these Terms.
THE SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE.”
TO THE MAXIMUM EXTENT PERMITTED BY LAW, GUARDYX DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, RELIABILITY, SECURITY, QUIET ENJOYMENT, AND UNINTERRUPTED OPERATION.
WITHOUT LIMITING THE FOREGOING, GUARDYX DOES NOT WARRANT THAT:
- THE SERVICES WILL BE ERROR-FREE OR UNINTERRUPTED;
- AI OUTPUTS, POLICY DECISIONS, APPROVAL OUTCOMES, OR GENERATED RESULTS WILL BE ACCURATE, COMPLETE, SAFE, OR APPROPRIATE FOR ANY PURPOSE;
- ALL UNSAFE, UNAUTHORIZED, OR UNDESIRED AGENT ACTIONS WILL BE PREVENTED;
- THIRD-PARTY SERVICES, FOUNDATION MODELS, OR INTEGRATIONS WILL REMAIN AVAILABLE, CONSISTENT, OR FUNCTION AS EXPECTED.
Customer acknowledges that AI-generated outputs may not be unique and that other users or systems may generate similar or identical outputs.
23. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW:
- NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, BUSINESS INTERRUPTION, OR COST OF SUBSTITUTE SERVICES, ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICES, WHETHER IN CONTRACT, TORT, NEGLIGENCE, STRICT LIABILITY, STATUTE, OR OTHERWISE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
- GUARDYX IS NOT LIABLE FOR GENERATED OUTPUTS, AGENT ACTIONS OR FAILURES TO ACT, CUSTOMER APPROVAL DECISIONS, MISSED, FAILED, DELAYED, OR INCORRECT POLICY ENFORCEMENT, THIRD-PARTY TOOL OR API FAILURES, FOUNDATION MODEL OUTPUTS OR MODEL BEHAVIOR, CUSTOMER CONFIGURATION ERRORS, OR LOSSES RESULTING FROM CUSTOMER’S FAILURE TO IMPLEMENT HUMAN REVIEW OR APPROPRIATE GOVERNANCE CONTROLS. THESE EXCLUSIONS APPLY REGARDLESS OF WHETHER GUARDYX’S GOVERNANCE, APPROVAL, OBSERVABILITY, OR POLICY ENFORCEMENT FEATURES WERE ENABLED, CONFIGURED, MISCONFIGURED, BYPASSED, UNAVAILABLE, OR FAILED TO OPERATE AS INTENDED.
- EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICES SHALL NOT EXCEED THE AMOUNTS PAID BY CUSTOMER TO GUARDYX FOR THE SERVICES DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
- THE LIMITATIONS IN THIS SECTION DO NOT APPLY TO:
- CUSTOMER’S PAYMENT OBLIGATIONS;
- FRAUD OR WILLFUL MISCONDUCT;
- LIABILITY THAT CANNOT BE LIMITED UNDER APPLICABLE LAW.
LIABILITY ARISING FROM A PARTY’S BREACH OF CONFIDENTIALITY OBLIGATIONS, GROSS NEGLIGENCE, OR INDEMNIFICATION OBLIGATIONS SHALL NOT EXCEED THREE (3) TIMES THE LIABILITY CAP SET FORTH IN SECTION 23(C).
Some jurisdictions do not permit certain limitations of liability, so portions of this Section may not apply.
24. Indemnification
24.1 Indemnification by Customer
Customer will defend, indemnify, and hold harmless Guardyx, its Affiliates, and their respective officers, directors, employees, contractors, and agents from and against any third-party claims, liabilities, damages, judgments, settlements, penalties, costs, and expenses, including reasonable attorneys’ fees, arising out of or relating to:
- Customer Data, including its content, accuracy, legality, and processing;
- Customer’s or its Authorized Users’ or Agents’ use of the Services;
- Customer’s AI agents, workflows, automations, approval decisions, or Tool configurations;
- Customer’s violation of applicable law or these Terms;
- Customer’s violation of any third-party rights;
- Customer’s use of Third-Party Services in connection with the Services.
24.2 Indemnification by Guardyx
Guardyx will defend Customer from and against any third-party claim alleging that the Services, as provided by Guardyx and used in accordance with these Terms, infringe such third party’s intellectual property rights, and will indemnify Customer for damages and reasonable attorneys’ fees finally awarded against Customer by a court of competent jurisdiction or paid in settlement approved by Guardyx in writing.
Guardyx’s obligations under this Section 24.2 do not apply to claims arising from:
- Customer Data;
- modifications to the Services not made by Guardyx;
- combinations of the Services with products, models, systems, or data not provided by Guardyx where the claim would not have arisen but for such combination;
- use of the Services in violation of these Terms or Documentation;
- Beta Features;
- generated outputs, Agent actions, approval decisions, or Customer-configured workflows;
- third-party AI models or Third-Party Services;
- open-source software where the applicable open-source license terms grant the relevant usage rights or where Customer independently incorporated, required, modified, or substituted such open-source software.
If the Services become, or in Guardyx’s opinion are likely to become, subject to an infringement claim, Guardyx may, at its option:
- procure the right for Customer to continue using the affected Services;
- modify or replace the affected Services to make them non-infringing;
- terminate the affected Services and refund any prepaid, unused fees for the terminated portion of the Services.
This Section states Guardyx’s sole and exclusive liability, and Customer’s exclusive remedy, for intellectual property infringement claims relating to the Services.
Notwithstanding anything to the contrary in Section 23, Guardyx’s aggregate liability arising from its indemnification obligations under this Section 24.2 shall not exceed three (3) times the liability cap set forth in Section 23(C).
24.3 Indemnification Procedures
The indemnified party must:
- promptly notify the indemnifying party of the claim;
- provide reasonable cooperation at the indemnifying party’s expense;
- permit the indemnifying party to control the defense and settlement of the claim.
The indemnifying party may not settle any claim in a manner that admits liability or imposes obligations on the indemnified party without the indemnified party’s prior written consent, not to be unreasonably withheld.
25. Compliance and Export Controls
Customer represents and warrants that it is not, and is not acting on behalf of any party that is:
- located in, organized under the laws of, or ordinarily resident in an embargoed jurisdiction;
- identified on any restricted-party or sanctions list maintained by the U.S. government, the EU, the UK, or other applicable authority;
- otherwise prohibited from receiving the Services under applicable law.
Customer agrees to comply with all applicable export control, sanctions, anti-corruption, privacy, and AI governance laws.
Customer will promptly notify Guardyx if Customer becomes subject to any sanction, export restriction, denied-party listing, or similar legal restriction during the term.
Unless otherwise expressly agreed in writing, the Services are hosted in shared multi-tenant infrastructure and Customer Data may be processed or stored in the United States or other jurisdictions where Guardyx or its Subprocessors operate. Regional data residency, localization, or sovereign hosting commitments apply only where expressly stated in an applicable Order Form or DPA.
Customer acknowledges that the Services may depend on Third-Party Services, cloud infrastructure providers, and foundation model providers operating in multiple jurisdictions.
26. Force Majeure
Neither party will be liable for delays or failures resulting from causes beyond its reasonable control, including acts of God, natural disasters, internet failures, telecommunications failures, labor disputes, governmental actions, cyberattacks, denial-of-service attacks, failures of cloud providers, failures of Third-Party Services, or foundation model provider outages or changes.
The affected party will use commercially reasonable efforts to mitigate the impact and resume performance.
27. Assignment
Neither party may assign these Terms without the other party’s prior written consent, except in connection with a merger, acquisition, reorganization, financing, or sale of substantially all assets.
Neither party may assign these Terms to a direct competitor of the other party without prior written consent, not to be unreasonably withheld, conditioned, or delayed.
Any attempted assignment in violation of this Section is void. These Terms bind and inure to the benefit of the parties’ permitted successors and assigns.
28. Notices
Legal notices to Guardyx must be sent in writing to: Code Above Lab, Inc., Attn: Legal, legal@guardyx.ai, with a copy to any registered address provided by Guardyx.
Notices to Customer may be sent to the email address associated with Customer’s account or any address provided in the applicable Order Form.
Notices are deemed given upon delivery if sent by email, provided the sender has not received a bounce or non-delivery notification, or three (3) business days after dispatch if sent by recognized courier.
Each party is responsible for maintaining current notice and contact information during the term.
29. Governing Law and Dispute Resolution
These Terms are governed by the laws of the State of Delaware, excluding conflict-of-law principles.
Before initiating arbitration, the parties agree to attempt in good faith to resolve disputes through informal negotiations between authorized representatives for at least thirty (30) days following written notice of the dispute. If either party fails to respond to a written notice of dispute within fifteen (15) days, the informal negotiation requirement will be deemed satisfied.
If unresolved, disputes will be resolved by binding arbitration administered by JAMS in San Francisco, California under its Comprehensive Arbitration Rules.
Either party may seek injunctive or equitable relief in any court of competent jurisdiction for misuse of Confidential Information, intellectual property, or security violations.
Nothing in this Section prevents either party from seeking relief in small claims court for qualifying claims.
Each party waives any right to participate in class actions or class-wide arbitration.
30. Changes to Terms
Guardyx may modify these Terms from time to time.
For material changes that adversely affect Customer’s rights or obligations, Guardyx will provide at least thirty (30) days’ prior notice through the Services, email, or other reasonable means.
Non-material changes become effective upon posting.
If Customer does not agree to a material change, Customer may terminate the affected subscription or Order Form before the effective date of the change.
Changes do not retroactively modify executed Order Forms unless expressly agreed by the parties.
31. Survival
The following provisions survive termination or expiration of these Terms:
- accrued payment obligations;
- confidentiality obligations;
- intellectual property rights;
- disclaimers and limitations of liability;
- indemnification obligations;
- audit and compliance obligations;
- governing law and dispute resolution provisions;
- any provision that by its nature should survive termination.
32. Miscellaneous
32.1 Entire Agreement
These Terms, together with any applicable Order Form, DPA, SLA, Acceptable Use Policy, Privacy Policy, Security Addendum, and Documentation referenced herein, constitute the entire agreement between the parties regarding the Services and supersede all prior or contemporaneous agreements and understandings on the subject matter.
32.2 Order of Precedence
In the event of a conflict between the governing documents, the order of precedence is:
- applicable Order Form;
- applicable Data Processing Addendum;
- applicable Service Level Agreement;
- these Terms;
- Documentation and policies.
32.3 Independent Contractors
The parties are independent contractors. These Terms do not create any partnership, joint venture, agency, or employment relationship.
32.4 No Third-Party Beneficiaries
These Terms do not confer rights on any third party, except as expressly provided for Guardyx’s Affiliates and indemnified parties.
32.5 Waiver and Severability
Failure to enforce any provision is not a waiver. If any provision is held unenforceable, it will be enforced to the maximum extent permitted, and the remaining provisions remain in full force and effect.
32.6 Counterparts and Electronic Signatures
These Terms and any Order Forms may be executed in counterparts and by electronic signature, each of which is deemed an original.
32.7 Open Source Software
Certain components of the Services may include or be distributed with open-source software subject to applicable open-source license terms.
Guardyx will make available applicable attribution notices and license disclosures as required by applicable open-source licenses, including through documentation, the Services, or an online attribution page maintained by Guardyx.
32.8 Usage Protection and Platform Integrity
Guardyx may implement reasonable technical measures to protect the Services, including rate limits, workload throttling, abuse detection, usage caps, anti-automation protections, or suspension of workloads that threaten the security, integrity, availability, or stability of the Services.
Guardyx may restrict or suspend workloads involving excessive resource consumption, scraping, credential abuse, malware, unauthorized cryptomining, denial-of-service activity, or other abusive behavior.
32.9 Professional Advice Disclaimer
Guardyx does not provide legal, medical, accounting, financial, employment, cybersecurity, or regulatory advice. Customer is solely responsible for obtaining qualified professional review where appropriate and for determining whether use of the Services is appropriate for Customer’s specific legal, regulatory, operational, or business requirements.
32.10 U.S. Government Rights
If Customer is a U.S. Government entity, the Services are “commercial computer software” and “commercial computer software documentation” and are provided with only those rights specified in these Terms pursuant to FAR 12.212 and DFARS 227.7202.
32.11 Publicity
Neither party may publicly use the other party’s name, logo, or trademarks without prior written consent, except as required by law.
Notwithstanding the foregoing, Customer may publicly reference its use of the Services in factual statements, and Guardyx may identify Customer in factual customer lists, in each case without separate written consent and subject to any trademark usage guidelines provided by the other party.
32.12 Feedback
Customer may provide suggestions, enhancement requests, recommendations, or other feedback regarding the Services (“Feedback”). Feedback does not include Customer Data or Confidential Information.
Customer grants Guardyx a perpetual, irrevocable, worldwide, sublicensable, transferable, royalty-free license to use, modify, incorporate, and otherwise exploit such Feedback without restriction or obligation to Customer.
33. Contact Information
Code Above Lab, Inc.
Operator of the Guardyx AI service
Legal Contact: legal@guardyx.ai
Privacy Contact: privacy@guardyx.ai
Website: https://guardyx.ai
See also: Privacy Policy · Data Processing Addendum · Acceptable Use Policy · Cookie Policy.