Terms of Service

Effective date: August 27, 2026

Last updated: August 27, 2026

Version 1.0

1. Who we are and what these Terms cover

These Terms are between you and Inexorable, Inc., a Delaware corporation doing business as Confidential AI ("we", "us"). They govern your use of:

  • Confidential Cloud: our hosted services, including the Inference API, Confidential VMs, and Confidential Agents (the "Cloud Services").
  • Confidential Software: our licensed software stack for running TEE-based confidential computing on your own infrastructure, including Confidential Metal, C8s, AI Workload Services, Confidential OS and Hardened VM Images, Attested Builds, and Client Libraries and SDKs (the "Software").

Together, the "Services".

By creating an account, accepting these Terms, or using the Services, you agree to them. If you act for an organization, you represent that you are authorized to bind it, and "you" means that organization.

If you have a signed agreement with us (an "Enterprise Agreement"), it controls where it conflicts with these Terms. Your purchase orders and click-through terms have no effect.

2. Who may use the Services

You must be 18 or older and not barred from using the Services under applicable law, export controls, or sanctions.

3. Accounts and API keys

Keep your account information accurate. You are responsible for all activity under your account and API keys. Keep keys secret, do not embed them in client-side code, and tell us at security@confidential.ai if you believe one has been compromised.

4. Cloud Services

4.1 What we provide

We run your workloads inside hardware-backed Trusted Execution Environments (TEEs). Your prompts, completions, data, and workloads are processed inside confidential virtual machines, and TLS is terminated only inside the TEE. During normal operation we do not have, and our architecture is designed to prevent us from obtaining, access to the plaintext of your requests, responses, or workload memory.

Confidential computing reduces risk. It does not eliminate it. Hardware vulnerabilities, firmware issues, side-channel attacks, customer misconfiguration, compromised credentials, and infrastructure outside our control may affect confidentiality. The hardware and firmware of Intel, AMD, and NVIDIA form the root of trust for the Services and are not open source.

Every Cloud Service exposes attestation. Verify it before sending sensitive data.

4.2 What we do not provide

We do not guarantee that model output is accurate or fit for any purpose. Output comes from third-party open-weight models and is yours to evaluate. We do not provide medical, legal, financial, or other professional advice. We do not prevent denial of service. The Services are not designed for fail-safe uses where failure could cause death, injury, or severe damage.

4.3 Your responsibilities

You are responsible for verifying attestation against measurements you have chosen to accept; the lawfulness of the data you send, including any consents; your end users and any application you build on the Services; reviewing model output before relying on it; and complying with laws that apply to your use of AI.

4.4 Regulated data

Do not use the Services to process Protected Health Information under HIPAA, payment card data, or other sector-regulated data unless we have agreed in writing to permit it. Personal data under the GDPR or UK GDPR is covered by our Data Processing Addendum, available on request.

4.5 Confidential VMs and Agents

You are responsible for everything you deploy, configure, store, or run inside a confidential VM, including secrets, access controls, backup, and recovery. We do not back up in-enclave state and cannot recover it. Export anything you need before terminating an instance. We may suspend or terminate an instance where we reasonably believe it necessary to protect the Services, other customers, or the attestation chain, or where required by law or for non-payment. Suspension may interrupt a workload. Terminated instances are irrecoverable. You have no right to physically access our hardware.

4.6 Changes, limits, and previews

We may add, change, or retire models, endpoints, measurements, regions, and features. We will give reasonable notice of changes that affect attestation measurements or pricing, except where security requires faster action. We may apply rate limits and quotas. Features labeled alpha, beta, or preview are provided as is and may change or be discontinued.

5. Licensed Software

5.1 License

The Software is licensed only under a signed Enterprise Agreement, for the use, term, scope, and quantities stated in your Order Form. No other rights are granted. Unless the Order Form says otherwise, use is limited to internal evaluation and testing.

5.2 Open source and proprietary components

The software components that run inside the TEE and handle your data are open source by default. Our own components are published at github.com/confidential-dot-ai; third-party components, such as inference engines and open-weight models, come from their upstream projects, each under its own license. We also offer proprietary components, such as performance-optimized inference engines. Where one is used on the Cloud Services, we will identify it in the model catalog; where one is included in licensed Software, we identify it in your Enterprise Agreement. Proprietary components are measured and attested like any other component, but their source is not published.

5.3 Restrictions

You may not reverse engineer or derive the source of the Software except for open source components or where law permits; copy, modify, or create derivative works except as an open source license allows; remove proprietary notices; use the Software to build or benchmark a competing product; sublicense, host, or provide the Software to third parties; circumvent license or technical controls; or use the Software outside the permitted use.

5.4 Support, updates, and verification

Support and updates are as stated in your Enterprise Agreement. You are responsible for deploying updates and for the security of your own infrastructure. From time to time, on reasonable notice, we may verify that your deployment conforms to the licensed scope, relying on the Software's attestation and metering records. Use beyond the licensed scope requires a prompt true-up.

6. Fees

Cloud Services are billed at the rates published at confidential.ai/pricing or in your Enterprise Agreement. Software licenses are billed as stated in your Enterprise Agreement. Usage is measured by our systems. Fees exclude taxes, which you are responsible for other than taxes on our income. We may change published prices with notice; changes do not apply to a committed term in an Enterprise Agreement. We may suspend service for non-payment.

7. Acceptable use

You may not use the Services, or allow anyone else to, for illegal, harmful, abusive, or unsafe activity. That includes: violating any law, sanctions, or the rights of others; processing data you have no right to process; generating or distributing child sexual abuse material; facilitating terrorism, trafficking, or serious violence; harassment, defamation, impersonation, or unlawful discrimination; malware or attacks on any system; non-consensual sexual content involving real people; deceptive synthetic media where disclosure is required by law; instructions for weapons or other materials likely to cause serious harm; attempting to extract model weights, defeat attestation, or probe the TEE boundary other than through responsible disclosure to security@confidential.ai; bypassing authentication, rate limits, or quotas; falsifying usage or attestation data; or reselling API access except through an application you operate or an arrangement we have approved in writing.

We may investigate suspected violations and throttle, suspend, or terminate access. Because we cannot inspect your content, enforcement relies on metadata, reports, and legal process.

8. Your data

You own your prompts, completions, workloads, models, and data ("Your Content"). We claim no rights in it and do not use it to train models. Our architecture is designed so that we cannot access it in plaintext.

We collect and process account data, usage metadata, logs from outside the TEE boundary, and operational telemetry, as described in our Privacy Policy. For licensed Software we may use aggregated, de-identified operational data.

Where you send us personal data subject to the GDPR or UK GDPR, we act as your processor under our Data Processing Addendum.

On termination we delete account data within a reasonable period, except where retention is required by law. Content is processed transiently inside TEEs and is not stored by us; anything you have stored in Confidential VMs or Agents must be exported before termination.

9. Intellectual property

We own the Services, the Software, our documentation, and all related intellectual property, including attestation and measurement logic, TEE configuration, security architecture, and any improvements, regardless of who develops them. Nothing transfers ownership to you. Feedback you give us may be used without restriction. Open source components are governed by their own licenses. Third-party models are provided under their own licenses, which you are responsible for locating, reviewing, and complying with.

10. Confidentiality

Each party will protect the other's non-public information with reasonable care and use it only under these Terms. Our confidential information includes the Software, its architecture, attestation and measurement logic, documentation, pricing, and roadmap, except to the extent published as open source. Standard exceptions apply. This section survives termination for three years. Your Content is not our confidential information because we do not receive it in readable form. If we have a separate NDA with you, the more protective terms control.

11. Security and attestation

We maintain a security program appropriate to a confidential computing provider. We will notify you of security incidents affecting your account or the integrity of the attestation chain as required by law.

Attestation evidence describes the state of the enclave at a point in time. It is not a warranty that hardware is free of undisclosed vulnerabilities and is not a substitute for your own security review. It is your responsibility to verify it. We are not liable for loss arising from your failure to verify attestation or your acceptance of a measurement you did not intend to accept.

12. Disclaimers

THE SERVICES AND SOFTWARE ARE PROVIDED "AS IS" AND "AS AVAILABLE". WE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, AND ANY WARRANTY AS TO MODEL OUTPUT. WE DO NOT WARRANT THAT THE SERVICES ARE FREE FROM HARDWARE-LEVEL VULNERABILITIES, INCLUDING SIDE-CHANNEL ATTACKS, IN THIRD-PARTY PROCESSORS OR ACCELERATORS. Any warranty for the Software is as stated in your Enterprise Agreement.

13. Limitation of liability

NEITHER PARTY IS LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR LOST PROFITS, REVENUE, OR DATA. EACH PARTY'S TOTAL LIABILITY UNDER THESE TERMS IS LIMITED TO THE FEES YOU PAID US FOR THE SERVICES GIVING RISE TO THE CLAIM. These limits do not apply to your breach of section 5 or 7, either party's breach of section 10, your payment obligations, infringement of the other party's intellectual property, indemnity obligations, or liability that cannot be limited by law.

14. Indemnity

You will defend and indemnify us against third-party claims arising from Your Content, your application, your end users, your workloads, your use of the Software outside the permitted use, or your breach of section 5 or 7. Any indemnity from us is as stated in your Enterprise Agreement.

15. Term and termination

These Terms apply while you use the Services. Either party may terminate on notice; committed terms in an Enterprise Agreement survive as agreed. We may suspend access immediately to protect the Services, other customers, or the attestation chain, where required by law, or on breach of section 5, 7, or 10. On termination of a Software license, stop using the Software, delete all copies, and return or destroy our confidential information. Accrued fees remain payable. Sections 6, 8 through 14, and 16 through 17 survive, with section 10 surviving for the period stated in it.

16. Governing law and disputes

These Terms are governed by the laws of the State of Delaware, without regard to conflict of laws principles. Disputes are subject to the exclusive jurisdiction of the state and federal courts located in Delaware, except that either party may seek injunctive relief in any court of competent jurisdiction. The UN Convention on Contracts for the International Sale of Goods does not apply.

17. General

You agree to receive notices electronically. You will comply with US export controls and sanctions. Neither party may assign these Terms without consent, except to a successor in a merger or sale of substantially all assets. We may update these Terms with notice; continued use after the effective date is acceptance, and material changes do not apply to a committed term without your agreement. These Terms, the Privacy Policy, the Data Processing Addendum where one applies, and any Enterprise Agreement are the entire agreement, in that order of precedence reversed. Standard severability, waiver, and force majeure terms apply.