These Terms govern business access to the software, APIs, and related services provided by Triage Sec, Inc. ("Triage"). They apply when you affirmatively accept them or enter an order or agreement that incorporates them. If you accept for an organization, you represent that you have authority to bind it, and "Customer" means that organization.
1. The agreement
An "Order" is an order form, statement of work, or other ordering document agreed by Customer and Triage. It identifies the services and scope being provided. "Customer Data" means information submitted to, accessed by, or generated through the services on Customer's behalf, excluding Triage's underlying technology.
A separate signed agreement controls over these Terms for the services it covers. An Order controls where it expressly overrides these Terms. An applicable data processing addendum ("DPA") and mandatory transfer terms control conflicts concerning their subject matter. Product documentation does not amend agreed commercial or data-use terms.
Our Privacy Policy describes how we handle personal information. It does not replace a DPA. The parties must put any legally required data processing terms in place before the relevant processing begins.
2. Access and accounts
Subject to the agreement, Customer may use the services for its business purposes within the agreed scope and term, including in its own applications where that use is included. Customer may authorize employees and contractors to use the services on its behalf and is responsible for their compliance. Customer may not resell access unless agreed in writing.
Account users must be adults legally able to accept the applicable obligations. Customer must provide accurate account information, protect credentials, manage access and integrations, and notify Triage of suspected unauthorized use. Administrators may manage users, settings, and data within their permissions. Customer is responsible for appropriate notices to its users.
3. Deployment and integrations
The applicable Order or agreement identifies the services, deployment, usage limits, and any implementation or support commitments. Hosted and customer-managed arrangements may have different responsibilities and data flows. Customer-managed software is licensed within the agreed scope; delivery does not transfer ownership of Triage technology.
Customer is responsible for the models, tools, accounts, infrastructure, permissions, and applications it controls. Customer authorizes connections it enables and must have the rights needed to use them. Separate terms may apply to customer-selected providers and open-source components. Triage remains responsible for its own obligations, including those concerning providers it engages.
The services can evaluate and steer activity made available through supported integrations. Customer remains responsible for its agent harness and downstream tool execution. Controls depend on the integration and configuration; they do not cover activity outside that boundary.
4. Authorized use
Customer must use the services lawfully and only with data and systems it is authorized to access. Customer must not:
- Violate privacy, confidentiality, intellectual property, or other legal rights.
- Conduct unauthorized access, credential theft, unlawful surveillance, fraud, or destructive activity.
- Disrupt the services or other users, bypass access controls or usage limits, or misuse another party's credentials.
- Copy or extract proprietary technology without authorization, or reverse engineer it except where applicable law permits.
- Represent that Triage guarantees security or regulatory compliance or has certified a system without written authorization.
Authorized security research and adversarial evaluation are permitted within the agreed scope, including attack examples needed for that work. Customer must contain the activity and avoid harm to others. Testing Triage's infrastructure requires separate authorization.
Data requiring special contractual or technical arrangements may be submitted only after those arrangements are agreed. Customer is responsible for lawful collection, required notices and permissions, and lawful instructions for processing Customer Data.
5. AI and security limitations
AI judgments and corrections can be wrong. The services may miss harmful activity, flag legitimate activity, or produce an unsuitable correction. Results depend on the models, policies, data, tools, and deployment involved.
Customer is responsible for validating its use case, reviewing material decisions and configurations, and maintaining appropriate oversight and independent safeguards. The services do not guarantee security, alignment, legal compliance, or detection of every problem. They must not be the sole safeguard for activities where failure could cause death, serious injury, or comparable harm.
An evaluation or activity record is not by itself proof of a downstream outcome or regulatory compliance. These limitations do not reduce Triage's express obligations under the agreement.
6. Customer Data and adaptation
Customer retains its rights in Customer Data. Customer authorizes Triage to process that data as needed to provide, secure, and support the agreed services and follow Customer's lawful documented instructions, including through personnel and service providers involved in that work.
Where authorized, this includes evaluating activity, calibrating components, preparing examples and datasets, and training and evaluating customer-specific adaptations. The applicable agreement and documented instructions govern those uses. Acceptance of these Terms does not by itself authorize unrelated model training or cross-customer reuse of Customer Data.
Rights in customer-specific adaptations, model artifacts, and bespoke deliverables are governed by the applicable Order or separate agreement, subject to underlying technology and third-party licenses. No rights in Triage's or its licensors' underlying software, models, or other technology are transferred except as expressly granted.
Customer may voluntarily provide feedback about the services. Triage may use that feedback to improve its products, subject to confidentiality and Customer Data restrictions. Neither party may use the other's name or logo as an endorsement without permission.
7. Confidentiality and data protection
Each party will protect the other's nonpublic information that is identified as confidential or should reasonably be understood to be confidential. Customer Data is Customer's confidential information. The recipient will use it only for the agreement, protect it with reasonable care, and disclose it only to people who need it for that purpose and are subject to appropriate confidentiality obligations.
This does not cover information the recipient can show was lawfully known without restriction, became public without a breach, was independently developed, or was lawfully received without a confidentiality duty. Legally required disclosure is permitted, with notice where legally allowed and disclosure limited to what is required.
Each party must comply with the data protection obligations applicable to it. Security commitments, incident cooperation, processing instructions, and return or deletion requirements are governed by the applicable agreement and DPA. Retained confidential information remains protected after the services end.
8. Fees, term, and service commitments
Fees, usage charges, payment timing, service term, renewal, cancellation, refunds, and any service levels are specified in the applicable Order or separate agreement. These Terms do not create an automatic renewal or convert a trial into a paid subscription. A purchase requires an agreed commercial arrangement.
Preview or evaluation features may change or be discontinued. Any production use, support, or other commitments for those features must be agreed. Confidentiality and applicable data protection obligations continue to apply.
Product descriptions and roadmap discussions do not create a commitment to future functionality or a particular uptime or support response time. Express commitments in an Order or separate agreement remain binding.
9. Suspension and ending access
Triage may suspend affected access where reasonably necessary to address unlawful use, a material breach, a security risk, or a legal requirement. Where practicable, Triage will provide notice and an opportunity to resolve the issue, limit the action to the affected services, and restore access when the reason is resolved.
Customer may stop using the services, subject to its agreed payment and term obligations. Termination rights for paid services follow the applicable agreement. Triage may discontinue free or evaluation access on reasonable notice, unless immediate action is needed for security or legal reasons.
When access ends, Customer must stop using software whose license has ended. Return, export, deletion, and any required retention of Customer Data follow the applicable agreement and law. Ending access does not eliminate accrued obligations or provisions intended to continue, including ownership, confidentiality, and data protection.
10. Warranties and responsibility
Except for express commitments in the applicable agreement and to the extent permitted by law, the services are provided "as is" and "as available." Triage disclaims implied warranties of merchantability, fitness for a particular purpose, and noninfringement. Triage does not warrant that the services will be uninterrupted or error-free, or that AI outputs will be accurate or suitable for every use.
Any agreed liability limits, indemnities, warranties, and remedies are set out in the applicable Order or separate agreement. Nothing in these Terms excludes obligations or liability that cannot lawfully be excluded or limits an individual's nonwaivable rights.
11. Updates and general provisions
Triage may issue updated Terms and will identify the version date. Material changes will be communicated through an appropriate channel, with acceptance obtained where required. Posting new Terms does not retroactively change an existing signed agreement or expand rights to Customer Data.
Each party must comply with applicable laws, including export controls and sanctions. The parties are independent contractors. If a provision is unenforceable, the remaining provisions continue to apply to the extent permitted by law. Failure to enforce a provision is not a waiver.
Any agreed governing law, venue, and dispute procedures are set out in the applicable Order or separate agreement. Notices follow that agreement; otherwise, contact Triage Sec, Inc. at info@triage-sec.com with the subject Legal notice.