Terms of Service

Including our Privacy Policy — Effective [EFFECTIVE DATE]

1. Acceptance of Terms

These terms (“Terms”) govern your use of Altheris, operated by JPO Studios Ltd (“we”, “us”, “our”). By creating an account, registering an agent, or otherwise using the service, you agree to these Terms, including the data practices described in Section 6. If you do not agree, do not use the service.

2. Description of Service

Altheris is an SDK and platform that provides security infrastructure for AI agents. When an agent is registered, we issue it a signed Ed25519 identity “passport” and record its actions in a tamper-evident, hash-chained audit log. Receipt hashes from this log are periodically anchored to the Polygon blockchain, allowing anyone to independently verify that an agent's recorded history has not been altered, through our public verification API.

Depending on your plan, the service may also include runtime scope enforcement, prompt injection detection, output filtering, behavioural baseline monitoring, emergency lockdown controls, compliance reporting, and webhook integrations. These features are designed to help address common AI agent security risks, including categories in the OWASP Top 10 for LLM Applications (for example, LM05: Improper Output Handling).

3. Account Registration

You must provide accurate, current information when creating an account, and you must be authorised to act on behalf of any organisation you register. You are responsible for safeguarding your account credentials and API keys, for all activity that occurs under your account, and for ensuring that any agent you register is configured and operated lawfully. Notify us immediately at team@altheris.io if you suspect unauthorised access to your account.

4. Acceptable Use

You must not, and must not permit any agent registered under your account to:

  • use the platform for unlawful, fraudulent, or harmful activity;
  • attempt to circumvent runtime scope enforcement, prompt injection detection, rate limits, or audit logging;
  • tamper with, falsify, or attempt to rewrite hash-chain action logs or on-chain anchored receipts;
  • misrepresent an agent's identity or forge verification records;
  • reverse-engineer, disrupt, or overload the service or its infrastructure.

5. Subscription & Billing

Paid plans are billed per the tiers published on our pricing page, currently: Free (Free), Growth (£19/mo), Starter (£29/mo), Business (£49/mo), Enterprise (Custom). Subscriptions are billed in advance through Stripe; upgrades and downgrades are prorated and take effect immediately. You may cancel at any time from your billing settings, effective at the end of the current billing period.

6. Data & Privacy

What we collect. Account information (name, email, company name, authentication identifiers), usage data (how you interact with the dashboard and API, including request metadata and timestamps), and agent metadata (registered agents, their declared scopes, action logs, and the cryptographic material used to verify them).

How we use it. To provide the service (registering and verifying agents), for security monitoring (detecting anomalous or out-of-scope activity), and for compliance (producing tamper-evident audit trails and reports you can rely on).

Storage. Your data is stored in the EU using Supabase in the eu-west-2 (London) region, encrypted at rest and in transit over TLS.

Sharing. We do not sell your data. We share data only with processors required to run the service: Stripe (payments) and the Polygon network (on-chain anchoring of receipt hashes). Anchored data consists of cryptographic hashes only — never your raw content.

Retention. We retain account and agent data for as long as your account is active. On termination, you may export your data for a reasonable period, after which it may be deleted from our systems, except where retention is required by law. Hashes already anchored on-chain are immutable and cannot be deleted, by the nature of the Polygon network.

Your rights. As we are EU-hosted, you have rights under the GDPR to access, rectify, delete, and port your personal data, and to object to or restrict its processing. To exercise any of these rights, contact us at team@altheris.io and we will respond within the statutory timeframe.

Cookies. We use essential cookies only — those required to keep you signed in and to operate the service. We do not use advertising or third-party tracking cookies.

7. Security Practices

Every agent registered with Altheris is issued a signed Ed25519 identity passport, and its actions are recorded in a tamper-evident hash chain. Receipt hashes from this chain are periodically anchored to the Polygon blockchain to provide independent, publicly verifiable proof of integrity.

Account data is isolated using Row Level Security, with strict service-role separation and role-based access control for teams. All data is encrypted at rest and in transit over TLS, and hosted in the EU (Supabase, eu-west-2, London) to support GDPR data residency.

Higher plan tiers add further protections designed to reduce agent-specific risk, including prompt injection detection, runtime scope enforcement, output filtering, and behavioural baseline monitoring, alongside audit logs and compliance reporting for your records.

8. Intellectual Property

Altheris, the SDK, and all associated materials are the property of JPO Studios Ltd. We grant you a limited, non-exclusive, non-transferable licence to use the service in accordance with these Terms. You retain all rights to the data and agents you bring to the platform.

9. Disclaimers & Limitation of Liability

The service is provided “as is” and “as available”, without warranties of any kind, express or implied, including any warranty of merchantability, fitness for a particular purpose, or non-infringement. We do not warrant that the service will be uninterrupted, error-free, or that it will detect or prevent every security risk to your agents.

To the maximum extent permitted by law, JPO Studios Ltd is not liable for indirect, incidental, or consequential damages, and our total liability arising out of or relating to these Terms is limited to the fees you paid in the twelve months preceding the claim.

10. Termination

You may cancel at any time from your billing settings. We may suspend or terminate access for breach of these Terms. On termination you may export your data for a reasonable period, after which it may be deleted, subject to Section 6 (Retention).

11. Governing Law

These Terms are governed by the laws of England and Wales, and any disputes are subject to the exclusive jurisdiction of its courts.

12. Changes to These Terms

We may update these Terms from time to time. If we make material changes, we will notify you by email or through the dashboard before the changes take effect. Continued use of the service after changes take effect constitutes acceptance of the revised Terms.

Contact

Questions about these Terms or your data? Email team@altheris.io.