Terms of Service
Last updated: 5 July 2026
1. Acceptance and Scope
The service is offered to businesses and professionals acting in the course of their trade or profession. By creating an Asqav account, signing into the Asqav cloud, or using the Asqav SDK against our hosted services, you confirm you are not acting as a consumer and agree to these Terms of Service.
If you are accepting on behalf of an organization, you confirm that you have authority to bind that organization. If you do not agree, do not use the service.
Legal notices to Asqav must be sent to info@asqav.com. Notices to you are sent to the email address on your account, deemed received one business day after sending.
2. The Service
Asqav provides governance infrastructure for AI agents. The service is delivered in two forms:
- Asqav SDK: a source-available library released under the Elastic License 2.0 and distributed on GitHub, PyPI and npm. The SDK can be self-hosted with no dependency on the Asqav cloud. The standalone receipt verifier inside it carries a separate Apache-2.0 grant, so verifying a receipt stays unrestricted.
- Asqav Cloud: a hosted service at asqav.com that issues ML-DSA agent identities, signs action records, runs policy checks, issues PQC-JWT tokens, and stores tamper-evident audit trails. The cloud runs in hash-only mode by default, as described in our Data Handling page.
These Terms govern your use of the Asqav Cloud. Use of the SDK on its own is governed by the Elastic License 2.0 in the SDK repository, and the standalone verifier by its Apache-2.0 grant.
3. Account and API Key Responsibility
You are responsible for everything that happens under your account and your API keys.
- Provide accurate registration details and keep them current.
- Keep your password and API keys secret. Treat API keys like production credentials.
- Notify info@asqav.com promptly if you suspect unauthorized use.
- You are liable for activity signed by your keys until they are revoked.
4. Acceptable Use
You agree not to:
- Use the service for any unlawful purpose, or to violate the rights of others.
- Attempt to gain unauthorized access to our systems, other accounts, or other organizations' data.
- Probe, scan, or stress-test the service except against your own organization and within rate limits.
- Transmit malware, exploits, or content designed to disrupt the service.
- Resell, sublicense, or white-label the Asqav Cloud without a written agreement.
- Access the service for the purpose of building a competing service, or publish performance benchmarks of the service, only with our prior written consent. A competing service means a service that offers cryptographic receipts for AI-agent actions as its primary function. Commercial use that competes with Asqav, such as reverse-engineering the API to build a competing receipt product or using receipts issued by the service to calibrate a competing signer, requires a commercial license. This does not limit your rights under the Elastic License 2.0 to the SDK source code, or your Apache-2.0 rights to the standalone verifier.
- Reverse engineer, decompile, or attempt to extract the source of paid features of the Asqav Cloud, except to the extent that applicable law explicitly permits.
5. Tiers, Billing, and Cancellation
The service is offered on two plans, Free and Enterprise. Current features and limits are listed on our pricing page.
- Free: no fee, subject to the limits and retention windows shown on the pricing page. We may rate-limit, throttle, or reduce free-plan capacity at any time.
- Enterprise: priced by volume under a written agreement with us. Fees, billing period, and any custom limits are set out in that agreement. Contact info@asqav.com for a quote.
- Taxes: fees are exclusive of VAT and other applicable taxes, which we add where required.
- Late or failed payment: we may suspend the service if an invoice is more than 14 days overdue, after notice to your billing contact.
Cancellation. You may stop using the Free plan and delete your account at any time from the dashboard or by writing to info@asqav.com. Enterprise customers may cancel as set out in their written agreement, or otherwise on 30 days written notice effective at the end of the then-current billing period.
Refunds. Fees already paid are non-refundable, except that if you terminate for our uncured material breach under section 9, we refund the prepaid fees covering the period after the effective date of termination. Nothing in this section limits rights that mandatory law gives you.
6. Service Availability and Support
We work to keep the Asqav Cloud available, but we do not offer an uptime commitment on the Free plan. Maintenance windows, third-party outages (for example our hosting or email providers), and force majeure events can affect availability.
Enterprise customers may sign a separate written agreement with explicit uptime targets and service credits. In the absence of such a written agreement, no uptime commitment is made.
We respond to support requests by email at info@asqav.com. Enterprise agreements define response times for support and any severity-based targets. This is a support commitment and is separate from any uptime commitment.
7. Customer Data
You own your customer data. You grant Asqav a limited license to process it solely to operate, secure, and support the service.
- In hash-only mode (the cloud default), Asqav receives a SHA-256 hash of each action context plus a small whitelisted metadata bag. We never receive the prompts, tool arguments, or model outputs themselves. The hash is unsalted unless you supply a salt of your own, and an unsalted hash over a predictable action context can be guessed by anyone holding it, so we make no claim that the underlying content is beyond recovery. See How the hash is computed.
- In self-hosted deployments, customer data does not leave your infrastructure unless you opt into cloud telemetry.
- We do not sell customer data and we do not use customer data to train machine-learning models.
See the Privacy Policy and Data Handling page for details.
8. Intellectual Property
Asqav owns the Asqav Cloud, including its UI, backend services, ML-DSA signing infrastructure, dashboards, and brand assets. Nothing in these Terms transfers ownership of the platform to you.
The Asqav SDK is released under the Elastic License 2.0, which is source-available rather than open source: you may read, modify and self-host the source, and you may not provide it to third parties as a managed service or circumvent its license keys. The standalone receipt verifier is separately licensed Apache-2.0, so an independent party can verify an Asqav receipt without accepting the Elastic License 2.0. That Apache-2.0 grant covers exactly one file, verify_receipt.py; no other file, including the TypeScript verifier, carries that grant. Those licenses, not these Terms, govern your rights to the SDK source code.
You retain all rights in your customer data and in any application you build that uses the service. Feedback you send us about the product may be used by Asqav without obligation.
9. Termination and Data Export
Either party may terminate this agreement on 30 days written notice (email is sufficient). Either party may terminate immediately if the other materially breaches these Terms and does not cure within 14 days of written notice.
On termination:
- Your access to the Asqav Cloud ends.
- You may export your data for 30 days after termination through the standard export endpoints or by written request to info@asqav.com.
- Records you anchored to public timestamping services contain only hashes and cannot be recalled by us.
- Sections that by their nature should survive termination (IP, liability cap, indemnification, governing law) survive.
10. Limitation of Liability
To the maximum extent permitted by law, Asqav's total aggregate liability arising out of or related to these Terms or the service is limited to the fees you paid Asqav in the 12 months immediately preceding the event giving rise to the claim. For free-plan users, that cap is 100 EUR.
Neither party is liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, lost data, or business interruption, even if advised of the possibility.
These limits do not apply to liability that cannot be limited under applicable law, including liability for intent or deliberate recklessness. For a party's indemnification obligations and breach of confidentiality, the total aggregate liability is limited to two times the cap above.
11. Disclaimers
The service is provided on an "AS IS" and "AS AVAILABLE" basis. Asqav disclaims all warranties, express or implied, including merchantability, fitness for a particular purpose, non-infringement, and any warranty arising from course of dealing or usage of trade.
Asqav does not warrant that the service will be uninterrupted, error-free, or secure against every threat, that defects will be corrected, or that the service will meet your specific regulatory requirements without configuration on your side.
12. Indemnification
You agree to defend and indemnify Asqav against third-party claims arising from your customer data, your use of the service in violation of these Terms, or your violation of applicable law.
Asqav agrees to defend and indemnify you against third-party claims that the Asqav Cloud, as provided by us and used in accordance with these Terms, infringes that third party's intellectual property rights.
Indemnification is conditioned on prompt written notice of the claim, sole control of the defense by the indemnifying party, and reasonable cooperation from the indemnified party.
13. Governing Law and Disputes
These Terms are governed by the laws of the Netherlands, excluding its conflict-of-laws rules and the United Nations Convention on Contracts for the International Sale of Goods. The parties first attempt to resolve any dispute informally by writing to info@asqav.com. Any dispute that is not resolved within thirty days of that written notice is submitted to the exclusive jurisdiction of the competent courts of Amsterdam, the Netherlands.
Either party may seek injunctive or equitable relief in any court of competent jurisdiction to protect confidential information or intellectual property.
14. Changes to These Terms
We may update these Terms. Material changes will be announced by email to the address on your account at least 14 days before they take effect. Non-material changes (typos, clarifications, broken links) take effect on posting. The "Last updated" date at the top of this page reflects the current version.
Your continued use of the service after the change takes effect constitutes acceptance of the updated Terms. If you do not agree, you may cancel as described in section 5.