LEGAL & TRUST

Terms of Service. Governed systems, shared expectations.

Last updated: September 25, 2026. These terms govern your access to and use of the Spctre platform, CLI tools, SDKs, and managed decision gateway services operated by Ciwrl Technologies LLC d/b/a Spctre. Refunds, cancellation, and renewals are covered by the Refund Policy.

Agreement Service Scope Billing Fees & Renewal Access Control API & Credential Security Agent Liability Autonomous Execution Conduct Acceptable Use
Agreement

Platform capabilities and scope of service

Service terms

Spctre is operated by Ciwrl Technologies LLC d/b/a Spctre. Spctre provides a unified control plane to write, test, simulate, compile, and publish security and governance policies for autonomous systems.

Core Control Plane & Gateways

Subject to compliance with these terms, Spctre grants you a limited, non-exclusive, non-transferable, revocable license to access our administrative console, compile policy bundles, and integrate your runtimes with our decision gateways.

Open Source Components & Tooling

Our core engine and command-line interfaces (CLIs) are distributed under separate open-source licenses (typically Apache 2.0). Your use of those specific components is governed by their respective licenses, which take precedence over these terms where applicable.

Service Level Agreements (SLA)

Standard workspaces are provided on an "as-is" and "as-available" basis. Premium Spctre Cloud workspaces are governed by dedicated Service Level Agreements covering latency, availability, and dedicated review queues.

Billing

Fees, billing, and renewal

Paid plans

The Community edition is free and open source under Apache 2.0, and nothing in this section applies to it. Paid Spctre Cloud plans, their rates, and what each includes are set out on the pricing page; all amounts are in US dollars. Enterprise engagements are governed by a signed order form, which takes precedence over this section where the two differ.

Who collects payment

Paddle.com Market Limited is our merchant of record and reseller. Payments are collected by Paddle, charges appear on your statement as Paddle rather than as Spctre, and Paddle's Buyer Terms apply to the transaction alongside these terms. As merchant of record, Paddle determines, collects, and remits any sales tax, VAT, or GST due on the purchase; the amount is shown at checkout and itemized on the receipt Paddle issues.

Billing period and renewal

  • Subscriptions are billed in advance for the period you choose, monthly or annually, and annual plans are charged once for the year.
  • Subscriptions renew automatically at the then-current rate for the same plan and period unless cancelled before the renewal date. Paddle emails a receipt for every charge.
  • We may change a rate. A change applies from your next renewal and never mid-period, and we will give you at least 30 days' notice before it takes effect.
  • The hosted trial is limited by capacity rather than by time. Nothing is charged until you choose a paid plan.

Usage beyond an included capacity

Each paid plan includes a governed-event capacity and a retention window. Where your plan meters usage beyond what it includes, that usage is billed monthly in arrears at the rate published on the pricing page — monthly in arrears even on an annual plan, so a busy month cannot accumulate into a single surprise at renewal — and appears as a separate line item on the invoice.

Failed payments

If a charge fails, Paddle retries it and notifies you. If an invoice remains unpaid after those attempts we may suspend access to the hosted workspace, and we will tell you before we do. Suspension does not delete your evidence: governance records remain subject to the retention window for your plan and can be exported while the account exists. Continued non-payment may lead to termination under Rules & Suspensions below.

Cancellation and refunds

You can cancel at any time and keep access until the end of the period you have paid for. A first subscription payment is covered by a 14-day money-back guarantee, and your statutory rights are never reduced. The full terms, including how to request a refund, are in the Refund Policy, which forms part of these terms.

Billing questions go to support@spctre.dev.

Access Control

Account credentials and API token security

User obligations

Token Custody

You are entirely responsible for the security and confidentiality of your administrative credentials, client IDs, and API keys. Any action authorized by your keys is deemed authorized by your organization.

Rate Limits

To maintain gateway reliability, we apply dynamic rate limits on policy compilation and gateway evaluation requests. Circumventing these limits via concurrent key generation is strictly prohibited.

Security Incidents

You must immediately notify Spctre Security at security@spctre.dev in the event of any unauthorized credential exposure, workspace compromise, or token leak in your agent configuration repos.

Agent Liability

Liability boundaries for autonomous agent actions

CRITICAL STATEMENT

IMPORTANT NOTICE ON RUNTIME ACTIONS: Spctre is a policy evaluation and audit control plane. Spctre does NOT execute the actual tools, write the code files, transfer funds, or invoke external APIs on behalf of your autonomous systems.

Autonomous Consequences

You retain exclusive ownership, configuration, and control over the agent runtimes that call the Spctre gateway. You are solely responsible for the actions, database mutations, infrastructure costs, and API side-effects generated by your autonomous agents.

Enforcement Deficiencies

Spctre evaluates metadata against policies you author. If an agent executes a destructive action due to an incorrectly configured policy rule, a bypassed SDK check, or a missing runtime target mapping, Spctre is not liable for any resulting damage or loss.

Limits of Liability

To the maximum extent permitted by law, Ciwrl Technologies LLC d/b/a Spctre shall not be liable for any direct, indirect, incidental, special, or consequential damages resulting from tool execution failures, agent operational failures, or ledger synchronization delays.

Acceptable Use

Prohibited Operations

  • You may not use Spctre to coordinate or manage agents engaged in illegal activities or cyberwarfare.
  • You may not probe, scan, or test the vulnerability of our decision gateways without explicit permission.
  • You may not inject malicious payloads, loop scripts, or exploit the rule engine compiler.
  • You may not build wrappers designed to hide agent identity or bypass audit chain transparency.
Termination

Rules & Suspensions

  • We reserve the right to suspend workspaces in active breach of access control or acceptable use guidelines.
  • Upon termination, your right to evaluate policy decisions via our hosted gateways will immediately cease.
  • You can delete your account and export your rule history at any time through the administrative console.
  • Provisions regarding intellectual property, autonomous liability, and limits of liability shall survive termination.