Terms of Service
Last updated: July 15, 2026
These Terms of Service ("Terms") form a binding agreement between you (an individual or the entity you represent, "Customer," "you," or "your") and ValGuard.ai ("ValGuard," "we," "us," or "our") governing access to and use of the ValGuard AI Security & Governance Gateway, including the validation proxy, dashboard, APIs, SDKs, documentation, and website (together, the "Service").
By creating an account, connecting an application to the Service, clicking "I agree," or signing an order form that references these Terms, you accept these Terms on behalf of yourself and, where applicable, your organization. If you do not agree, do not use the Service. These Terms incorporate by reference the Privacy Policy, Acceptable Use Policy, Data Processing Agreement, Service Level Agreement, and Subprocessors list, each as updated from time to time. If you have an executed order form or enterprise agreement with ValGuard, that document controls to the extent it conflicts with these Terms.
1. Definitions
- "Agent" means a configured routing/validation profile within the Service (guardrails, providers, budgets, and orchestration steps) that Customer creates via the dashboard or declarative JSON/YAML configuration.
- "API Key" means a credential issued by ValGuard to authenticate Customer's calls to the Service.
- "BYOK" ("Bring Your Own Key") means Customer supplies its own upstream LLM provider credentials on a per-request basis; ValGuard uses the key transiently to fulfill that request and does not persist it.
- "Provider Vault" means the ValGuard feature (available on Growth and higher plans) that stores Customer's upstream provider credentials in encrypted form so the Service can use them on Customer's behalf across requests.
- "Customer Data" means data that Customer or its end users submit to or generate through the Service, including account, configuration, and billing information, and — where Customer enables payload logging — Prompts and Outputs.
- "Prompts" means inputs (including system, user, and tool messages) that Customer or its systems send through the Service to an upstream LLM Provider.
- "Outputs" means completions, structured responses, or other content returned by an upstream LLM Provider through the Service.
- "LLM Provider" means a third-party large language model or inference provider (e.g., OpenAI, Anthropic, Google, or a Customer-configured custom/self-hosted endpoint) to which the Service routes Prompts under Customer's instruction and, where applicable, credentials.
- "Guardrails" / "Validators" means the configurable rules (160+ built-in, plus any custom validators Customer configures) the Service applies to ingress (Prompt) and egress (Output) traffic, such as schema, PII/compliance, safety, and format checks.
- "Playbook" means a declarative JSON/YAML export/import of Agent, validator, or orchestration configuration.
- "Order Form" means a mutually executed ordering document, quote, or online checkout referencing these Terms.
- "Plan" means the subscription tier (Free, Developer, Growth, Production, Enterprise, or a custom Enterprise plan) governing Customer's usage limits and features, as described at /pricing or in an Order Form.
2. Eligibility and account registration
You must be at least 18 years old and able to form a binding contract to use the Service. You must provide accurate, current registration information and keep it up to date. You are responsible for all activity that occurs under your account, organization workspace, and API Keys, whether or not you authorized it, except to the extent caused by ValGuard's breach of these Terms. Notify us promptly at security@valguard.neteos.eu if you suspect unauthorized access to your account or a compromised API Key or provider credential.
3. Description of the Service
3.1 What ValGuard does. ValGuard operates as a network proxy positioned between Customer's applications or agents and one or more LLM Providers. Customer routes LLM API calls through the ValGuard gateway, which: (a) validates ingress traffic (Prompts) and egress traffic (Outputs) against Customer-configured Guardrails; (b) monitors usage and cost (budget alerts, token and request limits); and (c) provides observability (analytics, request and validation logs). ValGuard does not train models on, sell, or independently use Customer Data for purposes other than providing, securing, and improving the Service, as further described in the Privacy Policy.
3.2 No payload storage by default. Unless Customer explicitly enables payload logging for an Agent (currently the "Full (debug)" log level, corresponding to the payload_logged request attribute), Prompt and Output content is processed in memory to apply validation and is not persisted by the Service. When payload logging is enabled, stored content is subject to the retention period Customer configures (up to the maximum allowed by its Plan) and to the Privacy Policy and DPA. Customer is solely responsible for deciding whether to enable payload logging, including for any Prompts or Outputs containing personal data or regulated information, and for configuring an appropriate log level and retention period for its use case.
3.3 Guardrails and configuration. Customer configures Guardrails, Agents, budgets, and routing through the dashboard GUI or by importing/exporting Playbooks. Guardrail outcomes (pass/fail/reask) depend entirely on Customer's configuration; ValGuard does not guarantee that any Guardrail will catch every category of unwanted content, and Customer remains responsible for selecting Guardrails appropriate to its use case, industry, and jurisdiction.
3.4 Provider connectivity — BYOK and Provider Vault. Customer may connect to LLM Providers using BYOK (per-request credentials, not stored by ValGuard) or, on eligible Plans, Provider Vault (credentials stored encrypted at rest and used by the Service on Customer's instructions). Customer represents that it holds all rights necessary to use the credentials and models it configures, and that its use of each LLM Provider complies with that provider's own terms of service, usage policies, and applicable law. ValGuard is not a party to, and has no responsibility for, the relationship or agreement between Customer and any LLM Provider.
3.5 Beta and preview features. Features labeled beta, preview, early access, or similar are provided for evaluation purposes only, may change or be discontinued at any time, and are provided without warranty and without SLA credits.
4. Subscription plans, billing, and payment
4.1 Plans and limits. The Service is offered under Free, Developer, Growth, Production, and Enterprise Plans (or a custom Plan under an Order Form), each with its own usage limits (e.g., requests per minute, tokens per month, validations per month, log retention, and feature availability) as published at /pricing or set out in an Order Form. We may update published Plan pricing, limits, and features prospectively; changes to a signed Order Form's pricing during its committed term require mutual agreement or apply only at renewal.
4.2 Billing. Paid Plans are billed in advance on a monthly or annual basis through our payment processor (Stripe) and renew automatically until cancelled. Usage that exceeds Plan limits may be billed as overage at the published per-unit rate, throttled, or both, depending on the Plan. All fees are exclusive of taxes, which Customer is responsible for unless Customer provides a valid tax exemption certificate. Fees are non-refundable except as required by law or expressly stated in an Order Form.
4.3 Free Plan. The Free Plan is provided for evaluation, development, and light production use, without an SLA or uptime commitment, and may be modified, rate-limited, or discontinued at our discretion with reasonable notice where practicable.
4.4 Cancellation. Customer may cancel a paid Plan at any time through the dashboard billing settings or by contacting support@valguard.neteos.eu; cancellation takes effect at the end of the then-current billing period unless otherwise stated. We may suspend or terminate access for non-payment after reasonable notice.
5. Acceptable use
Customer must comply with the Acceptable Use Policy, which prohibits unlawful, abusive, infringing, or security-harming use of the Service, including attempts to circumvent rate limits, billing meters, or Guardrail enforcement, and unauthorized probing of our infrastructure. We may investigate suspected violations and suspend or terminate access as described in the Acceptable Use Policy and Section 13 below.
6. API keys, credentials, and security responsibilities
6.1 Customer responsibilities. Customer is responsible for generating, distributing, rotating, and safeguarding its ValGuard API Keys and any BYOK provider credentials, and for the security configuration of any systems, endpoints, or infrastructure Customer connects to the Service (including custom/self-hosted model endpoints registered via Provider Vault). ValGuard is not responsible for unauthorized access, data loss, or other harm arising from Customer's failure to secure its own API Keys, credentials, or infrastructure.
6.2 Provider Vault security. For credentials stored in Provider Vault, ValGuard encrypts stored credentials at rest and in transit and restricts access on a role and audit-logged basis, as further described in the DPA and Security page. Customer remains responsible for granting appropriate access within its own organization workspace and for promptly revoking or rotating credentials that may be compromised.
6.3 Rate limits and abuse prevention. We may throttle, queue, or reject traffic that exceeds Plan limits or that we reasonably believe is fraudulent, abusive, or a security risk to the Service or other customers.
7. Customer Data, payload handling, and data protection
7.1 Roles. Where Customer Data includes personal data, Customer is the controller (or a processor acting for its own controller) and ValGuard acts as a processor (or sub-processor), as described in the DPA, which is incorporated by reference for customers subject to the GDPR/UK GDPR or similar laws. Enterprise customers may request a signed DPA.
7.2 Processing purposes. ValGuard processes Customer Data to provide, secure, support, and bill for the Service, including in-memory validation of Prompts and Outputs, and — only where Customer enables payload logging — storage of that content for the retention period Customer configures. See Section 3.2.
7.3 International transfers. Where Customer Data is transferred outside the EEA/UK or another jurisdiction with data-transfer restrictions, ValGuard relies on appropriate safeguards (such as Standard Contractual Clauses) as described in the DPA and Privacy Policy.
7.4 Subprocessors. ValGuard uses the subprocessors listed at /legal/subprocessors to deliver the Service. LLM Providers that Customer configures and routes to (via BYOK or Provider Vault) are not ValGuard subprocessors — Customer controls whether and when to send traffic to them, and Customer's relationship with each LLM Provider is governed by that provider's own terms and privacy practices.
7.5 Data subject and consumer rights. Customer is responsible for providing appropriate notices to, and obtaining any consents required from, its own end users regarding Customer's use of the Service and any LLM Provider. ValGuard will provide reasonable assistance with data subject or consumer rights requests as described in the DPA and Privacy Policy.
8. Intellectual property
8.1 Customer IP. As between the parties, Customer retains all right, title, and interest in and to its Prompts, Outputs, Customer Data, configurations, and Playbooks. Subject to the limited rights granted below, ValGuard claims no ownership over Customer's Prompts or the Outputs generated by LLM Providers on Customer's behalf.
8.2 ValGuard IP. ValGuard and its licensors own all right, title, and interest in and to the Service, including the validation proxy, dashboard, configuration engine, Guardrail/validator catalog, orchestration engine, documentation, and all related software, designs, and trademarks (collectively, "ValGuard IP"). Except for the limited right to access and use the Service under these Terms, no rights in ValGuard IP are granted to Customer.
8.3 License to Customer Data. Customer grants ValGuard a limited, non-exclusive, worldwide license to host, process, transmit, and display Customer Data solely to provide, secure, support, and improve the Service, and to comply with law.
8.4 Feedback. If Customer provides feedback or suggestions about the Service, ValGuard may use that feedback without restriction or obligation to Customer.
8.5 Restrictions. Customer must not reverse-engineer, decompile, or attempt to extract source code or the underlying Guardrail catalog from the Service, except to the extent such restriction is prohibited by applicable law, nor use the Service to build a competing product, as further described in the Acceptable Use Policy.
9. Service availability and support
The Service's availability commitments, exclusions, and any service-credit remedies are set out in the Service Level Agreement, which varies by Plan. Free, Developer, and Growth Plans are provided on a best-effort basis without financial credits; Production and Enterprise Plans include the uptime commitments described in the SLA or an Order Form. Support channels and response targets likewise vary by Plan as described in the SLA.
10. Disclaimer of warranties
EXCEPT AS EXPRESSLY SET FORTH IN A SIGNED ORDER FORM OR AS REQUIRED BY APPLICABLE LAW, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING WITHOUT LIMITATION ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. VALGUARD DOES NOT WARRANT THAT: (A) ANY GUARDRAIL OR VALIDATOR WILL DETECT OR PREVENT EVERY UNWANTED, INACCURATE, HARMFUL, OR NON-COMPLIANT PROMPT OR OUTPUT; (B) THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE; OR (C) ANY LLM PROVIDER'S OUTPUT WILL BE ACCURATE, LAWFUL, OR FIT FOR CUSTOMER'S INTENDED USE. VALGUARD IS NOT RESPONSIBLE FOR, AND EXPRESSLY DISCLAIMS ALL LIABILITY ARISING FROM: (I) UNINTENDED AGENTIC LOOPS, RUNAWAY ORCHESTRATION, EXCESSIVE FAN-OUT, OR RETRY/REASK BEHAVIOR RESULTING FROM CUSTOMER'S OWN AGENT, PLAYBOOK, OR ORCHESTRATION CONFIGURATION; (II) COST OVERRUNS, RATE-LIMIT CHARGES, OR BILLING DISPUTES ARISING FROM CUSTOMER'S USE OF, OR AGREEMENTS WITH, ANY THIRD-PARTY LLM PROVIDER (INCLUDING OPENAI, ANTHROPIC, OR ANY OTHER PROVIDER), REGARDLESS OF WHETHER TRAFFIC WAS ROUTED THROUGH THE SERVICE; OR (III) SECURITY BREACHES, DATA LOSS, OR UNAUTHORIZED ACCESS OCCURRING ON CUSTOMER'S OWN INFRASTRUCTURE, ENDPOINTS, ACCOUNTS, OR SYSTEMS, INCLUDING CUSTOM/SELF-HOSTED MODEL ENDPOINTS CUSTOMER CONNECTS VIA PROVIDER VAULT OR BYOK. CUSTOMER IS SOLELY RESPONSIBLE FOR CONFIGURING BUDGET ALERTS, TOKEN LIMITS, ORCHESTRATION DEPTH/FAN-OUT LIMITS, AND GUARDRAILS APPROPRIATE TO ITS RISK TOLERANCE.
11. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW: (A) NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS OPPORTUNITY, ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICE, REGARDLESS OF THE THEORY OF LIABILITY (WHETHER CONTRACT, TORT, NEGLIGENCE, STRICT LIABILITY, OR OTHERWISE) AND EVEN IF THE PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES; AND (B) EACH PARTY'S TOTAL, AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICE WILL NOT EXCEED THE TOTAL FEES ACTUALLY PAID BY CUSTOMER TO VALGUARD IN THE SIX (6) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM. THESE LIMITATIONS APPLY REGARDLESS OF WHETHER A REMEDY FAILS OF ITS ESSENTIAL PURPOSE, AND APPLY TO THE FULLEST EXTENT PERMITTED BY LAW EVEN WHERE A CUSTOMER IS LOCATED IN OR CONTRACTS FROM THE EUROPEAN UNION, PROVIDED THAT NOTHING IN THIS SECTION LIMITS ANY LIABILITY THAT CANNOT LAWFULLY BE LIMITED OR EXCLUDED UNDER MANDATORY PROVISIONS OF APPLICABLE LAW, INCLUDING LIABILITY FOR DEATH, PERSONAL INJURY, FRAUD, OR GROSS NEGLIGENCE WHERE SUCH LIMITATION IS PROHIBITED. THE FEE-BASED CAP IN CLAUSE (B) DOES NOT APPLY TO A PARTY'S INDEMNIFICATION OBLIGATIONS UNDER SECTION 12 FOR THIRD-PARTY IP INFRINGEMENT CLAIMS OR TO CUSTOMER'S BREACH OF SECTION 5 (ACCEPTABLE USE) OR SECTION 8 (INTELLECTUAL PROPERTY).
12. Indemnification
12.1 By Customer. Customer will defend, indemnify, and hold harmless ValGuard and its officers, employees, and agents from and against any third-party claims, damages, and reasonable expenses (including attorneys' fees) arising from or related to: (a) Customer's Prompts, Outputs, or Customer Data; (b) Customer's use of the Service in violation of these Terms, the Acceptable Use Policy, or applicable law; (c) Customer's configuration of Guardrails, budgets, or orchestration; or (d) Customer's relationship or agreement with any LLM Provider.
12.2 By ValGuard. ValGuard will defend, indemnify, and hold harmless Customer from third-party claims alleging that the Service, as provided by ValGuard and used in accordance with these Terms, infringes a valid patent, copyright, or trademark of a third party, except to the extent the claim arises from Customer Data, Customer's configuration, a combination with non-ValGuard products, or Customer's breach of these Terms. If such a claim arises, ValGuard may, at its option, procure a license, modify the Service to avoid infringement, or terminate the affected feature and refund prepaid, unused fees for it.
12.3 Procedure. The indemnified party must promptly notify the indemnifying party of the claim and provide reasonable cooperation; the indemnifying party controls the defense and settlement, provided any settlement that imposes liability or obligations on the indemnified party requires its prior written consent (not to be unreasonably withheld).
13. Term, suspension, and termination
13.1 Term. These Terms remain in effect while Customer maintains an account or an active Plan.
13.2 Termination for convenience. Either party may terminate a month-to-month Plan at any time as described in Section 4.4. Annual or committed Plans terminate at the end of their committed term unless earlier terminated for cause.
13.3 Termination for cause. Either party may terminate these Terms if the other party materially breaches them and fails to cure the breach within thirty (30) days of written notice (or immediately, without notice, if Customer breaches Section 5 (Acceptable Use) or fails to pay undisputed fees when due).
13.4 Suspension. We may suspend access to the Service, in whole or in part, immediately and without prior notice where we reasonably believe suspension is necessary to prevent harm to the Service, other customers, or third parties, to comply with law, or where required by Section 5 or the Acceptable Use Policy, and we will use reasonable efforts to notify Customer promptly where feasible.
13.5 Effect of termination. Upon termination, Customer's right to access the Service ends, and ValGuard will delete or return Customer Data in accordance with the DPA and applicable retention obligations. Sections 1, 7, 8, 10, 11, 12, 14, 15, and 18 survive termination, along with any other provisions that by their nature should survive.
14. Confidentiality
Each party may disclose non-public business, technical, or product information ("Confidential Information") to the other in connection with the Service. The receiving party will use Confidential Information only to perform its obligations or exercise its rights under these Terms, and will protect it using at least the same degree of care it uses for its own confidential information of similar nature (and no less than reasonable care). These obligations do not apply to information that is or becomes public through no fault of the receiving party, was already known to the receiving party without confidentiality obligations, or is independently developed. A party may disclose Confidential Information if legally compelled, provided it gives the other party reasonable notice where legally permitted.
15. Governing law and dispute resolution
15.1 General framework. These Terms are governed by, and will be construed in accordance with, the laws of the Republic of Poland and, as applicable, European Union law, without regard to conflict-of-laws principles, and the courts located in Poland will have jurisdiction over disputes, except as provided below or in an Order Form.
15.2 EU/EEA and UK customers; consumers. Nothing in these Terms limits any mandatory statutory rights, including consumer-protection rights, that Customer has under the law of its country of residence and that cannot be waived by contract. Where Customer qualifies as a consumer under EU or UK law, disputes may also be brought before the competent courts of Customer's habitual residence, and Customer may be entitled to use the EU Online Dispute Resolution platform.
15.3 U.S. and other non-EU commercial customers. For Customer entities incorporated or headquartered outside the European Economic Area and the United Kingdom that contract with ValGuard on a purely commercial (B2B) basis, and where not otherwise specified in a signed Order Form, the parties agree that disputes will be resolved in the courts of Poland as the exclusive forum, and each party waives any objection to that forum on grounds of inconvenient venue, provided that either party may seek interim injunctive relief in any court of competent jurisdiction to protect its intellectual property or Confidential Information.
15.4 Waiver of jury trial and class actions. To the extent permitted by applicable law, each party waives any right to a jury trial and to participate in a class, collective, or representative action against the other party arising out of or related to these Terms or the Service.
15.5 Order Form precedence. An executed Order Form or enterprise agreement may specify a different governing law, venue, or dispute-resolution mechanism (including arbitration), which will control for that Customer to the extent it conflicts with this Section 15.
16. Export control and compliance
Customer will comply with all applicable export control, sanctions, and anti-corruption laws in connection with its use of the Service, and represents that it is not located in, or ordinarily resident in, a country or region subject to comprehensive trade sanctions, and is not listed on any restricted-party list, in each case to the extent such laws apply.
17. Changes to these Terms
We may update these Terms from time to time to reflect changes in the Service, legal or regulatory requirements, or our business practices. For material changes, we will provide notice by posting the updated Terms on this page with a revised "Last updated" date and, where required by law or where changes materially reduce Customer's rights, by additional notice (such as email or an in-dashboard notice) at least thirty (30) days before the change takes effect for existing paid customers. Continued use of the Service after the effective date of a change constitutes acceptance of the updated Terms. If Customer does not agree to a material change, Customer's sole remedy is to stop using the Service and, where applicable, cancel its Plan before the change takes effect.
18. General provisions
18.1 Entire agreement. These Terms, together with the documents incorporated by reference and any applicable Order Form, constitute the entire agreement between the parties regarding the Service and supersede all prior or contemporaneous agreements on the subject.
18.2 Assignment. Customer may not assign these Terms without ValGuard's prior written consent, except to a successor in connection with a merger, acquisition, or sale of substantially all assets, provided the successor agrees to these Terms. ValGuard may assign these Terms in connection with a similar corporate transaction. Any attempted assignment in violation of this Section is void.
18.3 Force majeure. Neither party is liable for delay or failure to perform caused by events beyond its reasonable control, including natural disasters, internet or utility failures, government action, labor disputes, or LLM Provider outages, provided the affected party uses reasonable efforts to mitigate the impact.
18.4 Severability; waiver. If any provision of these Terms is held unenforceable, the remaining provisions remain in full effect, and the unenforceable provision will be modified to the minimum extent necessary to make it enforceable while preserving its intent. Failure to enforce a provision is not a waiver of the right to enforce it later.
18.5 Notices. Legal notices to ValGuard should be sent to legal@valguard.neteos.eu. We may send notices to Customer via the email address or in-dashboard notification associated with its account.
18.6 No third-party beneficiaries. These Terms do not create any rights for, and may not be enforced by, any person or entity that is not a party to them, except as expressly stated in the DPA regarding data subject rights.
18.7 Independent contractors. The parties are independent contractors. Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship.
19. Contact
Questions about these Terms can be sent to:
- Legal: legal@valguard.neteos.eu
- Support: support@valguard.neteos.eu
- Privacy/DPA: privacy@valguard.neteos.eu
- Security: security@valguard.neteos.eu