Arbitex EULA — End User License and Usage Agreement
Last updated: March 7, 2026
Draft — for reference and review only. Non-binding until attorney-reviewed and approved.
This agreement is between you (the person or organization using the Arbitex platform) and Arbitex, Inc. ("Arbitex," "we," or "us"). By using the platform, you agree to these terms.
If you are using Arbitex on behalf of an organization, "you" in this agreement refers to that organization, and you are representing that you have the authority to bind them to these terms.
1. Customer Data Protection
These are Arbitex's core commitments on how we handle data you send through the Platform. They are not buried in fine print — they are foundational to how the service works.
We will not train AI models on your data. Arbitex will not use your data — including your prompts, AI responses, policy configurations, or any other content you route through the Platform — to train, fine-tune, benchmark, or otherwise improve any AI model, whether operated by Arbitex or any third party. No exceptions. No opt-outs required — this prohibition is the default and only mode.
We will not use your data for secondary purposes. Your data may only be used for: (a) fulfilling the specific service request you submitted; (b) providing the contracted services described in your subscription agreement; and (c) security monitoring and compliance obligations required to operate a trustworthy service. Your data will not be used for analytics, product improvement, marketing, or any other purpose beyond these three permitted uses.
We collect only what we need. Arbitex applies data minimization principles throughout the Platform. We collect and process only the minimum data required to provide the service. We do not retain prompt or response content beyond what is necessary for DLP inspection and the audit log retention period you configure. We do not build profiles of your users beyond what is needed to operate your account.
Retention follows your configuration and applicable law. Audit log records are retained for the period you set in your account settings. When your account closes, we delete your data within the timeframe specified in Section 5, subject to any retention obligations required by law or regulation. You may request earlier deletion at any time by contacting [email protected].
2. What You Are Getting
Arbitex grants you a limited, non-exclusive, non-transferable license to use the Arbitex platform ("the Platform") as described in our documentation. This license is subject to the terms below.
The Platform is a software service — we are not selling you ownership of any code or infrastructure.
3. Acceptable Use
You may use the Platform to:
- Route AI requests from your applications to supported AI model providers
- Inspect and enforce policies on AI traffic passing through your account
- Log AI interactions for compliance and audit purposes
- Configure governance rules for your organization's AI usage
You may not use the Platform to:
a. Attempt to break or probe the Platform itself. Security research against Arbitex infrastructure requires prior written agreement. Running automated scans, fuzzing, adversarial inputs designed to test our defenses, or any activity intended to find vulnerabilities in the Platform without authorization is not permitted. If you find a security issue, report it to [email protected].
b. Circumvent safety controls of your AI providers. Do not use the Platform in a way that is designed to bypass, disable, or work around the safety systems, usage policies, or content restrictions of the AI model providers whose APIs you route through Arbitex. Arbitex is a governance tool — using it to evade governance, including your providers' governance, is a misuse of the Platform.
c. Send data you are not authorized to process. You are responsible for ensuring that the data you route through the Platform is data you are legally permitted to process, share with third-party AI providers, and store in connection with the governance records Arbitex creates.
d. Use the Platform for illegal purposes. Do not use the Platform to process, transmit, or store information in violation of applicable law, or to facilitate any activity that violates applicable law.
4. Your Responsibility for AI Provider Compliance
The Platform routes your requests to AI model providers (such as OpenAI, Anthropic, Google, and others). Each of those providers has their own terms of service, acceptable use policies, and content restrictions.
You are responsible for complying with your AI providers' terms. Arbitex does not represent or guarantee that using the Platform puts you in compliance with your providers' policies. The governance infrastructure Arbitex provides is a tool to help you enforce your own policies — it does not substitute for reading and following your providers' terms.
If your use of a provider through the Platform violates that provider's terms, you bear that responsibility. Arbitex is not a party to your agreements with AI providers and will not be held liable for violations you cause.
5. Data You Send Through the Platform
What you send is yours. Arbitex does not claim ownership of the data you route through the Platform, the prompts you send, the responses you receive, or the audit log records generated from your usage.
What Arbitex processes. In operating the Platform, Arbitex processes request metadata and inspection results as necessary to provide the service. In the Hybrid Outpost deployment model, AI traffic (prompts and responses) is processed entirely within your infrastructure and does not pass through Arbitex servers. In SaaS deployments, traffic passes through Arbitex infrastructure for inspection and routing.
Retention. Audit log records are retained for the period specified in your account settings (30 days, 90 days, or a custom period if your subscription includes it). You can export your audit records at any time. When your account is closed, we will retain records for a period required by applicable law, then delete them. You may request deletion of your data by contacting [email protected]; we will process deletion requests subject to any retention obligations imposed by law or regulation.
Your data obligations. If you route personal data through the Platform, you are responsible for having a lawful basis to process that data, for any disclosures required by privacy law, and for compliance with regulations that govern personal data (such as GDPR and HIPAA). Arbitex's DLP inspection features are tools to help you identify and act on sensitive data — using them does not automatically make you compliant with any specific regulation.
6. What Arbitex Does Not Do
To be clear about the scope of the Platform:
- Arbitex does not provide legal advice about your compliance obligations.
- Arbitex does not guarantee that the Platform will detect all sensitive data in all contexts. The inspection pipeline is designed to be accurate, but no automated system is perfect.
- Arbitex does not review the content of your AI prompts or responses for purposes other than operating the Platform as described.
- Arbitex does not provide indemnification for violations of AI provider terms that you cause through your use of the Platform.
7. No Reverse Engineering or Competitive Use
You may not:
- Reverse engineer, decompile, or disassemble the Platform
- Copy the Platform's interfaces or functionality to build a competing product
- Use access to the Platform to gather information about Arbitex's architecture or security controls for competitive intelligence purposes
8. Liability Limitations
The Platform is provided "as is." To the maximum extent permitted by applicable law, Arbitex does not make warranties — express or implied — about the Platform's fitness for any particular purpose, its accuracy, or its uninterrupted availability.
Liability cap. Arbitex's total liability to you for any claims arising from your use of the Platform is limited to the fees you paid for the Platform in the 12 months before the claim arose. This cap applies to all types of claims — contract, tort, or otherwise — to the fullest extent permitted by law.
No liability for consequential damages. Arbitex is not liable for indirect, incidental, special, or consequential damages — including lost profits, data loss, or business interruption — arising from your use of or inability to use the Platform, even if Arbitex was advised that such damages were possible.
Exceptions. These limitations do not apply to liability that cannot be excluded by law in your jurisdiction, or to claims arising from Arbitex's fraud, gross negligence, or willful misconduct.
9. Changes to This Agreement
Arbitex may update this agreement. When we do, we will post the updated version with a new effective date. If the changes are material, we will notify you by email or through the Platform at least 30 days before they take effect. Continued use of the Platform after that date means you accept the updated terms.
10. Governing Law
This agreement is governed by the laws of the State of Delaware, United States, without regard to conflict of law principles. Any disputes will be resolved in the state or federal courts located in Delaware, and both parties consent to jurisdiction there.
11. Contact
Questions about this agreement:
- Legal: [email protected]
- Security issues: [email protected]
- Support: [email protected]
Arbitex, Inc.
United States