Kloy.ai
About Platform Intelligence Blog Contact Us
Navigation menu
About Platform Intelligence Blog Contact Us

Legal / Engagement framework

Terms and Conditions

A non-binding public framework for discussing qualified defensive-security services.

Effective July 21, 2026 Service framework / version 2.1
TERMS02

On this page

  1. Status and formation
  2. Scope and changes
  3. Customer duties
  4. Sensitive handling
  5. Data and security
  6. IP and confidentiality
  7. Commercial terms
  8. Governance and continuity
  9. Risk and termination

This page does not itself create a service agreement. The parties must identify themselves and accept scope and commercial terms in writing.

Contract order

A public inquiry does not purchase a service. No work begins until authorized representatives accept written terms that identify the parties, scope, price, handling requirements, and applicable law.

01

Status of this framework and contract formation

This page describes topics that may apply to a focused evaluation, pilot, or defensive-intelligence service. It is informational and non-binding unless a signed order, proposal, statement of work, master agreement, or other written contract expressly incorporates it.

A binding engagement begins only when authorized representatives identify the contracting entities and accept the applicable written documents. A contact submission, call, demonstration, estimate, draft, or exchange of public information does not create a purchase, service obligation, testing authorization, exclusivity, or confidentiality duty.

If accepted documents conflict, the negotiated master agreement controls, then the order or statement of work, then expressly incorporated policies, unless the signed documents state a different order of precedence.

02

Qualification, scope, acceptance, and changes

Coverage and feasibility depend on the authorized defensive purpose, product family, available context, information sensitivity, customer environment, dependencies, and current availability. Public descriptions and illustrative records do not guarantee support.

  • The written scope should define deliverables, exclusions, assumptions, milestones, dependencies, review contacts, acceptance criteria, and delivery channel.
  • Dates are estimates unless the signed agreement expressly makes them binding.
  • Customer delay, missing authorization, inaccurate input, third-party action, or a material change in risk may change schedule and feasibility.
  • Work outside scope requires an approved written change addressing price, schedule, and handling impact.
  • Acceptance and correction procedures apply only as stated in the signed agreement.
03

Customer authorization and responsibilities

The customer must provide accurate information, qualified contacts, timely decisions, and only systems, data, software, and access it has legal authority to provide. On request, the customer must provide reasonable evidence of authorization and applicable restrictions.

The customer remains responsible for production systems, backups, recovery, change control, regulatory duties, notices to users or third parties, and decisions made from any deliverable. It must independently assess whether an action is appropriate for its environment.

The customer must not direct work against an unauthorized third party or use any information to exploit, harm, surveil, evade controls, or obtain unauthorized access. Validation may occur only within the agreed authorization and safety boundary.

04

Defensive use and sensitive information

The parties must classify and exchange sensitive material only through approved channels with access limited to people who need it for the engagement. The public form and ordinary initial email are not approved for exploit code, credentials, regulated datasets, undisclosed targets, payloads, or reproduction steps.

Safety and disclosure boundaryKloy.ai may redact, delay, limit, return, quarantine, or decline information or work when authorization is unclear, disclosure could create unreasonable harm, coordinated disclosure is affected, or the request exceeds the agreed defensive purpose.

Any vulnerability-coordination duties, disclosure contacts, embargo expectations, regulator notices, and emergency procedures must be written into the engagement where applicable.

05

Data protection and security

Each party must comply with privacy, security, export, and data-handling duties applicable to its role. The customer must minimize personal data and must not provide regulated or sensitive personal data unless the signed scope expressly permits it and establishes appropriate safeguards.

The written agreement should identify permitted data, processing roles, locations, subprocessors if relevant, retention and return or deletion requirements, incident contacts, and any required data-processing terms. It should also allocate responsibility for instructions, rights requests, legal holds, cross-border transfers, backups, and legally required incident notifications.

Kloy.ai may use reasonable security controls appropriate to the agreed information, but no system eliminates all risk. Any specific control standard, certification, audit, recovery objective, notification period, or data location applies only when the signed agreement states it.

The website Privacy Notice governs the initial public inquiry. It does not replace a customer-specific data-processing agreement where one is legally required.

06

Intellectual property and confidentiality

Each party retains its pre-existing technology, data, tools, methods, materials, marks, and know-how. Ownership, license scope, restrictions, and permitted users for engagement-specific deliverables must be stated in the signed agreement. No source-code, patent, trademark, or broader method license is implied.

Confidentiality begins only under an applicable written obligation. The agreement should define confidential information, care standards, permitted recipients, use limits, duration, compelled disclosure, and customary exclusions for information independently developed, already lawfully known, publicly available without breach, or lawfully received from another source.

Public examples and generalized learning may not identify the customer or reveal its confidential information. Any right to use names, marks, testimonials, or case studies requires separate written approval.

07

Fees, taxes, third parties, and compliance

Fees, currency, invoicing, payment timing, expenses, taxes, renewal, price changes, and late-payment consequences apply only as stated in the accepted documents. Unless those documents say otherwise, each party bears its own pre-contract costs.

Third-party products, services, data, licenses, and access may have separate terms and fees. Kloy.ai does not control third-party changes or availability. Each party is responsible for applicable anti-bribery, sanctions, export-control, and trade-compliance duties, and neither party is required to act unlawfully.

08

Governance, service dependencies, and continuity

The signed agreement should name accountable operational, security, privacy, billing, and legal contacts; identify who may approve scope or handling changes; and define the records each party must preserve. Access to another customer's information, internal methods, or unrelated systems is never an audit entitlement.

  • Any service level, support window, response target, maintenance process, escalation path, or recovery objective must be stated expressly.
  • Use of a subcontractor or infrastructure provider remains subject to the allocation of responsibility and notification terms in the signed agreement.
  • Each party should maintain proportionate continuity, backup, incident-response, and personnel-transition measures for the obligations it owns.
  • Neither party should claim compliance from a report, questionnaire, or control description beyond the period, system, and scope that evidence actually covers.

Events outside reasonable control may affect performance. The signed agreement must define notice, mitigation, payment, suspension, and termination consequences for any force-majeure event rather than relying on this public summary.

09

Uncertainty, risk allocation, suspension, and termination

Security work is incomplete by nature. Unless a signed agreement expressly states otherwise, no service guarantees discovery of every issue, prevention of every incident, compatibility with every environment, vendor action, or a particular security or business outcome.

Warranties, remedies, indemnities, liability caps, excluded losses, insurance, audit rights, and responsibility for third-party claims must be negotiated in the signed agreement and remain subject to mandatory law. This public framework does not independently impose or waive those terms.

Kloy.ai may pause or decline work when authorization, payment, required access, safety, legality, sanctions, capacity, or disclosure obligations create a material concern. The signed agreement must govern termination, transition, work in progress, fees, data return or deletion, and surviving obligations.

The signed agreement must also identify notices, governing law, forum or dispute process, assignment, amendment, severability, waiver, order of precedence, and the complete contracting entities. It should state which payment, confidentiality, intellectual-property, data, audit, risk, and dispute obligations survive expiration or termination. Questions may be sent to official@kloy.ai.

Kloy Lab

Kloy.ai develops proactive, defense-first zero‑day intelligence for the patch gap.

Public materials exclude payloads, reproduction steps, and weaponization details.

You can reach us at official@kloy.ai.

Terms of Use Terms and Conditions Cookies Policy Privacy Notice

© 2026 KLOYLAB Inc. All rights reserved.