Legal
Terms of Service
Last updated
Draft — review by counsel pending
This document is the initial version of MCP Guard’s standard Terms of Service. Customers under a signed Master Services Agreement (MSA) are governed by the MSA, not by these terms. Contact legal@mcp-guard.ai for the MSA.
1.What MCP Guard is — and what it is not
MCP Guard provides software: a deterministic policy gate for agent tool calls, a hash-chained audit log, an embeddable review queue, and (in the Enterprise tier) a managed policy authoring service. These Terms govern your use of that software and any hosted components (the “Services”).
MCP Guard is software, not insurance. We do not act as an insurer, indemnifier, or guarantor of the behavior, output, or consequences of any AI agent. We do not assume your regulatory obligations under HIPAA, PCI-DSS, GDPR, SOX, or any other framework. We do not warrant that any specific policy you author or adopt will prevent any specific outcome.
What we warrant is bounded and stated in Section 5 (Software Warranty).
2.Definitions
- Customer
- The legal entity that accepts these Terms or executes an Order Form referencing them.
- Services
- The MCP Guard software, SDKs, hosted endpoints, dashboard, and any documentation we publish at mcp-guard.ai.
- Policy
- The set of rules, action catalogs, risk classifications, and reviewer configurations that the Customer authors, adopts, or otherwise causes the Services to enforce.
- Risk Pack
- A reference template we publish (e.g., Healthcare, Fintech, Ops/IT) that includes an action catalog, starter Policy, reviewer playbook, and a rationale document reviewed by outside counsel for the accuracy of the statements it makes. Risk Packs are templates, not legal advice.
- Customer Data
- Any data the Customer or its agents submit to the Services for evaluation, audit, or display.
- Documentation
- The published technical and operational documentation for the Services at docs.mcp-guard.ai and mcp-guard.ai.
3.License
Subject to these Terms and payment of fees, we grant the Customer a worldwide, non-exclusive, non-transferable, revocable license, during the term, to use the Services for the Customer’s internal business purposes. The Customer may not (a) resell, sublicense, or commercially exploit the Services, (b) reverse-engineer them except as required by law, (c) use them to develop a competing product, or (d) use them in violation of applicable law.
4.Customer obligations and Policy ownership
The Policy is the Customer’s. The Customer authors, adopts, or selects the Policy that the Services enforce. The Customer is solely responsible for ensuring the Policy is appropriate for its use case, complies with applicable law and regulation, and reflects the Customer’s risk tolerance. We provide templates, simulators, linters, and (in Enterprise) drafting assistance — we do not select Policy for the Customer.
Risk Packs are templates. If the Customer adopts a Risk Pack, the resulting Policy in the Customer’s repository is the Customer’s Policy. The counsel-reviewed rationale document accompanying a Risk Pack is provided for the Customer’s CISO, compliance team, and outside counsel to review; it is not legal advice to the Customer and does not establish an attorney-client relationship.
The Customer is responsible for: (i) the lawfulness and accuracy of Customer Data; (ii) securing its own credentials, API keys, and reviewer accounts; (iii) ensuring its agents and integrations comply with the Customer’s own contractual and regulatory obligations; and (iv) any decisions made or actions taken by its agents, employees, or systems on the basis of the Services’ output.
5.Software warranty
For paid tiers, during the term, we warrant that the Services will perform substantially as described in the Documentation. If they do not, the Customer’s exclusive remedy is for us to use commercially reasonable efforts to correct the non-conformity, or — if we cannot — to refund prepaid fees for the affected period.
For hosted Services, we will use commercially reasonable efforts to meet the uptime targets published in the Documentation. SLA credits (if any) are the Customer’s exclusive remedy for downtime.
The free SDK and free tier are provided as-is, with no warranty.
6.Disclaimer of warranties
EXCEPT AS EXPRESSLY STATED IN SECTION 5, THE SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE,” AND MCP GUARD DISCLAIMS ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.
Without limiting the foregoing, we do not warrant that: (a) the Customer’s Policy will prevent any specific outcome; (b) any agent will behave correctly, safely, or as the Customer expects; (c) the Services will catch hallucinations the Customer did not write a rule for; (d) the Services will satisfy any specific regulatory framework absent the Customer’s correct configuration and operation.
7.Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY CONSEQUENTIAL, INCIDENTAL, INDIRECT, SPECIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, DATA, OR BUSINESS OPPORTUNITY, EVEN IF ADVISED OF THE POSSIBILITY.
EACH PARTY’S TOTAL CUMULATIVE LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS WILL NOT EXCEED THE AMOUNTS PAID BY THE CUSTOMER TO MCP GUARD IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM.
This cap is fundamental to the parties’ bargain and applies regardless of the form of action (contract, tort, statute, or otherwise). It does not apply to a party’s indemnification obligations under Section 8, breach of confidentiality, or payment obligations.
8.Mutual indemnification (IP only)
By MCP Guard. We will defend the Customer against any third-party claim alleging that the Services, when used as permitted by these Terms and the Documentation, infringe a third party’s patent, copyright, or trademark — and pay damages finally awarded.
By the Customer. The Customer will defend MCP Guard against any third-party claim arising from: (i) the Customer’s Policy, Customer Data, or use of the Services in violation of these Terms or applicable law; (ii) decisions made or actions taken by the Customer’s agents, employees, or systems; or (iii) any allegation that the Customer’s use of the Services caused harm to a third party arising from agent behavior — and pay damages finally awarded.
These are the parties’ sole and exclusive indemnification obligations.
9.Confidentiality
Each party will protect the other’s confidential information with at least the care it uses for its own — and not less than reasonable care. Confidential information excludes information that (a) was already known without an obligation of confidence, (b) becomes publicly known without breach of these Terms, (c) is rightfully received from a third party without obligation, or (d) is independently developed without use of the other party’s information.
10.Data protection
For the hosted Services, we process Customer Data as a data processor on the Customer’s behalf. A separate Data Processing Addendum is available on request and is incorporated by reference for Customers subject to GDPR, UK GDPR, or comparable regimes. HIPAA Business Associate Agreements are available only on the Enterprise tier.
11.Fees and term
Fees are stated on the pricing page or in the applicable Order Form. Self-serve subscriptions auto-renew monthly or annually as indicated; either party may cancel before the next renewal. Enterprise subscriptions are governed by the executed Order Form and (if any) MSA.
We may suspend the Services if fees are more than 15 days overdue, after written notice. Either party may terminate for the other’s uncured material breach (30 days’ notice).
12.Governing law and dispute resolution
These Terms are governed by the laws of Switzerland, without regard to conflict-of-laws principles. Each party submits to the exclusive jurisdiction of the courts of Zurich for any dispute arising under or related to these Terms.
13.Changes
We may update these Terms from time to time. We will post the updated version here and update the “Last updated” date. If a change materially reduces the Customer’s rights, we will give 30 days’ advance notice by email. Continued use after the effective date constitutes acceptance.
14.Miscellaneous
These Terms (together with any Order Form, DPA, BAA, or MSA the parties have signed) are the entire agreement on the subject and supersede prior agreements. If any provision is held unenforceable, the rest stays in effect. Neither party may assign these Terms without the other’s consent, except in connection with a merger, acquisition, or sale of substantially all assets.
Contact: legal@mcp-guard.ai