CODEAWARE TERMS & SERVICE AGREEMENT

Codeaware Terms of Service

Last Updated: August 5, 2026

This Terms of Service Agreement ("Agreement") governs your access to and use of Codeaware.ai’s out-of-band control plane for human + AI collaborative software engineering, including the Headless Intelligence Orchestrator, AI FinOps circuit breakers, and all connected repository, chat, and issue-tracking integrations. By provisioning a workspace, authorizing API access, or registering an autonomous agent, you agree to be bound by the terms below.

CONTRACT_REF_TOS_2026.SH

ARTICLE 1

Acceptance of Terms

By creating a workspace, initiating a private pilot, or authorizing API access, you agree to comply with and be bound by this Agreement. If you are accepting these terms on behalf of an enterprise entity, you represent and warrant that you hold direct administrative authorization to bind your organization to these legal parameters.

  • You must be at least 18 years old, or the age of legal majority in your jurisdiction, to enter into this Agreement.
  • Continued use of the dashboard, webhooks, or CLI after a posted amendment constitutes acceptance of the revised terms.
ARTICLE 2

Service Description — Headless Intelligence Orchestrator

Codeaware.ai operates the Headless Intelligence Orchestrator ("HIO"), an out-of-band telemetry control plane that supervises autonomous coding agents across your software development lifecycle without executing code inside your production infrastructure. The HIO ingests repository telemetry, attributes work to human or agent actors, and coordinates dispatch across your connected toolchain.

  • Passive Compliance Layer: the Orchestrator observes and routes signals; it never merges, deploys, or executes code changes on your behalf.
  • Agent Attribution Engine: behavioral analytics classify every commit, pull request, and review comment by its true human or AI author with documented confidence scoring.
  • Vendor-Agnostic Dispatch: the HIO can supervise agents from multiple vendors concurrently without requiring migration off your existing toolchain.
ARTICLE 3

User Responsibilities & API Guardrails

You are responsible for securing every API token, webhook secret, and service-account credential issued to your workspace. You are solely accountable for actions performed by any human developer or autonomous agent operating under your organization's authorized scope.

  • Credential Hygiene: rotate and revoke API tokens immediately upon employee offboarding or agent decommissioning.
  • Agent Registration: all autonomous agents (e.g. Devin, Claude Code, GitHub Copilot Workspace) must be registered before being granted write access to monitored repositories.
  • Suspension Rights: Codeaware reserves the right to suspend any workspace exhibiting high-frequency recursive anomalies or abuse of shared infrastructure.
ARTICLE 4

AI FinOps & Circuit Breaker Limits

Each workspace defines spending guardrails through its agent_budget_policies configuration, which governs the maximum token spend, dollar ceiling, and retry count permitted per autonomous task before Codeaware’s circuit breaker suspends execution.

  • Default Safety Margin: workspaces without a custom agent_budget_policies entry inherit a $15.00 per-task safety margin, matching the platform default circuit breaker threshold.
  • Manual Override: halted tasks require an authorized administrator to acknowledge and release the circuit breaker before execution resumes.
  • No Liability for Upstream Token Costs: Codeaware meters and reports LLM token consumption but is not liable for usage charges billed directly on your third-party Anthropic, OpenAI, or self-hosted model provider account.
ARTICLE 5

Third-Party Integrations

The Service integrates with third-party providers to extend telemetry coverage across your toolchain. Your use of these integrations is additionally governed by each provider's own terms of service, and Codeaware is not responsible for their availability, security, or data handling practices.

  • Atlassian (Jira & Confluence): OAuth-scoped read access correlates issue keys with pull requests; disconnecting the integration inside Jira revokes Codeaware’s access within minutes.
  • GitHub: webhook subscriptions stream commit, pull request, and review events; Codeaware requests the minimum repository scopes required for attribution and never requests write access to your default branch protections.
  • Anthropic: Claude-family models may be invoked on your behalf for code review summarization; requests are subject to Anthropic’s API terms and are never used to train third-party foundation models.
ARTICLE 6

Intellectual Property & Transient Processing

We enforce strict row-level security (RLS) parameters. Under no circumstances does Codeaware retain, store, or utilize your proprietary intellectual property or codebase repository files to train public models. Every retrieval action performed by our indexing system is transient, isolated, and encrypted in memory.

ARTICLE 7

Acceptable Use & Anti-Feedback Loop Guard

You agree not to bypass, abuse, or systematically manipulate the platform's telemetry protocols. Specifically, you shall not configure autonomous agents to repeatedly perform recursive loop operations targeting our feedback channels in a manner intended to trigger artificial rating inflation or adversarial token consumption.

ARTICLE 8

Limitation of Liability

To the maximum extent permitted by law, Codeaware.ai shall not be held liable for any indirect, incidental, special, or consequential damages. This includes, without limitation, direct loss of source code, automated database drops, budget overruns from unchecked loop warnings, production system locks, or unauthorized human/AI repository merges.

ARTICLE 9

Indemnification

You agree to defend, indemnify, and hold harmless Codeaware.ai, its subsidiaries, founders, and officers from and against any claims, damages, liabilities, or losses arising from your deployed autonomous engineering workflows or any violations of acceptable repository security guidelines.

ARTICLE 10

Termination of Service

Either party may terminate active services upon 30 days written notice. Upon termination, all API webhooks and data stream authorizations must be revoked. Your access to historical attribution scorecards, FinOps telemetry logs, and agent benchmark metrics will be permanently de-provisioned.

ARTICLE 11

Governing Law & Dispute Resolution

This Agreement shall be governed, interpreted, and construed in accordance with the laws of the State of California, without regard to its conflict of law principles. In the event of any controversy, claim, or dispute arising out of this Agreement, the parties agree to first seek informal mediation in good faith.

  • Venue: any legal suit, action, or proceeding shall be instituted exclusively in the federal or state courts of San Francisco.
  • Binding Arbitration: if a dispute remains unresolved within 45 days of informal mediation, it shall be finalized via binding arbitration administered by the American Arbitration Association (AAA) under its Commercial Arbitration Rules.
ARTICLE 12

Miscellaneous & Amendments

This document constitutes the entire legal agreement between you and Codeaware.ai. If any provision of these terms is deemed invalid or unenforceable, the remaining parameters shall survive in full effect. We reserve the right to amend these Terms of Service upon major version releases — continued workspace telemetry implies consent.

  • Questions about this Agreement can be directed to security@codeaware.ai.