Skip to content
bolde.What’s yours stays yours.
AboutFeaturesRoadmapFAQ
Request Early Access
AboutFeaturesRoadmapFAQ
Request Early Access

Legal

Terms of Service.

Last updated
2026-07-25
Scope
The Bolde platform, applications, and services; United States customers only
Contracting entity
Agentic Secure Group Inc., a Delaware C-Corporation, trading as Bolde
Publisher of record
Mojave Research Inc., the verified Microsoft publisher of the Bolde applications (Microsoft Partner ID 7086299)
Contact
legal@bolde.ai

PLEASE READ — THESE TERMS AFFECT YOUR LEGAL RIGHTS.

These Terms include a BINDING ARBITRATION AGREEMENTand a CLASS-ACTION, COLLECTIVE-ACTION, AND REPRESENTATIVE-ACTION WAIVER (Section 20) that govern how disputes between you and the ASG ecosystem are resolved. Except for the limited matters described in Section 20, you and the Company agree to resolve disputes through individual arbitration, and you waive the right to a jury trial and the right to participate in a class or representative proceeding. You may opt out of the arbitration agreement within 30 days by following the procedure in Section 20.7 and emailinglegal@bolde.ai.

PLEASE READ — WHAT THE APPLICATIONS CAN DO, AND ADMINISTRATIVE AND DESTRUCTIVE ACTIONS.

The Bolde applications are not read-only. The application registrations Customer consents to hold read, write, and administrative permissions in Customer’s connected tenant, and the permissions held by a given registration are broader than the mode Customer has enabled. A current, per-application, permission-by-permission description is published atbolde.ai/security and should be read before consent is granted. If Customer enables the Administermode, the Service can change the configuration of Customer’s connected tenant — including directory roles, application registrations, domains, conditional-access policy, device management, compliance and eDiscovery configuration, and agent identities — and, where Customer separately enables it, can executeDESTRUCTIVE ACTIONS, including remote wipe or retirement of an enrolled device. Those capabilities, the authorization required before they may be used, the limits on their scope, and the way risk is allocated between the parties are set out in Sections 23, 24, and 25. Administer is off by default and is not enabled unless and until Customer completes the separate Administer Authorization described in Section 23.2.

1. Acceptance of These Terms.

These Platform Terms of Service (the “Terms”) form a binding agreement between you and Agentic Secure Group Inc., a Delaware C-Corporation doing business as “Bolde” (“Bolde,” “Company,” “we,” “us,” or “our”), governing your access to and use of the Bolde platform, websites, applications, application programming interfaces, and related services (collectively, the “Service”). Company is the contracting party and the operator of the Service, and is a member of the ASG ecosystem defined in Section 2.

1.1 Clickwrap Assent. By clicking “I agree,” checking a box that references these Terms, signing an order form, connecting a business system, or otherwise accessing or using the Service, you agree to be bound by these Terms and by the documents they incorporate by reference, including our Privacy Policy and Data Processing Addendum (“DPA”). Company records the version of the Terms you accepted together with the date and time of acceptance, and that record is admissible evidence of your assent.

1.2 Authority to Bind. If you accept these Terms on behalf of a company, organization, or other legal entity (a “Customer”), you represent and warrant that you have the authority to bind that entity, and “you” refers to that entity. If you do not have such authority, or if you do not agree to these Terms, you must not access or use the Service.

1.3 Separate Assent for Administrative Authority. Acceptance of these Terms does not by itself authorize Company to take Administrative Actions or Destructive Actions. Those capabilities require the separate, affirmative, recorded Administer Authorization described in Section 23.2, given by a Designated Administrative Contact. The risk allocation in Sections 16 and 17 as it relates to Administrative Actions and Destructive Actions applies only to Administrative Actions and Destructive Actions occurring after the date on which Customer’s Administer Authorization is recorded.

PLEASE READ SECTIONS 15, 16, 17, 20, 21, 23, 24, AND 25 CAREFULLY

These Terms contain a binding individual arbitration provision and a class, collective, and representative action waiver that affect your legal rights. They require most disputes to be resolved through individual arbitration rather than in court and waive your right to a jury trial and to participate in class or representative proceedings. You may opt out of arbitration within 30 days as described in Section 20.7. Sections 15, 16, and 17 disclaim warranties, limit liability, and allocate indemnification obligations, and they operate for the benefit of every member of the ASG ecosystem. Sections 23, 24, and 25 govern tenant administration, Destructive Actions, and Agent Identities. The obligations stated in those Sections are binding contractual and operational commitments; which of them are additionally enforced by a technical control, and which are not, is published at bolde.ai/security.

2. Definitions.

  • “ASG ecosystem” means, collectively: Agentic Secure Group Inc., a Delaware C-Corporation trading as Bolde, which is the contracting party and the operator of the Service; Agentic Secure Inc.; Mojave Research Inc., which is the verified Microsoft publisher of the applications through which the Service connects to Connected Services (Microsoft Partner ID 7086299); IP Strategy & Advocacy; Agent Xero LLC; and Agentic Trace LLC; and their respective parents, subsidiaries, affiliates, predecessors, successors and assigns, and their respective officers, directors, employees, agents, contractors and licensors. “ASG ecosystem” is the sole party-group term used in these Terms, and it benefits those persons only in Sections 15, 16, 17, 20, and 21.
  • “Customer Data” means data, content, files, communications, records, and other information that Customer or its Authorized Users provide to, connect to, ingest into, or generate within the Service, including data ingested from Customer’s Connected Services, Control-Plane Objects, Security Signals, and outputs derived from any of the foregoing.
  • “Service” means the Bolde sovereign AI platform and all of its modes, models, features, applications, and interfaces, as described in Sections 3 and 4.
  • “Authorized User” means an individual whom Customer permits to access and use the Service under Customer’s account, including Customer’s employees, contractors, and administrators.
  • “Administrator” means an Authorized User designated by Customer with rights to configure the account, grant or revoke connections and scopes, and manage other Authorized Users.
  • “Designated Administrative Contact” means an individual whom Customer identifies in writing, and keeps current, as authorized to give, narrow, suspend, or revoke the Administer Authorization and to authorize Destructive Actions on Customer’s behalf. Customer may designate more than one such contact and must designate at least two if Customer enables a Destructive Action Scope.
  • “Connected Service” means a third-party service that Customer connects to the Service, including the productivity and collaboration systems Customer connects, the identity, device-management, and compliance systems Customer connects, and, optionally, a connected HR or workforce system.
  • “Operator Action” means an action the Service takes within the content or communication surfaces of a Connected Service on Customer’s behalf and within Customer’s approved rules, including sending or drafting email, creating or updating calendar events, reading or writing document and file storage, and posting to messaging and collaboration channels. An Operator Action does not include an Administrative Action or a Destructive Action.
  • “Administrative Action” means an action the Service takes that creates, modifies, disables, or deletes the configuration or control-plane state of a Connected Service, including directory objects, users, groups, roles and role assignments, application registrations and their credentials, domains, authentication and conditional-access policy, device-management configuration and device enrollment state, compliance, retention, eDiscovery and data-subject-request configuration, and Agent Identities. Every Destructive Action is also an Administrative Action.
  • “Administer Authorization” means the separate, affirmative, recorded assent described in Section 23.2 by which Customer enables Administrative Actions, together with the itemized permission manifest that assent references.
  • “Administrative Scope” means the specific set of Administrative Actions, target objects, and Connected Services that Customer has enabled through the Administer Authorization, as narrowed, suspended, or revoked by Customer from time to time.
  • “Destructive Action” means an Administrative Action whose ordinary and intended effect is to render data, an account, a credential, a device, or a device’s enrolled state unavailable, unusable, or unrecoverable to Customer or to any individual, including remote wipe, factory reset, retirement or unenrollment of a device, deletion of a directory object or mailbox, deletion or revocation of a credential, and deletion of a retention, hold, or audit configuration.
  • “Destructive Action Scope” means the specific, enumerated set of Destructive Actions and eligible target classes that Customer has separately and affirmatively enabled under Section 24.2. The Destructive Action Scope is empty unless and until Customer enables it.
  • “Destructive Action Claim” means any claim, demand, or proceeding, by any person and on any legal or equitable theory, arising out of or relating to Company’s execution of, or failure to correctly execute, a Destructive Action. This definition identifies the operation to which Sections 16.2 and 17.3 apply; it does not characterize, limit, or bar any cause of action.
  • “Personally-Owned Device” means a device that is owned by an individual rather than by Customer, including a device enrolled under a bring-your-own-device or personally-enrolled program in a Connected Service.
  • “Hold-Suppressed Asset” means an account, mailbox, site, device, or other object that is subject to a litigation hold, legal hold, preservation obligation, retention lock, or regulatory preservation requirement, whether designated as such by Customer in the Service or reflected in the native hold or preservation state of the applicable Connected Service.
  • “Agent Identity” means a non-human identity, service principal, agent identity object, or equivalent principal that the Service creates, registers, configures, credentials, enables, disables, or deletes within a Connected Service in order to perform work on Customer’s behalf.
  • “Agent Action” means an action performed in a Connected Service under an Agent Identity.
  • “Control-Plane Object” means a configuration or governance object of a Connected Service, including a directory object, role assignment, policy, application registration, device or endpoint record, retention or hold configuration, or Agent Identity, together with its metadata.
  • “Security Signal” means an alert, risk indicator, posture finding, audit record, or similar security-relevant observation that the Service surfaces from or about a Connected Service.
  • “Output” means any analysis, summary, recommendation, draft, or other content the Service generates.
  • “Auditor” means the mode of the Service described in Section 4 that maintains the append-only audit trail in which the records required by Sections 24.7 and 25.6 are written. “Scouts” means the monitoring mode described in Section 4.
  • “Subprocessor” means a third party engaged by Company to process Customer Data in connection with the Service, as further described in the DPA.
  • “Order Form” means an ordering document or online order executed by or accepted by Customer that references these Terms.
  • “Fees” means the amounts payable by Customer for the Service as set out in an Order Form or subscription plan.

3. The Service.

3.1 Sovereign Platform. Bolde is a sovereign AI platform. Customer connects its productivity, collaboration, identity, device-management, and compliance systems, and optionally a connected HR or workforce system, and the Service ingests Customer’s business data into Customer’s own private Bolde deployment, then helps Customer’s Authorized Users work with that data. Inference runs on Company-controlled infrastructure; no third-party large language model vendor (such as OpenAI, Anthropic, or Google) is in the data path.

3.2 Models. The Service uses Bolde-Small, Company’s proprietary base model, and Bolde-Custom, the base model shaped by a Customer’s approved workflows. As described in Section 11, Company does not train its base or foundation models on Customer Data and performs Customer-scoped tuning of Bolde-Custom only with Customer’s consent.

3.3 Application Registrations and the Permissions They Hold. The Service connects to Connected Services through published application registrations. Those registrations are published by Mojave Research Inc. as the verified Microsoft publisher (Microsoft Partner ID 7086299) and include the Bolde Ingest, Bolde Connect, Bolde Control, and Bolde Keeper registrations. Each declares a specific and separately documented permission set. Those permission sets include write and administrative permissions, and the permissions a registration holds are broader than the product mode Customer has enabled. The permissions available in Customer’s tenant are determined by which registrations Customer consents to, not by which Bolde mode Customer switches on, and consenting to a registration confers every permission that registration declares. Company’s undertaking not to exercise a permission beyond the mode and scope Customer has enabled is the contractual commitment stated in Sections 9.2 and 23; it is not a limitation of the permission grant itself.

3.4 Accurate Capability Disclosure. Company will publish and keep current, at bolde.ai/security, a per-application, permission-by-permission description of what each registration is capable of, identifying which registrations hold read permissions, which hold write permissions, and which hold administrative or destructive permissions. Company will not make a capability-negative statement about the Service in its public documentation — including a statement that the Service is read-only, cannot write, or cannot change something — unless that statement is qualified by the specific application registration and permission set to which it applies. Company will correct a material inaccuracy in that description promptly on discovery. These are binding obligations of Company and are not warranties subject to Section 15.

4. Product Modes and Data Access.

The Service is delivered through six modes. A seventh mode, Sentry, is described below because its application registration exists and is publicly disclosed; Sentry is not part of the Service and is not available, and the conditions on which it could become part of the Service are stated in Section 4.4. Depending on Customer’s plan and configuration, the Service may read and, in the operate and administer modes, write, change, or delete Customer Data and Control-Plane Objects within Connected Services, in each case only to the extent Customer grants access and a Designated Administrative Contact or Administrator provides the necessary consents.

  • Console. A human-in-the-loop interface to ask, review, approve, and trace work across Customer’s data.
  • Analyst. Sourced analysis over Customer’s data, with references to the underlying records.
  • Scouts. Monitoring that watches for changes and surfaces them to Authorized Users. Scouts surfaces information; it does not undertake to detect, and does not guarantee detection of, any particular condition. See Section 26.
  • Operator. Performs repeatable work inside the rules Customer approves and takes Operator Actions, which may include sending and drafting email, creating and updating calendar events, reading and writing document and file storage, and posting to messaging and collaboration channels. Operator acts only within rules Customer has approved.
  • Administer. Configures and governs Customer’s connected tenant and takes Administrative Actions within the Administrative Scope Customer enables. Administrative Actions may include creating, modifying, disabling, or deleting users, groups, roles and role assignments, application registrations and their credentials, domains, authentication and conditional-access policy, device-management configuration and device enrollment state, compliance, retention, eDiscovery and data-subject-request configuration, and Agent Identities; and, where Customer separately enables a Destructive Action Scope, may include Destructive Actions such as remote wipe or retirement of an enrolled device. Administer is off by default and is governed by Sections 23, 24, and 25.
  • Auditor. Maintains an append-only record and audit trail of activity within the Service, including a record of each Administrative Action and Destructive Action as described in Section 24.7.
  • Sentry — not part of the Service; not available. See Section 4.4. If Sentry were enabled, it would surface security posture assessment, threat and identity-risk signals, unified audit-log query results, and configuration-monitoring findings from Customer’s Connected Services. Sentry would be delivered through a separate application registration — “Bolde Sentry — Security Posture & Threat Operations,” Application ID 3595ec54-f02e-4a89-9e72-7ab5fa33f04b — which requires its own express consent from a Designated Administrative Contact or Administrator. Consent to any other Bolde application registration does not consent to, enable, or confer any permission of the Bolde Sentry registration. Everything Sentry would surface is a Security Signal, and Section 26 applies to it in full. As of the “Last updated” date at the end of these Terms, Sentry is not available, is not part of the Service, and performs no function.

4.1 Connected Service Scope. Subject to the access Customer grants and the consents Customer provides, the Service may, via the Connected Service’s interfaces, read — and in the operate and administer modes write, change, or delete — mail (read and send), calendars, contacts, document and file storage (read and write), messaging and collaboration channels, chats, and messages (read and post), tasks and notes, users, groups, and directory data, roles and role assignments, application registrations, domains, authentication and conditional-access policy, device and endpoint management state, security and compliance data, retention and hold configuration, eDiscovery and data-subject-request configuration, audit logs, reports, and Agent Identities. The scope actually available in a given deployment is determined by the application registrations Customer consents to, each of which is separately documented at bolde.ai/security, and Customer should read that documentation before granting consent. Customer’s Administrator or Designated Administrative Contact controls, and may at any time narrow or revoke, all such access, including by revoking consent for an application registration directly within the Connected Service and without Company’s cooperation.

4.2 Connected HR or Workforce System (Optional). If Customer connects a HR or workforce system, the Service ingests HR, employment, and organizational data, which may include sensitive personal information such as Social Security numbers, dates of birth, and addresses. Customer authorizes such processing and is responsible for limiting the scopes it grants. Company treats such data as sensitive and processes it only as needed to provide the Service.

4.3 Device and Endpoint Data. Where Customer connects a device-management system, the Service processes device and endpoint records, including device identifiers, ownership designation, enrollment state, compliance state, and, where Customer enables it, device action state. Device and endpoint records are Control-Plane Objects, are Customer Data, and are processed under the DPA.

4.4 Sentry Is Not Part of the Service Unless Separately Consented and Generally Available. Sentry is not part of the Service, and no Sentry capability is available to Customer, unless and until both of the following have occurred: (a) a Designated Administrative Contact or Administrator has separately and expressly consented to the Bolde Sentry application registration identified in Section 4 within Customer’s tenant; and (b) Company has made Sentry generally available. Neither condition is satisfied as of the “Last updated” date at the end of these Terms. As of that date the Bolde Sentry registration holds no client secret, no certificate credential, and no consented application role assignment, and Sentry is not offered, provisioned, operating, or capable of authenticating against any tenant. Nothing in these Terms, and no consent Customer has given or may give to any other Bolde application registration, enables Sentry, constitutes an offer or provision of Sentry, or entitles Customer to Sentry. The description of Sentry in these Terms states the scope, consent basis, and risk allocation that would apply if Sentry were later made available and separately consented to; it is not a representation of present availability, a statement that Sentry exists as a service, or a commitment to make Sentry available.

5. Eligibility and United States Scope.

5.1 United States Only. The Service is offered solely to customers and users located in the United States. The Service is not offered or directed to data subjects in the European Union, the United Kingdom, or any other jurisdiction subject to the EU or UK General Data Protection Regulation, and you must not use the Service to process the personal data of such individuals.

5.2 Age and Capacity. You must be at least 18 years old and able to form a binding contract to use the Service. The Service is intended for business use and is not directed to consumers or children.

6. Order of Precedence.

6.1 General Order. If Customer has entered into a separate written enterprise agreement with Company governing the Service, or an Order Form or DPA that conflicts with these Terms, the documents control in the following order of precedence to the extent of the conflict: (a) a signed enterprise agreement; (b) the applicable Order Form and the DPA; and (c) these Terms. In all other respects these Terms remain in effect.

6.2 Administrative Authority Controls. Notwithstanding Section 6.1, Sections 23 (Administer Mode and Administrative Authorization), 24 (Destructive Actions), and 25 (Agent Identity) control as to the existence, authority, scope, records, and risk allocation for Administrative Actions, Destructive Actions, and Agent Identities, unless a signed enterprise agreement expressly identifies those Sections by number and states the parties’ intent to supersede them. A general integration, precedence, or “entire agreement” clause in another document does not supersede those Sections.

6.3 Single Defined Terms. The terms “ASG ecosystem,” “Administrative Action,” “Destructive Action,” “Control-Plane Object,” and “Agent Identity” have the meanings given in Section 2 throughout these Terms, and no other party-group or equivalent term is used in these Terms.

7. Accounts and Security.

  • Registration. Customer must provide accurate, current, and complete account information and keep it updated, including the identity and contact details of each Designated Administrative Contact.
  • Credentials. Customer is responsible for safeguarding its account credentials and for all activity that occurs under its account, whether or not authorized.
  • Authorized Users. Customer is responsible for its Authorized Users’ compliance with these Terms and for the acts and omissions of its Authorized Users as if they were Customer’s own.
  • Notice. Customer must promptly notify security@bolde.ai of any suspected unauthorized access or use of its account, and must promptly notify legal@bolde.ai of any change to a Designated Administrative Contact.

8. Acceptable Use.

Customer and its Authorized Users must not, and must not permit any third party to:

  • use the Service in violation of any applicable law, regulation, or third-party right, or in violation of any Connected Service’s terms;
  • connect data, or grant scopes, that Customer lacks the authority or consents to connect or grant;
  • enable, configure, or direct an Administrative Action or Destructive Action that Customer lacks the authority to take within the Connected Service or against the affected person or device;
  • include a Personally-Owned Device or a Hold-Suppressed Asset within a Destructive Action Scope;
  • upload or transmit malware, or attempt to gain unauthorized access to the Service, other accounts, or Company systems;
  • probe, scan, or test the vulnerability of the Service, or circumvent any security or access control, except under a written authorization from Company;
  • reverse engineer, decompile, or attempt to derive the source code, models, or weights of the Service, except to the extent this restriction is unenforceable under applicable law;
  • use the Service to build or train a competing model or service, or to benchmark the Service for a competitor;
  • resell, sublicense, time-share, or provide the Service to third parties as a service bureau, except as expressly permitted;
  • use the Service to make decisions that produce legal or similarly significant effects about an individual without appropriate human review;
  • use the Service to harass, defame, or infringe, or to generate unlawful, deceptive, or harmful content; or
  • interfere with or disrupt the integrity or performance of the Service or the data it contains.

Company may suspend access to the Service, in whole or in part, to address a violation of this Section, a security risk, or a legal requirement, with notice where practicable.

9. Connections and Customer Responsibilities.

9.1 Authority and Consent. Customer represents and warrants that it has all rights, authority, and consents necessary to connect its productivity, collaboration, identity, device-management, and compliance systems and, if applicable, a HR or workforce system; to ingest the Customer Data into the Service; and to authorize the access, reads, Operator Actions, Administrative Actions, and Destructive Actions it configures. Customer is solely responsible for providing any notices and obtaining any consents required from its Authorized Users and other individuals whose data or devices it connects, including any individual notice, acknowledgment, or agreement required before a device belonging to or used by that individual may be subject to an Administrative Action or Destructive Action.

9.2 Scope Configuration. Customer’s Administrator and Designated Administrative Contacts are responsible for configuring the permissions and scopes granted to the Service, for granting only the access Customer intends, and for narrowing or revoking access at any time. Company will process Customer Data only within the scopes Customer grants, will take Administrative Actions only within the Administrative Scope, and will take Destructive Actions only within the Destructive Action Scope. Customer acknowledges that, as stated in Section 3.3, an application registration may hold permissions broader than the mode Customer has enabled, and that Company’s restraint within the enabled scope is a contractual commitment.

9.3 Review of Actions. Operator Actions and Administrative Actions are taken within rules and scopes Customer approves. Customer is responsible for defining those rules, for setting approval thresholds and human-review checkpoints appropriate to the risk of each action, and for reviewing Operator Actions, Administrative Actions, and Outputs. Subject to Sections 16 and 17, Company is not responsible for the consequences of an Operator Action or Administrative Action taken within the rules and scopes Customer configured and correctly executed as configured. Nothing in this Section limits Company’s responsibility for its own acts, including an action executed outside the Administrative Scope or Destructive Action Scope, an action executed against a target Customer did not authorize, or an action executed incorrectly.

9.4 Connected Services. Connected Services are provided by third parties under Customer’s own agreements with those providers. Each Connected Service is Customer’s own provider, not Company’s Subprocessor. Company is not responsible for Connected Services, their availability, or changes they make.

10. Mutual Confidentiality.

10.1 Definition. “Confidential Information” means non-public information disclosed by one party (the “Disclosing Party”) to the other (the “Receiving Party”), whether orally, in writing, or by other means, that is designated as confidential or that reasonably should be understood to be confidential given its nature and the circumstances of disclosure, including the Disclosing Party’s business, technical, financial, product, security, and personnel information, and the terms and pricing of these Terms and any Order Form. Customer Data, Control-Plane Objects, and Security Signals are Customer’s Confidential Information. The Service, the models, and non-public technical, architectural, and security information about them are Company’s Confidential Information.

10.2 Non-Use and Non-Disclosure. The Receiving Party will: (a) use the Disclosing Party’s Confidential Information solely to perform its obligations and exercise its rights under these Terms; (b) not disclose such Confidential Information to any third party except as permitted in this Section; and (c) protect such Confidential Information using at least the same degree of care it uses to protect its own confidential information of like importance, and in no event less than a reasonable degree of care. The Receiving Party may disclose Confidential Information only to its employees, contractors, advisors, and Subprocessors who have a need to know it for purposes of these Terms and who are bound by written confidentiality obligations no less protective than those in this Section, and the Receiving Party remains responsible for their compliance.

10.3 Exclusions. Confidential Information does not include information that the Receiving Party can demonstrate: (a) was or becomes publicly available through no act or omission of the Receiving Party in breach of these Terms; (b) was rightfully known to the Receiving Party, without confidentiality obligation, before its disclosure by the Disclosing Party; (c) is rightfully obtained by the Receiving Party from a third party without breach of any confidentiality obligation; or (d) is independently developed by the Receiving Party without use of or reference to the Disclosing Party’s Confidential Information.

10.4 Compelled Disclosure. The Receiving Party may disclose Confidential Information to the extent required by applicable law, regulation, or a valid legal or governmental order, provided that, where legally permitted, the Receiving Party gives the Disclosing Party prompt prior written notice and reasonable cooperation, at the Disclosing Party’s expense, to enable the Disclosing Party to seek a protective order or other appropriate remedy. Any such disclosure will be limited to the portion of Confidential Information legally required to be disclosed, and the information otherwise remains Confidential Information subject to this Section.

10.5 Survival and Remedies. The obligations in this Section survive termination or expiration of these Terms and continue for so long as the Receiving Party retains the Disclosing Party’s Confidential Information and, with respect to any trade secret, for as long as the information remains a trade secret under applicable law. The Receiving Party acknowledges that a breach of this Section may cause irreparable harm for which monetary damages are inadequate, and the Disclosing Party may seek the injunctive or other equitable relief described in Section 20.6 in addition to any other available remedy.

11. Artificial Intelligence Terms.

11.1 Probabilistic Outputs. The Service uses generative and agentic AI. Outputs are probabilistic, are generated automatically, and may be inaccurate, incomplete, or otherwise unsuitable for a particular purpose. Outputs may vary even for similar inputs and may include errors or fabricated content.

11.2 No Professional Advice. The Service does not provide legal, financial, tax, accounting, medical, or other professional advice, and Outputs are not a substitute for professional judgment. Customer is responsible for evaluating Outputs, Operator Actions, and Administrative Actions for accuracy and appropriateness before relying on or acting on them.

11.3 Human Review. Customer must maintain meaningful human review of Outputs, Operator Actions, and Administrative Actions commensurate with their risk, particularly where they affect individuals or produce legal or similarly significant effects. Customer is responsible for compliance with applicable AI, automated-decisionmaking, anti-discrimination, and consumer-protection laws in connection with its use of the Service, and Customer is the deployer of the Service in its own context.

11.4 No Autonomous Destructive Action. Company will not execute a Destructive Action on the basis of a model inference, a Security Signal, or an automated rule alone. Every Destructive Action requires the human authorization described in Section 24.3. This is a binding contractual and operational commitment of Company; Company does not represent that it is additionally enforced by a technical control, and the current status of technical controls is published at bolde.ai/security.

11.5 No Base-Model Training on Customer Data. Company does not use Customer Data to train or improve its base or foundation models (including Bolde-Small). Company may shape Bolde-Custom for a Customer using that Customer’s approved workflows only with that Customer’s consent, and any such tuning is scoped to that Customer’s deployment. Company may use aggregated and de-identified data, and data necessary to operate, secure, troubleshoot, and provide the Service, consistent with the DPA. Company does not use Control-Plane Objects or Security Signals for its own purposes.

11.6 Ownership of Customer Data and the Service. As between the parties, Customer owns Customer Data and all rights in it. Company owns and retains all right, title, and interest in and to the Service, its models, software, and all related intellectual property, including all improvements and derivative works. No rights are granted except as expressly stated. Customer grants Company a non-exclusive, worldwide license to host, copy, process, transmit, and display Customer Data, and to generate Outputs, solely as necessary to provide, secure, and support the Service consistent with the DPA.

11.7 Feedback. If Customer or an Authorized User provides suggestions, ideas, or other feedback about the Service, Customer grants Company a perpetual, irrevocable, worldwide, royalty-free, sublicensable license to use and exploit such feedback for any purpose without restriction or compensation.

12. Subscriptions, Fees, and Payment.

  • Fees. Customer will pay the Fees stated in the applicable Order Form or subscription plan. Except as expressly stated, Fees are non-cancelable and non-refundable.
  • Taxes. Fees are exclusive of taxes. Customer is responsible for all sales, use, and similar taxes, excluding taxes on Company’s net income.
  • Payment. Unless otherwise stated, Fees are due in advance and payable by the method on file. Customer authorizes Company to charge that method for all Fees, including renewals.
  • Late Amounts. Overdue amounts accrue interest at the lesser of 1.5% per month or the maximum allowed by law, and Company may suspend the Service for non-payment after notice.
  • Auto-Renewal. Subscriptions automatically renew for successive periods equal to the prior term unless either party gives written notice of non-renewal at least 30 days before the end of the then-current term. Renewal Fees are at Company’s then-current rates unless otherwise agreed.

13. Modifications to the Terms and the Service.

13.1 Changes to the Terms. Company may modify these Terms from time to time. For material changes other than changes to the arbitration provision, Company will provide conspicuous advance notice (such as by email or in-product notice) at least thirty (30) days before the change takes effect, and such a change will take effect only after that advance notice and on the effective date stated in the notice. Non-material changes may take effect upon posting. Customer may reject a material change by ceasing all use of the Service before the change’s effective date; continued use of the Service on or after that date constitutes acceptance of the change. If a material change materially and adversely affects Customer’s rights, Customer’s sole remedy is to reject the change by stopping use of the Service before it takes effect. Changes to the arbitration provision are governed by Section 20 and require renewed assent or an opt-out opportunity as described there.

13.2 No Expansion of Administrative Authority by Amendment. Company will not, by amendment under Section 13.1, expand the Administrative Scope, create or expand a Destructive Action Scope, or expand the categories of Administrative Action or Destructive Action available in a Customer’s deployment. Any such expansion takes effect only on and after a new Administer Authorization recorded under Section 23.2, and applies only to Administrative Actions and Destructive Actions occurring after that recorded date. Continued use of the Service is not assent to an expansion of administrative authority.

13.3 Changes to the Service. Company may improve, update, or modify the Service and its models, including by changing or retiring features. Company will not materially degrade the core functionality of a paid subscription during a paid term without providing a comparable alternative or a refund of prepaid, unused Fees for the affected functionality. Company will communicate material AI-related changes (such as new models or new categories of data use) and material changes to the permission set of any application registration, and Customer may adjust its configuration or, where the change materially and adversely affects Customer, exercise its non-renewal or termination rights.

14. Term, Termination, and Data Return.

  • Term. These Terms apply for as long as Customer uses the Service or has an active subscription.
  • Termination for Cause. Either party may terminate for the other party’s material breach not cured within 30 days after written notice. Company may suspend or terminate immediately for a violation of Section 8, non-payment, a security risk, or a legal requirement.
  • Effect. On termination, Customer’s right to access the Service ceases, and Customer remains liable for all Fees accrued before termination. On termination, suspension, or expiration, the Administrative Scope and any Destructive Action Scope terminate immediately, and Company will not take any further Administrative Action or Destructive Action.
  • Agent Identity Deprovisioning. On termination, suspension, or Customer’s written request, Company will disable and deprovision the Agent Identities it created for Customer, revoke the credentials associated with them, and deliver a written attestation, as described in Section 25.5 and on the timetable set out in the DPA.
  • Data Return and Deletion. On termination or expiration, Company will, on Customer’s request made within 30 days, make Customer Data available for export, and thereafter will delete or return Customer Data in accordance with the DPA and applicable law, except for copies retained as required by law or held in routine backups deleted in the ordinary course. Records of Administrative Actions and Destructive Actions required by Section 24.7 are retained for the period stated there.
  • Survival. Sections that by their nature should survive (including Sections 2, 3.4, 10, 11.5 through 11.7, 14, 15, 16, 17, 18, 19, 20, 21, 22, 24.7, 24.8, 25.3, 25.5, and 26) survive termination.

15. Disclaimer of Warranties.

THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE”

TO THE FULLEST EXTENT PERMITTED BY LAW, THE SERVICE, THE MODELS, AND ALL OUTPUTS ARE PROVIDED “AS IS” AND “AS AVAILABLE,” WITH ALL FAULTS, AND EACH MEMBER OF THE ASG ECOSYSTEM DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.

15.1 No Warranty of Results. No member of the ASG ecosystem warrants that the Service will be uninterrupted, secure, or error-free, that defects will be corrected, or that Outputs, Operator Actions, or Administrative Actions will be accurate, complete, reliable, or suitable for any purpose. Customer is solely responsible for its use of, and reliance on, the Service, Outputs, Operator Actions, and Administrative Actions.

15.2 Connected Services. No member of the ASG ecosystem makes any warranty regarding Connected Services or any third-party products or data. Some jurisdictions do not allow the exclusion of certain warranties; to that extent, the exclusions in this Section may not apply to Customer.

15.3 Express Covenants Preserved. This Section does not disclaim, limit, or qualify the express covenants Company makes in Sections 3.3, 3.4, 23, 24, and 25, which are binding obligations and not warranties subject to this Section.

16. Limitation of Liability.

EXCLUSION OF INDIRECT DAMAGES

TO THE FULLEST EXTENT PERMITTED BY LAW, NEITHER CUSTOMER NOR ANY MEMBER OF THE ASG ECOSYSTEM WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOST PROFITS, LOST REVENUE, LOST DATA, LOSS OF GOODWILL, OR BUSINESS INTERRUPTION, ARISING OUT OF OR RELATING TO THE SERVICE OR THESE TERMS, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES AND EVEN IF A REMEDY FAILS OF ITS ESSENTIAL PURPOSE. THIS EXCLUSION DOES NOT APPLY TO A DESTRUCTIVE ACTION CLAIM, WHICH IS GOVERNED BY SECTION 16.2.

16.1 General Liability Cap. TO THE FULLEST EXTENT PERMITTED BY LAW, AND SUBJECT TO SECTIONS 16.2 AND 16.3, THE TOTAL AGGREGATE LIABILITY OF CUSTOMER ON THE ONE HAND, AND OF ALL MEMBERS OF THE ASG ECOSYSTEM TAKEN TOGETHER ON THE OTHER, ARISING OUT OF OR RELATING TO THE SERVICE OR THESE TERMS WILL NOT EXCEED THE GREATER OF (A) THE TOTAL FEES PAID OR PAYABLE BY CUSTOMER TO COMPANY FOR THE SERVICE IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE LIABILITY AND (B) TWO HUNDRED FIFTY THOUSAND U.S. DOLLARS (USD $250,000).

16.2 Destructive Action Claims — Separate Allocation. The general cap in Section 16.1 and the exclusion of indirect damages above do not apply to a Destructive Action Claim. Instead, and subject to Section 16.3:

  • Restoration and Replacement. Company will bear the documented, reasonable costs of (i) restoring data rendered unavailable or unrecoverable by a Destructive Action, including the cost of third-party forensic recovery, and (ii) replacing or re-provisioning each affected device at its documented replacement cost. This obligation is subject to, and counts against, the aggregate amount stated in the next bullet.
  • Aggregate Cap for All Other Damages. For all other damages arising from Destructive Action Claims, the aggregate liability of all members of the ASG ecosystem taken together will not exceed the greater of (i) three times the total Fees paid or payable by Customer to Company for the Service in the twelve (12) months immediately preceding the Destructive Action, and (ii) FIVE HUNDRED THOUSAND U.S. DOLLARS (USD $500,000).

16.3 Surviving Carve-Outs. The exclusions and caps in Sections 16.1 and 16.2 and in the first paragraph of this Section do not apply to: (a) Customer’s payment obligations; (b) a party’s indemnification obligations under Section 17; (c) a party’s breach of its confidentiality obligations; (d) Customer’s violation of Section 8 (Acceptable Use) or infringement or misappropriation of Company’s intellectual property; (e) a party’s fraud, willful misconduct, or gross negligence; (f) any liability that cannot be limited or excluded under applicable law, including liability for death or personal injury caused by a party’s negligence; and (g) any claim arising from an intentional tort, including conversion or trespass to chattels, to the extent California Civil Code § 1668 or a comparable law of another state applies.

16.4 Allocation of Risk. The parties agree that the limitations in this Section, taken together with the separate Destructive Action allocation in Section 16.2 and the carve-outs in Section 16.3, are a fundamental basis of the bargain and reflect a reasonable and negotiated allocation of risk between two commercial parties. These limitations apply regardless of the form of action, whether in contract, tort, strict liability, or otherwise, except as stated in Section 16.3.

16.5 Persons Not Bound. This Section allocates risk between the ASG ecosystem and Customer only. It confers no rights on, and imposes no obligation or limitation upon, any person who is not a party to these Terms, and it does not limit any right such a person may have against Customer or against any member of the ASG ecosystem.

17. Indemnification.

17.1 By Customer. Customer will defend, indemnify, and hold harmless each member of the ASG ecosystem from and against any third-party claim, and any resulting losses, damages, liabilities, costs, and reasonable attorneys’ fees, arising out of or relating to: (a) Customer Data, including its content and Company’s processing of it as instructed by Customer; (b) Customer’s connection of Connected Services or its grant of scopes or consents, including any lack of authority or consent, and including any failure by Customer to provide a notice or obtain a consent, acknowledgment, or agreement required by Section 9.1; (c) the rules, scopes, Administrative Scope, and Destructive Action Scope that Customer configured, including Customer’s designation of a target that Customer was not authorized to designate; (d) Customer’s use of the Service or Outputs, including its compliance or non-compliance with applicable AI, automated-decisionmaking, anti-discrimination, privacy, and consumer-protection laws; or (e) Customer’s violation of these Terms or applicable law. This indemnity does not extend to any claim to the extent caused by the negligence, gross negligence, or willful misconduct of a member of the ASG ecosystem, except as expressly and conspicuously provided in Section 17.2.

17.2 EXPRESS NEGLIGENCE — PLEASE READ. THIS PROVISION REQUIRES CUSTOMER TO INDEMNIFY MEMBERS OF THE ASG ECOSYSTEM FOR CERTAIN CLAIMS CAUSED IN PART BY THEIR OWN ORDINARY NEGLIGENCE.

TO THE EXTENT A THIRD-PARTY CLAIM WITHIN SECTION 17.1 ARISES FROM AN ACTION THAT CUSTOMER EXPRESSLY AUTHORIZED AND THAT COMPANY EXECUTED WITHIN THE ADMINISTRATIVE SCOPE OR THE DESTRUCTIVE ACTION SCOPE, CUSTOMER’S OBLIGATION UNDER SECTION 17.1 APPLIES EVEN IF THE CLAIM IS CAUSED IN WHOLE OR IN PART BY THE ORDINARY NEGLIGENCE OF A MEMBER OF THE ASG ECOSYSTEM. THIS SECTION 17.2 DOES NOT APPLY TO, AND CUSTOMER HAS NO OBLIGATION TO INDEMNIFY ANY MEMBER OF THE ASG ECOSYSTEM FOR, ANY CLAIM CAUSED IN WHOLE OR IN PART BY GROSS NEGLIGENCE, WILLFUL MISCONDUCT, OR FRAUD, OR BY AN ACTION EXECUTED OUTSIDE THE ADMINISTRATIVE SCOPE OR THE DESTRUCTIVE ACTION SCOPE, AGAINST A TARGET CUSTOMER DID NOT AUTHORIZE, OR WITHOUT THE AUTHORIZATION REQUIRED BY SECTION 24.3. IF THIS SECTION 17.2 IS HELD UNENFORCEABLE IN WHOLE OR IN PART, SECTION 17.1 REMAINS IN FULL FORCE AS TO CLAIMS NOT CAUSED BY SUCH NEGLIGENCE.

17.3 By Company — Preservation and Spoliation. Company will defend, indemnify, and hold harmless Customer from and against any judicially imposed or tribunal-imposed sanction, adverse-inference remedy, monetary award, or fee-shifting order, and any resulting reasonable attorneys’ fees, arising from Company’s execution of a Destructive Action against an asset that was a Hold-Suppressed Asset at the time of execution, where the hold or preservation state was reflected in the native hold or preservation state of the applicable Connected Service or had been designated by Customer in the Service. Company’s aggregate liability under this Section 17.3 will not exceed USD $1,000,000 and is separate from and additional to the caps in Sections 16.1 and 16.2. This indemnity does not apply to the extent the sanction arises from Customer’s own failure to preserve, Customer’s own conduct in the underlying proceeding, or Customer’s designation of a target it knew was subject to a hold.

17.4 By Company — Intellectual Property. Company will defend, indemnify, and hold harmless Customer from and against any third-party claim alleging that the Service, as provided by Company and used in accordance with these Terms, infringes or misappropriates that third party’s United States patent, copyright, trademark, or trade secret, and will pay resulting damages finally awarded or amounts agreed in settlement. This indemnity does not apply to a claim arising from Customer Data, Customer’s configuration, a Connected Service, or use of the Service in combination with anything not provided by Company where the claim would not have arisen absent that combination.

17.5 Procedure. The indemnified party will promptly notify the indemnifying party of the claim, allow the indemnifying party to control the defense and settlement (provided no settlement imposes a non-monetary obligation or admission on the indemnified party without its consent), and reasonably cooperate. Failure to give prompt notice relieves the indemnifying party only to the extent it is materially prejudiced.

18. Governing Law and Forum.

These Terms and any dispute arising out of or relating to them or the Service are governed by the laws of the State of Delaware, without regard to its conflict-of-laws rules, and, where applicable, by the Federal Arbitration Act. Nothing in this Section displaces a non-waivable protection available to a person under the law of the state in which that person resides or in which the relevant conduct occurred. Subject to Section 20, and solely for claims not subject to arbitration or for which a court is the proper forum, the parties consent to the exclusive jurisdiction and venue of the state courts located in Arapahoe County, Colorado, and the U.S. District Court for the District of Colorado, and waive any objection to such venue.

19. Informal Dispute Resolution.

Before initiating arbitration or any other proceeding, the party raising a dispute must first send a written notice of dispute to the other party describing the dispute and the relief sought. Notices to Company go to legal@bolde.ai and to the mailing address in Section 22. The parties will attempt in good faith to resolve the dispute for 30 days after the notice. This informal process is a precondition to arbitration, and the limitations period in Section 20.10 is tolled during it. Either party may seek the individual relief described in Section 20.6 during this period.

20. Binding Arbitration and Class Action Waiver.

PLEASE READ — THIS AFFECTS YOUR RIGHTS

EXCEPT FOR THE DISPUTES DESCRIBED IN SECTION 20.6, YOU AND COMPANY AGREE TO RESOLVE ALL DISPUTES THROUGH BINDING INDIVIDUAL ARBITRATION, NOT IN COURT, AND YOU AND COMPANY WAIVE THE RIGHT TO A JURY TRIAL AND THE RIGHT TO PARTICIPATE IN A CLASS, COLLECTIVE, CONSOLIDATED, OR REPRESENTATIVE ACTION. YOU MAY OPT OUT OF THIS SECTION WITHIN 30 DAYS AS DESCRIBED IN SECTION 20.7.

20.1 Agreement to Arbitrate. You and Company agree that any dispute, claim, or controversy arising out of or relating to these Terms, the Service, or the relationship between the parties, including any such claim asserted against a member of the ASG ecosystem (a “Dispute”), and that is not resolved under Section 19, will be resolved by binding arbitration on an individual basis, except as set out in Section 20.6. This agreement to arbitrate is mutual and applies equally to both parties and to any member of the ASG ecosystem that elects to invoke it. It binds only the parties to these Terms and no other person.

20.2 Arbitration Rules and Administrator. The arbitration will be administered by the American Arbitration Association (“AAA”) under its rules then in effect — the Consumer Arbitration Rules where applicable, otherwise the Commercial Arbitration Rules — as modified by this Section. The rules are available at adr.org. The arbitration will be conducted in the English language by a single neutral arbitrator selected under the AAA’s ordinary neutral-selection procedures, under which each party has an equal right to strike and rank proposed arbitrators. Neither party may unilaterally designate the arbitrator, the roster, or the appointing authority.

20.3 Fees. Company will pay the arbitration filing, administration, and arbitrator fees to the extent required by the applicable AAA rules and minimum standards; where those rules do not allocate fees, Company will pay all such fees for any individual arbitration brought under the Consumer Arbitration Rules, except that the claimant pays only the portion of the filing fee equal to the fee for filing suit in the local court. Each party otherwise bears its own attorneys’ fees and costs, except that the arbitrator may award attorneys’ fees and costs to the prevailing party to the extent authorized by applicable law.

20.4 Arbitrator’s Authority and Remedies. The arbitrator has exclusive authority to resolve the Dispute and may award, on an individual basis, any relief that a court could award under applicable law, including statutory damages, statutory penalties, and attorneys’ fees and costs where authorized by statute. Nothing in this Section limits the arbitrator’s authority to award public injunctive relief to the extent such relief is not waivable under applicable law. Any purported waiver of public injunctive relief is severed, and the claim to which it relates may be brought in the courts identified in Section 18, while all other Disputes proceed in arbitration. Except as to public injunctive relief, the arbitrator may grant injunctive relief only in favor of the individual party seeking relief and only to the extent necessary to provide relief warranted by that party’s individual claim. The arbitrator’s award is final and binding and may be entered in any court of competent jurisdiction.

20.5 Class, Collective, and Representative Action Waiver. DISPUTES MUST BE BROUGHT IN AN INDIVIDUAL CAPACITY ONLY, AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, COLLECTIVE, CONSOLIDATED, PRIVATE-ATTORNEY-GENERAL, OR REPRESENTATIVE PROCEEDING. The arbitrator may not consolidate or join the claims of more than one person and may not preside over any form of class, collective, or representative proceeding, except to the extent claimants elect coordinated administration in writing under Section 20.9, and then only as among those electing claimants. This waiver does not extend to public injunctive relief, which is addressed in Section 20.4. If this Section 20.5 is found unenforceable as to a particular claim or request for relief, then that claim or request for relief, and only that claim or request, will be severed and brought in a court of competent jurisdiction under Section 18, while all other claims proceed in arbitration.

20.6 Carve-Outs. This Section does not require arbitration of: (a) an individual claim brought in small-claims court, so long as it remains in that court and proceeds on an individual basis; (b) a request for temporary or preliminary injunctive or other equitable relief in a court of competent jurisdiction to prevent the actual or threatened infringement, misappropriation, or violation of a party’s intellectual property or confidential information; and (c) a claim for public injunctive relief to the extent it is not waivable and not arbitrable under applicable law. Seeking such relief does not waive the right to arbitrate other Disputes.

20.7 30-Day Right to Opt Out. You may opt out of this Section 20 by sending written notice within 30 days after first accepting these Terms (or, for a material change to this Section, within 30 days after the change takes effect) to legal@bolde.ai with the subject line “Arbitration Opt-Out,” and including your name, account, and a clear statement that you wish to opt out. Opting out does not affect any other part of these Terms and will not be the basis for any adverse action. Company will confirm receipt and route opted-out parties to the forum in Section 18. If you do not opt out within the 30-day period, you are bound by this Section.

20.8 Delegation. The arbitrator, and not any court, has exclusive authority to resolve any dispute about the interpretation, applicability, enforceability, or formation of this Section 20, including any claim that all or part of it is void or voidable. However, disputes about the enforceability of the class, collective, and representative action waiver in Section 20.5, about the availability of public injunctive relief under Section 20.4, and about whether a person is bound by this Section 20 at all, are for a court, not the arbitrator, to decide.

20.9 Coordinated Arbitration Is Elective, Not Automatic. If a substantial number of arbitration demands of a substantially similar nature are filed against Company or any member of the ASG ecosystem by or with the assistance of the same or coordinated counsel, the demands are not consolidated, batched, staged, or subjected to bellwether procedures automatically. Coordinated administration under the AAA’s Mass Arbitration Supplementary Rules applies only if (a) the claimants electing coordination consent to it in writing, and then only as among those electing claimants, or (b) Company and every affected claimant mutually agree in writing. Any claimant may decline coordination at any time and proceed in an ordinary individual arbitration under Section 20.2, and Company will not oppose that election. Where coordination is elected, no case may be stayed for more than one hundred eighty (180) days in the aggregate without that claimant’s written consent; on expiry of that period the case proceeds as an ordinary individual arbitration. All applicable limitations periods are tolled, automatically and without further action by any party, from the date a demand is filed until the case proceeds or is finally resolved. This Section confers no unilateral right on Company or on any member of the ASG ecosystem to control the pace, sequence, or grouping of any claimant’s case.

20.10 Two-Year Limitation. To the fullest extent permitted by law, any Dispute must be commenced within two (2) years after the claim accrues; otherwise it is permanently barred. This limitation does not apply: (a) where prohibited by applicable law; (b) to any claim under a statute that prohibits contractual shortening of the limitations period; (c) to any claim by or against a person not bound by these Terms; or (d) to a Destructive Action Claim, to which the limitations period supplied by applicable law applies without contractual shortening.

20.11 Severability and Jury-Trial Backstop. If any provision of this Section 20 (other than Section 20.5) is found unenforceable, that provision will be severed and the remainder will continue in effect. If, after severance, the agreement to arbitrate is held unenforceable as to a Dispute, or if a Dispute is found not subject to arbitration, that Dispute will be resolved in the courts identified in Section 18, and in that event EACH PARTY KNOWINGLY AND IRREVOCABLY WAIVES ANY RIGHT TO A TRIAL BY JURY in any such proceeding.

20.12 Mutuality and No Retroactive Change. This Section 20 is mutual in every respect: the same rules, the same forum, the same limitations, and the same fee allocation apply to claims brought by Company or any member of the ASG ecosystem as to claims brought against them. Company will not amend this Section 20 in a manner that applies to any Dispute for which a notice under Section 19 has been sent or an arbitration demand has been filed before the amendment’s effective date. No amendment to this Section 20 applies retroactively to conduct occurring before its effective date.

21. Release.

To the fullest extent permitted by law, Customer releases each member of the ASG ecosystem from claims, demands, and damages arising out of or relating to disputes between Customer and any third party (including any Authorized User, Connected Service provider, or other user) in connection with the Service. This Section does not extend to, and Customer does not release, any claim arising from Company’s own Administrative Actions, Destructive Actions, or Agent Actions, or from Company’s breach of Sections 3.3, 3.4, 23, 24, or 25. If Customer is a California resident, Customer waives California Civil Code § 1542 as to the claims actually released by this Section, which states: “A general release does not extend to claims that the creditor or releasing party does not know or suspect to exist in his or her favor at the time of executing the release and that, if known by him or her, would have materially affected his or her settlement with the debtor or released party.”

22. General Provisions.

  • Assignment. Customer may not assign or transfer these Terms without Company’s prior written consent. Company may assign these Terms in connection with a merger, acquisition, reorganization, or sale of all or substantially all of its assets, or to another member of the ASG ecosystem. Any prohibited assignment is void.
  • Force Majeure. Neither party is liable for any delay or failure to perform (other than payment obligations) due to causes beyond its reasonable control, including acts of God, natural disasters, labor disputes, internet or utility failures, denial-of-service attacks, governmental action, or failures of Connected Services or other third parties. Force majeure does not excuse the execution of an unauthorized Administrative Action or Destructive Action.
  • Severability and Blue-Pencil. If any provision of these Terms is held invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable, or if it cannot be so modified, severed, and the remaining provisions will continue in full force and effect. This Section is subject to the specific severability rules in Section 20 for the arbitration provision.
  • Entire Agreement. These Terms, together with the Privacy Policy, the DPA, the Administer Authorization, and any applicable Order Form or enterprise agreement, are the entire agreement between the parties regarding the Service and supersede all prior or contemporaneous agreements and understandings, subject to Section 6.
  • No Waiver. No failure or delay in exercising any right is a waiver, and no waiver is effective unless in writing.
  • Relationship. The parties are independent contractors. These Terms create no partnership, joint venture, agency, or employment relationship, except that, where the Service takes Operator Actions, Administrative Actions, or Destructive Actions, it does so as Customer’s configured tool acting within the rules and scopes Customer approved. This characterization is between the parties only and does not determine any third person’s rights.
  • Third-Party Beneficiaries. Each member of the ASG ecosystem is an intended third-party beneficiary of, and may enforce, Sections 15, 16, 17, 20, and 21. Except as so stated, these Terms create no third-party beneficiary rights, and no provision of these Terms limits, waives, or releases any right that a person who is not a party to these Terms may have against Customer or against any member of the ASG ecosystem.
  • Notices. Notices to Company must be in writing and sent to legal@bolde.ai and to: Agentic Secure Group Inc., c/o Hedberg Law, 5944 S Kipling Pkwy, Suite 200, Littleton, CO 80127. Notices to Customer may be sent to the email or account contact on file and are effective when sent.
  • Export and Sanctions. Customer must comply with all applicable U.S. export-control and economic-sanctions laws. Customer represents that it is not located in, or organized under the laws of, a country or region subject to comprehensive U.S. sanctions, and is not a party identified on any U.S. government restricted-party list, and will not use the Service in violation of such laws.
  • U.S. Government End Users. The Service is a “commercial product” consisting of “commercial computer software” and “commercial computer software documentation” as those terms are used in 48 C.F.R. § 12.212 and 48 C.F.R. § 227.7202. Any use, modification, reproduction, or disclosure by the U.S. Government is governed solely by these Terms, and all other use is prohibited.
  • Biometric Data. The Service does not capture, store, or use biometric identifiers or biometric information as those terms are defined by the Illinois Biometric Information Privacy Act or comparable laws. Where Customer connects an identity system, the Service may process metadata indicating whether a user has enrolled an authentication method, including a device-based biometric authentication method; that metadata is not a biometric identifier or biometric information, and the Service does not receive, derive, or retain the underlying biometric measurement, which remains within the user’s device or the Connected Service. Customer must not use the Service to collect, capture, transmit, or store biometric identifiers or biometric information.
  • Headings and Interpretation. Headings are for convenience only. “Including” means “including without limitation.”

23. Administer Mode and Administrative Authorization.

23.1 What Administer Does. Administer is the mode through which the Service takes Administrative Actions in a Connected Service. Administrative Actions change the configuration and control-plane state of Customer’s tenant. They are materially different in kind and consequence from reading Customer Data or from taking Operator Actions, and they are governed by this Section, Section 24, and Section 25 rather than by Section 9.3 alone. As stated in Section 3.3, Company does not represent that any application registration used by the Service is limited to read access.

23.2 Administer Authorization. Administer is off by default. Company will not take an Administrative Action unless and until a Designated Administrative Contact has completed an Administer Authorization, which requires all of the following: (a) presentation to that individual, at the time of authorization, of an itemized, per-application, permission-by-permission description of the Administrative Actions being enabled, identifying which of them are Destructive Actions; (b) that individual’s affirmative, separate assent to the Administer and Destructive Action terms in Sections 23, 24, and 25, distinct from acceptance of these Terms generally; and (c) Company’s creation of a record capturing the authorizing individual’s identity, the date and time, the version of these Terms, and the specific permission manifest authorized. Company will make that record available to Customer on request. The Administer Authorization is renewed at each Order Form and at each expansion of the Administrative Scope.

23.3 Administrative Scope and Customer Control. Company will take Administrative Actions only within the Administrative Scope. Customer may narrow, suspend, or revoke the Administrative Scope at any time, by notice to Company or by revoking or restricting consent for the relevant application registration directly within the Connected Service. Revocation within the Connected Service is effective immediately and does not require Company’s cooperation. Company will configure the Service to request and hold no more privilege than the Administrative Scope requires.

23.4 Privilege Ceiling. Company will not assume, request, self-assign, or operate under a tenant-wide privileged directory role — including Global Administrator, Privileged Role Administrator, or Application Administrator, or their equivalents in a Connected Service — and will not grant such a role to an Agent Identity, except pursuant to a specific, written, instance-level approval by a Designated Administrative Contact identifying the role, the purpose, and the duration.

23.5 Status of Technical Controls. The obligations Company undertakes in Sections 23, 24, and 25 are binding contractual and operational commitments, and Company’s failure to observe any of them is a breach of these Terms. Company does not represent that each of them is additionally enforced by a technical control in the Service, and Customer must not rely on any such technical control unless it is described as in place at bolde.ai/security, which states which controls are in place today and which are forthcoming. Customer should read that page before enabling Administer or a Destructive Action Scope.

24. Destructive Actions.

DESTRUCTIVE ACTIONS ARE IRREVERSIBLE

A DESTRUCTIVE ACTION — INCLUDING A REMOTE WIPE, FACTORY RESET, RETIREMENT, OR DELETION — IS EXECUTED BY THE CONNECTED SERVICE AND IS ORDINARILY IRREVERSIBLE. THE SERVICE DOES NOT TAKE A PRE-ACTION SNAPSHOT OR ESCROW COPY OF THE AFFECTED STATE, AND COMPANY CANNOT UNDO A COMPLETED DESTRUCTIVE ACTION. CUSTOMER MUST NOT ENABLE A DESTRUCTIVE ACTION SCOPE UNLESS IT HAS INDEPENDENTLY VERIFIED THAT ITS OWN BACKUP, PRESERVATION, AND RECOVERY ARRANGEMENTS ARE ADEQUATE.

24.1 Nature of the Capability. Where Customer enables it, the Service can direct a Connected Service to execute a Destructive Action, including remote wipe, factory reset, retirement, or unenrollment of a device, and deletion of a directory object, mailbox, credential, or retention or hold configuration. The consequences of a Destructive Action may extend to individuals who are not parties to these Terms, including individuals whose devices, accounts, or personal data are affected.

24.2 Destructive Action Scope Is Opt-In and Enumerated. The Destructive Action Scope is empty by default. Company will not execute any Destructive Action unless Customer, acting through a Designated Administrative Contact, has separately and affirmatively enabled a Destructive Action Scope that enumerates (a) each category of Destructive Action enabled and (b) each class of eligible target. Unless Customer expressly and in writing extends it, a Destructive Action Scope is limited to devices that Customer owns and that are enrolled in the applicable Connected Service as corporate-owned and fully managed. Enabling a Destructive Action Scope requires a current Administer Authorization under Section 23.2 and the designation of at least two Designated Administrative Contacts.

24.3 Authorization Required for Each Destructive Action. Company will not execute a Destructive Action except on the express authorization of a Designated Administrative Contact, given against an itemized list of the specific target objects and confirmed through a channel independent of the session in which the request originated. The operational procedure for that authorization — including confirmation, delay, abort, and second-approver requirements — is set out in the DPA. This Section states a binding contractual and operational obligation; Section 23.5 governs whether it is additionally enforced by a technical control.

24.4 Personally-Owned Devices. Customer must not include a Personally-Owned Device within a Destructive Action Scope. Company will not knowingly execute a Destructive Action against a device whose ownership designation in the Connected Service is personal, and will not execute a full-device wipe or factory reset of any device Customer has not designated as corporate-owned and fully managed. This is a contractual and operational commitment, not a technical restriction in the Service, and it depends on the accuracy of Customer’s ownership designations in the Connected Service. Company will make available a configuration option by which Customer may restrict all device actions to selective removal of Customer-controlled work data rather than full-device wipe, and Company recommends that Customer enable it.

24.5 Hold-Suppressed Assets. Customer may designate any asset as a Hold-Suppressed Asset in the Service. In addition, before executing a Destructive Action, Company will query the native hold, preservation, and retention state of the applicable Connected Service for each target and will not execute the action against a target reflecting an active hold or preservation state without a further, specific, written instruction from a Designated Administrative Contact that expressly acknowledges the hold. Company’s obligations if it executes a Destructive Action against a Hold-Suppressed Asset are set out in Section 17.3. Nothing in these Terms purports to limit any preservation obligation either party owes to a court, tribunal, or regulator.

24.6 Individual Notice and Consent Are Customer’s Responsibility. Customer is responsible for providing notice to, and obtaining any acknowledgment or agreement required from, each individual whose device or account is or may be within a Destructive Action Scope, and represents and warrants that it has done so before enabling that scope. Nothing in these Terms binds any individual who has not separately agreed to be bound.

24.7 Records. For each Administrative Action and Destructive Action, the Service records the initiating human, the Designated Administrative Contacts who authorized it, the governing rule or request, the Agent Identity under which it executed, the itemized target list, the timestamp, the correlation identifier, and the result. That record is written to the Auditor audit trail, is Customer Data, is made available to Customer on request in a machine-readable form, and is retained for not less than the applicable limitations period notwithstanding any earlier deletion of other Customer Data.

24.8 Risk Allocation and Incident Notice. Destructive Action Claims are governed by the separate and funded allocation in Section 16.2, the carve-outs in Section 16.3, the indemnity in Section 17.3, and the limitations-period rule in Section 20.10(d). If Company executes a Destructive Action outside the Destructive Action Scope, against a target Customer did not authorize, or without the authorization required by Section 24.3, Company will notify Customer within twenty-four (24) hours of becoming aware, will deliver the itemized target list and the authorization record, will identify the restoration options available, and will handle the event under the incident-response obligations in the DPA.

25. Agent Identity.

25.1 Lifecycle. Where Customer enables it within the Administrative Scope, the Service creates, registers, configures, credentials, enables, disables, restores, and deletes Agent Identities within Customer’s Connected Services, and performs Agent Actions under them. Agent Identity lifecycle operations are Administrative Actions; deletion of an Agent Identity and revocation of its credential are Destructive Actions.

25.2 Ownership. As between the parties, each Agent Identity created within Customer’s tenant, and each Control-Plane Object associated with it, is Customer’s property and Customer Data. Company claims no ownership interest in it and will not transfer, replicate, or reuse it outside Customer’s deployment.

25.3 Attribution Between the Parties Only. As between Company and Customer, Agent Actions performed within the Administrative Scope and in accordance with Customer’s configured rules are attributed to Customer. This allocation is solely between the parties, confers no rights on and imposes no obligation upon any third person, and does not limit any right a third person may have against either party. It does not apply to an Agent Action performed outside the Administrative Scope, against a target Customer did not authorize, or in breach of these Terms.

25.4 Customer Kill Switch. Customer may at any time, unilaterally and without Company’s cooperation or consent, revoke its consent for any application registration through which the Service operates, disable or delete the corresponding service principal, or delete an Agent Identity, in each case directly within the Connected Service; the effect is immediate and terminates the Service’s ability to act under that identity. Company will not obstruct, delay, or attempt to re-establish such a revocation, and will not re-request consent without a new instruction from a Designated Administrative Contact. Custody of the credentials through which the Service authenticates is addressed in the DPA.

25.5 Deprovisioning and Attestation. On termination or expiration of these Terms, on suspension of the Service, or on Customer’s written request, Company will disable every Agent Identity it created for Customer, revoke every associated credential in its custody, delete those Agent Identities except where Customer instructs otherwise or applicable law requires retention, and deliver to Customer a written attestation identifying each Agent Identity, the action taken, and the date and time. The timetable for each step is set out in the DPA. This Section survives termination.

25.6 Attribution Telemetry. For each Agent Action, the Service records the initiating human where one exists, the governing rule, the Agent Identity, the target, the timestamp, the correlation identifier, and the result. That record is written to the Auditor audit trail, is Customer Data, and is retained on the same basis as Section 24.7.

25.7 Privilege Ceiling for Agent Identities. Agent Identities are subject to the privilege ceiling in Section 23.4. Company will not grant an Agent Identity a permission outside the Administrative Scope, and will not use an Agent Identity to perform work for any customer other than the Customer in whose tenant it resides.

26. Security Services — Scope of Undertaking.

26.1 What the Service Is Not. The Service is not a managed security service, a managed detection and response service, a security operations center, an incident response service, a compliance certification, or a substitute for any of them. Company does not undertake, and expressly disclaims, any duty to monitor Customer’s environment, to detect any threat, compromise, misconfiguration, insider activity, data loss, or policy violation, to alert Customer to any condition, or to remediate any condition. Scouts and Security Signals surface information the Connected Service makes available; they are not a detection guarantee, and the absence of a Security Signal is not evidence that a condition does not exist.

26.2 Affirmative Acts Are Not Disclaimed. Nothing in this Section limits or disclaims Company’s responsibility for its own affirmative acts, including any Administrative Action, Destructive Action, or Agent Action the Service executes. This Section addresses only what Company does not undertake to do; it does not limit Company’s responsibility for what it does.

26.3 No Assumption of Customer’s Duties to Others. Company does not assume, and these Terms do not transfer to Company, any duty that Customer owes to any third person, including any duty Customer owes to its personnel, its customers, a regulator, or a court. Company’s performance of any service under these Terms is not an undertaking to render services to any third person, is not intended to protect any third person, and no third person is entitled to rely on it. Customer remains solely responsible for its own security program, its own preservation and retention obligations, and its own legal and regulatory duties.

26.4 No Third-Party Reliance on Security Signals. Security Signals, Outputs, posture findings, and audit records made available through the Service are provided to Customer for Customer’s internal use. They are not certifications, attestations, or assurances to any third person, and Company makes no representation to any third person regarding them. Customer must not present them to any third person as a Company certification or attestation.

26.5 Security Operations Mode Does Not Change the Undertaking. The Sentry mode described in Section 4 is not part of the Service unless and until the conditions in Section 4.4 are satisfied, and it is not available as of the “Last updated” date at the end of these Terms. If it later becomes part of the Service, it does not convert the Service into a managed security service, a managed detection and response service, a security operations center, an incident response service, or a substitute for any of them, and it does not create any duty to monitor Customer’s environment, to detect, investigate, triage, escalate, alert to, or remediate any threat, compromise, misconfiguration, insider activity, data loss, identity risk, or policy violation. Section 26.1 applies to that mode in full and without qualification, and applies to every Security Signal, posture finding, threat or identity-risk indicator, audit-log query result, and configuration-monitoring finding it surfaces; the absence of any such signal or finding is not evidence that a condition does not exist. Sections 26.2, 26.3, and 26.4 apply to that mode on the same terms.

27. Contact.

For questions about these Terms, contact legal@bolde.ai. For privacy requests, contact privacy@bolde.ai. For security matters, including to report an unauthorized or incorrectly executed Administrative Action or Destructive Action, contact security@bolde.ai. Mailing address: Agentic Secure Group Inc., c/o Hedberg Law, 5944 S Kipling Pkwy, Suite 200, Littleton, CO 80127.

Last updated: 2026-07-25.

Legal questions?

For questions about these Terms, disputes, or to exercise any rights described here, email us at legal@bolde.ai.

Privacy PolicySecurityBack to home
bolde.

AI that stays yours.

Private business intelligence for sensitive work. Ask questions, get sourced answers, and keep the work inside your boundary.

Product

  • Features
  • Roadmap
  • Request Early Access

Company

  • About
  • FAQ
  • Bolde Updates

Contact

  • hello@bolde.ai
  • support@bolde.ai
  • security@bolde.ai

Legal

  • Privacy
  • Terms
  • DPA
  • Security
  • Privacy Contact
5944 S Kipling Pkwy, Suite 200Hedberg LawLittleton, CO 80127

© 2026 Agentic Secure Group Inc. All rights reserved.

Delaware C-Corporation · United States