Token Custody
You are entirely responsible for the security and confidentiality of your administrative credentials, client IDs, and API keys. Any action authorized by your keys is deemed authorized by your organization.
Last updated: September 25, 2026. These terms govern your access to and use of the Spctre platform, CLI tools, SDKs, and managed decision gateway services operated by Ciwrl Technologies LLC d/b/a Spctre. Refunds, cancellation, and renewals are covered by the Refund Policy.
Spctre is operated by Ciwrl Technologies LLC d/b/a Spctre. Spctre provides a unified control plane to write, test, simulate, compile, and publish security and governance policies for autonomous systems.
Subject to compliance with these terms, Spctre grants you a limited, non-exclusive, non-transferable, revocable license to access our administrative console, compile policy bundles, and integrate your runtimes with our decision gateways.
Our core engine and command-line interfaces (CLIs) are distributed under separate open-source licenses (typically Apache 2.0). Your use of those specific components is governed by their respective licenses, which take precedence over these terms where applicable.
Standard workspaces are provided on an "as-is" and "as-available" basis. Premium Spctre Cloud workspaces are governed by dedicated Service Level Agreements covering latency, availability, and dedicated review queues.
The Community edition is free and open source under Apache 2.0, and nothing in this section applies to it. Paid Spctre Cloud plans, their rates, and what each includes are set out on the pricing page; all amounts are in US dollars. Enterprise engagements are governed by a signed order form, which takes precedence over this section where the two differ.
Paddle.com Market Limited is our merchant of record and reseller. Payments are collected by Paddle, charges appear on your statement as Paddle rather than as Spctre, and Paddle's Buyer Terms apply to the transaction alongside these terms. As merchant of record, Paddle determines, collects, and remits any sales tax, VAT, or GST due on the purchase; the amount is shown at checkout and itemized on the receipt Paddle issues.
Each paid plan includes a governed-event capacity and a retention window. Where your plan meters usage beyond what it includes, that usage is billed monthly in arrears at the rate published on the pricing page — monthly in arrears even on an annual plan, so a busy month cannot accumulate into a single surprise at renewal — and appears as a separate line item on the invoice.
If a charge fails, Paddle retries it and notifies you. If an invoice remains unpaid after those attempts we may suspend access to the hosted workspace, and we will tell you before we do. Suspension does not delete your evidence: governance records remain subject to the retention window for your plan and can be exported while the account exists. Continued non-payment may lead to termination under Rules & Suspensions below.
You can cancel at any time and keep access until the end of the period you have paid for. A first subscription payment is covered by a 14-day money-back guarantee, and your statutory rights are never reduced. The full terms, including how to request a refund, are in the Refund Policy, which forms part of these terms.
Billing questions go to support@spctre.dev.
You are entirely responsible for the security and confidentiality of your administrative credentials, client IDs, and API keys. Any action authorized by your keys is deemed authorized by your organization.
To maintain gateway reliability, we apply dynamic rate limits on policy compilation and gateway evaluation requests. Circumventing these limits via concurrent key generation is strictly prohibited.
You must immediately notify Spctre Security at security@spctre.dev in the event of any unauthorized credential exposure, workspace compromise, or token leak in your agent configuration repos.
IMPORTANT NOTICE ON RUNTIME ACTIONS: Spctre is a policy evaluation and audit control plane. Spctre does NOT execute the actual tools, write the code files, transfer funds, or invoke external APIs on behalf of your autonomous systems.
You retain exclusive ownership, configuration, and control over the agent runtimes that call the Spctre gateway. You are solely responsible for the actions, database mutations, infrastructure costs, and API side-effects generated by your autonomous agents.
Spctre evaluates metadata against policies you author. If an agent executes a destructive action due to an incorrectly configured policy rule, a bypassed SDK check, or a missing runtime target mapping, Spctre is not liable for any resulting damage or loss.
To the maximum extent permitted by law, Ciwrl Technologies LLC d/b/a Spctre shall not be liable for any direct, indirect, incidental, special, or consequential damages resulting from tool execution failures, agent operational failures, or ledger synchronization delays.