Legal / TermsBack to Kestrel

KESTREL ADVANCED SYSTEMS PTE. LTD.

MASTER TERMS OF SERVICE

Effective Date: 4 October 2026
Last Updated: 4 October 2026


IMPORTANT NOTICE

These Master Terms of Service (the “Terms”) constitute a legally binding agreement between Kestrel Advanced Systems Pte. Ltd., a private limited company incorporated in Singapore (“Kestrel”, “we”, “us” or “our”), and the organisation identified in an applicable Order Form, registration process or other accepted ordering document (“Customer”, “you” or “your”).

These Terms govern access to and use of Kestrel’s enterprise artificial-intelligence governance, security, runtime-control, assurance, audit and related software, APIs, gateways, dashboards, documentation, services and associated functionality.

KESTREL IS A BUSINESS-TO-BUSINESS SERVICE. IT IS NOT OFFERED FOR PERSONAL, FAMILY, HOUSEHOLD OR OTHER CONSUMER USE.

The individual accepting these Terms on behalf of Customer represents and warrants that the individual has authority to bind Customer.

By executing an Order Form referring to these Terms, clicking an acceptance mechanism presented with these Terms, accessing the Platform following an authorised enterprise registration, or otherwise affirmatively agreeing to these Terms, Customer agrees to be bound by them.

If the individual accepting these Terms does not have authority to bind the relevant organisation, that individual must not accept these Terms or use the Service on that organisation’s behalf.


SCHEDULE 1

KESTREL CONTRACT PARTICULARS

1. Corporate Information

Legal Entity: Kestrel Advanced Systems Pte. Ltd.

Country of Incorporation: Singapore

Entity Type: Private company limited by shares

UEN / Company Registration Number: 202644596C

Registered Office / Business Address:
Blk 31, #01-16C
535 Clementi Road
Singapore 599489

General Contact Email: contact@kestreladvanced.com

Legal Notices Email: legal@kestreladvanced.com

Privacy / Data Protection Email: privacy@kestreladvanced.com

2. Kestrel Online Properties

Primary Website: https://kestreladvanced.com

Platform / Dashboard Domain: https://kestreladvanced.com/admin

API / Gateway Domain(s): Customer-specific API and gateway domains will be specified in the applicable Order Form or deployment documentation.

Privacy Policy URL: https://kestreladvanced.com/privacy

Data Processing Addendum: Available upon request from legal@kestreladvanced.com until a public URL is deployed.

Security Information / Security Addendum: Available upon request from legal@kestreladvanced.com until a public URL is deployed.

Subprocessor List: To be published. Until publication, current subprocessor information is available upon request from privacy@kestreladvanced.com.

3. Contracting Entity

Unless an applicable Order Form expressly states otherwise, the contracting entity for the Service is:

Kestrel Advanced Systems Pte. Ltd.
Blk 31, #01-16C
535 Clementi Road
Singapore 599489

General enquiries: contact@kestreladvanced.com

Legal notices: legal@kestreladvanced.com

Privacy and data-protection enquiries: privacy@kestreladvanced.com

4. Authorised User Minimum Age

Default: 18 years.

No person below 18 years of age may establish or administer a Kestrel Account.

5. Production Subscription Term

Default: monthly subscription automatically renewing for successive one-month periods until Customer cancels before the next renewal date.

An executed Order Form may establish a longer committed Subscription Term.

6. Enterprise Volume Subscription Term

Default: annual committed contract unless the applicable Order Form states otherwise.

7. Payment Due Date

Default: fourteen (14) calendar days from invoice date for standard subscriptions. A negotiated enterprise Order Form may provide Net 30 or another expressly stated period.

8. Late Payment Interest

Default: 1.0% per month, or the maximum amount permitted by Applicable Law if lower.

9. Billable Request Rule

Unless an Order Form states otherwise:

  1. a Billable Request is a Request accepted past authentication and basic protocol validation and processed by Kestrel’s runtime-control infrastructure;
  2. a Request that Kestrel subsequently allows, audits, redacts, transforms, holds or blocks remains billable because Kestrel processing was performed;
  3. Requests rejected before substantive processing because of invalid authentication or malformed protocol data are not billable;
  4. Requests that fail solely because of a verified Kestrel internal service error are not billable;
  5. a customer-initiated retry that is separately processed constitutes another Request;
  6. a streaming request constitutes one Request unless Documentation expressly identifies another metering method; and
  7. batch operations may be metered by individual processed item where identified in the Documentation.

► ENGINEERING MUST VERIFY THIS MATCHES ACTUAL METERING BEFORE PUBLICATION.

10. Customer Content and Model Training

Customer Content is not used to train general-purpose Kestrel models or models made available to other customers.

Kestrel may use appropriately aggregated and de-identified operational and Usage Data for security, reliability, analytics, abuse prevention and product improvement in accordance with Section 17.

11. Pilot Production Data

Production traffic or live personal data may be used in a Pilot only where expressly permitted by the applicable Order Form, appropriate technical safeguards are active, and any required Data Processing Addendum is effective.

12. Customer Data Export Following Termination

Default: thirty (30) days after termination or expiry, unless legal, security or technical restrictions apply.

13. Data Deletion / Backup Cycle

Following the thirty-day export period, Kestrel will begin deleting Customer Data from active production systems within thirty (30) days, subject to legal holds and other retention required by Applicable Law.

Customer Data remaining solely in backups is intended to expire or be deleted through Kestrel's backup lifecycle within thirty (30) days after removal from active production systems, subject to legal holds and documented recovery-integrity constraints. Customer Data retained solely in backups will not be restored to active use except for disaster recovery, security, legal or continuity purposes.

► PUBLICATION GATE: Infrastructure must implement and verify the thirty-day production backup lifecycle before this commitment is published or accepted.

14. Service Level Agreement

Default: Kestrel provides no contractual uptime percentage or service-credit commitment unless an Order Form expressly incorporates an SLA.

This does not prevent Kestrel from maintaining internal availability objectives.

15. Support

Support channel: support@kestreladvanced.com and the authenticated Kestrel dashboard where available.

Standard support hours: Monday to Friday, 09:00 to 18:00 Singapore time, excluding Singapore public holidays.

Critical incidents: Customer should mark the matter as critical and report it through support@kestreladvanced.com and the authenticated Kestrel dashboard where available.

Guaranteed response targets: None for standard plans. Published or communicated response times are targets only unless an applicable Order Form expressly incorporates an SLA.

16. Automated Enforcement Defaults

Customer-configured policies may cause Kestrel to allow, audit, hold, deny, redact, transform or otherwise control activity.

► ENGINEERING / PRODUCT TO VERIFY: default fail-open/fail-closed behaviour, emergency behaviour and available override mechanisms.


17. Regulated and High-Impact Uses

Default contractual position: regulated industries are not categorically prohibited merely because they are regulated, but Customer must obtain written Kestrel approval before relying on the Service as a material control in a use case involving safety-critical systems or automated decisions that directly determine an individual’s legal rights or access to healthcare, credit, insurance, employment, education, housing, essential public services or comparable high-impact outcomes.

An applicable Order Form or sector-specific addendum may impose additional requirements.

18. Territorial Restriction

Subject to applicable sanctions, export controls and other legal restrictions, Kestrel is available for purchase and deployment worldwide, including by organisations in the United States and California, except that Kestrel is not currently available for deployment within the European Union or European Economic Area.

Unless Kestrel expressly agrees otherwise in writing, this restriction concerns the location of Customer’s Kestrel deployment, governed AI infrastructure and controlled production systems. Mere access to Kestrel’s public website from the EU or EEA does not, by itself, constitute a prohibited deployment.

A Customer headquartered in the EU or EEA may not assume that its non-EU deployment is permitted without Kestrel confirming the proposed architecture.

19. Professional Services

Professional Services are available only where described in a mutually executed Order Form or Statement of Work.

20. Publicity

Default: Kestrel may not publish Customer’s name, trademarks or logo as a customer reference without Customer’s prior written consent.


PART I — GENERAL CONTRACT TERMS

1. DEFINITIONS

1.1 Defined Terms

In these Terms:

“Account” means the Customer-specific account, tenant, workspace or environment through which Customer accesses the Service.

“Affiliate” means, with respect to an entity, another entity that directly or indirectly controls, is controlled by, or is under common control with that entity, where “control” means ownership or control of more than fifty percent (50%) of the voting interests or equivalent power to direct management.

“Applicable Law” means any law, regulation, legally binding governmental requirement, court order or regulatory obligation applicable to the relevant party, activity or jurisdiction.

“AUP” means the Acceptable Use Policy in Schedule 2.

“Authorised User” means an employee, contractor, service account or other individual or system authorised by Customer to use the Service within Customer’s Account.

“Billable Request” has the meaning stated in Schedule 1.

“Confidential Information” has the meaning set out in Section 21.

“Customer Content” means prompts, instructions, messages, files, datasets, configuration values, system messages, tool inputs, model outputs, personal data, records or other content submitted to, transmitted through, stored in or otherwise processed by the Service on Customer’s behalf.

“Customer Data” means Customer Content together with other data relating specifically to Customer or its Authorised Users, excluding Kestrel Technology and properly Aggregated Data.

“Documentation” means Kestrel’s then-current technical documentation, integration instructions and other documentation designated by Kestrel as governing authorised use of the Service.

“Effective Date” means the date on which the applicable agreement between Kestrel and Customer becomes effective.

“Feedback” means suggestions, comments, recommendations or other feedback voluntarily provided concerning Kestrel products or services.

“Fees” means amounts payable to Kestrel under an applicable Order Form, pricing arrangement or these Terms.

“Kestrel Technology” means the Service and all software, APIs, gateways, code, algorithms, classifiers, policy systems, methods, designs, templates, documentation, workflows, models, interfaces, inventions, architectures and technology owned or controlled by Kestrel, including modifications and improvements.

“Model Provider” means an external provider of artificial-intelligence models, inference APIs or related services.

“Order Form” means an ordering document, quotation, subscription page, statement of work or other mutually accepted document identifying the Service purchased by Customer.

“Output” means an output, decision, classification, score, alert, finding, recommendation, transformed response or other result generated, transmitted or surfaced through the Service.

“Pilot” means a time-limited evaluation subscription governed by Schedule 4.

“Platform” means Kestrel’s enterprise AI governance and control-plane platform.

“Professional Services” means implementation, onboarding, training, advisory, configuration, migration or similar services expressly purchased by Customer.

“Request” means an individual transaction, call, message or other processing event submitted to Kestrel for evaluation or processing.

“Security Incident” means a confirmed breach of security resulting in unauthorised access to, acquisition of, disclosure of, alteration of or destruction of Customer Data in Kestrel’s possession or control, excluding unsuccessful attempts or incidents occurring exclusively within Customer Systems.

“Service” means the Platform and any purchased software, API, gateway, dashboard, documentation, support or related service provided by Kestrel.

“Subscription Term” means the period during which Customer is authorised to access the applicable Service.

“Subprocessor” means a third party engaged by Kestrel to process personal data on Customer’s behalf as further addressed in the DPA.

“Supported Integration” means a third-party service or technical interface identified in current Documentation as supported by Kestrel.

“Third-Party Service” means any product, network, model, software, infrastructure, tool, platform, dataset, service or system not owned by Kestrel.

“Tool Action” means an action proposed or performed by an AI system, agent, service or workflow through an external tool, API, application or system.

“Usage Data” means service telemetry and information concerning operation and use of the Service, including request volumes, latency, system performance, security events, feature utilisation and technical metadata.

“Website” means Kestrel’s public websites identified in Schedule 1.

1.2 Interpretation

Unless context requires otherwise:

(a) “including” and similar expressions mean “including without limitation”;

(b) references to a statute include amendments, replacements and subordinate legislation;

(c) references to writing include legally valid electronic communications;

(d) the singular includes the plural and vice versa;

(e) headings are for convenience only;

(f) references to days are calendar days unless expressly stated otherwise; and

(g) no rule of construction requiring ambiguity to be resolved against the drafting party applies merely because Kestrel prepared these Terms, to the extent permitted by Applicable Law.


2. CONTRACT FORMATION AND AUTHORITY

2.1 Methods of Acceptance

Customer may accept these Terms through:

(a) execution of an Order Form;

(b) electronic signature;

(c) affirmative clickwrap acceptance;

(d) an authorised online ordering process; or

(e) another method that objectively demonstrates agreement.

2.2 Electronic Transactions

The parties agree that electronic records, electronic signatures, electronically accepted Order Forms and automated electronic systems may be used for contract formation and administration to the extent permitted by Applicable Law.

2.3 Authority

The individual accepting these Terms represents and warrants that:

(a) the individual has legal authority to bind Customer;

(b) Customer is entering the agreement for business purposes; and

(c) information supplied during registration is materially accurate.

2.4 No Consumer Contract

The Service is offered exclusively for business and organisational use.

Customer must not purchase or use the Service primarily for personal, family or household purposes.

2.5 Unauthorised Acceptance

Kestrel may request reasonable evidence of authority.

If an acceptance appears fraudulent, unauthorised or erroneous, Kestrel may suspend activation while investigating.

2.6 Electronic Errors

Where an obvious clerical, pricing, configuration or electronic transmission error occurs, Kestrel may correct the error promptly, provided Customer is not deprived of amounts properly paid for Services already lawfully provided.


3. ORDER OF PRECEDENCE

In the event of inconsistency, the following order applies unless a document expressly states otherwise:

  1. a mutually executed amendment expressly modifying the conflicting provision;
  2. the applicable Order Form;
  3. the Data Processing Addendum, but only for personal-data processing matters;
  4. an applicable product-specific schedule;
  5. an expressly incorporated SLA;
  6. these Master Terms;
  7. the AUP;
  8. Documentation; and
  9. general Website materials.

Marketing materials, presentations, demonstrations and sales discussions do not override an executed Order Form or these Terms.

Purchase orders issued by Customer are for administrative convenience only and do not modify this Agreement even if Kestrel accepts, references or processes the purchase order.


4. SUBSCRIPTION AND ACCESS RIGHTS

4.1 Subscription Grant

Subject to Customer’s compliance with the Agreement and payment of Fees, Kestrel grants Customer during the Subscription Term a limited, non-exclusive, non-transferable and non-sublicensable right to access and use the purchased Service for Customer’s internal business purposes.

4.2 Authorised Users

Customer may permit its Authorised Users to use the Service within the scope purchased by Customer.

Customer remains responsible for compliance by its Authorised Users.

4.3 Affiliates

An Affiliate may use Customer’s Account only where the Order Form permits such use.

An Affiliate entering its own Order Form becomes a separate Customer unless the applicable Order Form expressly provides otherwise.

4.4 Contractors

Customer may permit contractors to access the Service solely to perform services for Customer, provided:

(a) their use is within Customer’s purchased scope;

(b) Customer remains responsible for their conduct;

(c) appropriate confidentiality obligations apply; and

(d) access is terminated when no longer necessary.

4.5 APIs, Gateways and Service Accounts

The subscription may include API credentials, gateway credentials and machine identities.

Customer must use them only as documented and within purchased limits.

4.6 No Source-Code Rights

No source-code licence, ownership interest, patent licence or right to Kestrel Technology is transferred except as expressly stated.

4.7 Rights Reserved

Kestrel reserves all rights not expressly granted.


5. ACCOUNT ADMINISTRATION AND SECURITY

Customer must:

(a) maintain accurate registration, administrative and billing information;

(b) designate appropriate administrators;

(c) promptly disable access for departed or unauthorised personnel;

(d) protect passwords, API keys, signing materials, access tokens, certificates and other credentials;

(e) maintain appropriate endpoint and identity security;

(f) configure roles and permissions appropriately;

(g) avoid sharing individual credentials;

(h) promptly notify Kestrel of suspected unauthorised access;

(i) maintain reasonable controls to prevent unauthorised use; and

(j) cooperate reasonably in investigating credible security events.

Customer is responsible for activity performed through its Account using valid Customer credentials except to the extent such activity results directly from Kestrel’s breach of the Agreement.

Kestrel may revoke or rotate credentials and impose reasonable temporary safeguards where necessary to respond to suspected compromise.


6. CUSTOMER SYSTEMS AND INTEGRATION

6.1 Customer Architecture

Customer controls its deployment architecture and is responsible for ensuring that AI traffic intended to be governed by Kestrel is routed through applicable Kestrel control points.

6.2 Bypassed Traffic

Kestrel cannot inspect, govern, audit or control traffic that does not pass through an integrated Kestrel control point.

Customer acknowledges that direct model access, alternative credentials, unsupported routes or bypass mechanisms may render Kestrel controls ineffective.

6.3 Customer Responsibilities

Customer is responsible for:

(a) Customer Systems;

(b) network connectivity;

(c) certificates and endpoints;

(d) upstream and downstream applications;

(e) identity-provider configuration;

(f) model-provider credentials;

(g) prompts and system messages;

(h) datasets;

(i) tool permissions;

(j) model settings;

(k) schemas;

(l) quotas;

(m) integration testing;

(n) business continuity; and

(o) prevention of unintended bypass.

6.4 Technical Changes

Kestrel may modify interfaces, APIs and technical requirements to maintain, improve or secure the Service.

Kestrel will use commercially reasonable efforts to provide advance notice of material breaking changes where practicable.

Immediate changes may be made to address security vulnerabilities, legal requirements, provider changes or urgent operational risks.


PART II — AI GOVERNANCE AND RUNTIME CONTROL

7. NATURE OF THE SERVICE

Kestrel is an enterprise AI governance, security and runtime-control layer designed to assist organisations in governing interaction between enterprise AI applications, agents, models, datasets and tools.

Depending on configuration and technical availability, functionality may include:

(a) prompt inspection;

(b) response inspection;

(c) Tool Action evaluation;

(d) authentication of agents and service identities;

(e) intent classification;

(f) data-sensitivity classification;

(g) personal-data detection and redaction;

(h) prompt-injection and adversarial-technique detection;

(i) contextual and multi-turn risk assessment;

(j) policy enforcement;

(k) allow, audit, hold or deny decisions;

(l) tenant-, organisation-, team-, role- or agent-scoped policy;

(m) policy simulation and shadow mode;

(n) AI-system, model, dataset, vendor, agent and tool inventories;

(o) risk and lifecycle workflows;

(p) assurance observations and findings;

(q) evidence collection;

(r) audit and integrity records;

(s) cryptographic receipts and checkpoints;

(t) executive reporting;

(u) operational metrics;

(v) SIEM or webhook integrations; and

(w) related functionality identified in current Documentation.

The precise Service purchased by Customer is determined by the applicable Order Form and current Documentation.


8. NO GUARANTEE OF AI SAFETY OR COMPLIANCE

Customer acknowledges that artificial-intelligence, cybersecurity and automated-classification systems are inherently probabilistic and imperfect.

Kestrel does not warrant or represent that the Service:

(a) will identify every threat;

(b) will identify every prompt-injection or jailbreak technique;

(c) will detect every item of personal, confidential or sensitive information;

(d) will prevent every unauthorised disclosure;

(e) will prevent every harmful model response;

(f) will eliminate false positives or false negatives;

(g) will prevent all attacks;

(h) will make Customer legally compliant;

(i) will satisfy every regulator, auditor or certification body;

(j) will produce error-free classifications;

(k) will ensure desired model behaviour;

(l) will eliminate the need for human oversight;

(m) will make an AI system safe for a particular purpose; or

(n) will eliminate Customer’s need for independent security, privacy, legal, compliance or risk controls.

Kestrel is a risk-control and decision-support system, not a substitute for Customer’s judgment or legal obligations.


9. AUTOMATED CONTROL DECISIONS

9.1 Automated Processing

Kestrel may make automated decisions based on:

(a) Customer-configured rules;

(b) policy configuration;

(c) patterns and signatures;

(d) classifiers;

(e) confidence thresholds;

(f) session context;

(g) risk state;

(h) security signals; and

(i) other configured or documented factors.

9.2 Possible Actions

Depending on configuration, Kestrel may:

(a) allow activity;

(b) record activity;

(c) redact information;

(d) transform content;

(e) delay activity;

(f) hold activity for review;

(g) deny activity;

(h) require escalation; or

(i) produce another documented policy result.

9.3 Probabilistic Results

Automated classifications and security conclusions may be incomplete or incorrect.

9.4 Customer Decision

Customer remains responsible for deciding:

(a) which policies to deploy;

(b) thresholds;

(c) escalation rules;

(d) whether human review is required;

(e) whether Customer permits overrides;

(f) how downstream systems react; and

(g) how Customer uses Kestrel outputs.

9.5 Operational Consequences

Customer acknowledges that restrictive configuration may cause legitimate activity to be blocked, delayed, redacted or held.

Customer is responsible for designing appropriate fallback procedures, exception handling, continuity arrangements and human review.


10. MODEL OUTPUTS

Kestrel does not originate or independently verify every output generated by Third-Party Services.

Customer is responsible for independently validating any model output where the output may materially affect:

(a) safety;

(b) finances;

(c) legal rights;

(d) regulatory obligations;

(e) health;

(f) employment;

(g) security;

(h) critical operations; or

(i) other significant decisions.

No Kestrel classification, recommendation or risk score constitutes legal, financial, medical, investment, accounting or other regulated professional advice.


11. PERSONAL-DATA REDACTION

Where enabled, Kestrel may identify, mask, tokenise, redact or otherwise transform detected personal or sensitive data.

These functions reduce risk but cannot guarantee that every relevant value will be identified.

Customer must independently determine whether its data-handling architecture satisfies Applicable Law and contractual obligations.


12. AUDIT RECORDS, RECEIPTS AND CRYPTOGRAPHIC EVIDENCE

Kestrel may generate audit records, hashes, linked records, signatures, receipts, Merkle checkpoints, integrity proofs and related evidence.

These mechanisms are designed to support integrity verification and tamper evidence.

They do not, by themselves, establish:

(a) the factual truth of the underlying event;

(b) completeness of all events;

(c) legal admissibility;

(d) regulatory acceptance;

(e) identity beyond the properties actually cryptographically verified;

(f) absence of all tampering;

(g) compliance with any legal evidentiary standard; or

(h) that an auditor, regulator, insurer, tribunal or court will regard the evidence as sufficient.

Customer remains responsible for evidence preservation required by law.


13. HUMAN OVERSIGHT

Customer must implement human oversight appropriate to the nature and risk of its AI systems.

Customer must not knowingly configure the Service so that a materially consequential automated decision is treated as unquestionably correct merely because Kestrel generated or approved a classification.


PART III — CUSTOMER RESPONSIBILITIES

14. RESPONSIBILITY FOR CUSTOMER AI SYSTEMS

Customer retains responsibility for:

(a) its AI systems;

(b) its models;

(c) model-provider selection;

(d) prompts and system messages;

(e) datasets and training data;

(f) agents;

(g) tools;

(h) action permissions;

(i) business processes;

(j) policies;

(k) end-user notices;

(l) legal bases for processing;

(m) consents;

(n) human oversight;

(o) validation;

(p) risk acceptance;

(q) incident response;

(r) regulatory submissions;

(s) business continuity;

(t) backups; and

(u) decisions made using AI Outputs.


15. CUSTOMER AUTHORITY OVER DATA

Customer represents and warrants that it has all rights, permissions, notices, consents and lawful authority necessary to provide Customer Content to Kestrel and to instruct Kestrel to process that Customer Content.

Customer must not submit data where doing so violates:

(a) Applicable Law;

(b) intellectual-property rights;

(c) privacy rights;

(d) confidentiality obligations;

(e) contractual restrictions; or

(f) applicable Model Provider requirements.


16. THIRD-PARTY PROVIDER TERMS

Customer is responsible for complying with terms applicable to Model Providers and Third-Party Services selected, supplied or contracted directly by Customer.

Kestrel is not responsible for Customer’s breach of those terms.


PART IV — DATA AND PRIVACY

17. CUSTOMER CONTENT

17.1 Ownership

As between Kestrel and Customer, Customer retains its ownership rights in Customer Content.

17.2 Processing Licence

Customer grants Kestrel and authorised Subprocessors a limited, non-exclusive licence during the Agreement to host, receive, copy, transmit, inspect, analyse, classify, redact, transform, secure, store, log, display and otherwise process Customer Content solely as reasonably necessary to:

(a) provide the Service;

(b) enforce Customer policies;

(c) secure the Service;

(d) investigate abuse;

(e) provide support;

(f) comply with Applicable Law; and

(g) perform other processing expressly authorised under the Agreement and DPA.

17.3 No Sale of Customer Content

Kestrel does not acquire ownership of Customer Content merely because it processes Customer Content.

17.4 Model Training

Kestrel’s permitted use of Customer Content for training or evaluation purposes is governed by the position specified in Schedule 1 and the applicable DPA.

17.5 Aggregated Data

Kestrel may create statistical, aggregated or de-identified information derived from operation of the Service, provided the resulting information does not reasonably identify Customer, an Authorised User or an individual.

Kestrel may use such information for:

(a) service analytics;

(b) capacity planning;

(c) security research;

(d) abuse detection;

(e) reliability;

(f) product development;

(g) benchmarking of Kestrel’s own systems; and

(h) business operations.

Kestrel will not intentionally re-identify properly de-identified data except to test the effectiveness of de-identification or where legally required.


18. PRIVACY AND DATA PROCESSING

18.1 Kestrel’s Own Processing

Personal data processed by Kestrel for its own business purposes is governed by Kestrel’s Privacy Policy.

18.2 Customer Personal Data

To the extent Kestrel processes personal data on Customer’s behalf as a processor, data intermediary or equivalent role, the Data Processing Addendum applies.

18.3 Customer Responsibilities

Customer remains responsible for:

(a) determining lawful grounds for its processing;

(b) providing required notices;

(c) obtaining required consent;

(d) responding to data-subject rights;

(e) data minimisation;

(f) determining retention periods;

(g) determining whether transfers are lawful; and

(h) determining whether Customer’s proposed AI deployment is permitted.

18.4 Subprocessors

Kestrel may use Subprocessors as identified through the Subprocessor List or DPA.

Kestrel remains responsible for Subprocessors to the extent required under the DPA and Applicable Law.


19. SECURITY

19.1 Kestrel Safeguards

Kestrel will maintain reasonable administrative, organisational and technical safeguards appropriate to the Service and risk, as further described in its Security Addendum or Documentation.

19.2 No Absolute Security

No internet-connected or software-based system can be guaranteed completely secure.

19.3 Security Incident

Kestrel will notify Customer of a confirmed Security Incident in accordance with the applicable DPA, Security Addendum and Applicable Law.

19.4 Exclusions

Events are not Security Incidents attributable to Kestrel merely because they involve:

(a) Customer credentials compromised outside Kestrel;

(b) Customer Systems;

(c) Customer misconfiguration;

(d) Customer-authorised activity;

(e) unsupported integrations;

(f) Customer bypass of security controls; or

(g) third-party systems outside Kestrel’s responsibility,

except to the extent Kestrel’s breach materially contributed to the event.


PART V — INTELLECTUAL PROPERTY

20. KESTREL TECHNOLOGY

20.1 Ownership

Kestrel and its licensors retain all right, title and interest in and to the Kestrel Technology.

This includes:

(a) software;

(b) gateway technology;

(c) APIs;

(d) dashboards;

(e) source code;

(f) object code;

(g) architecture;

(h) policy engines;

(i) classifiers;

(j) detection logic;

(k) templates;

(l) control frameworks;

(m) workflows;

(n) documentation;

(o) interfaces;

(p) designs;

(q) models;

(r) inventions;

(s) know-how;

(t) improvements; and

(u) derivative works.

20.2 Customer Configurations

Customer owns Customer Content incorporated into Customer-created policies and configurations.

Kestrel retains ownership of underlying Kestrel Technology, templates, schema, engines and generic methods used to implement them.

20.3 Reports and Exports

Subject to payment of applicable Fees, Customer may internally use reports and evidence exports generated specifically for Customer.

Such rights do not transfer ownership of Kestrel’s underlying technology, report architecture or generic templates.

20.4 Feedback

Customer grants Kestrel a perpetual, worldwide, irrevocable, transferable, sublicensable, royalty-free right to use and incorporate voluntary Feedback without restriction.

Kestrel will not exercise this right in a manner that intentionally publicly identifies Customer or discloses Customer Confidential Information without permission.


21. CONFIDENTIALITY

21.1 Confidential Information

“Confidential Information” means non-public information disclosed by one party to the other that a reasonable recipient would understand to be confidential.

It includes:

(a) Customer Content;

(b) non-public security information;

(c) source code;

(d) product architecture;

(e) vulnerabilities;

(f) business plans;

(g) pricing;

(h) non-public roadmaps;

(i) financial information;

(j) trade secrets; and

(k) confidential commercial information.

21.2 Obligations

The receiving party must:

(a) use Confidential Information only to perform or exercise rights under the Agreement;

(b) protect it using at least reasonable care;

(c) disclose it only to personnel, professional advisers, Affiliates and subcontractors with a legitimate need to know and appropriate confidentiality obligations; and

(d) not disclose it to another person except as authorised.

21.3 Exclusions

Confidential Information does not include information that the receiving party establishes:

(a) became public without breach;

(b) was lawfully known without confidentiality restriction before receipt;

(c) was independently developed without use of the disclosing party’s Confidential Information; or

(d) was lawfully received from another source without confidentiality obligation.

21.4 Compelled Disclosure

A party may disclose Confidential Information where legally compelled, provided it gives advance notice where legally permitted and reasonably cooperates with protective measures.

21.5 Security Information

Customer must not publicly disclose non-public vulnerabilities, penetration-test results or detailed security architecture in a manner that creates material security risk.

Nothing in this Section prevents lawful reporting to regulators, law enforcement, professional advisers or protected whistleblowing channels.

21.6 Injunctive Relief

Unauthorised disclosure of Confidential Information may cause harm not adequately compensated by damages.

The affected party may seek injunctive or equitable relief where legally available.

21.7 Survival

Confidentiality obligations survive for five (5) years following termination, except trade secrets and Customer Content remain protected for so long as they qualify for protection under Applicable Law or another contractual obligation requires longer protection.


PART VI — ACCEPTABLE USE AND RESTRICTIONS

22. ACCEPTABLE USE

Customer and Authorised Users must comply with Schedule 2.


23. RESTRICTIONS

Except to the limited extent Applicable Law makes a restriction unenforceable, Customer must not:

(a) reverse engineer, decompile or disassemble the Service;

(b) attempt to obtain Kestrel source code;

(c) circumvent authentication, tenant boundaries or access controls;

(d) disable or defeat metering;

(e) remove proprietary notices;

(f) resell or sublicense the Service unless expressly authorised;

(g) operate the Service as a service bureau for unrelated third parties unless expressly authorised;

(h) white-label the Service without permission;

(i) use the Service to develop a substantially competing product through systematic extraction of non-public functionality;

(j) conduct unauthorised penetration testing;

(k) access another tenant’s data;

(l) interfere with infrastructure;

(m) intentionally overload systems; or

(n) violate the AUP.


24. COMPETITIVE ANALYSIS AND BENCHMARKING

Customer may conduct ordinary internal testing of its purchased Service.

Customer may not, without Kestrel’s prior written consent:

(a) access the Service primarily to reverse engineer competitive functionality;

(b) systematically benchmark Kestrel for the principal purpose of developing or marketing a competing service; or

(c) publish non-public security or performance testing in a materially misleading manner.

This Section does not prohibit lawful independent research that cannot legally be restricted.


PART VII — THIRD-PARTY SERVICES

25. MODEL PROVIDERS AND THIRD-PARTY SERVICES

25.1 Dependencies

The Service may interoperate with Model Providers and Third-Party Services.

25.2 Independent Terms

Third-Party Services may have independent:

(a) terms;

(b) pricing;

(c) retention rules;

(d) privacy practices;

(e) usage limits;

(f) availability;

(g) content restrictions; and

(h) security practices.

25.3 Customer-Supplied Accounts

Where Customer supplies its own third-party account, licence, API key or credential, Customer is responsible for the applicable relationship with that provider.

25.4 Provider Changes

Third parties may modify APIs, models or services.

Kestrel is not liable for a third party’s independent decision to discontinue or materially alter a Third-Party Service, but Kestrel will use commercially reasonable efforts to mitigate material effects on Supported Integrations where appropriate.

25.5 Suspension of Integration

Kestrel may suspend an integration that creates a credible security, legal, compliance or operational risk.


PART VIII — FEES AND COMMERCIAL TERMS

26. FEES

Customer must pay all Fees specified in the applicable Order Form, pricing arrangement or Schedule 3.

Unless expressly stated otherwise, all Fees are denominated in United States dollars (USD).


27. STANDARD PLAN PRICING

Subject to an Order Form and future prospective pricing changes:

27.1 Pilot

Platform Fee: USD 500 per month

Included Requests: 100,000 Requests per month

Usage Cap: 100,000 Requests per month

Maximum Pilot Term: three months

27.2 Production

Platform Fee: USD 2,500 per month

Included Requests: the first 1,000,000 Requests per monthly billing period

Usage pricing:

  • Requests above 1,000,000 through 10,000,000 per monthly billing period: USD 1.00 per 1,000 additional Requests; and
  • Requests above 10,000,000 per monthly billing period: USD 0.60 per 1,000 additional Requests.

27.3 Enterprise Volume

Platform Fees, usage pricing, commitments and other commercial terms are established by Order Form.

The standard Enterprise Volume Subscription Term is annual.


28. BILLING

Unless an Order Form states otherwise:

(a) recurring platform Fees are invoiced in advance;

(b) measured usage is invoiced in arrears;

(c) Customer must pay invoices within the period specified in Schedule 1;

(d) payment obligations are non-cancellable during a committed Subscription Term except where the Agreement expressly provides otherwise; and

(e) Fees are non-refundable except as expressly stated in the Agreement or required by Applicable Law.


29. METERING

Kestrel’s service records constitute the initial basis for determining usage.

Customer may dispute an invoice in good faith by providing reasonably detailed information identifying the disputed amount.

Kestrel will investigate genuine metering disputes and correct verified errors.


30. TAXES

Fees exclude applicable GST, VAT, sales, use, withholding and similar taxes unless expressly stated otherwise.

Customer is responsible for taxes arising from its purchase, excluding taxes imposed on Kestrel’s net income.

Where Customer is legally required to withhold tax, Customer must provide appropriate official documentation.

The parties will cooperate reasonably concerning available treaty relief or exemptions.


31. OVERDUE AMOUNTS

Undisputed overdue amounts may accrue interest at the rate specified in Schedule 1.

Kestrel may recover reasonable lawful collection costs.


32. NON-PAYMENT SUSPENSION

Kestrel may suspend Service for materially overdue undisputed amounts after giving reasonable notice and an opportunity to cure.

Kestrel may act more quickly where there is credible evidence of fraud, payment abuse or material credit risk.


33. NO SET-OFF

Customer may not withhold or set off amounts owed to Kestrel except where required by Applicable Law or expressly agreed in writing.


34. PRICE CHANGES

Kestrel may change public pricing prospectively.

A price change does not retroactively alter Fees committed under an existing fixed-term Order Form.

For an automatically renewing subscription, Kestrel will provide reasonable advance notice before materially increasing recurring Fees.


PART IX — SERVICE OPERATION

35. AVAILABILITY

Unless an Order Form expressly incorporates an SLA:

KESTREL DOES NOT PROVIDE A CONTRACTUAL UPTIME PERCENTAGE OR SERVICE-CREDIT COMMITMENT.

Kestrel will nevertheless use commercially reasonable efforts to operate and maintain the Service in a manner suitable for the purchased subscription.


36. MAINTENANCE

Kestrel may perform:

(a) scheduled maintenance;

(b) emergency maintenance;

(c) security updates;

(d) upgrades; and

(e) infrastructure changes.

Where practicable, Kestrel will provide advance notice of maintenance expected to cause material disruption.


37. SUPPORT

Support is provided in accordance with Schedule 1, the applicable Order Form or an incorporated Support Schedule.

Unless expressly designated as contractual response commitments, response targets are operational goals and not guarantees of resolution.


38. CHANGES TO SERVICE

Kestrel may modify and improve the Service.

Kestrel will use commercially reasonable efforts to avoid materially reducing the core functionality purchased under a committed Order Form during its committed term.

If Kestrel permanently removes material paid functionality and that removal substantially impairs Customer’s purchased use case, Kestrel may, as appropriate:

(a) provide substantially equivalent functionality;

(b) provide a workaround;

(c) adjust the affected subscription; or

(d) permit termination of the materially affected Service with a pro-rata refund of prepaid unused Fees.

This does not apply to changes necessary because of:

(a) Applicable Law;

(b) urgent security risks;

(c) third-party deprecation beyond Kestrel’s reasonable control;

(d) Customer’s unsupported configuration; or

(e) free, beta or preview functionality.


39. ROADMAPS AND FUTURE FEATURES

Roadmap statements, demonstrations, mock-ups, screenshots, anticipated features and estimated release dates are informational only.

Customer must not base a purchasing obligation on a future feature unless the applicable Order Form expressly identifies delivery of that feature as a contractual commitment.


PART X — BETA AND PREVIEW FEATURES

40. BETA SERVICES

Kestrel may offer functionality designated “beta”, “preview”, “experimental”, “early access”, “developer preview” or similar.

Unless otherwise stated:

(a) participation is optional;

(b) the feature may contain defects;

(c) functionality may change;

(d) Kestrel may discontinue it;

(e) it is not subject to an SLA;

(f) it must not be relied on for safety-critical or essential production functions;

(g) support may be limited; and

(h) Kestrel may request Feedback.

Kestrel will not designate established production functionality “beta” merely to evade commitments expressly made for that functionality.


PART XI — PROFESSIONAL SERVICES

41. PROFESSIONAL SERVICES

Professional Services require an Order Form or Statement of Work identifying applicable:

(a) scope;

(b) deliverables;

(c) dependencies;

(d) responsibilities;

(e) timing;

(f) Fees;

(g) expenses;

(h) acceptance criteria; and

(i) change-control procedures.

Implementation guidance does not constitute legal or regulatory advice.

Customer is responsible for determining whether configurations ultimately selected by Customer satisfy Customer’s legal and business requirements.

Delays caused by Customer’s failure to provide required access, personnel, information or decisions may extend applicable timelines.


PART XII — WARRANTIES

42. MUTUAL AUTHORITY WARRANTY

Each party warrants that it has authority to enter into the Agreement.


43. KESTREL LIMITED SERVICE WARRANTY

For paid production Services, Kestrel warrants that the Service will, under normal authorised use, materially conform to the applicable Documentation.

Customer must notify Kestrel of a material non-conformity with sufficient information for Kestrel to reproduce or investigate it.

Kestrel’s obligation is to use commercially reasonable efforts to:

(a) correct the non-conformity;

(b) provide a reasonable workaround; or

(c) re-perform the affected Service.

If Kestrel cannot remedy a material non-conformity within a reasonable period and it substantially defeats the principal purpose of the affected Service, Customer may terminate the materially affected portion and receive a pro-rata refund of prepaid Fees covering the unused terminated period.


44. WARRANTY EXCLUSIONS

The warranty in Section 43 does not apply where a problem results from:

(a) Customer Systems;

(b) unauthorised modification;

(c) unsupported integration;

(d) misuse;

(e) Customer configuration contrary to Documentation;

(f) Model Provider behaviour;

(g) third-party systems outside Kestrel’s control;

(h) Customer’s failure to implement required updates;

(i) Beta Services; or

(j) force majeure.


45. DISCLAIMERS

EXCEPT FOR EXPRESS WARRANTIES IN THE AGREEMENT AND TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE SERVICE IS PROVIDED WITHOUT OTHER EXPRESS, IMPLIED, STATUTORY OR COLLATERAL WARRANTIES OR CONDITIONS.

TO THE MAXIMUM EXTENT PERMITTED BY LAW, KESTREL DISCLAIMS IMPLIED WARRANTIES OR CONDITIONS OF:

(a) MERCHANTABILITY;

(b) SATISFACTORY QUALITY;

(c) FITNESS FOR A PARTICULAR PURPOSE;

(d) NON-INFRINGEMENT, EXCEPT TO THE EXTENT ADDRESSED BY SECTION 48;

(e) UNINTERRUPTED AVAILABILITY;

(f) ERROR-FREE OPERATION; AND

(g) PARTICULAR RESULTS.

Nothing in these Terms excludes a warranty or liability that cannot lawfully be excluded.


PART XIII — INDEMNITIES

46. CUSTOMER INDEMNITY

Subject to Section 50, Customer will defend Kestrel and its officers, directors and employees against a third-party claim to the extent arising from:

(a) Customer Content allegedly violating intellectual-property, privacy, publicity or confidentiality rights;

(b) Customer’s unlawful AI system or deployment;

(c) Customer’s material violation of the AUP;

(d) Customer’s use of Kestrel in an expressly prohibited regulated use;

(e) Customer’s fraud or wilful misconduct;

(f) Customer’s unauthorised use of another person’s credentials or data;

(g) Customer’s tools, datasets, products or services; or

(h) Customer instructions that Kestrel executes as authorised and that create the claimed violation.

The indemnity applies only to the extent the claim is attributable to Customer and not Kestrel’s own breach, negligence or misconduct.


47. KESTREL INTELLECTUAL-PROPERTY INDEMNITY

Kestrel will defend Customer against a third-party claim alleging that the unmodified paid Service, when used by Customer as authorised, directly infringes that third party’s copyright, patent or registered trademark, and will pay damages finally awarded against Customer or settlement amounts approved by Kestrel.

This indemnity does not apply to a claim resulting from:

(a) Customer Content;

(b) Customer modification;

(c) use contrary to Documentation;

(d) combination with items not supplied by Kestrel where the combination causes the infringement;

(e) continued use after Kestrel gives notice to stop;

(f) an unsupported or obsolete version where a non-infringing replacement was made available; or

(g) compliance with Customer-specific designs or instructions.


48. IP REMEDIES

If the Service becomes, or Kestrel reasonably believes it is likely to become, subject to an infringement claim, Kestrel may:

(a) procure continued rights;

(b) modify the Service;

(c) replace affected functionality with substantially equivalent functionality; or

(d) terminate the affected Service and refund prepaid unused Fees for the terminated period.

This Section states Customer’s exclusive contractual remedy for third-party intellectual-property infringement claims relating to the Service, except where Applicable Law prohibits such limitation.


49. INDEMNITY PROCEDURE

An indemnified party must:

(a) provide reasonably prompt notice of the claim;

(b) provide reasonable cooperation at the indemnifying party’s expense; and

(c) permit the indemnifying party to control defence and settlement.

Delay in notice reduces obligations only to the extent the delay materially prejudices the defence.

The indemnifying party may not settle a claim in a manner that:

(a) admits wrongdoing by the indemnified party;

(b) imposes non-monetary obligations on the indemnified party;

(c) materially restricts the indemnified party’s business; or

(d) requires payment by the indemnified party,

without prior written consent, not to be unreasonably withheld.


PART XIV — LIMITATION OF LIABILITY

50. LIABILITY FRAMEWORK

THE PARTIES AGREE THAT THE LIMITATIONS IN THIS PART ALLOCATE COMMERCIAL RISK BETWEEN SOPHISTICATED BUSINESS PARTIES AND ARE REFLECTED IN THE FEES CHARGED.

THE LIMITATIONS APPLY ONLY TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW.


51. EXCLUDED LOSSES

Subject to Section 54, neither party is liable to the other for:

(a) indirect loss;

(b) consequential loss;

(c) incidental loss;

(d) special loss;

(e) exemplary or punitive damages;

(f) loss of anticipated profit;

(g) loss of anticipated revenue;

(h) loss of anticipated savings;

(i) loss of goodwill;

(j) loss of business opportunity;

(k) loss of anticipated contracts; or

(l) indirect business interruption,

to the extent such categories are legally excludable and are not direct losses recoverable notwithstanding their label.


52. ORDINARY AGGREGATE LIABILITY CAP

Subject to Sections 53 and 54, each party’s aggregate liability arising out of or relating to an affected Order Form will not exceed:

For a Production or Enterprise subscription:

the Fees paid or payable to Kestrel under the affected Order Form during the twelve (12) months immediately preceding the event giving rise to liability.

For a claim arising during the first twelve months, the cap will be the Fees paid and contractually payable under the affected Order Form through the first anniversary of its Effective Date.

For a Pilot:

the greater of:

(a) all Fees paid or payable for that Pilot; and

(b) USD 5,000.


53. SUPER-CAP

Subject to Section 54, aggregate liability for:

(a) breach of confidentiality obligations;

(b) Kestrel’s IP indemnity;

(c) material breach of the DPA; and

(d) a Security Incident caused by a material breach of Kestrel’s expressly agreed security obligations,

will not exceed two (2) times the applicable ordinary liability cap in Section 52.


54. LIABILITY NOT LIMITED BY THE CONTRACTUAL CAPS

Nothing in the Agreement excludes or limits liability to the extent such exclusion or limitation is prohibited by Applicable Law.

Without limiting that principle, the contractual caps do not limit:

(a) Customer’s obligation to pay properly due Fees;

(b) either party’s fraud or fraudulent misrepresentation;

(c) death or personal injury caused by negligence to the extent liability cannot lawfully be excluded;

(d) deliberate infringement or misappropriation of the other party’s intellectual property;

(e) wilful misconduct where exclusion would be unlawful; or

(f) any other liability that Applicable Law prohibits the parties from limiting.


55. REGULATORY FINES

Neither party assumes responsibility for fines, penalties or enforcement measures imposed because of the other party’s independent legal violation.

Where a fine results from conduct attributable to both parties, responsibility will be allocated according to their respective responsibility to the extent permitted by Applicable Law.


56. THIRD-PARTY AND CUSTOMER-CONTROLLED EVENTS

In determining Kestrel’s liability, Kestrel is not responsible for loss caused solely by:

(a) Customer Systems;

(b) bypassed traffic;

(c) Customer’s configuration;

(d) Customer overrides;

(e) Customer credentials compromised outside Kestrel;

(f) unsupported integrations;

(g) Customer-selected Model Provider behaviour;

(h) Customer instructions; or

(i) events otherwise outside Kestrel’s reasonable control.

This Section does not excuse Kestrel from its own contractual breach merely because a third party was involved.


57. DUTY TO MITIGATE

Each party must take reasonable steps to mitigate recoverable loss.


58. CLAIM PERIOD

Except for claims involving fraud, deliberate concealment, unpaid Fees, intellectual-property ownership or another matter for which Applicable Law does not permit contractual shortening, a party should provide written notice of a contractual claim promptly after becoming aware of it.

Nothing in this Section eliminates a claim solely because preliminary notice was delayed unless the delay materially prejudices the responding party or a valid limitation period has expired.


59. NO PERSONAL LIABILITY

To the maximum extent permitted by law, no Kestrel director, officer, employee, shareholder, contractor or agent incurs personal contractual liability to Customer solely because that person performed obligations on Kestrel’s behalf.


PART XV — SUSPENSION

60. SUSPENSION RIGHTS

Kestrel may suspend affected access where reasonably necessary because of:

(a) credible security risk;

(b) unauthorised access;

(c) material AUP violation;

(d) legal prohibition;

(e) sanctions restrictions;

(f) material risk to other customers or infrastructure;

(g) repeated abuse;

(h) materially overdue undisputed payment;

(i) provider restriction; or

(j) imminent risk of material harm.


61. EMERGENCY SUSPENSION

Where delay would create material security, legal or operational risk, Kestrel may suspend immediately.

Kestrel will provide notice as soon as reasonably practicable where legally permitted.


62. PROPORTIONALITY

Where reasonably practicable, Kestrel will limit suspension to the affected Account, credential, integration, function or traffic rather than suspending unrelated Services.


63. RESTORATION

Kestrel will restore suspended access after the underlying issue is reasonably remedied, subject to continuing legal or security restrictions.


PART XVI — TERM AND TERMINATION

64. TERM

These Terms begin on the Effective Date and continue until all applicable subscriptions have expired or been terminated.


65. SUBSCRIPTION TERMS

Subscription terms are determined by:

(a) Schedule 1;

(b) Schedule 3;

(c) Schedule 4; and

(d) an applicable Order Form.

An Order Form controls where it expressly provides different terms.


66. TERMINATION FOR MATERIAL BREACH

Either party may terminate an affected Order Form if the other party materially breaches the Agreement and fails to cure the breach within thirty (30) days after written notice describing the breach.


67. IMMEDIATE TERMINATION

A party may terminate immediately where:

(a) a material breach is incapable of cure;

(b) the other party commits fraud materially affecting the Agreement;

(c) continued performance becomes unlawful;

(d) the other party commits severe intentional security abuse;

(e) continued use would violate sanctions or export restrictions; or

(f) termination is otherwise expressly permitted by the Agreement.


68. INSOLVENCY

To the extent permitted by Applicable Law, either party may terminate where the other:

(a) ceases substantially all business;

(b) enters liquidation other than a solvent restructuring;

(c) becomes subject to a winding-up order; or

(d) enters an equivalent insolvency proceeding that is not dismissed within a reasonable period.


69. TERMINATION FOR CONVENIENCE

Month-to-Month Production

If Schedule 1 establishes month-to-month Production subscriptions, Customer may prevent renewal by cancelling in accordance with the specified cancellation process.

Committed Terms

A committed Order Form is not terminable for convenience unless that Order Form expressly permits it.

Kestrel

Kestrel may elect not to renew a subscription by providing reasonable advance notice.

Kestrel will not terminate a fully prepaid committed subscription for convenience mid-term merely to charge Customer a higher price.


70. EFFECT OF TERMINATION

Upon termination:

(a) Customer’s right to access the terminated Service ends;

(b) accrued payment obligations remain due;

(c) Kestrel may issue a final usage invoice;

(d) Customer must cease using Kestrel Technology except as expressly permitted;

(e) Customer may export available Customer Data during the period stated in Schedule 1;

(f) Kestrel may subsequently delete Customer Data in accordance with the DPA and retention architecture; and

(g) provisions intended by their nature to survive remain effective.


71. SURVIVAL

Without limitation, provisions concerning:

(a) Fees;

(b) confidentiality;

(c) intellectual property;

(d) Feedback;

(e) indemnities;

(f) liability;

(g) dispute resolution;

(h) data retained pursuant to law;

(i) audit evidence; and

(j) interpretation

survive to the extent necessary to give them effect.


PART XVII — TERRITORIAL, REGULATORY AND LEGAL COMPLIANCE

72. GENERAL COMPLIANCE

Each party must comply with Applicable Law governing its own performance.

Customer is responsible for laws governing Customer’s:

(a) AI deployment;

(b) business sector;

(c) models;

(d) end users;

(e) regulated decisions;

(f) datasets;

(g) notices;

(h) licences;

(i) human-review processes; and

(j) records.


73. NO REGULATORY GUARANTEE

Purchase or use of Kestrel does not mean that:

(a) Customer is compliant with any AI law;

(b) Customer satisfies a regulator;

(c) Customer has completed a legally required risk assessment;

(d) Customer has satisfied cybersecurity obligations;

(e) a Kestrel control satisfies a mandatory industry control; or

(f) Kestrel has certified Customer’s compliance.

Any such commitment must be expressly stated in a signed Order Form or regulatory addendum.


74. EUROPEAN UNION AND EUROPEAN ECONOMIC AREA

Kestrel is not currently available for deployment within the European Union or European Economic Area as we continue our work toward supporting applicable requirements under the EU Artificial Intelligence Act. EU and EEA availability will be introduced once the necessary compliance requirements have been addressed.

Customer must not deploy the Service contrary to the territorial restriction described in Schedule 1.

Customer must promptly notify Kestrel if its proposed deployment location changes in a manner that may make the restriction applicable.

This restriction does not represent that no European law could ever apply to activity occurring outside the EU or EEA.

In particular, nothing in these Terms should be interpreted as stating that the EU Artificial Intelligence Act, GDPR or any other European legislation can never have extraterritorial effect.


75. SANCTIONS AND EXPORT CONTROLS

Customer must not access, export, re-export, transfer or use the Service in violation of applicable sanctions, export-control or strategic-goods laws.

Customer represents that it will not knowingly use the Service:

(a) on behalf of a prohibited or restricted person where unlawful;

(b) for a prohibited end use;

(c) in violation of applicable embargo restrictions; or

(d) to transfer controlled technology unlawfully.

Kestrel may conduct reasonable compliance screening and request information reasonably necessary to assess legal restrictions.


76. ANTI-BRIBERY AND CORRUPTION

Each party must comply with anti-bribery and anti-corruption laws applicable to its conduct relating to the Agreement.

No party may offer or accept an improper payment on behalf of the other.


PART XVIII — AUDIT AND VERIFICATION

77. USAGE VERIFICATION

Kestrel may use its service records to verify:

(a) usage limits;

(b) Account scope;

(c) licensing;

(d) territorial restrictions;

(e) request volumes; and

(f) AUP compliance.

Kestrel will not use this Section as a general right to inspect unrelated Customer Systems.


78. CUSTOMER SECURITY REVIEWS

Where Customer reasonably requires information concerning Kestrel security or privacy, Kestrel may initially satisfy the request through:

(a) security documentation;

(b) questionnaires;

(c) available audit reports;

(d) certifications;

(e) penetration-test summaries; or

(f) other reasonable evidence.

Any additional audit rights are governed by the DPA, Security Addendum or Order Form.

Audits must not unreasonably interfere with Kestrel operations or compromise other customers’ confidentiality or security.


PART XIX — PUBLICITY

Kestrel will not publicly identify Customer as a Kestrel customer or use Customer’s trademarks for promotional purposes without prior written consent.

An Order Form may grant specific publicity rights.


80. ANONYMISED STATISTICS

Kestrel may publish aggregate statistics that do not reasonably identify Customer or disclose Customer Confidential Information.


PART XX — WEBSITE AND MARKETING MATERIALS

81. ILLUSTRATIVE CONTENT

Website screenshots, simplified UI, example metrics, animations, diagrams and mock-ups may be illustrative.

They do not necessarily represent the exact interface, configuration or functionality available to every Customer.


82. PRODUCT DESCRIPTION

The applicable Order Form and current Documentation determine the Service purchased.

Marketing materials do not constitute a guarantee that:

(a) every depicted feature is available;

(b) every integration is supported;

(c) every feature works identically for every architecture; or

(d) unreleased functionality will be delivered.


83. WEBSITE INFORMATION

Kestrel attempts to maintain accurate Website information but may correct errors and update descriptions.

Website pricing is subject to an executed Order Form and prospective pricing changes.


PART XXI — DISPUTE RESOLUTION

84. GOOD-FAITH ESCALATION

Before commencing ordinary arbitration proceedings, a party must provide written notice describing the dispute.

The parties will attempt in good faith to resolve the dispute through representatives with settlement authority for at least thirty (30) days.

This requirement does not prevent a party from seeking urgent interim, injunctive or protective relief.


85. GOVERNING LAW

The Agreement and any non-contractual obligations arising out of or relating to it are governed by the laws of the Republic of Singapore, without regard to conflict-of-law principles that would require application of another jurisdiction’s laws.


86. SIAC ARBITRATION

Any dispute, controversy or claim arising out of or relating to the Agreement, including any question concerning its existence, validity, interpretation, performance, breach or termination, that is not resolved under Section 84 will be finally resolved by arbitration administered by the Singapore International Arbitration Centre (“SIAC”) in accordance with the SIAC Rules in force when the arbitration is commenced, which Rules are deemed incorporated into this Section.

The seat of arbitration is Singapore.

The language of arbitration is English.

Unless the parties agree otherwise:

(a) disputes with an amount in controversy below USD 5,000,000 will be determined by one arbitrator; and

(b) disputes with an amount in controversy of USD 5,000,000 or more will be determined by three arbitrators,

subject to any mandatory or applicable power under the SIAC Rules concerning tribunal constitution.

The parties may use any streamlined, expedited, emergency or other procedure available under the applicable SIAC Rules where its requirements are satisfied.


87. INTERIM RELIEF

Nothing prevents a party from seeking urgent interim, conservatory or injunctive relief from:

(a) an emergency arbitrator;

(b) the arbitral tribunal; or

(c) a court of competent jurisdiction,

where necessary to protect confidentiality, intellectual property, security, access credentials, evidence or other rights pending arbitration.

Seeking such relief does not waive arbitration.


88. CONFIDENTIALITY OF DISPUTES

To the extent permitted by law and applicable SIAC Rules, the parties will maintain the confidentiality of arbitration proceedings, evidence and awards except where disclosure is reasonably necessary for:

(a) enforcement;

(b) legal obligations;

(c) regulators;

(d) insurers;

(e) auditors;

(f) professional advisers; or

(g) protection of legal rights.


PART XXII — GENERAL

89. INDEPENDENT CONTRACTORS

The parties are independent contractors.

Nothing creates:

(a) a partnership;

(b) joint venture;

(c) fiduciary relationship;

(d) employment relationship;

(e) franchise; or

(f) agency,

except where expressly agreed in writing.

Neither party may bind the other without authority.


90. ASSIGNMENT

Customer may not assign the Agreement without Kestrel’s prior written consent, not to be unreasonably withheld in connection with a bona fide corporate reorganisation that does not materially increase Kestrel’s risk.

Kestrel may assign the Agreement:

(a) to an Affiliate; or

(b) in connection with a merger, reorganisation, sale of substantially all relevant assets or change of control,

provided the assignee assumes applicable contractual obligations.

Neither party may assign the Agreement to a direct competitor of the other in a manner reasonably likely to compromise Confidential Information without consent.


91. SUBCONTRACTORS

Kestrel may use contractors and subcontractors to perform the Service.

Kestrel remains responsible for contractual obligations to the extent stated in the Agreement.

Processing of personal data by Subprocessors remains subject to the DPA.


92. FORCE MAJEURE

Neither party is liable for delay or failure caused by circumstances beyond its reasonable control, including:

(a) natural disaster;

(b) fire;

(c) flood;

(d) epidemic;

(e) war;

(f) terrorism;

(g) civil disorder;

(h) governmental action;

(i) widespread internet failure;

(j) electrical-grid failure;

(k) telecommunications failure;

(l) labour disruption not limited to the affected party’s own workforce;

(m) major cloud infrastructure failure;

(n) widespread third-party provider failure; or

(o) comparable events beyond reasonable control.

The affected party must use commercially reasonable efforts to mitigate the impact.

Force majeure does not excuse Customer’s obligation to pay Fees already accrued for Services received.

If a force-majeure event materially prevents performance for more than sixty (60) consecutive days, either party may terminate the materially affected Service.


93. NOTICES

Legal notices must be sent to the notice details specified in Schedule 1 and, for Customer, to the address or email stated in the applicable Order Form.

Notices concerning ordinary Service operations may be provided:

(a) by email;

(b) through the Platform;

(c) through administrative notifications; or

(d) through documented support channels.

A legal notice is deemed received when delivery is confirmed electronically or, for physical delivery, when delivered according to recognised courier records, subject to Applicable Law.


94. CHANGES TO THESE TERMS

Kestrel may update these Terms prospectively.

For material adverse changes affecting an existing paid subscription, Kestrel will provide reasonable notice before the change becomes effective.

Kestrel will publish an updated version on the Website and, where a change is material, will also provide notice by email or through the authenticated Platform dashboard.

A unilateral online update will not retroactively modify a negotiated Order Form or separately executed amendment.

If Customer continues a renewable subscription after properly notified revised Terms become effective, the revised Terms may govern the renewed period.


95. ENTIRE AGREEMENT

The Agreement constitutes the entire agreement between the parties concerning its subject matter and supersedes prior proposals, representations and communications concerning that subject matter.

Nothing in this Section excludes liability for fraud or fraudulent misrepresentation or another representation that Applicable Law prohibits the parties from excluding.


96. WAIVER

Failure to enforce a provision is not a waiver.

A waiver must be specific and does not waive future rights unless expressly stated.


97. SEVERABILITY

If a provision is held invalid or unenforceable, it will be enforced to the maximum extent lawfully possible and, where appropriate, modified only to the minimum extent required to make it enforceable.

The remaining provisions remain effective.


98. THIRD-PARTY RIGHTS

Except as expressly stated in relation to Kestrel indemnified parties or permitted successors, a person who is not a party to the Agreement has no right under the Contracts (Rights of Third Parties) Act 2001 to enforce a term of the Agreement.

The parties may amend or terminate the Agreement without obtaining consent from any third party unless Applicable Law or an expressly granted third-party right requires otherwise.


99. COUNTERPARTS AND ELECTRONIC SIGNATURES

Order Forms and amendments may be executed in counterparts and using electronic signatures.

Each counterpart forms part of the same instrument.


100. FURTHER ASSURANCES

Each party will execute documents and perform reasonable acts necessary to give effect to expressly agreed rights and obligations.


101. LANGUAGE

The controlling language of the Agreement is English.

Any translation is provided for convenience unless expressly agreed otherwise.


102. NO EXCLUSIVITY

Nothing creates exclusivity or a most-favoured-customer obligation unless expressly stated in an executed Order Form.


103. NO ROADMAP COMMITMENT

Kestrel has no obligation to develop or release future functionality merely because it was discussed, demonstrated or included in a roadmap.


104. PROCUREMENT TERMS

Customer procurement portals, purchase orders, vendor forms or policies do not modify the Agreement solely because Kestrel interacts with, uploads information to or acknowledges them.

Additional terms bind Kestrel only where expressly accepted in writing by an authorised Kestrel representative.


SCHEDULE 2

ACCEPTABLE USE POLICY

This Acceptable Use Policy forms part of the Agreement.

Customer must not, and must not permit any person to, use the Service:

1. Illegal Activity

for illegal, fraudulent, deceptive or rights-infringing activity;

2. Unauthorised Access

to gain or attempt to gain unauthorised access to:

  • accounts;
  • systems;
  • credentials;
  • networks;
  • tenants;
  • data;
  • devices; or
  • services;

3. Malicious Code

to create, distribute, deploy or operate malware, ransomware, credential theft, destructive payloads or comparable malicious code, except authorised defensive-security testing expressly approved by Kestrel;

4. Circumvention

to bypass, disable, evade or defeat:

  • authentication;
  • rate limits;
  • tenant isolation;
  • policy controls;
  • evidence mechanisms;
  • billing controls;
  • usage limits; or
  • security protections;

5. Disruption

to conduct denial-of-service activity, excessive automated access, resource exhaustion or other activity intended to materially disrupt the Service;

6. Unauthorised Testing

to conduct penetration testing, vulnerability scanning or exploit testing against Kestrel infrastructure without prior written authorisation;

7. Credential Sharing

to disclose credentials or access to unauthorised persons;

8. Unlawful Data

to provide data Customer lacks legal authority to process or disclose;

9. Exploitation and Abuse

for child sexual abuse material, human trafficking, terrorist activity or other serious unlawful exploitation;

10. Credential Harvesting

for unlawful phishing, credential harvesting, impersonation or account theft;

11. Unlawful Surveillance

for unlawful interception, stalking or surveillance;

12. Discriminatory Decisions

to facilitate unlawful discrimination or unlawful automated decision-making;

13. Deceptive Impersonation

to impersonate another person unlawfully or deceive persons concerning material identity or authority;

14. Restricted Territories

in violation of Section 74 or applicable sanctions or export restrictions;

15. Intellectual Property Abuse

to materially infringe or misappropriate third-party intellectual property;

16. Competitive Extraction

to systematically copy non-public Kestrel functionality for the principal purpose of building a competing product in violation of the Agreement;

17. Benchmark Publication

to intentionally publish materially misleading non-public security or performance results without giving Kestrel a reasonable opportunity to verify disputed technical facts;

18. Highly Sensitive Data

to process categories of extremely sensitive data expressly prohibited by an applicable Order Form, Documentation or DPA.


AUP ENFORCEMENT

Where Kestrel reasonably believes a violation has occurred, Kestrel may:

(a) investigate;

(b) request information;

(c) require remediation;

(d) impose proportionate technical controls;

(e) suspend affected access; or

(f) terminate for serious or repeated violations.

Kestrel will provide notice and an opportunity to respond where practicable.

Immediate action may be taken where Kestrel reasonably believes delay would create significant legal, security, infrastructure or human-safety risk.

Customer may contact Kestrel through the legal or support contact in Schedule 1 to dispute an enforcement decision.


SCHEDULE 3

COMMERCIAL PLAN TERMS

1. PILOT

Platform Fee

USD 500 per month.

Included Usage

100,000 Requests per monthly billing period.

Maximum Usage

100,000 Requests per monthly billing period.

Pilot usage does not continue automatically beyond the stated cap unless Kestrel expressly authorises additional capacity in writing.

Maximum Term

Three months.

Purpose

Evaluation, validation and limited real-environment testing.

SLA

No contractual SLA unless expressly stated in the applicable Order Form.

Conversion

A Pilot does not automatically convert into Production unless Customer affirmatively purchases or accepts a Production subscription.


2. PRODUCTION

Platform Fee

USD 2,500 per month.

Included Requests

The first 1,000,000 Requests per monthly billing period.

Usage

1,000,001 through 10,000,000 Requests:
USD 1.00 per 1,000 additional Requests.

Above 10,000,000:
USD 0.60 per 1,000 additional Requests.

Kestrel may contact Customer to establish Enterprise Volume pricing where usage materially exceeds standard Production bands.


3. ENTERPRISE VOLUME

Enterprise Volume terms are individually contracted.

They may include:

(a) committed volume;

(b) annual Fees;

(c) minimum spend;

(d) custom usage tiers;

(e) true-ups;

(f) support commitments;

(g) SLA;

(h) security terms;

(i) professional services;

(j) implementation terms; and

(k) other enterprise-specific requirements.

The applicable Order Form controls.


4. FEATURE AVAILABILITY

Where Kestrel publicly states that platform capabilities are included in a plan, that statement means Customer is not intentionally required to purchase another feature tier merely to unlock generally released core capabilities unless clearly disclosed.

However, functionality remains subject to:

(a) technical availability;

(b) supported integrations;

(c) customer configuration;

(d) release status;

(e) Documentation;

(f) capacity;

(g) lawful territorial availability;

(h) technical prerequisites; and

(i) the applicable Order Form.

“Included” does not mean every capability is technically compatible with every Customer architecture.


SCHEDULE 4

PILOT AND EVALUATION TERMS

These terms supplement the Agreement for a Pilot.

1. Evaluation Purpose

Pilot subscriptions are designed to allow Customer to evaluate Kestrel before broader production adoption.

2. Three-Month Maximum

A standard Pilot may not exceed three months unless Kestrel expressly agrees otherwise in writing.

3. Request Cap

Pilot usage is capped at 100,000 Requests per monthly billing period.

4. Cap Behaviour

Once the applicable cap is reached, Kestrel may:

(a) stop accepting additional Pilot Requests;

(b) require Customer to wait for the next billing period;

(c) offer migration to Production; or

(d) agree to another arrangement in writing.

Kestrel is not required to permit overage usage at Pilot pricing.

5. Critical Operations

Unless an Order Form expressly states otherwise, Customer must not rely on a Pilot as the sole control protecting safety-critical, mission-critical or legally required functions.

6. Live Data

Live production data may be processed only in accordance with Schedule 1 and any applicable DPA.

7. No SLA

A Pilot has no contractual uptime SLA unless expressly stated otherwise.

8. Support

Pilot support may be more limited than support available under a negotiated Production or Enterprise arrangement.

9. Evaluation Results

Customer is responsible for evaluating whether Kestrel is appropriate for Customer’s proposed deployment.

Successful Pilot results do not guarantee identical performance under different:

(a) traffic volumes;

(b) models;

(c) configurations;

(d) datasets;

(e) infrastructure;

(f) attack patterns; or

(g) production conditions.

10. End of Pilot

At Pilot expiry, Customer must:

(a) purchase an applicable Production or Enterprise subscription;

(b) enter another written arrangement with Kestrel; or

(c) cease use.

There is no automatic paid conversion unless Customer affirmatively accepts it.


SCHEDULE 5

AI AND RUNTIME CONTROL PRODUCT TERMS

1. Control-Point Dependency

Kestrel governs only traffic and actions reaching supported Kestrel control points.

2. Model Provider Independence

Kestrel does not control independent Model Provider behaviour.

3. Security Detection

Threat detection is probabilistic and may produce false positives and false negatives.

4. Policy Enforcement

Customer is responsible for policy design and approval.

5. Personal-Data Detection

PII detection and redaction reduce risk but cannot guarantee complete removal of sensitive data.

6. Multi-Turn Analysis

Risk accumulated across a session may depend on session continuity and availability of required context.

7. Tool Actions

Kestrel may evaluate proposed Tool Actions but cannot control actions performed outside supported control points.

8. Evidence

Cryptographic records establish only the technical properties actually verified by the applicable mechanism.

9. Shadow Mode

Shadow-mode or simulation results do not themselves enforce policy unless enforcement is enabled.

10. Assurance

Assurance scores, indicators, findings and recommendations are decision-support information and are not certifications of legal compliance.

11. Inventory and Governance Records

Customer is responsible for ensuring inventory, ownership, classification and lifecycle information supplied to Kestrel remains materially accurate.

12. Customer Overrides

Where Customer overrides, bypasses, disables or weakens a control, Customer accepts responsibility for the consequences of that decision except to the extent caused independently by Kestrel’s breach.


SCHEDULE 6

WEBSITE USE TERMS

The following provisions apply to use of Kestrel’s public Website before a subscription is established.

1. Informational Purpose

Website content is provided for general business information and does not itself constitute a binding offer to provide a particular Service.

2. No Reliance on Roadmaps

Future features and timelines are not contractual commitments.

3. Website Intellectual Property

Website text, graphics, software, designs, trademarks and other proprietary materials are owned by or licensed to Kestrel.

Visitors may view them for legitimate informational and business-evaluation purposes.

4. Prohibited Website Conduct

Visitors must not:

(a) attack the Website;

(b) attempt unauthorised access;

(c) distribute malicious code;

(d) scrape the Website at a rate that materially burdens infrastructure;

(e) evade technical restrictions;

(f) reproduce substantial proprietary content for competing commercial use; or

(g) misrepresent an affiliation with Kestrel.

External links may be provided for convenience.

Kestrel does not control third-party websites merely because it links to them.

6. Privacy

Website personal-data processing is governed by Kestrel’s Privacy Policy and applicable Cookie Policy.

7. Website Availability

Kestrel does not guarantee uninterrupted public Website availability.

8. Enterprise Agreements Control

These Website provisions do not override an executed enterprise Order Form, DPA, MSA or negotiated amendment.


ACKNOWLEDGEMENT

BY ACCEPTING THESE TERMS ON BEHALF OF CUSTOMER, THE ACCEPTING PERSON REPRESENTS THAT:

  1. CUSTOMER IS ENTERING INTO A BUSINESS-TO-BUSINESS AGREEMENT;
  2. THE ACCEPTING PERSON HAS AUTHORITY TO BIND CUSTOMER;
  3. CUSTOMER HAS REVIEWED THESE TERMS;
  4. CUSTOMER UNDERSTANDS THAT AI AND SECURITY CONTROLS ARE NOT INFALLIBLE;
  5. CUSTOMER RETAINS RESPONSIBILITY FOR ITS AI SYSTEMS AND LEGAL OBLIGATIONS; AND
  6. CUSTOMER AGREES TO THE GOVERNING LAW AND DISPUTE-RESOLUTION PROVISIONS ABOVE.

KESTREL ADVANCED SYSTEMS PTE. LTD.

Blk 31, #01-16C
535 Clementi Road
Singapore 599489

Website: kestreladvanced.com

General enquiries: contact@kestreladvanced.com

Legal notices: legal@kestreladvanced.com

Privacy and data-protection enquiries: privacy@kestreladvanced.com

© 2026 Kestrel Advanced Systems Pte. Ltd. All rights reserved.