Superagent Technologies, Inc.
Last updated: 8/31/2026
This Services Agreement (the "Agreement") is between Superagent Technologies, Inc., a Delaware corporation with offices at 1111B S Governors Ave, Suite 3232, Dover, Delaware 19904 ("Superagent," "Company," "we," "us," or "our"), and the person or entity accepting this Agreement ("Customer," "you," or "your").
By creating an account, selecting a plan, placing an Order, or clicking an acceptance checkbox or similar control that references this Agreement, you accept it on behalf of Customer and represent that you have authority to bind Customer. If you do not agree, do not use the Services.
1. Definitions
"Access Protocols" means passwords, API keys, access codes, authentication tokens, connectivity standards, and other procedures used to access the Services.
"Aggregated Data" means data relating to Customer's use of the Services that has been aggregated and deidentified so that it does not identify Customer or an individual.
"Agreement" means this Services Agreement, the applicable Order, the Global Data Processing Addendum, and documents expressly incorporated by reference.
"Authorized User" means Customer's employee, contractor, or other individual whom Customer authorizes to use the Services on its behalf.
"Connected Account" means a third-party platform, repository, website, service, or account connected to or accessed by the Services at Customer's direction.
"Connected Account Data" means data collected from, submitted to, or made available by a Connected Account.
"Credits" means usage units allocated under an Order and consumed at the rate displayed to Customer for a metered Service.
"Customer Data" means Connected Account Data, Inputs, and other content, information, or data that Customer or an Authorized User submits, transmits, makes available, or authorizes Company to access through the Services. Customer Data does not include Aggregated Data.
"Documentation" means Company-provided documentation relating to the Services, including our public product documentation.
"Input" means information, code, repository content, files, prompts, targets, credentials authorized for testing, rules, configurations, and other material submitted, collected, or made available for processing through the Services.
"Order" means the online checkout, plan-selection screen, account plan record, order form, or other ordering document that identifies Customer's plan, billing period, Credit allocation, price, or other commercial terms. An Order becomes binding when Customer accepts it electronically or signs it.
"Output" means content, findings, scores, decisions, reports, signatures, records, recommendations, patches, or other material generated by or for Customer through the Services.
"Personal Data" means Customer Data that is personal data, personal information, personally identifiable information, or a similar regulated category under applicable data-protection law.
"Platform" means Superagent's hosted application, APIs, MCP server, webhook functionality, endpoint software, integrations, and related technology used to provide the Services.
"Products" means PR Scans, Contributor Trust, Agreements, Runtime Guardrails, Context Guardrails, Red Team, and any related or successor functionality included in Customer's plan.
"Services" means the Platform, Products, Documentation, support, and other services provided under an Order.
2. Provision of Services
2.1 Orders
Each Order is governed by this Agreement. If an Order expressly identifies a provision of this Agreement that it supersedes, the Order controls for that provision; otherwise, this Agreement controls. Prices, Credit allocations, rate cards, billing periods, and plan features presented during checkout or plan selection form part of the Order.
2.2 Access to the Platform
Subject to Customer's payment of fees and compliance with this Agreement, Company grants Customer a non-exclusive, non-transferable right during the applicable Order term to permit Authorized Users to access and use the Services for Customer's internal business purposes in accordance with the Documentation.
All generally available plans include access to all Products, APIs, MCP access, and unlimited Authorized Users, subject to the usage allocation, technical limits, and other terms of the applicable Order. Public-repository usage identified as free in an Order does not consume paid private-use Credits unless stated otherwise. Runtime Guardrails is included without Credit charges; other metered Products consume Credits according to the rate card displayed in the applicable Order.
2.3 Products
Depending on Customer's configuration, the Services may:
- review pull requests, repository contents, dependencies, and contributor activity and publish findings or proposed fixes;
- analyze public contribution history and related signals to produce contributor trust results;
- create, manage, version, sign, and enforce contributor agreements, including through an electronic-signature provider;
- evaluate endpoint events against Customer rules and transmit health, finding, decision, and enforcement records to the Platform;
- analyze web pages, email, files, agent skills, public repositories, registry packages, and other context before consumption;
- conduct authorized adversarial assessments of repositories, web applications, deployed agents, model endpoints, and packages in isolated environments; and
- store, display, deliver, and integrate associated Outputs through the Platform, GitHub, APIs, MCP, or webhooks.
Customer acknowledges that Runtime Guardrails may evaluate rules locally but uploads and stores finding, decision, enforcement, and health records. The amount and content transmitted depend on Customer's rules, endpoint configuration, and events.
2.4 Connected Accounts
Some features require access to Connected Accounts. By connecting or authorizing access to a Connected Account, Customer represents that it has authority to provide credentials, install applications, grant permissions, and permit Company to process Connected Account Data.
Availability and operation of a Connected Account are controlled by its provider. Company is not responsible for a third party's modification, suspension, or termination of a Connected Account.
2.5 Third-party services
The Services may use third-party infrastructure and services, including cloud hosting, databases, authentication, GitHub, electronic signatures, billing, communications, AI inference, analytics, error monitoring, and isolated compute. Providers that may process Customer Data are listed on our Subprocessor List.
Customer-directed integrations and destinations, such as Customer's GitHub organization or webhook endpoint, are under Customer's control. Their separate terms apply.
2.6 Support and changes
Company provides support at support@superagent.sh on a commercially reasonable basis unless an Order states otherwise.
Company may update the Services to improve security, functionality, performance, or compliance. Company will not materially reduce the core functionality of a paid Service during a prepaid term without providing a substantially equivalent replacement or a reasonable remedy.
2.7 Data processing
The Global Data Processing Addendum applies when Company processes Personal Data on Customer's behalf and is incorporated into this Agreement.
Customer must not intentionally submit protected health information, payment card data, biometric data, government-issued identification numbers, children's data, production financial-account credentials, or other regulated sensitive data unless the parties expressly agree in writing and implement required safeguards.
Customer may provide test credentials and other test data specifically authorized for an assessment, provided they do not grant access to systems or information outside the agreed testing scope.
3. Customer restrictions and responsibilities
3.1 Restrictions
Customer will not, and will not permit another person to:
- access or use the Services except as authorized by this Agreement;
- sell, sublicense, rent, lease, or distribute the Services as a standalone product;
- reverse engineer, decompile, disassemble, or attempt to derive source code or non-public model parameters, except to the extent a restriction is prohibited by law;
- bypass usage, authentication, rate, safety, or access controls;
- interfere with or disrupt the integrity, security, or availability of the Services;
- use the Services to violate law, infringe rights, distribute malware, conduct unauthorized surveillance, or attack systems without authorization;
- submit data Customer does not have the right to process or authorize Company to process;
- use Outputs as the sole basis for decisions that produce legal or similarly significant effects on an individual; or
- use the Services or Outputs to represent that an automated security result is a guarantee of security, compliance, or absence of vulnerabilities.
3.2 Authorized assessments
Customer may use Red Team and other testing features only against systems, accounts, repositories, applications, agents, endpoints, and packages that Customer owns or is expressly authorized to test. Customer is responsible for defining scope, obtaining permission, maintaining backups, and avoiding material disruption to third parties.
Company may suspend an assessment that appears unauthorized, unlawful, unsafe, or outside documented scope.
3.3 Authorized Users and credentials
Customer is responsible for Authorized Users and activity under its accounts, API keys, and Access Protocols. Customer will use reasonable safeguards, prevent unauthorized access, promptly revoke access that is no longer required, and notify Company of suspected compromise.
3.4 Customer Data and compliance
Customer is responsible for the accuracy, quality, legality, and collection of Customer Data and for providing required notices and obtaining required rights, permissions, and consents.
Customer will configure the Services appropriately for its risk and legal obligations, review Outputs before acting on them, and comply with applicable laws and third-party terms.
4. Ownership and data rights
4.1 Company technology
Company and its licensors own the Services, Platform, Documentation, underlying software, methods, workflows, templates, and related intellectual-property rights. Except for the access right in Section 2.2, no rights are transferred to Customer. Open-source components remain governed by their licenses.
4.2 Customer Data and Outputs
As between the parties, Customer retains all rights in Customer Data. Subject to third-party rights and applicable law, Customer owns Outputs generated specifically for Customer.
Customer grants Company a non-exclusive, worldwide right during the applicable term to host, copy, transmit, modify, and otherwise process Customer Data solely as necessary to provide, secure, support, and comply with law regarding the Services and as otherwise instructed by Customer.
Company will not use Customer Data to train, fine-tune, develop, or improve a generalized artificial-intelligence or machine-learning model, and will prohibit subprocessors from doing so for their own purposes, unless Customer expressly instructs or authorizes that use in writing.
4.3 Aggregated Data
Company may generate and use Aggregated Data to operate, secure, analyze, and improve the Services and for other lawful business purposes. Aggregated Data must not identify Customer, an Authorized User, or another individual, and Company will not attempt to reidentify it except to test deidentification safeguards.
4.4 Feedback
Customer grants Company a perpetual, irrevocable, worldwide, non-exclusive, fully paid, royalty-free right to use feedback and suggestions without restriction or attribution. Feedback does not include Customer Data or Customer Confidential Information.
5. Fees, Credits, and payment
5.1 Plans and fees
Customer will pay the fees shown in its Order. Except as expressly stated otherwise, amounts are in U.S. dollars and exclude taxes.
Plan prices and Credit rates are incorporated by reference from the checkout or plan-selection terms accepted by Customer. Company may change pricing for a future renewal period by providing notice before renewal.
5.2 Credit allocations
Credits are allocated monthly, including under annual plans. Credits expire at the end of each monthly allocation period, do not roll over, are non-transferable, and have no cash value.
Annual plans are billed upfront and receive the monthly allocations, including any additional Credits, displayed in the Order. Credit usage is measured according to the rate card displayed in the Order.
Company does not provide automatic top-ups, overages, or automatic plan upgrades. When Customer reaches 100% of the available Credit allocation, metered Products are paused until the next allocation period or until Customer affirmatively upgrades its plan. Services that do not consume Credits may remain available.
5.3 Billing and renewal
Stripe processes online billing. Customer authorizes Company and Stripe to charge the payment method associated with the account for initial and renewal fees, taxes, and other amounts in the Order.
Paid subscriptions renew for the same billing period unless Customer cancels before renewal. Cancellation stops future renewal and does not end access before the paid term expires.
5.4 Taxes
Customer is responsible for applicable sales, use, value-added, withholding, and similar taxes, excluding taxes based on Company's net income. If Customer claims an exemption, it must provide valid documentation.
5.5 Refunds
Paid amounts are non-refundable and non-creditable except where required by law or to correct a billing error. Cancellation does not create a refund or extend the expiration of Credits.
5.6 Suspension for nonpayment
Company may suspend paid Services if payment is overdue after reasonable notice. Customer remains responsible for amounts accrued before suspension.
6. Warranties and disclaimers
6.1 Mutual warranties
Each party represents that it has authority to enter into this Agreement and that doing so does not violate another binding obligation.
6.2 Customer warranties
Customer represents that:
- it has all rights and authorizations required for Customer Data, Connected Accounts, assessment targets, and instructions;
- its use of the Services will comply with this Agreement, Documentation, law, and third-party rights; and
- it will not knowingly submit malware or data intended to compromise the Services, except for authorized testing material submitted within a documented feature and scope.
6.3 General disclaimer
EXCEPT AS EXPRESSLY PROVIDED IN THIS AGREEMENT, THE SERVICES, PLATFORM, DOCUMENTATION, INPUTS, OUTPUTS, AND THIRD-PARTY SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW, COMPANY DISCLAIMS ALL IMPLIED AND STATUTORY WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, AND WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.
COMPANY DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, COMPLETELY SECURE, OR THAT THEY WILL IDENTIFY, PREVENT, OR REMEDY EVERY VULNERABILITY, THREAT, POLICY VIOLATION, MALICIOUS CONTRIBUTOR, UNSAFE INPUT, OR HARMFUL ACTION.
6.4 Outputs
Automated Outputs may be incomplete, inaccurate, non-unique, or unsuitable for Customer's purpose. Customer is responsible for reviewing Outputs, validating findings and proposed fixes, maintaining human oversight, and deciding whether and how to act.
The Services do not provide legal advice, certify compliance, or replace Customer's security program, testing, professional judgment, or regulatory obligations.
7. Limitation of liability
7.1 Excluded damages
EXCEPT FOR EXCLUDED LIABILITY, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, GOODWILL, OR DATA, ARISING FROM THIS AGREEMENT, EVEN IF ADVISED OF THE POSSIBILITY.
"Excluded Liability" means liability arising from a party's gross negligence or willful misconduct, infringement or misappropriation of the other party's intellectual-property rights, breach of confidentiality obligations, or indemnification obligations.
7.2 Liability cap
EXCEPT FOR EXCLUDED LIABILITY, EACH PARTY'S TOTAL AGGREGATE LIABILITY ARISING FROM OR RELATING TO THIS AGREEMENT WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER TO COMPANY DURING THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY.
For free Services, Company's aggregate liability will not exceed $100.
7.3 Scope
These exclusions and limitations apply to the maximum extent permitted by law regardless of the theory of liability and survive failure of an exclusive remedy.
8. Confidentiality
8.1 Confidential Information
"Confidential Information" means non-public information disclosed by one party ("Disclosing Party") to the other ("Receiving Party") that is marked confidential or reasonably should be understood as confidential, including Customer Data and non-public product, technical, security, pricing, and business information.
Confidential Information does not include information that the Receiving Party can demonstrate:
- is public through no breach of this Agreement;
- was lawfully known without confidentiality restriction;
- is received lawfully from a third party without confidentiality duty; or
- is independently developed without using the Disclosing Party's Confidential Information.
8.2 Protection and use
The Receiving Party will use Confidential Information only to perform or exercise rights under this Agreement, protect it using at least reasonable care, and disclose it only to personnel and contractors who need to know it and are bound by appropriate confidentiality obligations.
8.3 Required disclosure
The Receiving Party may disclose Confidential Information when required by law if, where legally permitted, it gives prompt notice and reasonable assistance so the Disclosing Party may seek protection.
8.4 Return and deletion
On request or termination, the Receiving Party will return or delete Confidential Information it no longer has a right or obligation to retain, subject to routine backups and legal retention. Retained information remains protected by this Agreement.
9. Indemnification
9.1 By Company
Company will defend Customer against a third-party claim alleging that Customer's authorized use of the Services infringes a U.S. patent, copyright, or trade secret and will pay damages finally awarded or agreed in settlement.
Company has no obligation for claims arising from Customer Data, Inputs, Outputs, third-party services, combinations not supplied by Company, modifications not made by Company, or use outside this Agreement or Documentation.
Company may obtain the right to continue use, modify or replace the affected Service, or terminate it and refund prepaid fees for the unused portion of the affected paid term. This Section states Customer's exclusive remedy for covered infringement claims.
9.2 By Customer
Customer will defend Company and its affiliates, officers, directors, employees, and agents against third-party claims arising from:
- Customer Data, Connected Accounts, or assessment targets;
- Customer's breach of Sections 3 or 6.2;
- Customer's unlawful, unauthorized, or out-of-scope testing; or
- Customer's use of Outputs.
Customer will pay damages finally awarded or agreed in settlement.
9.3 Procedure
The indemnified party must promptly notify the indemnifying party, provide reasonable cooperation, and allow the indemnifying party to control defense and settlement. A settlement may not admit fault or impose non-monetary obligations on the indemnified party without consent.
10. Term and termination
10.1 Term
This Agreement begins when Customer first accepts it and continues while Customer has an account, active Order, or access to the Services.
Each paid Order continues for the monthly or annual term shown at checkout and automatically renews for successive terms unless canceled before renewal.
10.2 Cancellation
Customer may cancel renewal through account settings or by contacting support. Cancellation takes effect at the end of the paid term. Credits continue to follow their normal monthly allocation and expiration schedule during the remaining term.
10.3 Termination for breach
Either party may terminate this Agreement or an affected Order if the other party materially breaches it and does not cure the breach within 30 days after written notice. A party may terminate immediately if a breach cannot reasonably be cured, continued use would violate law, or the other party becomes insolvent.
10.4 Suspension
Company may suspend access when reasonably necessary to prevent security risk, unauthorized activity, harm to third parties, material breach, or legal exposure. Where practicable, Company will give notice and an opportunity to remedy the issue.
10.5 Effect
Upon termination, Customer's right to use affected Services ends and outstanding amounts become due. Sections that by their nature should survive will survive, including ownership, payment, disclaimers, limitations, confidentiality, indemnification, dispute resolution, and miscellaneous terms.
Customer Data is returned or deleted as described in the Global Data Processing Addendum.
11. Miscellaneous
11.1 Governing law
This Agreement is governed by Delaware law, without regard to conflict-of-law rules.
11.2 Dispute resolution and JAMS arbitration
Before initiating a formal proceeding, a party must send written notice describing the dispute and requested relief to the other party. Notices to Company must be sent to legal@superagent.sh. The parties will attempt in good faith to resolve the dispute for 60 days.
Except for individual small-claims matters and requests for equitable relief relating to intellectual property, confidentiality, or data security, disputes arising from this Agreement will be resolved by binding individual arbitration administered by JAMS under its applicable commercial rules. Arbitration will occur remotely or in New Castle County, Delaware, unless the parties agree otherwise.
EACH PARTY WAIVES A JURY TRIAL FOR COVERED CLAIMS. CLAIMS MUST BE BROUGHT INDIVIDUALLY, NOT AS A PLAINTIFF OR CLASS MEMBER IN A CLASS, COLLECTIVE, CONSOLIDATED, OR REPRESENTATIVE PROCEEDING.
Customer may opt out of arbitration within 30 days after first accepting this Agreement by sending Customer's legal name, account email, and a clear opt-out statement to legal@superagent.sh.
Claims not subject to arbitration must be brought exclusively in the state or federal courts in New Castle County, Delaware, and each party consents to their jurisdiction and venue.
11.3 Assignment
Neither party may assign this Agreement without the other's consent, except to an affiliate or in connection with a merger, reorganization, financing, acquisition, or sale of substantially all relevant assets. An unauthorized assignment is void.
11.4 Publicity
Company may identify Customer as a customer only with Customer's permission or as otherwise agreed.
11.5 Force majeure
Neither party is liable for delay or failure caused by events beyond its reasonable control, except payment obligations. The affected party will use reasonable efforts to mitigate the effect.
11.6 Relationship
The parties are independent contractors. This Agreement does not create a partnership, joint venture, employment, fiduciary, or agency relationship.
11.7 Notices
Legal notices must be in writing. Notices to Company must be sent to legal@superagent.sh and, for breach or termination notices, by mail to Superagent Technologies, Inc., 1111B S Governors Ave, Suite 3232, Dover, Delaware 19904. Notices to Customer may be sent to the account email or address in the Order.
11.8 Electronic acceptance
Electronic acceptance, signatures, and records have the same effect as originals. Company records identifying the accepting user, organization, Agreement version, and acceptance time may evidence acceptance.
11.9 Entire agreement and precedence
This Agreement is the complete agreement concerning the Services and supersedes prior discussions on that subject. Amendments must be in writing or accepted through an electronic process that clearly identifies the amendment.
If documents conflict, the following order controls: an Order that expressly overrides a provision; the Global Data Processing Addendum for Personal Data; this Services Agreement; and the Documentation.
11.10 Severability and waiver
If a provision is unenforceable, it will be modified to the minimum extent necessary and the remainder will continue in effect. Failure to enforce a provision is not a waiver.