Terms of Service
These Terms of Service ("Terms") govern your access to and use of Lelu AI's website, APIs, authorization engine, human-in-the-loop review system, software development kits (SDKs), and managed platform services.
AI Action Governance
Lelu provides policy enforcement & confidence evaluation for autonomous agents before actions execute.
Zero Model Training
Your prompt payloads, tool inputs, and decision hashes are never used to train global AI models.
Dual Licensing Model
Core engine & SDKs are open-source under the MIT license; hosted platform APIs operate under these cloud terms.
Human Oversight SLAs
Confidence-gated actions routed to human review queues remain pending until explicit approval or timeout.
1. Agreement & Acceptance of Terms
By creating an account, integrating the Lelu SDKs, invoking Lelu APIs, or utilizing the Lelu Agent Authorization Platform (collectively, the "Service"), you ("Customer," "You," or "User") agree to be legally bound by these Terms of Service. If you are accepting these Terms on behalf of an entity, company, or organization, you represent and warrant that you possess the legal authority to bind that organization.
If you do not agree to all of the terms and conditions set forth herein, you must not access or use the Service.
2. Description of Services & Infrastructure
Lelu provides security and authorization infrastructure specifically engineered for autonomous AI agents, non-human identities (NHIs), and language-model-driven application tools. The Service encompasses:
- Confidence-Aware Authorization Engine: Real-time evaluation of agent action requests, tool call parameters, confidence scores, and context against declarative security policies (YAML, Rego).
- Human-in-the-Loop Review System: Async queueing and routing mechanisms for low-confidence or high-risk agent actions requiring explicit human approval prior to execution.
- Audit Trail & Evidence Logging: Cryptographically linked logging of input/output hashes, policy evaluation decisions, actor metadata, and execution latency.
- Managed Platform & APIs: Hosted control plane, web dashboard, registry, and cloud endpoint routing.
3. Account Credentials & API Key Security
To utilize the Service, you must register for an account and generate API access keys. You are solely responsible for:
- Maintaining the strict confidentiality of your account credentials, passkeys, and API keys.
- Restricting access to API keys that carry administrative or policy modification privileges.
- All activities, requests, and policy decisions executed under your account credentials or API tokens.
You must notify Lelu immediately at security@lelu-ai.com if you discover or suspect any unauthorized use of your API keys or security compromise.
4. Autonomous Agent Governance & Policy Responsibility
Customer is solely responsible for authoring, configuring, and testing the security policies (allow/deny rules, confidence threshold boundaries, and approval workflows) deployed within the Lelu platform. Lelu does not guarantee that a given policy configuration will prevent all unauthorized or unintended AI model behaviors.
5. Confidence-Gated Authorization & Human-in-the-Loop
When an agent action is evaluated by Lelu's confidence engine:
- Allowed Actions: Actions exceeding specified confidence thresholds and matching allow policies are permitted to execute immediately.
- Escalated Actions: Actions falling below confidence thresholds or explicitly tagged for review are paused and placed into Customer's human review queue.
- Timeout & Expiration: Customer must configure review expiration behavior (e.g. auto-deny after 24 hours). Lelu is not liable for delayed business workflows caused by unreviewed items in Customer's queue.
6. Data Rights, Telemetry & Audit Logs
Customer Ownership: Customer retains all rights, title, and interest in Customer Data, including agent prompts, response payloads, custom policies, and audit logs.
Zero Training Pledge: Lelu will never use Customer Data or audit log payloads to train foundational AI models or share customer data across tenant boundaries.
Usage Metrics: Lelu collects aggregated, anonymized operational metrics (e.g., policy evaluation count, latency percentiles, error rates) to maintain platform stability and improve performance.
7. Open Source Licensing vs. Cloud Platform
Lelu's core authorization engine and SDKs are distributed under the open-source MIT License. You are free to inspect, modify, and self-host the open-source repository in accordance with the MIT license terms.
These Terms of Service specifically apply to the hosted cloud infrastructure, managed dashboard, global control plane, multi-tenant database services, and enterprise API endpoints provided by Lelu AI.
8. Acceptable Use Policy & Restrictions
You agree not to misuse the Service or assist any third party in doing so. Prohibited activities include:
- Attempting to bypass, disable, or tamper with Lelu's security controls or rate limit quotas.
- Using the Service to authorize malware execution, automated cyberattacks, unauthorized surveillance, or spam.
- Reverse engineering, decompiling, or probing the proprietary hosted components of the Service.
- Conducting denial-of-service (DoS) attacks against Lelu infrastructure.
9. Service Levels, Availability & Maintenance
Lelu strives to maintain 99.9% uptime for production API endpoints. Scheduled maintenance windows will be communicated via our status page and email notifications. Enterprise SLA commitments are set forth in separate Enterprise Service Agreements.
10. Fees, Billing & Subscription Terms
Certain features of the Service are offered on a paid subscription or usage basis (e.g. monthly API authorization calls, evaluation throughput, team seats). All fees are non-refundable except as required by law or explicitly stated in writing.
11. Intellectual Property Rights
Lelu retains all right, title, and interest in and to the Service, including all software, branding, trademarks, logos, domain names, design patterns, and proprietary evaluation algorithms.
12. Limitation of Liability & Warranty Disclaimer
Provided "As Is"
THE SERVICE IS PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, LELU AI DISCLAIMS ALL WARRANTIES, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
IN NO EVENT SHALL LELU AI OR ITS OFFICERS, DIRECTORS, OR EMPLOYEES BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING FROM OR RELATED TO YOUR USE OF THE SERVICE OR AGENT ACTIONS AUTHORIZED THROUGH THE PLATFORM.
13. Indemnification
You agree to defend, indemnify, and hold harmless Lelu AI and its affiliates from and against any claims, liabilities, damages, judgments, losses, and expenses (including reasonable attorney fees) arising out of or in connection with your breach of these Terms or your deployment of AI agents.
14. Termination & Suspension
Lelu reserves the right to suspend or terminate your access to the Service at any time, with or without prior notice, in the event of a material violation of these Terms, non-payment, or security threat to our platform.
15. Governing Law & Contact Information
These Terms shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict of law principles.