Terms of Service
Last updated: 29 June 2026
Service Description
Good CISO Limited maintains AWARE, the open-source security control plane for autonomous AI agents. AWARE is licensed under Apache 2.0 and may be self-hosted, modified, and redistributed without fee. Good CISO additionally offers optional paid support contracts (see /pricing.html) and enterprise agreements for organisations that need SLA-backed help.
Acceptable Use
You agree to use AWARE solely for lawful agent governance purposes, maintain the confidentiality of any paid support account credentials, and not attempt to interfere with other users' deployments. For the open-source framework itself, see the Apache 2.0 license terms — modification and redistribution are permitted, subject to license obligations. You must not use the framework or any hosted service for any unlawful purpose including fraud, money laundering, or unauthorised data exfiltration.
No Legal or Compliance Advice
AWARE is a decision-support tool. It does not provide legal, compliance, or financial advice. All outputs should be reviewed by qualified professionals. Good CISO disclaims liability for decisions made based on AWARE outputs. Firms remain responsible for their own regulatory obligations.
Limitation of Liability
Good CISO's aggregate liability is limited to fees paid in the 12 months preceding the claim. We are not liable for indirect, incidental, special, or consequential damages; loss of profits, revenue, or data; regulatory penalties; or third-party claims.
Service Availability
We target 99.5% uptime, excluding scheduled maintenance and force majeure. Scheduled maintenance is announced 48 hours in advance. If uptime falls below 99.5% in a calendar month, affected clients receive a service credit equal to the shortfall.
Intellectual Property
All IP in the AWARE platform — software, algorithms, models, and branding — is owned by Good CISO. You retain ownership of all data you upload. Nothing transfers ownership of your data to us.
Termination
Either party may terminate with 30 days written notice. Upon termination, we will export your data in a standard format within 30 days and delete client data from production systems within 60 days, subject to regulatory retention requirements.
Governing Law
These terms are governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction. If any provision is unenforceable, the rest remains in full effect.
Contact
Legal enquiries: legal@goodciso.org