This Platform Agreement (the “Agreement”) governs subscription access to the Enjamb platform provided by Enjamb Labs, Inc., a Delaware corporation (“Enjamb,” “we,” “us”), to the organization identified in an Order (“Customer,” “you”).
The Agreement takes effect on the date stated in the first Order and replaces any Evaluation Terms of Service between us, including for the evaluation period itself.
The Agreement consists of these terms, each Order, the Data Processing Addendum, the Security Addendum, and any other addendum the parties execute. Where they conflict, the Order controls, then any executed addendum, then these terms. A purchase order or vendor portal term that adds to or differs from the Agreement has no effect unless we sign it.
The individual accepting this Agreement represents that they are authorized to bind the organization named in the Order.
2. Definitions
- “Services” means the Enjamb platform, including the workspace, agents, connectors, memory, routines, the MCP server, APIs, and the documentation and support provided with them.
- “Order” means an ordering document signed by both parties that identifies the subscription, the term, the authorized users or capacity, and the fees.
- “Customer Data” means all content and data you or your Users submit to the Services, all data the Services retrieve from Connected Systems on your instruction, and all Output generated from it.
- “User” means an individual authorized by you to use the Services under your workspace, including employees, contractors, and personnel of your Affiliates.
- “Affiliate” means an entity controlling, controlled by, or under common control with a party.
- “Connected System” means a third-party or internal system you authorize the Services to reach on your behalf.
- “Output” means content the Services generate in response to a User instruction.
- “Subscription Term” means the period stated in an Order, including renewals.
3. Access and Use
For the Subscription Term we grant you a non-exclusive, non-transferable right to access and use the Services for your internal business purposes, within the users or capacity stated in the Order. Your Affiliates may use the Services under your Order, and you remain responsible for their compliance.
You are responsible for your Users' compliance with this Agreement, for the accuracy and legality of what you submit, and for the security of your credentials. You will notify us promptly at security@enjamb.ai if you learn of unauthorized access to your workspace.
You will not: reverse engineer or attempt to derive the source code or model weights behind the Services; probe or breach their security except under a written testing agreement; use them to build a competing product; resell or provide them to a third party as a service; exceed documented rate limits or otherwise degrade them for others; upload malicious code; or use them in violation of law or of a third party's rights.
You will not use the Services to make a clinical, diagnostic, or treatment decision about an identifiable patient, or as the sole basis for a decision with legal or safety consequences. The Services support professional judgment and do not replace it.
4. Agents, Identity, and Approvals
Agents act with the authority of the User who instructs them. An agent reaches a Connected System as that User, inside the permissions that User already holds, and cannot reach data the User could not reach directly. Delegating work to an agent does not widen access.
You control what the Services may do. Your administrators decide which systems are connected, which tools each agent may use, and which actions require human approval before they execute. Configuring those controls to match your policies and regulatory obligations is your responsibility.
Each run retains the requester, the instruction, the systems reached, the actions taken, and the sources behind the result. That record is Customer Data, is available to you throughout the Subscription Term, and is retained for the period you configure.
Where you authorize an agent to write to a Connected System, the resulting record in that system remains yours, including any record-keeping, review, or validation obligation attaching to it under your quality system.
5. Customer Data
You own your Customer Data. You grant us only the limited right to host, process, and transmit it as needed to provide and support the Services during the Subscription Term.
We do not train, fine-tune, or evaluate models on your Customer Data, and our agreements with model providers prohibit them from doing so with data we send on your behalf. We do not sell it, and we do not use it to serve any other customer. This commitment survives termination.
We may generate aggregated, de-identified usage data that cannot identify you, any User, or any individual, and may use it to operate, secure, and improve the Services. We will not publish it in a form that identifies you.
On request during the Subscription Term, or within thirty days after it ends, we will make your Customer Data available for export and then delete it. Backups age out on a documented cycle after that. Where you instruct earlier deletion of specific records, we will action it within the period stated in the Data Processing Addendum.
You are responsible for having the right to submit your Customer Data and to authorize each connection you make, including any consent, authorization, or notice your own agreements or applicable law require.
6. Outputs
As between the parties, you own Outputs generated for you, subject to our rights in the Services. We assign to you whatever rights we may hold in Outputs generated from your Customer Data.
Outputs are produced by statistical models and can be incomplete, out of date, or wrong. Similar instructions can produce different Outputs, and an Output may resemble one produced for another customer. Reviewing an Output before relying on it, and confirming any claim it makes against the sources it cites, is your responsibility.
You will not represent an Output as having been reviewed, validated, or approved by Enjamb.
7. Regulated Use and Validation
The Services are general-purpose software. They are not a medical device, are not validated on your behalf for any regulated purpose, and are not certified against any standard except as we state in writing.
Where you use the Services in or near a regulated process, validation for your intended use remains yours. We will support it: on request we provide documentation of the controls, access model, and audit record that the Services implement, together with reasonable information about material changes that could affect a validated state.
The Services do not capture electronic signatures and are not offered as a system of record for signature-based approvals. Where a signature is required by your procedures or by law, it belongs in the system that holds that record.
The audit record the Services maintain is designed to be attributable, time-stamped, and reviewable. Determining whether it satisfies a particular regulatory obligation of yours is your responsibility, and we will provide the information you reasonably need to make that determination.
8. Fees and Payment
You will pay the fees stated in the Order. Unless the Order says otherwise, fees are invoiced annually in advance, are payable within thirty days of the invoice date, and are non-refundable except where this Agreement expressly provides.
Where an Order includes metered capacity such as compute for model execution, the Order states the included allowance and the rate for usage beyond it. We will notify you before you exceed an allowance rather than invoice you for it after the fact.
Fees are exclusive of taxes. You are responsible for taxes other than those on our income. Where you are required to withhold tax, the amount payable is grossed up so that we receive the amount we would have received without the withholding.
Undisputed amounts more than thirty days overdue may accrue interest at the lower of one and a half percent per month or the maximum permitted by law. We will not suspend the Services for non-payment without at least ten days' written notice and an opportunity to cure. Amounts disputed in good faith and raised in writing before the due date are not overdue while the dispute is being resolved.
Fees for a renewal term may change if we give notice at least sixty days before the renewal date.
9. Term, Renewal, and Termination
The Agreement begins on the effective date of the first Order and continues while any Order is in effect. Each Order runs for the Subscription Term stated in it and renews for successive periods of the same length unless either party gives written notice of non-renewal at least thirty days before the end of the current term.
Either party may terminate for material breach on thirty days' written notice, if the breach is not cured within that period. Either party may terminate immediately if the other becomes insolvent or enters a bankruptcy or similar proceeding.
We may suspend access without prior notice where necessary to protect the Services, another customer, or a person from imminent harm, or where required by law. We will tell you why as soon as we reasonably can and restore access once the cause is resolved. Suspension does not relieve you of the obligation to pay for the suspended period unless the suspension was our fault.
If you terminate for our uncured material breach, we will refund prepaid fees for the remainder of the term. On expiry or termination, access ends and Customer Data is handled as section 5 provides. Sections 5, 6, 7, 11, 12, 13, 14 and 15 survive.
10. Availability, Support, and Security
We will use commercially reasonable efforts to make the Services available in accordance with the availability commitment stated in the Order or an executed support addendum, excluding scheduled maintenance we give reasonable notice of, and events beyond our reasonable control.
We will maintain the technical and organizational measures described in the Security Addendum, which include encryption in transit and at rest, workspace isolation, access control, and logging. We will not materially reduce them during the Subscription Term.
We will notify you of a security incident affecting your Customer Data without undue delay and within the timeframe stated in the Data Processing Addendum, with the facts established rather than a holding statement, and will keep you informed as the investigation proceeds.
Once in any twelve-month period, and on reasonable notice, you may review our then-current audit reports, certifications, and responses to a security questionnaire. Where your regulator requires an on-site audit, the parties will agree scope and timing in good faith.
We may engage subprocessors and remain responsible for their performance. The current list is published at Subprocessors, and we will give notice before adding one, with the objection process stated in the Data Processing Addendum.
11. Indemnification
We will defend you against a third-party claim that the Services, used as permitted by this Agreement, infringe that party's intellectual property rights, and will pay the damages finally awarded or agreed in settlement.
If the Services become, or we believe they may become, the subject of such a claim, we may at our option procure the right for you to continue using them, modify them so they are no longer infringing, or terminate the affected subscription and refund prepaid fees for the remainder of the term. We have no obligation for a claim arising from your Customer Data, from use outside this Agreement, or from combination with something we did not supply, where the claim would not have arisen otherwise.
You will defend us against a third-party claim arising from your Customer Data or your use of the Services in breach of this Agreement, and will pay the damages finally awarded or agreed in settlement.
Indemnification is conditioned on the indemnified party giving prompt written notice, granting sole control of the defense and settlement (subject to not admitting liability on the indemnified party's behalf without consent), and providing reasonable cooperation at the indemnifying party's expense.
12. Warranties and Disclaimer
Each party warrants that it has the authority to enter into this Agreement. We warrant that we will provide the Services with reasonable skill and care, in accordance with the documentation in all material respects, and that we will not knowingly introduce malicious code. Your exclusive remedy for breach of this warranty is our correction of the non-conformity, or, if we cannot correct it within a reasonable period, termination and refund of prepaid fees for the affected remainder of the term.
Otherwise, and to the fullest extent permitted by law, the Services are provided “as is.” We disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose, non-infringement, and any warranty that the Services will be uninterrupted or error free, or that any Output will be accurate or complete.
13. Limitation of Liability
Neither party is liable for indirect, incidental, special, consequential, or exemplary damages, or for lost profits, revenue, or goodwill, whether in contract, tort, or otherwise, even if advised of the possibility.
Each party's total liability arising out of this Agreement is limited to the fees paid or payable by you in the twelve months before the event giving rise to the claim.
For claims arising from a party's breach of its confidentiality or security obligations, or from our breach of the commitment in section 5 not to train on Customer Data, that cap is instead three times the fees paid or payable in the same period.
The caps do not apply to your obligation to pay fees, to either party's indemnification obligations, or to liability that cannot be limited by law, including for fraud, willful misconduct, or death or personal injury caused by negligence.
14. Confidentiality
Each party may receive information the other treats as confidential, including Customer Data, the Services and their non-public functionality, and the terms of each Order. The receiving party will protect it with at least reasonable care, use it only to perform under this Agreement, and disclose it only to personnel and advisors who need it and are bound to equivalent obligations.
These obligations do not apply to information that is public through no fault of the receiving party, was already known to it without duty of confidence, is independently developed, or is lawfully received from a third party. Disclosure compelled by law is permitted where the receiving party gives prompt notice, unless legally prohibited from giving it.
Confidentiality obligations continue for three years after termination, and for Customer Data and trade secrets, for as long as the law protects them.
15. General
Governing law and venue. This Agreement is governed by the laws of the State of Delaware, without regard to conflict of laws rules. The state and federal courts located in Delaware have exclusive jurisdiction, and each party consents to that venue. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
Insurance. During the Subscription Term we will maintain commercial general liability, professional liability including errors and omissions, and cyber liability coverage in amounts customary for a company of our size and stage. Certificates are available on request.
Use of name. Neither party will use the other's name, marks, or logo publicly without prior written consent, which may be given in an Order and may be withdrawn on reasonable notice.
Feedback. If you give us suggestions about the Services, we may use them without restriction or obligation. Feedback does not include Customer Data.
Assignment. Neither party may assign this Agreement without the other's written consent, except to a successor in a merger or sale of substantially all assets, on notice. Any other attempted assignment is void.
Export and sanctions. Each party will comply with applicable export control and sanctions laws. You represent that you are not located in, and will not access the Services from, an embargoed country, and that you and your Users are not on a restricted party list.
Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control, other than an obligation to pay.
Changes, waiver, severability, notices, and entire agreement. We may update this Agreement for future Orders, and will post the current version here with its date; a change applies to an in-force Order only on renewal or by written agreement. A failure to enforce a provision is not a waiver of it. If a provision is unenforceable, the rest remains in force. Legal notices to us go to legal@enjamb.ai, and to you at the contact in the Order. This Agreement, its Orders, and its addenda are the entire agreement between the parties on this subject and supersede prior discussions.
Independent contractors. The parties are independent contractors. Nothing here creates a partnership, agency, or employment relationship, and there are no third-party beneficiaries other than Affiliates using the Services under your Order.
Contact
Contractual and legal notices: legal@enjamb.ai. Security reports and incident contact: security@enjamb.ai. Privacy questions: privacy@enjamb.ai, and see our Privacy Policy.
Enjamb Labs, Inc., a Delaware corporation, United States.


