Terms of Service

Terms of Service

Last updated: 10 August 2026

AGREEMENT TO OUR LEGAL TERMS

We are XTrace Inc. (“Company,” “we,” “us,” “our”).

We operate the website xtrace.ai (the “Site”), as well as any other related products and services that refer or link to these legal terms (the “Legal Terms”) (collectively, the “Services”).

You can contact us by email at admin@xtrace.ai.

These Legal Terms constitute a legally binding agreement made between you, whether personally or on behalf of an entity (“you”), and XTrace Inc., concerning your access to and use of the Services. You agree that by accessing the Services, you have read, understood, and agreed to be bound by all of these Legal Terms. IF YOU DO NOT AGREE WITH ALL OF THESE LEGAL TERMS, THEN YOU ARE EXPRESSLY PROHIBITED FROM USING THE SERVICES AND YOU MUST DISCONTINUE USE IMMEDIATELY.

We will provide you with prior notice of any scheduled changes to the Services you are using. The modified Legal Terms will become effective upon posting or notifying you by XTrace Inc., as stated in the email message. By continuing to use the Services after the effective date of any changes, you agree to be bound by the modified terms.

All users who are minors in the jurisdiction in which they reside (generally under the age of 18) must have the permission of, and be directly supervised by, their parent or guardian to use the Services. If you are a minor, you must have your parent or guardian read and agree to these Legal Terms prior to you using the Services.

We recommend that you print a copy of these Legal Terms for your records.

1. Our Service

The information provided when using the Services is not intended for distribution to or use by any person or entity in any jurisdiction or country where such distribution or use would be contrary to law or regulation or which would subject us to any registration requirement within such jurisdiction or country. Accordingly, those persons who choose to access the Services from other locations do so on their own initiative and are solely responsible for compliance with local laws, if and to the extent local laws are applicable.

2. Intellectual Property Rights

Our intellectual property

We are the owner or the licensee of all intellectual property rights in our Services, including all source code, databases, functionality, software, website designs, audio, video, text, photographs, and graphics in the Services (collectively, the “Content”), as well as the trademarks, service marks, and logos contained therein (the “Marks”).

Our Content and Marks are protected by copyright and trademark laws (and various other intellectual property rights and unfair competition laws) and treaties in the United States and around the world.

The Content and Marks are provided in or through the Services “AS IS” for your internal business purpose only.

Your use of our Services

Subject to your compliance with these Legal Terms, including the “PROHIBITED ACTIVITIES” section below, and to payment of any applicable fees, we grant you a non-exclusive, non-transferable, non-sublicensable, revocable license to:

  1. access and use the Services through the interfaces we make available, for your internal business purposes;

  2. permit your employees, contractors, and agents (“Authorized Users”) to access and use the Services on your behalf and for your benefit, up to any seat or usage limit applicable to your plan, provided you remain responsible for their compliance with these Legal Terms;

  3. access and use our documentation as reasonably necessary to exercise the rights above; and

  4. use, reproduce, and internally distribute the outputs generated through your authorized use of the Services.

This license lasts only for so long as these Legal Terms remain in effect and your account remains in good standing. All rights not expressly granted are reserved.

Except as set out in this section or elsewhere in our Legal Terms, no part of the Services and no Content or Marks may be copied, reproduced, aggregated, republished, uploaded, posted, publicly displayed, encoded, translated, transmitted, distributed, sold, licensed, or otherwise exploited for any commercial purpose whatsoever, without our express prior written permission.

If you wish to make any use of the Services, Content, or Marks other than as set out in this section or elsewhere in our Legal Terms, please address your request to: XTrace Inc. If we ever grant you the permission to post, reproduce, or publicly display any part of our Services or Content, you must identify us as the owners or licensors of the Services, Content, or Marks and ensure that any copyright or proprietary notice appears or is visible on posting, reproducing, or displaying our Content.

We reserve all rights not expressly granted to you in and to the Services, Content, and Marks.

Any breach of these Intellectual Property Rights will constitute a material breach of our Legal Terms and your right to use our Services will terminate immediately.

Your submissions

Please review this section and the “PROHIBITED ACTIVITIES” section carefully prior to using our Services to understand the (a) rights you give us and (b) obligations you have when you post or upload any content through the Services.

Submissions: By directly sending us any question, comment, suggestion, idea, feedback, or other information about the Services (“Submissions”), you agree to assign to us all intellectual property rights in such Submission. You agree that we shall own this Submission and be entitled to its unrestricted use and dissemination for any lawful purpose, commercial or otherwise, without acknowledgment or compensation to you.

You are responsible for what you post or upload: By sending us Submissions through any part of the Services you:

You are solely responsible for your Submissions and you expressly agree to reimburse us for any and all losses that we may suffer because of your breach of (a) this section, (b) any third party’s intellectual property rights, or (c) applicable law.

3. User Representations

By using the Services, you represent and warrant that: (1) you have the legal capacity and you agree to comply with these Legal Terms; (2) you are not a minor in the jurisdiction in which you reside, or if a minor, you have received parental permission to use the Services; (3) you will not access the Services through automated or non-human means, whether through a bot, script or otherwise; (4) you will not use the Services for any illegal or unauthorized purpose; and (5) your use of the Services will not violate any applicable law or regulation.

If you provide any information that is untrue, inaccurate, not current, or incomplete, we have the right to suspend or terminate your account and refuse any and all current or future use of the Services (or any portion thereof).

4. Prohibited Activities

You may not access or use the Services for any purpose other than that for which we make the Services available. The Services are made available for business use in accordance with the license granted in Section 2.

As a user of the Services, you agree not to, and not to permit any Authorized User or third party to:

  1. access or attempt to access any account, workspace, or data that you are not authorized to access;

  2. probe, scan, or test the vulnerability of the Services, or breach or circumvent any authentication, authorization, tenant-isolation, quota, filtering, or security measure, except under a written authorized-testing agreement with us or as expressly permitted by our vulnerability disclosure terms in Section 20.6;

  3. introduce malware, or use the Services to distribute malware or to stage, launch, or assist an attack on any system;

  4. use the Services to send unsolicited bulk communications, to harvest contact details, or in any way that breaches anti-spam, telemarketing, or electronic communications laws;

  5. interfere with or unreasonably burden the Services or their infrastructure, or take any action that degrades the Services for other users;

  6. exceed, evade, or attempt to evade any published rate limit, quota, plan limit, or usage cap, including by rotating credentials, creating multiple accounts, or misrepresenting your identity;

  7. interfere with, falsify, or attempt to defeat the metering, usage measurement, or billing mechanisms of the Services;

  8. share, publish, or embed credentials or API keys outside your organization, or in any client-side context accessible to a third party;

  9. copy, modify, translate, or create derivative works of the Services;

  10. reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, non-public APIs, models, prompts, ranking logic, or algorithms of the Services, except to the extent applicable law expressly permits and then only on prior written notice to us;

  11. resell, sublicense, rent, lease, time-share, or provide the Services as a service bureau to any third party without our prior written agreement;

  12. use the Services, or their outputs, to build or improve a product or service that competes with the Services;

  13. benchmark or perform competitive analysis of the Services other than for your own internal evaluation, or publish the results of any benchmark without our prior written consent;

  14. use inputs to, or outputs from, the Services to train, fine-tune, distil, or evaluate any machine learning model without our prior written authorization, or query the Services systematically for the purpose of reconstructing or deriving our knowledge base, retrieval behaviour, ranking, or prompts;

  15. deliberately bypass, disable, or interfere with any content filter, safety system, classification gate, sharing restriction, or guardrail in the Services, or prompt the Services with the intent of causing them to produce infringing, unlawful, or harmful output;

  16. present output as human-authored where a person receiving it would need to know it was AI-generated, or fail to make any AI-interaction or AI-content disclosure that applicable law requires of you;

  17. use the Services to generate or distribute content that is unlawful, defamatory, harassing, or that sexually exploits or endangers minors, or to conduct unlawful surveillance, profiling, or social scoring;

  18. remove, obscure, or alter any proprietary notice in the Services; or

  19. infringe or misappropriate any third party’s intellectual property, publicity, or privacy rights, or submit content you do not have the right to submit.

We may suspend or restrict access where we reasonably believe it is necessary to stop a breach of this section, to protect the Services or another user, or to comply with law. We will give notice before suspending where practicable, will limit the suspension to what is reasonably necessary, and will restore access when the cause is resolved.

5. User Generated Contributions

The Services does not offer users to submit or post content. We may provide you with the opportunity to create, submit, post, display, transmit, perform, publish, distribute, or broadcast content and materials to us or on the Services, including but not limited to text, writings, video, audio, photographs, graphics, comments, suggestions, or personal information or other material (collectively, “Contributions”). Contributions may be viewable by other users of the Services and through third-party websites. When you create or make available any Contributions, you thereby represent and warrant that:

Any use of the Services in violation of the foregoing violates these Legal Terms and may result in, among other things, termination or suspension of your rights to use the Services.

6. Contribution License

You and Services agree that we may access, store, process, and use any information and personal data that you provide and your choices (including settings).

By submitting suggestions or other feedback regarding the Services, you agree that we can use and share such feedback for any purpose without compensation to you.

We do not assert any ownership over your Contributions. You retain full ownership of all of your Contributions and any intellectual property rights or other proprietary rights associated with your Contributions. We are not liable for any statements or representations in your Contributions provided by you in any area on the Services. You are solely responsible for your Contributions to the Services and you expressly agree to exonerate us from any and all responsibility and to refrain from any legal action against us regarding your Contributions.

7. Services Management

We reserve the right, but not the obligation, to: (1) monitor the Services for violations of these Legal Terms; (2) take appropriate legal action against anyone who, in our sole discretion, violates the law or these Legal Terms, including without limitation, reporting such user to law enforcement authorities; (3) in our sole discretion and without limitation, refuse, restrict access to, limit the availability of, or disable (to the extent technologically feasible) any of your Contributions or any portion thereof; (4) in our sole discretion and without limitation, notice, or liability, to remove from the Services or otherwise disable all files and content that are excessive in size or are in any way burdensome to our systems; and (5) otherwise manage the Services in a manner designed to protect our rights and property and to facilitate the proper functioning of the Services.

8. Term and Termination

These Legal Terms shall remain in full force and effect while you use the Services. WITHOUT LIMITING ANY OTHER PROVISION OF THESE LEGAL TERMS, WE RESERVE THE RIGHT TO, IN OUR SOLE DISCRETION AND WITHOUT NOTICE OR LIABILITY, DENY ACCESS TO AND USE OF THE SERVICES (INCLUDING BLOCKING CERTAIN IP ADDRESSES), TO ANY PERSON FOR ANY REASON OR FOR NO REASON, INCLUDING WITHOUT LIMITATION FOR BREACH OF ANY REPRESENTATION, WARRANTY, OR COVENANT CONTAINED IN THESE LEGAL TERMS OR OF ANY APPLICABLE LAW OR REGULATION. WE MAY TERMINATE YOUR USE OR PARTICIPATION IN THE SERVICES OR DELETE ANY CONTENT OR INFORMATION THAT YOU POSTED AT ANY TIME, WITHOUT WARNING, IN OUR SOLE DISCRETION.

If we terminate or suspend your account for any reason, you are prohibited from registering and creating a new account under your name, a fake or borrowed name, or the name of any third party, even if you may be acting on behalf of the third party. In addition to terminating or suspending your account, we reserve the right to take appropriate legal action, including without limitation pursuing civil, criminal, and injunctive redress.

9. Modifications and Interruptions

We reserve the right to change, modify, or remove the contents of the Services at any time or for any reason at our sole discretion without notice. However, we have no obligation to update any information on our Services. We will not be liable to you or any third party for any modification, price change, suspension, or discontinuance of the Services.

We cannot guarantee the Services will be available at all times. We may experience hardware, software, or other problems or need to perform maintenance related to the Services, resulting in interruptions, delays, or errors. We reserve the right to change, revise, update, suspend, discontinue, or otherwise modify the Services at any time or for any reason without notice to you. You agree that we have no liability whatsoever for any loss, damage, or inconvenience caused by your inability to access or use the Services during any downtime or discontinuance of the Services. Except as expressly provided in Section 20 (Service Levels, Security, and Vulnerability Management), nothing in these Legal Terms will be construed to obligate us to maintain and support the Services or to supply any corrections, updates, or releases in connection therewith.

10. Governing Law

These Legal Terms shall be governed by and defined following the laws of California. XTrace Inc. and yourself irrevocably consent that the courts of California shall have exclusive jurisdiction to resolve any dispute which may arise in connection with these Legal Terms.

11. Dispute Resolution

Binding Arbitration

If the Parties are unable to resolve a Dispute through informal negotiations, the Dispute (except those Disputes expressly excluded below) will be finally and exclusively resolved by binding arbitration. YOU UNDERSTAND THAT WITHOUT THIS PROVISION, YOU WOULD HAVE THE RIGHT TO SUE IN COURT AND HAVE A JURY TRIAL. The arbitration shall be commenced and conducted under the Commercial Arbitration Rules of the American Arbitration Association (“AAA”) and, where appropriate, the AAA’s Supplementary Procedures for Consumer Related Disputes (“AAA Consumer Rules”), both of which are available at the American Arbitration Association (AAA) website at http://www.adr.org. Your arbitration fees and your share of arbitrator compensation shall be governed by the AAA Consumer Rules and, where appropriate, limited by the AAA Consumer Rules. The arbitration may be conducted in person, through the submission of documents, by phone, or online. The arbitrator will make a decision in writing, but need not provide a statement of reasons unless requested by either Party. The arbitrator must follow applicable law, and any award may be challenged if the arbitrator fails to do so. Except where otherwise required by the applicable AAA rules or applicable law, the arbitration will take place in California. Except as otherwise provided herein, the Parties may litigate in court to compel arbitration, stay proceedings pending arbitration, or to confirm, modify, vacate, or enter judgment on the award entered by the arbitrator.

If for any reason, a Dispute proceeds in court rather than arbitration, the Dispute shall be commenced or prosecuted in the state and federal courts located in California, and the Parties hereby consent to, and waive all defenses of lack of personal jurisdiction, and forum non convenience with respect to venue and jurisdiction in such state and federal courts. Application of the United Nations Convention on Contracts for the International Sale of Goods and the Uniform Computer Information Transaction Act (UCITA) are excluded from these Legal Terms.

If this provision is found to be illegal or unenforceable, then neither Party will elect to arbitrate any Dispute falling within that portion of this provision found to be illegal or unenforceable and such Dispute shall be decided by a court of competent jurisdiction within the courts listed for jurisdiction above, and the Parties agree to submit to the personal jurisdiction of that court.

Restrictions

The Parties agree that any arbitration shall be limited to the Dispute between the Parties individually. To the full extent permitted by law, (a) no arbitration shall be joined with any other proceeding; (b) there is no right or authority for any Dispute to be arbitrated on a class-action basis or to utilize class action procedures; and (c) there is no right or authority for any Dispute to be brought in a purported representative capacity on behalf of the general public or any other persons.

Exceptions to Arbitration

The Parties agree that the following Disputes are not subject to the above provisions concerning binding arbitration: (a) any Disputes seeking to enforce or protect, or concerning the validity of, any of the intellectual property rights of a Party; (b) any Dispute related to, or arising from, allegations of theft, piracy, invasion of privacy, or unauthorized use; and (c) any claim for injunctive relief. If this provision is found to be illegal or unenforceable, then neither Party will elect to arbitrate any Dispute falling within that portion of this provision found to be illegal or unenforceable and such Dispute shall be decided by a court of competent jurisdiction within the courts listed for jurisdiction above, and the Parties agree to submit to the personal jurisdiction of that court.

12. Corrections

There may be information on the Services that contains typographical errors, inaccuracies, or omissions, including descriptions, pricing, availability, and various other information. We reserve the right to correct any errors, inaccuracies, or omissions and to change or update the information on the Services at any time, without prior notice.

13. Disclaimer

THE SERVICES ARE PROVIDED ON AN AS-IS AND AS-AVAILABLE BASIS. YOU AGREE THAT YOUR USE OF THE SERVICES WILL BE AT YOUR SOLE RISK. TO THE FULLEST EXTENT PERMITTED BY LAW, WE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, IN CONNECTION WITH THE SERVICES AND YOUR USE THEREOF, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. WE MAKE NO WARRANTIES OR REPRESENTATIONS ABOUT THE ACCURACY OR COMPLETENESS OF THE SERVICES’ CONTENT OR THE CONTENT OF ANY WEBSITES OR MOBILE APPLICATIONS LINKED TO THE SERVICES AND WE WILL ASSUME NO LIABILITY OR RESPONSIBILITY FOR ANY (1) ERRORS, MISTAKES, OR INACCURACIES OF CONTENT AND MATERIALS, (2) PERSONAL INJURY OR PROPERTY DAMAGE, OF ANY NATURE WHATSOEVER, RESULTING FROM YOUR ACCESS TO AND USE OF THE SERVICES, (3) ANY UNAUTHORIZED ACCESS TO OR USE OF OUR SECURE SERVERS AND/OR ANY AND ALL PERSONAL INFORMATION AND/OR FINANCIAL INFORMATION STORED THEREIN, (4) ANY INTERRUPTION OR CESSATION OF TRANSMISSION TO OR FROM THE SERVICES, (5) ANY BUGS, VIRUSES, TROJAN HORSES, OR THE LIKE WHICH MAY BE TRANSMITTED TO OR THROUGH THE SERVICES BY ANY THIRD PARTY, AND/OR (6) ANY ERRORS OR OMISSIONS IN ANY CONTENT AND MATERIALS OR FOR ANY LOSS OR DAMAGE OF ANY KIND INCURRED AS A RESULT OF THE USE OF ANY CONTENT POSTED, TRANSMITTED, OR OTHERWISE MADE AVAILABLE VIA THE SERVICES. WE DO NOT WARRANT, ENDORSE, GUARANTEE, OR ASSUME RESPONSIBILITY FOR ANY PRODUCT OR SERVICE ADVERTISED OR OFFERED BY A THIRD PARTY THROUGH THE SERVICES, ANY HYPERLINKED WEBSITE, OR ANY WEBSITE OR MOBILE APPLICATION FEATURED IN ANY BANNER OR OTHER ADVERTISING, AND WE WILL NOT BE A PARTY TO OR IN ANY WAY BE RESPONSIBLE FOR MONITORING ANY TRANSACTION BETWEEN YOU AND ANY THIRD-PARTY PROVIDERS OF PRODUCTS OR SERVICES. AS WITH THE PURCHASE OF A PRODUCT OR SERVICE THROUGH ANY MEDIUM OR IN ANY ENVIRONMENT, YOU SHOULD USE YOUR BEST JUDGMENT AND EXERCISE CAUTION WHERE APPROPRIATE.

THE DISCLAIMERS IN THIS SECTION ARE SUBJECT TO THE EXPRESS COMMITMENTS WE MAKE IN SECTION 20 (SERVICE LEVELS, SECURITY, AND VULNERABILITY MANAGEMENT).

14. Limitations of Liability

IN NO EVENT WILL WE OR OUR DIRECTORS, EMPLOYEES, OR AGENTS BE LIABLE TO YOU OR ANY THIRD PARTY FOR ANY DIRECT, INDIRECT, CONSEQUENTIAL, EXEMPLARY, INCIDENTAL, SPECIAL, OR PUNITIVE DAMAGES, INCLUDING LOST PROFIT, LOST REVENUE, LOSS OF DATA, OR OTHER DAMAGES ARISING FROM YOUR USE OF THE SERVICES, EVEN IF WE HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

15. Indemnification

You agree to defend, indemnify, and hold us harmless, including our subsidiaries, affiliates, and all of our respective officers, agents, partners, and employees, from and against any loss, damage, liability, claim, or demand, including reasonable attorneys’ fees and expenses, made by any third party due to or arising out of: (1) use of the Services; (2) breach of these Legal Terms; (3) any breach of your representations and warranties set forth in these Legal Terms; (4) your violation of the rights of a third party, including but not limited to intellectual property rights; or (5) any overt harmful act toward any other user of the Services with whom you connected via the Services. Notwithstanding the foregoing, we reserve the right, at your expense, to assume the exclusive defense and control of any matter for which you are required to indemnify us, and you agree to cooperate, at your expense, with our defense of such claims. We will use reasonable efforts to notify you of any such claim, action, or proceeding which is subject to this indemnification upon becoming aware of it.

16. User Data

We will maintain certain data that you transmit to the Services for the purpose of managing the performance of the Services, as well as data relating to your use of the Services. Although we perform regular routine backups of data, you are solely responsible for all data that you transmit or that relates to any activity you have undertaken using the Services. You agree that we shall have no liability to you for any loss or corruption of any such data, and you hereby waive any right of action against us arising from any such loss or corruption of such data.

17. Electronic Communications, Transactions, and Signatures

Visiting the Services, sending us emails, and completing online forms constitute electronic communications. You consent to receive electronic communications, and you agree that all agreements, notices, disclosures, and other communications we provide to you electronically, via email and on the Services, satisfy any legal requirement that such communication be in writing. YOU HEREBY AGREE TO THE USE OF ELECTRONIC SIGNATURES, CONTRACTS, ORDERS, AND OTHER RECORDS, AND TO ELECTRONIC DELIVERY OF NOTICES, POLICIES, AND RECORDS OF TRANSACTIONS INITIATED OR COMPLETED BY US OR VIA THE SERVICES. You hereby waive any rights or requirements under any statutes, regulations, rules, ordinances, or other laws in any jurisdiction which require an original signature or delivery or retention of non-electronic records, or to payments or the granting of credits by any means other than electronic means.

18. California Users and Residents

If any complaint with us is not satisfactorily resolved, you can contact the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs in writing at 1625 North Market Blvd., Suite N 112, Sacramento, California 95834 or by telephone at (800) 952-5210 or (916) 445-1254.

19. Miscellaneous

These Legal Terms and any policies or operating rules posted by us on the Services or in respect to the Services constitute the entire agreement and understanding between you and us. Our failure to exercise or enforce any right or provision of these Legal Terms shall not operate as a waiver of such right or provision. These Legal Terms operate to the fullest extent permissible by law. We may assign any or all of our rights and obligations to others at any time. We shall not be responsible or liable for any loss, damage, delay, or failure to act caused by any cause beyond our reasonable control. If any provision or part of a provision of these Legal Terms is determined to be unlawful, void, or unenforceable, that provision or part of the provision is deemed severable from these Legal Terms and does not affect the validity and enforceability of any remaining provisions. There is no joint venture, partnership, employment or agency relationship created between you and us as a result of these Legal Terms or use of the Services. You agree that these Legal Terms will not be construed against us by virtue of having drafted them. You hereby waive any and all defenses you may have based on the electronic form of these Legal Terms and the lack of signing by the parties hereto to execute these Legal Terms.

20. Service Levels, Security, and Vulnerability Management

20.1 Status of this section

This Section 20 states express commitments we make to you. Notwithstanding Sections 9, 13, and 14, and notwithstanding any general disclaimer or exclusion elsewhere in these Legal Terms, the commitments in this Section 20 are binding, and in the event of any conflict this Section 20 prevails.

Nothing in this Section creates a warranty as to the accuracy, completeness, or fitness for purpose of any output the Services generate, which remains governed by Section 13.

20.2 Availability

We will use commercially reasonable efforts to make the Services available on a continuous basis, excluding scheduled maintenance and the exclusions in Section 20.9.

We do not currently offer a numeric uptime commitment or service credits for the Services. Where we agree a numeric availability commitment with you, it will be set out in a signed order form or written agreement, and that agreement governs.

We will give at least forty-eight (48) hours’ advance notice of scheduled maintenance expected to cause an interruption, and will perform it outside 09:00–18:00 United States Pacific Time where reasonably feasible. We may perform emergency maintenance without advance notice where necessary to preserve the security, integrity, or lawful operation of the Services, and will notify affected users as soon as reasonably practicable and in any event within twenty-four (24) hours.

20.3 Support — severity definitions

We classify support issues into four severity levels:

  1. Severity 1. The Services are down, or so severely impaired that routine operation is impossible, and no workaround is available.

  2. Severity 2. The Services are functioning but in a materially degraded or restricted capacity, or a workaround exists but is materially burdensome.

  3. Severity 3. Minor functionality is impaired, or a non-production issue occurs, with limited business impact.

  4. Severity 4. A request for information, documentation, configuration assistance, or a feature request, with no impact on business operations.

We assign the final severity of a ticket, acting reasonably.

20.4 Support — initial response targets

Measured from ticket creation to our first substantive human response, during business hours only.

On paid plans, our initial response targets are:

  1. Severity 1: one (1) business day.

  2. Severity 2: two (2) business days.

  3. Severity 3: three (3) business days.

  4. Severity 4: no target.

Free and other no-charge plans have no initial response target at any severity level.

“Business hours” means 09:00 to 18:00 United States Pacific Time, Monday to Friday, excluding United States federal public holidays. A response target is a target for an initial response only and is not a commitment to resolve within any period.

20.5 Security vulnerability management

We maintain a vulnerability management process covering the Services, our source repositories, and our third-party dependencies. It includes automated dependency vulnerability monitoring, review of vendor and provider security advisories, and triage of vulnerabilities reported to us under Section 20.6.

Severity classification. We classify vulnerabilities using the Common Vulnerability Scoring System (CVSS), adjusted for the exploitability and exposure of the affected component in our environment. A vulnerability that is known to be actively exploited in the wild — including any vulnerability listed in the CISA Known Exploited Vulnerabilities catalog and present in our environment — is treated as Critical regardless of its base score.

Remediation targets. Following confirmation of a vulnerability affecting the Services, we will use commercially reasonable efforts to remediate or mitigate it within the following periods:

  1. Critical (CVSS base score 9.0–10.0): within 7 days of confirmation.

  2. High (CVSS base score 7.0–8.9): within 30 days of confirmation.

  3. Medium (CVSS base score 4.0–6.9): within 90 days of confirmation.

  4. Low (CVSS base score 0.1–3.9): in the next scheduled release; no committed period.

What these targets mean.

  1. “Remediate or mitigate.” A target is met by deploying a fix, or by applying a compensating control that reduces the vulnerability below the applicable severity threshold — for example disabling the affected feature, restricting network exposure, revoking or rotating a credential, or applying a configuration or filtering rule. Where we mitigate rather than remediate, we will pursue full remediation on the timetable for the reduced severity.

  2. The clock runs from confirmation, meaning the point at which we have validated that the vulnerability is genuine and affects the Services — not from the point of first report, publication of an advisory, or internal discovery.

  3. Third-party and managed components. Some components of the Services are operated by third-party providers, including our cloud, database, identity, and model providers. Where remediation requires a fix from such a provider, our commitment is to apply that provider’s fix within the applicable period once it is made available to us, and in the meantime to apply mitigations within our control.

  4. Where a target cannot be met, we will apply available mitigations, document the reason and the remediation plan, and, where the vulnerability is Critical or High and materially affects the security of your data, inform you.

  5. These are commitments as to process and effort. They are not a warranty that the Services are or will be free of vulnerabilities.

Change management. Changes to production, including security patches, are subject to our change management process. Emergency security changes may be deployed outside the standard process where necessary to remediate a Critical vulnerability, and are recorded and reviewed after the fact.

20.6 Reporting a vulnerability

Report suspected security vulnerabilities to security@xtrace.ai. Please include enough detail to reproduce the issue.

Our commitments to you. We will acknowledge your report within three (3) business days, provide an initial assessment including our severity classification within ten (10) business days, keep you informed of remediation progress at reasonable intervals, and tell you when the issue is resolved. We will credit you publicly if you wish.

Safe harbour. If you make a good-faith effort to comply with this Section while researching and reporting a vulnerability, we will not pursue or support legal action against you in relation to that research, and we will treat your activity as authorized under the Computer Fraud and Abuse Act and comparable laws and as not a breach of Section 4. To stay within this safe harbour you must:

  1. give us reasonable time to remediate before disclosing publicly or to any third party;

  2. make a good-faith effort to avoid privacy violations, degradation of the Services, disruption to other users, and destruction or alteration of data;

  3. access, and copy, only the minimum amount of data necessary to demonstrate the vulnerability, delete it as soon as it is no longer needed, and tell us immediately if you encounter any personal data;

  4. not use social engineering, physical attacks, denial-of-service testing, spam, or automated scanning that generates significant load, and not test against any account or data other than your own or an account you have permission to test; and

  5. comply with all applicable laws.

We do not currently operate a paid bug bounty programme. This safe harbour does not extend to testing against our third-party providers, whose own policies apply.

20.7 Security incident notification

We will notify you without undue delay, and in any event within seventy-two (72) hours, after confirming a security incident that has resulted in the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to your data held by us.

The notification will describe, to the extent known and in phases as information becomes available: the nature of the incident, the categories and approximate volume of data concerned, the likely consequences, the measures taken or proposed to address it, and a point of contact. We will provide reasonable cooperation and information to enable you to meet any notification obligation of your own. A notification is not, and will not be construed as, an acknowledgement of fault or liability.

20.8 Security measures and certifications

We maintain a written information security programme with administrative, technical, and physical safeguards appropriate to the nature of the data processed, and will not materially degrade the overall level of security of the Services during a paid subscription term. Those measures currently include: encryption of data in transit using industry-standard transport-layer security; encryption of data at rest at the storage layer of our cloud and managed-database providers; application-layer encryption of third-party credentials and OAuth tokens; storage of machine credentials in hashed rather than recoverable form; logical tenant separation enforced at the application and database layer; role-based access control administered by you; server-side request filtering for user-supplied URLs; secrets management for production credentials with rotation on suspected compromise; and audit logging of security-relevant actions.

Tenant isolation is enforced at the application and database layer. We do not claim cryptographic or infrastructure-level isolation between tenants, and we do not provide client-side, end-to-end, or homomorphic encryption of your data. Your data is processed by us, and by the third-party model providers we use, in unencrypted form.

We do not currently hold a SOC 2, ISO/IEC 27001, HIPAA, or PCI DSS certification, report, or attestation, and make no representation that we do. We design our controls with reference to the AICPA SOC 2 Trust Services Criteria and will make any report available under a non-disclosure agreement once completed.

We may update the measures described in this Section provided we do not materially reduce the overall level of security.

20.9 Exclusions

No commitment in Sections 20.2 to 20.5 applies to any unavailability, degradation, or delay that: (a) arises from factors outside our reasonable control, including internet, DNS, routing, or network failures beyond the point at which we maintain access and control, denial-of-service attacks, and force majeure events; (b) results from an act or omission of you, an Authorized User, or anyone using your credentials, including misconfiguration, credential revocation, or exhaustion of a plan limit; (c) results from your equipment, software, network, browser, or client library version; (d) results from use of the Services other than in accordance with these Legal Terms; (e) occurs during scheduled or emergency maintenance under Section 20.2; (f) affects a free, trial, evaluation, sandbox, beta, preview, or experimental plan or feature, all of which are provided on a best-effort basis without commitment; or (g) originates in a third-party service you have connected to the Services, or in a third-party cloud, infrastructure, or model provider, where we cannot route around the failure.

20.10 Security contact

Please direct enquiries to the following addresses:

  1. Security and vulnerability reports: security@xtrace.ai

  2. Support requests and severity escalation: support@xtrace.ai

  3. All other matters: admin@xtrace.ai


21. Contact Us

In order to resolve a complaint regarding the Services or to receive further information regarding use of the Services, please contact us at: admin@xtrace.ai