Truvant
Compare Case Studies ▾
Plugin Supply Chain Attack
How marketplace plugins hijack dependencies
Rogue AI Database Deletion
How an AI agent wiped a production database
Malicious Package Registry
How the reputation registry blocks known threats
Pricing About GitHub Docs Login

Terms of Service

Last Updated: February 5, 2026

These Terms of Service ("Terms") govern your access to and use of the products and services provided by Truvant ("Truvant," "we," "us," or "our"), including the Truvant command-line tool, the Trust Intelligence Service, the management console, and the truvant.ai website (collectively, the "Service").

By creating an account, installing the CLI, or using any part of the Service, you agree to these Terms. If you are using the Service on behalf of an organization, you represent that you have the authority to bind that organization to these Terms.


1. Service Description

Truvant is a security platform for AI agent extensions built on the Model Context Protocol (MCP). The Service consists of two primary components:

Truvant CLI — A locally-installed command-line tool that scans MCP servers, skills, plugins, and container images for vulnerabilities, secrets, and risky configurations. The CLI performs scanning locally on your machine and enforces security policies on MCP server installations and AI agent command execution.

Trust Intelligence Service — A cloud-hosted service at trust.truvant.ai that provides credibility scores for remote MCP endpoints, fleet-wide visibility through a management console, organization-level policy management, and an AI-powered research agent for endpoint analysis.


2. Account Registration

To use features beyond local scanning, you must create an account. You agree to:

  • Provide accurate and complete registration information
  • Keep your authentication credentials secure
  • Notify us promptly if you suspect unauthorized access to your account
  • Accept responsibility for all activity under your account

We support authentication through OIDC-compliant identity providers (Google Workspace, Okta, Azure AD/Entra ID, Auth0, OneLogin, Keycloak, and others). You are responsible for the security of your identity provider configuration.


3. Service Tiers and Pricing

3.1 Tiers

We offer three service tiers:

Tier Price Includes
Starter Free CLI scanning, local policy enforcement, community support
Team $10 per seat per month Everything in Starter, plus Trust Intelligence Service, management console, organization-level policies, fleet monitoring, priority support
Enterprise Custom pricing Everything in Team, plus custom integrations, dedicated support, SLA commitments, SSO configuration assistance

3.2 Seat Definition

A "seat" is a named user within your organization who is authorized to access the Service. Each individual who authenticates to the Service or is assigned to your organization counts as one seat. Seats are not transferable between individuals but may be reassigned when an individual leaves your organization.

3.3 Free Trial

New Team tier subscriptions include a 30-day free trial. During the trial period:

  • You have full access to all Team tier features
  • No payment information is required to start the trial
  • At the end of the 30-day period, your account will automatically downgrade to the Starter tier unless you enter payment information and convert to a paid subscription
  • Data created during the trial (policies, scan history, trust scores) will be retained for 30 days after downgrade, then deleted
  • Trial eligibility is limited to one trial per organization

3.4 Payment Terms

For paid tiers:

  • Billing is monthly in arrears, charged to the payment method on file
  • All fees are in US dollars and exclusive of applicable taxes
  • You are responsible for all taxes associated with your use of the Service (excluding taxes on our net income)
  • Failed payments will result in a 7-day grace period, after which your account may be downgraded to the Starter tier

3.5 Pricing Changes

We may change our pricing with at least 30 days' advance written notice (sent to the email address associated with your account). Price changes will take effect at the start of your next billing cycle after the notice period. If you do not agree to a price change, you may cancel your subscription before the change takes effect.


4. Acceptable Use

You agree to use the Service only for lawful purposes and in accordance with these Terms. Specifically, you agree NOT to:

  • Use the Service to attack, compromise, or exploit systems you do not own or have authorization to test. Truvant is a defensive security tool. Using scan results, trust intelligence, or any other output of the Service to identify and exploit vulnerabilities in third-party systems is strictly prohibited.
  • Reverse engineer, decompile, or disassemble any part of the Service, except to the extent expressly permitted by applicable law that cannot be waived by contract.
  • Circumvent or disable security features of the Service, including policy enforcement mechanisms, authentication requirements, or rate limiting.
  • Share account credentials or allow multiple individuals to use a single seat.
  • Use the Service to develop a competing product by systematically extracting trust scores, scan methodologies, or detection rules.
  • Interfere with or disrupt the Service or the servers and networks connected to the Service.
  • Submit false or misleading information to the Trust Intelligence Service, including fabricated MCP endpoint metadata.
  • Exceed reasonable usage limits as determined by your service tier. We will notify you before taking action on usage concerns.

We reserve the right to suspend or terminate accounts that violate these restrictions.


5. Data Handling

5.1 What We Collect

We collect the following categories of data:

  • Account information: Email address, name, organization name, identity provider metadata
  • Scan metadata: Package names, versions, risk scores, finding summaries, and timestamps for scans processed through the Trust Intelligence Service. This does not include your source code.
  • Trust intelligence data: Remote MCP endpoint URLs, trust scores, TLS configurations, and publisher information submitted for analysis
  • Usage data: Feature usage, CLI version, operating system, error reports
  • Policy configuration: Organization-level security policies and command rules you define
  • Audit logs: Command execution decisions (allowed/blocked), timestamps, and matched policy rules reported through the agent

5.2 What We Do NOT Collect

  • Source code: The CLI performs scanning locally on your machine. Source code, file contents, and repository contents are never transmitted to our servers.
  • Credentials: We do not store your identity provider passwords or tokens beyond what is necessary for session authentication.
  • Command output: The command interception shim logs decisions locally. Command output is not transmitted to our servers.

5.3 How We Use Data

We use the data we collect to:

  • Provide, maintain, and improve the Service
  • Generate trust scores and security assessments
  • Enforce your organization's security policies
  • Detect and prevent abuse of the Service
  • Communicate with you about your account and the Service

For more details, see our Privacy Policy.


6. Intellectual Property

6.1 Our IP

The Service, including the CLI, Trust Intelligence Service, management console, detection rules, scoring algorithms, and all related documentation, is owned by Truvant and protected by applicable intellectual property laws. These Terms do not grant you any ownership rights in the Service.

6.2 Your Data

You retain ownership of all data you submit to or generate through the Service, including your security policies, organizational configurations, and scan results. We claim no ownership over your data.

6.3 License to Use

Subject to these Terms, we grant you a limited, non-exclusive, non-transferable, revocable license to use the Service during your subscription period in accordance with your service tier.

6.4 Feedback

If you provide us with feedback, suggestions, or ideas about the Service, we may use that feedback without restriction or obligation to you.


7. Termination

7.1 Termination by You

You may cancel your subscription at any time through your account settings or by contacting us at mike@truvant.ai. Cancellation takes effect at the end of your current billing period. You will not receive a refund for partial billing periods.

7.2 Termination by Us

We may suspend or terminate your access to the Service:

  • Immediately if you breach Section 4 (Acceptable Use) or engage in activity that threatens the security or integrity of the Service
  • With 30 days' notice for any other reason, including discontinuation of the Service

7.3 Effect of Termination

Upon termination:

  • Your right to access the Trust Intelligence Service and management console ends immediately (or at the end of your billing period for voluntary cancellations)
  • The CLI will continue to function for local scanning without cloud features
  • You may request export of your data for 30 days following termination
  • We will delete your data within 90 days of termination, except as required by law or our data retention policies

8. Warranty Disclaimer

THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY. We specifically disclaim all implied warranties of merchantability, fitness for a particular purpose, and non-infringement.

Without limiting the foregoing:

  • We do not warrant that the Service will identify all security vulnerabilities, threats, or risks in MCP servers, plugins, skills, or remote endpoints
  • Trust scores and risk assessments are informational and should not be your sole basis for security decisions
  • We do not guarantee uninterrupted or error-free operation of the Service
  • Security scanning results may contain false positives or false negatives

You acknowledge that no security tool provides absolute protection and that you remain responsible for your organization's security posture.


9. Limitation of Liability

9.1 Exclusion of Damages

TO THE MAXIMUM EXTENT PERMITTED BY LAW, Truvant WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, including but not limited to loss of profits, data, business opportunities, or goodwill, regardless of the cause of action or the theory of liability, even if we have been advised of the possibility of such damages.

9.2 Cap on Liability

OUR TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE WILL NOT EXCEED THE GREATER OF (A) THE AMOUNTS YOU PAID TO US IN THE 12 MONTHS PRECEDING THE CLAIM, OR (B) ONE HUNDRED US DOLLARS ($100).

9.3 Exceptions

The limitations in this section do not apply to (a) either party's indemnification obligations, (b) either party's breach of confidentiality obligations, or (c) your breach of Section 4 (Acceptable Use).


10. Indemnification

You agree to indemnify, defend, and hold harmless Truvant and its officers, directors, employees, and agents from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising from:

  • Your use of the Service in violation of these Terms
  • Your violation of any third party's rights
  • Your use of scan results or trust intelligence to attack or exploit systems

11. Dispute Resolution

11.1 Governing Law

These Terms are governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, without regard to conflict of laws principles.

11.2 Jurisdiction

Any disputes arising from these Terms that are not resolved informally will be resolved in the courts located in Toronto, Ontario, Canada, and you consent to personal jurisdiction in those courts.

11.3 Informal Resolution First

Before filing any claim, you agree to attempt to resolve the dispute informally by contacting us at legal@truvant.ai. We will attempt to resolve the dispute within 30 days.


12. General Provisions

12.1 Changes to Terms

We may update these Terms from time to time. We will provide notice of material changes by email or through the Service at least 30 days before they take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Terms.

12.2 Entire Agreement

These Terms, together with the Privacy Policy and any applicable Enterprise Agreement or Order Form, constitute the entire agreement between you and Truvant regarding the Service.

12.3 Severability

If any provision of these Terms is held to be unenforceable, the remaining provisions will continue in full force and effect.

12.4 Waiver

Our failure to enforce any provision of these Terms does not constitute a waiver of that provision.

12.5 Assignment

You may not assign your rights under these Terms without our prior written consent. We may assign our rights without restriction.

12.6 Notices

Notices to you will be sent to the email address associated with your account. Notices to us should be sent to legal@truvant.ai.


13. Contact Us

If you have questions about these Terms, contact us at:

Truvant
Email: legal@truvant.ai
Website: https://truvant.ai

GitHub Documentation Privacy Policy Terms of Service Contact

© 2026 Truvant. All rights reserved.