ZeroGrantZEROGRANT

Legal

ZeroGrant Terms of Service

These Terms govern access to and use of the ZeroGrant website, API, SDKs, dashboard, sandbox, and documentation.

Operated by
Neuroclusive, Inc.
Last updated
2026-07-28
Version
1.0
Applies to
zerogrant.io, the ZeroGrant API, SDKs, dashboard, sandbox, and documentation (together, the "Service")

Section 1

Agreement to these Terms

These Terms of Service ("Terms") form a binding agreement between you ("you", "Customer") and Neuroclusive, Inc. governing your access to and use of the Service.

By registering for an account, generating API keys, integrating the SDKs, or otherwise using the Service, you accept these Terms. If you are entering into these Terms on behalf of an organisation, you represent that you have authority to bind that organisation, and "you" refers to that organisation.

If you do not agree to these Terms, do not use the Service.

Your use of the Service is also governed by the Privacy Policy and, where you process personal data through the Service, the Data Processing Addendum ("DPA"). In the event of conflict between these Terms and the DPA regarding the processing of personal data, the DPA prevails.

Section 2

The Service, in plain terms

ZeroGrant provides a cryptographic authority and delegated-access infrastructure implementing the Sovereign Delegated Access and Revocation Chain ("SDARC") protocol. In ordinary use:

  1. the owner of the underlying data or resource remains in control of whether authority exists;
  2. you, the Customer, integrate the Service into your application to request scoped, purpose-bound, time-limited authority to perform defined operations;
  3. ZeroGrant verifies live authority and returns only the permitted result to your application.

Owner-controlled authority. The Service is designed so that ZeroGrant cannot, by itself, create owner authority or use owner-controlled resources outside a live grant. This architectural property is described further in the Privacy Policy and DPA. It is a description of the system's design and is not a warranty that any system is incapable of compromise (see Section 8).

Sandbox. The sandbox environment is provided for development and testing. It does not charge and must not be used to process real personal data or production workloads. Data and behaviour in the sandbox may be reset or deleted at any time.

We may modify, add, or remove features of the Service. We will give reasonable notice of material adverse changes to production functionality where practicable.

Section 3

Roles and legal responsibility

Purpose of this Section. The SDARC architecture separates the owner, Customer, and ZeroGrant roles. This Section describes how legal responsibility is allocated between those roles. The allocation reflects who controls each decision about processing.

The Owner (control of the resource). The owner decides whether, to whom, for what purpose, and for how long any access is granted. As between the parties, the owner is the source of authority for every approved operation. No operation occurs over the owner's resource without live, owner-authorised permission.

The Customer (delegated authority - data controller for its processing). You determine the purposes and means of the processing your application carries out using the Service: which claims you request, for what stated purpose, on what lawful basis, for how long, and how you handle results returned to you. Accordingly, for personal data you process through the Service, you act as the data controller (or, where you process on behalf of your own customer, as controller or processor as the facts determine), and you are responsible for that processing, including:

  1. establishing and documenting a lawful basis for each request;
  2. providing all notices and obtaining all consents required from data subjects and owners;
  3. honouring data-subject and owner rights in respect of data and results within your control;
  4. the security, retention, and lawful use of any result, proof, or derived output your application receives and stores; and
  5. your own compliance with applicable data-protection, employment, financial, health, identity-verification, and sector-specific law.

ZeroGrant (infrastructure - processor, and controller only for limited operational data). In providing the Service, ZeroGrant acts as your processor in respect of personal data processed on your instructions through the Service, as set out in the DPA. ZeroGrant acts as an independent controller only for the limited operational data it determines the purposes and means of, for example account and billing data, security logs, and service telemetry, as described in the Privacy Policy.

Responsibility follows control. The parties intend that legal responsibility for processing tracks actual control over the relevant authority and decisions: the owner controls whether access exists at all; the Customer controls the purpose and means of its processing and is the controller of it; and ZeroGrant controls only the operational running of the infrastructure and the limited operational data described in the Privacy Policy.

You are responsible for your owners and end users. Where your application onboards owners or end users, you are responsible for your relationship with them, for the accuracy of what you tell them about how their data is used, and for ensuring your instructions to the Service are lawful. ZeroGrant has no direct contractual relationship with your owners or end users through your use of the Service unless separately agreed.

Section 4

Accounts, keys, and security

You must provide accurate registration information and keep it current.

API keys. You are responsible for all activity under your account and API keys. Secret keys must be kept on your server and never exposed in a browser or public client. Publishable keys are for client-side use only. You must rotate keys you believe may be compromised and notify us without undue delay of any suspected compromise of your account or keys.

Owner recovery. Owner authority credentials are controlled by the owner and are not recoverable by ZeroGrant. You acknowledge that if an owner loses all recovery material, the affected authority may be permanently unrecoverable by design, and neither you nor ZeroGrant can restore it. You are responsible for communicating this to owners where your application initiates owner onboarding.

You must not attempt to circumvent the Service's authority checks, rate limits, or security controls, or use the Service to do so against any third party.

Section 5

Acceptable use

You must not use the Service to:

  1. violate any applicable law or regulation, or infringe the rights of any person;
  2. process personal data without a valid lawful basis and required consents;
  3. upload or process content that is unlawful, or that you are not authorised to process;
  4. attempt to derive, reconstruct, or exfiltrate raw underlying data beyond the scope of a granted, live authority;
  5. probe, scan, or test the vulnerability of the Service except under a program we expressly authorise in writing;
  6. build a competing protocol or service by copying the Service, or reverse-engineer it except to the extent that restriction is prohibited by law; or
  7. misrepresent to owners or data subjects what data is processed or how.

We may suspend access without prior notice where we reasonably believe your use poses a security risk, is unlawful, or materially breaches these Terms, and will restore access promptly once the issue is resolved where appropriate.

Section 6

Fees

Paid plans are billed as described at zerogrant.io/pricing or in an order form. The sandbox is free.

Fees are exclusive of taxes, which you are responsible for except for taxes on our income.

Late amounts may accrue interest at the maximum rate permitted by applicable law, and we may suspend paid features for non-payment after reasonable notice.

Except as required by law or expressly stated, fees are non-refundable.

Section 7

Intellectual property

The Service, SDARC protocol implementation, SDKs, documentation, and all related intellectual property are owned by Neuroclusive, Inc. and its licensors. Nothing transfers ownership to you.

We grant you a non-exclusive, non-transferable, revocable licence to use the SDKs and API during the term, solely to integrate and use the Service in accordance with these Terms and the documentation.

You retain all rights in your application and in your data. You grant us only the limited rights necessary to provide, secure, and improve the Service, and to meet legal obligations, as described in the Privacy Policy and DPA.

If you give us feedback, we may use it without restriction or obligation to you.

"ZeroGrant", "SDARC", and associated marks are ours. You may not use them except to accurately describe your integration, and not in a way that implies endorsement without our written permission.

Section 8

Warranties and disclaimers

We will provide the Service with reasonable skill and care.

No absolute-security warranty. You acknowledge that the Service's security properties, including owner-controlled authority, bounded outputs, and restore-proof revocation, describe the system's design and intended operation. We do not warrant that the Service, or any system, is unhackable, error-free, or immune to compromise, and we make no such claim. No cryptographic system can recall data that has already been disclosed to, and retained by, a recipient.

Except as expressly stated and to the fullest extent permitted by law, the Service is provided "as is" and we disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose, and non-infringement.

Nothing in these Terms excludes or limits liability that cannot lawfully be excluded, including for death or personal injury caused by negligence, fraud, or fraudulent misrepresentation.

Section 9

Limitation of liability

Subject to Section 8.4, and to the fullest extent permitted by law:

  1. neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for loss of profits, revenue, goodwill, or anticipated savings, however arising;
  2. our total aggregate liability arising out of or related to the Service in any 12-month period is limited to the fees you paid or were required to pay us for the Service in that period.

Allocation of responsibility. The limitations in this Section reflect the allocation of roles in Section 3. You remain responsible for your own processing as controller, for your lawful basis and consents, and for your handling of results your application receives and stores. ZeroGrant is not liable for loss arising from your processing decisions, your unlawful instructions, your retention or misuse of results, or an owner's loss of their own root authority.

The limitations apply in aggregate across both these Terms and the DPA and do not stack, except where mandatory data-protection law provides otherwise for data-subject claims.

Section 10

Indemnity

You will defend and indemnify Neuroclusive, Inc. against third-party claims, and resulting losses, arising from (a) your use of the Service in breach of these Terms or applicable law, (b) your processing of personal data, including your lawful basis, notices, and consents, (c) your application and content, or (d) your handling, retention, or disclosure of results the Service returned to you.

We will defend and indemnify you against third-party claims that the Service, used in accordance with these Terms, infringes that third party's intellectual property rights, subject to the liability limits in Section 9 and to customary conditions (prompt notice, our control of defence, your cooperation).

Section 11

Term, suspension, and termination

These Terms apply while you use the Service.

Either party may terminate for material breach not cured within 30 days of notice. You may stop using the Service and close your account at any time.

On termination, your licence ends and you must stop using the Service. Provisions that by their nature survive, including Sections 3, 7, 8, 9, 10, and 12, survive.

Data handling on termination is governed by the Privacy Policy and DPA, including return or deletion of personal data we process on your behalf.

Section 12

General

Applicable law. These Terms are governed by the law applicable to the agreement between you and Neuroclusive, Inc. Any dispute must be brought before a court with lawful jurisdiction. Nothing in these Terms limits mandatory consumer or data-protection rights.

Changes. We may update these Terms. For material changes we will give reasonable notice by email or in-product. Continued use after the effective date constitutes acceptance.

Assignment. You may not assign these Terms without our consent. We may assign to an affiliate or in connection with a merger, acquisition, or sale of assets.

Entire agreement. These Terms, the Privacy Policy, the DPA, and any order form are the entire agreement and supersede prior agreements on their subject matter.

Severability and waiver. If any provision is unenforceable, the rest remains in effect. Failure to enforce is not a waiver.

Notices. Legal notices to us must be sent to legal@neuroclusive.com. Notices to you will be sent using the contact details on your account.

Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control.