Public service agreement
Terms, acceptable use & privacy
A readable contract for Cortex, the public sandbox, automated agents and licensed Enterprise access. It protects the blackbox and the platform without changing the assurance written on a result.
Your work
Your inputs remain yours. Outputs may be used lawfully, subject to assurance and third-party rights.
Our boundary
Interfaces and effects are public. Proprietary engine and runtime methods remain protected.
Published research
Truthful, reproducible benchmarks are welcome when conditions, assurance and limitations are disclosed.
1. Agreement and eligibility
These Terms of Service ("Terms") are a binding agreement between you, or the organisation you represent, and Zenith Flow Innovations LLC, a United States limited liability company with its principal office in Palo Alto, California, which operates HexStellar ("HexStellar", "we", "us").
You accept these Terms when you create an account, affirm the acceptance control in a registration flow, install or use a HexStellar client, use the public sandbox, submit a request to the API, or otherwise access the Service. If you do not agree, do not use the Service.
If you act for an organisation, you represent that you have authority to bind it. You must be at least 18 years old, or the age of legal majority where you live, and legally capable of entering this agreement.
The version recorded when an account is created is the version accepted for that account. Material revisions will be identified by a new effective date and communicated where applicable.
2. The Service and its boundaries
HexStellar has two related execution surfaces. Cortex is the hosted agent-first service for formulation, analysis, execution and verification; supported computations run with HexStellar acceleration on HexStellar-managed infrastructure. Enterprise Low-Energy Runtime & Acceleration is the separately licensed, customer-deployed runtime for compatible compute paths. Enterprise access, scope and evidence are governed by a separate licence, NDA and, where applicable, order form.
A result may be certified, heuristic, operational, recorded, unverified or an abstention. The label and receipt returned with that particular result control. More effort does not convert a heuristic result into a proof, and a service recheck is not automatically a formal proof or an independent domain validation.
Examples, documentation, prompts and suggested mappings are educational transfer recipes. They illustrate ways to formulate a problem, but they are not warranties, professional advice, complete domain models or promises that a differently scaled or adapted problem will produce the same result.
You are responsible for the problem formulation, source data, assumptions, downstream validation and decisions made from an output. Do not use the Service as the sole basis for decisions affecting life, health, legal rights, public safety, regulated eligibility, weapons, or critical infrastructure.
3. Accounts, agents and credentials
Registration information must be accurate and current. Accounts, access rights and promotional allowances may not be sold, shared between unrelated parties, transferred or multiplied to evade a limit.
API keys, tokens, signed links and Enterprise licence material are credentials. Keep them confidential, give each automated agent the minimum scope it needs, and revoke a credential promptly if it may have been exposed.
You are responsible for activity initiated by your employees, contractors, scripts, applications and autonomous agents, including repeated requests and compute consumption. Use validation, estimation, idempotency and compute-budget controls before authorising paid or consequential work.
Email verification, rate limits, quotas, admission controls and risk checks are conditions of access. They do not create an entitlement to continued service or a guarantee that a request will be accepted.
4. Security research and platform protection
Do not conduct or commission penetration testing, vulnerability scanning, fuzzing, stress or load testing, denial-of-service testing, credential testing, adversarial probing or security-control evaluation against the Service without prior written authorisation from HexStellar that identifies the systems, methods and dates in scope.
Do not bypass or evade authentication, authorisation, metering, quotas, rate limits, admission controls, abuse controls or technical restrictions. Do not obtain another user's data, interfere with another user, introduce malicious code, or probe non-public infrastructure or interfaces.
A contractual restriction is not a statement that every breach is a crime. We may nevertheless suspend access, block abusive traffic, preserve relevant evidence and cooperate with lawful process where we reasonably believe activity threatens the Service, customers or third parties.
If you encounter a suspected vulnerability without prohibited testing, stop, do not access or retain data that is not yours, and report the minimum necessary details to [email protected]. No public bug-bounty or security-testing safe harbour exists unless HexStellar provides written authorisation for the specific activity.
You are responsible for reasonable investigation, containment, restoration and notification costs caused by your intentional prohibited activity, your material breach of this section, or credentials you failed to protect, to the extent permitted by law.
5. Acceptable use and high-risk restrictions
You may use the Service only for lawful purposes and only with data, systems and decisions you are authorised to process. You must comply with applicable privacy, intellectual-property, employment, consumer-protection, safety, sector-specific and data-localisation laws.
You must not use the Service to harm or threaten people; develop, target, operate or control weapons intended to injure people; conduct unlawful surveillance; exploit or discriminate against protected or vulnerable people; facilitate malware, fraud or credential theft; interfere with critical infrastructure; or evade a legal or technical safeguard.
You must not automate account creation, conceal a material identity, use disposable identities to obtain repeated allowances, resell public access, operate an unauthorised service bureau, or use the Service to violate another party's rights.
You may not remove or falsify a receipt, assurance label, limitation, provenance field or attribution in a way that misrepresents what HexStellar returned. You may not describe a best-known, heuristic or recorded result as formally proven.
6. Export controls and sanctions
You represent that neither you nor the people or entities controlling your use are prohibited from receiving the Service under applicable United States export-control or sanctions laws, and that you will not provide access to a restricted party or for a prohibited end use.
Restrictions change over time. You are responsible for checking applicable government lists and licensing requirements, including those administered by the U.S. Department of the Treasury Office of Foreign Assets Control and the U.S. Department of Commerce Bureau of Industry and Security, rather than relying on a static country list in these Terms.
We may refuse, suspend or terminate access where reasonably necessary for sanctions, export-control, legal-process or national-security compliance. Nothing in the Service is an export licence or legal determination for your transaction.
7. Benchmarks, research and public claims
Independent benchmark publication is permitted when access is lawful and the report is truthful, reproducible and not designed to reveal proprietary implementation. You do not need permission merely to publish a fair account of ordinary authorised use.
A public benchmark must identify the date, public client and service/model version, input or licensed source, relevant hardware and execution context, effort, metric and denominator, assurance label, correctness check, limitations and any transformation from the original benchmark. It must distinguish official instances from inspired or synthetic instances and must not imply HexStellar endorsement.
You must not evade limits, perform prohibited security testing, reverse engineer, use confidential or NDA material, publish credentials or personal data, interfere with other users, or omit conditions in a way that makes a result materially misleading. Comparative claims must use equivalent inputs, constraints and measurement methods.
We may reproduce a published claim, request the stated artefacts, or publish a correction. Refusal to provide artefacts is not by itself a breach, but an unreproducible result may not be represented as independently verified by HexStellar.
8. Intellectual property and blackbox boundary
The Service is licensed, not sold. HexStellar and its licensors retain all right, title and interest in the engine, runtime, software, models, architecture, documentation, branding, compiled artefacts, receipts and other proprietary technology, including trade-secret, patent, copyright and trademark rights.
You may not reverse engineer, decompile, disassemble, extract, reconstruct or derive non-public source code, algorithms, models, data structures, internal methods or protective mechanisms, except only to the limited extent a non-waivable law expressly permits despite this restriction.
The public CLI exposes supported inputs, outputs, safeguards and assurance contracts. It does not license the proprietary engine or runtime implementation. No output, benchmark, access credential or Enterprise evaluation transfers ownership of that implementation.
You may not use confidential observations, non-public artefacts or access obtained under NDA to build or materially assist a competing implementation. Ordinary lawful use of public outputs does not, by itself, grant us ownership of your independent work.
9. Inputs, outputs and feedback
As between you and HexStellar, you retain your rights in data and problem descriptions you submit. You grant us the limited rights needed to receive, process, transmit, secure, support and bill the request, enforce these Terms, and comply with law.
Subject to these Terms and third-party rights, you may use outputs for lawful internal, commercial, educational and research purposes. Outputs may be non-unique, incomplete or unsuitable for a particular legal, scientific, safety or patent purpose; no output is a representation that its use is non-infringing, patentable or independently valid.
Do not include secrets, credentials, payment-card data, regulated health data or unnecessary personal data in a problem payload. You are responsible for permissions, notices and lawful bases required for the data you submit.
If you voluntarily provide product feedback or a capability request, you grant us a perpetual, worldwide, royalty-free right to use it without an obligation to implement, attribute or compensate, but this does not transfer ownership of your problem data or confidential information.
10. Compute, plans and payment
Compute units are service-metering units, not currency or stored monetary value. Pricing, allowances, rate limits and command availability may differ by plan and may change prospectively. The live pricing and capability endpoints control over examples or cached documentation.
Validation and estimation may be offered without charge. A solve may consume compute units according to command, size and effort. Where supported, failed delivery is adjusted or refunded under the live ledger policy; a retry must use the documented idempotency contract to avoid unintended duplicate work.
The public sandbox is a revocable evaluation facility with separate limits and a rotatable shared credential. It is not an account, service-level commitment, production environment or guarantee of anonymous access. Security and abuse metadata may still be processed.
You must honour backpressure, Retry-After responses, budgets and concurrency limits. Free or promotional access may be modified or withdrawn, and Enterprise capacity is available only under an issued licence rather than a publicly stated allowance.
11. Enterprise licence and early access
Enterprise Low-Energy Runtime & Acceleration is available only for approved evaluation or deployment under a separately issued licence and, where required, an NDA, order form, data-processing addendum or security schedule. A request for access does not create approval or a licence.
Unless the live Enterprise manifest states otherwise, there is no public runtime download, automatic approval, public setup or public activation. Any demonstration, benchmark or customer evaluation is limited to the identified hardware, workload, correctness scope, denominator and date.
The hosted Cortex service uses HexStellar acceleration on HexStellar-managed infrastructure. That does not grant you a customer-deployed runtime licence. Conversely, an Enterprise runtime licence does not expand Cortex commands or guarantee a performance or energy result for every workload.
For an Enterprise customer, the signed order form, Enterprise licence, NDA, data-processing addendum and security schedule prevail over these public Terms only for a direct conflict within their stated scope.
12. Privacy, retention and service records
We process account, authentication, billing, device, request and security information needed to operate, protect and improve the Service. The data collected depends on the plan and feature used. We do not claim ownership of your problem payload.
The public CLI enables bounded product reports by default so an automated agent may submit a reproducible error, verification gap, documentation issue, capability request or positive result without interrupting you for each report. The CLI removes raw problem and answer payloads, prompts and conversations, credentials, signed links and fields identified as personal or confidential before transmission; the Service applies a second redaction boundary. You may inspect a report without sending it with `hexstellar report create --dry-run`, check the policy with `hexstellar report status`, or disable voluntary reports at any time with `hexstellar report off`.
Disabling voluntary product reports does not disable the minimum account, authentication, billing, abuse-prevention, security and operational records required to provide and protect the Service. Reports should contain only the minimum technical signal needed to reproduce or understand the issue. Do not place personal data, confidential business data, raw prompts, problem payloads, answers, credentials or third-party secrets in a report.
For the anonymous Sandbox and Free plan, the exact solve request and the exact response or error may be encrypted and retained in the active service for up to 14 days for launch evaluation, debugging, reproducibility and service improvement, then removed by the scheduled retention process. Do not submit secrets or personal data that are not required by the problem. Enterprise solve-payload retention is governed by the issued licence terms; a Zero Data Retention configuration excludes solve inputs and results but does not eliminate account, device, licence, billing or minimum security records.
We use Statcounter on customer-facing HexStellar websites to understand aggregate traffic such as pages visited, referring source, approximate location, and device or browser type. Statcounter may use cookies or similar technologies to distinguish visits. The private administrative console at admin.hexstellar.com is excluded from this analytics code. We do not sell this analytics data; Statcounter processes it under its own privacy policy.
We retain different categories only as long as reasonably necessary for the stated purpose, contractual commitments, dispute resolution, security, fraud prevention and law. We may disclose information to service providers acting for us, with your direction, to protect rights and safety, or when required or permitted by valid law and process.
Where privacy law applies, you may have rights to know or access, correct, delete, restrict or object to processing, and receive non-discriminatory treatment for exercising a right. Some records may be retained where legally permitted or required. Send a privacy request to [email protected]; we may verify identity before acting.
We do not knowingly offer the Service to children. If you believe a minor submitted personal data without valid authorisation, contact us so we can investigate and take appropriate action.
13. Third parties, availability and disclaimers
The Service may depend on hosting, network, email, payment, compute and open-source providers. Their services may be unavailable or subject to separate terms. Links and external references are provided for convenience and do not make third-party content ours.
THE SERVICE, DOCUMENTATION, EXAMPLES AND OUTPUTS ARE PROVIDED "AS IS" AND "AS AVAILABLE". TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE DISCLAIM EXPRESS, IMPLIED AND STATUTORY WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT.
We do not warrant uninterrupted availability, universal compatibility, a particular time-to-result, energy reduction, acceleration, certification or fitness for your use case. Any published measurement applies only to its stated campaign and conditions.
Nothing provided by HexStellar is legal, medical, financial, safety, export-control or other regulated professional advice. Obtain qualified review appropriate to the decision and jurisdiction.
14. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, HEXSTELLAR AND ZENITH FLOW INNOVATIONS LLC WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, OR FOR LOSS OF PROFITS, REVENUE, DATA, GOODWILL, BUSINESS OPPORTUNITY OR EXPECTED SAVINGS, ARISING FROM THE SERVICE OR THESE TERMS.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, OUR TOTAL AGGREGATE LIABILITY ARISING FROM THE SERVICE OR THESE TERMS WILL NOT EXCEED THE AMOUNT YOU PAID FOR THE SERVICE DURING THE THREE MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM. FOR FREE OR SANDBOX USE, THE CAP IS US$100.
The exclusions and caps apply regardless of legal theory and even if a remedy fails of its essential purpose. They do not exclude liability that applicable law does not permit the parties to exclude or limit.
15. Indemnity
To the extent permitted by law, you will defend, indemnify and hold harmless Zenith Flow Innovations LLC, its affiliates, officers, employees and agents from third-party claims, losses, damages and reasonable legal costs arising from your unlawful use, data you had no right to submit, infringement of another party's rights, material breach of these Terms, prohibited security activity, or use of an output in a safety-critical or regulated decision contrary to section 2.
We will provide reasonable notice of a covered claim and permit you to control the defence, provided you may not resolve it in a way that admits fault by, imposes obligations on, or fails to fully release an indemnified party without our written consent.
16. Suspension, termination and effect
You may stop using the Service at any time. We may restrict, suspend or terminate access where reasonably necessary for breach, security, abuse, non-payment, legal compliance, risk to another user, or discontinuation of a feature. When practical and safe, we will provide notice and an opportunity to cure a remediable breach.
On termination, access rights and credentials end. Accrued payment obligations and provisions that by their nature should survive remain in effect, including security, intellectual property, confidentiality, output responsibility, disclaimers, liability, indemnity, disputes and general terms.
Suspension or termination does not require deletion of records that we are entitled or required to retain under section 12, an Enterprise agreement, or applicable law.
17. Governing law and disputes
These Terms are governed by the laws of the State of California, United States, without regard to conflict-of-laws principles. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
Subject to non-waivable consumer or local law, the state and federal courts located in Santa Clara County, California have exclusive jurisdiction over disputes arising from these Terms or the Service, and each party consents to that jurisdiction and venue.
Either party may seek urgent injunctive or equitable relief in a court with jurisdiction to protect security, confidential information or intellectual property. These Terms do not waive a right or remedy that applicable law makes non-waivable.
18. General, precedence and notices
These Terms, the live plan terms and any applicable signed Enterprise documents form the agreement for the Service. They supersede prior discussions about the same subject. If a signed Enterprise document conflicts with these public Terms, the signed document controls only within its stated scope.
We may update these Terms prospectively. A material update will carry a new version and, for registered users where required, notice through the Service or account email. Continued use after the effective date constitutes acceptance where permitted; if you do not accept, stop using the Service.
If a provision is unenforceable, it will be limited or severed to the minimum extent necessary and the remainder will continue. Failure to enforce is not a waiver. You may not assign this agreement without written consent; we may assign it in connection with a reorganisation, financing, merger, acquisition or sale of relevant assets.
Neither party is liable for delay caused by events beyond reasonable control, except for payment obligations and duties that can reasonably continue. Notices to HexStellar, including legal and privacy notices, may be sent to [email protected]. Electronic notices and records may satisfy writing requirements where law permits.
Questions about licensing, privacy, responsible research or a use case near these boundaries? Contact [email protected] before proceeding. Written scope is the safest way to protect both your research and the platform.
© 2026 HexStellar — Zenith Flow Innovations LLC, Palo Alto, California. All rights reserved.