Terms of Service
Last updated: August 6, 2026 · COS TRINITY · Regina, Saskatchewan
- ›Use VITNA responsibly: no crimes, no abuse, no using us to attack others.
- ›Free tier is genuinely free. Paid tiers (Pro / Team / Enterprise) bill monthly.
- ›Your data is yours. Export anytime. Delete anytime.
- ›No measured uptime commitment yet. If we are down, desktop mode keeps working; webhooks are not an independent fallback.
- ›No warranty. Liability capped at what you paid us in the last 12 months. Standard SaaS terms.
1. Who We Are
VITNA is a product of COS TRINITY ("COSTRINITY", "we"). These terms govern your use of vitna.costrinity.xyz, vitna.costrinity.xyz/dashboard, the VITNA Desktop application, and the @costrinity/vitna-compliance-mcp npm package. By using any of these, you agree to these terms.
2. What VITNA Does
VITNA is a compliance evidence layer for AI agents. You point your agent's events at our ingest endpoint (the default, stored in our cloud) or at the local SQLite store (opt-in); we render them as a searchable, real-time dashboard with threat detection, severity classification, compliance tagging, and alert routing, and we produce Ed25519-signed evidence packages you can verify offline. The cloud build runs at vitna.costrinity.xyz; the desktop build keeps event payloads on your machine. Detection is heuristic pattern matching and VITNA is a cooperative guardrail that evaluates and records rather than enforcing, and those limits are documented publicly. See the Privacy Policy for which mode stores what where.
3. Acceptable Use
4. Your Account
Cloud users: you create an account with an email + password. You're responsible for keeping the password safe. If your API key leaks, rotate it immediately from Dashboard → Agent → Rotate Key. We're not liable for events submitted from a compromised key. The rotation flow is the remedy. Desktop users have no account; the API key is generated locally and lives only on your machine.
5. Pricing & Billing
Free tier is free, forever. Paid tiers are purchased one month at a time via PayPal (USD, card accepted); INR/Razorpay checkout for India-region accounts is pending merchant onboarding. There is no auto-renewing subscription and no annual billing: each payment grants 30 days of paid access, after which the account returns to the free tier until you purchase again. We don't auto-upgrade you and we don't silently stop accepting your events — if your usage runs well above your tier's guideline volumes we'll contact you. Questions or refund requests: hello@costrinity.xyz.
6. Your Data
You own your event data. Cloud storage is the default: your events and decision records are stored on our servers, subject to the retention windows in the Privacy Policy, and we can see what you send us. Local and desktop mode is the opt-in alternative that keeps event payloads on your device. You can export everything as JSON or CSV from the dashboard at any time, and export signed evidence packages via the evidence export endpoint. You can delete your account or wipe local data with a single click. On account deletion we delete your server-side event data within 30 days; append-only audit rows are retained with the owner reference removed. See the Privacy Policy for exactly which mode stores what where.
7. Service Availability
We aim for high availability but do not currently offer a measured uptime commitment or SLA credits: we do not yet run an uptime probe, so there is no measurement we could hold ourselves to. Desktop mode keeps working when the cloud is unreachable, because it reads and writes locally. Alert evaluation currently runs on the same infrastructure as the dashboard, so do not treat webhooks as an independent fallback during a cloud outage. If any of this changes we will say so here.
8. Termination
You can delete your account anytime from Dashboard → Settings → Delete Account. We can suspend or terminate your account if you violate the acceptable-use rules in §3, with as much warning as the situation allows (typically 14 days; for severe abuse, immediate). On termination by either party, you keep your local data (it's yours) and we delete the server-side account record within 30 days.
9. No Warranty
VITNA is provided "as is." We don't warrant that it will be error-free, that the dashboard will always render every event in a specific order, or that threat detection will catch every malicious input. The threat-detection patterns are best-effort heuristics: they are not a substitute for a security audit, code review, or an actual SOC. Don't use VITNA as your only line of defense against adversarial agents.
10. Limitation of Liability
Our total liability to you for any claim arising from your use of VITNA is capped at the amount you paid us in the 12 months preceding the claim. For free-tier users, that's $0. We're not liable for indirect, incidental, special, consequential, or punitive damages, even if we should have known they were possible. This is the standard SaaS liability cap; if you need higher liability for an enterprise deployment, contact hello@costrinity.xyz to negotiate a Master Services Agreement.
11. Indemnification
You agree to indemnify us against any third-party claim that your use of VITNA caused them harm. For example, if your agent harassed someone via VITNA-mediated event payloads, or you uploaded copyrighted material as a payload. This is the developer's responsibility because we don't (and can't) inspect event content.
12. Governing Law
COS TRINITY is a Canadian studio based in Regina, Saskatchewan. These terms are governed by the laws of Canada and the Province of Saskatchewan, without regard to conflict-of-law principles. Disputes that aren't resolvable by talking to us at hello@costrinity.xyz will be heard in the courts of Saskatchewan, Canada. VITNA is accessible worldwide: if you use it from outside Canada, you agree Canadian law governs our relationship for the purposes of these terms. If you're a consumer in a jurisdiction with mandatory consumer-protection law (EU, UK, US states, Australia, India, and others), nothing here overrides the rights that local law guarantees you.
13. Changes to These Terms
We can update these terms. Material changes (anything that affects your rights, like the liability cap or the data-handling commitments) will be posted here with an updated date at least 14 days before they take effect (we do not currently send change notifications by email). Non-material changes (typo fixes, clarifications) we just edit, and the Last updated date at the top of this page reflects the change.
14. Contact
Questions about these terms, requests for an MSA, security disclosures, or anything else: hello@costrinity.xyz. We aim to respond promptly.