This page as Markdown, byte for byte: /terms.md
Craton terms of service#
Terms for Craton, the risk-analytics platform. They say what the software does, what you may expect of it, what it costs, and what happens to the data you send. Read them with the acceptable-use page, which holds the rules of use these terms refer to.
Status of this page#
Approved by the operator on 2026-08-18 (BLOCKED_OPERATOR.md item 8, docs/GTM.md GTM-14 and GTM-15).
- Every decision this page reserved to a human — the contracting entity and its registered address, the governing law, the venue, the liability position, the fee terms, the data-protection position, the notice periods and the contact address — was made by the operator on that date and recorded in item 8. This page transcribes those decisions; it adds nothing to them.
- Craton is pre-release. The environment you can reach today runs on the operator's private network, and no account on it has ever been charged. These terms take effect for fees only from the date the operator turns real billing on (section 3).
1. What Craton is#
Craton is software: an API-first, self-service platform for risk analytics and structuring, built around a canonical machine-readable risk object, and a registry of versioned models and data feeds. Everything it does, it does as software you call.
Craton outputs technical prices, never quotes; it drafts terms, never offers; it cannot bind, issue, endorse, claim or settle.
Craton is not a carrier, a broker or an MGA. It never sells cover, never touches paper, and is not a party to any contract of insurance or reinsurance. The paper, the counterparties and the decision are yours.
What the software serves, stated plainly so these terms are read against the real thing:
- Live today: ingest, analyse, price, structure, backtest, monitor and package, plus the model registry, its composition primitives and the no-code model builder.
- Analyse is live on every route the specification names for it: the point
hazard lookup
GET /hazardanswers from a pinned public snapshot, the public event catalogue and event footprints are served from the same pinned record,POST /objects/{id}/analyseruns both readings over an object and records the artifacts on its provenance, andPOST /accumulationtotals the exposure already stored on a set of your own objects — at portfolio level, per peril, per declared region and by concentration, never a schedule served back. - Monitor is live on its first slice: you can record a structure as in force — which is your assertion about a transaction executed entirely outside Craton, and nothing Craton arranged, witnessed or is party to — and read the index against the newest pinned snapshot. Craton reports the measurement and never what follows from it: it decides nothing about anybody's obligations under any contract, is not the calculation agent of record for anything, notifies nobody and moves no money. Webhooks have no address on this build.
- Package is live on its first slice: a submission pack assembled from the runs an object already carries, every document in it watermarked as a draft produced by analytics software. The draft slip is not one of its documents yet, and nothing in a pack is signed, accepted or executed here.
- The specification names seven verbs; this build now has an address for each of them, on the slices named above and no wider.
2. Accounts and keys#
Accounts are self-service: one unauthenticated call signs you up and returns your first key. No invitation, no approval queue, no payment details.
- You are responsible for what happens under your keys. Keep the secret safe — anybody holding it can call the API as you, and a secret this platform has handed out once is never shown again.
- One account per person or organisation, and keys are not for sharing outside it.
- Tell the operator promptly if you think a key has leaked, so it can be retired.
3. Fees and billing#
- Pricing is metered usage — per risk object and per model run — and it is self-service. There are no seat licences and no negotiated contracts.
- A free sandbox tier exists and is meant to be enough to integrate against and to finish a real job on.
- Billing runs through a payment processor — Stripe. Craton never holds or moves money. Premium, losses and collateral never pass through this platform; fees for software usage are the only money flow it has.
- Today billing is in test mode. Usage is metered and readable back through the API, and no charge is possible until the operator throws the real-money switch, which no automated session can reach. These terms take effect for fees only from the date the operator turns real billing on.
- Tax. All prices are exclusive of taxes — sales, use, VAT or similar. Where such a tax applies to your use of the platform, it is yours to pay.
- Currency, invoicing and payment. Fees are billed in USD. Usage is invoiced monthly in arrears and charged automatically through Stripe; invoices are due on receipt. Staging's short test-mode invoice cycle is a setting on a pre-release environment, not a term of this agreement.
4. Your data#
- You keep your data. You grant Craton only the licence it needs to run the verbs you call, to store the objects and results in your account, and to keep backups of them.
- We use your inputs to serve your requests and to run the platform — metering, debugging, security and abuse handling. We do not sell them.
- Do not send individual-level personal records. The platform is built for exposure and event data, not for data about identified people; the acceptable-use page states this as a rule.
- Published data feeds are aggregate only — triangles, tables and indices at portfolio level, never individual-level records.
- Roles. Barite Strategies LLC is controller for account and billing data, processor for uploaded exposure data — for that data it acts on your instructions, which are the verbs you call.
- Storage region. Your data is stored in the United States (DigitalOcean SFO3, San Francisco).
- Sub-processors. DigitalOcean (hosting), Stripe (billing), Anthropic (AI-assist features, only while enabled). Those three, and no others.
- Retention. Objects and results live as long as your account, plus the backup window. Deletion is an operator-handled request today: this build has no self-service route that erases an account. When an account is closed, its data is deleted 30 days after account closure.
5. What the outputs are, and what they are not#
- Every technical price carries its assumption set — model versions, data vintages, event set, loadings, currency basis — on the face of the response. A number without its assumptions is not a Craton output.
- Terms the platform drafts are drafts, and are marked as drafts.
- Every result is labelled with the model and the version that produced it.
- The platform never ranks, recommends or endorses a model. Registry measurements are measurements; model cards carry authorship, assumptions and limitations.
Craton output is never a quote, never an offer, and never a binding commitment of any kind.
Not advice. Craton's outputs are analysis and drafts. They are not legal, regulatory, actuarial, tax or financial advice, they are not a substitute for your own judgement or your own advisers, and no output creates any duty on Craton's part towards you or towards anybody you show it to. What you do with a number this platform computes is your decision.
6. The registry#
- Models you create are private by default.
- A published model version is immutable: a change is a new version, so a result anybody recorded can always be re-run against the exact thing that produced it.
- Publishing a model grants other users of the platform the right to run it and to read its card, under the licence you declare on the card. You keep authorship.
- Models are deterministic against pinned data snapshots and make no network calls. That is enforced, not requested.
- A published version that breaches the acceptable-use page may be withdrawn from the public registry.
7. The open schema#
The canonical risk-object schema is open source, versioned, and usable with no account at all, under the licence carried in the schema itself. The engine, the normalisation that turns ugly files into canonical objects, and the hosted verbs are the paid part.
8. Availability and change#
- This is a pre-release build. There is no service-level commitment in this draft; the operator sets one before any public launch.
- Environments may be reset, and data on them cleared, while the platform is pre-release. Keep your own copy of anything you care about.
- The platform changes continuously. Where a change removes something you could rely on, it is announced in these docs before it lands, and the schema version tells you what you are speaking to.
- Notice. Once the platform is public, you get 30 days before a change that removes a documented capability takes effect. While it is pre-release, changes land as they are built and this page says so rather than promising otherwise.
9. As-is, and liability#
The platform is provided as it stands, without warranties of any kind, to the extent the law where you are allows that. Risk analytics is a modelling exercise: results depend on the data and assumptions declared with them, and neither this platform nor its outputs promise anything about what will actually happen.
The cap. Craton's total liability to you, on any theory and taken together, is capped at the fees paid in the 12 months preceding the claim.
Excluded. Indirect, consequential and special damages are excluded, however they arise.
Carve-outs. Neither the cap nor the exclusion applies to fraud, wilful misconduct, anything the law does not allow to be excluded.
10. Suspension, and ending your use#
- You may stop using Craton at any time. Metered usage already incurred stays payable once real billing is on.
- Access may be suspended or ended for a breach of the acceptable-use page, for a security reason, or where the law requires it. Where it is not urgent, you are told why first and given a chance to put it right.
- Sections 4, 5 and 9 survive the end of your use.
11. Changes to these terms#
These terms are versioned in the repository that builds Craton, so every edit has a date and a diff. A material change is announced on this page with the date it takes effect; using the platform after that date is acceptance of the version then published.
12. Law, and disputes#
The contracting entity is Barite Strategies LLC. Its registered address is available from the contact address in section 13.
Governing law: the law of the State of Delaware. Venue: the state and federal courts sitting in Delaware, and you and Barite Strategies LLC each agree to that venue.
13. Contact#
The address for legal and privacy notices, and for a request about your own data, is [email protected]. Abuse and security reports go to the same address — the acceptable-use page says so too, so a reader who lands on either page has it.
*Drafted 2026-08-13 by the build fleet under docs/GTM.md GTM-14; approved by the operator 2026-08-18 (BLOCKED_OPERATOR.md item 8) and the recorded values transcribed here under GTM-15. Companion page: acceptable use.*