# Craton terms of service

Terms for Craton, the risk-analytics platform. They say what the software
does, what you may expect of it, what it costs, and what happens to the data
you send. Read them with the [acceptable-use page](/acceptable-use), which
holds the rules of use these terms refer to.

---

## Status of this page

**Approved by the operator on 2026-08-18** (`BLOCKED_OPERATOR.md` item 8,
`docs/GTM.md` GTM-14 and GTM-15).

* Every decision this page reserved to a human — the contracting entity and
  its registered address, the governing law, the venue, the liability
  position, the fee terms, the data-protection position, the notice periods
  and the contact address — was made by the operator on that date and recorded
  in item 8. This page transcribes those decisions; it adds nothing to them.
* Craton is pre-release. The environment you can reach today runs on the
  operator's private network, and no account on it has ever been charged.
  These terms take effect for fees only from the date the operator turns real
  billing on (section 3).

## 1. What Craton is

Craton is software: an API-first, self-service platform for risk analytics and
structuring, built around a canonical machine-readable risk object, and a
registry of versioned models and data feeds. Everything it does, it does as
software you call.

Craton outputs technical prices, never quotes; it drafts terms, never offers; it cannot bind, issue, endorse, claim or settle.

Craton is not a carrier, a broker or an MGA. It never sells cover, never touches
paper, and is not a party to any contract of insurance or reinsurance. The
paper, the counterparties and the decision are yours.

What the software serves, stated plainly so these terms are read against the
real thing:

* Live today: ingest, analyse, price, structure, backtest, monitor and
  package, plus the model registry, its composition primitives and the no-code
  model builder.
* Analyse is live on every route the specification names for it: the point
  hazard lookup `GET /hazard` answers from a pinned public snapshot, the public
  event catalogue and event footprints are served from the same pinned record,
  `POST /objects/{id}/analyse` runs both readings over an object and records
  the artifacts on its provenance, and `POST /accumulation` totals the exposure
  already stored on a set of your own objects — at portfolio level, per peril,
  per declared region and by concentration, never a schedule served back.
* Monitor is live on its first slice: you can record a structure as in force —
  which is your assertion about a transaction executed entirely outside Craton,
  and nothing Craton arranged, witnessed or is party to — and read the index
  against the newest pinned snapshot. Craton reports the measurement and never
  what follows from it: it decides nothing about anybody's obligations under
  any contract, is not the calculation agent of record for anything, notifies
  nobody and moves no money. Webhooks have no address on this build.
* Package is live on its first slice: a submission pack assembled from the
  runs an object already carries, every document in it watermarked as a draft
  produced by analytics software. The draft slip is not one of its documents
  yet, and nothing in a pack is signed, accepted or executed here.
* The specification names seven verbs; this build now has an address for each
  of them, on the slices named above and no wider.

## 2. Accounts and keys

Accounts are self-service: one unauthenticated call signs you up and returns
your first key. No invitation, no approval queue, no payment details.

* You are responsible for what happens under your keys. Keep the secret safe —
  anybody holding it can call the API as you, and a secret this platform has
  handed out once is never shown again.
* One account per person or organisation, and keys are not for sharing outside
  it.
* Tell the operator promptly if you think a key has leaked, so it can be
  retired.

## 3. Fees and billing

* **Pricing is metered usage** — per risk object and per model run — and it is
  self-service. There are no seat licences and no negotiated contracts.
* **A free sandbox tier exists** and is meant to be enough to integrate
  against and to finish a real job on.
* **Billing runs through a payment processor — Stripe.** Craton never holds or
  moves money. Premium, losses and collateral never pass through this
  platform; fees for software usage are the only money flow it has.
* **Today billing is in test mode.** Usage is metered and readable back
  through the API, and no charge is possible until the operator throws the
  real-money switch, which no automated session can reach. These terms take
  effect for fees only from the date the operator turns real billing on.
* **Tax.** All prices are exclusive of taxes — sales, use, VAT or similar.
  Where such a tax applies to your use of the platform, it is yours to pay.
* **Currency, invoicing and payment.** Fees are billed in USD. Usage is
  invoiced monthly in arrears and charged automatically through Stripe;
  invoices are due on receipt. Staging's short test-mode invoice cycle is a
  setting on a pre-release environment, not a term of this agreement.

## 4. Your data

* **You keep your data.** You grant Craton only the licence it needs to run the
  verbs you call, to store the objects and results in your account, and to
  keep backups of them.
* **We use your inputs to serve your requests** and to run the platform —
  metering, debugging, security and abuse handling. We do not sell them.
* **Do not send individual-level personal records.** The platform is built for
  exposure and event data, not for data about identified people; the
  acceptable-use page states this as a rule.
* **Published data feeds are aggregate only** — triangles, tables and indices
  at portfolio level, never individual-level records.
* **Roles.** Barite Strategies LLC is controller for account and billing
  data, processor for uploaded exposure data — for that data it acts on your
  instructions, which are the verbs you call.
* **Storage region.** Your data is stored in the United States (DigitalOcean
  SFO3, San Francisco).
* **Sub-processors.** DigitalOcean (hosting), Stripe (billing), Anthropic
  (AI-assist features, only while enabled). Those three, and no others.
* **Retention.** Objects and results live as long as your account, plus the
  backup window. Deletion is an operator-handled request today: this build has
  no self-service route that erases an account. When an account is closed, its
  data is deleted 30 days after account closure.

## 5. What the outputs are, and what they are not

* Every technical price carries its assumption set — model versions, data
  vintages, event set, loadings, currency basis — on the face of the response.
  A number without its assumptions is not a Craton output.
* Terms the platform drafts are drafts, and are marked as drafts.
* Every result is labelled with the model and the version that produced it.
* The platform never ranks, recommends or endorses a model. Registry
  measurements are measurements; model cards carry authorship, assumptions and
  limitations.

Craton output is never a quote, never an offer, and never a binding commitment of any kind.

**Not advice.** Craton's outputs are analysis and drafts. They are not legal,
regulatory, actuarial, tax or financial advice, they are not a substitute for
your own judgement or your own advisers, and no output creates any duty on
Craton's part towards you or towards anybody you show it to. What you do with a
number this platform computes is your decision.

## 6. The registry

* Models you create are private by default.
* A published model version is immutable: a change is a new version, so a
  result anybody recorded can always be re-run against the exact thing that
  produced it.
* Publishing a model grants other users of the platform the right to run it
  and to read its card, under the licence you declare on the card. You keep
  authorship.
* Models are deterministic against pinned data snapshots and make no network
  calls. That is enforced, not requested.
* A published version that breaches the acceptable-use page may be withdrawn
  from the public registry.

## 7. The open schema

The canonical risk-object schema is open source, versioned, and usable with no
account at all, under the licence carried in the schema itself. The engine,
the normalisation that turns ugly files into canonical objects, and the hosted
verbs are the paid part.

## 8. Availability and change

* This is a pre-release build. There is no service-level commitment in this
  draft; the operator sets one before any public launch.
* Environments may be reset, and data on them cleared, while the platform is
  pre-release. Keep your own copy of anything you care about.
* The platform changes continuously. Where a change removes something you
  could rely on, it is announced in these docs before it lands, and the schema
  version tells you what you are speaking to.
* **Notice.** Once the platform is public, you get 30 days before a change
  that removes a documented capability takes effect. While it is pre-release,
  changes land as they are built and this page says so rather than promising
  otherwise.

## 9. As-is, and liability

The platform is provided as it stands, without warranties of any kind, to the
extent the law where you are allows that. Risk analytics is a modelling
exercise: results depend on the data and assumptions declared with them, and
neither this platform nor its outputs promise anything about what will
actually happen.

**The cap.** Craton's total liability to you, on any theory and taken
together, is capped at the fees paid in the 12 months preceding the claim.

**Excluded.** Indirect, consequential and special damages are excluded,
however they arise.

**Carve-outs.** Neither the cap nor the exclusion applies to fraud, wilful
misconduct, anything the law does not allow to be excluded.

## 10. Suspension, and ending your use

* You may stop using Craton at any time. Metered usage already incurred stays
  payable once real billing is on.
* Access may be suspended or ended for a breach of the acceptable-use page,
  for a security reason, or where the law requires it. Where it is not urgent,
  you are told why first and given a chance to put it right.
* Sections 4, 5 and 9 survive the end of your use.

## 11. Changes to these terms

These terms are versioned in the repository that builds Craton, so every edit
has a date and a diff. A material change is announced on this page with the
date it takes effect; using the platform after that date is acceptance of the
version then published.

## 12. Law, and disputes

**The contracting entity** is Barite Strategies LLC. Its registered address
is available from the contact address in section 13.

**Governing law:** the law of the State of Delaware. **Venue:** the state and
federal courts sitting in Delaware, and you and Barite Strategies LLC each
agree to that venue.

## 13. Contact

The address for legal and privacy notices, and for a request about your own
data, is support@barite.co. Abuse and security reports go to the same address
— the [acceptable-use page](/acceptable-use) says so too, so a reader who
lands on either page has it.

---

*Drafted 2026-08-13 by the build fleet under `docs/GTM.md` GTM-14; approved
by the operator 2026-08-18 (`BLOCKED_OPERATOR.md` item 8) and the recorded
values transcribed here under GTM-15. Companion page:
[acceptable use](/acceptable-use).*
