Master Legal & Compliance Hub
The exhaustive legal directory, operational compliance framework, and contractual covenants governing Microbix enterprise subscriptions, developer APIs, cloud primitives, and data sovereignty worldwide.
1. Master Services Agreement (MSA)
This Master Services Agreement ("Agreement" or "MSA") forms the binding legal covenant between Microbix India Pvt. Ltd. (along with its global subsidiaries and affiliates, "Microbix") and the enterprise or individual developer accessing or subscribing to Microbix systems, products, APIs, or software ("Customer").
1.1 Service Provisioning: Microbix delivers cloud-native AI computing primitives, including but not limited to the Aether OS cognitive environment, Aether Code CLI, Neural Gateway proxy, Aether Team multi-agent councils, and dedicated NVIDIA H100 GPU compute clusters. Access is granted on a non-exclusive, worldwide, subscription or metered pay-per-compute basis.
1.2 Account Responsibility & Credential Hygiene: Customer retains exclusive liability for safeguarding API secrets, CLI token pairs, and session tokens. All calls dispatched utilizing Customer's API keys will be deemed authorized transactions billable to Customer's account ledger.
1.3 Enterprise Modifications: Microbix reserves the right to deploy backward-compatible optimizations, API schema patches, and security enhancements to its platform endpoints without prior notice. Deprecations of public REST API endpoints follow a mandatory 180-day formal deprecation lifecycle.
2. Service Level Agreement (SLA & 99.95% Availability)
Microbix warrants an Monthly Uptime Percentage of at least 99.95% across all production REST APIs, Neural Gateway inference streams, and Aether OS production instances.
Downtime Exclusions: Uptime calculations strictly exclude: (a) scheduled maintenance communicated 72 hours prior via status.microbix.in; (b) client-side networking anomalies or DNS ISP failures; (c) Force Majeure events or upstream backbone fiber severance.
Total API outage or customer data isolation breach. 24/7/365 immediate escalation.
Degraded inference throughput or selective model gateway latency spike.
Non-blocking questions, quota adjustments, or documentation clarifications.
3. Data Sovereignty & Global Privacy (GDPR, CCPA & DPDPA)
Microbix engineers its data pipeline to satisfy the world's most stringent data protection frameworks: the European Union General Data Protection Regulation (Regulation (EU) 2016/679 - GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and the Digital Personal Data Protection Act 2023 of India (DPDPA).
Data Subject Rights (DSR)
Users and enterprise personnel possess the inviolable right to: (1) Request complete disclosure of collected personal identifiers; (2) Rectify inaccurate records; (3) Invoke permanent cryptographic erasure ("Right to Be Forgotten"); (4) Export structured JSON archives under data portability protocols.
Cross-Border Data Transfers & Standard Contractual Clauses (SCCs)
When international transfers occur from the European Economic Area (EEA) or Switzerland, Microbix implements EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). For Indian entities subject to DPDPA, localized sovereign VPC cluster routing is available upon enterprise provisioning.
4. Intellectual Property & 100% Customer Ownership
Microbix asserts zero copyright, zero licensing claims, zero royalty rights, and zero residual ownership over code, software architectures, algorithms, or documentation written or refactored using Aether OS or Aether Code CLI. Customer is free to license, patent, commercialize, or open-source generated outputs under any license terms Customer deems fit.
5. Zero Model Retraining & Ephemeral Processing
Customer Data Is Never Used to Train Models: Microbix strictly covenants that no customer input prompt, proprietary codebase context, AST metadata, terminal command, or API payload will ever be used to train, retrain, fine-tune, distill, or reinforce foundation weights (including Aether Ultra or public partner checkpoints).
All inference payloads sent to Neural Gateway or Aether OS exist in volatile GPU High Bandwidth Memory (HBM) strictly during forward-pass token generation. Upon stream completion, inference memory buffers are securely zeroized. Zero log retention of raw proprietary code is enforced across our inference cluster infrastructure.
6. Acceptable Use Policy (AUP) & Safety Guardrails
Customers are prohibited from utilizing Microbix infrastructure or models to generate, orchestrate, or facilitate:
- Automated vulnerability exploitation tooling, polymorphic malware, zero-day payloads, or ransomware distribution.
- Distributed Denial of Service (DDoS) amplification attacks or credential stuffing tools.
- Non-consensual sexual media, sexual exploitation, or synthetic deepfake fabrication of living persons without consent.
- Autonomous kinetic weaponry, chemical, biological, radiological, or nuclear (CBRN) threat synthesis.
- Algorithmic market manipulation, illegal financial fraud schemes, or unlawful surveillance networks.
Enforcement: Violations of the Acceptable Use Policy result in immediate token revocation, account suspension, and potential referral to global cybercrime authorities.
7. Vulnerability Disclosure & Bug Bounty Program
Microbix actively cooperates with ethical security researchers worldwide under a legally binding Safe Harbor framework. We reward responsible vulnerability disclosures that improve the safety of our cloud infrastructure, CLI agents, and inference sandboxes.
8. Commercial Terms & Merchant of Record (Lemon Squeezy)
Online developer subscriptions, tier renewals, and mX compute credit packs are fulfilled and processed through Lemon Squeezy Inc., acting as our official Merchant of Record ("MoR").
8.1 Tax Remittance: Lemon Squeezy collects and remits applicable Value Added Tax (VAT), Goods & Services Tax (GST), and provincial sales tax according to Customer's designated billing jurisdiction.
8.2 mX Credit Economy: Microbix platform credits (mX tokens) represent prepaid computational access to GPU milliseconds and model inference. mX credits possess no independent monetary fiat value, cannot be redeemed for legal tender, and expire strictly pursuant to plan terms.
8.3 Enterprise Invoicing: Dedicated enterprise VPC deployments, sovereign cluster leases, and custom SLA agreements may be invoiced directly via wire transfer / ACH under standard Net-30 payment terms upon mutual execution of an enterprise order form.
9. Sub-Processors & Cloud Infrastructure Registry
Microbix engages third-party infrastructure providers to deliver high-availability cloud computing. All sub-processors undergo stringent SOC 2 Type II audits, sign binding Data Processing Addendums (DPAs), and enforce AES-256 encryption at rest:
10. Security Controls & Cryptographic Architecture
Security is an architectural primitive, not an afterthought. Microbix maintains continuous controls aligned with SOC 2 Type II and ISO/IEC 27001 standards:
- In-Transit Encryption: Mandatory TLS 1.3 encryption across all public ingress endpoints and internal gRPC node-to-node telemetry.
- At-Rest Cryptography: Hardware-accelerated AES-256-GCM encryption with envelope keys managed in dedicated Hardware Security Modules (HSMs).
- Code Execution Containment: Aether Code CLI and Aether OS execute autonomous tools inside network-isolated, read-only root ephemeral microVM sandboxes.
- Continuous Penetration Testing: Biannual independent black-box and white-box penetration testing by CREST-accredited security research firms.
11. Governing Law & Binding Arbitration
11.1 Jurisdiction: For customers outside North America, this Agreement is governed by the laws of India, and courts in Bengaluru, Karnataka shall have exclusive jurisdiction. For North American enterprise contracts, Delaware law governs without regard to choice of law principles.
11.2 Binding Arbitration: Any controversy or claim arising out of or relating to this contract, or the breach thereof, shall be settled by binding arbitration in accordance with the Arbitration and Conciliation Act, 1996 (or AAA Commercial Arbitration Rules for US contracts).
11.3 Class Action Waiver: Both Customer and Microbix agree that each party may bring claims against the other only on an individual basis, and not as a plaintiff or class member in any purported class, collective, or representative proceeding.
12. Legal Service of Process & Notices
Formal legal notices, subpoenas, regulatory inquiries, or service of process must be transmitted via registered post or delivered directly to our corporate compliance registry:
Microbix Corporate Legal Registry
Reviewing Employment & Internal Policies?
Learn about our 100% WFH mandate, radical leave trust, async work, and anti-harassment standards.