The terms under which you access and use the InventDB managed data platform.
"Platform" means the InventDB AI-driven data platform service operated by InventDB Software LLP, including the InventDB engine, the AI Canvas, the inventdb-console management application, the InventDB AI Gateway, all updates, patches, and documentation.
"Licensor" means InventDB Software LLP, operating at inventdb.com.
"Subscriber" or "you" means the individual or legal entity that has subscribed to use the Platform.
"Instance" means an isolated logical or physical workspace provisioned for a single Subscriber.
"Customer Encryption Key" means the master encryption key used by the Platform to protect your data, generated at the time your Instance is provisioned.
"AI Gateway" means the Licensor-operated proxy through which all AI inference requests from the Platform are routed to Anthropic. Pre-production-launch the Gateway calls the Anthropic API directly; at production launch the Gateway will route to Anthropic Claude on AWS Bedrock. The no-training opt-out is applied at the Anthropic level in either configuration.
The Platform is offered under the following subscription tiers, all delivered as managed cloud services on infrastructure operated by the Licensor (currently Amazon Web Services). Pricing is published at inventdb.com/pricing and follows a transparent bundled-tier model: each tier consists of a fixed Platform Fee plus a fixed AWS Hosting Allocation and a fixed AI Usage Allocation, set at the Licensor's negotiated volume rates with the underlying vendors.
Single-user subscription. Multi-tenant shared compute cluster with per-user encryption-key isolation. Two sub-tiers (Standard, Pro) varying by record cap, storage, and included AI Usage Allocation.
Multi-user subscription with role-based access. Dedicated InventDB Instance per Subscriber, running as a dedicated container task on the Licensor's managed AWS infrastructure, with a per-Instance master encryption key (see Section 6). The underlying compute hosts and storage volumes are operated by the Licensor and may be shared with other Subscribers; isolation between Subscribers is enforced at the application, filesystem, cryptographic, and identity layers (Subscriber data is encrypted with the Subscriber's own key and is unreadable by any other Instance). Five sub-tiers (Starter, Small, Medium, Large, X-Large) varying by compute allocation, record cap, storage, and included AI Usage Allocation. AWS KMS-backed customer-managed key (CMEK) is on the roadmap for the Business tier; the Licensor will update this Agreement on at least 30 days' notice when KMS integration becomes generally available, and the prior version of this Section will remain authoritative for Subscribers provisioned before that date until they opt in to the new architecture.
Subject to these terms and payment of the applicable fees, the Licensor grants you a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to access and use the Platform during your active subscription period.
You must not:
Your data is encrypted at rest with a per-user AES-256-GCM encryption key generated when your account is created. The key may be passphrase-derived (Argon2id) at the Subscriber's option. You can rotate this key from your admin console.
At provisioning, a per-Instance AES-256-GCM master encryption key is generated. The key lives in the Instance's configuration on the Licensor's managed AWS infrastructure. You can rotate this key at any time through the admin console. Revocation will render your Instance unable to read your data until you supply a new key. The Licensor's authorized engineers have operational access to the Instance configuration containing the key — this is required to operate a Managed Service. The Licensor maintains audit logs of any such access.
The Licensor intends to migrate the Business tier to a Customer-Managed Encryption Key model backed by AWS KMS in the Subscriber's own AWS account, in which (i) the master key never leaves the Subscriber's KMS instance, (ii) every key access by the Platform is logged to the Subscriber's CloudTrail, and (iii) the Subscriber can revoke the Licensor's access at the KMS-policy layer without the Licensor's intervention. This Section will be updated when the KMS architecture is generally available, on at least 30 days' notice. Until then, Section 6.2 governs.
If you require an architecture in which the Licensor has no operational access to the Customer Encryption Key under any circumstances, the Platform's current managed-only deployment model is not suitable for you. The KMS architecture described in Section 6.3, once shipped, will materially narrow but not eliminate the Licensor's access (the running Platform process must still load the key into memory to serve your queries).
The Platform's AI Canvas connects to Anthropic via the InventDB AI Gateway operated by the Licensor. The current routing is the Anthropic API directly; the Licensor will migrate routing to Anthropic Claude on AWS Bedrock at the Platform's production launch (the no-training guarantee applies to both configurations). You acknowledge:
THE PLATFORM IS PROVIDED "AS IS" AND THE LICENSOR DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT.
IN NO EVENT WILL THE LICENSOR'S AGGREGATE LIABILITY UNDER THIS AGREEMENT EXCEED THE FEES YOU PAID FOR THE PLATFORM IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
This Agreement is governed by the laws of the jurisdiction in which the Licensor is incorporated. Disputes shall be resolved in the courts of that jurisdiction.
The Licensor may update this Agreement with at least 30 days' prior notice to the email on file for your subscription. Continued use of the Platform after the effective date of an update constitutes acceptance.
For questions about this Agreement, email support@inventdb.com.