Terms

Master Service Agreement

Between: CommandKey AI, LLC, an Alabama limited liability company ("Provider," "we," "us"), and [Client Legal Name], a business entity ("Client," "you"). Each is a "Party."

Effective Date: [Date] | Version: 6.1, dated September 29, 2026

1. Services, Order Forms, and Order of Precedence

Provider supplies planning documents, self-install release packages, configuration materials, documentation, and ongoing release support for a client-controlled AI system built to run with Anthropic's Claude. Provider will not intentionally start a login to, remotely control, or open a remote-access session with Client's computers or Client-controlled accounts. Provider receives only what Client or the installed system sends through the channels this Agreement and the Client Security Disclosure describe.

Each engagement is described in an order form. An "Engagement" means an accepted order form and the services under it. An order form is accepted when Client replies by email to the message that attached it, from an email address Client has designated or has used to deal with Provider, with the words "I accept the attached order form, this Master Service Agreement, and its jury waiver" and the typed full name and title of the person accepting. The reply accepts the attached order form and the versions of this Agreement and the Client Security Disclosure identified in it. The person accepting represents that they are authorized to bind Client, and each Party represents that it has authority to enter into this Agreement.

Prices are fixed once an order form is accepted, except Care prices, which may change only as Section 2 allows. Provider's website is descriptive only and is not part of this Agreement. No purchase order, supplier portal, or other Client form adds to or changes these terms.

Order of precedence. If documents conflict: (1) an applicable open-source or third-party license controls, but only for the material it governs; (2) the order form controls on price, scope, users, computers, schedule, payment, and any provision it expressly says amends this Agreement; (3) this Agreement controls on all other terms; (4) the Client Security Disclosure controls on the technical description of the security controls and their known limits.

Engagement types:

Work outside an order form's scope needs a new order form or a written change accepted by both Parties.

Definitions. "Business day" means Monday through Friday, excluding US federal holidays, US Central time. "Minimum Requirements" means the computer and account requirements stated in the Client Security Disclosure or the order form. "Security Layer" has the meaning in Section 12. "Release" means a versioned software package Provider distributes through its designated release channel.

2. Fees, Payment, and Taxes

3. How the Work Is Delivered

Communications, instructions, reports, approvals, notices, and support are delivered in writing by email. No calls are required. Any call is optional, informational, and does not change this Agreement. Releases are delivered through Provider's designated release channel.

Client runs and supervises the installation using Client's own Claude subscription, Client's own agent, Provider's written instructions, and the release package. Client controls every step and can stop at any time. No Engagement runs on Provider's accounts or credentials. Client's Claude subscription and other accounts, including their billing, are Client's own.

Before installation, Client confirms in writing that a current backup of the computer exists and that full-disk encryption is on (Section 7).

Go-live occurs when: (1) Client runs the supplied post-install check script on Client's computer; (2) Client sends Provider the resulting status report, and Provider replies in writing that the status report shows each check as passed (the "install report"); and (3) Client confirms in writing that the system is running, or 5 business days pass after the install report without Client reporting a reproducible failed check. The install report repeats what Client's own status report says. It is not an inspection of Client's computer and not a certification of Client's security. If Client reports a reproducible failed check in that period, Provider supplies a corrected release or written correction instructions, and the period restarts once Client reports that the checks pass. The 30 days of included Care start at go-live.

Service standard. Provider will perform the services in a professional and workmanlike manner, consistent with generally accepted industry practice for similar services. If Client tells Provider in writing within 30 days after delivery that a deliverable does not meet this standard, Provider will re-perform or correct it at no charge, and if Provider cannot do so within a reasonable time, will refund the fees paid for that deliverable. The 30-day window sets when the free re-performance is available. It does not shorten any time the law gives Client to bring a claim. Re-performance or refund is Client's exclusive remedy for breach of this service standard, and any other claim about a deliverable is subject to Section 5.

Not a security or compliance service. The services are planning, configuration, documentation, and software-release services. They are not managed security, monitoring, incident-response, legal, audit, or compliance services. Provider does not promise to find or prevent every vulnerability, malicious instruction, unauthorized action, or security incident.

Provider's tools and subcontractors. Provider uses AI tools, under human accountability, to draft, review, and deliver its work. The AI providers that may receive Client information are named in the Client Security Disclosure. Provider may use subcontractors and remains responsible for their work under this Agreement.

4. Data Handling

Client's data. Client's data, files, and business information remain Client's property. The installed system's files and memory stay on Client's computer. Provider does not host the system. In ordinary operation, Provider receives only (a) what Client sends by email, which is stored in Provider's business email account and processed with the AI providers named in the Client Security Disclosure, and (b) Care metadata, described below.

Client grants Provider a limited, non-exclusive right to receive, store, copy, and process information Client sends only as needed to perform the Engagement, administer this Agreement, secure Provider's systems, and comply with law. Provider does not sell Client information and does not itself use it to train any AI model. Provider will not send Client information to an AI provider not named in the Client Security Disclosure without first telling Client and getting Client's written consent.

Care metadata. While Care is active (including the 30 days included with an Install), the installed system emails Provider a monthly status summary: counts and categories of actions the system attempted, blocked, or held for approval; component status and release version; and whether the Security Layer is enabled. Provider uses commercially reasonable measures to design this summary to exclude Client content, prompts, command text, credentials, and file names. If Provider learns that materially different information was sent, Provider will stop or correct the transmission and handle the information under Sections 4, 8, and 11. Provider will not add any other automated communication from the installed system to Provider unless the Client Security Disclosure describes it and Client approves the change in writing.

Third parties in the data path. The system runs on Client's own Claude subscription, so the content it processes is sent to Anthropic under Client's own Anthropic account terms. If Client uses the optional texting feature, messages travel through Telegram, a third party. The Client Security Disclosure explains what data leaves Client's computer and to whom.

Data Client may not send to Provider or through Telegram: passwords, authentication tokens, or private keys; full Social Security numbers; payment card data or bank account numbers; protected health information; Federal Contract Information, Controlled Unclassified Information, export-controlled technical data, or classified information; and any other information the law or Client's contracts bar from that channel or from disclosure to Provider.

Excluded use. The standard service is not offered for, and Client will not use it with, Controlled Unclassified Information, export-controlled data, classified information, protected health information, or regulated financial-services data. Client remains responsible for access, permissions, retention, and safeguards for all information on its own systems.

Retention and deletion. While an Engagement continues, Provider purges emailed content older than 12 months that it no longer needs. When the last Engagement ends, or on Client's written request, Provider deletes the Client information it holds within 30 days, except billing records, copies the law requires Provider to keep, and copies in routine provider backups until they expire, which stay covered by Section 8.

4A. Security Disclosure

Before accepting, Client acknowledges receiving and reviewing the Client Security Disclosure. It describes the security controls in the installed system, the categories of attack they do not fully defend against, and what data leaves Client's computer. The disclosure describes the system as Provider understood it on the Effective Date. Provider prepared it with reasonable care and will tell Client without unreasonable delay if Provider learns of a material change or a material error that affects Client's installed release or Provider's handling of Client's information. The disclosure is not a warranty. No security control described in this Agreement or the disclosure is absolute or guaranteed, and Client agrees not to treat any statement in the disclosure as a promise that a listed control will catch every action it targets.

5. LIMITATION OF LIABILITY

THIS SECTION LIMITS WHAT EITHER PARTY CAN RECOVER. PLEASE READ IT.

5A. AI Output; No Guaranteed Results; DISCLAIMER

The installed system and some of Provider's written deliverables use probabilistic AI models. Outputs may be inaccurate, incomplete, biased, outdated, not unique to Client, or fabricated, and factual statements that look reliable may be wrong. Outputs are not legal, tax, accounting, financial, medical, cybersecurity, or other professional advice. Unless an order form says otherwise, outputs are not reviewed by a human on Provider's behalf. Client is responsible for reviewing outputs before relying on them, making a decision with them, or sending them outside Client's organization.

Provider does not promise any particular time saved, revenue, cost reduction, or other business result.

DISCLAIMER. EXCEPT FOR THE SERVICE STANDARD IN SECTION 3 AND ANYTHING ELSE THIS AGREEMENT EXPRESSLY STATES, THE SERVICES, THE RELEASES, THE PROVIDER MATERIALS, AND THE INSTALLED SYSTEM ARE PROVIDED "AS IS" AND "WITH ALL FAULTS," WITHOUT ANY WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, OR NON-INFRINGEMENT. PROVIDER DOES NOT WARRANT THAT THE SYSTEM OR ANY AI OUTPUT WILL BE ACCURATE, COMPLETE, SECURE, UNINTERRUPTED, OR ERROR-FREE. Section 6 is Client's exclusive remedy for infringement claims.

5B. Third-Party Services

The installed system depends on services Client contracts for directly, including Anthropic, Telegram, and Client's email and calendar providers. Provider does not accept, negotiate, or sign any provider's terms for Client, does not control those services, and is not responsible for their availability, pricing, terms, model changes or retirements, or actions on Client's accounts.

6. Indemnification

7. Client Responsibilities

Client is responsible for:

Authorized Users are the people named in the order form. An approval given by any Authorized User is Client's approval. Client is responsible for its Authorized Users' use of the system.

Always-on work. Scheduled and after-hours agent work runs on Client's own computer and happens only while that computer meets the Minimum Requirements and is powered on, awake, and connected to the internet.

8. Confidentiality

9. Intellectual Property, License, and Attribution

9A. Case Study and Publicity

Provider will not publish a case study, Client's name or logo, or anything that reasonably identifies Client without Client's written approval of the final version. Any case-study commitment tied to founding pricing is stated in the order form.

10. Care, Corrections, Term, and Termination

Optional paid Care. The included 30-day Care period ends automatically unless Client affirmatively enrolls in paid Care in writing. At least 15 days before it ends, Provider will email the available plan, monthly price, start date, and cancellation terms. Paid Care begins only after Client replies that it accepts the identified plan and price. Continued use of the installed release does not by itself enroll Client. Either Party may end paid Care with 30 days' written notice.

What Care corrects. Care includes commercially reasonable correction of reproducible failures of the installed release to perform materially as described in the Handoff Documentation, up to the number of correction requests per month stated in the order form. Corrections for a material security vulnerability in Provider Materials, or for a defect Provider's own release introduced, are free and do not count toward that number. Care does not include new functionality, changed requirements, or restoring functionality a third-party provider discontinued, and does not cover problems caused by Client's changes, Client's hardware, operating system, network, or internet, Client's third-party accounts and their outages or terms, or data Client put into the system. Work outside Care needs a fixed-price order form.

Upstream changes. If Anthropic or another upstream provider makes a change that materially affects installs, Provider will assess it promptly and give Care clients a written status and plan, and a tested release or documented workaround when one is reasonably available.

Term. This Agreement starts on the Effective Date and continues until every Engagement has ended and, after that, until either Party ends it by written notice. A Blueprint is complete on delivery. An Install is complete at go-live plus the 30 days of included Care.

Inactive Engagements. If Client does not respond to Provider's written requests for 60 days during an Install, Provider may close the Engagement by written notice. Amounts paid are kept for work performed, no further milestone payments are due, and Client may restart within 6 months under a new order form at then-current pricing, with the amount paid credited in full.

Termination for cause. Either Party may end this Agreement or any Engagement by written notice if the other materially breaches it and does not cure the breach within 30 days after written notice describing it (10 days for non-payment). Either Party may end it immediately if the other stops doing business in the ordinary course.

After termination. Client pays fees for work delivered through the end date and keeps its license under Section 9. Nothing in this Agreement gives Provider any ongoing access or control. When Care ends, Provider stops release notices, reports, corrections, and support, and Client may keep using the last installed release. Provider is not responsible for changes Client or a third party makes after Care ends.

11. Security Incidents

A "Security Incident" means (1) confirmed unauthorized access to or disclosure of Client information held in Provider's own systems, or (2) Provider's confirmation that malicious or unauthorized code was introduced into a release Provider delivered to Client. Provider will notify Client within 3 business days after confirming a Security Incident, unless the law requires earlier notice, with the information reasonably available to it, written containment or remediation instructions or a corrected release where available, and reasonable cooperation with Client's own legally required notifications. Provider does not monitor Client's computer or accounts and may not detect an incident occurring there. Client handles containment and investigation on its own systems, following Provider's written instructions where they apply.

12. Approval for High-Risk Actions

The installed release is designed so that the system drafts by default and asks an Authorized User for approval before taking the high-risk actions listed in the Client Security Disclosure. The Disclosure states which of those actions are enforced by the Security Layer (a code-level check that runs before the AI model's own judgment and outside the customizable persona configuration) and which depend on configuration that Client controls and Section 7(h) protects. Client acknowledges that configuration-based controls are less reliable than code-enforced controls. A reply to an Authorized User through the channel that user used to make a request counts as approved by that request. Model-processing calls, read-only retrieval, and the Care metadata email are not communications for this section. Approving a workflow in advance does not approve each action in it, unless the order form and release documentation expressly identify a specific recurring action as approved in advance.

The Security Layer reduces risk but can be bypassed by defects, unsupported tools, Client modifications, malicious instructions or code, third-party changes, or the other limits described in the Client Security Disclosure. It is not a guarantee that every covered action will be caught. Approvals are given on Client's computer unless the release documentation states that another channel is supported.

13. No Compliance or Certification Claims

Provider does not certify, and does not represent, that Client is compliant with any law, regulation, or framework, including CMMC, FAR 52.204-21, HIPAA, or GLBA. Any mapping of system controls to a framework is supporting evidence only. Compliance remains Client's responsibility. The services are commercial services and the Provider Materials are commercial computer software and documentation. If Client intends to use any deliverable in performing a Government contract or subcontract, Client will say so before ordering, and no Government contract clause applies to Provider unless Provider expressly accepts it in a signed addendum.

14. Insurance

During each paid Engagement, Provider intends to carry professional liability and cyber liability insurance and will give Client a certificate of insurance on reasonable written request. The certificate, not this Agreement, states the coverage in force.

15. Governing Law, Courts, and Disputes

This Agreement is governed by the laws of the State of Alabama, without regard to its conflict-of-laws rules. Client is a business and enters this Agreement for business purposes, not for personal, family, or household use.

Before filing any claim, the Parties will try in good faith to resolve the dispute by email between their decision-makers for 30 days. After that, any suit must be brought exclusively in the state courts located in Coffee County, Alabama, Enterprise Division, or, if federal subject-matter jurisdiction independently exists, the United States District Court for the Middle District of Alabama. Each Party consents to personal jurisdiction and venue in those courts and waives any objection based on inconvenient forum. This does not prevent either Party from filing an eligible claim in the small-claims division of the Coffee County District Court, or from seeking an injunction in any court to protect its Confidential Information or intellectual property without waiting out the negotiation period. In any suit to collect fees or to enforce Section 8 or Section 9, the prevailing Party may recover its reasonable attorneys' fees and costs.

JURY WAIVER. EACH PARTY KNOWINGLY, VOLUNTARILY, AND INTENTIONALLY WAIVES ANY RIGHT TO A TRIAL BY JURY IN ANY ACTION, PROCEEDING, OR COUNTERCLAIM ARISING OUT OF, RELATING TO, OR IN ANY WAY CONNECTED WITH THIS AGREEMENT, ANY ORDER FORM, ANY ENGAGEMENT OR DELIVERABLE, THE CLIENT SECURITY DISCLOSURE, OR THE RELATIONSHIP BETWEEN THE PARTIES, WHETHER THE CLAIM SOUNDS IN CONTRACT, TORT, FRAUD, OR STATUTE, AND INCLUDING CLAIMS ABOUT HOW THIS AGREEMENT OR ANY ORDER FORM WAS FORMED OR INDUCED. EACH PARTY CONFIRMS THAT IT HAS READ THIS WAIVER, HAS HAD THE OPPORTUNITY TO REVIEW IT WITH A LAWYER OF ITS CHOICE, AND IS A BUSINESS ENTERING THIS AGREEMENT FOR BUSINESS PURPOSES.

16. General Terms

ACCEPTANCE. Accepted as described in Section 1, by email reply stating: "I accept the attached order form, this Master Service Agreement, and its jury waiver," with the typed full name and title of the person accepting.

Every order form carries, directly above its acceptance line: "This order form is governed by the Master Service Agreement, version 6.1, dated September 29, 2026, including its limitation of liability in Section 5, its disclaimer in Section 5A, and its jury waiver in Section 15, which apply to this order form."

Fit Check terms (placed on the Fit Check request form and at the top of every Fit Check): "This Fit Check is a free written opinion based only on the answers you gave us. We have not seen your systems. It is not a warranty and not advice on security, legal, or compliance matters. By requesting it, you agree that our total liability for it will not exceed $100, and that it is otherwise governed by our Master Service Agreement, which you can read at https://commandkey.ai/terms.html before requesting it."

← Back to home