Skip to content
ARXIMUS AI Runtime Authorization
Platform Security
Financial Services Transaction-level authority Defense & National Security Mission-bounded authority Critical Infrastructure Operational authority control AI Startups Runtime authority from day one
Explore Applications Where else machine authority applies
Enterprise Pricing
Request a Demo ↗
Platform Security Industries Financial Services Defense & National Security Critical Infrastructure AI Startups Explore Applications Enterprise Pricing Request a Demo
ARXIMUS LEGAL

TERMS
of Service

These Terms govern business use of Arximus Cloud, Enterprise services and runtime security capabilities.

BUSINESS ACCESS AUTHORITY DATA SECURITY COMMERCIAL TERMS CONTRACTS
TERMS OF SERVICE

Terms for Arximus business customers.

Effective date: 26 August 2026.

These Terms apply to Arximus business and institutional customers unless an executed Enterprise Agreement, Order Form or other binding written agreement expressly provides different terms.

01

Agreement, Scope & Contract Structure

These Terms of Service apply between Arximus ("Arximus") and the business, organization, public-sector body or other institutional customer that enters into an agreement for the Services ("Customer"). The Services are provided exclusively for business, organizational and institutional use and are not offered for personal, family, household or other consumer purposes.

If an individual accepts these Terms, an Order Form, an Enterprise Agreement or another contractual document on behalf of Customer, that individual represents that they have authority to bind Customer.

The agreement between Arximus and Customer (the "Agreement") consists of these Terms together with any applicable Order Form, Enterprise Agreement, Data Processing Agreement, Security Addendum, Service Level Agreement, Regulatory Addendum and other written terms expressly incorporated into the Agreement.

Enterprise customers may negotiate customer-specific terms with Arximus. A negotiated term changes the baseline Terms only to the extent that the signed document expressly addresses and changes that subject. All provisions not expressly changed continue to apply.

If documents conflict, subject-specific documents control within their subject matter: the Data Processing Agreement controls personal-data processing, the Service Level Agreement controls uptime, service levels and service credits, the Security Addendum controls expressly agreed security commitments, and a Regulatory Addendum controls the regulatory matters it expressly addresses. For other conflicts, a signed Enterprise Agreement controls an Order Form, an Order Form controls these Terms, and these Terms control general Documentation or policies unless a signed document expressly states a different order of precedence.

02

Definitions

"Customer Data" means data, prompts, content, policies, configurations, protected operations, instructions and other material submitted to, transmitted through or made available to the Services by or for Customer.

"Customer Personal Data" means personal data contained in Customer Data that Arximus processes as processor or subprocessor on behalf of Customer.

"Service Content" means prompts, model inputs and outputs, submitted operations, tool or API requests, protected-function parameters, documents, retrieved context and other content processed through the applicable service path.

"Security Evidence" means structured records generated for security, authorization, release and accountability purposes, including relevant identifiers, policy and decision information, verification results, protected-operation information, release information and execution results where an authoritative source reports such results.

"Operational Metadata" means technical, service, usage, metering and operational information generated in connection with operating, securing, supporting, measuring and troubleshooting the Services, excluding ordinary Service Content except where expressly stated.

"Customer-Controlled Executor" means the Customer-controlled system or Customer-designated execution environment that receives an authorized released operation and performs the underlying Customer business action using Customer-controlled execution authority.

"Documentation" means Arximus's then-current official technical or product documentation describing the operation and supported use of the applicable Services.

"Order Form" means an ordering document, order confirmation or other binding commercial document identifying Services purchased by Customer.

"Services" means the Arximus Cloud, Enterprise, runtime authorization, security, evidence, deployment and related services purchased or authorized for use under the Agreement, excluding Customer-selected third-party products and services.

"Security Measures" means the technical and organizational security measures Arximus expressly commits to maintain under the Agreement, including any applicable Data Processing Agreement or Security Addendum.

"Arximus Provider" means a hosting provider, subprocessor, contractor or other third party selected by Arximus to support delivery of the Services.

"Customer-Selected Third-Party Service" means an application, AI provider, API, database, executor, destination, identity system, infrastructure service or other third-party product or service selected, controlled or directed by Customer rather than Arximus.

03

The Arximus Service

Arximus provides runtime security and authorization capabilities for protected machine-driven operations. The Services may evaluate trusted identity, delegated authority, policy, context, verification results and operation binding to determine whether a requested operation is authorized.

For consequential operations, Arximus may authorize, bind and release an exact approved operation through a protected service path. Arximus does not perform the Customer's underlying payment, deployment, booking, command, database change, API operation or other protected business action.

A Customer-Controlled Executor performs actual execution using Customer-controlled execution authority. Arximus authorization, release, acknowledgement and reported execution are distinct events: AUTHORIZED ≠ RELEASED ≠ ACKNOWLEDGED ≠ EXECUTED / RESULT REPORTED.

Arximus does not treat authorization or release as proof that Customer-side execution occurred. Arximus records an execution result as such only where the Customer-Controlled Executor or another authoritative source reports that result to Arximus.

04

Accounts & Access Security

Customer is responsible for maintaining accurate account information, protecting credentials and authentication factors, controlling authorized users and workloads, configuring appropriate roles and permissions and promptly notifying Arximus of suspected unauthorized access.

Customer must not share credentials in a manner that defeats account controls, bypass authentication or security mechanisms, or grant access to persons or workloads that are not authorized to use the Services.

Arximus may require credential rotation, additional authentication, verification or access restrictions when necessary to address a security risk or protect the Services, Customer or other customers.

Service access may be restricted to authorized domains, personnel, workloads, deployment environments or other access boundaries established for Customer.

05

Customer Authority, AI & Execution Responsibility

Customer controls its applications, AI systems, models, agents, policies, delegated authority, human approval requirements, integrations, protected operations, execution environments, destinations and customer-controlled executors. Customer is responsible for determining whether those elements are lawful and appropriate for Customer's intended use.

Customer is responsible for defining who or what may request protected operations, the authority those actors receive, the policies and approval paths that apply, and which customer-controlled systems may execute released operations.

Arximus authorization decisions depend on the policy, authority, trusted context and other information supplied or made available to the applicable service path. Customer must ensure that Customer-controlled inputs used for authorization are accurate, authorized and appropriate for the intended decision.

Arximus does not control the underlying AI system and does not assume responsibility for AI-generated content, hallucinations, reasoning, recommendations, classifications, tool selections, autonomous behavior, prompt injection, model compromise or other behavior originating from an AI system or customer-controlled component, except to the extent a loss is independently caused by Arximus's breach of an obligation expressly assumed under the Agreement.

Customer-Controlled Executors remain responsible for actual execution and for the credential, account, token, signing authority, network privilege or other runtime capability required to perform the underlying Customer action. Provider credentials used by Arximus to connect to an AI or service provider are distinct from the execution authority used by a Customer-Controlled Executor.

Where Customer requires a protected destination to reject direct bypass traffic, including through an Arximus Lock configuration, Customer must configure the relevant executor, destination, network or surrounding infrastructure to enforce the trusted Arximus release path. Arximus cannot prevent or control a path that the Services do not observe or that Customer-controlled infrastructure does not require to pass through Arximus.

Customer must not treat an Arximus authorization, release decision, verification result, security signal, classification, evidence record or other service output as a substitute for any independent review, professional judgment, human approval or legal safeguard required for Customer's use case.

06

Customer Data, Ownership & Data Use

As between the parties, Customer retains all right, title and interest in Customer Data. Except for the limited rights needed to provide the Services, the Agreement does not transfer ownership of Customer Data to Arximus.

Customer grants Arximus and its authorized Arximus Providers a limited, non-exclusive right to host, transmit, process, copy and otherwise handle Customer Data only as necessary to provide, secure, support and maintain the Services, comply with the Agreement and applicable law, and perform Customer's documented instructions.

Arximus will not use Customer Data to train general-purpose or unrelated AI models, or to develop products for other customers, unless Customer expressly agrees in writing.

Arximus may generate and use aggregated or de-identified service telemetry, including usage volumes, latency, reliability, capacity, security and error-rate information, to operate, secure, plan, maintain and improve the Services, provided that such information does not identify Customer, identify an individual or disclose Customer Data.

Customer is responsible for the lawfulness of Customer Data and represents that it has the rights, permissions, notices, consents and other authority required to provide Customer Data to Arximus and instruct Arximus to process it.

Arximus treats Service Content, Security Evidence and Operational Metadata as distinct categories with separate processing and retention purposes. Ordinary Service Content, including ordinary AI content, is not retained by default and may be processed transiently where necessary to provide the applicable service path. Additional Service Content retention may occur where enabled or requested by Customer, required for authorized support or forensic work, required for a configured feature, or required by applicable law.

Security Evidence may be retained separately from Service Content according to service configuration, the Agreement, security requirements and applicable law. Security Evidence may continue to exist even where the underlying Service Content was processed transiently and was not retained.

Arximus may process short-lived runtime security state and Operational Metadata necessary to apply policy, preserve relevant security context, operate and secure the Services, troubleshoot technical issues, meter usage and maintain service reliability. Runtime security state is intended to preserve security meaning rather than become an uncontrolled copy of complete conversations.

07

Privacy & Data Protection

Arximus processes personal data in accordance with its Privacy Policy.

Where Arximus processes Customer Personal Data as processor or subprocessor, the applicable Arximus Data Processing Agreement forms part of the Agreement before that processing begins.

Where Customer acts as controller, Customer determines the purposes and lawful basis of the underlying processing and provides the documented instructions under which Arximus processes Customer Personal Data. Where Customer acts as a processor for another controller, Customer represents that it is authorized to appoint Arximus as subprocessor.

Customer remains responsible for the legality of its collection, use and disclosure of personal data and for satisfying the controller or processor obligations that apply to Customer.

Arximus's compliance posture does not transfer Customer's independent legal obligations to Arximus and does not by itself make Customer's AI system, deployment, organization or processing activity compliant with any law or standard.

08

Security, Compliance & Assurance

Arximus will maintain the Security Measures applicable to the Services. These may include controls relating to authentication, authorization, access restriction, logical separation, system integrity, secure development, monitoring, vulnerability management, resilience, supplier security and incident response.

Current public assurance status and controlled access to additional security and compliance documentation are available through Compliance & Assurance.

Certification, independent attestation, regulatory applicability, standards alignment and Arximus's own implementation of controls are distinct concepts. No statement constitutes certification, attestation or regulatory approval unless expressly stated as such.

Any contractual security-incident notification period, audit right, control commitment or customer-specific security requirement applies only where set out in the applicable Data Processing Agreement, Security Addendum, Regulatory Addendum, Enterprise Agreement or other binding written term.

09

European Service Environment & Regulated Deployments

Arximus is a Swedish company and operates its standard European service environment within the European Union unless another deployment location is expressly agreed with Customer.

Current processing locations and infrastructure information relevant to legal, security or procurement review are made available through the applicable customer or compliance channel.

Specific Enterprise deployment, residency, dedicated infrastructure, connectivity or geographic commitments apply only where included in an Order Form, Enterprise Agreement or other binding written agreement.

Where a regulated Customer requires additional contractual terms, including requirements applicable to regulated ICT services or operational resilience, the parties may enter into a Regulatory Addendum addressing the required service description, locations, service levels, incident assistance, audit or access rights, transition arrangements and other required matters. Such additional obligations apply only to the extent incorporated into the Agreement.

10

Arximus Providers & Subprocessors

Arximus may use Arximus Providers to support hosting, infrastructure, authentication, monitoring, communications, support, security and other operational functions required to provide the Services.

Arximus remains Customer's contractual counterparty and remains responsible for performing the obligations that Arximus expressly assumes under the Agreement, including obligations that Arximus performs through an Arximus Provider. Use of an Arximus Provider does not transfer those contractual responsibilities to Customer.

Arximus does not guarantee that an Arximus Provider, network or infrastructure component will never experience an outage, attack, defect or other failure. Arximus is responsible for its own provider selection, contractual controls, architecture and response obligations to the extent expressly required by the Agreement.

Where an Arximus Provider processes Customer Personal Data, subprocessor appointment, notice and objection rights are governed by the applicable Data Processing Agreement. Current subprocessor information is made available through the applicable compliance or contractual channel.

11

Customer-Selected Third-Party Services

Customer may configure the Services to interact with Customer-Selected Third-Party Services, including external models, classifiers, APIs or other services selected by Customer or invoked through a Customer-configured private extension. Customer is responsible for its relationship with those providers and for obtaining the rights, permissions, licenses, credentials and authority necessary to use them with Arximus.

Where the Services execute a Customer-defined private extension, that extension remains Customer-controlled logic within the configured service path. If Customer configures the extension to transmit data to a Customer-Selected Third-Party Service, that transmission is performed according to Customer's configuration and instruction.

Where Customer directs Arximus to transmit data, an operation or other information to a Customer-Selected Third-Party Service, Arximus is responsible for performing the agreed transmission through the Arximus-controlled service path. Arximus is not responsible for what the Customer-Selected Third-Party Service subsequently does with that information or operation.

To the maximum extent permitted by law, Arximus is not responsible for the availability, security, performance, accuracy, reliability, conduct, compatibility or failure of Customer-Selected Third-Party Services, except to the extent a loss is independently caused by Arximus's breach of an obligation expressly assumed under the Agreement.

12

Acceptable Use

Customer must not use the Services to violate applicable law, infringe third-party rights, gain unauthorized access to systems or data, distribute malicious code, intentionally disrupt or degrade the Services, circumvent security or authorization controls, misrepresent identity or authority, or violate applicable sanctions or export-control requirements.

Customer must not probe, scan or test the vulnerability of Arximus systems except under written authorization or an applicable published security-testing program, and must not attempt to obtain Arximus credentials, cryptographic material, source code or protected internal security mechanisms except where such restriction is prohibited by law.

Arximus may investigate suspected misuse and may take proportionate protective action where necessary to protect the Services, customers, third parties or legal compliance.

13

Commercial Terms, Fees & Billing

Customer's pricing, service term, minimum commitments, included usage, billing model, invoicing terms and payment obligations are determined by the applicable Order Form, Enterprise Agreement or other binding commercial agreement.

Where usage-based pricing applies, Arximus measures usage according to the metering method specified in the applicable commercial terms. Where secured-token metering applies, input and output tokens processed by Arximus are combined into the applicable secured-token total.

Customer must pay applicable fees, usage charges, taxes and other amounts according to the payment terms in the Agreement. Model-provider, cloud-infrastructure and other third-party charges are separate from Arximus charges unless expressly included in writing.

If a payment is cancelled, reversed, disputed, charged back, unauthorized or otherwise not successfully received, Arximus may restrict or suspend affected Services after any notice period required by the Agreement until the resulting undisputed amount is resolved.

Fees for completed Services and incurred usage are non-refundable except where required by law or expressly provided by the Agreement. Minimum commitments remain payable for the applicable committed term unless Customer terminates for Arximus's uncured material breach or another express contractual termination right provides otherwise.

14

Service Changes & Core Functionality

Arximus may update, maintain and improve the Services and may change functionality for product development, security, reliability, legal compliance or third-party dependency changes.

During a paid committed service term, Arximus will not intentionally make a change that materially reduces the core functionality of the affected paid Service as described in the applicable Documentation or Order Form, except where the change is required to address law, security, reliability, a material third-party dependency issue or another circumstance outside Arximus's reasonable control.

For a planned material reduction that Arximus controls, Arximus will provide at least thirty days' prior notice. If thirty days' notice is not possible because of law, security, an emergency or a dependency outside Arximus's control, Arximus will provide notice before the change where legally and operationally possible, or otherwise promptly after the change.

If a required change materially impairs functionality expressly purchased by Customer, Arximus will use commercially reasonable efforts to provide materially equivalent replacement functionality. If Arximus cannot provide such replacement within thirty days after the material impairment begins, Customer may terminate the affected Service and receive a pro rata refund of prepaid, unused fees for that affected Service. This paragraph does not apply to beta, preview, evaluation or no-charge functionality.

15

Service Levels & Support

No contractual uptime percentage, support response time, service credit, recovery objective or other service-level commitment applies unless expressly stated in an applicable Service Level Agreement, Order Form, Enterprise Agreement or other binding written agreement.

Where a Service Level Agreement applies, it controls the measurement, exclusions, maintenance treatment, support response commitments, service credits and remedies for the service levels it addresses.

Failure of an Arximus Provider does not automatically excuse Arximus from a service-level commitment that Arximus expressly assumed. Any provider, network, force-majeure or other exclusions from an SLA must be stated in the applicable SLA or other binding agreement.

16

Suspension

Arximus may suspend or restrict access where necessary to address an active attack, fraud, unlawful use, unauthorized access, material non-payment, a Security Emergency, a material breach of the Agreement or an urgent risk to the integrity of the Services or other customers.

Where the circumstances allow, Arximus will provide notice before suspension and will limit the suspension to the users, workloads, integrations or Services reasonably necessary to address the issue. Where immediate action is required, Arximus may act without prior notice and will notify Customer as soon as legally and operationally possible after taking the action.

Arximus will restore affected access after the condition requiring suspension has been resolved, subject to payment of undisputed overdue amounts and any security verification reasonably required to restore access safely.

17

Intellectual Property

Arximus and its licensors retain all right, title and interest in the Services, software, interfaces, Documentation, security mechanisms, designs, trademarks, know-how and related technology, excluding Customer Data.

Subject to the Agreement and payment of applicable fees, Arximus grants Customer a limited, non-exclusive, non-transferable right to access and use the Services during the applicable service term.

Customer may not copy, resell, sublicense or distribute the Services, remove proprietary notices or attempt to obtain source code except as expressly permitted by the Agreement or where such restriction is prohibited by law.

If Customer voluntarily provides ideas, suggestions or feedback about the Services without a separate written development agreement, Arximus may use that feedback without restriction or compensation, provided that doing so does not grant Arximus ownership of Customer Data or Customer Confidential Information.

18

Indemnification

Arximus IP indemnity. Arximus will defend Customer against a third-party claim alleging that the unmodified Services, when used by Customer as authorized under the Agreement, infringe a third party's patent, copyright, trademark or other intellectual property right in a jurisdiction in which Arximus has expressly agreed to provide the affected Services. Arximus will indemnify Customer for damages, costs and reasonable legal fees finally awarded against Customer or agreed in a settlement approved by Arximus resulting from such claim.

Arximus has no obligation for a claim to the extent it results from Customer Data, Customer's modification of the Services, use contrary to the Agreement or Documentation, a combination with products or services not supplied or approved by Arximus where the claim would not otherwise have arisen, or a Customer-Selected Third-Party Service.

If an infringement claim is made or Arximus reasonably believes one is likely, Arximus may obtain the right for Customer to continue using the affected Service, modify or replace the affected Service with a materially equivalent non-infringing alternative, or terminate the affected Service and refund prepaid, unused fees for the remaining committed term of that affected Service.

Customer indemnity. Customer will defend Arximus against third-party claims to the extent arising from Customer Data, a Customer-controlled application or system, Customer's use of the Services in violation of the Agreement, or Customer's infringement or violation of third-party rights. Customer will indemnify Arximus for damages, costs and reasonable legal fees finally awarded against Arximus or agreed in a settlement approved by Customer resulting from such claim.

An indemnified party must promptly notify the indemnifying party of the claim, provide reasonable cooperation at the indemnifying party's expense and allow the indemnifying party to control the defense and settlement. Failure to give prompt notice relieves the indemnifying party only to the extent the delay materially prejudices the defense. The indemnifying party may not settle a claim in a manner that requires the indemnified party to admit fault, pay money or undertake a material obligation without the indemnified party's prior written consent.

This Section states the parties' exclusive contractual remedies for third-party intellectual-property infringement claims, except for any separate termination right expressly provided by the Agreement.

19

Confidentiality

"Confidential Information" means non-public information disclosed by one party (the "Disclosing Party") to the other (the "Receiving Party") that is marked confidential or that, given its nature and the circumstances of disclosure, should reasonably be understood to be confidential.

Confidential Information does not include information that the Receiving Party can demonstrate was lawfully known without confidentiality restriction, independently developed without use of the Confidential Information, lawfully received from a third party without confidentiality duty, or becomes public through no breach of the Agreement.

The Receiving Party will use Confidential Information only to exercise its rights and perform its obligations under the Agreement, will protect it using at least the same degree of care used for its own confidential information of similar sensitivity and in no event less than commercially reasonable care, and will not disclose it except as permitted by this Section.

The Receiving Party may disclose Confidential Information to its employees, Affiliates, contractors, Arximus Providers, lawyers, auditors, accountants and professional advisers who have a need to know the information for the Agreement and are bound by confidentiality obligations or professional duties protecting the information. The Receiving Party is responsible for compliance with this Section by those persons acting on its behalf.

If the Receiving Party is legally compelled to disclose Confidential Information, it will, to the extent legally permitted, provide prior notice to the Disclosing Party and disclose only the portion legally required. The Receiving Party will reasonably cooperate, at the Disclosing Party's expense, with lawful efforts to seek confidential treatment or limit the disclosure.

Upon termination or written request, each party will return or destroy the other party's Confidential Information that it no longer needs, except for copies retained in standard backups, internal legal or compliance records, or where retention is required by law. This Section continues to protect any retained copies.

Confidentiality obligations continue for five years after termination or expiration of the Agreement. Trade secrets remain protected for as long as they qualify as trade secrets under applicable law.

20

Service Warranties

During the applicable paid service term, Arximus warrants that the Services, when used in accordance with the Agreement and Documentation, will materially conform to the applicable Documentation.

Arximus warrants that it will provide the Services with professional care and skill, maintain the Security Measures, comply with laws directly applicable to Arximus in providing the Services, and not knowingly introduce malware or malicious code into the Services.

If Customer believes Arximus has materially breached a warranty in this Section, Customer must provide written notice describing the failure in sufficient detail for Arximus to investigate. Arximus will have thirty days after receipt of the notice to cure the failure.

If Arximus does not cure the material warranty failure within that thirty-day period, Customer may terminate the affected Service and receive a pro rata refund of prepaid, unused fees for the remaining committed term of that affected Service. Unless another remedy is expressly stated in a signed agreement, this is Customer's exclusive remedy for breach of the warranties in this Section.

These warranties do not apply to failures caused by Customer Data, Customer-controlled systems, Customer-Selected Third-Party Services, unauthorized modifications, use contrary to the Agreement or Documentation, or beta, preview, evaluation or no-charge functionality.

21

Service Disclaimers

Subject to the express warranties and obligations in the Agreement, and to the maximum extent permitted by law, the Services are otherwise provided "as is" and "as available" without additional warranties, whether express, implied or statutory.

Arximus does not warrant that the Services will operate continuously, without interruption, without delay, without error, without vulnerability or without failure, or that every defect, security event, attack or service interruption can be prevented or detected.

The occurrence of a cyberattack, criminal act or third-party infrastructure failure does not by itself establish that Arximus breached the Agreement. Where a loss results from Arximus's failure to comply with an express Security Measure or other contractual obligation, Arximus's responsibility is determined under the Agreement, including the applicable liability limits.

Arximus does not warrant the accuracy, completeness, reliability, suitability, safety or lawfulness of AI-generated content, model outputs, instructions, recommendations, classifications, reasoning, tool selections, proposed operations or other behavior originating from an AI system, model, agent, application or component outside Arximus's control.

Arximus does not warrant that Customer's configuration, policies, authority model, integrations, human approval process, execution environment or use of the Services will independently satisfy Customer's legal, regulatory, contractual, security or operational requirements.

Beta, preview, evaluation and no-charge functionality may be changed or discontinued at any time, may not be supported and may not have the same security, availability or assurance characteristics as paid generally available Services.

22

Liability Exclusions, Limits & Special Claims

To the maximum extent permitted by law, neither party will be liable to the other for indirect, incidental, special, exemplary, punitive or consequential damages, or for lost profits, lost revenue, lost business opportunities, loss of goodwill, loss of anticipated savings or reputational damage, regardless of the theory of liability and even if the possibility of such loss was known.

Reasonable direct costs required to restore or reconstruct Customer Data that Arximus directly loses or corrupts through Arximus's breach of the Agreement are not excluded solely because they relate to data, but remain subject to the applicable liability cap. Service credits expressly payable under an applicable Service Level Agreement are governed by that Service Level Agreement.

Except for Special Claims, Customer payment obligations and liability that cannot lawfully be limited, each party's total aggregate liability arising out of or relating to the Agreement will not exceed the fees paid or payable by Customer to Arximus for the affected Services during the twelve months immediately preceding the first event giving rise to the liability (the "General Liability Cap").

For Special Claims, each party's total aggregate liability will not exceed two times the General Liability Cap (the "Special Liability Cap"). Special Claims are: (a) Arximus's breach of the Security Measures that results in unauthorized access to, disclosure of or loss of Customer Data; (b) a party's breach of the confidentiality obligations in Section 19; (c) claims subject to the Data Processing Agreement where that agreement does not expressly provide a different liability limit; and (d) either party's indemnification obligations under Section 18.

The General Liability Cap and Special Liability Cap are aggregate limits, not amounts payable automatically. A claimant must establish an actual recoverable loss caused by the other party's breach. Multiple claims, events or legal theories do not increase the applicable aggregate cap.

Customer remains responsible for fines, penalties, claims and losses arising from Customer's unlawful use, Customer Data, Customer-controlled systems, Customer's AI behavior, Customer's instructions or Customer's failure to comply with obligations applicable to Customer, except to the extent Arximus independently caused the same loss through breach of an obligation expressly assumed under the Agreement.

Nothing in the Agreement excludes or limits liability to the extent that exclusion or limitation is prohibited by mandatory applicable law. The limitations in this Section apply regardless of whether a claim is framed in contract, tort, negligence, statute or another legal theory and survive termination or expiration.

23

Term & Termination

The Agreement continues for the service term stated in the applicable Order Form or Enterprise Agreement. Renewal terms and non-renewal requirements, if any, are governed by the applicable commercial terms.

Either party may terminate the Agreement or an affected Service for material breach if the breaching party fails to cure the breach within thirty days after receiving written notice that describes the breach in sufficient detail to identify the contractual obligation at issue.

Either party may terminate the Agreement if the other party ceases business operations, becomes insolvent or becomes subject to a formal insolvency, liquidation or similar proceeding that is not dismissed within the period required by applicable law.

Arximus may suspend or terminate affected access immediately where continued use presents an active security threat, involves fraud or unlawful activity, is prohibited by law, or creates an urgent risk that cannot safely be addressed through the ordinary thirty-day cure process. Where legally and operationally possible, Arximus will notify Customer promptly of the action and its basis.

Customer may terminate for convenience only where the applicable Order Form or Enterprise Agreement permits it. A Customer that terminates a committed term without contractual cause remains responsible for the committed fees.

If Customer terminates an affected Service because of Arximus's uncured material breach, or if Arximus terminates an affected Service because Arximus is unable to continue providing it for reasons not caused by Customer, Arximus will refund prepaid, unused fees allocable to the terminated portion of that affected Service. No refund is owed for termination caused by Customer's breach or for usage already provided.

24

Data Exit, Retention & Deletion

For thirty days after expiration or termination of the affected Services, Customer may request or retrieve the Customer Data, Security Evidence and customer-owned configuration that the Services make available for export, subject to payment of undisputed amounts due and any security restrictions necessary to protect the data. Data that was processed only transiently, has already expired under applicable runtime controls or has already been deleted is not available for later export.

If live account access has been suspended or terminated for security or legal reasons, Arximus may provide an export through another secure method where legally permitted and technically available rather than restoring live service access.

After the thirty-day exit period, Arximus may delete remaining Customer Data from active systems in accordance with its standard deletion processes and applicable contractual retention requirements. Backup copies may remain until deleted through normal backup rotation. Any retained backup remains subject to applicable confidentiality and security obligations.

Arximus may retain billing records, Security Evidence, legal records or other information for longer where retention is required by law, required by the Agreement, necessary to establish or defend legal claims, or necessary to complete an active security or fraud investigation. Retained information may be used only for the purpose justifying the retention and remains protected under the Agreement.

Upon written request, Arximus will provide confirmation after deletion from active systems has been completed, subject to backup rotation and legally required retention.

Enterprise customers may purchase or negotiate additional transition assistance, export support or a limited post-termination service period. Arximus has no obligation to configure a replacement provider or migrate Customer into a competitor's service. Continued live processing after termination applies only where separately agreed in writing and paid in advance.

25

Events Beyond Reasonable Control

Neither party is liable for delay or failure to perform an obligation to the extent caused by an event beyond that party's reasonable control, including war, terrorism, civil unrest, governmental action, natural disaster, fire, flood, extreme weather, epidemic, pandemic, labor disruption, utility failure, telecommunications or Internet failure, widespread cyberattack, previously unknown vulnerability, or material failure of infrastructure outside the party's control.

This Section does not excuse Customer's obligation to pay undisputed amounts already due, does not excuse a party from obligations that by their nature continue during the event, and does not excuse a failure to the extent caused by that party's own breach of an express contractual security, resilience or continuity obligation.

The affected party will use commercially reasonable efforts to reduce the impact of the event and resume performance as soon as reasonably practicable. Any specific disaster-recovery, business-continuity or resilience commitments are governed by the applicable Enterprise Agreement, Security Addendum, Service Level Agreement or Regulatory Addendum.

26

Publicity & Customer References

Neither party may use the other party's name, logo, trademarks or branding in public marketing materials, customer lists, case studies, press releases or other public statements about the relationship without the other party's prior written consent.

Consent may be limited to a specific use and may be withdrawn prospectively in writing, subject to any publication already lawfully distributed before withdrawal.

27

General Contract Terms

Contracting entity. The Arximus contracting entity is the Swedish legal entity identified as supplier on the applicable Order Form, invoice, Enterprise Agreement or other contracting document. Arximus will make the applicable registered entity details and legal-notice contact available to Customer through its contracting materials or website.

Notices. Routine operational notices may be provided through the Services, the account email address or another agreed communication channel. A notice of material breach, termination for cause or indemnification claim must be sent in writing to the legal or contractual notice contact identified by the receiving party in the Order Form, Enterprise Agreement, account records or other contracting materials. A party must keep its notice information current.

Assignment. Neither party may assign the Agreement without the other party's prior written consent, except to an Affiliate or in connection with a merger, reorganization, sale of substantially all assets or other change of control, provided that the assignee assumes the assigning party's obligations and the assignment does not materially reduce the other party's contractual rights.

Independent parties. The parties are independent contractors. The Agreement does not create a partnership, joint venture, fiduciary relationship, employment relationship, franchise or agency relationship between the parties.

No third-party beneficiaries. Except for persons expressly entitled to protection under an indemnification provision, the Agreement does not give rights or remedies to any person that is not a party to the Agreement.

Entire agreement. The Agreement is the complete agreement between the parties concerning its subject matter and replaces prior or contemporaneous proposals, discussions and representations concerning that subject matter. Purchase-order terms or other unilateral customer documents do not modify the Agreement unless Arximus expressly accepts them in a signed writing.

Waiver and severability. Failure to enforce a provision is not a waiver. If a provision is held unenforceable, it will be enforced to the maximum extent permitted and the remaining provisions will continue in effect.

Survival. Provisions that by their nature should continue after expiration or termination survive, including payment, confidentiality, intellectual property, indemnification, liability limitations, data-retention obligations, dispute provisions and any accrued rights or obligations.

Export and sanctions. Each party is responsible for complying with export-control, sanctions and trade laws that apply directly to that party's performance under the Agreement.

Electronic contracting. The Agreement may be accepted electronically and may be executed in counterparts. Electronic acceptance and electronic signatures have the same contractual effect as other forms of execution to the extent permitted by law.

Language. If the Agreement is translated, the English-language version controls to the extent permitted by law unless a signed Enterprise Agreement expressly states otherwise.

28

Governing Law & Disputes

These Terms and the Agreement are governed by the laws of Sweden, without regard to conflict-of-law rules, except where mandatory applicable law requires otherwise.

Any dispute arising out of or relating to the Agreement or Services will be subject to the exclusive jurisdiction of Stockholm District Court (Stockholms tingsrätt), Sweden, as the court of first instance, unless the parties expressly agree to a different dispute-resolution mechanism in an Enterprise Agreement or other binding written agreement.

Before commencing formal proceedings, each party will provide written notice describing the dispute and the relief requested. Authorized representatives of the parties will attempt in good faith to resolve the dispute for thirty days after receipt of that notice. This process does not prevent either party from seeking urgent interim or injunctive relief where delay could cause irreparable harm or compromise security.

29

Changes to These Terms

Arximus may update these public Terms to reflect changes to the Services, law, security requirements, billing practices or business operations. The current public version will be published on this page with an updated effective date.

For Customers using the Services under public Terms without a separately signed Enterprise Agreement, a material change that adversely affects Customer's contractual rights will take effect no earlier than thirty days after notice, except where an earlier change is required by law or necessary to address an urgent security issue. During a paid committed term, a materially adverse change will otherwise apply at renewal rather than retroactively to the existing committed term.

Publication of revised public Terms does not amend or override a signed Enterprise Agreement, Order Form, Data Processing Agreement, Security Addendum, Service Level Agreement or Regulatory Addendum except through the amendment process stated in that document or another written agreement signed by the parties.

COMPLIANCE & ASSURANCE

Review Arximus before deployment.

Request data-processing terms, security documentation, subprocessor information and other procurement material through the Arximus compliance review process.

Compliance & Assurance ↗ Privacy Policy
ARXIMUS AI Runtime Authorization

Arximus is the authorization and enforcement layer between AI and the systems it can act on. It determines whether protected actions are authorized, enforces those decisions at runtime and preserves evidence of what happened.

Privacy Policy Terms of Service
Product Platform Security Enterprise Pricing Applications
Industries Financial Services Defense & National Security Critical Infrastructure AI Startups
Company About Compliance Contact
AI Runtime Authorization Control AI authority before execution. Request a Demo↗
© 2026 Arximus. All rights reserved. AI Security & Governance Infrastructure