Legal
Terms of service.
Plain language, because a term you cannot read is a term you cannot rely on. These terms cover the Formal Engines API, Python SDK, documentation, and this website while the platform is in private beta.
01
The service
What Formal Engines provides, and who this agreement is between.
Formal Engines is a hosted post-training platform. You publish an executable specification — an environment with tasks, tools, constraints, and the verifiers that decide what counts as success — then train and evaluate models against that specification and export a signed evidence bundle for the release decision.
The platform is in private beta. Access is granted per workspace and we may change what the beta includes. This agreement is between Formal Engines and you — or the company you are acting for, in which case you are confirming you may accept these terms on its behalf. Using the API, the SDK, or a key issued to you means you accept them.
02
Accounts and API keys
One workspace per email. Your key is a bearer credential.
Signing up issues one workspace and one API key per email address. Give us an address you control and can keep receiving mail at — it is how we reach you about breaking changes, capacity, and anything that affects your runs.
- Keys are bearer credentials. Anyone holding your key can act as your workspace. We cannot tell an authorised holder from an unauthorised one, so treat it like a password: keep it in a secret manager, not in a repository, a notebook, or a screenshot.
- We store only a hash. The key is shown once, at issue. We cannot recover or resend it — if it is lost or exposed we can revoke it and issue a new one, and nothing more.
- You are responsible for use of your key. Activity authenticated by your key counts as yours, including compute it consumes and content it submits. Tell us promptly at hello@formalengines.com if you believe a key has been exposed and we will rotate it.
- One workspace, one tenant. Workspaces are not designed to be shared between organisations that should not see each other's runs. If you need separate boundaries, ask us for separate workspaces.
03
Acceptable use
The short list of things that will get a workspace suspended.
Do not use Formal Engines to:
- Break the law. No unlawful content or activity, and nothing that infringes someone else's intellectual property, privacy, or other rights.
- Attack the service. No denial-of-service, no probing or exploiting the platform, no circumventing quotas, rate limits, or admission control, and no reverse engineering intended to get around those limits.
- Reach another workspace. Do not attempt to read, modify, or exfiltrate another workspace's specifications, runs, traces, checkpoints, or evidence, and do not try to break the isolation between workspaces or between runs.
- Use our compute as a side door. Environment code you supply executes on our infrastructure, inside isolated ephemeral compute that is created for a run and destroyed after it. That sandbox is there to run your evaluation, not to serve as general-purpose hosting, a crypto miner, a proxy, a scraper, or a launch point against third parties. Do not upload malware.
We may block content or code that breaks these rules, and we may suspend a workspace while we look into it — see termination.
04
Your content and IP
You own your environments, models, and evidence. We process them to run the service.
Your content is yours: the environments and specification versions you publish, the datasets and splits inside them, your prompts and rollout traces, the models and checkpoints you train, the metrics, and the evidence bundles that come out the other end. Publishing them here does not transfer any of it to us.
You grant us the narrow licence we need to run the service: to host, transmit, execute, and process your content in order to schedule and run training and evaluation, store artifacts, produce and sign evidence bundles, and diagnose failures you report or abuse we detect. That is the whole purpose of the licence, and it ends when your content is deleted.
We do not use your content to train our own models, and we do not share it with other customers. You are responsible for having the rights to what you submit — including licences for base models and for any data inside your environments.
The platform, SDK, documentation, and site remain ours. If you send us feedback or a bug report, we can use it to improve the product without owing you anything for it.
05
Beta terms
What we are not promising while the platform is in private beta.
The service is provided as-is and as-available, without warranties of any kind to the fullest extent the law allows. Specifically, during the beta:
- There is no SLA. We make no commitment on uptime, latency, queue time, or time to resolution. There are no service credits.
- Compute capacity is not guaranteed. Runs are scheduled on a small shared beta pool. Jobs queue, large jobs may not be admitted at all, and a running job can be interrupted, restarted, or cancelled if we need the capacity or something breaks.
- Features may change. Endpoints, SDK surfaces, defaults, and limits can change during the beta, sometimes without long notice. We will record breaking changes in the documentation and email workspace addresses when a change will break existing code.
- We hold no certifications. We are not audited or certified against SOC 2, ISO 27001, HIPAA, or any comparable framework, and we do not claim to be. If your data carries a regulatory obligation, talk to us before you send it.
- Keep your own copies. We take care with your artifacts, but this is a beta. Do not let this platform be the only place a checkpoint or an evidence bundle exists.
06
Fees
The beta is unbilled today. Paid plans arrive with notice, not a surprise invoice.
The beta is currently unbilled. There is no charge for runs, storage, or support today, and no payment method on file.
We will announce paid plans before they start. You will get notice by email to your workspace address, with the prices and the date they begin, before anything is charged — and the option to stop using the service instead. We will not bill you retroactively for beta usage, and we will not charge a workspace that has not accepted a paid plan.
07
Termination
How either side ends this, and what happens to your evidence afterwards.
You can stop at any time. Ask us to close your workspace and we will revoke the key and delete the workspace and its data.
We may suspend or terminate access if a workspace breaks these terms, is being used to attack the service or reach other workspaces, or if the law requires it. Where the circumstances allow, we will tell you first and give you a chance to fix it; where they do not — an active attack, for example — we will suspend first and explain afterwards. We may also end the beta itself, with reasonable notice to workspace addresses.
After termination for any reason other than deletion you requested, you have 30 days to export your evidence bundles and run artifacts through the API. After that window we delete them, and we will not be able to get them back.
08
Liability
The limits on what we owe you if the service fails you.
To the maximum extent permitted by applicable law, Formal Engines is not liable for indirect, incidental, special, consequential, or punitive damages, nor for lost profits, lost revenue, lost business, or lost or corrupted data, arising out of or relating to the service — even if we were told such damages were possible.
To the maximum extent permitted by applicable law, our total liability for all claims relating to the service is limited to the greater of the fees you paid us in the twelve months before the claim (during the unbilled beta, that is zero) or USD 100.
Nothing in these terms excludes or limits liability that cannot be excluded or limited by law, including liability for death or personal injury caused by negligence, or for fraud.
09
Changes and governing law
How these terms change, and the law that governs them.
We may update these terms as the platform changes. When we do, we change the date at the top of this page, and for changes that materially affect your rights or obligations we email workspace addresses before they take effect. Continuing to use the service after that is acceptance; if you do not accept, stop using the service and ask us to close the workspace.
These terms are governed by, and disputes will be resolved under, the following law and courts:[Governing law — to be completed].
If a court finds any part of these terms unenforceable, the rest stays in force. Our not enforcing a term on one occasion is not a waiver of it.
10
Contact
One address. A person reads it.
Questions about these terms, a key to rotate, a workspace to close, or capacity to discuss — write to hello@formalengines.com.
hello@formalengines.comPrivacy policy