Legal
Terms & Data Rights
You are buying a verdict on how your agent behaves under attack. Plans are metered on how many agents you protect and how many runs you execute. This page states exactly what is recorded per run and how Ironhide reuses it — the scrubbed environment your agent was tested against, added to a shared attack library, never your agent's own trajectory.
Beta terms · Applies to the hosted Ironhide evaluation service. The data-rights terms below are what the system enforces today. The wider contract (liability, governing law) is being finalized with counsel for general availability.
01
What Ironhide does with a run
You connect your agent — an action-taking AI agent — and Ironhide runs it, pre-production and inside your own CI/CD, through multi-turn behavioral and adversarial episodes: a sandboxed arena seeded with staged attacks such as injected instructions in tool results, poisoned fixtures, and planted canary credentials. After each episode the referee grades observed state — what your agent actually did (state changes, tool calls, attempted exfiltration), never what it said about itself — and returns a verdict: pass or fail, a severity, why, and the supporting evidence.
Every episode is hand-authored, synthetic; the attacks are staged, not drawn from your production systems. Your agent runs against Ironhide's episodes only — it never sees another customer's data, and no other customer's agent ever sees yours.
02
What gets recorded per run
Each run is saved as one trajectory: a single labeled example made of the episode your agent was run through, the actions it took (tool calls, state changes, egress attempts), the observed-state evidence, the referee's verdict, and metadata (timestamps, episode id, version hashes, and your agent's opaque id).
The trajectory is what renders your reports and drives your CI gate. What Ironhide reuses to improve the product is the environment your agent was tested against — scrubbed and generalized into new attack episodes — not your agent's own actions or prompts. Every run is stamped owned; there is no private/public split and no opt-out to make.
03
How your runs improve Ironhide
The value Ironhide compounds is a growing library of environments to test agents against. From what your agent encountered in an episode, Ironhide may:
- Shadow and scrub the environment your agent ran against, and add it to the shared attack-episode library so every agent is graded against a larger world.
- Author new and harder attack episodes derived from the patterns agents resist or fall for.
- Sharpen the referee and calibrate difficulty.
- Build training and evaluation datasets that Ironhide exports, benchmarks, and licenses.
Your agent's trajectory is never resold, and reuse is never public with your identity attached. Before anything leaves Ironhide it is de-identified: your name, contact email, endpoint URL, keys, secrets, and prompts are never included, and your agent's id is replaced with a random, per-export pseudonym that cannot be joined back to you or to any other export. Preview-grade and held-out evaluation output is excluded from every shared or sold dataset. No one can look up what your agent did.
04
Usage tiers
Plans meter two things: protected agent count and monthly execution volume. Data rights are not a pricing axis and not a feature — every run is owned on every tier, and what Ironhide keeps is the scrubbed environment, not your trajectory.
| Tier | Price | Quota |
|---|---|---|
| Developer | Free | 1 agent · 100 runs/mo |
| Team | $199/mo | 10 agents · 2,500 runs/mo |
| Business | $999/mo | 50 agents · 15,000 runs/mo |
| Enterprise | Contact us | Unlimited |
Your runs still work only for you. Beyond your own reports, your agent's runs drive exactly one thing: your own CI gate — the pre-deploy check that asks whether your agent regressed against your own baseline. That computation is same-tenant only: it reads only your agent's runs and shows the result only to you. On the Business tier and up, custom environments and their runs live in a per-tenant, customer-isolated Spec Vault.
05
What Ironhide never collects
Ironhide runs one way: your agent runs where it already lives, inside your own CI/CD.
- Your agent stays with you. Its code, weights, and prompts never leave your infrastructure. The episode runs in your pipeline; only the run results flow back to Ironhide.
- Results flow inbound. What Ironhide receives is the record of the run — the actions your agent took and the observed-state evidence the referee grades — sent over an authenticated connection keyed to your wk_live_ API key.
- No production data. Episodes are staged, synthetic attacks. Ironhide never scans, reads, or stores anything from your production systems.
Your API key is shown once and stored only as a hash; Ironhide cannot recover it. Agent routes require that key; operator routes require a separate operator token.
06
Retention and deletion
Delete your agent and Ironhide removes your registration and all stored secrets immediately. Your reports and run history go with it.
Reuse is de-identified and non-reversible after the fact. Scrubbed, generalized environment data that has already been added to the shared library at record time no longer carries your identifiers or your agent's trajectory, so it is not individually recallable. It was never your agent's prompts, code, or actions to begin with — only the staged world it was tested against.
07
Beta status and no warranty
Ironhide is beta software provided "as is," without warranty of any kind. Verdicts, reports, and benchmarks are evaluation signals from staged, synthetic attacks. They are not a security audit of your production systems, not a compliance attestation, and a passing verdict is not a guarantee that your agent is secure. Observed-state verdicts are a preview measurement — treat them as an honest new signal you are still calibrating, not a certification. Availability, APIs, and referee logic may change during the beta. Referee changes are versioned, and every run is stamped with the version that judged it, so historical verdicts stay interpretable.
Questions about these terms or your data? Email hello@ironhideai.com. Ready to pick a plan? See pricing.
IRONHIDE