• Agentic AI
    Attribution Agent Identity Secretless AI Tool Call Security
    Workload IAM
    Connection Security Identity Federation Secretless Infrastructure Zero-Touch Operations Quantum-Safe Connections
    Kubernetes
    mTLS Without a Service Mesh SPIFFE Without SPIRE Machine Identity
    Agentic AI
    attribution Attribution north_east Trace every AI action back to the human who initiated it. fingerprint Agent Identity north_east Give every agent its own cryptographic identity and permissions. key_off Secretless AI north_east Agents reach tools and data without ever holding a credential. policy Tool Call Security north_east Inspect and authorize every tool call in real time.
    Workload IAM
    lock Connection Security north_east Authenticate and encrypt every workload connection, automatically. hub Identity Federation north_east Bridge workload identities across clouds, clusters, and providers. vpn_key_off Secretless Infrastructure north_east Replace static secrets with short-lived, attested identities. autorenew Zero-Touch Operations north_east Issue, rotate, and revoke identities with no human in the loop. enhanced_encryption Quantum-Safe Connections north_east Post-quantum cryptography on every connection, today.
    Kubernetes
    sync_lock mTLS Without a Service Mesh north_east Mutual TLS between pods with no sidecars and no mesh to run. verified_user SPIFFE Without SPIRE north_east SPIFFE-compatible identities without operating SPIRE servers. memory Machine Identity north_east A cryptographic identity for every VM, container, and process.
    Not sure where to start? Talk to us arrow_forward
  • Pricing
  • Docs
  • Blog
Talk to us Start Free
Talk to us
Start Free

Riptides End User License Agreement

Last updated: Oct 8, 2026.


Agreement and acceptance

This End User License Agreement (“Agreement”) is between Riptides Labs, Inc., a Delaware corporation with its address at 1111B South Governors Avenue STE 28385, Dover, DE 19901 (“Riptides”, “we”, “us”), and the organization that accepts it (“Customer”, “you”).

You accept this Agreement by signing an Order Form that references it, by clicking to accept it, or by installing or using the Software. If you accept on behalf of an organization, you confirm that you have authority to bind it. If you do not agree, do not install or use the Software.

If a signed Order Form or a separate signed agreement conflicts with this Agreement, the signed document controls for that conflict only.

This Agreement is published at riptides.io/eula. If Customer uses a self-serve plan, including the Free Tier, Riptides’ Terms also apply. The Terms govern accounts, plans and billing. This Agreement governs the license, Customer Data and security. If the two conflict, this Agreement controls.

1. Definitions

  • “Agent Software” means the Riptides software components installed on Customer’s endpoints, including workstations, servers, cloud virtual machines and containers. It includes kernel modules, drivers, daemons and command-line tools.
  • “Console” means the Riptides software that configures the Agent Software and issues and manages workload identities and credentials. It is either hosted by Riptides (“Hosted Console”) or installed by Customer on infrastructure Customer controls (“Self-Hosted Console”).
  • “Software” means the Agent Software, the Console, related APIs, and all Updates and Documentation.
  • “Documentation” means the user guides and technical documentation Riptides publishes for the Software.
  • “Order Form” means a signed ordering document, or the self-serve plan Customer selects online, that states the subscription scope, term and fees.
  • “Free Tier” means use of the Software at no charge, within the limits Riptides publishes for it.
  • “Terms” means Riptides’ Terms of Service for self-serve accounts and plans, published at riptides.io/terms-of-services.
  • “DPA” means Riptides’ Data Processing Agreement, published at riptides.io/dpa.
  • “Authorized Users” means Customer’s employees and contractors whom Customer allows to use the Software for Customer’s benefit.
  • “Customer Data” means data Customer or its systems submit to the Software, including configuration, policies, workload metadata and logs.
  • “Updates” means patches, fixes and new versions of the Software that Riptides makes generally available.
  • “Subscription Term” means the period stated in the Order Form, including renewals. For the Free Tier, it means the period Customer uses it.

2. License grant

2.1 Agent Software. During the Subscription Term, Riptides grants Customer a non-exclusive, non-transferable, non-sublicensable license to install and run the Agent Software, in object code form only, on the endpoints (workstations, servers, cloud virtual machines and containers), up to the number stated in the Order Form, solely for Customer’s internal business operations.

2.2 Console. During the Subscription Term, Customer and its Authorized Users may access and use the Console and its APIs within the limits of the Order Form.

2.3 Documentation. Customer may copy the Documentation as reasonably needed to support its permitted use.

2.4 Authorized Users. Customer is responsible for its Authorized Users’ compliance with this Agreement and for all activity under Customer’s accounts.

2.5 Reserved rights. The Software is licensed, not sold. Riptides reserves all rights not expressly granted in this Agreement.

2.6 Self-Hosted Console. If the Order Form includes a Self-Hosted Console, Riptides grants Customer a license on the same terms as section 2.1 to install and run it on infrastructure Customer controls, in the number of instances the Order Form states. Customer operates, secures and backs up that infrastructure.

2.7 Free Tier. Customer may use the Free Tier within its published limits. Riptides may change those limits, or end the Free Tier, with 30 days’ notice. The Free Tier has no support or availability commitments. Sections 10.3 and 11.2 limit Riptides’ warranties and liability for it.

3. Restrictions

Customer will not, and will not allow anyone else to:

  1. copy, modify or create derivative works of the Software, except as this Agreement allows;
  2. reverse engineer, decompile or disassemble the Software, except to the extent applicable law expressly permits despite this restriction;
  3. sell, rent, lease, sublicense or provide the Software to third parties, including as a hosted or managed service;
  4. remove or bypass license keys, usage limits or security mechanisms in the Software;
  5. use the Software to build a competing product, or publish benchmarks without Riptides’ prior written consent;
  6. probe, scan or test the vulnerability of the Console without Riptides’ prior written consent;
  7. use the Software in violation of applicable law or to harm any person or system;
  8. exceed the usage limits in the Order Form. If Customer does, Riptides may invoice the excess at its then-current rates.

4. Ownership and feedback

4.1 Riptides property. Riptides and its licensors own all rights, title and interest in the Software, including all intellectual property rights and all improvements, whoever suggests them.

4.2 Customer property. Customer owns Customer Data. Riptides acquires no rights in Customer Data except the limited rights in section 5.

4.3 Feedback. If Customer gives Riptides suggestions or feedback about the Software, Riptides may use them without restriction or payment. Feedback does not include Customer Data or Customer’s Confidential Information.

5. Customer data, privacy and security

5.1 Use of Customer Data. Riptides processes Customer Data only to provide, secure, support and improve the Software, and as Customer instructs. Riptides does not sell Customer Data.

5.2 Usage data. Riptides may collect technical data about how the Software runs (for example, Agent Software version, health and error reports). Riptides may use it to operate and improve the Software, and may publish it only in aggregated form that does not identify Customer.

5.3 Security program. Riptides maintains a written information security program with administrative, technical and physical safeguards appropriate to the Software. It includes at least:

  • encryption of Customer Data in transit (TLS 1.2 or later) and at rest;
  • role-based access to production systems, limited to personnel who need it, with multi-factor authentication;
  • background checks for personnel with access to production systems, where local law permits;
  • security awareness training for personnel at hire and every year;
  • logging and monitoring of production systems;
  • vulnerability management and regular penetration testing;
  • a documented incident response plan;
  • backups and a tested disaster recovery plan for the Console.

5.4 Independent audits. Riptides undergoes an annual SOC 2 Type II audit, or an equivalent independent assessment. On request and under confidentiality obligations, Riptides will share its most recent report.

5.5 Security incidents. If Riptides confirms unauthorized access to Customer Data in its systems, it will notify Customer without undue delay and within 72 hours. It will also share the information Customer reasonably needs to meet its own obligations, and take reasonable steps to contain the incident.

5.6 Subprocessors. Riptides may use subprocessors, including its affiliate Riptides Kft. and its hosting providers, to provide the Software. Riptides remains responsible for them and keeps a current list available on request.

5.7 Personal data. If Customer Data includes personal data subject to GDPR or similar laws, the DPA at riptides.io/dpa applies and controls for that data.

5.8 Deletion. Within 30 days after the Subscription Term ends, Riptides will delete Customer Data from the Console, unless the law requires it to keep the data. Backups age out on their normal schedule. Customer may export its configuration before the term ends.

5.9 Self-Hosted Console. With a Self-Hosted Console, Customer Data stays on infrastructure Customer controls. Riptides accesses it only if Customer grants access, for example for support. Sections 5.3 to 5.6 then apply to the systems Riptides operates: its development, build and release pipeline, support tooling, and any Hosted Console. Section 5.8 applies only to data Riptides holds.

6. Third-party and open-source components

The Software includes open-source components. Each is licensed under its own license, which Riptides lists in the Documentation or in a notices file shipped with the Agent Software. Where an open-source license grants Customer broader rights than this Agreement, that license governs that component. Nothing in this Agreement limits those rights.

If Customer connects the Software to third-party services (for example, a cloud provider, secrets manager or identity provider), Customer’s use of those services is governed by Customer’s agreements with those providers. Riptides is not responsible for them.

7. Updates, support and customer responsibilities

7.1 Updates. Riptides provides Updates during the Subscription Term. Customer should install security Updates promptly. Riptides supports the current major version of the Agent Software and the previous one; older versions may stop working with the Console.

7.2 Support and availability. Riptides provides support and Console availability as described in the Order Form or Riptides’ then-current support policy. Riptides may perform scheduled maintenance and will give reasonable advance notice of maintenance that affects availability.

7.3 Changes. Riptides may change the Software over time. It will not make changes that materially reduce the Software’s core functionality or security during the current Subscription Term.

7.4 Customer responsibilities. The Software protects Customer’s environment only when Customer also does its part. Customer is responsible for:

  • securing the endpoints, clusters and networks where the Agent Software runs, and limiting who can install, configure or remove it;
  • for a Self-Hosted Console, securing, patching, monitoring and backing up the infrastructure it runs on;
  • protecting its account credentials and API keys, and enabling multi-factor authentication for Console users;
  • granting and promptly removing access for Authorized Users, including when people leave Customer;
  • configuring identity and access policies in the Software to suit its own requirements, and reviewing them;
  • installing Updates, especially security Updates, in a timely manner;
  • reporting suspected security incidents involving the Software to Riptides promptly;
  • ensuring it has the rights and consents needed to submit Customer Data.

8. Fees

Customer will pay the fees in the Order Form. The Free Tier has no fees. Unless the Order Form says otherwise, fees are invoiced annually in advance, due within 30 days of invoice, in US dollars, and non-refundable except as this Agreement provides. Fees exclude taxes; Customer pays applicable taxes other than taxes on Riptides’ income. If an undisputed invoice is more than 30 days overdue, Riptides may suspend access to the Console after 10 days’ written notice.

9. Confidentiality

“Confidential Information” means non-public information one party discloses to the other that is marked confidential or that a reasonable person would understand to be confidential. Customer Data, the Software, its pricing and Riptides’ audit reports are Confidential Information.

The receiving party will use Confidential Information only to perform this Agreement, protect it with at least reasonable care, and disclose it only to its employees, contractors and advisors who need to know it and are bound by similar obligations.

These obligations do not apply to information that is or becomes public through no fault of the receiving party, was already known to it, is independently developed, or is lawfully received from a third party. A party may disclose Confidential Information when the law requires, after giving prompt notice where legally allowed. These obligations last for 3 years after this Agreement ends, and for as long as the information remains a trade secret.

10. Warranties and disclaimers

10.1 Mutual. Each party warrants that it has the authority to enter into this Agreement.

10.2 Software warranty. Riptides warrants that, during the Subscription Term, the Software will perform materially as described in the Documentation, and that Riptides will not knowingly introduce malicious code into it. If the Software does not conform, Customer must notify Riptides. Riptides will then use reasonable efforts to correct the problem. If it cannot within 30 days, either party may terminate the affected subscription, and Riptides will refund prepaid fees for the remaining term. This is Customer’s sole remedy for breach of this warranty.

10.3 Disclaimer. Except as stated in this section, the Software is provided “as is”. Riptides disclaims all other warranties, express or implied, including merchantability, fitness for a particular purpose and non-infringement. Riptides does not warrant that the Software will be error-free or uninterrupted, or that it will prevent every security incident. Free, trial and beta versions are provided “as is” with no warranty.

11. Limitation of liability

11.1 Excluded damages. Neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue or data, even if advised of their possibility.

11.2 Cap. Each party’s total liability arising out of this Agreement is limited to the fees Customer paid or owes Riptides in the 12 months before the event giving rise to the claim. For free or trial use, Riptides’ total liability is limited to US$100.

11.3 Exceptions. Sections 11.1 and 11.2 do not apply to Customer’s payment obligations, either party’s indemnification obligations, breach of section 3 (Restrictions), or liability that the law does not allow to be limited, such as liability for fraud or wilful misconduct.

12. Indemnification

12.1 By Riptides. Riptides will defend Customer against any third-party claim that the Software, as provided by Riptides, infringes that party’s intellectual property rights, and will pay the resulting damages and costs a court awards or Riptides agrees to in settlement. If such a claim is made or likely, Riptides may obtain the right for Customer to keep using the Software, modify it so it does not infringe, or end the license and refund prepaid fees for the remaining term. Riptides has no obligation for claims caused by Customer’s modifications, combination with items Riptides did not provide, or use in breach of this Agreement.

12.2 By Customer. Customer will defend Riptides against any third-party claim arising from Customer Data or from Customer’s use of the Software in violation of law or this Agreement, and will pay the resulting damages and costs.

12.3 Process. The indemnified party must notify the other party promptly, give it sole control of the defense and settlement, and provide reasonable cooperation. No settlement may impose obligations on the indemnified party without its consent.

13. Term and termination

13.1 Term. This Agreement starts when Customer accepts it and continues while any Subscription Term is in effect. Unless the Order Form says otherwise, subscriptions renew automatically for the same length unless either party gives notice of non-renewal at least 30 days before the end of the current term.

13.2 Termination for breach. Either party may terminate this Agreement if the other party materially breaches it and does not cure the breach within 30 days of written notice. If Customer terminates for Riptides’ breach, Riptides will refund prepaid fees for the remaining term.

13.3 Suspension. Riptides may suspend access immediately if Customer’s use poses a security risk to the Software or to others, or violates section 3. Riptides will notify Customer and restore access once the issue is resolved.

13.4 Effect of termination. When this Agreement ends, Customer’s licenses end. Customer must stop using the Software and uninstall the Agent Software and any Self-Hosted Console. Section 5.8 governs Customer Data. Sections 4, 5.8, 8 (for amounts owed), 9, 10.3, 11, 12, 13.4, 15 and 16 survive.

14. Export control and compliance

The Software includes encryption technology and may be subject to US and EU export control and sanctions laws. Customer will not export, re-export or provide access to the Software in violation of those laws, including to any embargoed country or to any person on a US or EU restricted-party list. Each party will comply with anti-bribery and anti-corruption laws in connection with this Agreement.

15. Governing law and disputes

This Agreement is governed by the laws of the State of Delaware, USA, without regard to its conflict-of-laws rules. The UN Convention on Contracts for the International Sale of Goods does not apply. The state and federal courts located in Delaware have exclusive jurisdiction, and each party consents to it. Either party may seek injunctive relief in any court of competent jurisdiction to protect its intellectual property or Confidential Information.

16. General provisions

  • Entire agreement. This Agreement, with any Order Forms, the Terms (for self-serve plans) and the DPA, is the parties’ entire agreement on its subject and replaces prior discussions. Terms in Customer’s purchase orders do not apply.
  • Changes to this Agreement. Riptides may update this Agreement by publishing a new version at riptides.io/eula and giving at least 30 days’ notice. For paid subscriptions, changes apply from Customer’s next renewal unless Customer agrees earlier. For the Free Tier, they apply when the notice period ends.
  • Assignment. Neither party may assign this Agreement without the other’s consent, except to an affiliate or a successor in a merger, acquisition or sale of substantially all its assets.
  • Force majeure. Neither party is liable for delays caused by events beyond its reasonable control. This does not excuse payment obligations.
  • Independent contractors. The parties are independent contractors. Nothing creates a partnership, agency or employment relationship.
  • Publicity. Riptides may name Customer as a customer and show its logo, unless Customer opts out in writing.
  • Notices. Notices must be in writing. Notices to Customer go to the address in the Order Form or Customer’s account. Notices to Riptides go to Riptides Labs, Inc., 1111B South Governors Avenue STE 28385, Dover, DE 19901, USA, with a copy to legal@riptides.io.
  • Severability and waiver. If a provision is unenforceable, the rest of this Agreement remains in effect. Failing to enforce a provision is not a waiver.
  • US Government users. The Software is commercial computer software, licensed to US Government users only under the rights in this Agreement.

Riptides is a unified identity fabric for access control and secure communication across workloads, services, and AI agents.

Solutions

Attribution Agent Identity Secretless AI Tool Call Security Connection Security Identity Federation Secretless Infrastructure Zero-Touch Operations Quantum-Safe Connections mTLS Without a Service Mesh SPIFFE Without SPIRE Machine Identity

Company

Pricing Blog Talk to us RSS Privacy Policy Cookie Policy Terms of Service EULA

Contact

Github X Linkedin

Copyright © 2026 Riptides Labs. All rights reserved.

Cookies on riptides.io

We'd like to see which pages actually help people and which ones lose them, so we can fix them — that needs a few analytics cookies. They are never used for advertising, we do not sell your data, and this site has no session recording. Necessary cookies are always on; analytics only if you allow it. Cookie policy · Privacy policy

Strictly necessary Required for the site to work, including remembering this cookie choice and running the demo request form. These cannot be turned off.
Always on
Google Analytics and PostHog, used to count visits and see which pages and posts people read. No session recording on this site.