Terms of Service
By using Troxy you agree to these terms. Please read them carefully. Troxy is a policy enforcement layer for AI agents — it evaluates, logs, and governs actions your agents attempt. You are responsible for the policies you configure and the actions your agents take under those policies.
1. Acceptance of Terms
By creating a Troxy account, accessing dash.troxy.io, installing the Troxy CLI, or integrating Troxy with your AI agents via MCP, you agree to be bound by these Terms of Service and our Privacy Policy. If you do not agree, do not use the service.
If you are using Troxy on behalf of an organization, you represent that you have the authority to bind that organization to these terms.
2. Description of Service
Troxy is an AI governance and policy enforcement platform that allows users to:
- Define governance policies that govern what actions AI agents may take
- Connect AI agents (via MCP) to route action requests through those policies before execution
- Monitor agent activity, receive alerts, and approve or deny escalated actions in real time
- Track agent decisions, audit trails, and policy outcomes
Troxy is a policy enforcement and governance layer. It is not a payment processor, bank, or financial institution. Troxy does not execute actions on your behalf — it evaluates whether actions proposed by your AI agents comply with your defined policies and returns a decision (allow, block, escalate, or notify).
3. Accounts and Eligibility
- You must be at least 18 years old to use Troxy
- You must provide a valid email address to create an account
- You are responsible for maintaining the security of your account credentials
- You must notify us immediately at [email protected] if you suspect unauthorized access to your account
- You may not create accounts on behalf of others without their consent
- One person may not maintain multiple active accounts
4. Agent Actions and Authorization
Troxy evaluates actions your AI agents attempt — such as sending messages, accessing data, executing code, or making purchases — against your defined policies. Troxy does not execute these actions itself; it returns a policy decision that your agent is expected to follow.
- You authorize Troxy to evaluate agent actions against your configured policies and return allow, block, escalate, or notify decisions
- You are solely responsible for all actions taken by your AI agents, whether or not those actions were evaluated by Troxy
- Troxy does not guarantee that an agent will respect a policy decision. If an agent bypasses Troxy's evaluation, the action is outside Troxy's control
- You are responsible for ensuring your agents are configured to call Troxy's evaluation endpoints before taking actions
- Troxy is not responsible for the outcomes of actions that agents take, regardless of whether those actions were approved or blocked by your policies
5. Governance Policies
- You are responsible for configuring your governance policies correctly. Incorrectly configured policies may result in actions being approved or blocked in ways you did not intend
- Policies are evaluated top-to-bottom, with the first matching policy determining the outcome
- Troxy provides templates and suggestions for common governance scenarios, but you must review and customize them for your specific use case
- You can pause, reorder, and modify policies at any time. Changes take effect for subsequent evaluations immediately
- Troxy is not liable for outcomes resulting from misconfigured policies or policy gaps
6. Sensitive Data and Credentials
Troxy includes a secrets detection checkpoint that scans agent payloads for sensitive data patterns, including:
- API keys and tokens (AWS, Stripe, GitHub, generic patterns)
- Credit card numbers
- Private keys and certificates
- JWTs and other credential formats
Secrets detection is pattern-based and may not catch all sensitive data. You should not rely solely on Troxy's secrets checkpoint as your only data protection mechanism. Combine it with proper credential management and access controls.
- Detected secrets are handled according to your configured policy: block, escalate, notify, or allow
- Troxy does not store the full content of detected secrets. Detection results are logged with redacted previews only
- You are responsible for ensuring that credentials stored in or accessible by your AI agents are properly secured
7. Acceptable Use
You agree not to use Troxy to:
- Facilitate illegal activities or violate any applicable law or regulation
- Attempt to circumvent Troxy's policy enforcement mechanisms
- Use the service to build surveillance systems that violate applicable privacy laws
- Integrate Troxy with agents designed to cause harm, damage systems, or exfiltrate data
- Reverse engineer, decompile, or disassemble the Troxy platform
- Resell or sublicense access to Troxy without express written permission
- Use Troxy in a way that could damage, disable, or impair the service
8. Third-Party Services
- Troxy integrates with third-party AI agents and platforms (Claude, OpenAI, Cursor, etc.) via MCP and API connections. These integrations are subject to the respective providers' terms
- Troxy may integrate with notification services (email, Telegram) to deliver alerts. These services have their own privacy policies and terms
- Troxy is not responsible for the actions, availability, or data practices of third-party AI agents or platforms
- If a third-party service changes its API or terms in a way that affects Troxy's ability to evaluate actions, Troxy is not liable for any resulting policy enforcement gaps
9. Disclaimers
Troxy is provided "as is" and "as available," without warranties of any kind, express or implied. Specifically:
- Troxy does not guarantee that all policy-violating actions will be blocked. Policy enforcement depends on agents calling Troxy before acting
- Troxy does not guarantee that secrets detection will identify all sensitive data in all formats
- Troxy does not warrant that the service will be uninterrupted, error-free, or secure
- Troxy is not responsible for actions taken by AI agents that bypass or ignore Troxy's policy decisions
- Any reliance on Troxy's policy decisions is at your own risk
10. Limitation of Liability
To the maximum extent permitted by law:
- Troxy shall not be liable for any indirect, incidental, special, or consequential damages, including loss of data, revenue, or business, arising from the use or inability to use the service
- Troxy's total liability for any claim arising from these terms shall not exceed the amount you paid for the service in the 12 months preceding the claim, or $100, whichever is greater
- Troxy is not liable for actions taken by your AI agents, whether or not those actions were evaluated by Troxy
- Troxy is not liable for data loss or exposure resulting from misconfigured policies or agent behavior that circumvents Troxy's evaluation
11. Indemnification
You agree to indemnify and hold Troxy harmless from any claims, damages, losses, or expenses (including legal fees) arising from:
- Your use of the service
- Actions taken by your AI agents, whether or not evaluated by Troxy
- Your configuration of governance policies
- Violation of these terms or any applicable law
12. Termination
- You may close your account at any time from the dashboard settings
- Troxy may suspend or terminate your account if you violate these terms
- Troxy may discontinue or modify the service at any time with reasonable notice
- Upon termination, your policy configurations and agent connections will be deactivated
- Sections that by their nature should survive termination (liability, indemnification, governing law) shall remain in effect
13. Changes to Terms
We may update these terms from time to time. We will notify you of material changes via email or dashboard notification at least 14 days before they take effect. Continued use of the service after changes take effect constitutes acceptance of the updated terms.
14. Governing Law
These terms are governed by the laws of the State of Israel, without regard to conflict of law principles. Any disputes shall be resolved in the competent courts of Tel Aviv, Israel, unless you are a consumer with mandatory jurisdiction rights in another country.
15. Contact Us
If you have questions about these terms, contact us at:
- Email: [email protected]
- Website: troxy.io