Terms of Service
The terms on which Fuga Labs provides detection, monitoring and coordination services. Written to match what the platform does, including the parts that limit what it can promise.
1. Who these terms bind
These terms govern access to the Fuga Labs platform by an organisation whose tenant has been provisioned by a Fuga Labs operator. There is no self-serve registration, so acceptance happens at the point of engagement rather than by clicking through. The operator who provisions your tenant records the acceptance, and the record is in the audit log. [Counsel: contracting entity, registered number and address.]
2. What the service is
Detection, monitoring, scoring, coordination and attestation. Fuga Labs observes public chain state and whatever signed off-chain feeds you choose to publish to it, evaluates them against detectors you can enumerate, and issues signed statements about what it observed.
3. Custody: we never hold anything of yours
Fuga Labs does not take custody of, and has no technical means to move, your keys, funds, admin roles or unilateral authority. Circuit breakers execute through a guardian module you deploy, own and can revoke at any block. Fuga Labs signs an attestation; your contract decides what to do with it. This is architectural rather than contractual, and it is the reason the ceiling on our liability and the ceiling on our capability are the same ceiling.
4. What an attestation is, and is not
An attestation is a threshold-signed, expiring statement that a specific detector fired on specific evidence at a specific block. It is an observation, not a warranty that an attack did or did not occur, and not an instruction. Acting on one is your decision, and the response policy in your guardian module is yours to write.
5. Detection is best-effort and bounded by coverage
No monitoring system detects every attack. Coverage is bounded by the chains and adapters attached, by the address set you qualify at onboarding, and by the data sources reachable at the moment of evaluation. Every onboarding preset declares its perimeter in writing, That declaration, rather than this page, is the operative statement of what is covered for your deployment.
6. The verdict lane fails open, by design
Where Fuga Labs returns a synchronous verdict, a timeout or infrastructure failure returns warn, never block. A security service that halts your users during its own outage has converted its incident into yours. You must treat warn as not screened rather than as screened and satisfactory, and design your integration so that a degraded answer is safe.
7. Screening, sanctions and your own obligations
Where a screen cannot consult a live source it returns insufficient data, never a pass. Screening output is an input to your compliance programme and does not discharge any sanctions, AML, KYC or reporting obligation that applies to you. You remain the responsible party for every such obligation in every jurisdiction you operate in.
8. Ratings are published opinions
Asset Ratings floor levels are opinions derived from a public methodology, and they measure configuration structure, not code correctness. A dependency can hold the highest floor and still contain a defect. Ratings are not investment advice, not a recommendation to integrate, and not a certification.
9. Acceptable use
The platform is for defensive security on infrastructure you control or are authorised to monitor. You may not use it to monitor a protocol you neither control nor have authorisation for, to develop offensive capability, or to evade sanctions or lawful process. Address-set qualification at onboarding exists partly to enforce this.
10. Availability, support and change
Service levels, support model and maintenance windows are set in your engagement rather than on this page, because they differ by contract. Detectors, thresholds and methodology change as the threat landscape does; material changes to the detector catalogue or the Asset Ratings methodology are versioned and published.
11. Fees
Pricing is not published and is scoped per engagement, taken individually or bundled. Fees, invoicing and term are set in your engagement rather than on this page, and there is no free tier, no trial by default and no self-serve checkout.
12. Intellectual property
Fuga Labs retains all rights in the platform, the detector catalogue, the methodology and the software. You retain all rights in your data, your addresses and your contracts. Attestations issued about your subjects are yours to publish, quote and rely on.
13. Confidentiality
Tenant data is confidential and is not shared between tenants; the isolation is structural rather than a filter (see the tenancy reference). Aggregate, non-attributable threat intelligence derived from platform-wide observation may be used to improve detection for all customers, and never includes your identity, addresses or positions.
14. Warranties and liability
The platform is provided without warranty that it will detect every attack or prevent every loss. [Counsel: warranty disclaimer, liability cap, carve-outs for fraud, wilful misconduct, death or personal injury, and any non-excludable statutory rights in the relevant jurisdictions.]
15. Termination and exit
Either party may terminate per the engagement. On termination you revoke the guardian module and stop paying; there is no data you need back from us in order to operate, because we never held anything you could not reproduce from the chain. Your compliance export remains available for the period set in your engagement.
16. Governing law and disputes
[Counsel: governing law, jurisdiction, dispute resolution mechanism and any arbitration clause.]
One thing this page cannot do.
Questions about any clause on this page?
Ask before you sign, not after. Every engagement is scoped by the team, and the terms are part of that conversation.