Ansight, Inc.

Terms of Service

Terms for using Ansight's developer tools, cloud evidence, and AI workflows.

Effective date: September 10, 2026

On this page

1. Agreement and scope

These Terms govern access to services provided by Ansight, Inc., a Delaware corporation, at 131 Continental Dr, Suite 305, Newark, DE 19713, United States (“Ansight,” “we,” “us”). “Customer” or “you” means the person or legal entity agreeing to use the services. If accepting for an organisation, you represent that you are authorised to bind it. You must be at least 18 and legally able to enter this agreement.

The services include the website, portal, CLI, local player, cloud capture and collaboration features, AI workflows, agent integrations, and remote companion connections. Separate open-source licences govern the components distributed under them. These Terms do not remove rights granted by those licences or convert an open-source licence into a paid subscription.

A signed order or negotiated agreement governs any express conflict with these Terms. An applicable DPA governs conflicts concerning processing on behalf of the customer. A service-level agreement governs only the service levels it expressly covers. A roadmap, demonstration or marketplace listing does not commit us to deliver an unpurchased feature. The Privacy Policy explains personal-information handling and does not replace a required DPA.

By accepting these Terms through an account, checkout or other acceptance process, or using the services after being presented with these Terms and notice that their use constitutes acceptance, you agree to them. If you do not agree, do not use the services governed by them. Existing signed agreements remain subject to their own amendment provisions.

2. Access, accounts and organisation authority

Subject to this agreement, you may use the services for authorised development, testing, analysis and collaboration. Maintain accurate account information, protect credentials, and manage the users, integrations and machines you authorise. Do not share individual accounts to evade seat or access restrictions.

Organisation administrators can manage membership, access and content within their permissions. You are responsible for obtaining permission from your employer, clients and other rights holders before connecting their apps or information. Notify support@ansight.ai promptly of suspected unauthorised access. We may require verification before changing ownership, exporting restricted data or processing account requests.

Customer-managed infrastructure remains your responsibility. We are responsible for the infrastructure we operate to provide the cloud services within the agreed scope. A remote connection does not transfer ownership of the connected machine or authorise unrelated access.

3. Development tools and authorised actions

Ansight can inspect and affect app state, screens, logs, network data, files, databases, preferences, secure storage and developer tools. Agents can tap, type, call tools, run workspace code and trigger effects in connected services. Configure permissions, tool guards and test accounts for the intended task. You authorise operations you or your authorised users initiate or configure, including automation deliberately enabled on a repository.

Use the SDK and privileged development connections only in authorised development or QA builds. Keep them out of production builds as described in the platform security guidance. Local SDK transport and workspace execution have the limitations stated in the security documentation: local development traffic is not universally encrypted, and workspace tasks, triggers and custom sanitizers are trusted code, not an OS sandbox. An allow-list for Ansight tools does not prevent that code from accessing the host’s other available resources.

Review repository code, dependencies, prompts, plugins, task imports and trigger changes before execution, particularly from untrusted pull requests. Restrict production credentials and disable automations when no longer needed. Stopping a job does not undo actions that already occurred. Human approval and independent review remain your responsibility for releases, payments, account changes and other consequential actions.

4. Customer Content and ownership

“Customer Content” means material you or your authorised users provide or make available through the services, including source code, binaries, app data, captures, prompts, files, tests, results and annotations. As between the parties, you retain your rights in Customer Content. You are responsible for the rights, permissions and lawful basis needed to submit it and request its processing.

You grant us a non-exclusive licence to host, copy, transmit, process, execute, display and create workflow outputs from Customer Content as necessary to provide, secure and support the requested services, comply with law and carry out your instructions. This operational licence does not give us ownership of your repository or authority to use its secrets for unrelated purposes. This licence does not authorise model training or fine-tuning; Section 5 explains our current practices and the restrictions on future changes.

You and your authorised organisation users decide which captures to upload, who can access them, and which cloud captures to delete within your permissions. Uploading a capture does not give us unrestricted rights to retain or use it. Retention and deletion follow Section 12 and the Privacy Policy. The CLI’s cloud-sharing flow uploads raw capture by default unless sanitization is selected. Public links are public, and authenticated links are not necessarily limited to your team. Redaction can miss information. Review content and audiences before sharing; deleting a link does not recall downloaded copies.

We retain rights in the services, software, documentation and our underlying technology, subject to applicable open-source licences. You may use the results provided to you under this agreement, subject to third-party rights and the limits of applicable law. AI outputs may not be unique or eligible for intellectual-property protection. Feedback you voluntarily provide can be used to improve the service without a payment obligation, but a feedback licence does not convert confidential attachments or personal data into unrestricted material.

5. Customer content and model training

Ansight does not currently use Customer Content to train or fine-tune models. We do not operate a customer-content training programme or collect contributions for a future programme. No training opt-out is needed under our current practices. Using an AI model to perform a test or analysis you request is separate from training that model.

These Terms grant no licence for a future customer-content training programme. Before introducing one, we will explain its scope, eligible information, retention and participation choices, update the applicable terms and Privacy Policy, and obtain permissions or consent required by law, customer agreements and source-platform terms. A future change will not retrospectively authorise training on existing content. An applicable no-training agreement or DPA continues to govern within its scope.

OpenAI integration: Data received or accessed through Ansight’s ChatGPT or Codex integration—including requests, prompts, tool outputs, app evidence and derived examples—is excluded from independent model training, fine-tuning and cross-customer evaluation. This exclusion follows copies and derivatives and cannot be removed through a future organisation training setting. We process App Requests only as necessary to fulfil their instructions or comply with law, and do not use them to develop models competing with OpenAI. OpenAI handles information under its own agreement with the user or workspace.

See the Privacy Policy, Section 6 for further information.

6. Confidentiality and data protection

Each party will protect the other’s non-public information disclosed in connection with the service, use it only for permitted purposes, and limit disclosure to people or providers who need it and are bound by appropriate obligations. Confidential information includes private Customer Content and security-sensitive details. Information independently developed, lawfully received without a restriction, already known without a duty, or publicly available without breach is excluded from this definition.

Disclosure required by law is permitted; where lawful, the receiving party will give notice and reasonably cooperate with protective measures. Authorised processing and a customer’s chosen sharing audience do not remove privacy duties or permit disclosure beyond that authorisation. Confidentiality obligations continue after termination for as long as the information remains confidential, and trade secrets remain protected as required by law.

Where a data processing agreement (DPA) is legally required for our processing of personal information on your behalf, the parties will enter into it before that processing begins. It will govern documented instructions, confidentiality, security, subprocessors, assistance with individual rights and incidents, and return or deletion of personal information. We will notify affected customers of a confirmed breach of Customer Content as required by applicable law and the governing agreement; any additional notice periods and cooperation arrangements agreed in the DPA also apply. You must provide a current security contact.

Do not submit children’s personal information. Do not submit production credentials, protected health information, biometric identification data, full payment-card data or other specially regulated information unless we expressly agree in writing to the use and required safeguards. A developer test environment can still contain regulated data. We do not provide a HIPAA business associate agreement, residency guarantee, government authorisation or certification by default.

The OpenAI integration must not collect, solicit or process protected health information, payment-card/PCI-regulated data, government identifiers, or access credentials and authentication secrets. Do not provide personal information of children under 13 or the applicable age of digital consent. Use synthetic or already-sanitized fixtures prepared outside the OpenAI integration for restricted sources. Other sensitive personal data requires strict necessity, legally adequate consent and prominent disclosure before collection. A separate Ansight agreement cannot waive these platform restrictions.

7. AI, integrations and third-party services

AI outputs may be incomplete, incorrect or inconsistent. Evidence shows what was captured in a particular run; it does not guarantee absence of defects, vulnerabilities or regressions. Review outputs and validate important conclusions. Do not use Ansight as the sole basis for safety-critical decisions or decisions about an individual’s legal rights.

You may enable providers, repositories, issue systems, agents, notifications and other integrations. Their own terms apply to your independent use. We are responsible for our obligations concerning providers engaged by us; customer-selected services remain subject to the relationship you establish with them. Availability, prices and functionality may change. Credentials and permissions must be appropriately scoped and revoked when no longer needed.

The OpenAI integration cannot execute or facilitate real money transfers, cryptocurrency transfers, investment trades or other financial transactions. Non-transactional synthetic tests must not move real funds. Ansight, Inc. independently develops and supports this plugin; it is not represented as made, endorsed or certified by OpenAI.

Ansight’s no-training practice does not change the terms or settings of providers you independently use. Provider retention, training and data location depend on the exact account and feature. A local orchestration process can still send requests to a hosted model.

8. Future services

Ansight-managed virtual machines and Mac instances are planned services and are not included in the current offering. If introduced, they will have separate service terms covering the purchased resources, charges, access, security responsibilities, storage, export and deletion before you enable them. These Terms do not reserve resources, authorise new access to your data or commit you to purchase future services.

9. Fees, subscriptions and cancellation

The applicable checkout, order or plan identifies price, currency, billing period, seats, included usage, metered charges, taxes and any minimum commitment. Free local functionality does not imply free third-party inference or cloud storage. We do not charge for a future feature merely because it appears in a roadmap.

For recurring subscriptions, the renewal terms and recurring charge must be disclosed when purchased. You authorise those disclosed charges until cancellation takes effect. Cancel through available billing controls or contact support before renewal. Unless the order or mandatory law states otherwise, cancellation ends renewal and access continues through the paid period; accrued usage remains payable. Do not assume revoking a model key, uninstalling the CLI, or deleting an account cancels a subscription.

Except where required by law or an applicable order, charges for delivered services and consumed usage are non-refundable. We correct verified billing errors. Credit expiry, refundability and consumption order must be disclosed when credits are purchased; silence does not establish a forfeiture rule. Any material renewal price change requires notice before the affected renewal and an opportunity to cancel. Taxes are your responsibility other than taxes on our income. We may suspend overdue paid services after reasonable notice, subject to applicable law and the agreement.

10. Acceptable use

Use the services only for systems and information you are authorised to access. Do not violate law or intellectual-property, privacy or confidentiality rights; introduce harmful code; evade limits or access controls; misrepresent your identity; interfere with other users; or use outputs to facilitate wrongdoing. Do not remove required licence notices or misrepresent Ansight as certifying an app’s safety or compliance.

Protect sensitive inputs and secure your environment. A test against a payment system, messaging service or production API can have real effects even if the UI is labelled a test. Use fixtures and explicit authorisation for consequential actions. Report suspected vulnerabilities privately through support; this agreement does not authorise testing against other customers or our production infrastructure.

Comply with applicable export controls, sanctions and restrictions on software, encryption, data and compute access. Do not use the service for a prohibited destination, person or end use, or to evade a supplier’s legal restrictions. Contact support about a suspected intellectual-property violation with the affected material, your rights and contact details; do not disclose another customer’s confidential content in a public complaint.

11. Availability, changes and previews

We may maintain, improve or change services. We will give reasonable notice of a material removal from a paid service where practicable and address resulting rights under the order and law. APIs, external providers and operating systems can change. Keep supported versions and review compatibility notices.

Preview and beta features may be incomplete, change or stop, and should not hold the only copy of important work. A preview label does not waive applicable security or privacy obligations. Uptime, recovery times, guaranteed response times and compensation are provided only in an express SLA. We do not warrant that every agent action succeeds or every defect will be detected.

12. Termination, export and deletion

You may stop using the service and cancel as described above. Either party may terminate a material breach not cured within 30 days after notice, unless it cannot be cured or immediate action is justified by security, illegality or applicable law. We may suspend access proportionately while investigating a serious risk and restore it when the issue is resolved where appropriate.

You control cloud capture uploads and deletion through the service within your organisation permissions. Cloud captures remain until you delete them, an organisation retention rule removes them, or the service or organisation closes, subject to applicable backup and legal retention exceptions. Where no retention rule is configured, captures have no automatic expiry.

Export needed cloud content before closing an organisation or ending access. Contact support if you need assistance with return or deletion. Any additional post-termination retrieval window or deletion deadline agreed in an order or DPA applies; otherwise, do not rely on continued access after termination. We handle retained information under the Privacy Policy’s retention and deletion provisions and applicable legal and contractual obligations. Records are retained only for as long as lawfully necessary for the disclosed purposes, including applicable recordkeeping duties; these Terms do not authorise indefinite retention of personal information.

Deleting your individual account or leaving an organisation does not delete that organisation’s captures or other users’ records. Organisation closure and cloud evidence deletion are separate from local cleanup. Local files remain on customer-controlled machines; termination does not remotely erase them. Deleted information may remain in backups until those backups expire or are replaced, or be preserved where law requires. A cloud deletion cannot recall recipients’ downloads or independently configured provider copies.

The operational licence in Section 4 continues after termination only to the extent necessary to complete authorised return or deletion, protect retained information, or meet legal obligations. Accrued payment obligations, ownership, confidentiality, liability limits, dispute terms and other provisions intended by their nature to survive continue after termination.

13. Warranties and responsibility

Each party represents that it has authority to enter this agreement. We will provide paid services with reasonable care and skill. Except for express commitments in the agreement and rights that law does not permit us to exclude, services and outputs are provided as available, and we disclaim implied warranties of merchantability, fitness for a particular purpose and non-infringement to the extent permitted by law. No statement here excludes a mandatory consumer guarantee or liability that cannot lawfully be excluded.

You are responsible for reviewing app releases, verifying outputs, maintaining appropriate backups and obtaining rights to workloads. You are not responsible for our failure to perform obligations expressly allocated to us. Safeguards and responsibility must follow actual control of a system; describing a service as self-service does not transfer our infrastructure obligations to you.

14. Liability

To the maximum extent permitted by law, neither party is liable to the other for indirect, special, consequential or punitive damages, or lost profits, arising from this agreement. Subject to the exceptions below and any negotiated order, each party’s aggregate liability arising from the service is limited to the greater of US$100 and the amounts paid or payable by you for the affected service during the 12 months before the event giving rise to the claim.

These limits do not apply to fraud, wilful misconduct, gross negligence, payment obligations, or liability that law prohibits limiting. They do not restrict statutory remedies available to individuals under applicable data-protection law. An order or DPA may specify different liability treatment for confidentiality, intellectual-property or security obligations.

15. Governing law and disputes

Unless a signed agreement provides otherwise, Delaware law governs this agreement, excluding conflict-of-law rules, and courts of competent jurisdiction in Delaware have jurisdiction over disputes. Mandatory protections and forums under applicable law remain available. Before filing an ordinary contractual claim, contact support so the parties can attempt in good faith to resolve it; this does not prevent urgent relief, regulatory complaints or meeting a limitation deadline. These Terms do not impose mandatory arbitration or a class-action waiver.

16. General terms and notices

Neither party may assign the agreement without the other’s consent, except to an affiliate or in connection with a merger, reorganisation or sale of substantially all relevant assets, provided the successor assumes the obligations and the assignment does not unlawfully reduce data protections. If a provision is unenforceable, the remainder remains effective to the extent lawful. Failure to enforce a provision is not a waiver. Neither party is the other’s agent, and there are no third-party beneficiaries except where applicable law or a DPA provides otherwise.

Neither party is liable for delay caused by circumstances beyond its reasonable control, but this does not excuse accrued payment obligations, required protection of retained information or reasonable mitigation. We will notify you of material amendments and their effective date through appropriate service channels. Changes do not retroactively authorise new content uses or replace consent where required. Where a change materially affects paid rights, applicable notice, cancellation and contract requirements apply.

Contact Ansight, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States, or support@ansight.ai. Notices affecting an organisation should identify the relevant account and be sent by an authorised person. See Customer Support and the Privacy Policy.