Pvotal Technologies, Inc.
These Terms of Service (“Agreement”) constitute a legally binding contract between Pvotal Technologies, Inc., a Delaware corporation (“Pvotal,” “we,” “us,” or “our”), and the entity or individual purchasing, accessing, or using the Services (“Customer,” “you,” or “your”).
By completing a purchase through a checkout page or payment link that provides notice of these Terms, executing an Order Form, creating or using an Infrastream account, or accessing or using the Services, you agree to be bound by this Agreement and represent that you have authority to bind the applicable organization.
If you do not agree to this Agreement, you must not purchase, access, or use the Services.
a promotional or subscription-related credit issued by Pvotal that may be applied only toward eligible Cloud Usage Charges, subject to the terms under which the credit is issued.
an employee, contractor, agent, or other individual authorized by Customer to access or use the Services on Customer’s behalf.
charges attributable to Customer’s actual consumption of GCP resources provisioned, administered, billed, or managed through Infrastream Cloud.
a developer or customer community operated or designated by Pvotal through Discord or another third-party platform.
data, information, files, instructions, prompts, configurations, code, documentation, records, communications, and other content submitted, uploaded, transmitted, generated, or otherwise made available by or on behalf of Customer through the Services.
cloud accounts, cloud resources, projects, environments, networks, repositories, identity systems, applications, workloads, and related technology owned, operated, or controlled by Customer.
YAML infrastructure definitions, configurations, declarations, templates, plans, policies, and similar infrastructure files authored, selected, approved, or maintained by or on behalf of Customer.
Customer’s GitHub, GitLab, or other version-control system containing Customer Manifests or other Customer Content.
the self-service Infrastream Cloud plan identified as “Developer” on the applicable pricing page, checkout page, or Order Form.
Pvotal’s then-current technical, product, security, support, and operational documentation for Infrastream, including documentation made available at docs.infrastream.io.
Google Cloud Platform and related Google Cloud services.
Pvotal’s infrastructure automation platform, including Infrastream Cloud, Infrastream Private Cloud, Infrastream Hub, Pvot AI Agent functionality, Software Artifacts, Documentation, and associated services.
the Pvotal-managed deployment of Infrastream through which Pvotal provisions, operates, administers, supports, meters, bills, or manages applicable platform components and cloud environments for Customer.
the Managed GCP Projects and related cloud resources provisioned, administered, operated, billed, or managed through Infrastream Cloud for Customer.
Pvotal’s hosted account portal at accounts.infrastream.io, through which Customers may authenticate, administer accounts, manage subscriptions, access billing information, manage licenses, access Software Artifacts, and use other available service-management features.
the customer-controlled deployment of Infrastream within Customer Infrastructure under an applicable Order Form.
a cryptographic token or other authorization mechanism issued by Pvotal to authorize use of Infrastream Private Cloud or applicable Software Artifacts within an approved scope.
the Infrastream platform-management fee charged for Infrastream Cloud and calculated as a percentage of applicable Cloud Usage Charges.
a GCP project provisioned, administered, operated, billed, or managed through Infrastream Cloud for Customer.
Pvotal’s customer onboarding portal, whether made available through onboard.pvotal.tech, Rocketlane, or a successor provider, through which Pvotal may provide structured implementation or onboarding support.
a written or electronic ordering document, checkout page, payment page, or other ordering record that references this Agreement and identifies the applicable Services, subscription plan, Subscription Term, fees, capacity, or other commercial terms.
implementation, onboarding, migration, enablement, consulting, configuration, training, or other professional services provided by Pvotal under an Order Form or Statement of Work.
AI-assisted functionality made available through Infrastream to generate, recommend, explain, plan, analyze, modify, or assist with infrastructure-related workflows.
Infrastream Cloud, Infrastream Private Cloud, Infrastream Hub, Software Artifact distribution, Documentation, support, Professional Services, and other services provided by Pvotal under this Agreement or an applicable Order Form.
compiled binaries, container images, executor packages, agents, releases, upgrade bundles, and other software components distributed or made available by Pvotal.
the period during which Customer is authorized to access or use the applicable Services, as stated in an Order Form, checkout page, or account.
Understanding Pvotal’s role requires understanding the two Infrastream deployment paths.
1. Infrastream Cloud. Under Infrastream Cloud, Pvotal manages applicable platform components and cloud environments for Customer. Depending on the applicable plan and configuration, Pvotal may provision, administer, operate, monitor, meter, support, bill, or control Managed GCP Projects and may process Customer Content as necessary to provide the Services.
2. Infrastream Private Cloud. Under Infrastream Private Cloud, Customer deploys and operates Infrastream within Customer Infrastructure. Customer directly controls its cloud environment, credentials, repositories, workloads, and cloud-provider billing. Pvotal provides Software Artifacts, licensing, documentation, available updates, support, and any professional services identified in an Order Form.
3. Infrastream Hub. Pvotal operates Infrastream Hub for account authentication, subscription management, billing, license management, software artifact distribution, upgrade administration, and other available service-management functions.
4. Manifest handling. Under Infrastream Cloud, Customer Manifests and related infrastructure information may be processed through Pvotal controlled systems as necessary to provide the managed services. Under Infrastream Private Cloud, Customer Manifests may remain within Customer VCS and Customer Infrastructure unless Customer enables a feature that transmits them to Pvotal or voluntarily shares them through support, onboarding, or Professional Services.
5. Pvotal’s access boundary. Pvotal’s access to Customer systems and data differs materially between Infrastream Cloud and Infrastream Private Cloud. The applicable boundaries are described in Sections 5 and 8.
6. Third-party services. The Services may depend on GCP, Stripe, GitHub, GitLab, identity providers, AI model providers, and other third-party systems. Pvotal does not control those third-party services and is not responsible for their independent acts, omissions, availability, pricing, policies, or terms.
Subject to this Agreement and Customer’s timely payment of applicable fees, Pvotal grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the applicable Subscription Term to:
(a) access Infrastream Hub for account, subscription, billing, license, Software Artifact, support, and upgrade administration;
(b) access and use Infrastream Cloud for Customer’s internal business operations and within the capacity included in Customer’s applicable plan;
(c) if Customer purchases Infrastream Private Cloud, download, install, and operate authorized Software Artifacts within the Customer Infrastructure and scope specified in the applicable Order Form; and
(d) access and use Pvotal’s Documentation at docs.infrastream.io in connection with Customer’s authorized use of the Services.
Customer receives only the rights expressly granted in this Agreement. No ownership interest in Infrastream, the Services, Software Artifacts, source code, platform infrastructure, models, system prompts, orchestration logic, or related intellectual property is transferred to Customer.
For Infrastream Private Cloud, Pvotal may issue Customer a License Key tied to cloud-organization identifiers, Customer Infrastructure, environments, capacity, or another authorized scope specified in the applicable Order Form.
A License Key:
● authorizes Infrastream Private Cloud or applicable Software Artifacts to operate only within the authorized scope;
● is non-transferable and may not be used outside the authorized scope without Pvotal’s prior written consent; and
● may be suspended or revoked in accordance with Section 14.
Customer shall not, and shall not permit any third party to:
(a) reverse engineer, decompile, disassemble, or attempt to derive source code, models, system prompts, proprietary algorithms, or non-public architecture from any protected component of the Services, except to the extent expressly permitted by applicable law or an applicable open-source license;
(b) remove, alter, or obscure cryptographic signatures, license-validation routines, proprietary notices, access restrictions, or security controls;
(c) redistribute, resell, sublicense, rent, lease, timeshare, or otherwise transfer the Services, Software Artifacts, License Keys, or account access to a third party without Pvotal’s prior written consent;
(d) use the Services to build, train, support, benchmark, or improve a directly competing infrastructure automation product, except for internal evaluation not intended for public disclosure or competitive development;
(e) interfere with, disrupt, degrade, or attempt to gain unauthorized access to Pvotal infrastructure, third-party infrastructure, another customer’s account, or another customer’s data;
(f) share License Keys or account credentials outside Customer’s organization or authorized contractor group;
(g) use Software Artifacts outside the Customer Infrastructure or scope specified in the applicable Order Form;
(h) bypass or attempt to bypass capacity limits, billing controls, usage restrictions, approval workflows, license controls, security controls, or technical safeguards;
(i) access or use the Services in violation of applicable law, sanctions, export controls, or third-party rights; or
(j) use the Services for unlawful, fraudulent, abusive, malicious, or unauthorized activity.
Infrastream Hub is accessed by Authorized Users through authentication methods made available by Pvotal, which may include OpenID Connect, supported identity providers, or other authentication methods.
Customer is responsible for:
● configuring and maintaining any Customer-controlled identity-provider integration;
● managing Authorized User access, including prompt revocation following a role change or termination;
● protecting credentials and authentication factors;
● promptly notifying Pvotal of suspected unauthorized account access; and
● ensuring that Authorized Users comply with this Agreement.
Customer is responsible for activity occurring through its accounts unless caused by Pvotal’s breach of this Agreement.
Depending on Customer’s plan and the features then available, Infrastream Hub may provide:
● Account Management: account, organization, subscription, and Authorized User administration.
● Billing Management: Subscription, payment, usage, credit, and billing information.
● Managed Project Administration: Information about Managed GCP Projects and related environments.
● License Management: License Key access, validation, and administration.
● Artifact Downloads: Software Artifacts, release notes, and changelogs.
● Upgrade Management: Available update or upgrade administration.
● Support Access: Access to applicable support channels and information.
Pvotal may add, modify, replace, or remove Hub features, provided that Pvotal will not materially reduce the core functionality of paid Services during a committed Subscription Term except where reasonably necessary for security, legal, technical, or third-party reasons.
Pvotal will use commercially reasonable efforts to maintain Infrastream Hub availability.
A binding uptime commitment or service-credit entitlement applies only if expressly stated in a written service level agreement (“SLA”) incorporated into the applicable Order Form.
Unless expressly stated otherwise, no SLA applies to:
● the Developer Plan;
● no-charge, promotional, trial, evaluation, beta, or preview access;
● Professional Services;
● the Onboarding Portal; or
● the Community Platform.
For Infrastream Private Cloud, Hub downtime ordinarily does not affect a then-running deployment operating independently within Customer Infrastructure, although it may affect authentication, licensing, Software Artifact access, upgrades, support access, or account administration.
For Infrastream Cloud, an interruption affecting Infrastream Hub or another Pvotal-operated system may affect Customer’s ability to access or administer the managed Services.
Customers may receive access to the Onboarding Portal as part of a subscription, enterprise onboarding package, or separately contracted Professional Services engagement.
Access is project-scoped and limited to Customer stakeholders invited by Pvotal or otherwise authorized for the applicable engagement.
The Onboarding Portal may be delivered using Rocketlane or another third-party project-management or customer-onboarding provider.
Customer acknowledges that:
● project data, milestones, communications, and uploaded documents may be processed by the applicable provider;
● the provider may act as a service provider or subprocessor to Pvotal where applicable;
● Customer stakeholders may interact with a third-party-hosted interface; and
● applicable personal-data processing is governed by this Agreement, the Privacy Policy, and any applicable Data Processing Addendum.
Onboarding Portal communications and deliverables constitute Professional Services unless otherwise specified.
Use of the Onboarding Portal does not independently create service levels, acceptance obligations, milestone guarantees, delivery commitments, or warranties.
Binding deliverables, timelines, dependencies, and acceptance criteria apply only when specified in an executed Order Form or Statement of Work (“SOW”).
Customer agrees to:
● designate an internal project lead authorized to make onboarding decisions;
● respond to Pvotal requests for information, approvals, access, or stakeholder availability within agreed timelines;
● provide accurate information regarding Customer’s systems, requirements, and intended use; and
● not upload credentials, secrets, private keys, regulated data, or unnecessary sensitive information unless expressly requested and authorized.
Pvotal is not responsible for delays caused by Customer’s failure to satisfy its onboarding responsibilities.
Pvotal may operate a developer or customer community through Discord or another Community Platform.
The Community Platform may provide:
● peer-to-peer support;
● release announcements and changelog discussions;
● technical discussions and product information; and
● best-effort engagement from Pvotal personnel.
Community Platform support is not covered by any SLA.
Statements made by Pvotal personnel through a Community Platform are informational and do not amend this Agreement, an Order Form, or an SOW.
Customers requiring contracted response times must use the official support channels applicable to their plan or Order Form.
Participants in a Community Platform must:
● treat other participants and Pvotal personnel respectfully;
● not engage in harassment, discrimination, threats, or abusive conduct;
● not disclose Pvotal Confidential Information, another party’s confidential information, proprietary source code, or unreleased Documentation;
● not post cloud credentials, API keys, tokens, secrets, private keys, regulated data, or sensitive Customer Infrastructure information;
● not use the Community Platform for unauthorized advertising, recruitment, spam, or promotion of directly competing products;
● not impersonate Pvotal personnel or other participants; and
● comply with the applicable provider’s terms.
Pvotal may remove content or restrict access for violations without prior notice and without liability, subject to applicable law.
Pvotal accepts good-faith reports of suspected security vulnerabilities affecting Pvotal-operated systems, including Infrastream Hub, Infrastream Cloud, the Onboarding Portal, and Pvotal-controlled Software Artifact distribution systems.
Reports should be sent to:
support@infrastream.io
A report should include, where reasonably available:
● the affected service or URL;
● reproduction steps;
● the suspected impact; and
● the reporter’s contact information.
Customer must not send credentials, personal data contained in Customer Content, private keys, or other unnecessary sensitive information unless specifically requested through a secure method designated by Pvotal.
Pvotal will not pursue legal action solely against a researcher who:
● acts in good faith;
● reports a suspected vulnerability promptly;
● does not access, retain, disclose, modify, or destroy data beyond what is reasonably necessary to demonstrate the issue;
● does not disrupt service availability;
● does not exploit the issue for personal or commercial benefit;
● complies with applicable law; and
● allows Pvotal a reasonable opportunity to investigate and remediate the issue before public disclosure.
This provision does not authorize access to Customer Infrastructure, Customer accounts, personal data, or third-party systems and does not protect unlawful, reckless, extortionate, or harmful conduct.
Any acknowledgement, investigation, triage, remediation, or disclosure-coordination period communicated by Pvotal is an operational target and not a contractual service commitment unless expressly incorporated into an Order Form.
The responsible-disclosure process may cover:
● Infrastream Hub;
● Infrastream Cloud;
● the Onboarding Portal; and
● Pvotal-controlled Software Artifact distribution systems.
Customer-operated Infrastream Private Cloud deployments, denial-of-service testing, social engineering, physical-security testing, and third-party-component findings without a demonstrated impact on a Pvotal-operated system are outside scope unless Pvotal expressly authorizes them in writing.
Nothing in this Agreement obligates Pvotal to provide monetary rewards or public recognition.
Pvotal will maintain administrative, technical, and organizational safeguards designed to protect information processed through Pvotal-controlled systems.
Depending on the applicable Service, configuration, and plan, such safeguards may include:
● encryption in transit;
● encryption at rest for applicable data;
● authentication and access controls;
● multi-factor authentication for applicable privileged access;
● least-privilege controls;
● dependency and vulnerability management;
● logging and monitoring;
● incident-response procedures; and
● security testing.
The controls applicable to a particular Service may vary by deployment model, feature, configuration, and plan.
Statements that Pvotal’s systems are designed to align with a framework, standard, or law do not constitute a certification, warranty, legal opinion, or guarantee of Customer’s compliance.
Pvotal-controlled platform data is generally hosted using Google Cloud infrastructure in the United States. Certain third-party services, including AI model providers used by Pvot AI Agent, may process data in other geographic regions based on service availability, model routing, Customer location, provider infrastructure, or the nearest available AI processing region. The specific locations used to host or process information may therefore depend on the applicable Service, Customer configuration, GCP services, subprocessors, and third-party AI providers. A binding data-residency requirement applies only if expressly stated in an executed Order Form or applicable Data Processing Addendum.
Pvotal may provide eligible enterprise Customers with available security documentation or summary information, subject to confidentiality and reasonable access restrictions.
Unless expressly incorporated into an executed Order Form, security documentation is informational and does not create additional warranties or contractual commitments.
Under Infrastream Cloud, Pvotal manages applicable platform components and the Infrastream Cloud Environment for Customer.
Depending on Customer’s plan and configuration, Pvotal may:
● provision or administer Managed GCP Projects;
● configure service accounts, integrations, roles, tokens, credentials, or permissions required to provide the Services;
● access and process Customer Manifests and other Customer Content;
● execute or facilitate Customer-authorized infrastructure actions;
● operate platform components, workflows, monitoring, metering, billing, and safeguards;
● collect usage, diagnostic, telemetry, and operational information;
● apply updates, configuration changes, and security patches; and
● engage third-party providers to deliver applicable functionality.
The Developer Plan includes capacity for up to nine Managed GCP Projects unless the applicable pricing page, checkout page, or Order Form states otherwise.
Additional projects, capacity, features, support, or usage may require additional fees or a different plan.
Customer is responsible for:
● determining whether the Services are appropriate for Customer’s intended use;
● the accuracy, lawfulness, completeness, and authorization of Customer Content and Customer Manifests;
● reviewing infrastructure plans, configurations, AI-assisted outputs, and proposed actions;
● maintaining appropriate approval, testing, backup, recovery, security, and change-management procedures;
● managing Authorized Users and their permissions;
● complying with applicable laws and third-party terms;
● monitoring Customer’s usage, charges, and account information;
● maintaining a valid payment method and paying all applicable charges;
● exporting Customer Content before termination where continued access is required; and
● all business, technical, security, compliance, and operational decisions made through Customer’s use of the Services.
Customer authorizes Pvotal to take actions within the Infrastream Cloud Environment that are reasonably necessary to provide the Services and carry out instructions initiated, configured, or approved by Customer or its Authorized Users.
Customer acknowledges that Infrastream may make real API calls that create, configure, modify, suspend, disable, or delete cloud resources.
A Customer Manifest, repository event, instruction, workflow, approval, integration, or AI-assisted action may result in material changes to Customer’s environment and may create additional Cloud Usage Charges.
Safeguards, validations, warnings, estimates, approval mechanisms, usage controls, and billing controls may reduce but do not eliminate operational, security, availability, configuration, or cost risk.
Customer remains responsible for:
● reviewing and authorizing material actions before execution;
● validating proposed infrastructure changes;
● maintaining recovery and rollback procedures;
● monitoring resulting infrastructure; and
● the consequences of actions initiated, configured, or approved through Customer’s account.
Under Infrastream Private Cloud, Customer deploys and operates Infrastream within Customer Infrastructure.
Customer is responsible for:
● provisioning, securing, monitoring, and operating Customer Infrastructure;
● maintaining Customer’s cloud account and paying cloud-provider charges directly to the applicable provider;
● managing credentials, Workload Identity configurations, service accounts, tokens, and permissions;
● configuring and securing Customer VCS;
● maintaining backups, disaster recovery, logging, monitoring, and incident response;
● evaluating and applying available Software Artifact updates and patches;
● the correctness, legality, and authorization of Customer Manifests; and
● all infrastructure actions executed within Customer Infrastructure.
The Infrastream Private Cloud includes capacity for up to 29 Managed GCP Projects unless the applicable pricing page, checkout page, or Order Form states otherwise.
No percentage-based Management Fee applies to Customer’s direct cloud-provider charges under Infrastream Private Cloud unless expressly stated in an Order Form.
Additional projects, capacity, features, support, or usage may require additional fees.
Infrastream Private Cloud is deployed within Customer Infrastructure. However, certain features and integrations may transmit information to Pvotal or applicable third-party service providers as necessary to provide the Services. Depending on Customer’s configuration and use of the Services, this information may include:
● Customer Manifests and infrastructure definitions;
● repository information;
● prompts and AI interactions;
● credentials or service-account information;
● usage and billing information;
● product telemetry;
● support communications; and
● information provided through onboarding or Professional Services.
Other information may remain solely within Customer Infrastructure unless Customer enables a transmitting feature, requests support, authorizes access, or otherwise provides the information to Pvotal. The specific data processed, transmitted, or retained may vary by feature, integration, deployment configuration, and third-party provider.
Customer is responsible for Customer Manifests and for ensuring that they:
● accurately reflect Customer’s intended infrastructure;
● are lawfully created, used, and authorized;
● do not infringe third-party rights;
● comply with applicable policies and technical requirements;
● are reviewed before execution; and
● are maintained through appropriate source-control, approval, and change-management procedures.
Pvotal does not independently verify that a Customer Manifest is suitable for Customer’s business, security, legal, regulatory, availability, or cost requirements.
Where Customer uses Pvot AI Agent:
● Pvot AI Agent may generate proposed configurations, manifest changes, plans, explanations, remediation steps, recommendations, or other AI-assisted outputs.
● AI-assisted outputs are probabilistic and may be inaccurate, incomplete, insecure, outdated, biased, fabricated, unsupported, or unsuitable for production use.
● Customer must independently review, test, validate, approve, and monitor AI-assisted outputs.
● Customer must maintain appropriate human oversight for material infrastructure actions.
● Customer assumes responsibility for decisions and actions taken in reliance on AI-assisted outputs.
● Customer shall not disable, bypass, or circumvent a required human-approval control.
Pvotal does not warrant that AI-assisted outputs are unique, non-infringing, secure, accurate, compliant, or suitable for any specific purpose.
Customer is responsible for authorizing and configuring integrations with Customer VCS.
For Infrastream Cloud, Customer authorizes Pvotal and applicable service providers to access and process repository information to the extent reasonably necessary to provide the configured Services.
For Infrastream Private Cloud, repository synchronization may occur directly between Customer Infrastructure and Customer VCS without routing repository content through Pvotal-controlled systems.
Customer is responsible for:
● repository permissions;
● credential and token security;
● branch protection;
● code review;
● access governance;
● webhook and integration settings; and
● actions triggered by repository activity.
Customer is responsible for the security posture of Customer Infrastructure, including identity and access management, network security, secrets management, repository security, workload configuration, backups, monitoring, and incident response.
Pvotal may provide security recommendations through the Documentation, but such recommendations do not transfer Customer’s responsibilities or guarantee that Customer Infrastructure will be secure or compliant.
Pvotal will use commercially reasonable measures designed to protect the integrity of Software Artifacts distributed by Pvotal.
Applicable Software Artifacts may be cryptographically signed.
Customer should follow the Documentation for verifying Software Artifact integrity before deployment into Customer Infrastructure.
For Infrastream Cloud, Pvotal may deploy updates, patches, improvements, model changes, configuration changes, and security fixes without Customer action.
For Infrastream Private Cloud, Pvotal may make available during the applicable Subscription Term:
● bug-fix releases;
● security patches;
● feature releases; and
● major-version upgrades.
Customer is responsible for evaluating, testing, scheduling, and applying updates and patches within Customer Infrastructure.
Pvotal is not responsible for vulnerabilities, incompatibilities, or failures caused by Customer’s failure to apply an available update or security patch within a commercially reasonable period after notice or availability.
Pvotal will use commercially reasonable efforts to provide at least 90 days’ advance written notice before ending support for a generally available major version of Infrastream Private Cloud. The 90-day notice period does not apply where accelerated action is reasonably necessary because of:
● a security vulnerability;
● a legal or regulatory requirement;
● a third-party dependency or service deprecation;
● an AI model or AI service deprecation;
● an intellectual-property concern;
● an emergency; or
● circumstances outside Pvotal’s reasonable control.
End-of-life versions may cease receiving fixes, support, updates, upgrades, or security patches after the applicable end-of-support date.
The Services may rely on third-party APIs, cloud services, AI models, integrations, software, or infrastructure.
Pvotal may modify, replace, suspend, or discontinue an affected integration or feature where reasonably necessary because of a third-party change, deprecation, restriction, outage, security issue, price change, or legal requirement.
Customer agrees to pay all fees and charges associated with Customer’s account and use of the Services.
Fees are stated in the applicable pricing page, checkout page, Order Form, or account.
By completing a purchase and providing a payment method, Customer authorizes Pvotal and its payment processor, including Stripe, to charge that payment method for:
● recurring subscription fees;
● Cloud Usage Charges;
● Management Fees;
● taxes; and
● other charges expressly authorized by the applicable plan, checkout page, Order Form, or Customer instruction.
Unless otherwise stated:
● fees are charged in United States dollars;
● fees exclude applicable taxes;
● subscription fees are charged in advance; and
● usage-based charges may be charged after usage is incurred, measured, received, reconciled, or reported.
Unless a different price is displayed on the applicable checkout page or Order Form, the Developer Plan subscription fee is $20 per month.
Each paid monthly billing period includes:
● one $20 Account Credit; and
● capacity for up to nine (9) Managed GCP Projects.
The Account Credit:
● applies only toward eligible Cloud Usage Charges;
● does not apply toward the Developer Plan subscription fee;
● does not reduce the Management Fee;
● expires at the end of the applicable monthly billing period;
● does not roll over;
● is non-transferable;
● is non-refundable; and
● has no cash value.
In addition to the applicable subscription fee, Customer must pay:
(a) Cloud Usage Charges based on actual GCP consumption through Infrastream Cloud; and
(b) a Management Fee equal to 15% of the applicable Cloud Usage Charges.
The Management Fee is calculated using applicable Cloud Usage Charges before the Account Credit is applied.
The Account Credit reduces only eligible Cloud Usage Charges and does not reduce the amount used to calculate the Management Fee.
GCP usage information may be delayed, estimated, corrected, reclassified, or adjusted after consumption occurs.
Customer authorizes Pvotal to make reasonable billing corrections, including charges or credits resulting from delayed or corrected usage information.
Any usage estimate, budget display, account balance, alert, warning, safeguard, or forecast shown through the Services is informational and does not guarantee final charges or prevent Customer from incurring charges beyond an expected amount.
Customer remains responsible for actual usage associated with its account and Infrastream Cloud Environment.
Customer must maintain sufficient account funding and a valid payment method to support continued use of Infrastream Cloud.
Pvotal may:
● charge an authorized payment method;
● require prepayment or account funding;
● require additional funds before enabling new resources or continued use;
● provide balance notifications or warnings; and
● apply reasonable billing and usage controls disclosed through the Services or an applicable Order Form.
Balance notifications and warnings are provided as a convenience. Pvotal does not guarantee that a notification will be delivered or received before Customer’s balance is exhausted. A Customer-funded balance is separate from an Account Credit.
If Customer’s available balance reaches zero, Pvotal may place the applicable Infrastream Cloud instance into hibernation or a paused state until additional funds are added. Hibernation may include:
● stopping virtual-machine instances;
● causing Cloud Run services and APIs to stop responding;
● pausing databases or placing them into a restricted state;
● blocking new deployments or infrastructure actions; and
● restricting access to paid functionality.
Customer acknowledges that hibernation may not immediately terminate or eliminate every underlying GCP resource or charge. Customer remains responsible for charges incurred before hibernation takes effect and for any charges generated by resources that remain active, reserved, retained, or billable during hibernation. Service may resume after sufficient funds are added, subject to processing time, technical availability, and applicable billing controls.
Infrastream Private Cloud fees are stated in the applicable Order Form.
Customer is billed directly by its cloud provider for Customer Infrastructure.
No percentage-based Management Fee applies to direct cloud-provider charges unless expressly stated in an Order Form.
Professional Services, onboarding, support, capacity, and other enterprise fees may be separately stated in an Order Form or SOW.
Self-service fees are due at the time indicated through the applicable checkout or account.
Unless an Order Form states otherwise, invoiced amounts are due within 30 days after the invoice date.
Overdue amounts may accrue interest at the lesser of:
● 1.5% per month; or
● the maximum rate permitted by applicable law.
Customer shall reimburse reasonable collection costs incurred by Pvotal in collecting undisputed overdue amounts.
Fees and charges exclude applicable sales, use, value-added, withholding, excise, and similar transaction taxes.
Customer is responsible for such taxes, excluding taxes based on Pvotal’s net income, property, or employees.
If Customer is legally required to withhold an amount, Customer shall gross up the payment so that Pvotal receives the amount it would have received absent the withholding, except where prohibited by law.
Pvotal may change self-service pricing by providing reasonable advance notice.
Pricing changes for a self-service subscription will take effect no earlier than the next renewal following the applicable notice period.
For an Order Form, pricing changes apply at renewal unless the Order Form states otherwise.
Changes to third-party charges, including GCP pricing, may take effect when imposed by the applicable provider.
Customer must notify Pvotal at support@infrastream.io of a billing dispute within 30 days after the applicable charge or invoice date.
Customer shall provide sufficient detail for Pvotal to investigate the dispute and shall timely pay all undisputed amounts.
Failure to notify Pvotal within the 30-day period waives the dispute to the extent permitted by applicable law.
Fees and charges are non-refundable except:
(a) where this Agreement expressly provides a refund following termination for Pvotal’s uncured material breach;
(b) for an applicable SLA credit;
(c) as stated in an Order Form; or
(d) as required by law.
Account Credits are non-refundable and have no cash value.
Cloud Usage Charges and Management Fees attributable to actual usage are non-refundable except in the case of a confirmed billing error.
For purposes of this Section 8, “Hub Data” means account, identity, authentication, subscription, billing, usage, support, licensing, and service-administration information processed through Infrastream Hub.
For purposes of this Section 8, “Customer Personal Data” means personal data, personal information, or similar regulated information contained in Customer Content and processed by Pvotal on Customer’s behalf.
Pvotal may process Hub Data to operate, secure, administer, support, bill, and improve the Services.
For Infrastream Cloud, Pvotal and applicable service providers may also process, to the extent reasonably necessary to provide the configured Services:
● Customer Manifests;
● infrastructure configurations;
● resource information;
● infrastructure state;
● deployment and workflow events;
● repository information;
● logs and diagnostics;
● telemetry;
● credentials, tokens, service-account information, and permissions;
● AI prompts and AI-assisted outputs;
● human-approval and workflow records;
● billing and usage information; and
● other Customer Content.
For Infrastream Private Cloud, Pvotal does not routinely receive information maintained solely within Customer Infrastructure unless Customer:
● enables a transmitting feature;
● requests support;
● purchases onboarding or Professional Services;
● voluntarily provides the information;
● expressly authorizes access; or
● instructs Pvotal to process the information.
Pvotal processes personal data as described in the applicable Privacy Policy.
For Hub Data and information processed for Pvotal’s own legitimate business purposes, Pvotal may act as an independent controller or business.
Where Pvotal processes Customer Personal Data solely on Customer’s behalf to provide the Services, Pvotal acts as a processor or service provider.
Customer is responsible for:
● providing required privacy notices;
● obtaining necessary consents;
● establishing a lawful basis for processing;
● responding to data-subject requests relating to Customer’s processing; and
● ensuring that Customer’s instructions comply with applicable law.
Where required by applicable law, a Data Processing Addendum (“DPA”) applies to Pvotal’s processing of Customer Personal Data on Customer’s behalf.
In the event of a conflict concerning such processing, the DPA controls.
For a Subscription Term governed by an executed Order Form, the version of the DPA referenced in that Order Form or otherwise executed by the parties will continue to apply for that Subscription Term unless:
● the parties agree otherwise in writing; or
● an update is required to comply with applicable law.
For purposes of this Agreement, a “Security Incident” means a confirmed unauthorized acquisition of, access to, use of, disclosure of, alteration of, or destruction of Customer Personal Data processed by Pvotal on Customer’s behalf within Pvotal-controlled systems, excluding unsuccessful attempts and incidents limited to Customer Infrastructure.
Pvotal will maintain commercially reasonable safeguards designed to protect Customer Personal Data processed on Pvotal-controlled systems.
After confirming a Security Incident, Pvotal will notify Customer without undue delay and provide information reasonably available to Pvotal regarding:
● the nature of the Security Incident;
● the categories of affected information;
● the mitigation or containment steps taken; and
● available remediation information.
Pvotal’s notification of a Security Incident does not constitute an admission of fault or liability.
This Section does not apply to incidents limited to Customer Infrastructure or caused by Customer, an Authorized User, or a third party outside Pvotal’s reasonable control.
A “Subprocessor” means a third party engaged by Pvotal to process Customer Personal Data on Customer’s behalf. Pvotal may engage Subprocessors to provide the Services.
Where Pvotal acts as a processor or service provider, Pvotal will impose data-protection obligations on Subprocessors that are materially consistent with Pvotal’s applicable obligations concerning Customer Personal Data.
Pvotal remains responsible for the performance of its Subprocessors to the extent required by applicable law and the DPA.
Subject to confidentiality and reasonable access restrictions, Pvotal may provide eligible enterprise Customers with available security documentation, questionnaires, or summary information no more than once per 12-month period unless otherwise agreed.
Pvotal is not required to disclose:
● information that would create a security risk;
● information relating to another customer;
● privileged information;
● proprietary testing materials; or
● information restricted by a third party.
Each party will reasonably cooperate with the other regarding a regulatory inquiry relating to that party’s obligations under this Agreement.
Customer shall reimburse Pvotal for reasonable costs arising from extraordinary cooperation requested by Customer, except where the cooperation is required because of Pvotal’s breach of this Agreement or applicable law.
Pvotal may generate and use aggregated, statistical, or de-identified information derived from use of the Services for purposes including:
● operating and improving the Services;
● measuring performance;
● developing analytics;
● security and abuse prevention;
● capacity planning; and
● business analysis.
Pvotal will not use aggregated or de-identified information in a manner that reasonably identifies Customer or an individual.
Unless Customer expressly opts in or the parties agree otherwise in writing, Pvotal will not use Customer Confidential Information or Customer Personal Data submitted through the Services to train generalized AI models for the benefit of unrelated customers.
This restriction does not prevent Pvotal from:
● processing Customer Content to provide Customer-specific AI functionality;
● using aggregated or de-identified information in accordance with Section 8.8;
● operating security, abuse-prevention, testing, or quality-assurance processes; or
● using Feedback that does not include Customer Confidential Information or Customer Personal Data.
Pvotal and its licensors retain all right, title, and interest in and to:
● Infrastream;
● Infrastream Cloud;
● Infrastream Private Cloud;
● Infrastream Hub;
● Software Artifacts;
● Pvot AI Agent;
● models and system prompts;
● orchestration logic;
● platform architecture;
● Documentation;
● improvements and derivative works; and
● all related intellectual-property rights.
Except for the limited rights expressly granted in this Agreement, no rights are granted to Customer by implication, estoppel, or otherwise.
Customer retains all right, title, and interest in and to:
● Customer Content;
● Customer Manifests;
● Customer VCS content;
● Customer Infrastructure; and
● Customer’s pre-existing intellectual property.
Customer grants Pvotal and its service providers a limited, non-exclusive right to host, copy, transmit, modify, display, process, and otherwise use Customer Content solely as reasonably necessary to:
● provide, secure, support, and administer the Services;
● carry out Customer’s instructions;
● prevent or address technical or security issues; and
● comply with applicable law.
Subject to applicable law and third-party rights, Customer may use AI-assisted outputs generated for Customer through the Services.
Pvotal does not represent or warrant that AI-assisted outputs are:
● unique;
● protectable;
● non-infringing;
● accurate;
● secure;
● complete; or
● suitable for Customer’s intended use.
Similar or identical outputs may be generated for other customers.
Customer is responsible for reviewing outputs before use and for determining whether additional rights, notices, approvals, or attribution are required.
“Feedback” means suggestions, recommendations, enhancement requests, corrections, ideas, evaluations, or other feedback relating to the Services. If Customer provides Feedback, Customer grants Pvotal a perpetual, irrevocable, worldwide, transferable, sublicensable, royalty-free right to use, reproduce, modify, create derivative works from, distribute, commercialize, and otherwise exploit the Feedback without restriction or compensation.
This license does not authorize Pvotal to disclose Customer Confidential Information incorporated into Feedback.
The Services may include open-source software governed by separate license terms.
Nothing in this Agreement limits Customer’s rights under an applicable open-source license.
To the extent an open-source license conflicts with this Agreement regarding a specific open-source component, the open-source license controls solely for that component.
“PS Deliverables” means configurations, templates, documentation, reports, materials, or other deliverables created or provided by Pvotal in connection with Professional Services. Unless an Order Form or SOW states otherwise, Pvotal retains all right, title, and interest in and to PS Deliverables, including improvements to Pvotal’s technology, methodologies, templates, tools, and know-how.
Subject to Customer’s payment of applicable fees, Pvotal grants Customer a non-exclusive, worldwide, royalty-free, non-transferable, non-sublicensable license during the applicable Subscription Term to use PS Deliverables solely in connection with Customer’s authorized use of the Services.
Customer retains ownership of its pre-existing materials and Customer Manifests incorporated into the Professional Services.
“Confidential Information” means non-public information disclosed by or on behalf of one party (“Disclosing Party”) to the other party (“Receiving Party”) that:
● is designated as confidential; or
● reasonably should be understood to be confidential based on its nature and the circumstances of disclosure.
Pvotal Confidential Information includes non-public:
● software;
● source code;
● architecture;
● models;
● system prompts;
● product roadmaps;
● security information;
● pricing;
● business plans;
● proprietary Documentation; and
● technology and know-how.
Customer Confidential Information includes:
● Customer Content processed by Pvotal;
● Customer Manifests disclosed to or processed by Pvotal;
● Customer Infrastructure information;
● credentials and security information;
● Customer business information; and
● non-public Order Form terms.
For Infrastream Cloud, Customer Manifests and other Customer Content processed through Pvotal-controlled systems constitute Customer Confidential Information.
For Infrastream Private Cloud, information that remains solely within Customer Infrastructure and is never disclosed or made available to Pvotal has not been disclosed to Pvotal for purposes of this Section.
The Receiving Party shall:
● protect Confidential Information using at least reasonable care and no less than the care it uses to protect its own similar information;
● use Confidential Information only to exercise rights or perform obligations under this Agreement;
● disclose Confidential Information only to affiliates, employees, contractors, professional advisers, and service providers who have a need to know and are bound by confidentiality obligations at least as protective as those in this Agreement; and
● remain responsible for violations of this Section by its permitted recipients.
The Receiving Party shall promptly notify the Disclosing Party of any unauthorized disclosure of Confidential Information known to the Receiving Party.
Confidential Information does not include information that the Receiving Party can demonstrate:
(a) is or becomes publicly available without breach of this Agreement;
(b) was lawfully known to the Receiving Party without restriction before disclosure;
(c) is lawfully received from a third party without breach of a confidentiality obligation; or
(d) is independently developed without use of or reference to the Disclosing Party’s Confidential Information.
The Receiving Party may disclose Confidential Information to the extent required by applicable law, regulation, subpoena, or court order, provided that the Receiving Party, where legally permitted:
● gives the Disclosing Party prompt written notice;
● reasonably cooperates, at the Disclosing Party’s expense, with efforts to seek a protective order or other appropriate remedy;
● discloses only the portion legally required; and
● uses reasonable efforts to obtain confidential treatment.
Pvotal warrants that, during the applicable Subscription Term:
(a) Pvotal has the authority to enter into this Agreement and grant the rights stated in it;
(b) the paid Services will materially conform to the applicable Documentation when used as authorized;
(c) Professional Services will be performed in a professional and workmanlike manner; and
(d) Pvotal will not knowingly introduce malicious code into Software Artifacts distributed by Pvotal.
Customer’s exclusive remedy for breach of Section 11.1(b) or 11.1(c) is for Pvotal to use commercially reasonable efforts to correct or reperform the affected Services.
If Pvotal does not correct or reperform the affected Services within a commercially reasonable period after receiving written notice, Customer may terminate the affected Services and receive a prorated refund of prepaid, unused subscription or Professional Services fees for the terminated portion.
The foregoing remedy does not apply where the nonconformity results from:
● Customer Content;
● Customer Infrastructure;
● Customer’s configuration or instructions;
● Customer’s failure to follow the Documentation;
● unauthorized modification or use;
● third-party services; or
● Customer’s failure to apply an available update or patch.
Customer represents and warrants that:
● Customer has authority to enter into this Agreement;
● Customer has all rights and permissions necessary for Pvotal to process Customer Content;
● Customer’s use of the Services complies with applicable law;
● Customer Content and Customer Manifests do not infringe or misappropriate third-party rights;
● Customer will not use the Services for unlawful or unauthorized purposes; and
● information provided to Pvotal for billing, account creation, or service delivery is accurate and complete.
EXCEPT FOR THE EXPRESS WARRANTIES IN SECTION 11.1, THE SERVICES, Software Artifacts, DOCUMENTATION, AI-ASSISTED OUTPUTS, ACCOUNT CREDITS, SUPPORT, PROFESSIONAL SERVICES, AND PS DELIVERABLES ARE PROVIDED “AS IS” AND “AS AVAILABLE.”
TO THE MAXIMUM EXTENT PERMITTED BY LAW, PVOTAL DISCLAIMS ALL EXPRESS, IMPLIED, STATUTORY, AND OTHER WARRANTIES, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, QUIET ENJOYMENT, ACCURACY, SECURITY, AND WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.
PVOTAL DOES NOT WARRANT THAT:
● THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, SECURE, OR AVAILABLE AT ALL TIMES;
● DEFECTS OR VULNERABILITIES WILL BE CORRECTED WITHIN A PARTICULAR PERIOD;
● CUSTOMER MANIFESTS, INFRASTRUCTURE PLANS, OR AI-ASSISTED OUTPUTS WILL BE ACCURATE, COMPLETE, SECURE, COMPLIANT, OR SUITABLE;
● SAFEGUARDS, ALERTS, ESTIMATES, APPROVAL CONTROLS, OR BILLING CONTROLS WILL PREVENT ERRORS, OUTAGES, SECURITY INCIDENTS, OR UNEXPECTED CHARGES;
● CUSTOMER WILL ACHIEVE A PARTICULAR BUSINESS, TECHNICAL, SECURITY, COST, OR COMPLIANCE OUTCOME; OR
● THE SERVICES WILL OPERATE WITHOUT INTERRUPTION CAUSED BY THIRD-PARTY SERVICES.
CUSTOMER ASSUMES RESPONSIBILITY FOR INFRASTRUCTURE DECISIONS, CUSTOMER MANIFESTS, CUSTOMER CONTENT, CUSTOMER INFRASTRUCTURE, AND RELIANCE ON AI-ASSISTED OUTPUTS.
The Services may interoperate with or depend on third-party services, including GCP, Stripe, GitHub, GitLab, Discord, Rocketlane, identity providers, AI model providers, and other vendors.
Pvotal is not responsible for the independent:
● availability;
● security;
● performance;
● pricing;
● policies;
● acts;
● omissions; or
● contractual terms
of a third-party provider.
Customer’s use of third-party services may be governed by separate terms between Customer and the applicable provider.
This Section does not limit an express obligation that Pvotal specifically assumes in an executed Order Form.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE UNDER OR IN CONNECTION WITH THIS AGREEMENT FOR ANY:
● INDIRECT;
● INCIDENTAL;
● SPECIAL;
● CONSEQUENTIAL;
● EXEMPLARY; OR
● PUNITIVE DAMAGES,
OR FOR ANY LOSS OF:
● PROFITS;
● REVENUE;
● BUSINESS;
● OPPORTUNITY;
● GOODWILL;
● ANTICIPATED SAVINGS; OR
● DATA,
OR FOR THE COST OF REPLACEMENT SERVICES, EVEN IF THE PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
THE FOREGOING EXCLUSION APPLIES REGARDLESS OF THE THEORY OF LIABILITY AND REGARDLESS OF WHETHER A REMEDY FAILS OF ITS ESSENTIAL PURPOSE.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT WILL NOT EXCEED THE TOTAL SUBSCRIPTION FEES AND MANAGEMENT FEES PAID OR PAYABLE BY CUSTOMER FOR THE AFFECTED SERVICES DURING THE 12 MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE FIRST CLAIM.
THE FEE BASE USED TO CALCULATE THE CAP EXCLUDES:
● CLOUD USAGE CHARGES;
● THIRD-PARTY PASS-THROUGH CHARGES;
● TAXES; AND
● AMOUNTS PAID DIRECTLY TO A THIRD-PARTY PROVIDER.
IF CUSTOMER HAS USED THE AFFECTED SERVICE FOR LESS THAN 12 MONTHS, THE CAP WILL BE BASED ON THE FEES PAID OR PAYABLE DURING THE PERIOD OF USE.
Sections 12.1 and 12.2 do not limit:
(a) Customer’s payment obligations;
(b) either party’s liability for fraud, willful misconduct, or gross negligence;
(c) either party’s infringement or misappropriation of the other party’s intellectual-property rights;
(d) Customer’s violation of Section 3.3;
(e) either party’s indemnification obligations under Section 13, except as expressly stated there; or
(f) liability that cannot legally be limited.
Pvotal’s aggregate liability arising from a Security Incident affecting Customer Personal Data on Pvotal-controlled systems will not exceed three times the cap calculated under Section 12.2.
The special Security Incident cap does not apply to:
● incidents limited to Customer Infrastructure;
● incidents caused by Customer, an Authorized User, or a third party outside Pvotal’s reasonable control; or
● unsuccessful security events that do not result in a confirmed Security Incident.
Except to the extent prohibited by law, the exclusion of consequential damages in Section 12.1 applies to Security Incident claims, provided that reasonable third-party investigation, notification, credit-monitoring, and remediation costs legally recoverable from Pvotal may be treated as direct damages within the applicable special cap.
Pvotal will defend Customer against a third-party claim alleging that:
(a) Infrastream Cloud, as operated by Pvotal and used by Customer as authorized under this Agreement; or
(b) an unmodified Software Artifact distributed by Pvotal and used within the authorized scope,
infringes a United States patent, copyright, or trade secret.
Pvotal will pay damages finally awarded against Customer or amounts approved by Pvotal in a settlement, subject to Section 13.3.
Pvotal has no obligation under this Section for a claim arising from:
● Customer Content;
● Customer Manifests;
● Customer Infrastructure;
● Customer’s specifications or instructions;
● Customer’s modification of a Software Artifact;
● unauthorized use of the Services;
● use outside the Documentation or authorized scope;
● a combination with technology not provided or required by Pvotal;
● continued use after Pvotal provides a replacement or written stop-use instruction;
● third-party services;
● open-source components; or
● AI-assisted outputs.
If an infringement claim is made or reasonably likely, Pvotal may:
1. procure the right for Customer to continue using the affected Service;
2. modify or replace the affected Service with a substantially equivalent non-infringing alternative; or
3. if the first two options are not commercially reasonable, terminate the affected Service and refund prepaid, unused subscription fees for the terminated portion of the Subscription Term.
This Section states Customer’s exclusive remedy and Pvotal’s sole liability for third-party intellectual-property infringement claims relating to the Services.
Customer will defend Pvotal, its affiliates, and their respective officers, directors, employees, and agents against a third-party claim arising from or relating to:
● Customer Content;
● Customer Manifests;
● Customer Infrastructure;
● Customer’s violation of this Agreement;
● Customer’s unlawful or unauthorized use of the Services;
● Customer’s infringement or misappropriation of third-party rights;
● Customer’s use of AI-assisted outputs;
● Customer’s modification or redistribution of Software Artifacts; or
● acts or omissions of Customer or an Authorized User.
Customer will pay damages finally awarded against an indemnified party or amounts approved by Customer in a settlement, subject to Section 13.3.
The indemnified party must:
(a) give the indemnifying party prompt written notice of the claim, provided that delayed notice relieves the indemnifying party only to the extent materially prejudiced;
(b) grant the indemnifying party sole control of the defense and settlement; and
(c) provide reasonable cooperation at the indemnifying party’s expense.
The indemnifying party may not settle a claim in a manner that:
● admits wrongdoing by the indemnified party;
● imposes a monetary obligation on the indemnified party;
● requires the indemnified party to take or refrain from an action unrelated to the affected Services; or
● fails to provide a full release,
without the indemnified party’s prior written consent, not to be unreasonably withheld.
The indemnified party may participate in the defense using counsel of its choice at its own expense.
This Agreement begins when Customer first:
● completes a purchase;
● executes an Order Form;
● creates an account; or
● accesses or uses the Services.
A self-service monthly subscription automatically renews for successive monthly periods until cancelled in accordance with this Agreement.
An Order Form renews only as stated in that Order Form.
Either party may terminate an affected Order Form or this Agreement for material breach if the breach is not cured within 30 days after written notice.
A party may terminate immediately if the other party:
● becomes insolvent;
● makes an assignment for the benefit of creditors;
● enters bankruptcy or similar proceedings that are not dismissed within 60 days; or
● ceases business operations.
Pvotal may suspend or terminate Services immediately where reasonably necessary to address:
● a material security risk;
● unlawful or fraudulent activity;
● sanctions or export-control concerns;
● infringement or misappropriation;
● harm to Pvotal, another customer, or a third party; or
● conduct that materially threatens the Services.
Customer may cancel a self-service subscription through the available account-management process or by contacting support@infrastream.io.
Cancellation takes effect at the end of the then-current paid billing period unless applicable law requires otherwise.
Customer remains responsible for charges incurred through the effective cancellation date and until applicable cloud resources stop generating charges.
Pvotal may terminate a self-service Service for convenience by providing at least 30 days’ notice.
Pvotal may terminate an enterprise Order Form for convenience only where the Order Form permits it or upon at least 90 days’ notice, in which case Pvotal will refund prepaid, unused subscription fees for the terminated portion.
Upon termination or expiration of Infrastream Cloud:
(a) Customer’s access rights end;
(b) Pvotal may disable accounts, managed workflows, deployments, and administrative access;
(c) Customer must cease initiating actions through the terminated Services;
(d) Customer remains responsible for Cloud Usage Charges, Management Fees, and other charges incurred until applicable resources are stopped, disabled, or deleted;
(e) Customer is responsible for exporting Customer Content before termination where continued access is required; and
(f) Pvotal may delete or retain Customer Content in accordance with the Privacy Policy, applicable DPA, and legal obligations.
Termination or suspension does not guarantee that GCP resources will immediately stop operating or generating charges.
Any transition assistance is subject to:
● technical availability;
● mutual agreement;
● applicable fees; and
● Customer’s timely cooperation.
Upon termination or expiration of Infrastream Private Cloud:
(a) all applicable license rights end;
(b) Customer’s access to related Hub functionality may end;
(c) Pvotal may revoke the applicable License Key; and
(d) Customer must cease use of and decommission applicable Software Artifacts, subject to the 30-day transition period described below (the “Wind-Down Period”).
Unless Pvotal terminates because of Customer’s uncured material breach, unlawful conduct, security risk, or intellectual-property violation, Customer may continue using then-installed Software Artifacts solely for transition and migration for up to 30 days after the effective termination date.
During the Wind-Down Period:
● no new production use is permitted;
● Customer may not expand the deployment;
● Customer remains responsible for cloud-provider charges;
● Pvotal has no obligation to provide support, updates, upgrades, or new License Keys unless otherwise agreed; and
● the disclaimers and limitations in this Agreement continue to apply.
At the end of the Wind-Down Period, Customer shall destroy or decommission the affected Software Artifacts and, upon reasonable request, certify completion in writing.
Pvotal may suspend all or part of the Services for:
● overdue payment;
● failed payment;
● insufficient funds;
● expiration or invalidity of the payment method;
● usage beyond applicable capacity;
● violation of the Acceptable Use Policy;
● a material security or legal risk;
● suspected fraud;
● sanctions or export-control concerns; or
● conduct that threatens the Services, Pvotal, another customer, or a third party.
Where reasonably practicable, Pvotal will provide notice and an opportunity to cure before suspension.
Suspension does not relieve Customer of payment obligations and may not stop existing resources or Cloud Usage Charges.
Customer remains responsible for charges incurred until applicable resources are stopped, disabled, or deleted.
The following survive termination or expiration:
● accrued payment obligations;
● Sections 3.3, 7, 8, 9, 10, 11, 12, 13, 14.4, 14.5, 14.7, and 15;
● any provision that by its nature should survive; and
● obligations under an applicable DPA that continue after termination.
This Agreement is governed by the laws of the State of Delaware, without regard to conflict-of-laws principles.
Subject to Section 15.2, each party submits to the exclusive jurisdiction of the state and federal courts located in Delaware.
Before initiating formal proceedings, the parties will attempt in good faith to resolve a dispute through business-level discussions for at least 30 days after written notice of the dispute.
This requirement does not prevent either party from seeking:
● injunctive relief;
● protection of intellectual-property rights;
● relief for unauthorized access or security threats; or
● collection of undisputed overdue amounts.
Each party shall comply with applicable export-control, sanctions, and trade laws.
Customer shall not access or use the Services:
● in a prohibited territory;
● on behalf of a prohibited person;
● for a prohibited end use; or
● in violation of applicable sanctions or export restrictions.
Customer represents that it is not a prohibited or restricted party under applicable law.
This Agreement, together with applicable Order Forms, SOWs, SLAs, DPAs, and incorporated addenda, constitutes the entire agreement between the parties concerning the Services and supersedes prior or contemporaneous agreements, communications, and proposals concerning the same subject matter.
Purchase orders and similar Customer documents are for administrative convenience only and do not modify this Agreement.
In the event of a conflict, the following order applies:
1. an executed Order Form;
2. a mutually executed addendum;
3. an SOW, solely regarding the applicable Professional Services;
4. an SLA, solely regarding the applicable service levels;
5. an AI-specific addendum, solely regarding covered AI functionality;
6. this Agreement;
7. the DPA, provided that the DPA controls regarding Pvotal’s processing of Customer Personal Data on Customer’s behalf;
8. the Privacy Policy, regarding Pvotal’s controller-side privacy disclosures; and
9. the Documentation.
A lower-ranked document controls where a higher-ranked document expressly states that the lower-ranked provision will control.
Pvotal may amend this Agreement by providing at least 30 days’ advance notice of a material change.
For a self-service subscription, a material change will take effect no earlier than the next renewal after the notice period, except where an earlier change is reasonably necessary to:
● comply with law;
● address a security issue;
● prevent fraud or abuse; or
● respond to a third-party requirement.
For an Order Form, the version of this Agreement in effect on the Order Form’s effective date governs during the committed Subscription Term unless:
● the parties agree otherwise in writing; or
● an update is required by applicable law.
Customer may not assign this Agreement without Pvotal’s prior written consent, except to an affiliate (an entity that directly or indirectly controls, is controlled by, or is under common control with Customer) or in connection with a merger, reorganization, or sale of substantially all of Customer’s assets, provided that:
● the assignee is not a direct competitor of Pvotal;
● the assignee agrees in writing to be bound by this Agreement; and
● Customer provides prompt written notice.
Pvotal may assign this Agreement to an affiliate or in connection with a merger, reorganization, financing, sale of assets, or change of control.
Any prohibited assignment is void.
Neither party is liable for delay or failure to perform caused by circumstances beyond its reasonable control, including:
● natural disasters;
● acts of government;
● war;
● terrorism;
● civil unrest;
● labor disputes;
● internet or telecommunications failures;
● cloud-provider outages;
● utility failures;
● epidemics;
● cyberattacks not caused by the affected party’s breach; or
● third-party-service failures.
The affected party will use commercially reasonable efforts to mitigate the impact.
This Section does not excuse Customer’s obligation to pay charges already incurred.
If a provision of this Agreement is unenforceable, it will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions will remain in effect.
A waiver must be in writing and signed by the waiving party.
Failure to enforce a provision does not waive future enforcement.
Formal legal notices to Pvotal must be sent to:
Pvotal Technologies, Inc.
Email: legal@pvotal.tech
Formal legal notices to Customer may be sent to the email address associated with Customer’s account or stated in an Order Form.
Notices are effective:
● when received, if delivered personally;
● on confirmed delivery, if sent by recognized courier;
● when transmitted without an error notice, if sent by email; or
● when displayed through the account for notices permitted to be delivered electronically.
Operational, billing, and support communications may be sent through the Services or to the account email address.
Neither party may issue a press release or public statement regarding the parties’ relationship or use the other party’s name, logo, or trademarks in public-facing marketing without the other party’s prior written consent, except where an applicable Order Form expressly permits such use.
Customer consents to receiving electronic communications concerning:
● the Services;
● billing;
● renewal;
● security;
● account administration;
● legal notices;
● changes to this Agreement; and
● operational matters.
Customer is responsible for maintaining a current email address in its account.
Electronic communications satisfy legal requirements that a communication be in writing to the extent permitted by law.
This Agreement does not create third-party beneficiary rights except for indemnified parties expressly identified in Section 13.
The parties are independent contractors.
Nothing in this Agreement creates a:
● partnership;
● franchise;
● joint venture;
● fiduciary relationship;
● employment relationship; or
● agency relationship.
Neither party has authority to bind the other except as expressly stated in writing.
Headings are for convenience only and do not affect interpretation.
“Including” means “including without limitation.” The singular includes the plural and vice versa where appropriate. A reference to “written” or “in writing” includes electronic communications where permitted by this Agreement.
Customer and Authorized Users must not use the Services to engage in the following conduct.
A. Infrastream Hub and Infrastream Cloud
1. Credential Sharing: Sharing account credentials or authentication factors with unauthorized persons.
2. Billing Circumvention: Avoiding, disabling, falsifying, or manipulating usage metering, Cloud Usage Charges, Management Fees, credits, or billing controls.
3. Unauthorized Access: Attempting to access another account, tenant, project, environment, data set, or system without authorization.
4. Infrastructure Abuse: Scraping, excessive automation, rate-limit circumvention, denial-of-service activity, or conduct that degrades Pvotal or third-party infrastructure.
5. Unauthorized Redistribution: Reselling, sublicensing, redistributing, or providing Services to unauthorized third parties.
6. Competitive Misuse: Accessing or using non-public aspects of the Services to develop, train, benchmark, or improve a directly competing product.
7. Malicious Activity: Creating, deploying, distributing, or facilitating malware, ransomware, destructive code, credential theft, botnets, or unauthorized access tools.
8. Safeguard Circumvention: Disabling or bypassing required approval workflows, security controls, billing controls, capacity restrictions, or technical safeguards.
9. Unlawful Content or Conduct: Using the Services to violate applicable law or third-party rights.
10. Misrepresentation: Providing false or misleading identity, billing, authorization, project, or infrastructure information.
B. Infrastream Private Cloud
11. License Circumvention: Operating Infrastream Private Cloud or Software Artifacts in environments not authorized by the applicable License Key or Order Form.
12. Artifact Tampering: Removing or altering cryptographic signatures, proprietary notices, license controls, or integrity mechanisms.
13. Unauthorized Distribution: Redistributing Software Artifacts, License Keys, or Documentation to an unlicensed entity.
14. Unauthorized Expansion: Expanding deployment scope, capacity, environments, or organizations beyond the authorized Order Form.
C. Infrastream Onboarding Portal
15. Unauthorized Invitations: Inviting individuals who are not authorized stakeholders for the applicable engagement.
16. Sensitive Data Upload: Uploading credentials, secrets, private keys, regulated data, or unnecessary sensitive information without authorization.
17. Misrepresentation: Providing materially false architectural, billing, security, or implementation information.
18. Disruption: Using the Onboarding Portal to harass participants, upload malicious content, or disrupt the engagement.
D. Community Platform
19. Credential Exposure: Posting credentials, tokens, API keys, secrets, private keys, or sensitive Customer Infrastructure information.
20. Harassment or Abuse: Engaging in threats, discrimination, harassment, personal attacks, or disruptive conduct.
21. Spam and Solicitation: Unauthorized advertising, recruitment, repeated solicitation, or irrelevant promotional activity.
22. Impersonation: Impersonating Pvotal personnel, another participant, or another organization.
23. Confidentiality Violations: Disclosing Pvotal Confidential Information, Customer Confidential Information, or another party’s protected information.
Violations may result in removal of content, restriction of account access, suspension of managed workflows, suspension or revocation of License Keys, or termination under Section 14. Pvotal may preserve evidence and report suspected criminal conduct to appropriate authorities where legally permitted.
A contractual service-level commitment applies only where an SLA is expressly incorporated into Customer’s Order Form or checkout terms. Where expressly included in an applicable SLA, the following monthly availability targets may apply:
● Infrastream Hub: 99.5%
● Infrastream Core: 99.5%
● Artifact Registry: 99.9%
● Onboarding Portal: 97.5%
● Pvot Agents: 95%
The applicable SLA will identify the covered components, measurement methodology, exclusions, remedies, and Subscription Term. Unless expressly stated otherwise, no contractual uptime commitment or service-credit entitlement applies to:
● the Infrastream Cloud Developer Plan;
● no-charge Services;
● promotional access;
● trial or evaluation access;
● beta or preview functionality;
● Professional Services;
● the Community Platform; or
● any Service not expressly identified in the applicable SLA.
Scheduled maintenance, emergency maintenance, Customer-caused downtime, Customer Infrastructure failures, third-party-service failures, AI-provider failures, force-majeure events, and other exclusions will be treated as stated in the applicable SLA. Service credits stated in an applicable SLA are Customer’s sole and exclusive remedy for failure to satisfy the corresponding service-level commitment unless the applicable Order Form expressly states otherwise.
Infrastream is developed and distributed by Pvotal Technologies, Inc. All rights reserved.
pvotal.tech · accounts.infrastream.io · docs.infrastream.io · legal@pvotal.tech