Marshal
Terms of servicePrivacy policyData processing addendumSubprocessors
Sign in
Draft for attorney review. This document has not been reviewed by counsel and is not yet in effect. It does not create obligations for Marshal or for you.

Terms of service

Last updated [DATE - SET AT PUBLICATION]

These terms are an agreement between [MARSHAL LEGAL ENTITY NAME] ("Marshal", "we", "us") and the organization that signs up for the service ("you", "your", the "Customer"). By creating an account or using the service you agree to them. If you are agreeing on behalf of a company, you confirm you are allowed to bind that company.

1. Definitions

  • Service means the Marshal platform at marshalcloud.com, its API, and any software we give you to run in your own environment (for example the Kubernetes agent and the device reporter script).
  • Organization (or "org") means a workspace in the Service. Your data, users, connections, and billing plan all belong to an organization.
  • Cloud account means a cloud provider account, project, or cluster you connect to the Service.
  • Customer data means everything the Service holds for your organization: billing and usage records read from your cloud accounts, resource configuration, monitor results, device reports, recommendations, alerts, audit records, and the account details of your users.
  • Action means a change to your infrastructure that the Service can carry out from our published action catalog, such as stopping a server, deleting an unattached disk, or releasing an unused IP address.
  • Credentials means the access you grant us to a cloud account, normally a cross-account role plus a secret external ID.

2. Accounts

  1. A login belongs to one person. Do not share a password or an API key between people. Add each colleague as a separate user in your organization.
  2. Users hold a role in each organization: owner, admin, infosec, sre, or viewer. Roles decide what a user can see and do, including who may approve an action. You are responsible for keeping the right people in the right roles and for removing people who leave.
  3. A DevOps agency organization can be linked to a client organization. In that case the client sets a ceiling on what the agency may do. If you are the client, that link is yours to grant and to revoke.
  4. You are responsible for everything done under your users' logins and API keys. Tell us at [SECURITY CONTACT EMAIL] as soon as you think a login or key has been misused.
  5. You must be old enough to enter a contract in your country, and at least [MINIMUM AGE - COMPANY TO CONFIRM]. The Service is for organizations, not for personal or household use.

3. What the Service does

3.1 Reading your cloud

When you connect a cloud account, the Service reads billing and usage records, resource configuration, and utilization metrics. It uses these to show spend, draw an architecture map, raise security findings, and estimate savings. The default connection is read-only and cannot create, change, or delete anything in your account.

3.2 Monitoring

The Service can check that your websites, endpoints, certificates, and domains are reachable and valid, and can alert you when they are not. Marshal is not a substitute for your own operational monitoring, and we do not promise that a check will always run or that an alert will always be delivered.

3.3 Recommendations and savings estimates

The Service proposes ways to reduce spend. Every estimate is an estimate. Each one records the source it was calculated from, such as your own last 30 days of billing combined with utilization metrics, or a recommendation returned by your cloud provider's own API, together with a confidence level. Estimates are not a guarantee of a result, an offer of a refund, and not a commitment to any level of saving. Your actual bill depends on your usage, your provider's pricing, and decisions you make after the estimate is produced.

3.4 Approval-gated changes

  1. Automated fixes are optional. They require you to install a second, separate role in your cloud account whose permissions match our action catalog and nothing else. If you never install it, the Service can never change anything.
  2. Before any change, the Service shows you a plain-language plan, the resource it affects, an estimated dollar impact, and whether the change can be undone.
  3. When you approve an action, you instruct and authorize Marshal to make that change in your cloud account using the credentials you granted us. Approval is per action, by a user holding an approving role. We act on your instruction, as your agent, for that action only. The Service has no fully automatic mode.
  4. Some actions cannot be undone, and we label them before you approve. Each action is shown as reversible (we can put the resource back), compensating (undo recreates an equivalent, the original is gone), or irreversible (we cannot undo it at all). Releasing an IP address, deleting a snapshot, and buying a savings plan are examples of irreversible actions. Where a delete is offered, we take a safety snapshot first and keep it for 14 days.
  5. You are responsible for deciding whether a change is safe for your business. We are responsible for carrying out the approved change as described, and for recording who proposed it, who approved it, and what happened.
  6. You can turn off any category of action, or remove the remediation role, at any time.

3.5 AI features

The Service uses third-party AI providers to explain your data in plain language. The AI surface is read-only by design: it can query your data in the Service but has no ability to change your infrastructure. AI output can be wrong. Check anything important before acting on it. See the privacy policy for what is sent to which provider.

4. Your responsibilities and acceptable use

  1. Only connect cloud accounts, monitor targets, and computers you own or are authorized to manage. You confirm you have that authority.
  2. If you install the device reporter on computers used by your staff, you are responsible for telling those people, and for having a lawful basis to do so. See section 5 of the privacy policy.
  3. Do not use the Service to attack, scan, or load-test systems you do not control. Do not use monitoring targets to reach private or internal addresses. We block this technically and will also treat it as a breach of these terms.
  4. Do not attempt to reach another customer's data, bypass rate limits, reverse engineer the Service, or resell access unless we have agreed to it in writing.
  5. Do not upload unlawful content, malware, or anything that infringes someone else's rights.
  6. Automated use through the API must stay within the published rate limits and your plan's limits.

We may suspend an organization without notice if its use threatens the security, integrity, or availability of the Service or of another customer. We will tell you why, and restore access once the cause is resolved.

5. Fees and billing

  1. The Service has a free plan and paid plans (Starter and Pro). Each plan has published limits, including how many cloud accounts and monitors you can have, how much history you can query, and whether automated fixes, Kubernetes, and API access are available.
  2. Paid plans are bought and billed through Stripe, our payment processor. We do not receive or store your full card details. Prices are in US dollars and exclude tax unless stated otherwise.
  3. Your subscription renews automatically each billing period until it is cancelled.
  4. Cancellation. [CANCELLATION MECHANISM AND TIMING - COMPANY TO CONFIRM]. In the product today, a subscription is cancelled through Stripe rather than through a Marshal screen, and your organization returns to the free plan when Stripe reports the subscription as ended. Whether that happens immediately or at the end of the paid period is set by the subscription configuration in Stripe, not by Marshal's code, so this clause must state the configured behaviour before publication.
  5. Refunds and proration. [REFUND AND PRORATION POLICY - COMPANY TO CONFIRM]. Marshal's code does not calculate proration or issue refunds; any such behaviour comes from the Stripe configuration and must be stated here.
  6. When an organization drops to the free plan, features above that plan's limits stop working. Your data is not deleted by a downgrade.
  7. We may change prices for a future billing period by giving you at least [PRICE CHANGE NOTICE PERIOD - COMPANY TO CONFIRM] notice by email.
  8. You pay your own cloud provider directly. Marshal never pays, receives, or takes a share of your cloud bill, and does not charge a percentage of savings unless a separate written agreement says so.

6. Intellectual property

  1. We own the Service, including its software, interfaces, documentation, templates, and brand. These terms give you a limited, non-exclusive, non-transferable right to use the Service during your subscription, and nothing more.
  2. You own your customer data. You grant us the right to process it only as needed to provide, secure, support, and improve the Service for you, and as described in the privacy policy and the data processing addendum.
  3. If you send us feedback, we may use it without obligation to you.
  4. We may use aggregated, de-identified statistics that cannot identify you or any individual to operate and improve the Service. We do not publish your name as a customer without your permission.

7. Disclaimers

THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, OR NON-INFRINGEMENT.

We do not promise any level of uptime or availability for the Service. There is no service level agreement, and none is incorporated into these terms unless we sign one with you separately. Uptime figures that the Service reports about your systems describe your systems, not ours.

We do not warrant that savings estimates will be achieved, that recommendations are complete or correct, that monitoring will detect every outage, that security findings identify every risk, or that AI-generated text is accurate. The Service supports your judgement. It does not replace it, and it is not legal, financial, tax, or compliance advice.

8. Limitation of liability

  1. Neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, lost revenue, lost savings, or lost or corrupted data, even if told such damages were possible.
  2. Each party's total liability arising out of or related to these terms is capped at the fees you paid or owed to us for the Service in the twelve months before the event that gave rise to the claim. [LIABILITY CAP - COUNSEL TO CONFIRM, INCLUDING THE CAP FOR FREE-PLAN CUSTOMERS WHO HAVE PAID NOTHING.]
  3. These limits do not apply to: your obligation to pay fees; either party's indemnification obligations; a party's fraud, wilful misconduct, or gross negligence; or any liability that cannot be limited by law.
  4. These limits apply in aggregate across all claims and regardless of the legal theory.

9. Indemnification

  1. You will defend and indemnify us against third-party claims arising from your customer data, your use of the Service in breach of these terms, your instruction to us to carry out an action, or your failure to notify the people whose computers you track with the device reporter.
  2. We will defend and indemnify you against third-party claims that the Service, as provided by us and used as permitted, infringes that party's intellectual property rights.
  3. The party seeking indemnity must give prompt notice, let the other party control the defence, and give reasonable help. No settlement that admits fault or imposes an obligation may be made without the indemnified party's consent.

10. Term, suspension, and termination

  1. These terms apply from the day you create an account until every organization you own is closed.
  2. You may stop using the Service at any time. You may end our access to your cloud immediately and independently of us by deleting the CloudFormation stack or role you installed, uninstalling the Kubernetes agent, or removing a device.
  3. Either party may terminate for material breach that is not fixed within 30 days of written notice.
  4. Deletion. When an organization is deleted, we erase its records from our primary database, delete its billing, usage, and uptime rows from our analytics store, and clear its cached data. The analytics and cache steps are best effort and are reported as succeeded or failed so that nobody assumes erasure finished when only part of it did; if a step fails we repeat it. A person's own login record and their account security log sit outside any single organization and are deleted separately, on request. Ask us at [PRIVACY CONTACT EMAIL] to delete an organization or a user, and see the privacy policy for what remains in backups.
  5. Sections on intellectual property, disclaimers, liability, indemnification, and governing law survive termination.

11. Confidentiality

Each party will protect the other's non-public information with at least reasonable care, use it only for this agreement, and share it only with people and subprocessors who need it and are under similar obligations. This does not cover information that is public, already known, independently developed, or lawfully received from someone else, and it does not prevent a disclosure required by law where notice is given if allowed.

12. Governing law and disputes

These terms are governed by the laws of [JURISDICTION - COMPANY TO CONFIRM], without regard to conflict-of-law rules. The courts of [VENUE - COMPANY TO CONFIRM] have exclusive jurisdiction. [ARBITRATION, CLASS-ACTION WAIVER, AND CONSUMER CARVE-OUTS - COUNSEL TO DECIDE.]

13. Changes to these terms

We may update these terms. If a change materially reduces your rights or increases your obligations, we will give you at least [TERMS CHANGE NOTICE PERIOD - COMPANY TO CONFIRM] notice by email to your organization's owners and by a notice in the product. Continuing to use the Service after the change takes effect means you accept it. If you do not accept it, stop using the Service and ask us to delete your organization.

14. General

  • Whole agreement. These terms, the privacy policy, and the data processing addendum are the whole agreement between us on this subject.
  • Assignment. Neither party may assign this agreement without the other's consent, except to a successor in a merger or sale of substantially all assets.
  • Severability. If a clause is unenforceable, the rest stays in force.
  • No waiver. Not enforcing a right once does not waive it.
  • Notices. We will contact you at the email addresses of your organization's owners. Contact us at [LEGAL CONTACT EMAIL], or at [COMPANY REGISTERED ADDRESS - COMPANY TO CONFIRM].
  • Force majeure. Neither party is liable for a delay caused by events outside its reasonable control, other than a failure to pay.

Questions about these documents: [LEGAL CONTACT EMAIL - COMPANY TO CONFIRM].