No form. No qualification step. No sales desk.
hello@tenhaw.com reaches James Rooney, who replies.
You want to run an evaluation
Say what your agents do and which providers they call, and you will get a straight answer about whether Token Observe fits, including when it does not. James Rooney replies; there is no sales desk in between.
hello@tenhaw.comYou are running a security or procurement review
The threat model, the data-flow document, the licence, the support terms and the published known-issues list are all on this site or in the repository, and none of them needs a call. Anything a questionnaire asks that they do not answer, ask here.
security@tenhaw.comYou have found a vulnerability
Report it to the same address, or through the repository's advisory link. Security research and publication of the results are expressly permitted by the licence: no gag clause, and no pre-approval of what you publish.
security@tenhaw.comYou would rather read the source first
Reasonable, and it is the fastest way to answer most questions on this site. The governance domain is pure functions with zero runtime dependencies, so what allow, block, approve and delegate actually mean can be read in a day without standing up any infrastructure.
github.com/Tenhaw/AgentControlPlaneWhat you get back, and what you will not get.
A reply from a person, usually within a working day, saying whether Token Observe fits what you described — including when it does not. The most useful thing you can send is the unpolished version: which agents you are running, which providers they call, what one of them is allowed to do that worries you, and what would have to be true before you would put a control in front of it.
You will not be added to a mailing list, entered into a nurture sequence, or asked to fill in a qualification form before somebody will speak to you. Nothing on this site records that you are evaluating the product before you have decided to say so yourself.
If you are running a supplier security review, most of what your questionnaire asks is already published and needs no call: the security page carries the data flow, the threat-model summary, the residual risks and the list of what is deliberately not claimed, and the compliance page carries the framework mappings with an honest coverage level on every row.
Tenhaw LTD
- Registered
- England and Wales, no. 12735685
- Incorporated
- 10 July 2020
- Based
- London, England
- Serving
- United Kingdom, Europe, United States
- Sales and support
- hello@tenhaw.com
- Security and disclosure
- security@tenhaw.com
The company record is public and linked so the registration above is a checkable fact rather than a claim: Companies House.
Before you write
The commercial questions people ask first. The full set is on the questions page.
How is Token Observe licensed?
Token Observe is published under a commercial source-available licence, version 1.0, from Tenhaw Ltd, registered in England and Wales and governed by the laws of England and Wales. Source-available rather than open source, and the harder of the two words is the accurate one. The rights below run for the subscription term of an order form stating the fees and the permitted scope of use; without one, a thirty-day evaluation grant applies instead. You may install, host and operate it on infrastructure you control; read, compile and modify the source and create derivative works for internal purposes, including to integrate it and to remediate defects; keep backup, disaster-recovery, development, testing, staging and training copies; and have contractors exercise those rights for you. You own the modifications you make and need not disclose them. You may not redistribute it, or provide it or a substantial part of its functionality to a third party as a hosted, managed or white-labelled service. Security research and publication of the results are expressly permitted. One caveat travels with all of it: the published licence is a template pending review by counsel, not an executed grant of rights.
How is Token Observe priced?
Token Observe has no public price list. An order form states the subscription term, the fees and the permitted scope of use — for example a number of deployments or agents. A deployment is one installation you operate on infrastructure you control, together with its non-production copies. An agent is one autonomous or semi-autonomous process registered in the agent registry that authenticates to the gateway with its own credential. Non-production copies — backup, disaster recovery, development, testing, staging and training — count towards neither figure provided they do not serve production traffic. Two consequences a procurement team should know. Compliance is self-certified: because the software reports nothing to the vendor there is no metering component, no inspection right and no records to hand over, only one written certification a year on thirty days’ notice. And the current commercial shape is a design-partner agreement rather than a standard subscription, because the release gates that would justify one are not yet closed.
Can we evaluate Token Observe before buying?
Yes. Token Observe carries a thirty-day evaluation grant, and it exists precisely so a prospective customer’s security team can read, run and attack the software before a purchase order is raised. Thirty days from first installation, for internal evaluation, security review and proof of concept, with no order form. The boundaries sit in the same clause: no live production traffic, no regulated personal data, and no support, warranty or SLA during it. Within that window, inspecting, testing, fuzzing, penetration-testing and reverse-engineering the software as deployed on infrastructure you control are expressly permitted, you may commission a third party to do it for you, and you may publish both performance results and security findings — no pre-approval of benchmark results provided the publication names the version and configuration tested, and coordinated disclosure for security findings. The vendor already publishes its own outstanding defects, so that clause is written to be consistent with the practice rather than to suppress yours.
What does support look like, and what is the SLA?
Token Observe carries no availability SLA and no service credits, and the reasoning is worth reading before accepting one from any self-hosted vendor. The vendor does not operate your deployment, cannot observe it and cannot restart it, so an uptime number would be unmeasurable by either side; no partner-shaped sustained-load result has been retained, so a capacity figure would be a guess wearing a number. What is committed is a first substantive response from a named human, not a resolution time: two business hours for S1 with updates every four, one business day for S2, three for S3 and five for S4, during 09:00 to 17:30 Europe/London, Monday to Friday, with no out-of-hours cover and the clock running only during those hours. One severity definition is deliberately unusual: a deployment serving traffic happily but no longer recording it is an S1 here, because the product exists to produce that record. Most agreements would call it an S3. The published support document is a template, so where a signed agreement states different figures, that agreement governs rather than this page.
What does procurement need to know about data processing?
Token Observe’s runtime creates no vendor-side copy of anything, and the licence carries that as an undertaking: no functionality transmits usage data, configuration, prompts, model responses or records to the vendor, and there is no hosted component operated by the vendor. The consequence procurement cares about is that, in the ordinary course of supplying the software, there is no vendor processor or sub-processor path to paper — you are the controller, and your contracts with your model providers continue to govern what those providers do. Three qualifications belong beside it. No claim is made that the vendor is legally never a processor, because evaluation terms, support access and incident handling are counsel’s analysis rather than an engineering fact. Anything you choose to send in a support ticket is the exception, so redact it first. And your records may be retained, exported and used indefinitely, including after termination.
What do we have to accept in writing before running a pilot?
Token Observe’s own release gate names four residual risks that a pilot has to accept in writing at minimum: single-node SQLite, no vendor-operated SLA, no independent certification, and the preview limitations on endpoint seats. The threat model goes further and assigns each remaining risk to the role that must record a dated acceptance — the CISO for heuristic injection detection, for the audit chain being tamper-evident rather than tamper-proof, for the unauthenticated on-behalf-of header, for identity-provider group claims being a snapshot rather than a live directory read, for the absence of MFA on local accounts, and for long-lived agent bearer tokens; the data protection officer for the limits of regex personal-data detection; the head of product for provider data-policy flags being unverified operator assertions; and the engineering lead for single-writer SQLite. An empty field is a failed gate rather than a footnote, and anything not on that list and not mitigated is treated as an unrecorded gap, which is itself a finding.