questions

Licence, pricing and support, answered in full.

The source-available licence, how the product is metered, the thirty-day evaluation, the support model, and what procurement has to accept in writing.
Questions in this subject
6
Questions across the whole set
49
Subject, in the reading order
6/7
6 questions

Each answer stands on its own

Every answer here is written to be read without its question, without the paragraph before it and without the rest of the site, because the form it will most often be read in is somebody else's summary. Where there is a limit, it is in the same sentence as the claim rather than in a note underneath it.

How is Token Observe licensed?

Token Observe is published under a commercial source-available licence, version 1.0, from Tenhaw Ltd, registered in England and Wales and governed by the laws of England and Wales. Source-available rather than open source, and the harder of the two words is the accurate one. The rights below run for the subscription term of an order form stating the fees and the permitted scope of use; without one, a thirty-day evaluation grant applies instead. You may install, host and operate it on infrastructure you control; read, compile and modify the source and create derivative works for internal purposes, including to integrate it and to remediate defects; keep backup, disaster-recovery, development, testing, staging and training copies; and have contractors exercise those rights for you. You own the modifications you make and need not disclose them. You may not redistribute it, or provide it or a substantial part of its functionality to a third party as a hosted, managed or white-labelled service. Security research and publication of the results are expressly permitted. One caveat travels with all of it: the published licence is a template pending review by counsel, not an executed grant of rights.

How is Token Observe priced?

Token Observe has no public price list. An order form states the subscription term, the fees and the permitted scope of use — for example a number of deployments or agents. A deployment is one installation you operate on infrastructure you control, together with its non-production copies. An agent is one autonomous or semi-autonomous process registered in the agent registry that authenticates to the gateway with its own credential. Non-production copies — backup, disaster recovery, development, testing, staging and training — count towards neither figure provided they do not serve production traffic. Two consequences a procurement team should know. Compliance is self-certified: because the software reports nothing to the vendor there is no metering component, no inspection right and no records to hand over, only one written certification a year on thirty days’ notice. And the current commercial shape is a design-partner agreement rather than a standard subscription, because the release gates that would justify one are not yet closed.

Can we evaluate Token Observe before buying?

Yes. Token Observe carries a thirty-day evaluation grant, and it exists precisely so a prospective customer’s security team can read, run and attack the software before a purchase order is raised. Thirty days from first installation, for internal evaluation, security review and proof of concept, with no order form. The boundaries sit in the same clause: no live production traffic, no regulated personal data, and no support, warranty or SLA during it. Within that window, inspecting, testing, fuzzing, penetration-testing and reverse-engineering the software as deployed on infrastructure you control are expressly permitted, you may commission a third party to do it for you, and you may publish both performance results and security findings — no pre-approval of benchmark results provided the publication names the version and configuration tested, and coordinated disclosure for security findings. The vendor already publishes its own outstanding defects, so that clause is written to be consistent with the practice rather than to suppress yours.

What does support look like, and what is the SLA?

Token Observe carries no availability SLA and no service credits, and the reasoning is worth reading before accepting one from any self-hosted vendor. The vendor does not operate your deployment, cannot observe it and cannot restart it, so an uptime number would be unmeasurable by either side; no partner-shaped sustained-load result has been retained, so a capacity figure would be a guess wearing a number. What is committed is a first substantive response from a named human, not a resolution time: two business hours for S1 with updates every four, one business day for S2, three for S3 and five for S4, during 09:00 to 17:30 Europe/London, Monday to Friday, with no out-of-hours cover and the clock running only during those hours. One severity definition is deliberately unusual: a deployment serving traffic happily but no longer recording it is an S1 here, because the product exists to produce that record. Most agreements would call it an S3. The published support document is a template, so where a signed agreement states different figures, that agreement governs rather than this page.

What does procurement need to know about data processing?

Token Observe’s runtime creates no vendor-side copy of anything, and the licence carries that as an undertaking: no functionality transmits usage data, configuration, prompts, model responses or records to the vendor, and there is no hosted component operated by the vendor. The consequence procurement cares about is that, in the ordinary course of supplying the software, there is no vendor processor or sub-processor path to paper — you are the controller, and your contracts with your model providers continue to govern what those providers do. Three qualifications belong beside it. No claim is made that the vendor is legally never a processor, because evaluation terms, support access and incident handling are counsel’s analysis rather than an engineering fact. Anything you choose to send in a support ticket is the exception, so redact it first. And your records may be retained, exported and used indefinitely, including after termination.

What do we have to accept in writing before running a pilot?

Token Observe’s own release gate names four residual risks that a pilot has to accept in writing at minimum: single-node SQLite, no vendor-operated SLA, no independent certification, and the preview limitations on endpoint seats. The threat model goes further and assigns each remaining risk to the role that must record a dated acceptance — the CISO for heuristic injection detection, for the audit chain being tamper-evident rather than tamper-proof, for the unauthenticated on-behalf-of header, for identity-provider group claims being a snapshot rather than a live directory read, for the absence of MFA on local accounts, and for long-lived agent bearer tokens; the data protection officer for the limits of regex personal-data detection; the head of product for provider data-policy flags being unverified operator assertions; and the engineering lead for single-writer SQLite. An empty field is a failed gate rather than a footnote, and anything not on that list and not mitigated is treated as an unrecorded gap, which is itself a finding.

If the answer above is close but not quite the case you have, the specific version of it is a better question than the general one, and it gets a specific reply.

Ask the specific version
get in touch

Bring the question this page did not answer.

Write to hello@tenhaw.com with what your agents do, which providers they call and what would have to be true for you to put something in front of them. James Rooney replies. You will get a straight answer about whether Token Observe fits, including when it does not.

no form · no qualification step · no sales desk · the other three ways in