What you are metered on, and what you never are.
No per-token component, no seat count on agents, and no figures on this page yet.
On this page
Why this page has no numbers on it.
This page publishes the commercial model and publishes no prices, and the reason is worth saying plainly rather than hiding behind a contact form. The licence a figure would be quoted under is still a template: it says on its own first page that it must be reviewed and approved by qualified counsel in England and Wales before it is offered to or relied upon by any customer, that every square-bracketed placeholder must be completed, and that its liability cap must be checked against insurance cover and against each Order Form’s fee level. Counsel approval is the first item on the product’s own mandatory design-partner gate, and that gate has not passed. Publishing a price ahead of it would be a number set for a website rather than agreed against a scope — and this is a product whose documentation already declines to publish an uptime percentage or a capacity figure on precisely those grounds, so it would be a strange place to make an exception for the one number that binds a customer’s budget. What you get here is the whole shape of the deal: the meters, the ceilings, the entitled modules, the support severities and targets, the evaluation grant, and the limits stated beside each of them. The figures are one conversation away, and they arrive attached to the scope they were quoted for.
Four lines, and only one of them has a figure.
The one that does is the evaluation, and the figure is nothing.
Evaluation licence
No chargethirty days from first installation, with no Order Form and no signature
Who it is for. A security reviewer, platform engineer or assurance lead who wants to read the source, run it and attack it before anyone raises a purchase order.
Section 3 of the licence grants any person the right to install and operate Token Observe for internal evaluation, security review and proof-of-concept purposes for thirty days from first installation, at their own risk. The licence states why the clause exists rather than leaving it to be inferred: so that a prospective customer’s security team can read, run and attack the software before a purchase order is raised. That is also why section 9 sits outside the restrictions — inspecting, fuzzing and penetration-testing your own deployment is expressly permitted, and so is commissioning somebody else to do it for you. Token Observe has not itself had an independent penetration test, which its own security policy and its README both state plainly rather than leaving to be discovered; a pre-purchase test is the answer offered in place of a certificate nobody has yet earned.
- Every control the product has. No licence state gates the gateway, RBAC, redaction, injection heuristics, approvals, budgets, rate limits, the flight recorder, the audit chain or the kill switch, so an evaluation governs exactly as a paid deployment does. What runs is not the same as what is warranted: section 11.2 disclaims any warranty that the policy, redaction, injection-detection and routing controls identify every instance of what they are designed to detect, calls them heuristic, and points at the threat model and the defect list for how they fail. Spending the thirty days on their false negatives is the right use of them.
- The right to inspect, test, fuzz, penetration-test and reverse-engineer the deployment you are running, and to commission a third party to do it on your behalf.
- The right to publish what you measure. A benchmark may be published if it names the version tested and the configuration used, and no pre-approval is required; the findings of a security assessment may be published, naming the software, after the coordinated-disclosure process in the security policy. One drafting detail belongs beside that rather than under it: the inspection and testing right in section 9.1 expressly names both the Licensee and any person operating an evaluation, while the two publication rights are written as the Licensee’s, so an evaluator who intends to publish before an Order Form exists should have the point confirmed in writing. It is offered as intent, and it is exactly the kind of thing counsel’s review is for.
- The published defect list to read alongside it, which names files, states the concrete cost, describes the attacks that still work, and records findings that were refuted on verification as well as those that were confirmed.
- Live production traffic and regulated personal data. Both are outside the evaluation grant, in section 3.2’s own words. The readiness documentation points the same way from the other direction: the scope it says may be considered once the design-partner gate passes is explicitly non-production-critical. That scope is written as the shape of a pilot rather than as a rule about evaluations, but an evaluation run outside it is running ahead of anything the product claims for itself.
- Support, warranty and service levels. The evaluation carries no support commitment, no warranty and no service level of any kind, in those words.
- Any right to continue afterwards. The thirty days do not roll over and there is no automatic conversion; continuing needs an Order Form.
- Liability. Under an evaluation, Tenhaw’s aggregate liability is limited to what cannot lawfully be excluded, and no other liability is accepted.
Self-hosted deployment subscription
On applicationper deployment, per subscription term, with a licensed ceiling on simultaneously active agents
Who it is for. One platform team running roughly five to fifty API-key agents in its own VPC, against one or two model providers and a bounded set of pinned MCP tools — the scope the product’s own readiness documentation says may be considered once its mandatory design-partner gate passes, which it has not yet.
This is the line almost every buyer is asking about. A deployment is one installation operated on infrastructure you control; an agent is one autonomous or semi-autonomous software process registered in the agent registry that authenticates to the gateway with its own credential. The Order Form states the subscription term, the fees and the permitted scope of use, and those two counts are the scope. The ceiling on active agents binds in exactly two places — creating an agent that is already active, and the transition into active — so suspending, retiring or editing an agent is never refused on licence grounds, because the route back under a ceiling must never be the thing the ceiling blocks. Being over a ceiling is reported and audited rather than retroactively enforced, and deleting the licence file returns the install to an unlimited unlicensed fallback with every control still enforcing: what a licence buys you is unforgeable terms and a visible record, not a technical restraint.
- The right to install, host, execute and operate one deployment on infrastructure you control — your own data centres, your cloud accounts, and air-gapped environments.
- Source access. You may read, compile and modify the source and create derivative works for your internal business purposes, including integrating it with your own systems and remediating defects yourself; you own your separable modifications and are under no obligation to disclose them.
- A reasonable number of non-production copies for backup, disaster recovery, development, testing, staging and training, none of which count towards a deployment or agent limit provided they serve no production traffic.
- Updates during the subscription term: bug fixes, security patches and new versions made generally available to licensees, provided to the extent the Order Form and the support documentation state rather than as a standalone promise of the licence. The version policy that travels with them is pre-1.0 and says so: only the latest published minor is supported, there is no long-term-support branch and there is no backporting, so an upgrade is the first ask on a defect found on an older one.
- Every governance control, in every tier. Capacity and the breadth of evidence modules are what a tier can scale; whether the controls work is not in a licence’s vocabulary at all.
- A per-release CycloneDX SBOM, checksums and a changelog entry, so a supply-chain review has something to consume. The state of that is worth stating exactly: the release workflow producing them — immutable image digest, SBOM, provenance, signature, checksums and packaged backup and restore evidence — is encoded and gated in the repository, and running it on a real semver tag and retaining its evidence is itself an open item on the design-partner gate rather than something already behind the product.
- Model spend. You bring your own keys to OpenAI, Anthropic, Google, OpenRouter, Amazon Bedrock or Azure OpenAI and pay those providers directly; Token Observe never stands between you and that invoice, which is also why it cannot take a margin on it.
- Your infrastructure: hosts, containers, network, load balancers, TLS certificates, secret managers, DNS, disk and backups. Token Observe will help you read an error; it cannot fix your cluster.
- Model behaviour and provider incidents. Quality, accuracy, refusals, latency and the cost of the models themselves are the provider’s; typed failover and circuit breakers are what Token Observe offers in response, and configuring them is covered.
- Your agents’ own code. Reading a trace with you is covered, because a trace is usually the fastest way to see what an agent actually sent; debugging the framework and application code that calls the gateway is not.
- Any availability, response-time or performance commitment from the licence itself. Section 8.2 grants none, and says why: you operate the deployment, so its availability in production is a property of your environment.
- Providing Token Observe, or a substantial part of its functionality, to a third party as a hosted, managed, embedded or white-labelled service. Governing agents that act on behalf of your own customers, and showing the evidence to your own auditors and regulators, is expressly permitted.
Design-partner agreement
On applicationstated on one design-partner Order Form, alongside the term and the permitted scope
Who it is for. An organisation that wants a named engineer, written response targets and real influence over what gets built, and that is prepared to accept a pre-1.0 product’s residual risks in writing.
The support documentation states the reasoning rather than dressing it up: a design-partner agreement is the right shape at this stage of the product — a named engineer, direct access, roadmap influence and honest limits, rather than a support desk and a service-credit schedule that neither party believes in. It runs in both directions, and the reciprocal asks are published too. What is asked is a regular feedback session at the cadence in the signed agreement, reasonable redacted diagnostics when you raise an issue — version, configuration and the relevant trace ids, because the vendor’s default position is to receive nothing and a support ticket is the one place that changes by your choice — and sight of the findings of any penetration test you commission, through the process in the security policy, with your right to publish intact. A reference conversation or a named logo is welcome if and when you are happy to give one, and is never a precondition of support.
- A named engineer, reachable directly, who has read your deployment.
- The response targets below, written into the agreement rather than into a web page.
- Direct influence on the roadmap, with your blocking issues prioritised explicitly.
- Early access to fixes on a branch, ahead of a tagged release, where it unblocks you.
- Full visibility of the defect list, published rather than shared under NDA.
- A contractual commitment, with a named date, to any certification milestone your procurement process requires. None is held today and none is in progress; certification is deliberately not pursued speculatively, so the date comes from your requirement rather than from a roadmap slide.
- Service credits. There are none, because there is no availability SLA to credit against; the remedy for persistent failure to meet these targets is termination under the agreement, not a discount.
- Out-of-hours cover. Hours are 09:00 to 17:30 Europe/London, Monday to Friday, excluding public holidays in England and Wales, and the clock on every target runs only during them. If you need follow-the-sun cover, ask before signing — it is a resourcing question with an honest answer, not something to discover at 02:00.
- Anything already published as an outstanding known issue. Raising one as an S2 does not move it; telling Tenhaw that it is blocking you specifically does, and weighting that is what a design partnership is for.
- Modified deployments, to the extent an issue arises from the modification. The licence permits you to modify the source and you are encouraged to; reproducing on an unmodified build is simply the first ask.
- Data recovery. If the database file is lost and there is no backup, the traces and the audit chain are gone — there is no vendor-side copy, and it cuts both ways. That absence is what the no-processor position rests on, and the product’s own readiness documentation is careful not to overclaim it: runtime phone-home is zero, but evaluation terms, support handling and anything you choose to put in a diagnostic bundle are contracts rather than architecture, so counsel decides whether a data-processing agreement is needed and one should be executed before personal data is disclosed that way.
Policy and control-framework engagement
On applicationquoted per engagement, against a written scope
Who it is for. A team that wants its policy set authored and mapped onto its own control framework, rather than writing it from templates and backtesting it alone.
The boundary here is drawn in the support documentation rather than discovered in a ticket, which is the only time it matters. Policy design guidance, template review and questions about whether a rule is expressible at all are covered by support. Authoring your policy set, mapping it onto your control framework, or acting as your compliance function is a professional-services engagement rather than support, and is therefore quoted separately. The status of this line deserves the same precision as the line itself: the documentation draws it as the outer edge of what support covers and nowhere describes a services offering behind it, so there is no published scope, no rate card and no delivery model yet — what exists is the statement that this work is not bundled into a subscription, and a conversation about what you actually need. The distinction is worth being precise about, because this is exactly where a governance product usually gets sold as a compliance outcome: Token Observe is a compensating control, it produces evidence, and it does not discharge an obligation you owe to a regulator, a data subject or a customer.
- Authoring your policy set, including the shadow-mode backtest of the exact policy digest that the product can be configured to require a named person to acknowledge before a policy is promoted from shadow to enforcing — a configuration the design-partner gate makes mandatory in a partner environment, rather than a behaviour that is simply on everywhere.
- Mapping that policy set onto your own control framework, and onto the EU AI Act, ISO/IEC 42001, NIST AI RMF and OWASP mappings the product documents.
- Work of the kind support excludes rather than covers: authoring rather than reviewing, mapping rather than advising. The support documentation puts standing in as your compliance function on the same side of that line, but nothing published describes such an engagement or what it would deliver, and it would still produce no attestation and no sign-off — so treat it as a conversation to have rather than a service to assume.
- Compliance sign-off. Tenhaw does not sign off your DPIA, FRIA, ROPA or risk register, and no engagement changes that.
- Certification of any kind. There is no SOC 2, no ISO 27001, no ISO 42001 and no independent penetration-test result today; an engagement produces a policy set and a mapping, not an attestation.
- Chasing down the agents the shadow-AI radar finds. The radar tells you that ungoverned agents exist; bringing them inside your organisation is your work.
The variables a quotation is actually built from.
Published so an approval paper can be drafted before the quotation arrives, and so the eventual number is checkable rather than assertable.
- Deployments
- One deployment is one installation operated on infrastructure you control, together with the non-production copies the licence permits. Backup, disaster recovery, development, testing, staging and training copies count towards nothing as long as they serve no production traffic, so a second line is only reached when you genuinely run a second production installation — a separate region, a regulated subsidiary, an air-gapped estate that cannot reach the first.
- Simultaneously active agents
- The registry ceiling is on agents in the active lifecycle state, not on agents that exist. Draft, suspended and retired records consume no licensed capacity, which is what makes the ceiling safe to set close to reality: the remedy for being over it is to suspend or retire something, and neither action is ever refused on licence grounds. An install that drops from fifty licensed agents to ten keeps running all fifty and reports as over-ceiling rather than silently losing forty. The ceiling also binds only on control-plane writes made by an authenticated human, and never on the governed request path: a gateway that refused live agent traffic over a licence count would take a fleet down for a commercial reason, which is the one failure mode a governance product cannot have.
- Entitled evidence modules
- A licence can name three modules and only three: scheduled pull connectors, where Token Observe holds an organisation-admin credential into a vendor system and fetches evidence on a timer; push receivers, the inbound credentials your own exporter or SIEM presents; and seat governance, the subscription-seat registry and its census. Every one of them is a place where Token Observe holds a credential into somebody else’s system or accepts a feed from one, which is where the cost and the blast radius both sit. Nothing that enforces is on that list, by construction.
- Subscription seats
- A licence carries a second ceiling for managed developer devices — a Claude Code, Codex or Copilot subscription governed by a signed, fail-closed bundle pushed to the machine, because the vendor credential is one Token Observe never issued and the endpoint hook is the only real enforcement point. This surface is preview, and it should be scoped rather than assumed: the product’s own readiness documentation says to treat it as preview, and a deployment with active seats always reports a technical blocker because the seat hook is marked not production-eligible. Ask what it does today before it appears on an Order Form.
- Subscription term
- The signed licence carries an issue date and an expiry, and expiry is a hard wall in one direction only: additions are refused and named, while nothing already running is touched. Agents keep serving, seats keep receiving bundles, connectors keep fetching and evidence keeps landing. A longer term is therefore a commercial conversation rather than a risk one, because the failure mode of a lapse is a refusal to grow, not an outage.
- The support relationship
- A design-partner agreement — a named engineer, the response targets in writing, roadmap influence, early access to fixes on a branch — is a different commitment from a licence with no support attached, and it is priced as one. What it cannot become at any price today is an availability commitment; the reasons are below, and they are structural rather than negotiable.
- Work that is not support
- Authoring your policy set, mapping it to your control framework, or acting as your compliance function is a professional-services engagement rather than something bundled into a subscription. So is any certification milestone your procurement requires: it can be committed to contractually with a named date, and that date has a cost, because certification is not being pursued speculatively in the hope that somebody will eventually ask.
Send the shape of your estate — how many deployments, roughly how many agents active at once, which providers — and the quotation comes back against exactly the definitions above.
Ask for a figureThirty days, no signature, and permission to attack it.
An evaluation costs nothing and needs no signature: section 3 of the licence lets any person install and operate Token Observe for internal evaluation, security review and proof-of-concept purposes for thirty days from first installation, at their own risk. The clause exists so that a prospective customer’s security team can read, run and attack the software before a purchase order is raised, and the rest of the licence is written to make that possible rather than to make it awkward.
- 01Thirty days from first installation. It does not roll over and there is no automatic conversion; continuing to use the software afterwards needs an Order Form.
- 02No live production traffic and no regulated personal data. That is the boundary of the grant, in section 3.2’s own words. It points the same way as the scope the readiness documentation says may be considered once the design-partner gate passes: one self-hosted install, a bounded set of agents owned by one platform team, shadow policies before enforcement, and nothing whose outage would harm customers or regulated operations. That scope is written as the shape of a pilot rather than as a rule about evaluations, but an evaluation outside it is running ahead of anything the product claims for itself.
- 03No support commitment, no warranty and no service level of any kind. Under an evaluation, Tenhaw’s aggregate liability is limited to what cannot lawfully be excluded and no other liability is accepted.
- 04You may inspect, test, fuzz, penetration-test and reverse-engineer the deployment you are running, and commission a third party to do it for you. Nothing in the restrictions section limits that, and there is no gag clause and no pre-approval of results.
- 05You may publish benchmarks, provided the publication identifies the version tested and the configuration used, and you may publish the findings of a security assessment and name the software after the coordinated-disclosure process in the security policy. Both are drafted as the Licensee’s rights, while the inspection and testing right in the clause above expressly names evaluators as well, so if you intend to publish before an Order Form exists, ask for that in writing rather than reading it across.
- 06Every control runs. A licence gates capacity and the breadth of evidence modules, never enforcement, so the gateway, RBAC, redaction, injection heuristics, approvals, budgets, rate limits, the flight recorder, the audit chain and the kill switch all behave in an evaluation exactly as they would under a paid subscription. What none of that promises is that they catch everything: the licence disclaims exactly that, calling the policy, redaction, injection-detection and routing controls heuristic and pointing at the threat model and the defect list for how they fail.
- 07The software sits inline and fails closed, so an evaluation belongs somewhere an outage is survivable. That is the design — a control you can bypass by turning it off is not a control — and the licence puts it in writing that you had the chance to evaluate it before purchase.
- 08Start with the published defect list rather than finding it later. It names the attacks that still work, the concrete cost of each gap, and the findings that were refuted on verification; if what you find is not on it, it is genuinely not known.
- Use, modify and self-host under a licence
- Read the entire governance domain before buying: the core package is pure functions with zero runtime dependencies
- Security research, and publication of the results, with no gag clause and no pre-approval
- Redistribution
- Offering Token Observe as a competing hosted service
The published licence is a template pending review by counsel rather than legal advice, and the final terms are the ones in your signed agreement.
Response targets, not resolution targets.
Token Observe is self-hosted, and that single fact decides what can honestly be committed to. Tenhaw can commit to responding, to diagnosing, and to fixing defects in the software; it cannot commit to the availability of your deployment, because it does not run it, cannot observe it and cannot restart it. Diagnosis depends on what you choose to share, since there is no access to your logs, your database or your traces unless you send them. The targets below are targets for a first substantive response — a named human engaging with the problem, not an automated acknowledgement — and they are response targets rather than resolution targets, because nobody can honestly commit to a fix time for a defect that has not yet been diagnosed. Severity is proposed by you and confirmed by Tenhaw; where the two disagree, the higher severity applies until the disagreement is resolved, and the resolution is written down. The clock runs during hours of cover only, so an S1 raised at 16:00 on a Friday has its two-hour target met by 11:00 on Monday. Security vulnerabilities do not use this path at all — they follow the faster, separate timetable in the security policy, where the patch target for a critical finding is seven calendar days measured from the triage verdict rather than from your report, and where the policy is careful to call its stages targets for a small team rather than a contractual service level. Read the table below with one thing the support documentation says before it: these severities and targets are the terms offered as a starting point, and what binds is what a signed agreement writes down, which takes precedence over the published document.
Production agent traffic is stopped, or a governance control has failed in a way that lets ungoverned or unrecorded traffic through, and there is no workaround. The second half is the unusual one and it is deliberate: a deployment serving traffic happily while it has stopped recording it is an S1 here, because the product exists to produce that record, and most support agreements would call it an S3.
First response within 2 business hours, an update every 4 business hours until it is downgraded, a same-business-day workaround where one exists, and a patch release as soon as a fix is validated — with no fixed date promised, because a date given before diagnosis is fiction.
A major function is broken or materially degraded in production, or a control is unreliable, but a workaround exists. One provider’s route failing consistently while failover masks it; a policy that fires on one provider dialect and not another; approvals that can be created but not decided; redaction missing a kind it is configured to catch.
First response within 1 business day, daily updates, a workaround targeted within 5 business days, and a fix in the next scheduled release.
A function is broken or incorrect with a straightforward workaround, or the impact is confined to non-production. A report column showing the wrong figure, a panel rendering incorrectly, a malformed CSV export, a migration warning on a staging restore.
First response within 3 business days, weekly updates, and a fix in the next scheduled release or a place in the backlog with the reason given.
A question, a documentation issue, a cosmetic defect or a feature request. Whether a policy is expressed the right way; a wrong link in the documentation; a confusing error message.
First response within 5 business days, then the backlog, with no commitment attached.
There is no availability SLA.
There is no availability SLA, no uptime percentage and no service credits, and the three reasons are published in order of weight rather than buried. First, Tenhaw does not operate your deployment: you control the host, the network, the TLS terminator, the disk and the restart policy, and an uptime number from a party with access to none of those, receiving no telemetry from them, would be unmeasurable by either side. Second, no retained partner-shaped sustained-load result exists — a bounded mixed-journey soak harness exercises allow, block, approval and read paths, and the older laboratory throughput probe establishes an order of magnitude for a loopback mock-provider path, but the evidence a commitment would need is a retained multi-hour run against your corpus, your concurrency, your policies and your provider latency, with an agreed degradation curve. Third, recovery automation exists while partner RPO and RTO proof does not: the release workflow boots the packaged image, takes and restores a live backup and checks the restored chain against externally retained values, and recovery is SQLite full-snapshot restore rather than point-in-time recovery, with backup scheduling, off-box placement, retention and freshness alerting all operator-owned. Two consequences belong in the same breath, because they are load-bearing for anyone assessing this risk: Token Observe is deliberately in the request path and fails closed, so if it is down, governed agents cannot call models — a control you can bypass by turning it off is not a control — and it is a single-writer process on one node by design at this scale, with no replica, no clustering and no high-availability story. An availability or performance commitment becomes possible once the partner-shaped load and recovery results are retained and approved. Until then no number is offered, rather than a number nobody could stand behind. Ask for the date; it is a fair thing to put in an agreement.
What a budget holder needs that is not on this page.
A figure, and the scope it was quoted against. Write to hello@tenhaw.com with how many deployments you would run, roughly how many agents would be licensed active at once, and which providers they call. If procurement needs the assurance material in parallel, the security page and the compliance mappings answer most of a standard questionnaire without a call.
What does Token Observe cost?
No figure is published yet, and that is a deliberate position rather than a sales tactic. The licence a price would be quoted under is still marked as a template requiring approval by qualified counsel in England and Wales, with every square-bracketed placeholder completed and its liability cap checked against insurance cover and against each Order Form’s fee level; counsel approval is item 1 of the product’s mandatory design-partner gate and it has not passed. What is fixed already is what you would be quoted on: a subscription to one self-hosted deployment, a ceiling on simultaneously active agents, an optional design-partner support agreement, and any professional-services work that falls outside support. Ask, and the number arrives attached to the scope it was quoted for.
Why is there no per-token, per-request or usage-based price?
Because there is nothing to meter. Token Observe runs in your network on your own provider keys, so every token you spend is billed by OpenAI, Anthropic, Google, OpenRouter, Amazon Bedrock or Azure OpenAI directly to you, and Token Observe never sits between you and that invoice. The licence goes further and undertakes that the software as distributed transmits no usage data, configuration, prompts, model responses or records to Tenhaw at all: no phone-home, no licence-check callback, no analytics beacon and no hosted component. The consequence is stated in the licence itself — with no visibility of your usage, Tenhaw relies on your own records, and the entirety of its verification right is a written certification by an authorised officer, no more than once in any twelve months and on at least thirty days’ notice, of the number of deployments and agents in use. There is no right to inspect your systems and no right to install a metering component.
What counts as an agent for licensing, and what happens if we exceed the ceiling?
An agent is one autonomous or semi-autonomous software process registered in the agent registry that authenticates to the gateway with its own credential, and the ceiling counts only those in the active lifecycle state. Draft, suspended and retired records consume no capacity. Exceeding the ceiling refuses the two actions that would take more capacity — creating an already-active agent, and transitioning one into active — with a typed error naming the reason, and files an audit row for every refusal. Nothing already running is touched, because a limit that could reduce a governed estate to an ungoverned one would be worse than no limit. Being over a ceiling is reported and audited rather than retroactively enforced, and that record is what a true-up conversation is argued from.
What happens if the licence expires, or if we never install one?
Every control keeps enforcing, in both cases. The gateway, RBAC, redaction, injection heuristics, approvals, budgets, rate limits, the flight recorder, the audit chain and the kill switch are present in every tier and cannot be entitled at all, so no licence state — valid, expired, forged or absent — can remove one. An expired licence is still a genuine statement of what you bought: its terms stay in force, agents keep serving, seats keep receiving bundles, connectors keep fetching, and what stops is buying more, refused with a typed code such as ACP_LICENCE_EXPIRED, ACP_LICENCE_CAPACITY_EXCEEDED or ACP_MODULE_NOT_ENTITLED. A forged or unreadable file grants nothing and constrains nothing, leaving the install in the unlicensed fallback, which is unlimited and is reported loudly as the fallback. This is honest about what it is: a contract mechanism producing evidence, not copy protection. Deleting the licence file is the whole bypass, and the product says so rather than implying otherwise, because a licence problem that degraded a customer’s safety controls is the one failure mode a governance product cannot have.
Is there an uptime SLA, and what do we get instead?
There is none, and none should be accepted from any self-hosted vendor without asking what it could possibly mean. Tenhaw does not operate your deployment, receives no telemetry from it and cannot restart it, so an uptime number would be unmeasurable by either side; beyond that, no retained partner-shaped sustained-load result and no timed partner-sized restore drill exist yet, and publishing a capacity figure before they do would be a guess wearing a number. What is offered instead, and written into a signed design-partner agreement rather than left to bind itself from a web page, is a first substantive response by a named human — two business hours for an S1, one business day for an S2, three for an S3, five for an S4 — with an update cadence on S1 and S2 so you are never left wondering. There are no service credits because there is no availability SLA to credit against; the remedy for persistent failure to meet the targets is termination under the agreement rather than a discount. An availability commitment becomes possible once the load and recovery evidence is retained and approved, and asking for that date is a fair thing to put in an agreement.
Can our security team test it before we buy anything?
Yes, and the licence is written for exactly that. The thirty-day evaluation grant lets any person install and run Token Observe for security review with no Order Form and no fee, and section 9 puts inspection, testing, fuzzing, penetration-testing and reverse-engineering of your own deployment outside the restrictions, including work you commission from a third party. Benchmarks may be published if they name the version and configuration; security findings may be published, naming the software, after coordinated disclosure. There is no gag clause and no pre-approval of results. Read that alongside the two things stated first rather than last: Token Observe has had no independent penetration test, and it holds no SOC 2, ISO 27001 or ISO 42001 certification. The published defect list, threat model and data-flow document are what stand in their place, and a pre-purchase test is welcome.
What happens to our evidence when a subscription ends?
You keep it, indefinitely, and the licence says so explicitly. Within thirty days of expiry or termination you must cease use, uninstall every deployment and destroy your copies of the software — but that obligation expressly does not reach your records: the traces, trace events, audit-log entries, approvals, policies, registry records, cost-ledger entries and exports the software generated in your own database. The reasoning is written into the clause: the product is bought precisely to produce that evidence, and losing it at the end of a subscription would defeat the purpose. It also means the retention is yours to run. There is no vendor-side copy of anything, which is what the no-processor position rests on — though the readiness documentation stops short of claiming the vendor is legally never a processor, because evaluation terms, support handling and anything you choose to send in a ticket are contracts rather than architecture, and counsel has still to rule on them. It also means that if the database file is lost and there is no backup, the traces and the audit chain are gone, and that backup scheduling, off-box placement, retention and freshness alerting are yours to own. Back it up like evidence.
Is the licence ready to sign today?
Not yet, and it says so on its own first page rather than in a footnote. It was drafted by the engineering team so that a customer’s procurement and legal teams have a concrete starting point instead of the word UNLICENSED and no file at all, and it must be reviewed and approved by qualified counsel in England and Wales, have every square-bracketed placeholder completed, have its liability cap checked against insurance cover and each Order Form’s fee level, and have its interaction with any master agreement, data-processing agreement or security schedule confirmed. Until that review completes it is a statement of intended commercial terms, not an executed grant of rights. The terms it intends are the ones set out on this page, and reading them now is the point: procurement can raise its objections against a document that exists rather than waiting for one that does not.
Ask for the figure, and the scope it is quoted against.
Send the shape of the estate — deployments, agents active at once, providers, and whether you need evidence modules beyond the defaults. The quotation comes back against exactly the definitions on this page, and the evaluation does not wait for it.
no form · no qualification step · no sales desk · the other three ways in