1. Who we are and what these Terms cover
Actual Armor is operated by Tuluko Group OÜ (Estonian Commercial Register code 14335661, Tuukri tn 19-315, 10120 Tallinn, Estonia), the operating entity of every direction of Actual Armor Group (Actual Armor, Actual Armor Enterprise, Reputation Tower and 4S8). These Terms are a binding agreement between you and Tuluko Group OÜ (“we”, “us”). Actual Armor turns public information into structured, source-linked investigation briefs: guided workflows for due diligence, public footprint and open-source research, built for analysts, researchers and risk teams.
The directions of Actual Armor Groupshare one engine, one platform, one billing model and one set of legal documents. The Terms you read on another direction’s site are the same Terms with that direction’s name, domains and contact details.
2. Definitions
- Solution — a packaged workflow on the Platform that takes an input and returns a Result. An Open solution runs fully automatically in the application. A Core solution is a service delivered by our back-office team of people and agents on your order (Section 6).
- Run — one execution of a Solution, agent, workflow or multi-agent system, however it was started: manually, by a schedule, through our API or MCP endpoint, or through a shared asset.
- Credits — the unit of consumption on the Platform, shown as a balance on your account. Purchased credits are bought by top-up. Bonus credits are granted at our discretion and have no monetary value. Consumed credits have been used by a Run or a Core order and are final.
- Your Assets — everything you create or configure on the Platform: agents, multi-agent systems, prompts, knowledge bases, workflows, connector and MCP configurations, schedules, chats.
- Your Content — files, text, URLs, subjects and other material you upload, enter or point the Platform at.
- Results — what a Run produces: reports, briefs, dashboards, tables, generative-UI artefacts, exports in HTML, PDF or other formats.
- Connectors — the tools a Run can switch on to reach outside the Platform: web search and retrieval, social-platform connectors, official and open registries, legal and court corpora, third-party data services, and MCP servers, whether provided by us or connected by you.
- Artifact — a Result or file kept on your account: an HTML page, image, video or document generated in a chat, or a file you uploaded. Every Artifact has a persistent identifier.
- Share — making an Artifact, a chat or an Asset (an agent, workflow or MCP configuration) available to other signed-in users of the Platform through its link.
3. Accounts and eligibility
You must be at least 18 years old and able to enter a binding contract. If you use the Platform for an organisation, you confirm that you are authorised to bind it, and “you” includes that organisation. You are responsible for your credentials and for every Run, order, Share and deletion made under your account, including those made through the API, the MCP endpoint or a schedule you configured.
Creating an account means accepting these Terms, the Privacy Policy and the Acceptable Use Policy. It does not mean consenting to marketing: product news and offers are sent only if you opt in separately, and you can opt out at any time.
4. The Platform as infrastructure
We provide the engine, the Solutions, the Connectors we host, the billing and the infrastructure the Platform runs on. Within the Open surfaces of the Platform you decide what to build, what data to bring, which sources and Connectors to switch on, whom to share a Result with, and when to delete it. We host, run, meter and secure that. The relationship is the one a cloud or workflow service has with its tenant, and these Terms follow from it:
- We do not review or approve Your Assets, Your Content or your Runs before they execute.
- We may inspect, restrict or remove Assets, Results, Shares or Runs when we have reason to believe they breach these Terms, the Acceptable Use Policy, the law, or the Platform’s safety limits, and we may preserve evidence of that.
- You are the controller of the personal data you process on the Platform about other people; we process it on your instructions (Section 9 and the Privacy Policy).
- Core solutions (Section 6) and on-premise deployments are governed by these Terms plus the order or the deployment contract; where they conflict, the order or contract prevails for that engagement.
5. Credits, top-ups and billing
5.1 Top-ups
You top up your balance through Stripe. Payments are processed in EUR (or as displayed at checkout). We do not store card data; it is stored and tokenised by Stripe (PCI DSS Level 1). Current packages and rates are shown at actualarmor.com/pricing and in the application, and may change more often than these Terms.
5.2 Credits become tokens
Credits are converted, when a Run happens, into the tokens and calls that Run consumes: inference across the model providers the Platform routes to (including OpenAI, Google Gemini, Anthropic Claude, xAI Grok and others as we add them), and every Connector the Run switches on, from social-platform connectors and open and official registries to legal and court corpora, web retrieval and third-party data services. The rate per provider and per Connector is shown in the application. Every Run shows what it consumed, and every deduction is a transaction you can see in your account.
5.3 What consumes credits
Any Run you start or have configured: a workflow run, a manual run of an agent or a multi-agent system, a scheduled run, a run started through our API or MCP endpoint, and a run started from an Asset you shared when it executes on your account. Runs started by your schedules and integrations are your Runs and are billed to your account. Credits are also consumed by Core orders (Section 6).
5.4 Bonus credits
- granted at our discretion, for onboarding or promotions;
- no monetary value, not refundable, not transferable;
- may be time-limited, revoked or changed.
5.5 Refunds
Refunds are available only for unused purchased credits, requested within 14 days of purchase. Consumed credits, including credits deducted for a delivered Core order, are final and cannot be reversed, reissued or exchanged for cash. Refunds may be reduced to account for chargebacks, fees or confirmed abuse, and may be refused in cases of fraud, abuse or breach of these Terms.
5.6 Limits
We may apply rate limits, schedule limits, concurrency limits and Connector quotas per account or per plan to keep the Platform stable and costs predictable. Limits are shown in the application where they apply.
6. Core solutions ordered through the Platform
Some Solutions are delivered by our back-office, where people and agents work together and where you have no access. The flow is:
- You top up and place a Core order in the application. The order states the price or the basis on which the price is set before you confirm.
- The back-office delivers the Result to you in the form the order states — by e-mail, as a presentation, in the application, or in another agreed form.
- After delivery the person responsible for your engagement deducts the agreed amount of credits from your balance. You are notified of the deduction. A deduction never exceeds what the order stated without a new confirmation from you.
A Core order is a contract for services. The Result of a Core solution is subject to Sections 10 and 11 in the same way as an automated Result. Where an order needs a data processing agreement, we sign one on request before the work starts.
7. What you build on the Platform
The Platform lets you create agents and multi-agent systems, write prompts and instructions, build node-based workflows (including steps that call external URLs, run code, or apply templates), attach knowledge bases, connect Connectors and MCP servers, and set schedules. Your Assets are yours (Section 14). Because we did not write them:
- you are responsible for what your Assets do, for the instructions you give them, for the URLs and services they call, and for the Results they produce;
- a workflow or agent that reaches an external service does so on your behalf, under your authority and under that service’s terms;
- a schedule is a series of bounded Runs you configured; it is billed per Run, and you can pause or cancel it at any time. The Platform does not offer continuous monitoring, and a schedule is not one;
- you can share an agent, workflow or MCP configuration with other signed-in users and withdraw or delete it whenever you choose; a shared Asset runs on the recipient’s account and credits (Section 12).
8. Connectors, integrations, API and MCP access
Connectors reach third-party services and sources — social platforms such as LinkedIn and YouTube, official and open registries, legal and court corpora, data providers, and MCP servers you bring yourself. Those services keep their own terms and their own limits. Switching a Connector on is your decision to use that service under those terms. You confirm that you have the rights and, for personal data, the lawful basis for what a Connector collects on your instruction, and you will not use a Connector to circumvent a platform’s terms, access controls or rate limits.
We may add, change, suspend or withdraw Connectors, sources and model providers at any time, including when a provider changes its terms or when a source proves unreliable. Coverage of any source is never complete, and we do not warrant that a Connector returns everything a source holds.
Access through our API or MCP endpoint uses your credentials, produces your Runs and is billed to your account. The Acceptable Use Policy and the limits in Section 5.6 apply in the same way as in the application. Keep your keys secret; rotate them if they leak.
9. Data you bring to the Platform
Much of what the Platform does is reading and reasoning over public information about people, companies and narratives. When you upload material, name a subject, or point a Run at a source, you are the controller of the personal data involved and we are your processor. That means:
- you must have a lawful basis and a legitimate purpose for the processing, and you must honour the rights of the people concerned;
- you must not bring special-category data (health, biometrics, sexual orientation, religion, political opinion, union membership, criminal history) about identified people to the Platform unless the law permits it and you have the safeguards it requires;
- you must not use real people’s data to test Assets when synthetic data would do;
- if a person named in your Result asks us about it, we will forward the request to you and expect you to answer it as the controller (Privacy Policy, “If you appear in someone’s result”).
Lookups in court and legal registries by a private individual’s name pass through a human gate on the Platform; lookups by company do not. The Acceptable Use Policy sets the boundary.
10. Results and the output notice
Every Result carries a notice stating that it was prepared with AI from publicly available sources, including international open sources and registries, as of a date; that the AI systems, multi-agent systems and Connectors used can make mistakes; and that the Result is decision support, not a decision and not legal, financial or compliance advice. Where a Run used material you supplied, the notice says so. Exports and shared Results additionally carry the Result identifier, the Solution and its version, the period of the sources and the source list. You agree not to remove or obscure this notice, and not to present a Result as something other than an AI-assisted analysis of the stated sources.
Results describe signals and evidence with a confidence level (High, Medium, Low) and describe allegations as allegations. A signal is not a verdict; a mention is not guilt. “No signals found in public scope” is not a clearance. The Platform does not provide KYC approval, AML or sanctions clearance, fraud or authenticity verdicts, legal or compliance determinations, complete background checks, private-data access, or continuous surveillance.
A Result is your analysis produced on our infrastructure. It is not an audit, certification, investigation report or finding of Tuluko Group OÜ or of any AA Group direction, and you may not present it as one. Where a Run used material you supplied, the notice separates it from what came from public sources, so that a reader can tell a claim you brought from a signal the Platform found. Every exported or shared Result carries a Result identifier and an integrity record; anyone who receives a Result can ask us to confirm that it was produced on the Platform, by which Solution and when, and whether it has been altered since. A Result that has been edited outside the Platform is no longer a Result of the Platform.
11. AI outputs can be wrong
- Results are produced by AI models and by our own multi-agent systems, tools and Connectors. Any of them can be wrong: an invented fact, a mistaken identity between people or companies with similar names, stale data, a missed source, a misread document.
- You must verify a Result against primary sources before relying on it, and you must not treat a Result as the sole basis for a decision that affects a person — employment, credit, insurance, housing, education, access to services, legal action, publication.
- Where a Result contributes to a decision about a person, a human reviews it, and the person is told that AI-assisted analysis was used where the law requires it.
- Results are not legal, financial, medical, tax or compliance advice.
- We do not warrant completeness of coverage; an absence of signals is not a clearance.
12. Sharing artifacts and chats
Every Artifact is either Private or Public, and you switch between the two at any time.
- Private: only you can open it, inside your account. New Artifacts are Private unless you change them.
- Public: any user who is signed in to the Platform and has the Artifact’s link can open, view and download it. “Public” means public to the Platform’s users, not to the open internet: the link does not work for anonymous visitors, and we do not list Public Artifacts in a directory or submit them to search engines.
- Sharing a chat exports the conversation to a link: whoever opens it sees the conversation as exported, including your prompts, the responses and the Artifacts in it. Share a chat only when you are content for its prompts to be read.
- Switching an Artifact back to Private ends access for everyone else immediately; deleting it removes the link. Copies that someone has already downloaded are outside our control.
- Sharing does not change ownership. Every Share ends when the object, the chat, or your account is deleted.
- Each Artifact carries a change record — created, updated, made Public or Private, downloaded, deleted; by which account and when — which we keep for verification (Section 10), disputes and the Acceptable Use Policy.
- An Artifact generated as an HTML page may load fonts, scripts or images from third-party servers when it is opened; those servers see the viewer’s request. Artifacts are rendered in an isolated context, and code in an Artifact must comply with the Acceptable Use Policy.
- Sharing an Asset— an agent, a workflow or an MCP configuration — lets other signed-in users see and run it. A shared Asset runs on the recipient’s account and credits; the recipient does not receive your credentials, Connector secrets or the content of your chats. You can stop sharing or delete the Asset at any moment, and every copy running from your share stops with it.
- Exports. Where the Platform offers an export (HTML today, PDF and other formats as they are added), the export is a snapshot of the Artifact at that moment and carries the output notice and the Artifact identifier (Section 10).
- You are the publisher of what you share, including toward the people named in it. A Result you send outside the Platform — by e-mail, in a publication, to a client — is your publication, and the Acceptable Use Policy applies to it.
13. Acceptable use
The Acceptable Use Policyis part of these Terms. In short: no surveillance, profiling or doxxing of private individuals; no stalking, harassment or intimidation; no bulk extraction of personal contact data; no scraping in breach of a platform’s terms; no disinformation, smear campaigns, defamation or impersonation; no suppression of lawful public-interest journalism; no unlawful discrimination or fully automated decisions about people; no sanctions or export-control evasion; no weapons, malware or unauthorised access; no child-safety violations; no circumvention of billing, limits or safety controls. High-risk uses — employment screening, credit and tenancy decisions, insurance, KYC and AML, litigation, journalism about identifiable people, reputation remediation, political analysis, security and defence — are permitted only as decision support with a human decision-maker and the safeguards the policy lists.
14. Ownership and licences
Yours. You keep every right you have in Your Content, Your Assets and your Results. We claim no ownership. You grant us a non-exclusive, worldwide, royalty-free licence to store, process, run, cache, back up and transmit them as needed to provide the Platform to you and to those you share with, and to inspect them where Section 4 allows. The licence ends when the material is deleted, except for copies in backups for the period stated in the Privacy Policy.
Ours.The Platform, the engine, the Solutions we wrote, the Connectors we host, the methodology, the models of the user interface and the brands are ours or our licensors’. You get a limited, non-exclusive, non-transferable, revocable licence to use them under these Terms. You may not extract our prompts, routes or methodology parameters, reverse-engineer the Platform, or use Results at scale to build a competing service.
Feedback you give us about the Platform may be used without obligation to you. Your Content and Results are not used to trainour models or our providers’ models; the Privacy Policy describes the terms under which model providers process them.
15. Export, deletion and retention
You can delete what you built at three levels, in the application and without a support ticket, where the Platform offers it:
- an object — an Artifact, chat, agent, workflow, MCP configuration or schedule — is removed from your workspace immediately, a schedule stops at once, its Public link and any chat export link stop working, and it is purged from backups within 30 days;
- all your content — everything you own, in one action, with the same effect;
- your account — you can export your data first; deletion starts a 14-day grace period during which you can cancel it; after that the account, all Artifacts and chats (Public ones included), Shares and Connector tokens are erased, and backups are purged within a further 30 days.
What survives deletion is what the law requires us to keep: the credit ledger, invoices and payment records for 7 years, security logs for up to 12 months, and the metadata of Runs needed for billing disputes and abuse investigation (what ran, when, how much it consumed — not the content) for 24 months. The Privacy Policy carries the full schedule. On-premise deployments are deleted by the client; we hold nothing.
16. Suspension and termination
You may stop using the Platform and delete your account at any time (Section 15). We may suspend or restrict Runs, Shares, Assets or accounts, or terminate an account, where we reasonably believe these Terms, the Acceptable Use Policy or the law are being breached, where a payment is reversed, or where security or the stability of the Platform requires it. Where lawful, we tell you why. On termination, unused purchased credits may be refunded under Section 5.5 subject to verification; bonus credits are forfeited; Sections 10, 11, 14, 17, 18 and 20 survive.
17. Disclaimers
The Platform is provided “as is” and “as available”. To the extent the law allows, we give no warranty that the Platform will be uninterrupted or error-free, that any Connector, source or model provider will remain available, or that Results will be complete, accurate or fit for a particular purpose. Nothing on the Platform is legal, financial, medical, tax or compliance advice, and nothing in it establishes that a person or company is, or is not, involved in any conduct.
18. Liability and indemnity
To the maximum extent permitted by law, we are not liable for indirect, incidental, special, consequential or punitive damages, or for loss of profit, business, reputation or data, arising from your use of the Platform, from a Result, from a Share, or from a Connector or provider we do not control. Our total liability for all claims arising under these Terms in any 12-month period is limited to the amounts you paid us in the 12 months before the event giving rise to the claim. Nothing limits liability that cannot be limited by law, including for gross negligence, wilful misconduct, or mandatory consumer rights.
You will indemnify us against claims, damages and costs arising from Your Content, Your Assets, your Runs, your Shares, your use of Connectors, and any breach by you of these Terms, the Acceptable Use Policy or the law, including claims by people named in your Results.
19. Changes to these Terms
We may update these Terms. We post the new version here with a new “Last updated” date, and we announce material changes in the application or by e-mail at least 14 days before they take effect, unless a change is required by law or protects the Platform. Continued use after the effective date is acceptance; if you do not accept, delete your account before that date.
20. Governing law and disputes
These Terms are governed by the laws of Estonia and applicable EU law. Disputes are subject to the exclusive jurisdiction of the courts of Tallinn, Estonia, unless mandatory consumer law gives you the right to another forum. EU consumers may also use the European Commission’s online dispute resolution platform.
21. Contact
Tuluko Group OÜ
Registry code 14335661
Tuukri tn 19-315, 10120 Tallinn, Estonia
Legal matters: support@actualarmor.com
Privacy and data-subject requests: privacy@actualarmor.com
Website: actualarmor.com