Terms of Service

Effective date [EFFECTIVE DATE]

What you agree to when you create an account: what you may store, how seats and billing work, and how either of us ends it.

Privacy policy · Subprocessor register

1. Acceptance, and who may use the service

These terms are an agreement between you and [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS], company number [COMPANY REGISTRATION NUMBER]. They cover the penv.cloud website, console, API, and command line tool. Creating an account means you accept them.

You may use the service if you are at least [MINIMUM AGE] and are not barred from it under [EXPORT AND SANCTIONS LIST]. If you accept these terms for a company, you are saying you have authority to bind that company, and "you" then means the company.

The open-source penv package is separate and carries its own licence. Nothing here changes it.

2. Accounts

Keep your sign-in credentials to yourself. You are responsible for what happens under your account. Turn on a second factor. Tell us at security@penv.cloud the moment you think an account has been taken.

We refuse throwaway mailboxes at sign-up and for recovery addresses. An address that stops being yours tomorrow cannot protect an account today.

Sign-in with Google, GitHub, or Microsoft links to an existing account only when the provider says the email address is verified. An unverified address links to nothing and opens nothing.

3. Workspaces

Your work lives in a workspace. Whoever creates it holds the owner role. The owner decides who joins, what role each member holds, and whether the workspace requires a second factor or company sign-in.

The workspace owner controls the data in it. If you are a member of somebody else's workspace, they decide what you can reach and they can remove you. Removal takes effect on the next request and ends live sessions at once.

An owner may connect a company identity provider on Enterprise, in which case that provider adds and removes people. Deprovisioning through the directory works the same way as removal by hand.

4. Seats, machines, and billing

4.1 The model

You pay for the people who sign in. Machines never take a seat. Your machines get unlimited scoped credentials at no cost on every plan, including Free. We do not charge per identity, per secret, per machine, or per API call, because that would put a price on rotating a credential.

A seat is an active membership in a workspace. Somebody the directory has deprovisioned stops counting from the moment they are marked, and does not wait for a renewal.

4.2 The plans

FreeProEnterprise
Price$0$18 per seat per month billed annually, or $22 monthlyBy agreement
Human seats3UnlimitedUnlimited
MachinesUnlimitedUnlimitedUnlimited
Projects and environments3 and 3UnlimitedUnlimited
Integration connections1UnlimitedUnlimited
Custom rolesNone. The built-in roles cover every planUnlimitedUnlimited
API rate limit per credential240 reads and 60 writes a minute480 reads and 120 writes a minuteBy agreement
Audit log retention7 days90 daysBy agreement
Company sign-in and directory syncNot includedNot includedIncluded
Your own encryption keyNot includedNot includedIncluded
SupportCommunityEmailDedicated

Encryption is identical on all three. A cheaper plan is never a weaker one.

Local prices are set from a price book in local currency and reviewed periodically, so they do not flap with the exchange rate. A discounted local price requires a payment instrument from that country. The price you see at checkout is the price that binds.

4.3 Paying

Stripe collects payment in most markets and Paystack collects it in African markets. Your processor and your currency are fixed when the subscription starts, so pick the right country at checkout. We keep our own record of seats, entitlements, and charges, and that record is what governs. A processor executes the charge.

Charges renew automatically until you cancel. Seat changes are charged on your next invoice or prorated, depending on the processor and cycle you chose. Prices exclude tax unless the checkout says otherwise, and you are responsible for any tax we are required to collect.

[REFUND POLICY]

We may change prices with [PRICE CHANGE NOTICE PERIOD] notice. A change applies from your next renewal, so you can cancel before it takes effect.

4.4 Failing to pay

If a payment fails we will tell you and retry. If it stays unpaid we may downgrade the workspace to Free or suspend it. Downgrading never deletes your values, and it never takes down a company sign-in connection you already had. It stops you building a new one and enforces the Free limits on new work.

5. Acceptable use

5.1 What to store

Store the keys and settings your own applications need, and credentials you are authorized to hold. Do not store somebody else's credentials without their permission, and do not store material that is illegal for you to hold.

5.2 What not to do

Do not resell the service or run it as a competing product. Do not attack it, probe it beyond your own workspace, or try to reach another customer's data. Do not work around a seat count, a quota, or a rate limit. Do not use the integrations to send traffic at systems you do not control. Our outbound requests refuse private and internal network ranges and never follow a redirect, and attempting to defeat that is a breach of these terms.

Do not use the service to build or run anything that breaks the law where you or your users are.

5.3 Rate limits

The limits in section 4.2 are per credential and per minute. A bulk read costs one request for each secret it returns. Going over gets you a refusal rather than a bill.

5.4 Regulated data

The service is not offered for regulated health data. Do not store protected health information (PHI) in it, and we do not sign a Business Associate Agreement. We hold no SOC 2 report today. On request, Enterprise customers receive our security questionnaire answers and a data processing agreement, and any further compliance commitment is agreed in your contract.

5.5 If you break these rules

We may remove offending content, limit a feature, or suspend the workspace entirely. Where the situation allows it we will tell you first and give you a chance to fix it.

6. Your data, and what we do with it

You own everything you put in. We claim no ownership of your values, your configuration, or anything else you store.

You grant us the permission we need to run the service for you: to store your data, encrypt it, back it up, transmit it, decrypt it to answer a request from you or one of your machines, and send it to a platform you told us to sync it to. That permission covers nothing else. It ends when your data is deleted.

You are responsible for the lawfulness of what you store and for having the right to store it. Where we process personal data on your behalf, our Data Processing Agreement governs. Ask at legal@penv.cloud.

Feedback you send us is ours to use without obligation. Do not send us anything confidential in feedback.

7. How your stored values are handled

Every value is encrypted, each one under its own key, and tied to its address so a copy cannot be opened elsewhere. The database itself keeps your workspace separate from every other one, on every plan.

The server can decrypt your values to serve your machines. That is what makes penv pull work. This is not zero-knowledge encryption and we do not present it as such. We treat your values as your confidential information, we limit access to what running the service requires, and every reveal is written to your audit log with who, what, and when. Our staff do not read your values in the ordinary course of running the service, and there is no support tool that shows one.

On Enterprise you can hold the wrapping key yourself. Disabling it ends our ability to open your values on the next call.

Two things are worth saying because your threat model depends on them. A malicious step running in the same CI job as a delivered value can read that value, and no product can prevent that. Values delivered to a build carry a five-minute lifetime, which is the guarantee, and the end-of-job revoke only shortens the usual case.

8. Availability and support

We work to keep the service up and we do not promise a specific uptime on Free or Pro. Enterprise customers get [UPTIME COMMITMENT] in their agreement.

Support is community-based on Free, by email on Pro, and dedicated on Enterprise. [SUPPORT RESPONSE TARGETS] Write to support@penv.cloud.

Features will change over time. If we remove something you depend on we will tell you before it goes.

Some capabilities are not built today. There is no dedicated infrastructure option, no choice of data region, and no tamper-evident chain on the audit log. Ask at legal@penv.cloud before you sign if one of those decides your evaluation.

9. Suspension, termination, and getting your data out

9.1 You can leave whenever you like

Cancel a subscription in the console and it runs to the end of the period you paid for. To close a workspace entirely, an owner cancels the plan first, confirms it is them, and types the workspace name. Access ends immediately. The data survives 30 days so a mistake is recoverable, then it is destroyed and cannot be brought back.

9.2 Export before you go

Your values can be read back at any time with penv pull or the API. Your audit log can be read in the console for as long as your plan retains it: 7 days on Free and 90 days on Pro, after which a daily job deletes the older entries, and on Enterprise the period agreed in your contract. Do this before you delete a workspace. After the 30 days we hold nothing to give you.

9.3 We can suspend or end an account

We may suspend or end your access if you break these terms, if payment stays unpaid, if a law requires it, or if your use is putting the service or another customer at risk. Except where a law or an immediate risk prevents it, we will tell you first and say why.

We may also stop offering the service with [TERMINATION NOTICE] notice. If we do, we will refund the unused part of anything you prepaid and give you time to export.

9.4 What survives

Sections 6, 10, 11, 12, 13, and 14 survive the end of this agreement, along with anything you owe us.

10. Our intellectual property

The service, the software behind it, and the marks used with it belong to us or to our licensors. These terms give you a limited right to use the service and nothing more. Do not copy it, resell it, reverse engineer it, or remove a notice from it. [TRADEMARK NOTICE]

You may say publicly that you use penv.cloud. We will ask before using your name or logo.

11. Warranty disclaimer

The service is provided as it is. To the extent the law allows, we disclaim every warranty that is not written into these terms, including merchantability, fitness for a particular purpose, and non-infringement.

We do not warrant that the service will be uninterrupted, that it will be free of errors, or that it will meet a requirement we have not agreed to in writing. Keep your own copies of anything you cannot afford to lose.

Nothing here excludes liability that the law does not let us exclude.

12. Limitation of liability

To the extent the law allows, neither party is liable for indirect, incidental, special, consequential, or punitive damages, for lost profits, or for lost revenue, whatever the theory of liability and even if warned that the loss was possible.

Our total liability for all claims under this agreement is limited to [LIABILITY CAP].

These limits do not apply to your obligation to pay, to either party's breach of the other's intellectual property rights, or to anything a law forbids us to limit.

13. Indemnity

You will defend us against a third-party claim arising out of your data, your use of the service in breach of these terms, or your breach of a law, and you will pay the damages and costs finally awarded. We will tell you about the claim promptly, let you control the defense, and help you at your expense. You cannot settle in a way that admits fault on our behalf without asking us.

14. Governing law and disputes

These terms are governed by the law of [GOVERNING LAW], without regard to its conflict of laws rules. Disputes go to [VENUE], and both parties agree to that forum.

The United Nations Convention on Contracts for the International Sale of Goods does not apply.

15. Changes to these terms

We may update these terms. We will post the new version with a new effective date and, when the change is material, email the workspace contact at least [TERMS CHANGE NOTICE PERIOD] beforehand. Using the service after the new date means you accept it. If you do not, stop using the service and close your workspace before the date.

16. Everything else

These terms, plus any order form or Data Processing Agreement you signed, are the whole agreement between us on this subject. If one part is held unenforceable the rest still applies. Not enforcing something once does not waive it. You may not transfer this agreement without our written consent, and we may transfer it to a successor of the business. Nothing in it makes either of us the other's agent or partner.

17. Contact

Write to legal@penv.cloud for anything about these terms, billing@penv.cloud about an invoice, support@penv.cloud for help, and security@penv.cloud to report a vulnerability. The postal address is [LEGAL ENTITY NAME], [REGISTERED ADDRESS].

Get your keys out of the chat.