Terms of Service
1. Who we are and what this covers
These Terms of Service ("Terms") are a contract between you ("you", "Customer") and Infrastratus, registered at a sole proprietorship registered in the Republic of the Philippines (full registered address available on request and stated on invoices) (registration number) ("we", "us", "KubeManta").
They cover your subscription to KubeManta — the right to use the Service at a particular tier, and your commercial relationship with us (billing, renewal, cancellation, support).
They do not cover the software license itself. KubeManta is self-hosted: you download and run the software inside your own Kubernetes cluster. Your right to run, copy and use that software is governed by the separate End User License Agreement ("EULA"). Both documents apply. If they genuinely conflict, the EULA governs questions about the software, and these Terms govern questions about the subscription and payment.
Related documents, all incorporated into these Terms by reference:
- End User License Agreement (EULA)
- Privacy Policy
- Refund & Cancellation Policy
- Subprocessor List
- Data Processing Addendum (DPA) — applies where you are a data controller under GDPR/UK GDPR
2. Definitions
Terms defined here carry the same meaning in the EULA and the other linked documents.
| Term | Meaning |
|---|---|
| Service | The KubeManta software, its container images, the Helm chart, our license-validation and update-feed endpoints, the website, and our support. |
| Software | The KubeManta agent and UI container images and Helm chart that you install into your own cluster. |
| Cluster | One Kubernetes cluster, identified by the stable Cluster Fingerprint described in §4. |
| Cluster Fingerprint | A stable identifier derived inside your cluster and sent with license validation, used to bind one license to one Cluster. It is a license-compliance identifier, not cluster content. |
| Subscription | Your paid or free entitlement to a Tier, for a stated number of Clusters and a stated number of Admin Seats. |
| Tier | Free, Pro, or Enterprise, as described on the pricing page and in LICENSING.md. |
| Admin Seat | The entitlement for one user account to hold the admin role in the Software — a user permitted to make changes. Pro is priced per Admin Seat (§5.3). |
| Viewer | A user account that can see but not change. Viewer accounts are free and unlimited on every Tier and are never counted or charged. |
| Your Data | Everything inside your cluster — workloads, logs, configuration, metrics, secrets. See §8. |
3. The Service, in plain terms
KubeManta is a self-hosted Kubernetes operations platform. You install it into your cluster with Helm. It runs there, under your control, on your infrastructure.
The practical consequences, which we consider a feature and state plainly:
- We do not host your cluster and we do not receive your cluster's data. See §8 and the Privacy Policy for the precise and complete description, including the one important exception (AI providers you choose to configure).
- We cannot fix your cluster for you. Support is advice, not operations.
- Availability of the Software is your responsibility, because you run it. We do not offer an uptime commitment for software running in your cluster, and we could not meaningfully do so. Our uptime obligations are limited to our own endpoints (license validation, image registry, website), and even there we offer no formal uptime SLA at this time. The Software is designed to degrade gracefully when our endpoints are unreachable — see §4.4.
4. Licensing model
4.1 One license per Cluster
A subscription entitles you to run the Software on a stated number of Clusters. A license is bound to one Cluster via its Cluster Fingerprint.
| Action | Consumes an additional Cluster entitlement? |
|---|---|
| Reinstalling or upgrading KubeManta on the same Cluster | No |
| Pod restart, redeploy, storage wipe, image upgrade | No |
| Installing on a second, different Cluster | Yes |
| Deleting and recreating the Cluster | Yes — it is a new Cluster |
A Cluster that stops checking in frees its entitlement automatically, so a rebuilt or migrated Cluster can activate on the same key without contacting us.
4.2 Tiers
Free — $0. The Free feature set on one Cluster, for as long as you like, with one Admin Seat and unlimited free Viewers. The Free set is centerd on read-only visibility; a small number of basic operational features (for example workload restart/scale) are also Free and are controlled by the Kubernetes permissions you grant at install, not by the license — the authoritative list is FEATURE_MATRIX.md. No payment, no commitment from us, and no support commitment.
Pro — a recurring fee per paid Admin Seat, as stated on the pricing page, with free unlimited Viewer accounts (§5.3). One subscription covers one Cluster (§4.1).
Enterprise — custom scope and pricing, agreed in a separate written order or agreement. Where an Enterprise agreement conflicts with these Terms, that agreement governs.
The authoritative, feature-by-feature breakdown of what each Tier unlocks is FEATURE_MATRIX.md, generated from the Software's own enforcement registry.
4.3 What happens when a paid subscription ends
The Software keeps running. It reverts to Free-tier behavior: paid features stop, the Free core continues, and nothing is deleted. No existing admin is signed out or demoted by a lapse; the seat limit constrains only the assignment of new admins (§5.3). Your data stays in your cluster because it never left it. This is described in detail in LICENSING.md and restated in the EULA §6 and the Refund & Cancellation Policy.
We consider a paid tool that bricks itself on expiry to be unacceptable behavior in infrastructure software, and we have deliberately not built one.
4.4 Grace and offline tolerance
License validation happens in the background. If our license service is unreachable, paid features continue on the last known good state for a grace period (currently 7 days) before degrading to Free. Expired paid licenses get the same grace window. We will not treat a network problem on either side as non-payment.
5. Fees, billing and payment
5.1 Paddle is our Merchant of Record
Payments are processed by Paddle (Paddle.com Market Ltd and its affiliates), acting as Merchant of Record — meaning Paddle, not us, is the seller of record for the transaction, and Paddle handles payment processing, invoicing, and global sales tax/VAT.
Consequences for you:
- Your purchase is also subject to Paddle's own buyer terms.
- We never see or store your full card details. Paddle holds them. See the Privacy Policy §4 and the Subprocessor List.
- Refunds are executed through Paddle (see §6).
5.2 Renewal
Subscriptions renew automatically at the end of each billing period at the then-current price for your plan, using your stored payment method, until cancelled. The billing period (monthly or annual) is the one you selected at checkout.
We will disclose the renewal terms, the price, and the billing period to you before you pay, on the checkout page — not only in this document.
If we change the price of your plan, the change applies from your next renewal and is disclosed to you at checkout before you are charged again. You may cancel before then (§6). A price change never takes effect during a period you have already paid for — that is a structural guarantee of the billing cycle, not a promise about notification.
5.3 Seats
Pro is priced per paid Admin Seat per billing period. An admin is a user account permitted to make changes through the Software. A Viewer account, which can see but not change, is free and unlimited on every plan.
The current seat price is the figure stated on the pricing page at kubemanta.com. It is stated there, and only there, so that one published number governs; this document deliberately does not repeat a figure that could drift out of date. For the avoidance of doubt, the figures applicable to you are those disclosed on the checkout page at the time you purchase or renew.
There is no charge based on the size of your cluster. We do not meter, limit or bill by node, CPU, memory, pod or workload count, and no such limit exists whose exceedance could reduce your access to the Software.
Seat limits affect assignment only. If all your seats are in use, the Software will decline to promote another user to admin until a seat is freed or added. It will never sign anyone out, never remove an existing admin, and never reduce the functionality available during an incident.
Changing your seat count. You may add or remove Admin Seats at any time. The change takes effect immediately in the Software, and your license remains valid throughout — removing a seat never suspends your license or signs anyone out. Billing changes take effect from your next billing period: we do not charge you mid-cycle for a seat change; your next invoice reflects the new seat count. Your price never changes without an action by you — we do not raise your subscription automatically based on how you use the Software.
What the Software reports to us. The Software reports a small number of
counts to us with its license heartbeat, including how many nodes your cluster
runs. This is for product and support purposes only and is not used to
calculate any charge. Exactly what is transmitted — counts only, and nothing
describing your workloads — is set out in the
Privacy Policy §3.3, and you may switch the reporting off
(LICENSE_METER_ENABLED=false) without affecting any functionality.
5.4 Taxes
Prices are exclusive of applicable taxes unless stated otherwise at checkout. Paddle calculates and collects VAT/GST/sales tax as Merchant of Record.
5.5 Failed payment
If a payment fails, Paddle will retry according to its dunning process. If payment is not recovered, the subscription is suspended and the Software degrades to Free tier (§4.3). We do not disable the Free core for non-payment, and a payment failure never signs out or demotes an existing admin (§5.3).
6. Cancellation and refunds
Summary — the full text is in the Refund & Cancellation Policy, which forms part of these Terms:
- 14-day money-back guarantee on your first purchase. Ask within 14 days of the date your first payment is taken and we refund that first payment in full. When a guarantee refund is granted, paid entitlements end at that point and the Software reverts to Free tier — a full refund and continued paid access do not combine.
- Changing your seat count does not restart the 14-day guarantee, and seat changes are billed from the next period — see §5.3 and the Refund & Cancellation Policy.
- After 14 days: cancel any time. Billing stops at the end of the current paid period; your access continues until that period ends; there is no pro-rata refund for the unused part of a period already paid for.
- On expiry the Software falls back to Free tier. Nothing of yours is deleted by us — it is in your cluster, not ours.
Nothing in this section removes any non-waivable statutory refund or withdrawal right you may have as a consumer under the law of your country (for example the EU/UK statutory right of withdrawal for consumers). Where such a right applies and is more generous, it prevails.
7. Acceptable use
You agree not to, and not to permit anyone else to:
- Use the Service in breach of applicable law, or to process data you have no right to process.
- Circumvent, disable, or tamper with license validation, feature gating, tier enforcement, or the Cluster Fingerprint — including by patching, rewriting, or proxying our endpoints.
- Share, resell, sublicense, or redistribute the Software, your license key, or the container images, except as the EULA expressly allows (internal mirroring is allowed; redistribution is not).
- Use one Cluster license to cover multiple Clusters.
- Circumvent seat-based pricing — including by operating a single admin account as a shared credential for multiple individuals in order to avoid paying for Admin Seats. (Viewer accounts are free and unlimited, so there is never a price reason to share a viewer account; an ordinary handover of an admin account between personnel is of course fine.)
- Reverse-engineer, decompile, or disassemble the Software, except to the extent that restriction is unenforceable under applicable law. See EULA §4.
- Use the Service to attack, disrupt, or gain unauthorized access to any system, including your own systems where you lack authorization.
- Conduct penetration testing or vulnerability scanning against our infrastructure (kubemanta.com, api.kubemanta.com, registry.kubemanta.com) without our prior written consent. Testing the Software inside your own cluster is expressly permitted and encouraged — and if you find something, please tell us: [email protected] (see Security & Trust §9).
- Use the Service's AI features to generate content that is unlawful, or to attempt to extract our prompts, models, or licensed materials for competitive purposes.
- Export, re-export, download or use the Software in violation of any applicable export control or economic sanctions law, or make it available to any person, entity or jurisdiction subject to such measures. You represent that you are not located in, under the control of, or a national or resident of any such jurisdiction, and that you are not named on any restricted-party list.
We may suspend a license for a serious or repeated breach of this section. Where practical and lawful we will tell you first and give you a chance to fix it.
Misuse is your liability. Any use of the Software or the Service in breach of this section, of the EULA, or of applicable law is a material breach of these Terms. To the fullest extent permitted by law, we are not liable for any loss, damage, claim, penalty or cost arising out of or relating to such use, whether suffered by you, by your personnel, or by any third party — and you remain responsible for it, including under §12.4. This applies however the misuse occurs, whether through the interface, the Resource Builder, the Helm interface, the browser terminal, the API, the MCP endpoints, or any AI feature, and whether it is carried out by you, by your personnel, or by anyone to whom you grant access.
8. Your data and your cluster
You own Your Data. We do not receive it.
KubeManta runs inside your cluster. Workload data, logs, metrics, configuration and secrets stay there. We have no access to your cluster, no back-channel into it, and no ability to read it.
There is one exception, and it is entirely under your control:
If you configure a third-party AI provider (for example Anthropic or OpenAI), then prompt content — which may include cluster context such as pod names, events, and redacted log excerpts — is sent from your cluster directly to that provider, under your own account and that provider's terms. It does not pass through us. The Software redacts secrets before sending, and offers a local-only mode and an outbound-domain allowlist so you can prevent this entirely.
This is described precisely, with the controls named, in the Privacy Policy §5. You are responsible for choosing whether to enable it and for your relationship with any AI provider you configure.
What we do collect — account, billing and licensing data, and website analytics — is listed exhaustively in the Privacy Policy.
8.1 Your responsibilities
The Software runs on infrastructure you control and which we cannot reach. As between you and us, you are solely responsible for:
- Your cluster and its infrastructure — its provisioning, configuration, networking, capacity, patching, availability and security, and the security of any system on which the Software runs.
- Backup, disaster recovery, retention and integrity of Your Data, including any data held in the Software's own datastore. We do not hold a copy of Your Data and cannot restore it for you.
- All access-control decisions — which of your personnel are granted the
admin role, who may reach the in-browser terminal, and whether you enable the
optional capabilities that permit changes to your cluster. Each of these is
disabled by default and becomes active only because you enable it: writes
(
rbac.allowWrites), Secret reading (rbac.readSecrets) and privileged operations (expertMode.enabled). - Reviewing and approving every change before it is applied, and satisfying yourself that it is appropriate for your environment.
- Custody of credentials — your license key, administrator passwords, API keys, identity-provider configuration, and any third-party provider credentials you supply to the Software.
- Your own legal and regulatory compliance in respect of your cluster, Your Data, and your use of the Software.
We have no access to your cluster and no ability to operate, monitor, back up, restore or repair it. Nothing in these Terms, any support agreement, or any documentation creates an obligation on us to do so.
8.2 Destructive operations and data loss
The Software can perform operations that permanently and irreversibly destroy resources and data in your cluster. These include, without limitation: deleting pods, workloads and namespaces (and with a namespace, the PersistentVolumeClaims in it and the data on the underlying volumes); scaling workloads to zero; uninstalling or rolling back Helm releases; applying manifests that replace or remove existing resources; and any command you run in the in-browser terminal.
These capabilities are disabled by default. They become available only because you enabled them under §8.1(3), and each individual action requires a human user holding the admin role to explicitly approve that specific action, in some cases by retyping the name of the resource to be destroyed.
You acknowledge and agree that:
- Approving such an action is your instruction, not our recommendation.
- We cannot assess whether any particular resource is safe to destroy, because we have no visibility of your cluster, your architecture, or your data.
- Some operations cannot be undone, and no undo facility is offered or implied.
- You are responsible for holding backups sufficient to recover from any such operation before you approve it.
To the fullest extent permitted by law, we are not liable for any loss, corruption, unavailability or destruction of workloads, volumes, configuration or data resulting from any operation that you or your personnel approve or initiate, regardless of how that operation was reached — whether suggested by an AI feature, selected from the interface, executed through the Resource Builder or the Helm interface, issued through the API, or entered in the browser terminal — and regardless of the theory of liability. This section is in addition to, and does not limit, §10, §11 and §12.
9. Intellectual property
We (and our licensors) own the Software and the Service. You get the license described in the EULA and nothing more. No implied licenses are granted.
The Software bundles third-party open-source components, each licensed under its own terms; see THIRD_PARTY_LICENSES.md. Those terms govern those components and are not overridden by these Terms or the EULA.
Feedback you send us may be used freely, without obligation or compensation. We will not identify you as the source without your permission.
10. AI features — advisory only
KubeManta's AI features are assistive and advisory. They can be wrong.
- AI output is a suggestion, not a decision. Verify before acting.
- No AI-initiated change is ever applied autonomously. Every write is approval-gated: a human with the admin role must explicitly approve each write action before it executes. This is enforced in the Software, not merely promised — see Security & Trust §6.
- Security scanning is assistive. A clean scan is not a guarantee that your images or configuration are secure.
- We are not liable for outcomes arising from AI output or from actions you take on an AI suggestion, to the fullest extent permitted by law (§12).
11. Warranties and disclaimers
THE SOFTWARE AND THE SERVICE ARE PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTY OR CONDITION OF ANY KIND, EXPRESS, IMPLIED OR STATUTORY, INCLUDING WITHOUT LIMITATION ANY IMPLIED WARRANTY OF MERCHANTABILITY, SATISFACTORY QUALITY, FITNESS FOR A PARTICULAR PURPOSE, ACCURACY, TITLE, OR NON-INFRINGEMENT, except to the extent such warranties cannot be excluded under applicable law.
Limited conformity warranty (paid tiers only). For paid tiers, and for so long as the subscription is active and the fees are paid, we warrant that the Software will perform substantially in accordance with the then-current published product description for that tier. This warranty is given by reference to that product description only, and not to any other statement, document, roadmap, benchmark, demonstration or communication.
Your sole and exclusive remedy, and our entire liability, for breach of that warranty is, at our option: (a) correcting the non-conformity within a reasonable period; or (b) terminating the affected subscription and refunding the fees you paid for the then-current billing period. This warranty does not apply where the non-conformity arises from Software that has been modified, from use outside the EULA or these Terms, from an unsupported version, or from your infrastructure, configuration or third-party components.
We do not warrant that the Service will be uninterrupted or error-free; that it will detect, prevent or correctly diagnose any particular incident, misconfiguration or vulnerability; that any security scan is complete or accurate; or that any AI output is accurate, complete or fit for any purpose.
Nothing in this section excludes or limits liability that cannot lawfully be excluded or limited, including for death or personal injury caused by negligence, or for fraud or fraudulent misrepresentation.
12. Limitation of liability
To the fullest extent permitted by law:
- Neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, lost revenue, lost data, or business interruption — even if advised such damages were possible.
- Our total aggregate liability arising out of or relating to the Service is capped at the greater of (a) the fees you actually paid us in the 12 months before the event giving rise to the claim, or (b) USD 100.
- For the Free tier, where you have paid us nothing, our aggregate liability is capped at USD 100.
The exclusions in §11 and the caps here do not apply to liability that cannot lawfully be limited — including, for the avoidance of doubt, liability for fraud or for wilful misconduct or gross negligence to the extent the Republic of the Philippines law (Civil Code Arts. 1171 and 1172) does not permit it to be excluded in advance.
12.4 Your indemnity
You will defend, indemnify and hold harmless Infrastratus, its proprietor, and its personnel from and against any third-party claim, demand, action or proceeding, and any resulting loss, damage, liability, settlement, penalty, cost or expense (including reasonable legal fees), arising out of or relating to:
- your breach of these Terms, the EULA, or §7 (Acceptable use);
- your use of the Software or the Service in violation of applicable law, including any export control or sanctions law;
- any operation performed in or against your cluster through the Software, including any destructive operation you or your personnel approved or initiated (§8.2);
- your configuration of any third-party AI provider, and any transmission of data to it (§8);
- your failure to maintain adequate backups or disaster recovery (§8.1(2)); and
- any claim brought by your personnel, customers or end users relating to Your Data or to your cluster.
This indemnity is not subject to the caps in §12.2 and §12.3. We will notify you promptly of any claim for which we seek indemnity, allow you to control the defense and settlement with counsel reasonably acceptable to us, and cooperate at your reasonable expense. You may not settle any claim in a way that imposes liability, admission of fault, or a non-monetary obligation on us without our prior written consent.
13. Term, suspension and termination
These Terms apply from the moment you first use the Service and continue while you use it.
You may terminate at any time by cancelling your subscription (§6) and, if you wish, uninstalling the Software.
We may terminate or suspend for material breach of these Terms or the EULA — including non-payment or a §7 breach — with notice and, where the breach is curable, a reasonable chance to cure.
On termination: paid entitlements end; the Software degrades to Free tier and keeps running (§4.3); §§8–12, 14 and 15 survive. We do not delete anything of yours, because we do not hold anything of yours.
14. Changes to these Terms
We may update these Terms. When we do:
- We update the Last updated date at the top of this document and publish the revised Terms at kubemanta.com/legal/terms. The current terms are always the ones published there.
- Material changes apply from your next renewal — never during a period you have already paid for. Continued use after they take effect means acceptance. If you do not accept, cancel before your next renewal (§6) and you will not be charged again.
- We may also notify you by email, but we do not commit to a fixed notice period: the protection you can rely on is the renewal boundary above, which applies automatically and does not depend on a message reaching you.
Every consent you give us is recorded against the Last updated date of the document you agreed to (see WEBSITE_INTEGRATION.md §7), so it is always determinable which text you actually accepted.
15. General
Governing law and venue. These Terms are governed by the laws of the Republic of the Philippines, and the courts of the Republic of the Philippines have exclusive jurisdiction — except that if you are a consumer, you keep the benefit of any mandatory protections and any right to sue in your country of residence under that country's law.
Additional terms for consumers in the EEA and the UK. If you are a consumer resident in the EEA or the UK, the following apply and prevail over anything inconsistent elsewhere in these Terms:
- your statutory right of withdrawal for distance contracts, as described in the Refund & Cancellation Policy §8;
- your mandatory statutory rights, which nothing in these Terms limits;
- your right to bring proceedings in your country of residence; and
- our obligation to make material changes effective only from your next renewal, never mid-period (§14).
Assignment. You may not assign these Terms without our written consent. We may assign them to a successor in a merger, acquisition, or sale of assets, on notice to you.
Entire agreement. These Terms, together with the EULA, the Privacy Policy, the Refund & Cancellation Policy, and any support agreement or Enterprise order form signed with you, are the entire agreement between us on this subject.
Severability. If a provision is unenforceable, the rest stands and the offending provision is narrowed to the minimum extent needed to make it enforceable.
No waiver. Failing to enforce a right is not a waiver of it.
Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control.
Notices. To us: [email protected]. To you: the email address on your account.
16. Contact
| Purpose | Contact |
|---|---|
| Support, billing, general | [email protected] |
| Privacy and data-protection requests | [email protected] (see Privacy Policy §10) |
| Security vulnerability reports | [email protected] |
Infrastratus · a sole proprietorship registered in the Republic of the Philippines (full registered address available on request and stated on invoices) ·