What Tallywyrm delivers, what we ask in return, and how disputes are resolved.
Tallywyrm is a 24/7 FinOps agent for multi-cloud spend. These terms describe what the service delivers, who may use it, how it is priced, and what happens when either side wants to stop.
24/7 multi-cloud FinOps, scoped to your own repos.
Every plan ships the same capability set; the page below codifies what the contract it sits behind. The full pricing math lives on /pricing; this section is what the rest of the contract governs.
- 24/7 multi-cloud inventory across AWS, GCP and Azure — instance, storage, network and tag taxonomy captured hourly.
- Scoped rightsizing PRs into your Terraform, Pulumi or Crossplane repo; your existing review, policy and merge gates own the change.
- Stop / start schedules for non-production environments.
- Weekly exec-ready savings report, signed off before the invoice is raised.
- A full audit trail covering every action listed above.
Keep the credential contract honest.
The same read-only OIDC trust the credential contract on /privacy binds to is what this contract relies on. The bullets below are what each side has to keep doing — and not doing — for it to stay that way.
- Provide and maintain a valid OIDC trust for the accounts you grant; rotate signing keys on your normal cadence.
- Do not point the agent at workloads you are not authorised to inventory.
- Neither side reverse-engineers, decompiles or otherwise attempts to derive the agent source.
- Do not sub-license, resell or time-share the service, and do not allow any third party to do so.
- Neither side attempts to expand the credential scope the OIDC trust brokers — read-only stays read-only.
- The agent surfaces recommendations as PRs; it does not merge on your behalf and it does not bypass your review, policy or merge gates.
Three tiers, verified-only invoicing, paid out of savings.
The full pricing math lives on /pricing; what this section codifies is the contract behind it. The percentage is what we keep of the savings that survived the weekly audit pass — not a forecasted figure, not a number from a native tool.
tier% × verified savings — the share, no floor, no claw-back.
The fee is paid out of savings before the cloud bill. The week after a rightsizing PR ships, Tallywyrm re-reads the same workload in the same account over the same time window; only the delta that survives the re-read enters the verified pool for that period. Same audit tuple the invoice, /pricing and /security-and-compliance already publish.
Each side owns what each side brings.
What Tallywyrm builds belongs to Tallywyrm; what you bring with you belongs to you. The boundary is the same line the IaC delivery channel enforces: the PR is the only delivery channel; everything inside it is yours the moment your existing review and merge gates approve it.
- The agent itself, the recommendation engine, the rightsizing heuristics and the workflow that produces the PR.
- The audit-trail schema, the verification heuristic and the Tallywyrm brand.
- Aggregated, fully de-identified service-health metrics (queue latency, scheduler success rate) used only to operate the platform.
- Your IaC repo — Terraform, Pulumi or Crossplane — every module, variable and policy you bring with it.
- Your inventory data — multi-cloud resource records, attached storage, network attachments, tag taxonomy, region and account / tenant lineage.
- Your audit exports — the CSV you can request at any time during the retention window published on /privacy.
- Your cloud account — we cannot and do not write to it; we surface PRs only.
Reciprocal protection, named sub-processors, named windows.
Each party protects the other's confidential information with the same standard it uses for its own. The named sub-processors and the retention windows are documented on /privacy — this section is what obligates us to uphold them under the contract.
- Each party protects the other's confidential information with industry-standard care, no less than the standard it uses for its own.
- Neither party shares the other's confidential information with anyone except the named sub-processors on /privacy, each bound by the same standard.
- Confidentiality obligations survive termination for the longer of the SOC 2 Type II / ISO 27001 retention window or any window required by applicable law.
- Customer-side confidential information includes IaC repo content, inventory snapshots, audit events and savings reports; Tallywyrm-side confidential information includes the agent source, the recommendation engine and the brand.
Standard carve-outs, both directions.
No party is liable to the other for indirect or consequential damages, lost profits, loss of goodwill or business interruption. Direct damages are capped at fees paid in the prior twelve months. The customer-facing safety net is the weekly audit pass and the read-only credential scope documented on /privacy and /security-and-compliance.
- Neither party is liable for indirect, incidental, special, consequential or punitive damages, including lost profits, loss of goodwill or business interruption.
- Direct damages are capped, in the aggregate, at the fees paid or payable by the customer to Tallywyrm in the twelve months preceding the event giving rise to the claim.
- The cap does not apply to a breach of confidentiality, an indemnified IP claim, gross negligence or wilful misconduct, or any liability that cannot be limited as a matter of law.
- The customer remains responsible for their IaC pipeline, their review / policy / merge gates, and the configuration and rotation of the OIDC trust the read-only credential scope depends on.
Either side, with thirty days written notice.
Either party may terminate at the end of any monthly billing cycle with thirty days written notice. On termination, the agent stops, the data is returned or deleted, and any verified-savings invoice for the partial cycle is settled in the normal way.
- Either party may terminate at the end of any monthly billing cycle with thirty days written notice, for any reason or no reason.
- On termination, Tallywyrm ceases inventory reads and PR opens within the next cycle and does not resume for that workspace.
- Tenancy-scoped data — inventory snapshots, audit events and weekly reports — is deleted within the retention window published on /privacy.
- The customer may request a copy of the audit trail during that window; once the window closes, the data is no longer recoverable.
- The customer pays any verified-savings invoice for the partial cycle in which termination took effect; no further invoices are raised.
Delaware (US) or England & Wales (UK/EU).
The governing law depends on the customer's residence. The detailed data-handling specifics (retention windows, named sub-processor list, GDPR / CCPA rights) live on /privacy; the framework-to-controls matrix lives on /security-and-compliance. Those documents are incorporated by reference and form part of this contract.
- Customers resident in the United States — these terms are governed by the laws of the State of Delaware, without regard to its conflict-of-laws principles, and any dispute is heard in the state or federal courts located in Delaware.
- Customers resident in the United Kingdom or the European Union — these terms are governed by the laws of England & Wales, and any dispute is heard in the courts of England & Wales.
- Before formal proceedings, the parties will attempt in good faith to resolve any dispute through informal escalation to legal@polsia.app. That escalation is not a precondition, but it is the channel we answer on first.
- The retention windows, sub-processor list and GDPR / CCPA rights on /privacy are incorporated by reference. The framework-to-controls matrix on /security-and-compliance is incorporated by reference.
Same compliance posture as the engineering pages — and a contracts desk that replies within one business day.
Same badges as /privacy and /security-and-compliance. The audit trail that backs the verified-only invoice model is what these frameworks demand. The contracts desk below answers procurement questions, redlines, MSA requests and termination in any direction.
- SOC 2 Type II
- ISO 27001
- FedRAMP Moderate
- EU CSRD
- SEC climate disclosure
- GDPR