Terms

Beta terms

Public beta. Last updated 9 October 2026.

The service

Counterseal is a credential broker, approval service and public receipts log for AI agents, run by Gautam Khosla, Ottawa, Canada. It is in public beta. By creating an account, sending requests through the broker, or sending receipts, you accept these terms.

As is, no guarantees

The service is provided as is and as available, without warranties of any kind, including availability, fitness for a purpose, that the irreversible map covers every dangerous call, or that a receipt will be accepted or kept online. You decide what you approve. Keep the receipt bundles you need: they verify offline without the service. To the extent the law allows, the service is not liable for indirect or consequential losses, and total liability is limited to the amount you paid for the service (during the beta, nothing).

Your keys and your agents

Only vault API keys you are allowed to use, and only send requests the provider's terms allow. You are responsible for what your agents do with the tokens you give them, and for keeping your passkeys, agent keys and tokens safe. Counterseal is not affiliated with GitHub, Cloudflare, Railway, Stripe, Supabase, Vercel, Neon, Fly.io, Resend or Shopify.

Teams

An account's owners decide who joins it and with which role, and are responsible for inviting only people who may see the account's keys' names, holds and audit log. Each person uses their own passkey; do not share one. Requiring two approvals means two different people approved, each with their own passkey; it does not stop people who agree to act together, and it does not stop an owner from changing who is on the team (every change is recorded and announced to the team).

Public and permanent

Receipts in the public log are public and permanent and cannot be removed. Broker receipts contain only what the privacy policy lists. For receipts you send yourself, you are responsible for their content: send hashes, not content, and do not send personal data, secrets, confidential content or anything you do not have the right to publish.

Fair use

Free during the public beta. Receipts: 10,000 per account per month and 2,000 per account per day, and a daily capacity for the whole log. Rate limits apply to the API and the proxy. Do not abuse the service, attack it, use the signature checker to probe other people's servers, or create accounts to get around limits. Accounts that do may be suspended.

Pricing

Paid plans for teams may come later. You will get at least 30 days' notice before anything you use starts to cost money.

Ending

You can delete your account at any time in the app (on a team, an owner can; anyone else can leave the team). Before you do, an owner can download all of the account's data, and anyone on it can export an evidence pack of its decisions. Businesses that need a data processing agreement can start from our template; it changes these terms only once both sides sign it. The beta may change or end; if it ends, the log's checkpoints and your bundles stay verifiable offline.

Contact

Questions: hello@gautamkhosla.com. Privacy: privacy@gautamkhosla.com. Security issues: security@gautamkhosla.com.