isolation.cloudDOCS

Terms of Service

The agreement between you (and your organization) and Isolation for using Isolation Cloud.

Version 1.0 (draft) — 22 September 2026

These Terms of Service (the "Terms") are an agreement between you and Isolation Labs S.r.l. ("Isolation", "we", "us"), the provider of Isolation Cloud — the service at isolation.cloud, its API, the isolation command, the Isolation apps for Slack, Microsoft Teams and other tools, and the software we distribute to run it (the "Service"). The Privacy Policy (isolation.cloud/legal/privacy) explains how we handle personal data and is part of these Terms. The container images and the isolation-server command are licensed under the End User License Agreement (isolation.cloud/legal/eula), which applies to them in addition to these Terms.

You accept these Terms by ticking the acceptance box when you first sign in. If you create an organization, you also accept them on behalf of that organization (section 3). If you do not accept them, do not use the Service.

1. Definitions

  • Account: your individual sign-in, identified by your email address.
  • Organization: the tenant that owns servers, workspaces, sessions, agents, apps, members and a balance. Every use of the Service happens inside an Organization.
  • Customer: the Organization, or, when an Organization is not created for a company or other legal entity, the individual who created it.
  • Member: an Account that belongs to an Organization, with the role Owner, Admin or Member.
  • Session: an isolated sandbox that the Service starts for a task, either on a Connected Server (a machine you run) or as a Cloud Session (a machine we run for you, billed per second).
  • Customer Content: everything you and your Members put into the Service or produce with it — repositories, files, environment values, secrets, prompts, conversations with agents, agent memory, and the output of your sessions.
  • Agent: an AI coding agent (a harness such as Claude Code, Codex or goose, with a model) that the Service runs inside a Session on your behalf, with credentials you provide.

2. Accounts

You must be at least 16 years old. You sign in with a code we email you; keep your inbox secure, because whoever reads your email can sign in as you. You are responsible for what happens under your Account, including through tokens you create for apps, MCP clients or the isolation command. Tell us at once at security@isolation.cloud if you believe your Account was used without your permission.

3. Organizations and authority

Creating an Organization makes you its Owner. If you create it for a company, non-profit or other entity, you represent that you are authorized to bind that entity to these Terms, and "Customer" means that entity. If you are not, you are the Customer personally. We record who accepted these Terms for an Organization, when, and which version, and the Organization's Owners can see it.

Owners and Admins control the Organization: they invite and remove Members, set roles, connect servers, install apps, buy and spend balance, and can list and stop any Member's sessions. A Member's workspaces and sessions are the Member's own — another Member cannot open them — but the Organization remains the Customer for all of them. When a Member leaves or is removed, their sessions are ended and their workspaces stay with the Organization.

4. The Service

Isolation starts sandboxes for coding agents and development work, keeps each workspace's files and each agent's memory between sessions, and lets people and agents drive it from the website, a terminal, an MCP client, Slack, Teams and other connected tools. We describe the current features at isolation.cloud/docs. We may add, change or retire features; we will not remove a paid feature without reasonable notice.

Connected Servers. You may pair a machine you own or control by running isolation-server on it. That software mounts the machine's Docker socket and starts sandboxes as containers on it, which is root-equivalent on that machine. You are responsible for that machine, its security, its network exposure (including the ssh door if you open it) and the cost of running it. We reach it only through the tunnel it opens to us and never store its credentials beyond what pairing needs.

Cloud Sessions. A Cloud Session is a machine we create on a compute provider in the region your Organization chose, of the sandbox type you picked, for as long as it runs, paused or stopped; you pay for it per second at the prices shown when you launch it, plus egress beyond the type's allowance. We may stop a Cloud Session that has been idle past the limits of your plan, and we will always tell you why.

5. Acceptable use

You may not use the Service, and you must not let your agents use it, to:

  • break the law, or infringe anyone's rights;
  • attack, scan, overload or interfere with any system, ours or anyone else's, or send spam;
  • mine cryptocurrency, run proxies, serve content to the public, or otherwise use sandboxes as general-purpose hosting;
  • try to escape a sandbox, reach another Customer's data, or defeat the isolation between Organizations, Members or sessions — if you find a way to, tell security@isolation.cloud and do not use it;
  • upload malware, or material that is illegal, or that sexualizes minors;
  • resell the Service, or use it to build a competing service by copying it;
  • exceed the limits of your plan by technical means.

We may suspend a Session, a Member, an Organization or an Account that we reasonably believe is breaking this section, and we will tell the Organization's Owners why unless the law forbids it.

6. Customer Content and credentials

Yours. You own Customer Content. We claim no rights over your code, your data or what your agents produce. You grant us only the license we need to run the Service for you: to store, transmit, process and display Customer Content as the Service does at your direction, and to keep the backups the Service keeps. We do not train models on Customer Content and we do not use it for anything but providing the Service to you.

Your responsibility. You are responsible for Customer Content: for having the right to put it in the Service, for what your agents do with it and produce from it, and for reviewing what an agent did before you rely on it. An agent is a tool that acts on your instructions; its output can be wrong, and you decide what to ship.

Credentials. The Service holds credentials you give it — AI provider keys and subscriptions, Git tokens, SSH keys, secrets in environments — encrypted, and delivers them to your sessions sealed so that only the session that needs them can read them. They are used only as you configure them. You are responsible for the terms you have with the provider of each credential (for example your AI provider's usage policy), and for the cost that provider charges you.

Open source and third-party software. Sessions run software you choose; our images include OpenSandbox (Apache-2.0) and other open-source components under their own licenses, listed in the EULA. Your use of a third-party AI provider, of GitHub, of Slack or Microsoft Teams is under those providers' terms.

7. Fees and payment

Connecting your own servers is free. Cloud Sessions and paid plans are billed as described at isolation.cloud/pricing at the time of use: prepaid balance that sessions draw down per second (a paused session is billed as the pricing page says), and, for paid tiers, a subscription per period. Payments are processed by Stripe; we never see or store your card number. Prices are in US dollars and exclude VAT and other taxes, which we add where the law requires. Balance you bought is not refundable once used; unused balance is refunded on written request if the law of your country requires it, otherwise at our discretion. We may change prices with 30 days' notice on the pricing page and by email to the Organization's Owners; the change applies to use after that date. If a payment fails we may suspend Cloud Sessions and paid features until it is settled.

8. Availability and support

We run the Service with care, but we do not promise it will be available without interruption. A Cloud Session lives on a third-party compute provider and can fail; the Service saves your workspace and agent state to durable storage at the points documented (save, pause, finish, and periodically), and what was not saved may be lost. Support is by email at support@isolation.cloud; paid tiers have the response targets shown on the pricing page.

9. Confidentiality and security

We treat Customer Content and your credentials as confidential, encrypt them at rest, and give access only to our staff who need it to run the Service or to help you when you ask. Our security practices are described at isolation.cloud/docs/servers. We will tell the Organization's Owners without undue delay if we learn of a breach affecting their Customer Content.

10. Term, suspension and termination

These Terms apply from your acceptance until your Account is deleted. You can delete your Account, leave an Organization, or delete an Organization you own, from the website at any time; deleting an Organization ends its sessions and deletes its Customer Content after the retention period in the Privacy Policy. We may suspend or terminate an Account or an Organization for a serious or repeated breach of these Terms, for non-payment, or if the law requires it, with notice to the Owners where possible. Sections 6 (ownership), 11, 12 and 13 survive termination.

11. Warranties and disclaimer

The Service is provided "as is" and "as available". To the fullest extent permitted by law we disclaim all warranties, express or implied, including merchantability, fitness for a particular purpose, non-infringement, and that the Service, the sandboxes or an agent's output will be error-free, secure or suitable for your purpose. Nothing in these Terms limits the rights you have as a consumer under mandatory law.

12. Limitation of liability

To the fullest extent permitted by law, Isolation is not liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue, data or goodwill, arising from the Service, from a sandbox, or from what an agent did or produced, however caused. Our total liability for all claims under these Terms is limited to the amount the Customer paid us in the twelve months before the claim, or one hundred euros (€100) if nothing was paid. These limits do not apply to liability that cannot be limited by law, including for fraud, gross negligence, wilful misconduct, or death or personal injury caused by negligence.

13. Indemnity

The Customer will defend and indemnify Isolation against third-party claims arising from Customer Content, from the Customer's or its Members' use of the Service in breach of section 5, or from what the Customer's agents did on its instructions.

14. Changes to these Terms

We may change these Terms. For a material change we will publish the new version at isolation.cloud/legal/terms, email the Organization's Owners at least 14 days before it takes effect, and ask you to accept the new version the next time you sign in; an Owner accepts it for the Organization. Continuing to use the Service after that date, and accepting the new version, means you agree to it. Every version stays available at that address with its date.

15. General

These Terms are governed by the laws of Italy, and the courts of Milan have exclusive jurisdiction, without prejudice to the mandatory consumer protections of your country of residence. If any part of these Terms is unenforceable, the rest stays in force. Our failure to enforce a right is not a waiver of it. You may not assign these Terms without our consent; we may assign them to a successor of our business. Notices to you go to the email address of your Account or of the Organization's Owners; notices to us go to legal@isolation.cloud. These Terms, the Privacy Policy and the EULA are the entire agreement between us about the Service, unless we sign a separate agreement with your Organization, in which case that agreement prevails where it conflicts.