rConfig AI Center Terms of Use Addendum
Version 1.1
Last Updated: 29th August 2026
Proposed Effective Date: 29th August 2026
Parties and Scope
This rConfig AI Center Terms of Use Addendum (“Addendum”) is made between:
OS Informatics Limited, trading as rConfig, a company incorporated in Ireland under company number 751053, with its registered office at 44 Longshore Drive, Jacobs Island, Cork, Ireland (“rConfig”); and
the customer identified in the applicable software licence agreement, order form, subscription agreement, invoice, or other contract (“Customer”).
This rConfig AI Center Terms of Use Addendum (the “Addendum”) governs the Customer’s access to and use of the rConfig AI Center functionality supplied by OS Informatics Limited trading as rConfig (“rConfig”).
This Addendum supplements and forms part of the software licence agreement, order form, subscription agreement or other contract under which the Customer is authorised to use the applicable rConfig product (the “rConfig License Agreement”).
If there is a conflict between this Addendum and the rConfig License Agreement, this Addendum will govern only in relation to the AI Center. The rConfig License Agreement will govern in all other respects. Any Data Processing Agreement will govern to the extent of a conflict concerning the processing of personal data.
Core architecture commitment. Prompts, device configurations, operational context and AI Output pass directly and exclusively between the Customer Environment and the Customer’s selected Model Provider. They never pass through an rConfig-operated service.
Acceptance
The AI Center may be enabled only after this Addendum has been expressly accepted through the rConfig customer portal by an Authorised Administrator and acknowledged within the local AI Center workspace as required by the applicable activation workflow.
The person accepting this Addendum represents that they have authority to bind the Customer.
An ordinary page view, passive access, continued use, or failure to disable the feature does not constitute initial acceptance.
1. Definitions
“AI Center” means the locally deployed rConfig functionality that enables AI-assisted analysis, summarisation, explanation, drafting and operator-controlled workflows using a Customer Connected AI Service.
“AI Output” means any text, analysis, summary, explanation, recommendation, command, script, configuration, draft artefact, embedding or other material generated by or returned from a Customer Connected AI Service through the AI Center.
“Applicable Law” means all laws and binding regulatory requirements applicable to a party, the Customer Environment, the Customer Content or the relevant use of the AI Center, including applicable data protection, cybersecurity, artificial intelligence, intellectual property, export control and sanctions laws.
“Authorised Administrator” means a person authorised by the Customer to accept contractual terms on the Customer’s behalf and to enable, configure or administer the AI Center.
“Customer” means the legal person or organisation that holds the applicable rConfig licence and on whose behalf the AI Center is enabled or used.
“Customer Connected AI Service” means a hosted or self-hosted model, Model Provider, inference service, embedding service, vector service or related artificial intelligence service selected, procured, configured and controlled by the Customer and connected to the AI Center using Customer Credentials or a Customer-controlled endpoint.
“Customer Content” means all data, prompts, instructions, device configurations, configuration history, credentials, metadata, operational records, files and other content that the Customer elects to process through the AI Center or a Customer Connected AI Service.
“Customer Credentials” means API keys, tokens, certificates, secrets, account identifiers or other authentication material supplied or controlled by the Customer for access to a Customer Connected AI Service.
“Customer Environment” means the Customer-controlled systems, networks, infrastructure and local rConfig deployment in which the AI Center operates.
“Model Provider” means the third party or Customer-controlled operator that supplies or operates a Customer Connected AI Service.
“Usage Metadata” means technical and administrative information relating to licensing, feature activation, software version, acceptance events, account identifiers, security events and feature availability, but expressly excludes Customer Content, prompts, device configurations and AI Output.
2. Purpose and Intended Use
The AI Center is intended to assist qualified network, infrastructure and security professionals with analysis, understanding, investigation, summarisation, drafting and operator-controlled automation workflows.
The AI Center is an assistive tool. It is not an autonomous network management system, a change control authority, a substitute for qualified engineering judgement or a source of authoritative technical, legal, regulatory or security advice.
The intended use of the AI Center requires meaningful human oversight, independent validation and the Customer’s established approval, testing, backup and rollback controls.
3. Licence Dependency and Access
Use of the AI Center is permitted only while the Customer holds a valid licence for an eligible rConfig product edition and remains in compliance with the rConfig License Agreement.
The Customer must restrict access to authorised users and is responsible for all activity performed through its accounts, roles and local deployment. The Customer must promptly disable access for persons who are no longer authorised.
Suspension, expiration or termination of the underlying rConfig licence automatically suspends or terminates the Customer’s right to use the AI Center.
4. Direct Customer-to-Provider Architecture
4.1 Direct and exclusive data path
The AI Center is designed so that Customer Content and AI Output travel directly and exclusively between the Customer Environment and the endpoint of the Customer Connected AI Service configured by the Customer.
4.2 No rConfig intermediary
At no time will Customer Content or AI Output be received, routed, proxied, relayed, transmitted, stored, cached, logged, inspected or otherwise processed through any infrastructure, API, cloud service, telemetry service, support system or other service operated by or on behalf of rConfig.
4.3 Local control
Any prompts, interaction history, Customer Credentials, AI Output or related records stored by the AI Center are stored only within the Customer Environment and remain under the Customer’s control. The Customer controls local access, retention, deletion, backup and recovery.
4.4 No automated support disclosure
The AI Center will not automatically send Customer Content or AI Output to rConfig for support, diagnostics, telemetry, licensing, product improvement or any other purpose. If the Customer deliberately provides such material to rConfig outside the AI Center in connection with a support request, that separate disclosure will be governed by the rConfig License Agreement, applicable Data Processing Agreement and privacy notice.
4.5 Architecture commitment
rConfig will not change the AI Center under this Addendum to route Customer Content or AI Output through an rConfig-operated service. Any future offering involving such routing must be a separately identified and optional service governed by a separate written agreement and separately enabled through an explicit action by an Authorised Administrator. It will not be enabled by default, by a software update, by continued use or by a general update to this Addendum.
5. Customer Connected AI Services
The Customer selects and controls every Customer Connected AI Service. The Customer is responsible for evaluating whether each service, model, deployment method and processing region is appropriate for the Customer’s requirements and intended use.
Without limiting the foregoing, the Customer is responsible for:
- entering into and complying with the Model Provider’s contract, licence, acceptable use policy, privacy terms and data processing terms;
- obtaining all accounts, subscriptions, permissions and licences required to use the selected model or service;
- configuring provider settings concerning retention, model training, human review, regional processing, security and content use;
- verifying the provenance, licence, maintenance status and suitability of any open weight or self-hosted model;
- providing and maintaining the hardware, software, network capacity, patches, monitoring and security required for any Customer-hosted deployment; and
- monitoring Model Provider changes, deprecations, incidents, policy changes and service limitations.
A Customer Connected AI Service is procured or operated directly by the Customer. Unless expressly stated in a separate written agreement, the Model Provider is not an rConfig subcontractor or subprocessor, and rConfig is not the Model Provider’s agent, reseller or representative.
The inclusion of a connector, compatibility option, provider name or model identifier in the AI Center does not constitute an endorsement, certification or warranty by rConfig.
6. Customer Credentials, Accounts and Provider Charges
The Customer must use its own Customer Credentials and its own account or deployment for each Customer Connected AI Service. Customer Credentials remain within the Customer Environment and are never transmitted to or held by rConfig.
The Customer is responsible for:
- protecting Customer Credentials against unauthorised access, disclosure and misuse;
- restricting credentials to the minimum permissions and scope reasonably required;
- rotating or revoking credentials when compromise is suspected or access is no longer required;
- ensuring that only authorised users may configure endpoints or credentials; and
- reviewing provider usage, billing, quotas, rate limits and account activity.
All fees, token charges, hosting costs, network charges, infrastructure costs, taxes and other amounts charged by a Model Provider or arising from a Customer Connected AI Service are payable solely by the Customer. rConfig does not control those charges and is not required to reimburse them.
Usage estimates, token counts or cost information displayed by the AI Center are informational only and may differ from the Model Provider’s final measurement or invoice.
7. Customer Content and Data Responsibility
7.1 Customer control
The Customer determines what Customer Content is submitted to a Customer Connected AI Service and remains responsible for that decision. rConfig does not select, review or approve Customer Content.
7.2 Rights and lawful processing
The Customer must ensure that it has all rights, permissions, licences, notices, consents and lawful bases required to collect, use, disclose, transmit and otherwise process Customer Content through the selected Customer Connected AI Service.
7.3 Sensitive information
Before enabling or using the AI Center, the Customer must assess whether Customer Content contains or may reveal credentials, private keys, tokens, personal data, special category data, regulated information, confidential information, export-controlled material or third-party proprietary information.
The Customer must apply appropriate minimisation, masking and redaction before transmission. The Customer must not rely on the AI Center or a Model Provider to identify or remove sensitive information. Any detection, masking or redaction feature may be incomplete.
7.4 Provider data practices
The Customer is responsible for understanding and configuring how the Model Provider collects, uses, retains, trains on, discloses, transfers and deletes Customer Content and AI Output. Provider data practices are governed by the Customer’s direct arrangement with that Model Provider.
7.5 Personal data
Where Customer Content contains personal data, the Customer is responsible for determining the data protection roles of the Customer and Model Provider, implementing any required data processing agreement and transfer mechanism, responding to data subject rights and completing any required risk or impact assessment.
7.6 No rConfig model training
Because rConfig never receives Customer Content or AI Output through the AI Center, rConfig cannot and will not use that material to train, fine-tune, evaluate or improve any model, product or service.
8. Third-Party Models and Services
Model Providers and Customer-hosted models operate independently of rConfig. Their models, safeguards, pricing, availability, geographic processing, behaviour and quality may change without notice.
To the maximum extent permitted by law, rConfig does not warrant or accept responsibility for a Customer Connected AI Service, including its availability, security, confidentiality, data practices, legality, compatibility, accuracy, output, continued availability or fitness for the Customer’s purpose.
rConfig may update or discontinue a connector where reasonably necessary because of provider changes, security risk, legal requirements, technical incompatibility or product maintenance. rConfig does not guarantee support for every model, model version, endpoint or provider feature.
9. Nature and Limitations of AI Output
AI Output is machine-generated and probabilistic. It is not independently verified by rConfig and must be treated as an assistive draft requiring qualified human review.
AI Output may:
- be factually incorrect, incomplete, misleading, fabricated or outdated;
- misinterpret device syntax, topology, dependencies, operational context or vendor documentation;
- omit material risks, prerequisites, exceptions, side effects or rollback requirements;
- contain insecure, destructive, unsupported or operationally unsafe commands;
- reflect bias, limitations or policy decisions of the selected Model Provider;
- differ when the same or similar input is submitted more than once; and
- resemble or reproduce material associated with third parties.
No AI Output is authoritative technical advice, a warranty, a certification, an assurance of compliance or a representation by rConfig concerning the Customer Environment.
10. Human Oversight and Operator-Controlled Automation
All AI Output that may affect a device, configuration, system, security control, network state or operational decision must be reviewed and approved by a qualified person before use.
Before using AI Output, the Customer must:
- verify the source data, assumptions, syntax, device scope and intended effect;
- compare the AI Output against authoritative vendor documentation and applicable internal standards;
- test proposed commands, scripts and configurations in an appropriate non-production or controlled environment;
- apply the Customer’s normal change approval, separation of duties and maintenance window procedures;
- maintain current backups and a tested rollback or recovery procedure; and
- monitor execution and validate the resulting operational state.
After qualified human review and approval, the Customer may schedule or automate execution using available rConfig functionality. Unattended execution after approval does not reduce the Customer’s responsibility for scope, testing, safeguards, rollback, monitoring and consequences.
The AI Center itself is not a change approval authority. The Customer must not configure the AI Center so that unreviewed AI Output is automatically applied to production infrastructure.
11. AI-Specific Security Risks
Customer Content may include malicious, misleading or hidden instructions capable of influencing AI Output. Neither the AI Center nor the selected model can be relied upon to detect all prompt injection, poisoned context, adversarial input, unsafe commands, model manipulation or data exfiltration attempts.
The Customer must:
- use least-privilege accounts, roles, Customer Credentials and execution permissions;
- restrict outbound connections to approved Model Provider endpoints;
- use appropriate transport security, certificate validation, network segmentation and monitoring;
- prevent untrusted users or data sources from silently altering prompts, retrieved context or instructions;
- review logs and provider account activity for unusual or unauthorised use; and
- disable the AI Center or affected credentials promptly when compromise or unsafe behaviour is suspected.
12. Restricted and Prohibited Use
The Customer must not use the AI Center:
- as a safety component or as the sole or autonomous control mechanism for critical infrastructure, life-safety systems or systems whose failure could reasonably cause death, personal injury, material environmental harm or serious property damage;
- for any prohibited artificial intelligence practice or high-risk use under Applicable Law unless rConfig has separately agreed in writing and all applicable legal and conformity requirements have been satisfied;
- to make or materially influence decisions about an identifiable person concerning employment, access to essential services, credit, insurance, healthcare, education, law enforcement, migration, biometrics or other legally protected interests;
- to generate, deploy or facilitate malware, exploits, destructive code or unauthorised offensive security activity;
- to access, compromise, disrupt or interfere with systems without lawful authority;
- to submit content that the Customer is not lawfully entitled to process;
- to circumvent licensing, entitlement, usage, authentication or security controls;
- to extract or use rConfig system prompts, templates or protected components to create a competing product or service, except to the extent restriction is prohibited by mandatory law;
- to resell AI Center capacity as a standalone service; or
- in violation of Applicable Law, the rConfig License Agreement or the Model Provider’s terms.
This section does not prevent authorised security testing, use of a Customer-owned model, lawful interoperability work or the provision of managed services expressly permitted under an applicable rConfig MSP or Vector licence.
Use by a Customer operating in a critical infrastructure sector is not prohibited solely for that reason, provided the AI Center remains an assistive tool subject to the human review and operational controls required by this Addendum and is not used as a safety component or autonomous control mechanism.
13. Regulatory Compliance and AI Literacy
Each party is responsible for the legal and regulatory obligations that apply to its own activities and matters within its control. Nothing in this Addendum transfers to the Customer an obligation that Applicable Law places on rConfig, or transfers to rConfig an obligation arising from the Customer’s selection or use of a Customer Connected AI Service.
The Customer is responsible for assessing its intended use, determining whether it is acting as a deployer or other regulated operator, and determining whether the selected model and use are prohibited, high-risk or subject to transparency, documentation, logging, impact assessment or human oversight obligations.
The Customer must ensure that users and administrators have appropriate technical knowledge, experience, education and training concerning AI capabilities, limitations, security risks and required human oversight.
The Customer must preserve any AI-generated labels, notices and provenance information provided by the AI Center and make any additional disclosures required when AI Output is shared, published or used.
AI Output must not be used as the sole basis for a regulatory certification, compliance conclusion, formal audit finding, security assurance, change record or evidence submitted to a regulator. Independent validation is required.
14. Usage Metadata, Privacy and Acceptance Records
rConfig may process Usage Metadata for licensing, entitlement, feature activation, account integrity, security, support, abuse prevention, software maintenance and acceptance records. Usage Metadata expressly excludes Customer Content, prompts, device configurations and AI Output.
Any Usage Metadata processed by rConfig will be handled in accordance with the applicable rConfig privacy notice, Data Processing Agreement where relevant, security controls and retention schedule. rConfig will not retain personal data for longer than reasonably necessary for the stated purpose or Applicable Law.
A record that a user viewed this Addendum is not, by itself, a record of acceptance. Acceptance is recorded only when the applicable affirmative acceptance action described in section 23 is completed.
Terms and security logging should not include raw Customer Content, prompts, AI Output, Customer Credentials, URL query strings or referrer values containing sensitive information.
15. Intellectual Property
15.1 Customer Content
As between rConfig and the Customer, the Customer retains all rights it holds in Customer Content. The Customer grants no rights to rConfig in Customer Content through the AI Center because rConfig does not receive or process that content.
15.2 Use of AI Output
Subject to the Model Provider’s terms and any third-party rights, the Customer may use, reproduce, modify and implement AI Output for its internal business purposes and for managed services authorised by the applicable rConfig licence.
15.3 No exclusivity or originality assurance
rConfig makes no representation that AI Output is original, unique, protectable by intellectual property rights or free from third-party rights. Similar or identical output may be generated for other persons. The Customer is responsible for reviewing the legal permissibility of its proposed use.
15.4 rConfig technology
rConfig and its licensors retain all rights in the AI Center, rConfig software, interfaces, connectors, system prompts, templates, workflows, documentation, branding and underlying technology. Except for the limited rights granted under the rConfig License Agreement, no rConfig intellectual property is transferred to the Customer.
16. Feature and Connector Availability
Feature and connector availability may vary by product edition, licence tier, software version, Model Provider, deployment architecture, security requirements and technical limitations.
rConfig may modify, replace, suspend or discontinue AI Center functionality or a connector where reasonably necessary for security, legal compliance, provider compatibility, maintenance or product development. Where reasonably practicable, rConfig will provide notice of a material reduction affecting a supported commercial edition.
Nothing in this section permits rConfig to alter the direct customer-to-provider architecture commitment in section 4.5.
17. Usage Limits and Fair Use
Access to AI Center functionality may be subject to documented software quotas, concurrency controls, rate limits or fair use thresholds associated with the applicable rConfig product edition. Such limits are separate from limits and charges imposed by the Model Provider.
rConfig may apply reasonable restrictions where usage materially threatens the stability or security of the rConfig software or is used to circumvent licensing controls. rConfig will make reasonable efforts to notify the Customer before imposing a sustained restriction unless immediate action is reasonably required.
No rConfig overage fee will apply unless it is stated in the applicable order, published pricing or a separate agreement accepted by the Customer.
18. Suspension
rConfig may suspend access to the AI Center where it reasonably believes that continued use presents a material security risk, violates Applicable Law, breaches this Addendum or the rConfig License Agreement, threatens the integrity of the rConfig software or infringes third-party rights.
Where practicable, rConfig will notify the Customer of the reason for suspension and provide a reasonable opportunity to remedy the issue. rConfig may act immediately where delay would increase security, legal or operational risk.
19. Warranties and Disclaimers
The AI Center is provided on the warranty basis stated in the rConfig License Agreement. Except for any express warranty in that agreement, and to the maximum extent permitted by law, the AI Center is provided “as is” and “as available.”
rConfig does not warrant that:
- AI Output will be accurate, complete, current, secure, suitable or free from harmful content;
- the AI Center will identify every risk, error, secret, vulnerability or compliance issue;
- a Customer Connected AI Service will remain available, compatible or unchanged;
- identical or similar input will produce identical or similar AI Output; or
- the AI Center will operate without interruption or error.
Nothing in this Addendum excludes a warranty or remedy that cannot lawfully be excluded.
20. Operational Responsibility
The Customer remains responsible for decisions and actions taken using AI Output, including configuration changes, command or script execution, system upgrades, rollbacks, incident response, security actions, audit conclusions and internal or external reporting.
The Customer is responsible for the design and operation of its change management, access control, backup, recovery, monitoring, business continuity and incident response processes.
This allocation does not exclude responsibility for a loss to the extent directly caused by rConfig’s breach of an express obligation concerning the rConfig software, subject to the exclusions and limitations in the rConfig License Agreement.
21. Limitation of Liability
All exclusions and limitations of liability in the rConfig License Agreement apply to this Addendum and the AI Center. Liability arising from or relating to the AI Center forms part of, and does not create a separate amount in addition to, the aggregate liability cap in the rConfig License Agreement.
To the maximum extent permitted by law and subject to the rConfig License Agreement, rConfig will not be liable for loss or damage caused by or arising from:
- a Customer Connected AI Service, Model Provider or Customer-hosted model;
- the Customer’s selection, configuration or use of a model, provider, endpoint or processing region;
- provider fees, token charges, quotas, suspension, deprecation or account activity;
- Customer Content or the Customer’s failure to minimise, mask, redact or lawfully process it;
- compromise or misuse of Customer Credentials within the Customer’s control;
- reliance on AI Output without the review, testing and approval required by this Addendum; or
- commands, scripts, configurations or other actions approved or executed by the Customer.
Nothing in this Addendum limits liability that cannot lawfully be limited, or expands any liability or remedy beyond that provided by the rConfig License Agreement.
22. Customer Indemnity
Subject to the indemnity procedures in the rConfig License Agreement, the Customer will defend and indemnify rConfig against third-party claims, damages, liabilities and reasonable costs to the extent caused by:
- Customer Content that infringes third-party rights or was processed without required authority;
- the Customer’s unlawful or prohibited use of the AI Center;
- the Customer’s breach of a Model Provider’s contract or licence;
- compromise or misuse of Customer Credentials within the Customer’s control; or
- the Customer’s use of AI Output without the review and approval required by this Addendum.
This indemnity does not apply to the extent a claim was caused by rConfig’s breach of contract, negligence, wilful misconduct or violation of Applicable Law. rConfig must provide prompt notice, reasonable cooperation and control of the defence to the extent stated in the rConfig License Agreement. The Customer may not settle a claim in a manner that admits wrongdoing by, imposes liability on or restricts rConfig without rConfig’s prior written consent, not to be unreasonably withheld.
23. Acceptance and Authority
The AI Center may be enabled only after this Addendum has been expressly accepted through the rConfig customer portal by an Authorised Administrator and acknowledged within the local AI Center workspace as required by the applicable activation workflow.
The person accepting this Addendum represents that they have authority to bind the Customer. An ordinary page view, passive access or failure to disable the feature does not constitute initial acceptance.
rConfig may retain an acceptance record containing:
- the Customer and organisation identifier;
- the accepting user’s identity and account identifier;
- the accepted version and an immutable copy or cryptographic record of that version;
- the timestamp and acceptance method; and
- reasonable security information associated with the acceptance event.
Local users who are not Authorised Administrators may be required to acknowledge operational notices or safe use requirements, but such acknowledgement does not replace organisational acceptance by an Authorised Administrator.
24. Updates to this Addendum
rConfig may update this Addendum to reflect changes in law, security requirements, providers, product operation or commercial terms. rConfig will notify the Customer of material changes through the portal, in-product notice, release documentation or another reasonable channel.
A material change that adversely affects the Customer’s rights or materially increases its obligations will require express reacceptance by an Authorised Administrator, unless the change is required immediately by law or to address a material security risk. Non-material clarifications may take effect on notice.
The direct customer-to-provider architecture and prohibition on routing Customer Content or AI Output through rConfig in section 4 cannot be changed by general notice, continued use, release documentation or passive acceptance. Any departure requires a separately identified optional service and separate express written agreement as stated in section 4.5.
If the Customer does not agree to an update requiring reacceptance, it must discontinue use of the AI Center. Discontinuing the AI Center does not, by itself, terminate the underlying rConfig licence.
25. Termination and Survival
This Addendum terminates when the Customer’s right to use the AI Center or the underlying eligible rConfig licence terminates. On termination, the Customer must stop using the AI Center and revoke or remove Customer Credentials and provider connections that are no longer required.
Termination does not automatically delete records held within the Customer Environment or by a Model Provider. The Customer remains responsible for deletion and retention under its local and provider-controlled systems.
Sections concerning architecture, Customer data responsibility, third-party services, intellectual property, liability, indemnity, acceptance records, governing law and any provision intended by its nature to survive will survive termination.
26. General and Governing Law
This Addendum does not amend pricing, payment, confidentiality, support, governing law, jurisdiction, dispute resolution, assignment, notices or other general provisions of the rConfig License Agreement except where this Addendum expressly states otherwise.
If a provision of this Addendum is unenforceable, it will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions will continue in effect. A failure or delay in enforcing a provision does not waive it.
This Addendum is governed by the law and dispute resolution provisions stated in the applicable rConfig License Agreement.
Acceptance Confirmation
By completing the affirmative acceptance process as an Authorised Administrator and enabling the AI Center, the Customer confirms that it has read, understood and agrees to be bound by this Addendum.