Sample agreement
Xianix Enterprise Licence, Implementation & Support Agreement
0 Parties & nature of this document
This Enterprise Licence, Implementation & Support Agreement (the "Agreement") is entered into between 99x, a software engineering company and the maker of the Xianix platform (the "Provider"), and [Customer Legal Name], of [Address] (the "Customer").
The Agreement combines three elements in one contract: (a) an annual licence to operate the Xianix Supported Distribution in-house, (b) a one-time implementation engagement, and (c) ongoing maintenance and support services. The underlying Xians Agent Control Plane remains open source under the MIT License and is not licensed under this Agreement; plugins developed by or for the Customer remain the Customer's property.
1 Definitions
- Platform
- The Xianix agent-team platform and the official Xianix agent plugin set as published by the Provider, excluding the Xians Agent Control Plane and excluding Customer Plugins.
- Supported Distribution
- The tested, hardened, ready-to-deploy builds of the Platform published by the Provider through the supported release line, together with the updates, hotfixes, and backports delivered under clause 4. The Supported Distribution is licensed under this Agreement; Platform source code openly published by the Provider may be inspected, and used for evaluation and non-commercial purposes, free of charge under the terms accompanying it.
- Control Plane
- The Xians Agent Control Plane, MIT-licensed open-source software self-hosted by the Customer, optionally covered by a separate Xians ACP Commercial Support agreement.
- Customer Plugins
- Agents and plugins built by or for the Customer as standard Claude Code plugins. These are the Customer's property and are out of scope of the licence grant and support obligations except as agreed in writing.
- Licensed Team
- A software delivery team of up to [N] members authorised to use the Platform. The number of Licensed Teams is set in the Order Form.
- Supported Deployment
- A production installation of the Platform on infrastructure the Customer controls. Non-production environments are covered as set out in clause 10.
- Business Hours
- [09:00–17:00, Mon–Fri, Customer's primary timezone], excluding Provider public holidays.
- Response Time
- The time between the Customer logging a valid support request and a Provider engineer acknowledging it and beginning active work — not an automated acknowledgement.
2 Licence grant & restrictions
Subject to payment of the licence fees, the Provider grants the Customer a non-exclusive, non-transferable licence for the Term to install and operate the Supported Distribution in production on infrastructure the Customer controls, for use by the Licensed Teams for the Customer's internal software delivery.
- The licence is per Licensed Team, per year, as set out in the Order Form;
- Production and commercial use of the Supported Distribution requires a current paid licence; evaluation, educational, and non-commercial use of the Platform is free of charge;
- The Customer may not sublicense, resell, or provide the Platform as a service to third parties;
- The Customer may modify configurations, prompts, and guardrail policies for internal use; redistribution of the Supported Distribution or the official agent set is not permitted;
- Nothing in this Agreement restricts the Customer's rights to the MIT-licensed Control Plane or to Customer Plugins.
3 Implementation services & acceptance
The Provider will deliver a fixed-scope implementation engagement as described in the Statement of Work, typically covering:
- Provisioning the Platform on the Customer's infrastructure alongside the Customer's Control Plane installation;
- Integration with the Customer's repositories and lifecycle tooling ([GitHub / Azure DevOps / other]);
- Configuration of guardrails, human checkpoints, and access controls to the Customer's policies;
- Enablement sessions for the Licensed Teams and platform operators;
- Handover against the acceptance criteria in the Statement of Work.
Acceptance occurs when the acceptance criteria are met or when the Customer uses the Platform in production, whichever is earlier. Defects notified within [30 days] of acceptance are remedied at no additional charge.
4 Maintenance & updates ("Xianix Updates")
During the Term, the Provider will:
- Make Platform updates, improvements, and fixes available to the Customer;
- Apply timely dependency and security updates to the supported release line;
- Backport critical fixes and security patches to the Customer's supported version, so the Customer is not forced to take a major upgrade to receive a fix;
- Provide release notes and, for major versions, a tested migration guide covering breaking changes and upgrade steps;
- Flag deprecations at least [one release cycle] in advance.
5 Support & response SLAs
Support is provided in two categories:
- Incident support — for defects and issues affecting the Customer's operation of the Supported Distribution. Incident cases are unlimited in number and handled against the severity-based response targets below;
- Query support — for best-practice, usage, and how-to questions. Queries are answered within [1 business day] and drawn from the advisory-hours allowance in the Order Form; additional hours are available as Additional Services under clause 9.
Incidents are classified by severity. The figures below are illustrative and finalised per engagement.
| Severity | Definition | Standard (9×5) | Enterprise (24×7) |
|---|---|---|---|
| S1 — Critical | Platform down or unusable in production. No workaround. | Same business day | Within 1 hour |
| S2 — High | Major degradation; workaround exists but is painful. | Next business day | Within 4 hours |
| S3 — Medium | Minor impact; a reasonable workaround exists. | 2 business days | 1 business day |
| S4 — Low | Questions, documentation, and feature requests. | 3 business days | 2 business days |
Response targets commit the Provider to begin work, not to a guaranteed resolution time. For S1 incidents the Provider works continuously during the applicable support window until a workaround or fix is in place, with status updates at an agreed cadence ([e.g. every 4 hours for S1]).
6 Security & vulnerability management
The Provider runs automated scanning (SAST and dependency analysis) against the Platform's repositories and conducts periodic manual assessments. Remediation targets are mapped to CVSS severity (illustrative):
- CVSS ≥ 9.0 (Critical): patch or mitigation within [24 hours] of confirmation;
- CVSS 7.0–8.9 (High): within [72 hours];
- CVSS < 7.0: within [30 days] or the next scheduled release.
The Customer receives private vulnerability advisories with remediation guidance ahead of public disclosure, under the confidentiality terms of this Agreement.
7 Data protection (GDPR)
The Platform runs on the Customer's infrastructure; personal data processed by agents in the course of the Customer's delivery work remains under the Customer's control, with the Customer acting as controller.
- Where the Provider accesses Customer systems or data for implementation or support, the Provider acts as a processor under the Data Processing Agreement at [Annex — DPA], which sets out subject matter, duration, purposes, security measures, sub-processors, international-transfer safeguards, and audit rights per Article 28 GDPR;
- Agent reasoning is performed via the Customer's agreed foundation-model arrangement ([Customer's Claude API agreement / other]); the model vendor's data-handling terms apply to that processing and are identified in the DPA;
- The Provider notifies the Customer without undue delay of any personal data breach affecting the Provider's processing.
8 AI regulatory roles (EU AI Act)
The parties allocate roles under Regulation (EU) 2024/1689 as follows:
- The Customer deploys the Platform for its internal software delivery and acts as deployer of the AI system in its use context;
- Obligations attaching to the underlying general-purpose AI model rest with the foundation-model provider ([model vendor]), not with 99x or the Customer;
- The Provider supports the Customer's oversight and transparency duties through the Platform's design: inspectable prompts, explicit human checkpoints, and recorded agent activity;
- If the Customer intends to use the Platform in a context that may be classified as high-risk under the AI Act, the parties will agree additional measures in writing before such use.
9 Fees & payment
Fees comprise the annual platform licence, the one-time implementation fee, and the annual maintenance & support fee. The figures below are illustrative and confirmed in the Order Form:
| Component | Basis | Indicative fee |
|---|---|---|
| Supported distribution licence — first team | Annual, per Licensed Team | from ~USD 60,000 / year |
| Supported distribution licence — each additional team | Annual, per Licensed Team | ~USD 15,000 / year |
| Implementation & integration | One-time, fixed scope per SOW | from ~USD 35,000 |
| Maintenance & support | Annual, per Supported Deployment | from ~USD 18,000 / year |
Fees are exclusive of applicable taxes. Invoiced [annually in advance]; payable within [30] days. Work beyond the agreed scope — custom feature development, bespoke integrations, additional enablement — is provided as Additional Services under a separate statement of work at [rate].
10 Environments
The licence and support cover [N] production deployment(s). Non-production environments (development, test, staging) are included or discounted as set out in the Order Form.
11 Term, renewal & termination
The initial Term is [12 months] from the effective date, renewing for successive [12-month] periods unless either party gives [60 days'] written notice. Either party may terminate for material breach not cured within [30 days] of notice.
On expiry or termination: the Customer's rights to operate the Supported Distribution in production end at the close of the then-current licence period, while free evaluation and non-commercial use remains available; the Customer's Control Plane installation (MIT-licensed) and Customer Plugins are unaffected. The Provider will provide reasonable wind-down assistance, including export of Customer configurations and records, for [60 days] after termination.
12 Exclusions
Unless agreed in writing, support does not cover:
- Defects in Customer Plugins, Customer code, third-party integrations, or foundation-model behaviour;
- Builds the Customer has modified away from the supported release line;
- The Control Plane layer (covered, if desired, by a separate Xians ACP Commercial Support agreement);
- Third-party infrastructure, cloud, networking, or hardware issues;
- Custom development and professional services (handled as Additional Services under clause 9).
13 Confidentiality & IP
Each party protects the other's confidential information with at least the care it applies to its own. The Provider retains all intellectual property in the Platform; the Customer retains all intellectual property in its data, its code, and Customer Plugins. Feedback may be used by the Provider to improve the Platform without identifying the Customer.
14 Warranties & limitation of liability
The Provider warrants that services will be performed in a professional and workmanlike manner and that the Platform will materially conform to its documentation during the Term. AI agent output is probabilistic and reviewed through the Platform's human checkpoints; the Provider does not warrant the correctness of individual agent outputs, and responsibility for accepting or rejecting agent output rests with the Customer's authorised reviewers. To the maximum extent permitted by law, the Provider's aggregate liability under this Agreement is limited to the fees paid by the Customer in the [12 months] preceding the claim. Neither party is liable for indirect or consequential loss. (Final legal terms are set by the parties' counsel.)
15 Signatures
For illustration only. No signature here creates any obligation.
Name: [Name]
Title: [Title]
Date: [Date]
Name: [Name]
Title: [Title]
Date: [Date]