WHEREAS Service Provider has previously developed for Client an AI-driven research system known as "Mímir" which is now operated by Client;
WHEREAS Client wishes to engage Service Provider to design, develop, and progressively iterate on a separate, dedicated AI agent system to support Client's daily research operation for its Viska Macro fund (the "Project");
WHEREAS the Project is intended to evolve over time on the basis of an indicative roadmap, with priorities reviewed monthly, rather than against fixed deliverable dates;
WHEREAS Service Provider is in the process of incorporating Galdr ehf. and intends to assign this Agreement to that entity upon its formation;
NOW, THEREFORE, the Parties agree as follows.
In this Agreement, unless the context otherwise requires:
Service Provider shall provide AI agent system development services to Client for Client's Viska Macro fund research operation, in accordance with the Roadmap and this Agreement.
Service Provider shall perform the services with the degree of skill, care, and diligence reasonably expected of a qualified professional in the field of AI software development. Service Provider does not guarantee any specific outcome, performance metric, profit, return, system uptime, or completion date.
The Roadmap describes the Parties' shared objectives and indicative timeline as of the Effective Date. The Roadmap is directional, not contractual. The Parties may amend the Roadmap by written agreement (email confirmation by both Parties is sufficient) at any time, and any such amendment supersedes the corresponding portions of the Roadmap on a going-forward basis.
The Parties shall meet on or about the first business day of each calendar month to review progress against the Roadmap, discuss adjustments, and document priorities for the upcoming month. Documented outcomes of the monthly review are deemed Roadmap amendments per Section 3.3 to the extent consistent in form.
The Parties acknowledge that the Project is iterative and that no deliverable is conditioned upon Client's formal acceptance. Client's sole remedy for dissatisfaction with the work is termination per Section 4.3.
Service Provider's obligation is to perform services on a best-efforts basis. Service Provider does not warrant that any particular feature will function as initially conceived, that any particular date will be met, or that any particular benefit will be realized.
This Agreement commences on the Effective Date.
The initial term is three (3) calendar months from the Effective Date (the "Initial Term"). Following the Initial Term, this Agreement continues on a month-to-month basis until terminated in accordance with this Section 4.
Either Party may terminate this Agreement at any time, including during the Initial Term, by providing thirty (30) days' written notice to the other Party. No cause is required.
Either Party may terminate this Agreement immediately upon written notice if the other Party (a) materially breaches this Agreement and fails to cure within fourteen (14) days of written notice describing the breach, or (b) becomes insolvent, files for bankruptcy, or ceases regular business operations.
Upon termination or expiration of this Agreement for any reason:
Both Parties shall cooperate in good faith to effect the handover. Service Provider shall provide up to eight (8) hours of synchronous knowledge-transfer assistance at no additional charge. Further assistance is billable at Service Provider's then-current hourly rate. Client shall procure its own infrastructure (Git hosting, database hosting, credentials, third-party platform accounts) sufficient to receive the Handover Deliverables prior to the handover date.
Client shall pay Service Provider a monthly fee of ISK 1,200,000 (one million two hundred thousand Icelandic krónur) plus applicable VAT (the "Service Fee"). The Service Fee covers Service Provider's professional services and all infrastructure, tooling, hosting, third-party software, and operational costs incurred by Service Provider in performing the services, except as set out in Section 6.4 (Client-Provided Resources) and Section 16.4 (Client-Procured Components).
Service Provider shall issue an invoice on or about the first business day of each calendar month for that month's services. Invoices are payable within fourteen (14) days of the invoice date. Late payments accrue interest at the rate set out in Icelandic Act no. 38/2001 on Interest and Price Indexation.
Invoices are denominated in ISK. VAT treatment is per Section 5.4.
As of the Effective Date, Service Provider operates as a German-resident sole-trader / Freiberufler. The Parties acknowledge that, during this bridge period and prior to the assignment to Galdr ehf. per Section 18, the supply of services from a German-established service provider to an Icelandic-established business customer falls outside the scope of German VAT under §3a paragraph 2 of the German Value Added Tax Act (UStG), with VAT accounted for in Iceland by the recipient under the reverse-charge mechanism in accordance with Icelandic VAT law. Service Provider shall accordingly issue invoices without German VAT and with a reverse-charge notation, and Client shall account for any applicable Icelandic VAT.
Upon assignment to Galdr ehf. per Section 18, invoices shall thereafter be issued by Galdr ehf. as a domestic Icelandic supplier to a domestic Icelandic recipient, with Icelandic VSK at the prevailing rate (currently 24%) added to invoiced amounts.
The Parties shall cooperate on reasonable invoice-format adjustments needed for VAT compliance. Treatment in this Section 5.4 is subject to confirmation by qualified tax advisors and shall be modified by written amendment if such confirmation requires a different approach.
Client shall pay all invoiced amounts in full without set-off, counterclaim, or deduction, except as required by applicable law.
Client shall procure, maintain, and bear all costs of the Client-Provided Resources specified in Schedule C, which are required for Service Provider's performance of the services.
Client grants Service Provider access to the Client-Provided Resources for the duration of this Agreement. Service Provider shall use such access solely for performance of this Agreement and shall not use the Client-Provided Resources for any other purpose.
Client retains administrative ownership of the Client-Provided Resources. Service Provider shall not transfer, share, or expose access credentials for Client-Provided Resources to any third party.
Service Provider shall monitor Service Provider's use of Client-Provided Resources and shall promptly notify Client if usage trends unexpectedly toward limits or budget thresholds.
Client bears all usage costs for Client-Provided Resources arising from operation of the System within reasonable parameters. Service Provider is liable for usage costs caused by Service Provider's gross negligence or willful misconduct, subject to the cap in Section 13.3.
Client bears the risk of insufficient capacity, rate-limit exhaustion, or service interruption attributable to the Client-Provided Resources or to the Client-Procured Components in Schedule F.2.
The System is designed to switch between language-model inference providers (for example via OpenRouter or equivalent abstraction) such that an outage at any single inference provider does not, in itself, cause a System-wide outage. Service Provider's commitment in this Section is best-efforts; Service Provider is not liable for cascading failures across multiple inference providers, for outages of the OpenRouter-equivalent abstraction itself, or for failures attributable to Client-Provided Resources.
Each Party retains all rights in its Background IP. Service Provider's Background IP includes (without limitation) Pantheon, generic agent patterns, reusable skills, development tooling, and Service Provider's open-source contributions. Client's Background IP includes (without limitation) Client's fund data, the Mímir corpus, the Viska Screener framework, Client's brand assets, and Client's pre-existing systems.
Subject to Section 7.3 and Client's payment in full of invoiced fees, Service Provider assigns to Client all rights in the Client Deliverables. Client owns all data the System processes for Client.
Service Provider retains:
The System delivered under this Agreement consists solely of (i) configurations and code authored specifically for the Project, (ii) third-party open-source and licensed components used as runtime dependencies, and (iii) Project-specific data, schemas, and operational records. The System does not contain any portion of Pantheon, Service Provider's internal tooling, or shared infrastructure used across Service Provider's other engagements.
The Mímir corpus and the Viska Screener framework are Client's Background IP. Service Provider's access during the Project is read-only for integration purposes only.
The Project Repositories are hosted by Service Provider during the Term on infrastructure controlled by Service Provider. The Project Repositories are isolated from Pantheon and from other Service Provider clients' code at the repository level. Client receives read access to the Project Repositories upon request during the Term.
Upon termination, Service Provider shall transfer ownership of the Project Repositories to Client by either (i) initiating a repository transfer to Client's hosting account on the same platform, or (ii) providing Client with a complete Git bundle of the repositories for Client's import into Client-controlled hosting. Method is at Service Provider's discretion unless the Parties agree otherwise.
Service Provider shall provide Client with a complete snapshot of the Client Database in a standard portable format. The Client Database is operated on infrastructure dedicated to the Project, such that the snapshot may be transferred in full without partitioning or redaction.
Notwithstanding the assignment in Section 7.2, Client grants Service Provider a perpetual, irrevocable, worldwide, non-exclusive, royalty-free license to use the general knowledge, methodologies, and non-Client-specific techniques developed during the Project for the purpose of evolving Service Provider's products and serving other clients. This license does not extend to Client's Confidential Information, Client-specific configurations or code, fund data, trading strategy, the Mímir corpus, the Viska Screener framework, or any artifact identifiable as belonging to Client. Service Provider shall not represent that Client endorses or is associated with any subsequent Service Provider product.
Service Provider shall provide Client with a list of all open-source components used in the Client Deliverables and their respective licenses as part of the Project Documentation under Schedule E. Client's use of such components is governed by their original licenses.
"Confidential Information" means non-public information disclosed by one Party to the other in connection with this Agreement, including (without limitation) Client's fund positions, NAV history, trading strategy, LP information, client lists, the contents of the Mímir corpus, the Viska Screener framework, and Client's pre-existing systems; and Service Provider's technical architecture, source code, methodologies, pricing, internal tooling, and Pantheon.
Each Party shall (a) hold the other's Confidential Information in strict confidence, (b) use it only to perform under this Agreement, (c) limit access to personnel and advisors with a need to know who are bound by confidentiality obligations at least as protective as this Section, and (d) protect it with the same degree of care it uses for its own Confidential Information of similar sensitivity, but no less than reasonable care.
Confidential Information does not include information that (a) is or becomes publicly known through no fault of the receiving Party, (b) was known to the receiving Party prior to disclosure without confidentiality obligation, (c) is rightfully received from a third party without confidentiality obligation, or (d) is independently developed without use of the disclosing Party's Confidential Information.
The receiving Party may disclose Confidential Information to the extent required by law, regulation, or court order, provided it gives the disclosing Party prompt written notice (where lawful) and cooperates with reasonable efforts to limit the scope of disclosure.
Confidentiality obligations survive termination of this Agreement for five (5) years, except for trade secrets and Client's investment data, which remain confidential for as long as they retain trade-secret or sensitive-financial status under applicable law.
Each Party shall comply with applicable data protection laws, including the Icelandic Act on the Protection of Privacy as regards the Processing of Personal Data and Iceland's implementation of the EU General Data Protection Regulation (GDPR), in performing this Agreement.
The Parties acknowledge that the Project, in its initial scope, primarily processes commercial fund data (positions, NAV, market data, news content, technical-analysis outputs) and is not expected to process material volumes of personal data. To the extent personal data is processed (for example LP names or contact records contained in the Mímir corpus), the Parties shall enter into a Data Processing Agreement (DPA) substantially in the form to be agreed prior to such processing commencing.
Service Provider shall use reasonable efforts to ensure that Client Database storage and processing occur within the European Economic Area (EEA). Cross-border processing outside the EEA, where necessary for service operation, shall be subject to appropriate safeguards (Standard Contractual Clauses or equivalent).
The Parties shall cooperate on a reasonable basis to respond to requests by data subjects exercising rights under applicable data-protection law.
Service Provider shall implement and maintain reasonable security measures appropriate to the nature of the data processed, in accordance with the security best practices set out in Schedule G. Such measures include (without limitation):
Service Provider shall implement controls reasonably designed to detect and prevent unauthorized access by external actors, including (without limitation) gateway-level authentication for the client portal, row-level security policies on the Client Database where the underlying platform supports them, rate limiting on public endpoints, and rejection of unauthenticated database connections from public networks.
Service Provider shall notify Client without undue delay (and in any event within seventy-two (72) hours) after becoming aware of any actual or reasonably suspected security incident materially affecting the Client Database, the System's authentication, or Client's Confidential Information. The notification shall describe the nature of the incident, the data and systems affected, the steps taken to contain it, and proposed remediation.
Client shall cooperate in good faith with Service Provider's security measures, including procuring its own access credentials promptly, applying multi-factor authentication on Client-administered systems where available, and notifying Service Provider promptly of suspected compromise of Client's own accounts.
Service Provider does not warrant that the System or its operations are immune to compromise. Section 10 sets out a standard of reasonable care, not a guarantee of outcome.
Service Provider shall configure automated backups of the Client Database and the Project Repositories with the following characteristics:
Because backups are written to Client-owned storage, Client retains independent access to backup data at all times, including after termination. Service Provider shall not be the sole holder of backup material.
Service Provider shall make operational audit information visible to Client through the client portal interface that forms part of the System. Such information shall include (at minimum):
On reasonable written request, Service Provider shall provide further audit information not available through the portal, subject to reasonable scope and a reasonable response window.
The Parties acknowledge and accept the disaster scenarios and corresponding mitigation approaches set out in Schedule H. Schedule H reflects the System's design assumptions and is not a service-level commitment unless explicitly stated therein.
The System is designed to switch between inference providers via OpenRouter or equivalent abstraction, such that an outage at any single inference provider should not, in itself, cause a System-wide outage. Service Provider's commitment in this Section is best-efforts.
The System depends on third-party platforms (Railway, Supabase, n8n, and others) for which Service Provider is not the operator. In the event of an outage of any such platform, Service Provider shall (a) communicate the outage status to Client through the client portal or other agreed channel, (b) follow the platform vendor's recommended remediation, and (c) where reasonable, switch to a fallback configuration. Service Provider is not liable for the duration or consequences of platform outages outside Service Provider's reasonable control.
In the event of catastrophic data loss attributable to the Client Database, Service Provider shall restore from the most recent available backup (per Section 11.1) on a best-efforts basis. Recovery point objective (RPO) is no greater than twenty-four (24) hours under normal operating conditions.
Sections 12.1 through 12.4 are best-efforts commitments. No specific service-level agreement (uptime percentage, response time, recovery time) applies unless separately documented in writing and signed by both Parties.
The services and any outputs from the System are informational tools for Client's internal use. Nothing in this Agreement constitutes investment advice, financial advice, regulatory advice, or a recommendation to buy, sell, or hold any security or financial instrument. All investment, trading, and portfolio decisions are made solely by Client and its personnel. Service Provider is not registered or regulated as an investment advisor, broker-dealer, or financial intermediary in any jurisdiction.
No fiduciary, agency, or advisory relationship is created by this Agreement.
Client confirms that it has the expertise, regulatory permissions, and internal controls necessary to operate as a fund manager and that all use of System outputs is subject to Client's own review, judgment, and risk-management framework.
The aggregate liability of each Party under this Agreement, whether in contract, tort (including negligence), strict liability, or otherwise, is limited to the total fees paid or payable by Client to Service Provider under this Agreement during the three (3) months immediately preceding the event giving rise to the claim.
Neither Party is liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for loss of profits, loss of trading opportunities, market losses, loss of goodwill, loss of data (except as recoverable from backups per Section 11), or business interruption, even if advised of the possibility of such damages.
Sections 13.3 and 13.4 do not apply to:
Service Provider shall defend, indemnify, and hold harmless Client from and against third-party claims to the extent arising from Service Provider's infringement of any third party's intellectual property rights through the Client Deliverables (excluding (i) infringement caused by Client-supplied materials, (ii) modifications made by Client or by third parties on Client's instruction, and (iii) use of the Client Deliverables in combination with materials not provided by Service Provider where the combination is the cause of infringement).
Client shall defend, indemnify, and hold harmless Service Provider from and against third-party claims to the extent arising from (a) Client's use of the System's outputs in violation of applicable law, (b) inaccuracy of Client-supplied data (including position records, fund data, and the Mímir corpus), or (c) Client's investment, trading, or portfolio decisions.
The Party seeking indemnification shall (a) give prompt written notice of the claim, (b) grant the indemnifying Party sole control of the defense and settlement (provided that no settlement adversely affecting the indemnified Party's rights may be entered without that Party's consent, not unreasonably withheld), and (c) provide reasonable cooperation at the indemnifying Party's expense.
The Parties acknowledge that the System, in its initial scope, is an internal informational tool for Client's research operation. The System does not place orders, transmit trade instructions, hold or move client capital, or provide investment recommendations to third parties. Accordingly, the initial phases of the Project are not within the scope of regulated investment-services activities under Icelandic, German, or EU law as applied to Service Provider.
If the Project's scope expands to include features that may bring the System within regulated activity — for example execution capability, automated order placement, advisory output to third parties, or capital movement — the Parties shall, before such scope expansion takes effect, conduct a regulatory compliance review and agree in writing on the additional measures required. Such measures may include licensing, registration, structural changes, additional indemnities, additional insurance, or commercial terms reflecting the change in risk profile.
Compliance certifications, regulatory audits, registrations with financial supervisory authorities (including Iceland's Fjármálaeftirlitið / FME and Germany's BaFin), and similar regulated-activity preparations are out of scope for the initial Project phases. Service Provider shall give Client reasonable notice if Service Provider becomes aware that any feature being built or maintained may push the System into regulated territory.
Each Party warrants that it shall comply with applicable anti-bribery, anti-corruption, and economic sanctions laws in performing this Agreement.
At any time within thirty (30) days before or after the termination or expiration date, Client may elect, by written notice to Service Provider, to engage Service Provider for ongoing operation, hosting, monitoring, and maintenance of the System (the "Maintenance Services").
The fee for Maintenance Services (the "Maintenance Fee") is agreed in writing by the Parties at the time Maintenance Services commence, taking account of the composition of the System's tech stack at handover. As an indicative reference, Service Provider's expected Maintenance Fee for a stack consistent with the Indicative Maintenance Stack in Schedule F is approximately ISK 100,000 per month plus VAT. Where the actual stack at handover materially differs from the Indicative Maintenance Stack, the Maintenance Fee shall be adjusted to reflect the difference, on a basis to be agreed in good faith.
The Maintenance Fee is all-inclusive for Service Provider's labor and the operation of services in the agreed tech stack, and shall not increase as a function of System usage volume, agent count, workflow count, data volume, or feature additions falling within the scope of this Section. It includes:
The Maintenance Fee does not cover, and Client shall procure and pay directly for, the items in Schedule F.2 (Client-Procured Components), and the following are out of scope and require a separate written statement of work:
If the Parties agree to add a new service to the tech stack during Maintenance Services that creates ongoing operational obligations for Service Provider, the Parties shall discuss in good faith whether and how the Maintenance Fee should adjust. Service Provider shall not unilaterally raise the Maintenance Fee.
The maintenance engagement runs month-to-month, terminable by either Party on thirty (30) days' written notice.
Maintenance Services are provided on a best-efforts basis during Service Provider's regular business hours. No specific service-level agreement applies unless separately documented. Service Provider undertakes to (a) acknowledge operational incidents reported in writing within one (1) business day, (b) restore service from outages caused by the System or Service Provider's operations using reasonable efforts, and (c) provide monthly written status.
Service Provider may decline to offer or continue Maintenance Services in its sole discretion. Decline does not prejudice Client's rights under this Agreement.
Nothing in this Section grants Service Provider a right of first refusal or exclusivity.
If Client elects per Section 16.1 prior to the termination date, Service Provider may continue operating the System during the election window at the then-current Service Fee, prorated daily, for up to thirty (30) days. If a maintenance engagement is not commenced within that period, the engagement terminates and Handover Deliverables transfer per Section 4.5.
Neither Party shall be liable for failure to perform, or delay in performance of, any obligation under this Agreement (other than payment obligations) caused by acts of God, war, terrorism, civil disturbance, natural disaster, government action, or other event beyond that Party's reasonable control. Such events expressly include outages of multiple inference providers occurring simultaneously and outages of multiple platform vendors (Railway, Supabase, n8n, or equivalents).
The affected Party shall give prompt written notice of the force majeure event and shall use reasonable efforts to mitigate the impact and resume performance as soon as practicable.
If a force majeure event continues for more than thirty (30) consecutive days, either Party may terminate this Agreement by written notice without further liability, except for accrued obligations and surviving provisions per Section 4.5.
Except as provided in Section 18.2 and Section 18.3, neither Party may assign this Agreement without the other Party's prior written consent.
Client consents in advance to Service Provider's assignment of this Agreement, in whole, to Galdr ehf. (an Icelandic einkahlutafélag in formation as of the Effective Date) upon issuance of Galdr ehf.'s registration number ("kennitala") by Iceland Companies Registry. Service Provider shall give Client written notice of the assignment, attaching evidence of the kennitala, and the assignment takes effect on the date of such notice. Following the assignment, Galdr ehf. assumes all of Service Provider's rights and obligations under this Agreement, and Service Provider in his personal capacity is released from future performance obligations, except for liabilities accrued prior to the assignment.
The terms of this Agreement, including the Service Fee, Term, all Schedules, and the Maintenance Option, continue without interruption upon assignment. Invoicing transitions from Service Provider's personal entity to Galdr ehf. on the effective date of the assignment, with VAT treatment adjusted as set forth in Section 5.4.
Either Party may assign this Agreement to a successor entity in connection with a merger, acquisition, or reorganization, on written notice and without consent, provided that the successor assumes all obligations under this Agreement.
All notices under this Agreement shall be in writing and shall be sent by email (with delivery confirmation) or by recognized courier to the addresses set out in Schedule B, as updated from time to time by written notice.
Notices are deemed received on (a) the date of delivery confirmation for email, or (b) the date of courier delivery.
This Agreement is governed by and construed in accordance with the laws of Iceland, without regard to conflict-of-laws principles.
The Parties shall attempt in good faith to resolve any dispute arising out of or relating to this Agreement through direct negotiation between authorized representatives. If the dispute is not resolved within thirty (30) days, the Parties shall attempt to resolve it through mediation administered by a mediator agreed between them or, failing agreement, appointed by the Reykjavík District Court.
If mediation does not resolve the dispute within sixty (60) days of commencement, either Party may bring the matter before the Reykjavík District Court (Héraðsdómur Reykjavíkur), which shall have exclusive jurisdiction.
Notwithstanding Section 20.2, either Party may seek injunctive or other equitable relief from any court of competent jurisdiction in respect of breach or threatened breach of intellectual property rights or confidentiality obligations.
This Agreement, including all Schedules, constitutes the entire agreement between the Parties with respect to its subject matter and supersedes all prior agreements, negotiations, and understandings.
Any amendment to this Agreement must be in writing and signed by authorized representatives of both Parties. Roadmap amendments per Section 3.3 may be made by exchange of confirming emails between named representatives.
If any provision of this Agreement is held invalid or unenforceable, the remaining provisions remain in full force and effect, and the invalid provision shall be replaced by a valid provision that most nearly reflects the original intent.
A Party's failure to enforce any provision of this Agreement is not a waiver of that or any other provision.
The Parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, employment, or agency relationship.
This Agreement may be executed in counterparts, each of which is an original, and may be signed electronically with the same legal effect as a handwritten signature.
This Agreement is executed in English. Should the Parties agree to prepare an Icelandic translation, the English version shall be controlling unless the Parties expressly agree otherwise in writing.Review note: subject to Service Provider's preference; can be flipped to Icelandic-controlling.
Headings are for convenience only and do not affect interpretation.
This Agreement does not confer rights on any third party.
By: _______________________
Name: Boas [Surname]
Capacity: Sole-trader / Freiberufler, with intent to assign to Galdr ehf. per Section 18
Date: _______________________
By: _______________________
Name: [CIO name], Viska sjóðir ehf.
Capacity: [title]
Date: _______________________
This Schedule references the working roadmap documents previously shared. The Roadmap is directional, not a fixed set of deliverables, per Section 3.3.
The Project Roadmap is set out in the following companion documents:
Phase 1, as adapted by mutual understanding between the Parties, comprises:
The Roadmap is reviewed monthly per Section 3.4 and may be amended in writing.
Notices addressed to Service Provider during the bridge period are valid; notices addressed to Galdr ehf. become valid upon assignment per Section 18.
The following are required for Service Provider's performance of the services. Client procures, maintains, and bears the cost of each. Client retains administrative ownership and grants Service Provider access for the duration of this Agreement.
Client shall provide credentials, scope, and reasonable usage limits for each of the above. Client shall promptly inform Service Provider of changes.
A specimen invoice issued under this Agreement shall include:
A specimen template shall be agreed between the Parties prior to issuance of the first invoice.
Upon termination per Section 4.5, Service Provider shall transfer the following:
Indicative basis for the Maintenance Fee referenced in Section 16.2. Composition at handover may vary.
Service Provider procures, operates, and bears the platform cost as part of the Maintenance Fee:
Client procures, pays directly, and grants Service Provider access for operation: per Schedule C.
| Ref | Adjustment Trigger |
|---|---|
| F.3 (a) | Addition of a separate hosting platform requiring distinct operational oversight |
| F.3 (b) | Addition of compliance, audit, or security services requiring Service Provider's ongoing administrative work |
| F.3 (c) | Addition of a second runtime environment (for example a staging copy operated alongside production) |
| F.3 (d) | Removal of a Client-Procured component requiring Service Provider to absorb the cost |
The fee adjustment, if any, is agreed in writing per Section 16.5.
The components in Section F.1 are provisioned per Client and isolated from Service Provider's other engagements at the platform level (separate Supabase project, separate n8n instance, separate Railway project, separate domain). At handover under Section 4.5, the entire stack transfers to Client without partitioning, redaction, or shared-resource extraction.
Service Provider's security measures referenced in Section 10 include the following, applied with reasonable adaptation as the System evolves and as platform capabilities permit:
| Ref | Category | Controls |
|---|---|---|
| G.1 | Authentication & Access Control | Multi-factor authentication required on all Service Provider developer and operator accounts; named-user authentication for administrative access; no shared accounts; principle of least privilege for all roles; periodic review of access rights; revocation of access on personnel changes. |
| G.2 | Credential Hygiene | Secrets stored in dedicated secret stores (platform-managed environment variables, vault, or equivalent); secrets never committed to source-code repositories; secrets never written to logs or audit output; rotation of long-lived credentials on a defined schedule. |
| G.3 | Transport Security | TLS 1.2 or higher for all client-facing endpoints and inter-service communication; HSTS enforced on the client portal; modern cipher suites; deprecation of weak algorithms. |
| G.4 | Network & Endpoint Controls | Client portal protected by authenticated entry points; database direct-access disabled from public networks; access only via authenticated application paths or platform-managed connection pools; administrative interfaces restricted by IP allowlist or zero-trust gateway where reasonably available; rate limiting on public endpoints. |
| G.5 | Database Hardening | Row-level security policies enabled on the Client Database where the underlying platform supports them, scoped to ensure that only the System's authenticated processes can read or write Client data; separation of read-only roles from read-write roles; encryption at rest using platform-default mechanisms; audit logging of administrative database actions where the platform supports it. |
| G.6 | Foreign Actor Defense | Client portal authentication required for all data access; anonymous access disabled; geographic anomaly detection where the underlying platform supports it; failed-authentication rate limiting and lockout; rejection of unauthenticated database connections from public networks; monitoring of unusual access patterns; notification per Section 10.3 on suspected compromise. |
| G.7 | Software Hygiene | Timely application of security patches and dependency updates; periodic review of open-source components for known vulnerabilities; removal of unused dependencies and dead code paths. |
| G.8 | Operational Logging | Append-only operational logs for material System actions; retention for at least the term of this Agreement plus one year; logs accessible to Client through the client portal per Section 11; logs include authentication events, configuration changes, data-modifying agent runs, errors, and security-relevant events. |
| G.9 | Backup & Recovery | Backups per Section 11 written to Client-owned storage; backup integrity tested at least quarterly; documented restore procedure included in Schedule E. |
| G.10 | Incident Response | Notification within 72 hours of confirmed or reasonably suspected security incident per Section 10.3; containment, investigation, and remediation steps documented; post-incident report shared with Client within fourteen (14) days of remediation. |
| G.11 | Personnel | All personnel with access to Client Confidential Information bound by confidentiality obligations; background level appropriate to the nature of access (no formal background checks required at the current scale, subject to scaling-up as the engagement evolves). |
Reasonably foreseeable disaster scenarios and Service Provider's mitigation approach. Schedule H is descriptive of design intent, not a service-level agreement, except where explicitly stated.
| # | Scenario | Mitigation | Recovery target |
|---|---|---|---|
| 1 | Client Database corruption or data loss | Restore from most recent automated backup (Section 11.1) to a fresh Supabase project or schema; replay any reproducible operations from Project Repositories | RPO ≤ 24h; recovery time best-efforts |
| 2 | Inference provider (e.g., OpenAI) outage | Automatic switchover to alternative inference provider via OpenRouter or equivalent abstraction | Best-efforts continuity; intermittent agent run failures may occur during switchover |
| 3 | Multiple inference providers down simultaneously | Force majeure per Section 17; agent runs paused; portal remains available for static data | No recovery target; resumes when at least one provider returns |
| 4 | Railway (or replacement hosting) outage | Communication via portal or alternate channel; switch to vendor-recommended remediation; failover where reasonably available | Subject to vendor outage duration |
| 5 | Supabase outage | Communication; vendor remediation; reads may fall back to recent backup snapshot for read-only display | Subject to vendor outage duration |
| 6 | n8n outage | Re-trigger workflows after restoration; persisted state in Client Database means runs are resumable | Subject to vendor outage duration |
| 7 | Repository host (e.g., GitHub) outage | Project Repositories are mirrored on backup destination; deployments may continue from local clones during outage | Subject to vendor outage duration |
| 8 | Compromise of a Service Provider credential | Immediate revocation; rotation of the affected credential; investigation per Section 10.3 | Notification within 72h |
| 9 | Compromise of a Client-Provided credential | Service Provider notifies Client; Client rotates; Service Provider receives new credential | Continuity dependent on Client rotation timing |
| 10 | Loss of single point of operator availability (e.g., Service Provider unavailability) | Documentation in Schedule E.3 enables Client or third party to operate the System; Maintenance Option provides continuity if Client elects | No specific recovery target during the bridge phase prior to Maintenance Option election |
| 11 | Client's own infrastructure compromise (Client-administered platforms) | Out of Service Provider's control; Service Provider cooperates on detection and notification | Client-owned response |
| 12 | Catastrophic loss of the System (e.g., total platform failure of Railway + Supabase simultaneously) | Restore from backups (Project Repositories from Git remote and Client-owned mirror; Client Database from Client-owned backup destination); rebuild on alternative platforms | Best-efforts; multi-day recovery acknowledged |
This document is to be reviewed by Service Provider's tax advisor (skattaráðgjafi) and Iceland-licensed legal counsel (lögmaður) before issuance to Client. Specific items requiring professional confirmation are flagged in the body and in Section 5.4.