Skip to content
The Membrane
Privacy GitHub

Legal

Terms of Service

Effective October 5, 2026

The Membrane is open-source software for authorizing AI agents, plus a public site and a hosted demo that show how it works. These terms cover the site, the documentation, the hosted sandbox, and your use of the software. They are short on purpose.

1. What this is

The Membrane is owned and maintained by Dojopop Nishi LLC, a Wyoming limited liability company. In these terms, "the project" and "the maintainer" mean Dojopop Nishi LLC.

The code is released under the GNU Affero General Public License v3.0 (AGPL-3.0), and the documentation under Creative Commons Attribution 4.0 (CC BY 4.0), as stated in the repository README. If these terms conflict with those licenses about using, copying, changing, or sharing the software or documentation, the licenses win. These terms are not a paid service agreement; there is no hosted production service.

2. The demo and the sandbox

The hosted sandbox at membrane-demo.dojopop.live and the demo you can run locally both run the gate code against simulated tools. No Jira, Slack, or GitHub action is actually performed, and the data on the demo pages of the site is invented. Treat everything shown as an illustration, not as evidence about any production deployment.

Use the sandbox as intended: try the flow, then leave. Do not enter secrets or confidential data, do not automate heavy traffic against it, and do not try to break out of it or probe it or the hosts around it. It is rate limited, it can be reset, changed, or taken offline at any time without notice, and it comes with no uptime promise.

3. What the software does and does not do

The gate decides on the traffic that is actually routed through it and denies when it cannot verify a request. That makes it fail closed: if a credential has expired, a clock cannot be read, or a check cannot be completed, the request is refused. You accept that tradeoff when you deploy it. Traffic, credentials, or tools that bypass the gate are not covered.

The dashboard, readings, alarms, and advisor are observational. They are computed from a bounded in-memory log, are not a signed evidence archive, and are never an input to an authorization decision. The advisor only suggests changes. Renewing a grant, re-issuing an IAC, or changing the registry is always an act by the operator, never something the software does on its own.

The project does not promise that the software is secure, free of bugs, compliant with any law or standard, or able to stop every unauthorized or harmful action. It is one control, not a replacement for testing, monitoring, access control, and incident response.

4. If you run it

You are responsible for your deployment: keys and tokens, the registry and IAC contents, which models, tools, and repositories are allowed, network exposure (keep the dashboard on loopback), updates, backups, review of what the agents do, and meeting any legal, contract, or third-party obligations that apply to you. Test before production use. Connectors such as GitHub act under the credentials you give them and the allowlists you set.

5. Acceptable use

Do not use the site, sandbox, or project channels to break the law, harm others, gain unauthorized access, spread malware, disrupt the service, or infringe someone else's rights. Do not misrepresent your relationship with the project or use it to make misleading security or compliance claims.

6. Third parties

The site and software link to or work with services the project does not control, including GitHub, Cloudflare, Google Fonts, model providers, and your own relays and tools. Their terms and privacy practices apply to them. The project is not responsible for their availability, content, or conduct.

7. No warranty, limited liability

To the extent the law allows, the site, documentation, sandbox, and software are provided "as is" and "as available" without warranties of any kind, and the maintainer is not liable for damages arising from their use. Some places do not allow these limits; where that is so, they apply only as far as the law permits.

8. Changes

The software, site, and these terms will change as the project does. When the terms change in a way that matters, the effective date above changes. Continued use after that means you accept the updated terms. Access to the site or sandbox can be limited or ended, for example to stop abuse.

9. Governing law

These terms are governed by the laws of the State of Wyoming, United States, without regard to its conflict-of-laws rules. This does not take away any rights you have under mandatory consumer law where you live.

10. Contact

Questions about these terms: open an issue at github.com/Z0rlord/the-membrane. Issues are public, so leave out secrets, personal data, and vulnerability details; report security problems by asking in an issue for a private channel.

See also the Privacy Policy.

The Membrane

Terms of Service Privacy Policy