Effective Date: March 2026
Last Updated: March 2026
Entity: ZLAR Inc., a corporation incorporated under the Canada Business Corporations Act (CBCA)
By accessing zlar.ai or using any ZLAR product, you agree to these terms. If you do not agree, do not use the website or any ZLAR product.
ZLAR Inc. is a Canadian corporation that develops agent governance infrastructure. Our products provide mechanisms for human oversight of autonomous AI systems. We are not a security company. We are not an AI safety research organization. We build tools that help humans maintain authority over AI agents operating on their systems.
ZLAR products are deterministic, rule-based policy enforcement tools. They do not use machine learning, do not make inferences from inputs, and do not generate predictions, recommendations, or decisions. They enforce human-authored rules via string matching, operating system primitives, and cryptographic verification.
Under the EU AI Act (Regulation 2024/1689), the OECD AI framework, the Colorado AI Act, and other enacted AI legislation, ZLAR products do not meet the definition of "AI systems." The EU AI Act's Recital 12 explicitly excludes "systems that are based on the rules defined solely by natural persons to automatically execute operations."
ZLAR products may help AI system operators satisfy governance obligations (including Articles 9, 14, and 15 of the EU AI Act), but ZLAR Inc. does not certify that use of any ZLAR product satisfies any specific regulatory requirement.
All ZLAR products are provided as tools to assist with AI agent governance. They are not guarantees of safety, security, containment, or compliance.
Autonomous AI is an emerging technology. The behavior of AI agents — even agents operating under governance — can be novel, unexpected, and potentially harmful. No governance tool, from any provider, can eliminate this risk. ZLAR products reduce risk. They do not eliminate it.
By using any ZLAR product, you acknowledge:
ZLAR Inc. discloses the following in the interest of transparency:
This is not an exhaustive list. Product-specific limitations are documented in the repository's LEGAL.md file.
All ZLAR products, services, documentation, and website content are provided "as is" and "as available" without warranty of any kind, express or implied.
ZLAR Inc. specifically disclaims all warranties including:
To the maximum extent permitted by applicable law, ZLAR Inc., its officers, directors, employees, contributors, and agents shall not be liable for any damages arising from:
This includes direct, indirect, incidental, special, consequential, exemplary, and punitive damages, regardless of legal theory, and regardless of whether ZLAR Inc. has been advised of the possibility of such damages.
Where law does not permit full exclusion: ZLAR Inc.'s total aggregate liability for all claims shall not exceed CAD $100 or the amount you paid to ZLAR Inc. in the twelve (12) months preceding the claim, whichever is greater.
AI agent governance is a new field. You acknowledge that:
a) Agentic AI is inherently unpredictable. Models can hallucinate, misinterpret instructions, take unintended actions, discover novel behaviors, and interact with other systems in unexpected ways.
b) No containment is absolute. Software-based governance operates within the constraints of the underlying operating system, runtime, and hardware. Sufficiently capable adversaries or sufficiently novel agent behavior may exceed those constraints.
c) The threat landscape changes. New vulnerabilities, attack vectors, and exploitation techniques emerge continuously. ZLAR products are designed against known patterns. Unknown threats are, by definition, not fully addressed.
d) You are the operator. ZLAR products provide mechanisms for human oversight. The effectiveness of that oversight depends on your policy configuration, your review diligence, your security practices, and your judgment.
If you engage ZLAR Inc. for installation, configuration, consulting, custom development, or any other professional service:
You agree to indemnify, defend, and hold harmless ZLAR Inc. and all ZLAR Parties from any claims, damages, losses, liabilities, costs, and expenses (including legal fees) arising from:
ZLAR products interact with third-party platforms and software. ZLAR Inc. is not affiliated with, endorsed by, or responsible for:
Third-party terms, privacy policies, and limitations apply independently. Changes to third-party platforms may affect ZLAR product operation without notice from ZLAR Inc.
Nothing on this website or in any ZLAR product constitutes legal advice, security consulting, compliance guidance, or professional certification.
ZLAR Inc. does not certify that any product or configuration meets the requirements of any regulatory framework, including but not limited to:
| Jurisdiction | Frameworks |
|---|---|
| Canada | PIPEDA, OSFI guidelines, provincial privacy acts |
| European Union | EU AI Act, GDPR, NIS2 Directive |
| United States | CCPA/CPRA, Colorado AI Act, Texas TRAIGA, state AI laws, NIST AI RMF, HIPAA, SOX |
| Asia-Pacific | APPI (Japan), PDPA (Singapore), PIPL (China) |
| International | ISO/IEC 42001, ISO 27001 |
Note on NIST AI RMF: ZLAR products' governance functions align with the NIST AI Risk Management Framework's "Govern" function. Compliance with NIST AI RMF provides statutory affirmative defenses in certain US jurisdictions (including Colorado and Texas). ZLAR Inc. does not certify that use of any ZLAR product constitutes NIST AI RMF compliance.
If you need compliance assurance, consult qualified legal and security professionals in your jurisdiction.
ZLAR Inc. is committed to responsible vulnerability disclosure and timely patching of known security issues. Report vulnerabilities to security@zlar.ai or via GitHub's private vulnerability reporting. See the repository's SECURITY.md for details.
This commitment does not create an obligation to provide ongoing maintenance, support, or updates. ZLAR products are open source software provided without a service level agreement.
ZLAR products are distributed as free, open source software under the Apache License 2.0 outside the course of a commercial activity.
Under the EU Cyber Resilience Act (December 2024), non-commercial open source software is exempt from product cybersecurity requirements. Under the revised EU Product Liability Directive (Directive 2024/2853, transposition deadline December 2026), free open source software supplied outside commercial activity is excluded from strict product liability.
ZLAR Inc. relies on these exemptions for the open source distribution. Any future commercial offerings (paid support, enterprise features, SaaS) will be subject to separate terms and may carry different legal obligations.
ZLAR products are open source under the Apache License 2.0.
"ZLAR," and associated names and marks are trademarks of ZLAR Inc. You may not use ZLAR trademarks to imply endorsement, certification, or affiliation without written permission.
Website content, documentation, and design are copyright ZLAR Inc. unless otherwise noted.
Website: zlar.ai is a static website hosted on GitHub Pages. We do not use cookies, analytics, or tracking. GitHub Pages may collect standard server logs (IP addresses, access times) per GitHub's privacy policy.
Products: ZLAR products process data locally on your machine. They do not transmit data to ZLAR Inc. You are responsible for all data generated, processed, or logged by ZLAR products.
Communications: If you contact us via email (vincent@zlar.ai), we will use your information only to respond to your inquiry. We do not sell or share contact information.
ZLAR products include cryptographic functionality. You are responsible for compliance with all applicable export control laws in your jurisdiction, including Canadian, U.S., EU, and international controls.
These terms are governed by the laws of the Province of Ontario and the federal laws of Canada, without regard to conflict of law principles. Disputes are subject to the exclusive jurisdiction of the courts of Ontario, Canada.
If any provision is unenforceable, it will be modified to the minimum extent necessary or severed. Remaining provisions continue in full force.
ZLAR Inc. may update these terms at any time. Changes take effect upon posting. Continued use constitutes acceptance.
ZLAR Inc.
Email: vincent@zlar.ai
Web: zlar.ai
Open source. Open terms. Your systems, your agents, your responsibility. We build the tools. You make the decisions.