Skip to content

Legal

Terms of service

The terms on which INTYGA is provided, including acceptable use, availability, liability, and what the service does and does not guarantee.

Agreement

These terms govern your use of the INTYGA service, operated by Janbjer Technologies AB (org. no. 559602-1757), a Swedish aktiebolag with its registered office at Rickards plan 3, 791 47 Falun, Sweden. Before a new self-service customer is given access, its initial administrator must expressly accept the version of these terms shown during enrollment. The accepting person confirms authority to bind the customer. Users invited into an existing workspace act under that customer’s agreement; enrolling their credential does not create a separate customer contract. Acceptance of the contract is separate from the privacy notice and is not consent to processing under the GDPR. This is version 2026-09-30.

The service

INTYGA provides an authorization gateway that holds designated actions until a human approves them with a cryptographic signature, and a witness log that records those approvals in a tamper-evident structure.

What INTYGA does not do

We would rather be explicit here than have you discover it during an incident.

  • INTYGA does not replace identity and access management, change control, or platform-native approval gates. It composes with them.
  • INTYGA does not decide whether an action is safe. It establishes that a specific human approved specific parameters. If that person approves something harmful, the signature proves they approved it — it does not prevent it.
  • INTYGA does not certify you as compliant with any standard. Published compliance material is a readiness mapping, not an attestation, and no vendor can sell conformity with a regulation.
  • INTYGA does not guarantee that a witness log captures every action in your environment. It evidences the integrity and completeness of the events that were committed to it.

Your responsibilities

You are responsible for the security of your accounts and authenticators, for configuring approval policies appropriate to your risk, and for the actions your users and automated systems take. You must not use the service to violate applicable law, to interfere with its operation or security, or to circumvent plan limits.

You are responsible for verifying receipts before executing the actions they authorize. The verification libraries are provided so you can do this without depending on us; a deployment that skips verification has not obtained the guarantee the service exists to provide.

Availability

The service is provided on an as-available basis. Where a plan includes a service level commitment, it is stated in the applicable order form. Free plans carry no availability commitment.

Fees

Paid plans are billed in advance on the cadence stated at purchase — monthly, or annually at the published annual price. Plans are flat: the subscription is the only recurring charge, and there is no usage-based fee, Protected-Op allowance, overage rate, spend cap, or top-up mechanism on any plan. Protected-Op volume is reported as telemetry but is never charged, and an approval is never declined because of volume. The most a month can cost is the plan price.

Monthly Active Approvers for embedded use

Monthly Active Approver (MAA) is the monthly usage measure for the embedded platform service. For one calendar month, INTYGA measures (a) active credentials: the number of distinct logical credential IDs used to complete at least one live, billable platform receipt, and (b) active subjects: the number of distinct internal INTYGA subject IDs associated with at least one such receipt. Test-mode receipts, rejected or expired ceremonies, and receipts that are not billable are excluded. A credential remains the same logical credential across ordinary key rotation; a subject is INTYGA's internal, frozen identifier rather than the customer's changeable external ID.

The credential count is the measurement and integrity-control unit. The active-subject count is the invoicing unit whenever an order form or other commercial agreement prices embedded use by MAA. One subject with several credentials is billed once; one credential used for several subjects does not collapse those subjects for billing. The credential count is not a second charge. Unless an order form expressly states MAA pricing, the flat-plan rule in the Fees section applies and MAA remains telemetry only.

Identity integrity

The customer must maintain one stable subject for each distinct natural person or end user represented in the embedded service. Combining, pooling, rotating, or otherwise representing distinct people under one subject ID to reduce or distort the active-subject count is prohibited and is a material breach of these terms (identity collapse). Changes in the customer's own external IDs do not permit the customer to merge distinct people into one INTYGA subject.

A credential may be used only by the one natural person or end user to whom it was enrolled. Sharing credentials, authenticators, passkeys, security keys, or equivalent signing access between distinct people is prohibited and is a material breach of these terms. One person may legitimately enroll several credentials or devices; the prohibited case is several people using the same credential or authenticator.

Measurement, disputes, and audit

INTYGA measures active credentials and active subjects from completed, committed receipt records in its tamper-evident ledger. Those ledger-derived measurements govern invoices and usage disputes unless the customer demonstrates a manifest measurement error. The customer must notify INTYGA of a disputed measurement within 30 days after the relevant invoice or usage statement and provide the records reasonably needed to identify the claimed error.

If the credential and subject counts materially diverge, show a repeated abnormal relationship, change abruptly, or otherwise give INTYGA reasonable grounds to suspect identity collapse, shared credentials, or under-reporting, INTYGA may audit the relevant identity mappings and enrollment records. On reasonable notice, the customer must provide records and cooperation reasonably necessary to verify the number of distinct people, subjects, and credentials for the affected period. INTYGA will limit the audit to that purpose, protect the records as confidential information, and avoid unreasonable disruption. If the audit confirms a material undercount or breach, INTYGA may correct the affected measurement and invoice, require remediation, recover reasonable audit costs, or suspend or terminate the affected access as permitted by these terms; divergence alone is a review signal and does not by itself create an automatic charge.

Termination

You may request termination at any time by contacting hello@intyga.com through an authorized customer representative. We confirm the effective termination date and the end of the export period. Cancelling a paid subscription and terminating a workspace are separate requests; a plan change alone does not delete your workspace. We may suspend or terminate access for material breach, non-payment, or where continued provision would be unlawful. On termination you have 30 days to export evidence still retained at that date, on every plan. Ordinary plan expiry or a downgrade will not shorten this export window or remove evidence preserved for it. If ordinary access must be suspended, we will arrange secure delivery to an authorized representative, subject to applicable law. You may request earlier erasure and expressly waive the remaining export period. Deletion and return then follow the agreed DPA and retention schedule. Downloaded copies are under your control. Erasure removes personal identity fields and readable content while preserving the cryptographic commitments described in the privacy notice; it does not grant a right to retain remaining personal data indefinitely.

Personal data and customer instructions

Where INTYGA processes personal data on your behalf, accepting these Terms also incorporates the Data Processing Agreement (DPA), version 2026-09-24.2, including its subprocessor list. The DPA prevails over conflicting Terms for that processing. A separately agreed DPA may replace it for the processing it covers. Mandatory law and applicable Standard Contractual Clauses retain their required precedence.

You are responsible for your lawful basis, notices to your users, documented instructions and the data you submit. Keep approval descriptions and parameters to what the action requires. Do not submit special-category personal data or criminal-offence data unless separately agreed in writing with appropriate safeguards. Our privacy notice describes processing for which INTYGA acts as controller. These terms do not limit data subjects’ statutory rights or either party’s duties to supervisory authorities.

Warranties and liability

Except as expressly stated, the service is provided without warranties of any kind, to the maximum extent permitted by law. Nothing in these terms excludes liability that cannot lawfully be excluded, including for death or personal injury caused by negligence, or for fraud.

Neither party is liable for indirect or consequential loss. Our aggregate liability in any twelve-month period is limited to the fees you paid in that period, subject to any separately agreed allocation in the DPA or order form and any liability that cannot lawfully be limited.

Governing law

These terms are governed by Swedish law, and the courts of Sweden have exclusive jurisdiction, without prejudice to any mandatory consumer protections available to you locally.