Skip to content

Terms of Service

The agreement between your company and ours for the identity service: what we owe you, what you owe us, and how either side walks away.

Version 1.0 In force since September 2, 2026 Updated September 2, 2026

These Terms govern your use of Quathos Auth — including the Quathos Account, the console at auth.quathos.com, the Management API and the hosted sign-in pages we operate for your tenant — all provided by Quathos LLC, a limited liability company organized under the laws of the State of Texas, United States, with offices at 3008 Ross Ave, Suite 100, Office 210, Dallas, TX 75204, United States. By creating an account or a tenant, or by using the service, you accept them. If you are accepting on behalf of a company, you confirm you have authority to bind it, and "you" means that company.

1. What the service is

Quathos Auth is a multi-tenant identity platform. You create a tenant, register the applications that will rely on it, and your users sign in through pages we host at auth.quathos.com or at a domain you own. The service issues tokens under the OAuth 2.1 and OpenID Connect standards, manages sessions, second factors, organisations and their members, and records what happened in an audit trail. Each tenant is isolated from every other.

  • The Quathos Account — the account you use for every Quathos product — is itself a tenant of Quathos Auth, operated by us for our own products under these same Terms. Nothing in the product is reserved for it.
  • Email leaves exclusively through Quathos Mailer, a sibling Quathos product. There is no other delivery route, in any environment. SMS, when you enable one-time codes by SMS for your tenant, goes through the SMS provider listed on the Subprocessors page.
  • We do not build your application, and we do not decide what it does with the identity we assert. A token proves who signed in; what your application allows that person to do is yours to decide and to secure.

2. Your account and your tenant

  • Give accurate registration details and keep them current. An email address we cannot reach is a tenant we cannot warn.
  • You are responsible for what happens under your credentials, under the administrators you appoint, and under the client credentials of the applications you register. A client secret is a password for a machine: keep it out of source code and browsers, and tell us at security@quathos.com the moment you suspect one has leaked. We rotate it with you.
  • You control who administers your tenant and with what role. Removing someone is your action, and it takes effect immediately for new requests; sessions already open end at the latest when they expire.
  • The service is for organisations and their staff. Whoever accepts these Terms must be at least 16 and legally able to enter into a contract. Who may sign in to your applications is governed by your own terms with your users.

3. Your users and your content

Everything inside your tenant — the users who sign in to your applications, their profiles, your organisations, your applications and their settings, the branding of your sign-in page, your logs — is yours. You grant us only the limited licence needed to host, process, transmit, back up and display it so the service can work, and to do what you instruct through the product and the API. We do not sell it, we do not mine it for our own purposes, and we do not use it to train models.

4. Acceptable use

The Acceptable Use Policy is part of these Terms. The short version, because an identity provider is only worth anything while it is trusted:

  • No phishing and no impersonation: a hosted sign-in page may carry your brand, never someone else’s. A tenant created to harvest credentials, to defraud people or to launder money is terminated, not warned.
  • Respect the rate limits. They protect every tenant’s sign-in from brute force, including yours; working around them with more IP addresses or more tenants is a breach.
  • No security testing without authorisation. Test your own tenant freely; anything beyond it needs our written go-ahead first. Report what you find to security@quathos.com, under the coordinated disclosure terms on our Security page — we answer researchers and we do not threaten them.

5. Plans, usage and payment

  • Plans are priced by monthly active users (MAU) — a user counts once per calendar month in which they sign in — plus optional add-ons. The limits of each plan, including log retention and the number of applications and organisations, are published on the pricing page and may change for future cycles with at least 30 days’ notice.
  • Paid plans renew automatically every cycle until cancelled. Cancel any time: the plan stays active until the end of the cycle you already paid for, and is not renewed after that.
  • Fees are stated in the currency shown at checkout and exclude taxes, which are added where the law requires. Payment is handled by Stripe; we never receive or store your card number.
  • Cycles already served are not refunded, except where consumer law gives you a refund right — in Brazil, that includes the seven-day withdrawal right for purchases made online.
  • If payment fails or usage exceeds your plan, we tell you before restricting anything. A restriction never turns off sign-in for your existing users without notice: we would rather send you an invoice than lock your customers out.
  • We may change prices for a future cycle with at least 30 days’ notice. You can cancel before it takes effect; continuing after that is acceptance.

6. Availability, support and changes

We work to keep the service available and we announce planned maintenance in advance whenever we can. Unless a separate written service level agreement says otherwise, the service is provided without an uptime commitment. We may improve, change or retire features and API versions; when a change removes something you rely on, we give reasonable notice — never less than 90 days for a protocol endpoint or an API version — and, where the change is material and adverse, you may cancel and receive a pro-rata refund of the unused part of the cycle.

7. Suspension

We may suspend a tenant for non-payment, for a serious breach of the Acceptable Use Policy, or for a live security risk to your users or to other tenants. Except when an immediate risk makes it impossible, we tell you first and give you a chance to fix it. A suspended tenant stops answering sign-in requests; its data is kept, and the return and deletion terms of section 10 and of the Data Processing Addendum still apply.

8. Intellectual property and feedback

The software, the brand and everything we built around them are ours and stay ours; these Terms grant you a limited, non-exclusive, non-transferable right to use the service while your tenant is active, and nothing more. Our SDKs and code samples carry their own open-source licences, which say what you may do with them. If you send us an idea or a suggestion, we may use it without owing you anything — and we would rather say that plainly than bury it in a definition.

9. Confidentiality

Each side keeps the other’s non-public information confidential, uses it only for this relationship, and protects it with at least the care it uses for its own. This does not cover what is already public, what was already known without an obligation, or what has to be disclosed by law — and in that last case, the disclosing side gives notice first if it is legally permitted to.

10. Ending the agreement

  1. 1 You may close your tenant at any time, from the console. We may terminate for material breach that stays uncured for 30 days after notice, or if we discontinue the service entirely — in which case we give at least 90 days’ notice and refund the unused part of any prepaid cycle.
  2. 2 For 30 days after closure, your tenant’s data — users, organisations, applications and logs — remains available for return on request, in a machine-readable format. Nobody should discover on the day they leave that leaving costs them their users.
  3. 3 After the window, we delete the tenant and its content, subject to the retention table in the Privacy Policy — invoices and records the law obliges us to keep survive deletion.
  4. 4 Sections on your content, confidentiality, disclaimers, liability, indemnity and governing law survive termination.

11. Warranties and disclaimer

We warrant that we will provide the service with reasonable skill and care and that the protocol endpoints will conform to the OAuth 2.1 and OpenID Connect specifications they claim to implement. Beyond that, and to the fullest extent the law allows, the service is provided "as is": we do not warrant that it will be uninterrupted, error-free, or fit for a particular purpose of yours. Nothing here excludes liability that cannot lawfully be excluded, and consumer rights that apply to you by law — including under the Brazilian Consumer Protection Code — are not affected by this section.

12. Limitation of liability

Neither side is liable for indirect, incidental, special or consequential damages, nor for lost profits or lost business. Our total liability arising out of these Terms is capped at the greater of (a) the amount you paid us for the service in the twelve months before the event that gave rise to the claim and (b) five hundred United States dollars (US$ 500). These limits do not apply to fraud, wilful misconduct, death or personal injury, breach of confidentiality, or amounts you owe us — and they do not apply where the law forbids them.

13. Indemnity

You will defend and hold us harmless against third-party claims arising from the data you load, the applications you connect, what those applications do with the identities we assert, or your breach of these Terms or of the Acceptable Use Policy. We will do the same for you against third-party claims that the service itself infringes their intellectual property.

14. Changes to these Terms

We announce material changes by email and on this page at least 30 days before they take effect, and the version and date at the top always say which text is in force. If you do not accept a change, close your tenant before it starts — using the service after that date is acceptance.

15. Governing law and disputes

These Terms are governed by the laws of the State of Texas, United States, and disputes go to the state and federal courts located in Dallas County, Texas. If you are a consumer, this does not deprive you of the protection of the mandatory consumer and data protection law of your place of residence, nor of the right to sue in your own domicile where the law gives it to you. Before filing anything, write to legal@quathos.com: most disagreements end in an email thread, and we would rather spend the money on the product.

16. General

  • These Terms, the Privacy Policy, the Cookie Policy, the Acceptable Use Policy and — whenever we process personal data on your behalf — the Data Processing Addendum are the whole agreement between us about the service.
  • If a clause is held invalid, the rest stands and the invalid part is read down to what the law allows.
  • Not enforcing a right on one occasion does not waive it.
  • You may not assign this agreement without our consent; we may assign it to a successor of the business, and we tell you when we do.
  • Neither side is liable for failures caused by events genuinely beyond its control.
  • Notices to you go to the email of your tenant’s administrators; notices to us go to legal@quathos.com.