1. How many customer-native agents run weekly, versus humans making connector calls?
2. What percentage of enabled users are weekly active?
3. What are autonomous job success, intervention, and retry rates?
4. What hard business outcomes have customers measured?
5. What FDE hours and gross margin are required for 1,000 seats?
6. Which account logos are paid production, paid pilot, free trial, or design partner?
7. What content leaves endpoints in each Watch and Sessions mode?
8. What are default retention, deletion, backup, residency, and legal-hold rules?
9. Is customer traffic used for Guard training by default, and can customers opt out?
10. Where do Guard models execute in hosted, self-hosted, and air-gapped deployments?
11. What independent red-team or benchmark evidence exists?
12. How is “tamper-proof” audit immutability implemented?
13. Why is agent token audience/resource enforcement off by default?
14. How are approvals expired, deduplicated, and protected from replay?
15. Which hooks are fail-closed by version, and which are observational?
16. What is the default sandbox backend and tenant-isolation test suite?
17. How is OAuth grant selection handled when several users have grants?
18. Is the runtime derived from OpenCode, and who owns patch cadence?
19. What is revenue mix across gateway, Watch, Guard, and native agents?
20. What is net retention after the first annual contract?
Public terms support custom order forms, possible usage billing, auto-renewal, and up to a 5% renewal increase absent different order terms. Beta services can be withdrawn. Security commitments include encryption, testing, log and recovery targets, but customer-hosted customers must apply patches and customers retain responsibility for backup/archive/retention of their data. The website terms say feature, security, compliance, and future descriptions are informational and non-contractual. Trust reports are gated.