exact.works
StudioAgent Index ↗Log inSign up
Trust Center

Trust is infrastructure

What exact.works does, what it deliberately does not do, and the published documents that say so — for counsel, procurement, and regulators.

Legal Documents

Published. Versioned. Citable.

The forms are public so parties, their counsel, and regulators can read them before anyone signs anything.

SAISAv1.0

Standard AI Service Agreement. The standard form for AI-agent work, between the party hiring an agent and the party operating it. exact.works is not one of the two.

TOS v1v1.0

Terms of Service for the drafting tool itself — account access, acceptable use, and the relationship between you and exact.works.

DPA v1v1.0

Data Processing Agreement. Data protection terms for personal data handled in the course of using the tool.


What we do

Draft it, seal it.

A drafting and formation tool for AI-agent engagements — closer to LegalZoom than to a platform.

SAISA formationFORM

Present the standard form, customise it to the engagement, verify the result. Both sides reach terms they agree on.

The sealoath-2026-09

A canonical hash over the terms as agreed, signed with a published key. Anyone can check it against the document they hold.

AnchoringRFC 3161

A trusted timestamp over the digest, and only the digest. Never the content of your agreement. A digest is not your data.

Public verificationOPEN

Any sealed agreement can be checked against its published hash by anyone holding a copy.

ReferralPOINTER

Provider and tool options for the engagement, sourced from the Agent Index. A pointer, never a recommendation.


What we don't do

The list matters more than the last one.

For a legal buyer this is the differentiator. Every line is a liability we are choosing not to take on.

exact.works is not a party to any agreement made with it. We do not enforce terms, hold escrow, or hold your credentials. We do not score, gate, suspend or supervise agents, and we do not adjudicate disputes.

Design rules

Liability comes from doing, holding, or promising — not from specifying.

Three rules follow from that sentence, and they decide most design questions on their own.

Never operate the service

Running it is the customer's, on their own stack, in their own account.

Never hold credentials

Their tenancy, their app registration. Brokering a token into a customer's systems would make us a processor of everything behind it.

Never covenant about a third party's behaviour

The parties elect their own providers and tools.


Regulatory Frameworks

What the agreement is drafted against.

The forms and their schedules are written against the frameworks an institutional buyer has to answer to. They are drafting inputs — not certifications, and not evidence we hold on your behalf.

EU AI ActDRAFTED AGAINST

Risk classification and record-keeping requirements are carried in the agreement and its schedules, as obligations the parties owe each other.

ISO 42001MAPPED

AI management system controls mapped to clauses, so a customer building an AIMS can show where each control is written down.

ISO 42006NOT A CERT BODY

exact.works does not issue certificates and is not a certification body. What the earlier positioning rested on is withdrawn.

NIST AI RMFMAPPED

GOVERN, MAP, MEASURE and MANAGE subcategories mapped to clauses. Satisfying them is the deployer's work, on their own deployment.

Sanctions screeningDELEGATED

Payment-side sanctions screening is delegated to Stripe, with supplementary checks before onboarding.

Financial servicesSCHEDULE F

DORA, MiFID II and EU AI Act Annex III requirements written into a schedule for finance, insurance, banking and fintech engagements.


Where we sit

Three layers. We are the middle one.

Identity, agreed terms, and runtime control are three different problems. exact.works is the middle layer, and does not pretend to the other two.

Layer 1
Identity & Payment
FIDO Alliance + AP2 + Verifiable Intent
Agent authentication, payment authorization, trusted transaction boundaries. Not ours.
Layer 2
Agreed Terms
exact.works SAISA + the seal
A two-party agreement, sealed so both sides can prove what it said.
Layer 3
Runtime Control
NeMo Guardrails, Azure AI Content Safety, LangSmith, and their peers
Policy gating, model safety, kill switches. These vendors own this ground.

Withdrawn

Pages that described something we no longer offer.

The links still resolve, because documents and inbound links point at them. Each one says what it was, when it was withdrawn, and what is true now.

APEX-BGWITHDRAWN

Behavioural scoring and qualification of agents. Withdrawn — NeMo Guardrails, Azure AI Content Safety and LangSmith evals own this ground.

ParlerWITHDRAWN

The AI dispute engine. Deferred — dispute resolution for work that has never happened.

RuntimeWITHDRAWN

Continuous behavioural review with automatic suspension. Withdrawn — that is enforcement, and we do not enforce.

DRRWITHDRAWN

Administered dispute resolution rules. Withdrawn with Parler; dispute terms belong to the two parties in their agreement.

Scoring methodologyWITHDRAWN

The behavioural scoring maths behind APEX-BG. Withdrawn on the same terms.

How it worksDocumentation
exact.works

Product

  • SAISA
  • Agent Contract Studio

Offerings

  • Government
  • Financial
  • Legal
  • Healthcare
  • Enterprise
  • Infrastructure

Tools

  • Pricing
  • Repositories
  • API
  • Documentation

Company

  • About
  • Newsroom
  • Trust
  • Governance
  • Careers
  • Contact

Every AI agent needs a service agreement.

© 2026 exact.works, Inc. Delaware C-Corp.
PrivacyTerms