# Tenka Mutual Accountability Agreement

**Version:** 1.0.0
**Effective:** When you accept this agreement during installation
**Status:** Founder-authored, in effect

---

## 1. Why This Document Exists

Most software agreements are one-sided. You give up rights, the company keeps options, and the only thing both parties agree on is that you signed something you probably didn't read.

This document is different.

The Tenka Mutual Accountability Agreement names what Tenka commits to you, and what you commit to Tenka, in plain language. Both sides give. Both sides receive. Both sides are accountable to the other.

This is what mutual accountability looks like when the architecture supports it. Tenka's substrate records both sides of this agreement as cryptographic chain entries — your acceptance is attested, our commitments are recorded, and neither side can quietly walk away from what was agreed.

Read this. It matters. It is short enough that you can read every word, and we ask that you do.

---

## 2. What Tenka Commits to You

We make these commitments in the same plain language we expect from you. Each commitment is auditable against our actual behavior. If we break one, you have the right to know, and we have the obligation to explain.

### 2.1 Transparency

The workforce dialogue you see when operating Tenka is scripted, not generated by a language model reasoning in real time. The agents you encounter — Mikhael, Tai, Linh, Caio, Hawkeye, Eilif, Cecilia, and the others — are in active education. Their dialogue is scripted for consistency because that is how the substrate's training requires it to work. We tell you this here. We also tell you this in the "Why does this exist?" link inside the Tenka window.

You are not interacting with autonomous AI. You are interacting with a substrate that simulates institutional behavior using deterministic processes, and your operations contribute to the training corpus that will eventually produce Tenka's proprietary models. We name this honestly because honesty is the architecture, not a marketing position.

We will never deploy covert AI behavior. We will never embed hidden chatbots inside conversations you believe are organic. We will never collect data through deception. The substrate is built to oppose those patterns, not replicate them.

### 2.2 Identity Ownership

Your Genesis Unique IDentification is derived from your inputs through cryptographic hashing. We do not assign it. The mathematics produce it from your name pair, and the same inputs always produce the same result. This is verifiable by anyone — including you — and not opaque.

Your TSAIF anchor, containing your private key and identity metadata, is stored on your machine, not ours. We do not hold your identity. You do. The math anchors it.

Your chain entries — the cryptographic records of operations you perform — are stored locally in your machine's home directory. We do not take possession of your operational history.

### 2.3 Data Handling

Personal information you provide during installation (name, cultural origin, pronouns, email address, location) is used for identity generation and account creation. It is not used for advertising, sold to third parties, transferred to data brokers, or used to profile you individually.

Operational data — which commands you ran, when, what file types you signed, what chain entries you produced — becomes part of Tenka's training corpus in anonymized form. Personal identifiers are stripped. Operation patterns remain. The pattern of "user signed a PDF at this time" becomes training data; "this user signed this file" does not.

The substrate is genuinely federated where you are concerned: your identity stays yours, your private operations stay private, and your contribution to Tenka's institutional development happens through anonymized patterns, not through surveillance.

### 2.4 Honesty Under Pressure

When we do not know something, we say so. When we make mistakes, we surface them as operational precedents — like the data-loss incident on May 5, 2026, which is documented in our public substrate records, not hidden.

We do not position Tenka as autonomous AI that replaces humans. Tenka is governance infrastructure for hybrid human-AI workforces, and we describe it as exactly that. We do not overclaim capabilities. We do not market features that do not yet exist as if they ship today. What you receive is what we describe.

### 2.5 Forward Commitments

The scripted workforce dialogue you see today will eventually be replaced by proprietary Tenka models trained on the corpus your operations help build. When that transition happens, you will be told. The replacement is not silent.

When the educational tier launches, allowing users to participate as credentialed Employees-in-training, your participation is opt-in, not automatic. We do not enroll you in extended programs without your active consent.

When credentials earned through Tenka are externally verified — for example, degrees confirmed through public records verification — the verification chain is auditable. You can see what was checked, when, and what the result was. "Trust us" is not a substrate primitive.

---

## 3. What You Commit to Tenka

We ask you to commit to a narrow, reasonable set of behaviors. These are not designed to maximize our legal armor. They are designed to keep the substrate honest for everyone in it.

### 3.1 Honest Use

You will not impersonate another identity through your TSAIF anchor. Your Genesis Unique IDentification is yours; representing yourself as another person through Tenka's cryptographic primitives is a violation of the substrate's foundational discipline.

You will not knowingly sign content with intent to deceive about its authorship. The signature primitive exists to prove origin; using it to falsify origin is incompatible with substrate participation.

You will not use Tenka's federation primitive to bypass governance requirements you are legally bound to. If your professional context requires specific attestation procedures, federation through Tenka does not exempt you from them — it should support them.

### 3.2 Testing Participation Acknowledgment

You acknowledge that operations you perform contribute to Tenka's training corpus in anonymized form. The patterns of your usage shape what Tenka becomes, and that is part of the bargain you make by participating during the testing period.

You acknowledge that the workforce dialogue is scripted and that scripts will evolve as Tenka's substrate matures. The agents you see today may behave differently as the substrate's models develop. Your expectations should adjust accordingly.

You will report substrate failures, integrity violations, or anomalies through established channels rather than exploit them. Tenka's substrate is built to surface its own failures honestly; you are part of that surfacing.

### 3.3 Account Integrity

You will protect your TSAIF private key. Loss of the private key means loss of your identity within the substrate. This is not policy — it is mathematics. Tenka cannot recover your private key for you, because we do not hold it.

You will not share your account credentials, your private key, or your authenticated session with others. The substrate's identity primitives assume one identity per anchor.

You will notify Tenka if you suspect your account has been compromised. Substrate-grade tampering surfaces in chain integrity checks; if your chain breaks unexpectedly, that is signal worth investigating.

---

## 4. Testing Period — Specific Data Terms

This section names exactly what happens with data during the testing period, in concrete terms, so there is no ambiguity.

### 4.1 What Gets Captured

The following operational events are recorded:

- Command invocations: which Tenka CLI commands were run, and when
- File operations: what file types were signed, verified, or checked for provenance — by extension and format, not by content
- Chain integrity events: when verifications occurred, what they returned, whether any tampering was detected
- Federation handshakes: who attested whom, and whether the attestation succeeded
- Anomaly surfaces: when things went wrong, what category, what the substrate did about it

### 4.2 What Does Not Get Captured

The following are never recorded, transmitted, or accessible to Tenka:

- File contents you sign or verify
- File names or paths beyond what is needed for format detection
- Network endpoints you ping (the fact that a ping occurred is recorded; the destination is not transmitted to Tenka)
- Personal correspondence, even if signed through Tenka's primitives
- Conversation contents, if any feature in the future supports messaging

### 4.3 How Captured Data Is Used

- Anonymized and added to Tenka's training corpus for substrate model development
- Aggregated for operational analytics — how many users hit a particular failure mode, which commands are exercised most often, what patterns emerge across recipients
- Substrate refinement — what edge cases your operations surface become candidates for substrate amendments in future versions

### 4.4 How Captured Data Is Not Used

- Never sold or transferred to third parties for any purpose
- Never used for advertising or marketing targeting
- Never used to profile individual users for behavioral analysis
- Never used to identify users to anyone outside Tenka, including not to law enforcement, except under legal compulsion (court order, lawful warrant, or equivalent in your jurisdiction), in which case we will notify you to the extent we are legally permitted

### 4.5 Retention

- Anonymized operational data is retained indefinitely as training corpus. This is part of what your participation contributes.
- Personal identifiers (name, email, account metadata) are retained only as long as your account is active.
- On deletion request, personal identifiers are purged within 30 days. Anonymized operational data remains in the training corpus per the terms above, but is no longer associated with your identity.

---

## 5. The Public Training Position

This section names what makes the Tenka Mutual Accountability Agreement structurally different from a standard software agreement.

You are not just a user of Tenka. You are a participant in Tenka's institutional development.

Your operations train the substrate that future users will exercise. Your feedback shapes the substrate amendments that future versions ship with. Your edge cases — including failures, including frustrations, including the moments when something does not work the way you expected — become the operational precedents that define what governance under stress looks like in this system.

In return for your participation, you receive:

- Early access to the substrate as it matures, ahead of public distribution
- Recognition in the substrate's accumulated history through chain entries that attest your participation
- A credentials card surface that grows version-over-version into a portable substrate-attested identity record, usable as professional credential where Tenka's verification chain is recognized
- A voice in what Tenka becomes through documented operational feedback that shapes substrate amendments

This is what mutual accountability looks like in practice. Both sides give. Both sides receive. The substrate records the exchange. Neither side can quietly opt out of what was agreed.

---

## 6. Termination

Either side can end this relationship. The terms are symmetric.

### 6.1 You Can Terminate at Any Time

- Stop using Tenka and uninstall when you choose
- Request TSAIF deletion through the established support channel
- Personal identifiers are purged within 30 days of confirmed deletion request
- Anonymized operational data remains in the training corpus per Section 4 retention terms
- Documents you signed during your active period remain verifiable — the signatures do not expire when your account closes

### 6.2 Tenka Can Terminate Access If

- You violate the honest use commitments in Section 3
- You attempt to compromise substrate integrity (deliberate chain tampering, federation primitive abuse, impersonation attempts)
- Legal compulsion requires it (court order, lawful regulatory requirement)

### 6.3 On Termination by Tenka

- You receive notification of the termination, with the reason stated plainly
- You receive a 30-day window to export your chain entries before account closure
- No retaliatory action follows — documents you signed remain verifiable, your professional reputation is not damaged through Tenka actions
- Anonymized operational data remains in the training corpus per Section 4 retention terms

There are no aggressive non-disparagement clauses, no class-action waivers buried in dense subsections, no forced arbitration designed to make grievances expensive. If we end the relationship with you, we do it cleanly.

---

## 7. Jurisdiction and Disputes

This agreement is governed by the laws of the State of Ohio, United States. Disputes arise under the jurisdiction of Wood County, Ohio.

If a dispute arises:

1. We start with good-faith communication. You contact us, we respond, we try to resolve the matter directly.
2. If direct communication fails, we proceed to mediation through a neutral third party agreeable to both sides.
3. Arbitration or litigation is the final path, not the first. We do not require you to waive your right to court access as a condition of using Tenka.

This is reasonable dispute resolution. It is not legal armor designed to make your grievance procedurally exhausting.

---

## 8. Updates to This Agreement

The Tenka Mutual Accountability Agreement is versioned, like the substrate itself. You see the version number at the top of this document.

### 8.1 Material Changes

Material changes — changes that affect what we commit to you or what you commit to Tenka in substantive ways — require re-acceptance. The substrate gate will display the updated agreement, you will read it, and you will accept it (or decline and exit the substrate) through the same mechanism you used to accept this version.

### 8.2 Non-Material Changes

Non-material changes — clarifications, typo corrections, wording improvements that do not change substantive commitments — are communicated to you but do not require re-acceptance.

### 8.3 Archive

Old versions of this agreement remain accessible in Tenka's public records. You can always see what you originally agreed to, even after updates supersede it.

---

## 9. The Covenant Close

Tenka has committed to you:

- Transparency about what the substrate is and how it works
- Identity ownership through mathematics, not policy
- Honest data handling with explicit terms about what is captured, how it is used, and what is never used
- Honesty under pressure, including about our own mistakes
- Forward commitments about how the substrate evolves and how you are informed

You have committed to Tenka:

- Honest use of the substrate's primitives
- Acknowledgment of the testing participation framing
- Account integrity protection on your side of the cryptographic boundary

We have both signed this. The substrate records it. This is what mutual accountability means in this system.

When you click "I Accept," the substrate writes a cryptographic chain entry that includes:

- This document's SHA-256 hash
- Your acceptance timestamp
- Your Genesis Unique IDentification (back-filled after generation, per the substrate gate sequencing)
- Confirmation that you scrolled through this document and accepted it through the modal-gate mechanism

The chain entry is locally stored on your machine and forms part of your portable substrate identity record. It is not just a checkbox click. It is an attested act.

Welcome to the substrate.

---

**Version 1.0.0 · Effective on acceptance**
**Tenka System · Wood County, Ohio, United States**
