Platform Requirements


indigo.ai Platform

Version 1.1 of 4 August 2026 — published on indigo.ai. Referenced in the contracts governing its application, including clause 12.1 of the Partnership Agreement. Published in identified and dated versions, archived and available; updates may only be made for operational and non-costly purposes, subject to the notice period specified in the applicable contract (for partners, clause 12.3 of the Partnership Agreement).

1. Purpose and Scope
‍1.1
This document sets out the requirements that anyone operating on the indigo.ai Platform (the “Operator”: partners, customers, their authorised representatives and suppliers) must comply with when accessing the Platform or interfacing with it via automated tools, including coding agents, the MCP protocol and APIs.
1.2 This document supplements the contracts to which it refers and does not amend their terms: in the event of a conflict, the applicable contract shall prevail. Sections 2 to 6 apply to all Operators; Section 7 sets out the specific roles of partners and customers.

2. Access to the Platform
‍2.1 Accounts and authentication
Accounts must be registered in the name of a specific individual: no account sharing, no anonymous ‘service’ accounts. MFA is mandatory; SSO where available.
2.2 Roles and Least Privilege
The Platform implements a workspace permissions model with system roles (Owner, Admin, Editor, Manager, Operator, Viewer), custom roles and permissions for individual users. The Operator: (a) assigns to each person the minimum role necessary for the task performed; (b) reserves the Owner and Admin roles solely for those responsible for the workspace, never for accounts used by automated tools; (c) reviews the assig
nments at least every twelve (12) months.
2.3 Machine-to-machine credentials
Server-side integrations (e.g. Chat API) use dedicated Personal Access Tokens, generated for the user/workspace pair: one token per integration, never reused across different environments or clients. Tokens have a set expiry date and their scope is limited to their actual use. They are rotated periodically and revoked immediately when the integration is decommissioned or the authorised user leaves the organisation.
2.4 Offboarding
Revocation of access rights and tokens within five (5) working days of the termination of the individual’s employment; removal of the user from the workspace.

3. Operations via coding agents and automated tools
‍3.1 Principles, applicable to any model or agent provider
(a) commercial/business accounts held by the provider of each agent or model used, with a prohibition on personal or consumer ‘ ’ accounts; (b) exclusion of the use of data for model training, as an active and verifiable condition of the arrangement; (c) signing of the supplier’s Data Processing Agreements (DPAs), so that all parties in the data processing chain, right up to the model provider, are covered by appropriate agreements (for partners: end customer – Indigo – Partner – supplier); (d) prior notification to Indigo regarding suppliers or tools not listed in this document.
3.2 Requirements for suppliers
References to suppliers’ plans and terms are provided for identification purposes only and are understood to refer to the terms currently in force; it is the Operator’s responsibility to verify that these remain in force and to adapt their framework accordingly.

Permitted accounts
Supplier
Prohibited
Conditions
Anthropic (Claude Code, Claude API)
Team, Enterprise, Commercial API
Personal Pro and Max plans
Data exclusion from training is active in accordance with the provider’s current commercial terms; Anthropic DPA signed
OpenAI (Codex, API)
Business, Enterprise, API with data controls enabled
ChatGPT Free/Plus personali
Training exclusion active; OpenAI DPA signed
GitHub (Copilot)
Copilot Business, Copilot Enterprise
Copilot Individual
Active exclusion of prompts and suggestions from training; GitHub for Business terms
Other providers
Compliant with Principle 3.1
Consumer accounts
Permitted subject to notification to Indigo


3.3 Agents’ access to the Platform via MCP
The Platform exposes a native MCP server, secured with OAuth 2.1: the agent presents a token linked to an existing Indigo user.The agent operates with that user’s permissions, within a predefined scope (reading and exporting the configuration of workspaces of which the user is a member, configuration changes, test conversations, debug traces, creation and cloning of workspaces; publication and deployment, account and workspace settings, billing, and deletion are excluded). The Operator using agents via MCP: (a) ensures they operate under the identity of an authorised person within the workspace, never using shared accounts; (b) subjects changes made by the agent to human review prior to publication in production; (c) does not circumvent the scope of the MCP server with unauthorised automations.
3.4 APIs and agent credentials
Tools that use the Platform’s APIs must employ dedicated and revocable PATs in accordance with section 2.3. It is prohibited to embed credentials in code, repositories, prompts or shared documents: secrets must be stored in a secret manager.

4. Data processing and security
‍4.1
Data processed via the Platform remains within authorised environments; copying or storing such data on personal or unmanaged systems is prohibited.
4.2 The Platform records users’ actions in the workspace’s Audit Logs (which can be viewed and exported, with Splunk integration available): agents’ activities are therefore tracked under the identity of the user under whose account they are operating. The Operator must also retain its own logs of automated activities carried out on the Platform for at least twelve (12) months and make them available to Indigo upon request.
4.3 Incidents (unauthorised access, data exfiltration, non-compliant use of an agent) must be reported within forty-eight (48) hours to the contact person specified by Indigo in the applicable contract (for partners, the Partnership Contact specified in the Enrolment Form), with a copy sent to any security email address specified by Indigo, or to any other contact person subsequently notified by Indigo.

5. Evidence and Certifications
‍5.1
Upon a reasoned request from Indigo, the Operator shall, within twenty (20) working days, provide a certificate of compliance signed by its legal representative or by a person with the relevant powers, which shall specify at least: (a) the agents and automated tools used and their respective suppliers; (b) for each supplier, the type of account used, whether data has been excluded from training, and whether a DPA has been signed; (c) the management of credentials and tokens in accordance with section 2.3. The Operator is solely responsible for preparing the certificate; Indigo may request further information if it is incomplete. Upon request, the Operator shall also provide evidence of the configuration (type of supplier accounts, training exclusion settings, signed DPAs, token management), including in the form of a configuration export or a copy of the settings. Indigo may verify activities on the Platform via its own logs and the workspace audit logs.
5.2 Failure to provide the evidence within the specified time limits constitutes a breach of the obligation to provide evidence or certification as set out in the applicable contract (for partners, clause 2.4 of the Partnership Agreement).

6. Updates
‍6.1
The document is published in identified and dated versions; each version is archived and remains available. Updates are communicated to Operators with the notice period specified in the applicable contract and relate exclusively to operational aspects and do not entail any costs.

7. Specific Provisions
‍7.1
Partner: the obligations set out in clauses 2.4 and 9.6 of the Partnership Agreement (responsibility for organisational structure, declaration and warranty of compliance, indemnity) remain in full force. The partner’s personnel working on end-customer workspaces are covered by a valid Individual Certification, within the limits set out in the Regulations.
7.2 Clients: equivalent obligations apply to the client and to anyone acting on their behalf pursuant to Article 1381 of the Italian Civil Code, in accordance with the corresponding clause of Indigo’s General Terms and Conditions.