Terms of Service
1. Acceptance
These Terms of Service ("Terms") form a binding agreement between you ("Customer") and AuditAI ("AuditAI," "we," "our") governing access to and use of the AuditAI platform, including web application, APIs, and related services (collectively, the "Service"). By creating an account, signing an order form, or otherwise accessing the Service, Customer agrees to these Terms.
2. Service description
The Service is a multi-tenant SaaS workbench for delivering AI workflow audits aligned to NIST AI RMF, ISO/IEC 42001, OWASP Top 10 for LLM Applications, the EU AI Act, MITRE ATLAS, and US state AI laws. AuditAI provides software, content libraries, and AI-assisted drafting; AuditAI does not, by virtue of providing the Service, become an auditor of Customer's clients or their AI systems.
3. Customer accounts and authority
Customer is responsible for: (a) maintaining the confidentiality of credentials, (b) all activity under its accounts, (c) ensuring users it invites are authorised to access the underlying audit work, and (d) keeping organisation contact and billing information current.
4. Permitted use
Subject to these Terms, AuditAI grants Customer a non-exclusive, non-transferable, revocable right to use the Service for its internal business purposes during the subscription term. Customer must comply with the Acceptable Use Policy.
5. Restrictions
Customer will not:
- reverse engineer, decompile, or attempt to derive source code or model weights;
- use Service outputs to train, fine-tune, or evaluate competing AI services;
- resell, sublicense, or repackage the Service except through a licensed licensee tier;
- circumvent rate limits, billing controls, or any technical safeguard;
- upload malware, content that violates law, or content for which Customer lacks rights.
6. Customer Data and ownership
As between the parties, Customer owns Customer Data (including engagement records, evidence files, surveys, and findings). Customer grants AuditAI a limited licence to process Customer Data solely to provide the Service, generate reports requested by Customer, produce de-identified, aggregated, k-anonymised benchmarks, and improve the Service consistent with the Privacy Policy and Data Processing Addendum.
7. AI-assisted outputs
The Service uses Claude (Anthropic) to draft findings, recommendations, executive summaries, and similar content. AI-drafted content is labelled in the report. Customer retains responsibility for the auditor's review, sign-off, and delivery to its end clients. AuditAI does not warrant that AI-drafted content is free of errors or suitable without human review.
8. Subscriptions, billing, taxes
Subscriptions auto-renew at the end of each term unless cancelled in advance through the Stripe customer portal. Fees are non-refundable except as required by law. AuditAI uses Stripe Tax to compute and collect applicable VAT, GST, or sales tax.
AuditAI may change pricing on at least 30 days' notice prior to a renewal term. Failed payments enter a 7-day grace period; if the invoice remains unpaid the account is suspended in accordance with Section 12.
9. Trial
New auditor firms may receive a 14-day free trial of a paid tier. Trials convert to a paid subscription unless cancelled before expiry. Trial periods are non-transferable and non-renewable.
10. Confidentiality
Each party will keep the other's Confidential Information in confidence using at least the same degree of care it uses for its own (no less than reasonable). Customer Data is Confidential Information of Customer. The Service's features, performance, and pricing not publicly disclosed are Confidential Information of AuditAI.
11. Security and incident response
AuditAI maintains organisational and technical safeguards described on the Security page. AuditAI will notify Customer of a confirmed security incident affecting Customer Data without undue delay and in any event within 72 hours of confirmation, consistent with the DPA.
12. Suspension
AuditAI may suspend access for: (a) non-payment after the grace period, (b) violation of the Acceptable Use Policy, (c) a credible security threat, or (d) court order or legal process. AuditAI will provide notice and an opportunity to cure where practical.
13. Termination
Either party may terminate for material breach uncured within 30 days of written notice. Upon termination, Customer's data export is available for 30 days through the in-app export tools and the GDPR portability endpoint. After 30 days, AuditAI will delete Customer Data per the retention policy in the DPA, except for backups and audit-log entries retained for security and regulatory purposes.
14. Warranties and disclaimers
AuditAI warrants that the Service will perform substantially as described in the documentation. EXCEPT AS EXPRESSLY STATED, THE SERVICE IS PROVIDED "AS IS" AND AUDITAI DISCLAIMS ALL OTHER WARRANTIES INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
15. Indemnification
AuditAI will defend Customer against third-party claims that the Service, used in accordance with these Terms, infringes a third party's intellectual property rights, and pay damages finally awarded. Customer will defend AuditAI against third-party claims arising from Customer Data, Customer's use in violation of the AUP, or Customer's representations to its end clients.
16. Limitation of liability
EXCEPT FOR EXCLUDED CLAIMS (INDEMNIFICATION OBLIGATIONS, BREACH OF CONFIDENTIALITY, VIOLATION OF THE AUP, OR FEES OWED), EACH PARTY'S AGGREGATE LIABILITY FOR ANY CLAIM IS LIMITED TO THE FEES PAID OR PAYABLE BY CUSTOMER IN THE 12 MONTHS PRECEDING THE CLAIM. NEITHER PARTY IS LIABLE FOR INDIRECT, INCIDENTAL, OR CONSEQUENTIAL DAMAGES, INCLUDING LOST PROFITS OR LOST DATA.
17. Governing law and dispute resolution
These Terms are governed by the laws of the State of Delaware, USA, without regard to conflict-of-laws rules. The parties consent to the exclusive jurisdiction of state and federal courts in Delaware for any dispute not subject to arbitration. Either party may elect binding arbitration administered by JAMS for any individual claim under $250,000.
18. Changes
AuditAI may update these Terms by posting a revised version with a new effective date. Material changes will be communicated by email or in-app notice at least 30 days before they take effect for existing customers.
19. Contact
Legal inquiries: legal@auditai.example. Notices to AuditAI must be in writing to that address.