NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

aisecurity.llc

Terms of Service

Effective June 27, 2026 · aisecurity.llc

Buyer-focused summary

  • These Terms cover the public website, self-service platform features, and online purchases.
  • Specific signed agreements control paid professional services and authorized security testing.
  • Using the site or platform does not authorize testing of any target.
  • AI outputs assist work, but do not replace human judgment or customer approval.
  • Public forms are not for secrets, access keys, or regulated production data.

1. Scope and Order of Precedence

These Terms govern access to the public website, trust center, legal pages, /scope and /start forms, no-cost scoping and intake workflows, self-service platform features, seat-based product purchases, LMS and academy access, SecEng Copilot, integrations, browser and native app surfaces where available, and related tools and services.

The covered surfaces can include the customer portal and platform web UI, generated packets and evidence artifacts, SSO/SAML/OIDC/SCIM onboarding, runtime proxy, model gateway, trace tooling, code scanner, adversarial range, RAG harness, artifact analyzer, security reports, attestations, and claim-readiness materials where those features are enabled or represented in product copy.

For paid professional services, private offers, security testing, AI Launch Security Reviews, pentests, red team engagements, customer data processing, or enterprise workspaces, the applicable SOW, Order Form, Private Offer, NDA, DPA, Assessment Terms, Rules of Engagement, Evidence Handling Policy, or other signed agreement controls if there is a conflict.

2. Accounts and Organization Responsibilities

You must provide accurate account and organization information. You are responsible for activity under your account and for keeping credentials secure.

  • Admins may manage members, roles, seats, entitlements, and integrations where supported.
  • Assigned legal, finance, IT, or security contacts may receive role-specific tasks and notices.
  • Accounts may not be shared except as allowed by workspace or seat controls.
  • You must only submit targets, artifacts, or integrations you own, control, or are authorized to use.
  • The customer is responsible for ensuring its users have authority to bind the customer for the actions they take in the workspace.

3. Self-Service Purchases and Subscriptions

Where available, you may purchase seats, subscriptions, usage allotments, and LMS or academy access through Stripe or another payment provider. The payment provider processes card and payment details. We receive transaction metadata, plan and subscription status, invoice and receipt data, seat counts, and entitlement information needed to administer access.

  • Access is granted after successful payment or provisioning, subject to fraud and abuse checks.
  • Enterprise purchases may use a private offer, SOW, invoice, or contract path instead of self-service checkout.
  • Taxes, fees, and billing terms shown at checkout or in the order apply where applicable.
  • If a subscription renews automatically, the renewal terms shown at purchase control that renewal.
  • We do not store full card numbers.

4. No-Cost Scoping, NDA, and Professional Services

Scoping and intake are for qualification and planning. They are not, by themselves, a promise to perform paid services.

Users may request a no-cost scoping retainer or NDA before sharing confidential details. Public forms should receive only non-sensitive preliminary information. Confidential system details, targets, prompts, logs, evidence, or customer data should be shared only after the appropriate agreement path and secure channel are in place.

  • No-cost scoping can define access boundaries, draft the review plan, and align stakeholders before paid work begins.
  • No-cost scoping does not mean free consulting, free testing, or a guarantee of delivery.
  • Paid services require an accepted SOW, private offer, order form, or other written agreement.
  • Scope, fees, timing, deliverables, assumptions, acceptance, and retesting are governed by the applicable paid agreement.
  • Either party may decline to proceed before a paid agreement is signed.
  • Legal, finance, procurement, and technical scoping may run in parallel.

5. Authorized Security Testing

Using the website, platform, or scoping forms does not authorize security testing of any target. Active testing requires explicit written authorization and, where applicable, approved scope and Rules of Engagement.

  • Security testing, pentesting, red teaming, cloud testing, adversarial testing, exploit validation, agent or tool abuse testing, and production testing require an approved scope and, where applicable, Assessment Terms and Rules of Engagement.
  • You must only submit targets you own, control, or are authorized to assess. Third-party targets require third-party authorization.
  • Boundaries, test windows, stop conditions, emergency contacts, and evidence rules must be documented before testing starts.
  • Destructive testing, denial of service, persistence, malware, phishing, social engineering, credential stuffing, password spraying, data exfiltration, production data modification, and third-party impact are prohibited by default unless expressly authorized in writing.
  • Cloud provider rules, platform terms, and environment-specific approvals may apply.

See the Trust Center contracts page for the current Assessment Terms and Rules of Engagement: Trust Center contracts.

6. AI Features and SecEng Copilot

Where enabled, AI features may assist with scoping, packet generation, security analysis, drafting, triage, report generation, training, and workflow guidance. SecEng Copilot may process prompts, workspace context, selected artifacts, uploaded files, and retrieved context to provide those features.

  • AI outputs may be incomplete, stale, or wrong and require human review.
  • AI outputs are not legal advice, certification, or a final security determination.
  • Consequential customer-facing outputs, findings, attestations, claims, or deliverables require human review and applicable engagement approval.
  • Users must not use AI features to bypass authorization, generate harmful activity, fabricate evidence, impersonate others, or make unsupported claims.
  • Customer content submitted through approved business or API pathways is not authorized for public model training.
  • Confidential or regulated material should only be submitted through approved agreement and secure-channel paths.

7. Generated Outputs and Work Product

Draft packets, AI-assisted drafts, and self-service generated outputs are informational and may require further review. Professional services deliverables are governed by the applicable SOW, private offer, or other signed agreement.

  • Reports, findings, attestations, and evidence packs are point-in-time and scope-limited.
  • No output guarantees future security, remediation success, or compliance.
  • Claim-readiness language and public-safe summaries must match the applicable scope, date, limitations, and review path.
  • Draft or internal artifacts cannot be represented as final assurance.

8. Customer Content and Limited License

You retain ownership of customer content. You grant aisecurity.llc a limited, non-exclusive, worldwide license to host, process, transmit, display, reproduce, and use customer content only as needed to provide the website, platform, products, support, scoping workflows, security services, and agreed deliverables.

  • We do not sell customer content.
  • We do not use client confidential engagement materials to train public models or to publish examples without written approval.
  • We do not use client confidential engagement materials to improve unrelated offerings except as permitted by agreement or written approval.
  • Public-safe derivatives or anonymized learnings may be used only where allowed by the applicable agreement and privacy commitments.
  • Public forms are not for secrets, access keys, regulated data, or production credentials.

9. Claims, Attestations, and References

You may not publicly claim certification, endorsement, continuous monitoring, compliance, or "approved by aisecurity.llc" unless we expressly authorize that claim in writing.

  • Any public-safe summary, attestation language, logo use, or buyer-facing claim must match the applicable scope, date, limitations, and claim-readiness terms.
  • Draft or internal artifacts cannot be represented as final assurance.
  • Research outputs, benchmarks, and public references must be used with proper attribution and without altering the underlying meaning.

Where claim language is part of the engagement, see the Publication & Claim-Readiness Policy.

10. Integrations and Third-Party Services

Where supported, you may connect third-party systems and SaaS services. You are responsible for having authority to connect those systems and for complying with their terms.

  • Data access depends on the scopes and permissions you grant.
  • Customer admins may manage or revoke connections where supported.
  • aisecurity.llc is not responsible for third-party services outside its control.
  • Integrations used in assessments may be subject to additional SOW, ROE, access, or evidence terms.
  • Users must not use integrations to violate third-party terms or local law.

11. Privacy and Data Protection

Privacy, AI processing, subprocessors, and customer data handling are governed separately by our Privacy Policy, AI Usage Policy, Customer Data & Model Training page, Subprocessors page, DPA, Evidence Handling Policy, Acceptable Use Policy, and Vulnerability Disclosure Policy.

Those documents are incorporated by reference where applicable and may provide additional requirements for a given engagement.

12. Disclaimers

The website, platform, and services are provided as available. Features may change, beta or prelaunch capabilities may be incomplete, and AI outputs may be wrong.

  • Security findings, assessments, and reports are point-in-time and scope-limited.
  • No service prevents all vulnerabilities, incidents, or losses.
  • We do not provide legal advice.
  • Any warranties for paid professional services are governed by the applicable SOW or other signed agreement.

13. Limitation of Liability

For public website and self-service use, our aggregate liability for claims arising from those uses is limited to the greater of the amounts you paid us for the affected service in the 12 months before the claim or $100, to the extent permitted by law.

For paid professional services or enterprise agreements, the liability allocation in the signed SOW, Order Form, Private Offer, MSA, DPA, or other written agreement controls for that engagement.

Nothing in these Terms excludes liability that cannot be excluded under applicable law.

14. Suspension and Termination

We may suspend or terminate access for violation of these Terms, nonpayment, abuse, security risk, legal risk, unauthorized testing, or misuse of AI or security tooling.

  • Access may also end when a subscription or engagement ends.
  • Data export, deletion, or retention after termination is handled under the Privacy Policy and the applicable agreement.
  • We may preserve records as needed for security, billing, legal, or contractual obligations.

15. Governing Law and Disputes

These Terms are governed by the laws of California, without regard to conflict-of-law rules. You agree to the exclusive jurisdiction of the state and federal courts in Los Angeles County, California, except for injunctive or equitable relief where permitted.

Before litigation, the parties should attempt good-faith informal resolution by contacting legal@aisecurity.llc and allowing a 30-day negotiation period.

16. Changes to These Terms

We may revise these Terms from time to time. When we do, we will update the effective date and provide notice for material changes when appropriate. Continued use after the revised Terms take effect means you accept them.

17. Contact

Legal questions or notices: legal@aisecurity.llc

Related documents: Privacy Policy, AI Usage Policy, Customer Data & Model Training, Subprocessors, Evidence Handling Policy, Assessment Terms, Rules of Engagement, and Acceptable Use Policy.

Terms of Service · aisecurity.llc · Effective June 27, 2026 · Version 2.0

← Back to Legal