PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

aisecurity.llc

Terms of Service

Effective June 27, 2026 · Version 2.1

Buyer-focused summary

  • These Terms cover the public website, self-service platform features, and online purchases.
  • Specific signed agreements control paid professional services and authorized security testing.
  • Using the site or platform does not authorize testing of any target.
  • AI outputs assist work, but do not replace human judgment or customer approval.
  • Public forms are not for secrets, access keys, or regulated production data.

1. Scope and Order of Precedence

These Terms govern access to the public website, trust center, legal pages, /scope and /start forms, no-cost scoping and intake workflows, self-service platform features, seat-based product purchases, LMS and academy access, Workbench Copilot, integrations, browser and native app surfaces where available, and related tools and services.

The covered surfaces can include the customer portal and platform web UI, generated packets and evidence artifacts, SSO/SAML/OIDC/SCIM onboarding, and other AI Security Workbench tools where those features are enabled or represented in product copy.

For paid professional services, private offers, security testing, AI Launch Security Reviews, pentests, red team engagements, customer data processing, or enterprise workspaces, the applicable SOW, Order Form, Private Offer, NDA, DPA, Assessment Terms, Rules of Engagement, Evidence Handling Policy, or other signed agreement controls if there is a conflict.

2. Workbench, Professional Services, Academy, OEM, and Partner Relationships

aisecurity.llc offers several distinct products and relationships, and they are not all governed by identical commercial terms:

  • AI Security Workbench — self-service and enterprise platform access, governed by these Terms and, where applicable, an order form, subscription agreement, or enterprise agreement.
  • Professional Services — paid, SOW-governed engagements (AI Launch Security Reviews, pentests, red-team assessments, advisory work), governed primarily by the signed SOW, Order Form, Assessment Terms Addendum, and Rules of Engagement. Where the SOW conflicts with these Terms, the SOW controls for that engagement.
  • Academy — seat-based LMS training access, governed by these Terms and any seat or enterprise training order.
  • OEM — engine or capability licensed into a partner's own product under a separate signed OEM or licensing agreement, which controls over these Terms for that relationship.
  • Partner — resellers, marketplace, interoperability, and consulting relationships governed by a separate signed partner agreement, which controls over these Terms for that relationship.

See the Relationship Matrix in the Data Processing Addendum — Public Summary for how ownership, deployment, and security boundaries typically differ across these surfaces.

3. Accounts and Organization Responsibilities

You must provide accurate account and organization information. You are responsible for activity under your account and for keeping credentials secure.

  • Admins may manage members, roles, seats, entitlements, and integrations where supported.
  • Assigned legal, finance, IT, or security contacts may receive role-specific tasks and notices.
  • Accounts may not be shared except as allowed by workspace or seat controls.
  • You must only submit targets, artifacts, or integrations you own, control, or are authorized to use.
  • The customer is responsible for ensuring its users have authority to bind the customer for the actions they take in the workspace.

4. Self-Service Purchases and Subscriptions

Where available, you may purchase seats, subscriptions, usage allotments, and LMS or academy access through Stripe or another payment provider. The payment provider processes card and payment details. We receive transaction metadata, plan and subscription status, invoice and receipt data, seat counts, and entitlement information needed to administer access.

  • Access is granted after successful payment or provisioning, subject to fraud and abuse checks.
  • Enterprise purchases may use a private offer, SOW, invoice, or contract path instead of self-service checkout.
  • Taxes, fees, and billing terms shown at checkout or in the order apply where applicable.
  • If a subscription renews automatically, the renewal terms shown at purchase control that renewal.
  • We do not store full card numbers.

5. No-Cost Scoping, NDA, and Professional Services

Scoping and intake are for qualification and planning. They are not, by themselves, a promise to perform paid services.

Users may request a no-cost scoping retainer or NDA before sharing confidential details. Public forms should receive only non-sensitive preliminary information. Confidential system details, targets, prompts, logs, evidence, or customer data should be shared only after the appropriate agreement path and secure channel are in place.

  • No-cost scoping can define access boundaries, draft the review plan, and align stakeholders before paid work begins.
  • No-cost scoping does not mean free consulting, free testing, or a guarantee of delivery.
  • Paid services require an accepted SOW, private offer, order form, or other written agreement.
  • Scope, fees, timing, deliverables, assumptions, acceptance, and retesting are governed by the applicable paid agreement.
  • Either party may decline to proceed before a paid agreement is signed.
  • Legal, finance, procurement, and technical scoping may run in parallel.

6. Authorized Security Testing

Using the website, platform, or scoping forms does not authorize security testing of any target. Active testing requires explicit written authorization and, where applicable, approved scope and Rules of Engagement.

  • Security testing, pentesting, red teaming, cloud testing, adversarial testing, exploit validation, agent or tool abuse testing, and production testing require an approved scope and, where applicable, Assessment Terms and Rules of Engagement.
  • You must only submit targets you own, control, or are authorized to assess. Third-party targets require third-party authorization.
  • Boundaries, test windows, stop conditions, emergency contacts, and evidence rules must be documented before testing starts.
  • Destructive testing, denial of service, persistence, malware, phishing, social engineering, credential stuffing, password spraying, data exfiltration, production data modification, and third-party impact are prohibited by default unless expressly authorized in writing.
  • Cloud provider rules, platform terms, and environment-specific approvals may apply.

See the Trust Center contracts page for the current Assessment Terms and Rules of Engagement: Trust Center contracts.

7. AI Features and Workbench Copilot

Where enabled, AI features may assist with scoping, packet generation, security analysis, drafting, triage, report generation, training, and workflow guidance. Workbench Copilot may process prompts, workspace context, selected artifacts, uploaded files, and retrieved context to provide those features.

  • AI outputs may be incomplete, stale, or wrong and require human review.
  • AI outputs are not legal advice, certification, or a final security determination.
  • Consequential customer-facing outputs, findings, attestations, claims, or deliverables require human review and applicable engagement approval.
  • Users must not use AI features to bypass authorization, generate harmful activity, fabricate evidence, impersonate others, or make unsupported claims.
  • Customer content submitted through approved business or API pathways is not authorized for public model training.
  • Confidential or regulated material should only be submitted through approved agreement and secure-channel paths.

8. Beta and Prelaunch Features

Features labeled beta, preview, early access, experimental, or similar are provided for evaluation only. They may change, be limited, or be discontinued at any time, may be incomplete, and are provided without warranty except where a signed agreement expressly states otherwise. Do not rely on beta or prelaunch features for production use, compliance, or consequential decisions.

9. Generated Outputs and Work Product

Draft packets, AI-assisted drafts, and self-service generated outputs are informational and may require further review. Professional services deliverables are governed by the applicable SOW, private offer, or other signed agreement.

  • Reports, findings, attestations, and evidence packs are point-in-time and scope-limited.
  • No output guarantees future security, remediation success, or compliance.
  • Claim-readiness language and public-safe summaries must match the applicable scope, date, limitations, and review path.
  • Draft or internal artifacts cannot be represented as final assurance.

10. Customer Content and Limited License

You retain ownership of Customer Content. You grant aisecurity.llc a limited, non-exclusive, worldwide license to host, process, transmit, display, reproduce, and use Customer Content only as needed to provide the website, platform, products, support, scoping workflows, security services, and agreed deliverables.

  • We do not sell Customer Content.
  • We do not use client confidential engagement materials to train public models or to publish examples without written approval.
  • We do not use client confidential engagement materials to improve unrelated offerings except as permitted by agreement or written approval.
  • Public-safe derivatives or anonymized learnings may be used only where allowed by the applicable agreement and privacy commitments.
  • Public forms are not for secrets, access keys, regulated data, or production credentials.

11. Feedback

If you send us feedback, ideas, or suggestions about the Services, you grant aisecurity.llc a perpetual, irrevocable, worldwide, royalty-free license to use that feedback for any purpose, without obligation or attribution to you. Do not submit feedback that contains Customer Content, secrets, or another party's confidential information.

12. Claims, Attestations, and References

You may not publicly claim certification, endorsement, continuous monitoring, compliance, or "approved by aisecurity.llc" unless we expressly authorize that claim in writing.

  • Any public-safe summary, attestation language, logo use, or buyer-facing claim must match the applicable scope, date, limitations, and claim-readiness terms.
  • Draft or internal artifacts cannot be represented as final assurance.
  • Research outputs, benchmarks, and public references must be used with proper attribution and without altering the underlying meaning.

Where claim language is part of the engagement, see the Publication & Claim-Readiness Policy.

13. Integrations and Third-Party Services

Where supported, you may connect third-party systems and SaaS services. You are responsible for having authority to connect those systems and for complying with their terms.

  • Data access depends on the scopes and permissions you grant.
  • Customer admins may manage or revoke connections where supported.
  • aisecurity.llc is not responsible for third-party services outside its control.
  • Integrations used in assessments may be subject to additional SOW, ROE, access, or evidence terms.
  • Users must not use integrations to violate third-party terms or local law.

14. Privacy and Data Protection

Privacy, AI processing, subprocessors, and customer data handling are governed separately by our Privacy Policy, AI Usage Policy, Customer Data & Model Training page, Subprocessors page, DPA, Evidence Handling Policy, Acceptable Use Policy, and Vulnerability Disclosure Policy.

Those documents are incorporated by reference where applicable and may provide additional requirements for a given engagement.

15. Disclaimers

Except as expressly stated in a signed agreement, the public website and self-service features are provided “as is” and “as available.” Paid professional services remain governed by their applicable SOW, order form, private offer, or other signed agreement. Features may change, beta or prelaunch capabilities may be incomplete, and AI outputs may be wrong.

  • Security findings, assessments, and reports are point-in-time and scope-limited.
  • No service prevents all vulnerabilities, incidents, or losses.
  • We do not provide legal advice.
  • Any warranties for paid professional services are governed by the applicable SOW or other signed agreement.

16. Limitation of Liability

For public website and self-service use, our aggregate liability for claims arising from those uses is limited to the greater of the amounts you paid us for the affected service in the 12 months before the claim or $100, to the extent permitted by law.

For paid professional services or enterprise agreements, the liability allocation in the signed SOW, Order Form, Private Offer, MSA, DPA, or other written agreement controls for that engagement.

Nothing in these Terms excludes liability that cannot be excluded under applicable law.

17. Export Controls and Sanctions

You may not use, export, re-export, or make the Services or related technology available in violation of U.S. export control or economic sanctions laws, including to a person, entity, country, or region subject to a U.S. government embargo or listed on a U.S. government restricted-party list. You represent that you are not located in, and are not ordinarily resident in, any such country or region, and are not on any such list.

18. Suspension and Termination

We may suspend or terminate access for violation of these Terms, nonpayment, abuse, security risk, legal risk, unauthorized testing, or misuse of AI or security tooling.

  • Access may also end when a subscription or engagement ends.
  • Data export, deletion, or retention after termination is handled under the Privacy Policy and the applicable agreement.
  • We may preserve records as needed for security, billing, legal, or contractual obligations.

19. Assignment

You may not assign or transfer these Terms, by operation of law or otherwise, without our prior written consent, except to a successor in connection with a merger, acquisition, or sale of substantially all of your assets. We may assign these Terms without restriction, including in connection with a merger, acquisition, reorganization, or sale of assets. Any attempted assignment in violation of this section is void.

20. Force Majeure

Neither party is liable for delay or failure to perform an obligation under these Terms (other than payment obligations) to the extent caused by events beyond its reasonable control, including natural disaster, war, terrorism, civil unrest, labor dispute, internet or utility failure, or action or inaction of a government authority.

21. Severability and Survival

If any provision of these Terms is held invalid or unenforceable, that provision will be limited or eliminated to the minimum extent necessary, and the remaining provisions will remain in full force and effect.

Provisions that by their nature should survive termination or expiration of these Terms — including Customer Content ownership and license limits, Feedback, Claims restrictions, Disclaimers, Limitation of Liability, Export Controls and Sanctions, Governing Law and Disputes, and any confidentiality obligations under a signed agreement — survive.

22. Notices

We may provide notices to you by email to the address on your account, through the Services, or by posting on the website. Legal notices to aisecurity.llc should be sent to legal@aisecurity.llc. Notices under a signed SOW, DPA, or other agreement follow the notice procedure stated in that agreement where it differs from this section.

23. Governing Law and Disputes

These Terms are governed by the laws of California, without regard to conflict-of-law rules. You agree to the exclusive jurisdiction of the state and federal courts in Los Angeles County, California, except for injunctive or equitable relief where permitted.

Before litigation, the parties should attempt good-faith informal resolution by contacting legal@aisecurity.llc and allowing a 30-day negotiation period.

24. Key Terms

AI Security Workbench
The hosted platform and product surface (also called the "Workbench") that provides scoping, packet generation, security analysis tools, Workbench Copilot, evidence handling, and related AI-security features to customers.
Customer Content
Files, prompts, targets, code, findings, artifacts, and other material a customer or its users submit to or generate through the Services. The customer retains ownership of Customer Content, subject to the limited license needed to provide the Services.
Professional Services
Paid, SOW-governed engagements such as AI Launch Security Reviews, penetration tests, red-team assessments, and advisory work, delivered under a signed Statement of Work, Order Form, Private Offer, Assessment Terms Addendum, or Rules of Engagement.
Academy
The LMS-based training product providing courses, labs, and certification workflows for security engineering and AI security skills, accessed through seat-based licenses.
OEM
A partner that licenses and embeds aisecurity.llc engine or analysis capability inside its own product under a signed OEM or licensing agreement, with responsibility boundaries defined in that agreement.
Partner
A reseller, marketplace, interoperability, consulting, or other third party with a signed partner agreement governing its relationship to aisecurity.llc and, where applicable, to shared or referred customers.
Pilot
A bounded, time-boxed evaluation engagement (for example a Vendor Pilot) with a defined input, capability, output contract, data boundary, and IP ownership, governed by its own SOW and ending in a documented proceed, revise, extend, or stop decision.
Authorized Testing
Security testing performed only after written scope authorization and, where applicable, an accepted Assessment Terms Addendum and Rules of Engagement. Using the website, platform, or scoping forms does not by itself authorize testing of any target.

25. Changes to These Terms

We may revise these Terms from time to time. When we do, we will update the effective date and provide notice for material changes when appropriate. Continued use after the revised Terms take effect means you accept them.

26. Contact

Terms of Service · aisecurity.llc · Effective June 27, 2026 · Version 2.1

← Back to Legal