Acceptable Use Policy
Published from canon — August 2026
- ACCEPTABLE USE POLICY
- 1. Permitted Use
- 3. Prohibited Content
- 4. Prohibited Activities
- 5. Reporting and Cooperation
- 6. Enforcement
- 7. Modifications
- 8. Contact
- Per-Brand Addenda
- Addendum — AccessConform
- Addendum — BreachDuty
- Addendum — DefenseScore
- Addendum — DSAR Engine
- Addendum — EllisIQ Practice (EllisIQ app)
- Addendum — Foothold
- Addendum — GovernMark
- Addendum — Peony & Lace
- Addendum — PlainNotice
- Addendum — RenewalProof
- Addendum — Reply Engine
- Addendum — RIAMark
- Addendum — SafeguardsMark
- Addendum — SRAReady
- Addendum — Underwrite
ACCEPTABLE USE POLICY
Effective Date: at product launch Brand: Ellis Intelligence LLC Operator: Ellis Intelligence LLC, a Colorado limited liability company ("we", "us", "our")
This Acceptable Use Policy ("AUP") governs your access to and use of the Ellis Intelligence LLC platform, web application, APIs, and related services (collectively, the "Service"). By accessing or using the Service, you ("Customer", "you") agree to this AUP. This AUP is incorporated into and forms part of our Terms of Service. This AUP is governed by the Terms of Service it accompanies, including its governing-law and dispute-resolution provisions.
If you violate this AUP, we may suspend or terminate your access without prior notice or refund and may pursue any other remedy available to us.
1. Permitted Use
You may use the Service only:
(a) For your own internal business purposes, or, if you operate as a service provider, for purposes of providing services to your direct end customers under your own customer relationships;
(b) In compliance with all applicable laws, regulations, and the Terms of Service;
(c) Within the usage limits of your subscription tier (rate limits, seats, document counts, storage caps); and
(d) Subject to the additional per-brand restrictions in the addendum below.
3. Prohibited Content
You will not upload, transmit, store, or generate through the Service any content that:
(a) Violates any applicable law, including export-control law, anti-bribery law, or law applicable to the handling of regulated data;
(b) Infringes any third party's intellectual property, privacy, publicity, or other rights;
(c) Contains malware, ransomware, exploits, worms, viruses, or any other code designed to interfere with software or hardware;
(d) Is unlawful, defamatory, harassing, threatening, hateful, obscene, or sexually exploitative;
(e) Constitutes "sensitive personal information" in jurisdictions where the Service is not designed to process it, or constitutes regulated data (protected health information ("PHI"), Payment Card Industry ("PCI") cardholder data, classified national-security information, or Controlled Unclassified Information ("CUI") / Federal Contract Information ("FCI")) unless your subscription tier and a separate written agreement expressly permit such use;
(f) You are not authorized to share, transmit, or process. This prohibition includes, without limitation, content covered by another party's confidentiality obligations that you cannot lawfully share with us.
4. Prohibited Activities
You will not, and will not permit any third party to:
4.1 Service Integrity.
(a) Attempt to gain unauthorized access to any portion of the Service, including any other tenant's data;
(b) Probe, scan, or test the vulnerability of the Service except through a coordinated security-research program we publish or pre-authorize in writing;
(c) Interfere with or disrupt the Service, including by overloading, flooding, or sending malformed input designed to cause failure;
(d) Reverse-engineer, decompile, or attempt to extract the source code, model weights, training data, or underlying architecture of the Service;
(e) Circumvent or attempt to circumvent rate limits, usage caps, billing controls, or feature gates;
(f) Use the Service to build or train a competing product, including by using Service outputs to train a model offered to third parties;
(g) Scrape, harvest, or systematically extract data from the Service except through the documented API at the rates we permit.
4.2 Resale and Wrapping. Except where your subscription tier explicitly grants white-label or reseller rights (see per-brand addendum):
(a) You will not resell, sublicense, lease, or wrap the Service for delivery to third parties as if it were your own;
(b) You will not use the Service to provide services to end customers without disclosing that the Service is built on third-party infrastructure (you may disclose by reference to our brand or generically — your choice).
4.3 AI and Output Use.
(a) You acknowledge the Service uses artificial intelligence systems whose outputs may be inaccurate, incomplete, biased, or contain hallucinations;
(b) Outputs may contain errors or omissions, and we make no warranty as to the accuracy, completeness, or reliability of any output. The Service assists your work; it does not make decisions for you. You will independently verify outputs before relying on them, and before submitting them to any third party, for any decision with legal, financial, professional, or safety consequences;
(c) You will not represent any output as having been generated by a human, where representation as human is material to the recipient (deception about AI authorship);
(d) You will preserve any disclaimers or attribution that the Service applies to outputs unless your subscription tier expressly grants removal rights;
(e) You will not use outputs to take any action prohibited by law, including but not limited to unauthorized practice of law, unauthorized practice of medicine, unauthorized financial advice, or unauthorized insurance brokerage (per-brand addenda contain track-specific clarifications).
4.4 Data Hygiene.
(a) You will not upload personally identifiable information ("PII") of any individual without a lawful basis under applicable privacy law;
(b) You will not upload data that you obtained through unauthorized access, theft, or breach of any third party's confidentiality;
(c) You will not upload children's data (subjects under 13 in the U.S., or, in the EU, under the applicable age of digital consent — 16 by default under the GDPR, though Member States may set it as low as 13) without verifiable parental or guardian consent and proper safeguards;
(d) You will not transmit sensitive data — including credentials, PII, or the regulated-data categories in §3(e) — to or from the Service over unencrypted channels. You will access the Service only through the encrypted (TLS) endpoints we provide and will not disable, downgrade, or bypass transport encryption. Our own commitments regarding encryption of data at rest and in transit are stated in the Data Processing Addendum and are not restated here.
4.5 Customer Responsibility; Indemnification. As between you and us, you are responsible for the lawfulness of the data you submit to the Service and of the instructions, configurations, and directions you give in using it, including every representation of lawful basis, authorization, or consent made in this AUP or in the per-brand addendum applicable to your subscription. Violations of this AUP (including those representations) that give rise to a third-party claim against us are covered by the indemnification provisions of the Terms of Service, subject to the conditions and procedures stated there; where the DPA applies, this allocation does not excuse our own compliance with our obligations under the DPA.
5. Reporting and Cooperation
5.1 Reporting Violations. Report suspected AUP violations to [email protected]. Include the relevant account or tenant identifier, a description of the issue, and any supporting evidence.
5.2 Legal Requests. We will respond to lawful subpoenas, court orders, and government requests in compliance with applicable law. We will notify the affected Customer where lawful to do so.
5.3 Cooperation. You will cooperate reasonably with any investigation of suspected AUP violations involving your account.
6. Enforcement
6.1 Range of Actions. Depending on severity, we may take any one or more of the following actions in response to an AUP violation:
(a) Issue a written warning;
(b) Temporarily throttle, restrict, or suspend specific features of your account;
(c) Suspend your account in full pending investigation;
(d) Terminate your account immediately for material breach;
(e) Refer the matter to law enforcement;
(f) Pursue civil remedies, including monetary damages and injunctive relief.
6.2 Material Breach — Immediate Action. The following constitute material breach permitting immediate suspension or termination without prior notice or refund:
(a) Any activity prohibited under §3 (Prohibited Content) involving illegal content, malware, or regulated-data violations;
(b) Any activity prohibited under §4.1 (Service Integrity) involving unauthorized access, vulnerability probing without authorization, or denial-of-service activity;
(c) Use of the Service in violation of export-control law, sanctions law, or anti-bribery law;
(d) Repeated lower-severity violations after written warning.
6.3 Refund Policy on Termination for AUP Violation. No refund of pre-paid fees is owed for the billing period in which the violation occurred. Future billing periods are credited or refunded in accordance with the refund provisions of the Terms of Service.
6.4 Survival. Termination, suspension, or expiration of your account or subscription does not relieve you of obligations that by their nature should survive, including but not limited to: obligations of confidentiality; obligations regarding the return or destruction of data (as provided in the Terms of Service and, where applicable, the DPA); the representations in §4.5; and liability for AUP violations accruing before termination.
7. Modifications
We may update this AUP from time to time. Material changes will be communicated by written notice sent by email to the account's designated contacts (or by in-product notice) and, in addition, posted at ellisintel.com/acceptable-use. Written notice is deemed given when sent; failure to read a properly sent notice does not extend any period. Each change takes effect on the effective date stated in the notice, and continued use of the Service after that effective date constitutes acceptance of the updated AUP.
8. Contact
Questions about this AUP: [email protected] (or current legal contact) Security and abuse reports: [email protected]
Per-Brand Addenda
Addendum — AccessConform
In addition to the base AUP:
AC1. Methodology Output — Not a Legal-Compliance Guarantee. AccessConform produces accessibility findings and an Accessibility Conformance Report ("ACR") / Voluntary Product Accessibility Template ("VPAT") style artifact using Web Content Accessibility Guidelines ("WCAG") / Section 508 / EN 301 549 methodology. It does not guarantee ADA, Section 508, or any legal compliance, and is not legal advice. The ACR/VPAT renders as plain text/typography only — no seal, badge, ribbon, watermark, or certificate-style graphic — so it does not visually resemble a third-party validation mark.
AC2. Automated-Detection Limits. Automated checks do not catch every issue that manual testing would. An ACR reflects the methodology and scope you ran, not a warranty of full conformance.
AC3. Customer Responsibility. You are responsible for the accuracy of any conformance statement you publish or share with a requesting party.
AC4. Share-ACR Integrity. Where the Service lets you share the methodology statement with a requesting reviewer, you will not alter it to overstate conformance.
Addendum — BreachDuty
In addition to the base AUP:
BD1. Obligation Map — Not a Legal Determination. BreachDuty computes notification obligations and deadlines from statutes it cites and from facts you enter. It is not a legal determination, certification, or opinion, and it is not a substitute for your counsel's judgment. You will not represent to any regulator, attorney general, consumer, auditor, or insurer that BreachDuty has determined, certified, or opined on your obligations.
BD2. Scope — Atlas and Clock Only. The Service is scoped to the obligation map and the timing clock. It does not generate, assemble, or deliver breach-notification content.
BD3. Notice Origination and Delivery Are Yours; Heightened Responsibility. You and your counsel originate, draft, assemble, and deliver every notice through your own systems. The Service never transmits anything to a regulator, attorney general, or consumer, and you will not attempt to configure or integrate it to do so. Because a delivered notice reaches a regulator, attorney general, or consumer — a party outside your control once sent — you bear sole responsibility for its accuracy, completeness, and legal sufficiency. Our non-involvement in delivery does not shift that responsibility to us.
BD4. Accuracy of Inputs. You are responsible for the accuracy of the incident facts, data categories, and jurisdictional inputs you enter.
Addendum — DefenseScore
In addition to the base AUP:
DS1. Self-Computed Score — Not an Official DoD/SPRS Score. DefenseScore computes a score from your inputs using the methodology of the U.S. Department of Defense ("DoD") Supplier Performance Risk System ("SPRS"). It is not the official score in DoD's SPRS, is not submitted to SPRS by us, and is not a Cybersecurity Maturity Model Certification ("CMMC") assessment or a certified third-party assessment organization ("C3PAO") / certified CMMC assessor ("CCA") service. The score renders as plain text/typography only — no seal, badge, ribbon, watermark, or certificate-style graphic — so it does not visually resemble a third-party validation mark.
DS2. Your Submission and Affirmation. You are responsible for the accuracy of your control inputs and for your own SPRS submission and annual affirmation. DefenseScore tracks clocks and computes; you submit.
DS3. Not Legal or Compliance Advice. The score, Plan of Action and Milestones ("POA&M") clock, and affirmation reminders are aids, not legal advice and not a guarantee of CMMC or Defense Federal Acquisition Regulation Supplement ("DFARS") compliance.
DS4. No Government Transmission. We do not transmit your data to SPRS or any government system.
Addendum — DSAR Engine
In addition to the base AUP:
D1. Consumer Intake Page — Your Responsibility. DSAR Engine hosts a Customer-configurable public intake page at which consumers submit privacy requests and complete identity verification. We host and render that page as your processor and on your behalf. You are the controller of every request and of the consumer data collected through that page. You represent that you have a lawful basis to receive, verify, track, and fulfill each request, and you are responsible for the content of any copy, logo, or accent you apply to the page (light white-label only).
D2. Verification-PII Minimization. You will select the lightest identity-verification method that meets your needs (email / document / third_party) and will not configure or use the Service to collect verification PII beyond what that method requires. You will not repurpose the intake page or the verification flow as a general identity-collection or identity-verification service.
D3. You Fulfill; We Track. The Service tracks deadlines and logs each step; it does not gather, redact, or transmit consumer data on your behalf, and it does not decide whether a request is valid. You will review and complete every fulfillment step (gather, redact, fulfill, close) yourself. You will not represent that DSAR Engine fulfills requests, validates requests, or guarantees compliance.
D4. Audit Export Is Integrity, Not Compliance. The chain-of-custody export evidences that a request record was not altered. You will not represent the export as a certification that you are compliant with any privacy law. The export renders as plain text/typography only — no seal, badge, ribbon, watermark, or certificate-style graphic — so it does not visually resemble a third-party validation mark.
D5. No Resale or Nested Tenancy. DSAR Engine is flat multi-tenant: one organization, one tenant. You may not provision Service access to other organizations as a resold, managed, or sub-tenant service without a separate executed agreement.
D6. Regulatory Contingency. If a regulatory body issues guidance or a rule that affects DSAR Engine's lawful operation in a state or for a use case, we may modify, restrict, or withdraw the Service accordingly, on written notice given per §7's notice mechanics and with pro rata refund per the Terms of Service.
D7. Fulfillment Reaches the Data Subject Directly; Heightened Responsibility. The Service does not auto-transmit any fulfillment response on your behalf; per D3, every delivery to a data subject requires your own affirmative action. Because a completed fulfillment step delivers a response directly to the data subject who submitted the request — an external party outside your control once delivered — and privacy regulators may examine your handling of that request, the disclaimers in D3 do not limit your responsibility for the accuracy, completeness, and legal sufficiency of what you deliver.
Addendum — EllisIQ Practice (EllisIQ app)
In addition to the base AUP:
E1. Legal-Practice Use Disclaimer. EllisIQ is a software vendor. EllisIQ is not a law firm and does not provide legal services or legal advice. No attorney-client relationship is created by your use of EllisIQ or by any output of the Service. Outputs are drafts intended for review by a licensed attorney before reliance.
E2. Bar Rules Compliance. You will use EllisIQ only in compliance with the Rules of Professional Conduct of each jurisdiction in which you practice, including without limitation rules governing competence (Model Rule 1.1), confidentiality (Model Rule 1.6), supervision (Model Rules 5.1 and 5.3), unauthorized practice of law (Model Rule 5.5), and disclosure of AI use where required.
E3. Output Disclaimers. All outputs include a "Draft for attorney review" disclaimer. You will not remove or obscure this disclaimer when distributing output to clients, courts, opposing counsel, or third parties.
E4. Privileged Information. You acknowledge that uploading attorney-client privileged information to EllisIQ may carry privilege risks. We process customer data through the Anthropic API, our AI/model subprocessor; personally identifying values are masked in the payload before it is sent and restored only in the response shown to you. We do not store privileged data beyond what is necessary to perform services. Privilege determination is yours to make for your matters.
E5. No Use as a Decision Engine for Client Matters. EllisIQ outputs are drafts and analysis aids. You will not configure EllisIQ to make autonomous decisions on a client matter (e.g., filing a document, sending a court submission, agreeing to a settlement) without attorney review.
Addendum — Foothold
In addition to the base AUP:
F1. Eligibility-Monitoring Tool — Not a Registered Agent or Legal Advice. Foothold surfaces federal-contracting eligibility signals (e.g., SAM.gov registration status, set-aside eligibility). It is not a registered agent, law firm, accountant, or contracting advisor, and does not provide legal advice. Determinations of eligibility, registration, and award are made by the relevant government system.
F2. Veteran-Tier Verification. The free veteran tier requires good-faith veteran-status verification. Misrepresenting veteran status to obtain it is prohibited and is grounds for immediate termination.
F3. Public-Source Data. Eligibility signals derive from public federal sources; we do not guarantee their accuracy or currency. Verify against the authoritative system before relying on any signal.
F4. No Autonomous Filing. Foothold does not file, submit, register, or transact with any government system on your behalf.
Addendum — GovernMark
In addition to the base AUP:
G1. Self-Attestation — Not a Certification. GovernMark produces a self-attested AI-governance artifact aligned to the National Institute of Standards and Technology Artificial Intelligence Risk Management Framework ("NIST AI RMF"). It is not a certification, audit, accreditation, or third-party assessment. The artifact reflects the information you attest to. The artifact renders as plain text/typography only — no seal, badge, ribbon, watermark, or certificate-style graphic — so it does not visually resemble a third-party validation mark.
G2. Accuracy of Inputs. You are responsible for the accuracy of the governance information you attest to. A sealed artifact built on inaccurate inputs is your representation, not ours.
G3. Not Legal or Compliance Advice. The artifact and the NIST-RMF mapping are aids, not legal advice and not a guarantee that you satisfy any framework, law, or customer requirement.
G4. Output Verification. Per base §4.3, you will independently verify AI-assisted outputs before relying on or distributing them.
Addendum — Peony & Lace
In addition to the base AUP:
P1. White-Label and Sub-Tenant Use. Peony & Lace's Studio and Pro tiers permit you to operate planner-branded couple-facing portals. The end couples ("End Users") are not parties to your subscription with us; they access only the portal you provision for them.
P2. End User Data. You represent that you have a lawful basis (typically contractual) to share each couple's wedding-planning data with us through the Service. You are the data controller; we are the data processor. The DPA addendum governs.
P3. No Resale as White-Label SaaS to Third-Party Planners. Studio tier permits you to use Peony & Lace for your own planning business. You may not provision Peony & Lace access to other wedding planners as a sub-resold service. Reseller arrangements require a separate written agreement.
P4. End User Communication. Communications to End Users (couples) sent through the Service must comply with applicable law and may not mislead End Users about the source of automated content. Couple-facing portals include a discreet "powered by Peony & Lace" footer that you may suppress only on Studio annual prepay accounts.
P5. Wedding Vendor Inquiries. You may use the Service to draft outreach to wedding vendors (venues, photographers, florists). You will not use the Service to spam vendors, to misrepresent yourself, or to send templated outreach at a volume that triggers a vendor's spam filtering or reporting threshold.
Addendum — PlainNotice
In addition to the base AUP:
PN1. Post-Decision Use Only; Your Underlying Compliance. You will use the Service only to generate and time adverse-action notices for decisions you (or a client company on whose behalf you manage adverse-action workflows (each, a "Client Company")) have already made, and only where you or that Client Company obtained the underlying consumer report lawfully and are the party carrying the Fair Credit Reporting Act ("FCRA") obligations for it. The Service is not part of how a consumer report is requested, obtained, or furnished — we are not the end user, a consumer reporting agency, or a reseller — and you will not upload or transmit a consumer report to the Service.
PN2. CRA Multi-Client Representations. On consumer-reporting-agency ("CRA") tiers, you represent that you are authorized to manage adverse-action workflows for each Client Company you onboard and that you have a lawful basis to share each Client Company's applicant data with us.
PN3. Human Review; No Banned Representations. Generated notices are drafts you review before delivery. You will not represent that PlainNotice "guarantees" FCRA compliance, produces "bulletproof" notices, or is "set-and-forget."
PN4. Business Use Only. The Service is for businesses (CRAs and Client Companies). It may not be used by or on behalf of individual applicants.
PN5. Delivery Is Yours; Heightened Responsibility for Delivered Notices. The Service generates notices and records delivery events; it does not itself deliver, mail, email, or otherwise transmit a generated notice to any applicant, consumer, or regulator. You (or your Client Company) deliver each notice yourself, through your own channels, only after the human review required by PN3. Because a delivered notice reaches the applicant directly — outside our control, and once sent, outside your own — and is itself an FCRA-regulated consumer disclosure that a regulator may examine, you bear sole responsibility for the accuracy and legal sufficiency of each notice at the moment you deliver it.
Addendum — RenewalProof
In addition to the base AUP:
RP1. Self-Conducted Exercise — Not an Assessment or Endorsement. RenewalProof records what your team does and decides during a tabletop exercise and produces a documentation artifact from it. It does not assess, grade, score, or validate your incident-response capability, and it is not affiliated with, endorsed by, or acting on behalf of any insurance carrier, broker, or producer. The artifact carries an issuance mark identifying who issued it and when; that mark records authorship and time, not verification.
RP2. Accuracy of Inputs. You are responsible for the accuracy of the plan content, participant records, and decisions your team enters.
RP3. No Representation to Carriers. You will not represent to any carrier, broker, underwriter, or auditor that RenewalProof has certified, assessed, graded, or validated your readiness.
RP4. Outputs Are Records. The artifact documents an exercise you ran; it is not legal advice, an insurance requirement determination, or a guarantee of any coverage or premium outcome.
Addendum — Reply Engine
In addition to the base AUP:
A1. Vendor Security Questionnaire Inputs. Questionnaires you upload may contain confidential information of a prospective enterprise customer of yours. You represent that you have the right to share each questionnaire with us for processing under our Data Processing Addendum ("DPA"). You will not upload questionnaires you obtained in breach of any non-disclosure agreement ("NDA"), NDA-equivalent confidentiality obligation, or request-for-proposal ("RFP")/vendor-selection process rule that prohibits AI-assisted response.
A2. Human Approval Required. Reply Engine outputs are drafts. You will not configure or use the Service to auto-submit a questionnaire response to an end recipient without human review. We may, in our discretion, suspend any account that we detect bypassing the human-approval rail.
A3. No Resale. Reply Engine seats are for your own organization's questionnaire-response workload. You may not resell Reply Engine seats to third parties as a managed-service or as a vendor-questionnaire-as-a-service offering without an executed reseller agreement.
Addendum — RIAMark
In addition to the base AUP:
RM1. Compliance-Calendar Tool — NOT Legal, Compliance, or Investment Advice. RIAMark is not an investment adviser, is not registered with or licensed by the SEC, FINRA, or any state securities regulator, and does not provide investment advice, legal advice, or regulatory advice, in any form. RIAMark calculates Form ADV and state / U.S. Securities and Exchange Commission ("SEC") regulatory deadlines from your inputs. It is a compliance-calendar tool only — it is not a law firm, compliance consultant, or investment adviser, and does not provide legal, regulatory, or investment advice.
RM2. Accuracy of Inputs; Your Filing Obligation. Deadlines depend on the registration, jurisdiction, and entity facts you provide and on rules that change. You remain solely responsible for your Form ADV and all regulatory filings and for verifying every deadline against the current SEC/state rule.
RM3. No Filing on Your Behalf. RIAMark does not file with the SEC, any state securities regulator, or the Investment Adviser Registration Depository ("IARD") / Financial Industry Regulatory Authority ("FINRA") on your behalf.
RM5. No Regulatory Review, Approval, or Endorsement. RIAMark, its calculations, and its outputs (including the Amendment Checklist PDF) have not been reviewed, approved, endorsed, certified, or sponsored by the SEC, the Financial Industry Regulatory Authority ("FINRA"), the Investment Adviser Registration Depository ("IARD"), any state securities regulator, or any other regulatory body. Nothing in the Service, its outputs, or its marketing should be read to imply any such review, approval, or endorsement.
Addendum — SafeguardsMark
In addition to the base AUP:
SM1. WISP Builder — Not Legal or Compliance Advice. SafeguardsMark helps you build a Written Information Security Program ("WISP") for the Federal Trade Commission ("FTC") Safeguards Rule under the Gramm-Leach-Bliley Act ("GLBA") from your inputs. It is not legal advice and does not guarantee compliance with the Safeguards Rule or any law. The WISP and its tamper-evidence seal render as plain text/typography only — no seal graphic, badge, ribbon, watermark, or certificate-style image — so it does not visually resemble a third-party validation mark.
SM2. Accuracy; Your Obligation. The WISP reflects the program facts you provide. You remain responsible for implementing, maintaining, and accurately representing your security program, and for your Safeguards Rule compliance.
SM3. No Customer Financial Data. The Service does not require customer financial-account or consumer financial data; do not upload it.
SM4. Outputs Are Drafts. The WISP and supporting documents are drafts you review and adopt.
Addendum — SRAReady
In addition to the base AUP:
SR1. SRA Aid — Not a Substitute or Legal Advice. SRAReady guides a security risk assessment ("SRA") under the Security Rule of the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") from your inputs. It is not legal advice, not a guarantee of HIPAA compliance, and not a substitute for a complete risk analysis or a qualified assessor where your circumstances require one. The assessment output renders as plain text/typography only — no seal, badge, ribbon, watermark, or certificate-style graphic — so it does not visually resemble a third-party validation mark.
SR2. No PHI. The Service is not designed to process Protected Health Information. Do not upload PHI; input only the security-program information the assessment needs.
SR3. Accuracy; Your Obligation. You are responsible for the accuracy of your inputs and for your own HIPAA compliance, remediation, and documentation retention.
SR4. Outputs Are Drafts. The assessment, gap list, and documentation are drafts you review and adopt.
Addendum — Underwrite
In addition to the base AUP:
U1. Not a Broker. Not Insurance Advice. Underwrite is a software vendor providing document-processing and comparison tools. Underwrite is not a licensed insurance producer, broker, agent, or advisor in any jurisdiction. Underwrite does not place insurance, negotiate insurance, or sell insurance. Underwrite does not provide insurance advice. You will not represent or imply to any third party that Underwrite places insurance or acts as a producer.
U2. Buyer Independent Decisions. Insurance decisions made on the basis of Underwrite outputs are your own decisions. You are responsible for consulting a licensed broker or producer in your jurisdiction before binding any policy.
U3. Carrier Templates. Carrier-specific questionnaire templates and renewal-narrative templates are provided for reference only. Underwrite makes no representation that any template reflects a carrier's current underwriting requirements as of any date. Verify with the carrier or your broker.
U4. MSP Multi-Client Use. Managed-service-provider ("MSP") tier accounts may process renewal data for multiple MSP-customer entities ("MSP Clients"). Customer represents that it has a lawful basis (typically a master services agreement with each MSP Client) to share each MSP Client's renewal data with Underwrite. Customer is the data controller for MSP Client data; we are the data processor.
U5. State DOI Compliance. If a state Department of Insurance issues guidance, no-action letter, or regulation that affects Underwrite's lawful operation in that state, we may modify, restrict, or withdraw the Service in that state. You acknowledge this regulatory contingency.