This version has been superseded. It is retained for reference only. The version in force is the current MSA.
AiBizzApps Limited
Company No. 16632419 • Registered in England & Wales
GRCxAI
AI-Powered Governance, Risk & Compliance Platform
This Master Subscription Agreement is entered into between:
(1) AiBizzApps Limited, a private limited company incorporated in England and Wales with company number 16632419 (the “Provider”); and
(2) the customer identified in the relevant Order Form (the “Customer”).
(each a “Party” and together the “Parties”).
(A) The Provider has independently developed, and operates, an AI-powered Governance, Risk and Compliance software platform marketed as GRCxAI (the “Service”).
(B) The Customer wishes to subscribe to the Service for use by itself and any of its Affiliates identified in the relevant Order Form, on the terms set out in this Agreement and the Order Form.
(C) The Service is provided on a multi-tenant basis. The Customer acknowledges that the Service is and will continue to be provided to a number of customers and that all customers are served from a common product.
(D) Where Authorised Users of the Customer have, prior to the Effective Date, accessed the Service in a pre-commercial, evaluation, pilot or trial capacity, the Parties acknowledge that the commercial arrangement set out in this Agreement applies prospectively from the Effective Date, without prejudice to any rights, remedies or claims either Party may have in respect of the period prior to the Effective Date, all of which are expressly reserved.
In this Agreement, the following terms shall have the meanings set out below:
the policy set out in Schedule 3, as updated by the Provider from time to time;
any module of the Service that is licensed separately from the Core Platform and is made available to the Customer only where expressly identified in the Order Form and paid for in accordance with clause 6. The Add-On Modules available as at the Effective Date are described in Part B of Schedule 1 and include the TPRM Module;
any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where “control” means ownership of more than 50% of the voting equity;
those employees, contractors and agents of the Customer Affiliates authorised to access and use the Service;
a day other than a Saturday, Sunday or public holiday in England;
has the meaning given in clause 9;
the GRCxAI governance, risk and compliance platform described in Part A of Schedule 1, excluding any Add-On Module;
any data, content, information or material uploaded to, processed by, or generated through the Service by or on behalf of the Customer or its Authorised Users;
the UK GDPR, the Data Protection Act 2018, and any other applicable data protection legislation;
the user and administrator documentation made available by the Provider for the Service, as updated from time to time;
the date set out in the relevant Order Form;
the subscription and other fees set out in the relevant Order Form;
any suggestions, ideas, requests, comments, feature requests, enhancement requests, defect reports or other input provided by the Customer or any Authorised User in relation to the Service;
the period of twelve (12) months commencing on the Effective Date;
all patents, copyrights, database rights, design rights, trade marks, trade secrets, know-how, rights in confidential information, moral rights and all other intellectual property rights, whether registered or unregistered, anywhere in the world;
any successive twelve (12) month period commencing on expiry of the Initial Term or a previous Renewal Term;
the Core Platform together with any Add-On Module expressly identified in the Order Form, in each case as described in Schedule 1 and as the same may be modified, evolved, enhanced or updated from time to time during the Term. An Add-On Module not identified in the Order Form does not form part of the Service;
the operational standards set out in Schedule 2;
the Initial Term together with any Renewal Term(s);
the Third-Party Risk Management module described in Part B of Schedule 1, being an Add-On Module licensed separately from the Core Platform and available either as an addition to the Core Platform or on a standalone basis.
Words importing the singular include the plural and vice versa. References to a person include any individual, company, partnership or unincorporated body. Headings are for convenience only. Any reference to “writing” or “written” includes email.
Right of Access. Subject to the Customer's compliance with this Agreement (including payment of the Fees), the Provider grants the Customer, for the Term, a non-exclusive, non-transferable, non-sublicensable, revocable right for its Authorised Users to access and use the Service solely for the Customer's and the Customer Affiliates' internal business purposes.
What is included in the Fees. The Fees set out in the Order Form are inclusive of, and the Customer shall not be charged separately for, the following in respect of the Core Platform and of any Add-On Module expressly licensed in the Order Form: (a) hosting, infrastructure and third-party cloud services consumed in delivering the Service; (b) routine maintenance, security patching, vulnerability remediation and infrastructure operations; (c) the Provider's ongoing product development, including new features, enhancements, modifications and upgrades made generally available to customers of the Service during the Term; and (d) standard technical support in accordance with Schedule 2.
What is not included. The Fees do not include, and the Provider may charge separately at its then-current professional services rates for: (a) integrations with the Customer's internal systems beyond the standard integrations made generally available within the Service; (b) data migration, onboarding or training services beyond those expressly included in Schedule 1; (c) consultancy, advisory or workshop services requested by the Customer; (d) work to remedy issues caused by the Customer's misuse of the Service or breach of this Agreement; (e) any Add-On Module, including the TPRM Module, which is licensed and charged separately in accordance with clause 6.7 and is not included in the Core Platform Fees unless expressly identified in the Order Form; and (f) any other work outside the scope of the Service as described in Schedule 1. Any such work shall be undertaken only where agreed in writing in advance.
Multi-Tenant Service. The Customer acknowledges that the Service is operated on a multi-tenant basis serving multiple customers from a common product. The Customer is not entitled to any bespoke version, fork, or modified instance of the Service.
Use Restrictions. The Customer shall not, and shall procure that its Authorised Users shall not: (a) resell, sublicense, rent, lease, distribute or commercially exploit the Service; (b) reverse engineer, decompile or disassemble the Service or any part of it, save to the extent permitted by mandatory law; (c) use the Service to build or assist in building any competing product or service; (d) remove or obscure any proprietary notices; (e) use the Service in breach of the Acceptable Use Policy or applicable law; or (f) attempt to circumvent any technical limitations of the Service.
Authorised Users. The Customer is responsible for the acts and omissions of its Authorised Users as if they were its own.
Continuous Evolution. The Customer acknowledges that the Service is a continuously evolving multi-tenant SaaS platform. The Provider may, in its sole discretion and at any time, add, modify, replace, deprecate or remove features and functionality of the Service, provided that the overall functionality of the Service is not, taken as a whole, materially diminished during the Term.
No Roadmap Commitment. Any product roadmap, release schedule, feature preview, beta capability or forward-looking statement made by the Provider is for informational purposes only and is not contractually binding. The Customer shall not rely on, and the Provider gives no warranty in respect of, the timing, scope or delivery of any future feature, capability or release.
Feedback and Feature Requests. The Customer may submit Feedback through the Provider's standard support channels. The Provider has sole and absolute discretion as to whether, when and how to act upon any Feedback, and gives no warranty, undertaking, commitment or representation as to:
whether any item of Feedback will be implemented;
the priority, scope, design or specification of any implementation;
the timeframe for any implementation;
the form, design, performance or fitness for purpose of any feature delivered following Feedback; or
the continued availability of any feature delivered following Feedback.
Feedback IP. The Customer hereby irrevocably and unconditionally assigns to the Provider all Intellectual Property Rights in any Feedback, with full title guarantee, free of all third-party rights, and waives any moral rights it or its Authorised Users may have therein. To the extent any such assignment is not effective, the Customer grants the Provider a perpetual, irrevocable, worldwide, royalty-free, sublicensable, transferable licence to use, modify, exploit and commercialise such Feedback for any purpose without restriction.
Standard Product; No Customer-Specific Versions. The Customer acknowledges and agrees that the Service operates on a single common codebase and that the Provider does not maintain, develop, branch, fork or otherwise produce customer-specific versions or exclusive features of the Service. Any feature, modification, enhancement, configuration, integration or other development that the Provider implements during the Term—whether on its own initiative, in response to Feedback, in response to feature requests from any customer of the Service, in response to general market or competitive considerations, or otherwise—shall form part of the standard Service, shall be made available on the Provider's terms to all customers of the Service, and shall be the sole and exclusive property of the Provider. The Provider has sole and absolute discretion as to what work to undertake and as to whether, when and how any feature is implemented or included in the Service.
The Customer shall: (a) provide the Provider with timely cooperation, information and access to Customer personnel reasonably required to enable the Provider to deliver the Service; (b) ensure that all Customer Data is lawful and does not infringe any third-party rights; (c) maintain the security of its Authorised Users' credentials and notify the Provider promptly of any actual or suspected unauthorised use of the Service; (d) comply with the Acceptable Use Policy set out in Schedule 3; and (e) use the Service in accordance with the Documentation.
The Customer warrants that it has, and will maintain throughout the Term, all rights, consents, authorities and lawful bases necessary for the Provider to host and process Customer Data as contemplated by this Agreement.
Customer Backups. Notwithstanding the Provider's backup arrangements described in Schedule 2, the Customer is responsible for maintaining its own redundant copies of any Customer Data critical to its operations, by exercising the export functions made available within the Service from time to time.
This Agreement commences on the Effective Date and continues for the Initial Term, after which it shall automatically renew for successive Renewal Terms unless terminated in accordance with this clause 5 or clause 14.
Either Party may prevent automatic renewal by giving the other not less than sixty (60) days' written notice prior to the end of the then-current Term.
The Customer has no right to terminate for convenience during the Initial Term. Termination during the Initial Term is permitted only in the circumstances set out in clause 14.
The Customer shall pay the Fees in the amounts and on the payment dates set out in the Order Form.
Fees shall be invoiced and paid via Stripe Billing using BACS Direct Debit (or, if agreed, debit/credit card) on a recurring monthly basis in advance. Where the Customer has opted for purchase-order driven invoicing, monthly invoices shall be issued via Stripe with auto-pay enabled and shall be payable on the date of issue.
All Fees are exclusive of VAT, which shall be payable in addition at the prevailing rate.
If any sum payable is not paid by the due date, the Provider may, without prejudice to any other right or remedy: (a) charge interest under the Late Payment of Commercial Debts (Interest) Act 1998; (b) recover its reasonable costs of collection; and (c) exercise its rights under clause 7 (Suspension).
The Provider may increase the Fees for any Renewal Term by written notice given not less than thirty (30) days prior to the start of that Renewal Term. Fees are held flat for the duration of the Initial Term.
All payments due under this Agreement shall be made in full, without any set-off, counterclaim, deduction or withholding, save as required by law.
Add-On Modules. Each Add-On Module is licensed and charged separately from the Core Platform, at the fee stated for that Add-On Module in the Order Form, and on the same billing cycle and payment terms as the Core Platform Fees unless the Order Form states otherwise. An Add-On Module may be taken as an addition to the Core Platform or, where the Order Form so provides, on a standalone basis. Where an Add-On Module is charged per company entity, a separate fee is payable for each entity for which it is enabled. Adding an Add-On Module during a Term does not alter the expiry date of that Term, and the fee for it shall be pro-rated to the end of the then-current Term. The Customer may elect not to renew an Add-On Module at the end of a Term without affecting the continuation of the Core Platform subscription, and vice versa, by written notice given in accordance with clause 5.
The Provider may suspend the Customer's and any Authorised User's access to the Service, in whole or in part, on written notice (which may be by email) where: (a) any sum payable is overdue by more than fourteen (14) days; (b) the Provider reasonably believes that the Service is being used in breach of this Agreement, the Acceptable Use Policy, or applicable law; (c) the Provider reasonably believes that suspension is necessary to prevent or mitigate a security incident, threat to platform integrity, or risk to other customers; or (d) it is required to do so by law, court order or regulatory authority.
The Provider shall, where reasonably practicable, give the Customer prior notice of suspension and an opportunity to remedy the cause. Suspension under this clause 7 shall not relieve the Customer of its obligation to pay the Fees, save where the suspension is solely due to an act or omission of the Provider not attributable to a default of the Customer.
All Intellectual Property Rights in and to the Service, the GRCxAI Platform, the underlying source code, architecture, models, prompt libraries, templates, content, training materials, the Documentation, and any modifications, configurations, customisations, integrations, derivative works, enhancements, bug fixes, optimisations or improvements thereof (whether developed by the Provider, the Customer, jointly, or by any third party, and whether before, during or after the Term, and whether on the Provider's own initiative, in response to Feedback or Customer requests, or otherwise) are and shall at all times remain the sole and exclusive property of the Provider. No right, title or interest in such Intellectual Property Rights is granted to the Customer save for the limited right of access and use expressly set out in clause 2.1.
The Customer acknowledges and agrees that nothing in this Agreement, nor any prior or contemporaneous engagement, discussion, partnership proposal, proposal review, consultancy arrangement, evaluation, pilot, trial or other dealing between the Parties (or their respective Affiliates), shall operate to transfer, assign, license (except as expressly set out in this Agreement) or grant any beneficial interest in the Provider's Intellectual Property Rights to the Customer.
Customer Data. The Customer retains all Intellectual Property Rights in Customer Data. The Customer grants the Provider a non-exclusive, royalty-free, worldwide licence, for the Term and any post-termination data export period, to host, copy, process, transmit and display Customer Data solely as necessary to provide the Service and to comply with its obligations under this Agreement.
Anonymised and Aggregated Data. The Provider may collect, generate, use and retain anonymised, de-identified and aggregated data derived from use of the Service (“Service Data”) for the purposes of operating, securing, improving and developing the Service and the Provider's other products and services, provided such Service Data does not identify the Customer, any Customer Affiliate or any individual.
Each Party (the “Receiving Party”) shall keep confidential all information of a confidential nature disclosed to it by the other (the “Disclosing Party”), including the terms of this Agreement, technical and commercial information, and any information marked or reasonably understood to be confidential (“Confidential Information”).
The Receiving Party shall: (a) use Confidential Information only for the purposes of performing this Agreement; (b) not disclose it to any third party except to its employees, professional advisers and contractors with a need to know and who are bound by equivalent obligations of confidentiality; and (c) protect it using at least the same degree of care it uses for its own confidential information, and in any event no less than a reasonable standard of care.
Clause 9 does not apply to information that: (a) is or becomes public other than through breach of this Agreement; (b) was known to the Receiving Party before disclosure free of any duty of confidentiality; (c) is independently developed without reference to the Disclosing Party's information; or (d) is required to be disclosed by law or regulatory authority, provided (where lawful) the Disclosing Party is given prior notice.
The obligations in this clause 9 survive termination for a period of five (5) years.
Each Party shall comply with its obligations under Data Protection Laws in connection with this Agreement.
Where the Provider processes personal data on behalf of the Customer in providing the Service, the Customer is the controller and the Provider is the processor. The processing terms set out in Schedule 4 (Data Processing Agreement) shall apply.
The Provider shall implement and maintain appropriate technical and organisational measures to protect Customer Data against unauthorised access, loss, alteration or disclosure, in accordance with Schedule 4.
Mutual Warranties. Each Party warrants to the other that: (a) it is duly incorporated and validly existing under the laws of its jurisdiction of incorporation; (b) it has full authority to enter into and perform this Agreement; and (c) its entry into this Agreement does not conflict with any other agreement to which it is a party.
Limited Provider Warranty. The Provider warrants that the Service will be provided with reasonable care and skill.
Disclaimer. Except as expressly set out in this clause 11, and to the fullest extent permitted by law: (a) the Service is provided “as is” and “as available”; (b) the Provider gives no warranty, condition, guarantee or other term, express or implied, including any implied warranty as to satisfactory quality, fitness for a particular purpose, non-infringement, accuracy, completeness, or that use of the Service will be uninterrupted, error-free, secure, or that all defects will be corrected; (c) the Provider does not warrant that the Service will meet the Customer's requirements; (d) the Provider does not warrant the accuracy, completeness, or appropriateness of any AI-generated output, content, recommendations, scoring, classification or analysis produced by the Service, all of which are provided for informational purposes only and require human review and verification before being relied upon; and (e) the Customer is solely responsible for any decisions made, actions taken or omissions in reliance on the Service or any output thereof.
AI Outputs. The Customer acknowledges that the Service incorporates third-party large language models and other AI components, and that AI-generated outputs may be inaccurate, incomplete, inconsistent or otherwise unsuitable. The Customer shall apply appropriate human review to all AI-generated outputs before use, particularly in connection with regulatory, audit, legal or compliance matters.
Consequences of Service Failure. Save as expressly set out in this Agreement, the Customer's sole and exclusive remedies in respect of any failure of the Service to perform satisfactorily are: (a) to exercise its rights of termination under clause 14; and (b) to recover damages, subject to the limitations in clause 12.
Liability that Cannot Be Excluded. Nothing in this Agreement excludes or limits either Party's liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; or (c) any other liability that cannot lawfully be excluded or limited.
Excluded Loss. Subject to clause 12.1, neither Party shall be liable to the other (whether in contract, tort (including negligence), breach of statutory duty, restitution or otherwise) for any:
loss of profit (whether direct or indirect);
loss of revenue, business or business opportunity;
loss of anticipated savings;
loss of goodwill or reputation;
loss or corruption of data (save as expressly addressed under Schedule 4);
regulatory fines, penalties, or sanctions imposed on the Customer;
loss arising from the Customer's reliance on AI-generated outputs without human review; or
any loss that is indirect, special, punitive or consequential, in each case howsoever arising.
Liability Cap. Subject to clauses 12.1 and 12.2, the total aggregate liability of each Party arising out of or in connection with this Agreement (whether in contract, tort, breach of statutory duty or otherwise) shall not exceed an amount equal to one hundred per cent (100%) of the Fees paid by the Customer in the twelve (12) month period immediately preceding the first event giving rise to the claim (or, if the claim arises before twelve months have elapsed, the annualised value of the Fees as set out in the Order Form).
Reasonableness. The Parties acknowledge that the limitations and exclusions in this clause 12 are reasonable having regard to the nature of the Service, the Fees payable, the multi-tenant model on which the Service is provided, and the allocation of risk between the Parties.
Customer Indemnity. The Customer shall indemnify and hold harmless the Provider, its directors, officers, employees and agents, from and against any and all losses, damages, costs (including reasonable legal costs), liabilities and expenses arising out of or in connection with: (a) any Customer Data or the processing thereof; (b) any breach by the Customer or any Authorised User of clause 2.5, the Acceptable Use Policy, or applicable law; (c) any third-party claim arising from the Customer's use of, or reliance on, the Service or any output thereof; and (d) any claim by an Authorised User against the Provider, save where such claim arises from the Provider's breach of this Agreement.
Provider IP Indemnity. The Provider shall indemnify the Customer against direct losses awarded against the Customer by a court of competent jurisdiction in respect of any third-party claim that the Customer's use of the Service in accordance with this Agreement infringes that third party's UK Intellectual Property Rights, provided that:
the Customer notifies the Provider promptly of the claim;
the Customer gives the Provider sole control of the defence and settlement of the claim;
the Customer provides reasonable cooperation at the Provider's cost; and
the Customer makes no admission, settlement or compromise without the Provider's prior written consent.
Exclusions. The Provider's indemnity in clause 13.2 does not apply to any claim arising from: (a) Customer Data; (b) modifications to the Service made by anyone other than the Provider; (c) combination of the Service with materials not supplied by the Provider; (d) use of the Service other than in accordance with this Agreement and the Documentation; or (e) use of any AI-generated output without appropriate human review.
Mitigation. If a claim of the type covered by clause 13.2 is made or appears likely, the Provider may, at its option and at no cost to the Customer: (a) procure for the Customer the right to continue using the affected part of the Service; (b) modify or replace the affected part so that it is non-infringing; or (c) on written notice, terminate this Agreement and refund the pro-rata portion of any pre-paid Fees attributable to the unused remainder of the Initial Term or then-current Renewal Term. The remedies in this clause 13 are the Customer's sole and exclusive remedies, and the Provider's sole liability, in respect of any infringement of third-party Intellectual Property Rights.
Either Party may terminate this Agreement immediately by written notice if the other: (a) commits a material breach of this Agreement which, if remediable, is not remedied within thirty (30) days of written notice requiring remedy; or (b) becomes insolvent, ceases or threatens to cease to carry on business, has a receiver or administrator appointed, enters into any composition with its creditors, or any analogous event occurs in any jurisdiction.
The Provider may terminate this Agreement immediately by written notice if: (a) the Customer fails to pay any undisputed sum within thirty (30) days of the due date, having received written notice of such failure; or (b) the Customer commits a material breach of clause 2.5, the Acceptable Use Policy, or any law applicable to its use of the Service.
On termination or expiry: (a) the Customer's rights to access and use the Service shall cease immediately; (b) all accrued Fees become immediately due and payable; (c) the Provider shall, on request made within thirty (30) days of termination, make Customer Data available for export in a commonly used machine-readable format for a period of ninety (90) days, after which the Provider may delete or anonymise Customer Data subject to its lawful retention obligations; and (d) clauses 8, 9, 10, 11.3, 12, 13, 14.3, 16 and 17 shall survive termination.
Neither Party shall be liable for any delay or failure in performance (other than payment obligations) caused by events beyond its reasonable control, including acts of God, war, terrorism, civil unrest, fire, flood, pandemic, governmental action, failure of public infrastructure, cyber attacks affecting third-party providers, or failure of upstream cloud, AI model, or telecommunications providers, provided that the affected Party promptly notifies the other and uses reasonable endeavours to mitigate the effect. If a force majeure event continues for more than ninety (90) consecutive days, either Party may terminate this Agreement on written notice without liability.
Negotiation. If any dispute arises out of or in connection with this Agreement, the Parties' senior representatives shall meet (in person or by videoconference) within fourteen (14) days of written notice of the dispute and use reasonable endeavours to resolve it in good faith.
Mediation. If the dispute is not resolved by negotiation within thirty (30) days of the notice, the Parties shall attempt to resolve it by mediation under the Centre for Effective Dispute Resolution (CEDR) Model Mediation Procedure. The mediation shall take place in London, in English. The fees of the mediator shall be borne equally by the Parties.
Litigation. Nothing in this clause 16 shall prevent a Party from seeking urgent injunctive or other equitable relief from a court at any time. Following compliance with clauses 16.1 and 16.2 (or where a Party fails to participate in good faith), either Party may commence proceedings in accordance with clause 17.6.
Entire Agreement. This Agreement (including its Schedules) constitutes the entire agreement between the Parties in relation to its subject matter and supersedes all prior agreements, proposals, partnership proposals, partnership reviews, evaluations, communications and understandings, whether written or oral. Each Party acknowledges that, in entering into this Agreement, it has not relied on any statement, representation, assurance or warranty other than those expressly set out in this Agreement.
Variation and Updates. No variation of the commercial terms of this Agreement (as set out in any Order Form) is effective unless in writing and signed by an authorised representative of each Party. The Provider may, however, update this Agreement (excluding any signed Order Form) from time to time as set out below:
The Provider may publish a revised version of this Agreement on its website at https://grcxai.com/legal/msa, indicating the version number and effective date.
The Provider shall give the Customer not less than thirty (30) days' written notice (which may be by email to the Customer's notice contact, or by in-platform notice) of any update which would constitute a material adverse change to the Customer's rights or obligations under this Agreement.
If the Customer does not agree to a material adverse change, the Customer may terminate this Agreement by written notice given before the effective date of such change. In such event, the Provider shall refund any pre-paid Fees attributable to the unused remainder of the then-current Term.
Updates which do not constitute material adverse changes — including but not limited to additions to the sub-processor list, updates to the Acceptable Use Policy, expansions of features or coverage, clarifications, and changes required to comply with law or to address platform security — shall take effect on the date specified in the notice or, if no date is specified, immediately upon publication.
The Customer's continued access to or use of the Service after the effective date of an update constitutes acceptance of the updated Agreement.
The Provider shall maintain a publicly accessible archive of previous versions of this Agreement at https://grcxai.com/legal/msa/archive.
Assignment. Neither Party may assign or transfer its rights or obligations without the prior written consent of the other (such consent not to be unreasonably withheld), save that the Provider may assign or novate this Agreement to any acquirer of all or substantially all of its business or assets relating to the Service.
Notices. Notices shall be given in writing to the addresses set out in the Order Form (or such other address as notified in writing) and shall be deemed received: if delivered by hand, on delivery; if sent by email, on transmission with confirmation of delivery; or if sent by recorded post, two Business Days after posting.
Third Party Rights. A person who is not a party to this Agreement has no rights under the Contracts (Rights of Third Parties) Act 1999 to enforce any of its terms, save that Customer Affiliates identified in the Order Form may enforce their rights of access to the Service.
Governing Law and Jurisdiction. This Agreement and any dispute arising out of or in connection with it shall be governed by the laws of England and Wales, and the Parties submit to the exclusive jurisdiction of the courts of England and Wales.
Severability. If any provision of this Agreement is held by any court or other competent authority to be invalid or unenforceable, the remainder of this Agreement shall continue in full force and effect.
Counterparts. This Agreement may be executed in counterparts (including by electronic signature), each of which shall be deemed an original and all of which together constitute one agreement.
GRCxAI Enterprise Edition is a multi-tenant SaaS platform delivering AI-powered Governance, Risk and Compliance management. The Service is delivered through cloud infrastructure operated by the Provider and accessed by Authorised Users via a web browser over HTTPS. The Service is, and shall continue to be, provided on a multi-tenant basis.
The Core Platform provides content, controls libraries, assessment questions and document templates aligned to twenty-seven (27) international compliance, assurance and sustainability reporting frameworks, being:
ISO/IEC 27001, ISO/IEC 42001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27701, ISO 22301, ISO 31000, ISO 37001, ISO 37301, ISO 45001, UK GDPR / EU GDPR, SOC 2, PCI DSS, NIST CSF, NCSC Cyber Assessment Framework (CAF), Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance, Defence Cyber Certification (DCC) Level 1, IASME MSP, and the sustainability reporting frameworks GRI, CSRD/ESRS, TCFD, CDP, ISSB (IFRS S1 & S2), SASB and the UN Sustainable Development Goals.
The IASME MSP scheme is under development by the IASME Consortium; the Provider makes available such content for it as exists from time to time and gives no commitment as to the date on which that scheme will be finalised. In addition to the frameworks listed above, the Core Platform includes dedicated modules for the EU AI Act and for Provision 29 of the UK Corporate Governance Code (Principal Risks and Uncertainties).
The Core Platform additionally addresses the following regulatory frameworks and standards through mapped controls, guided assessments and document templates delivered within the frameworks listed above and within the guided assessment library, rather than as separate framework programmes:
(a) ISO/IEC 27002 — as the control basis of ISO/IEC 27001 Annex A and of the ISO/IEC 27017 and ISO/IEC 27701 control sets;
(b) CCPA / US state privacy law — through the privacy information management programme (ISO/IEC 27701 and ISO/IEC 27018 controls, privacy assessments, privacy document templates and data-privacy audit categories);
(c) the FCA Handbook (relevant sections) — through guided assessments covering FCA authorisation and FSMA 2000, client assets (CASS), consumer credit (CONC), conduct risk and treating customers fairly, and operational resilience under FCA PS21/3 and PRA PS6/21; and
(d) ISO 9001 — through integrated management system alignment, quality impact scales and cross-standard integration templates; and
(e) the NIST AI Risk Management Framework — mapped across the AI Maturity Assessment, each question of which carries both an ISO/IEC 42001 clause reference and a NIST AI RMF function mapping (GOVERN, MAP, MEASURE, MANAGE).
The Provider may add, modify or replace frameworks covered by the Service from time to time.
The Core Platform includes the following capabilities, as the same may evolve during the Term:
(a) AI-powered policy and document generation, drawing on a library of audit-ready templates;
(b) Risk register, control library, evidence repository and assurance scoring engine, with cross-framework mapping;
(c) Guided compliance assessments built on structured workflows;
(d) Vendor register and questionnaire-based vendor assessments, with vendor categorisation and assessment tracking. Continuous, evidence-based vendor intelligence is provided by the TPRM Module and is not included in the Core Platform (see Part B);
(e) Training module library covering security awareness, AI governance and framework-specific topics;
(f) Intelligent compliance chatbot with retrieval over Customer Data and the Provider's compliance corpus;
(g) Per-entity tenancy for each Customer Affiliate identified in the Order Form, with consolidated group-level dashboarding and reporting;
(h) Audit log, role-based access control, single sign-on (SAML/OIDC) where supported, and standard reporting exports.
During the first sixty (60) days following the Effective Date, the Provider shall, at no additional charge:
(a) provision separate tenancies for each Customer Affiliate identified in the Order Form;
(b) configure framework selection, risk taxonomy and reporting templates per Customer Affiliate based on Customer-supplied configuration inputs;
(c) perform any agreed initial data migration of existing risk and control records, where data is provided by the Customer in the Provider's specified import format; and
(d) deliver up to five (5) administrator training sessions of up to ninety (90) minutes each, conducted by video conference.
Onboarding services beyond the scope set out above are subject to clause 2.3 and the Provider's then-current professional services rates.
The Service is hosted on enterprise cloud infrastructure within the United Kingdom and/or European Economic Area. Hosting and infrastructure costs incurred by the Provider in delivering the Service are included in the Fees.
A current list of sub-processors is set out in Schedule 4. The Provider may update its sub-processor list in accordance with Schedule 4.
The modules in this Part B are licensed separately from the Core Platform. An Add-On Module forms part of the Service only where it is expressly identified in the Order Form, and is charged in accordance with clause 6.7. Where no Add-On Module is identified in the Order Form, the Customer receives the Core Platform only.
The TPRM Module provides continuous, evidence-based third-party risk management, going beyond the vendor register and questionnaire-based assessments included in the Core Platform under paragraph 3(d). It comprises, as the same may evolve during the Term:
(a) continuous monitoring of third parties from external evidence sources, in place of point-in-time questionnaires;
(b) external attack-surface assessment of monitored third parties;
(c) financial and credit checks on third parties, subject to the credit allowance stated in the Order Form;
(d) a supply-chain map showing relationships and concentration across monitored third parties;
(e) a monitored-vendor pool, together with review and remediation queues for triaging and tracking identified issues;
(f) third-party information requests and the tracking of responses; and
(g) reporting and dashboarding across the monitored third-party portfolio.
The TPRM Module may be licensed either as an addition to the Core Platform or on a standalone basis. Where licensed on a standalone basis, the Customer receives the TPRM Module together with such parts of the platform as are necessary to operate it (authentication, tenancy, user administration, audit logging and reporting), and paragraphs 2 and 3 of Part A do not apply.
The TPRM Module draws on third-party and public data sources, including the Provider's affiliated Corvus vendor-intelligence corpus. The Provider does not warrant the accuracy or completeness of information obtained from third-party or public sources, and clause 11 applies to it. Findings produced by the TPRM Module are decision-support information and do not constitute a credit reference, a security certification, or professional advice regarding any third party.
Important. This Schedule 2 describes the operational standards on which the Provider operates the Service and the support arrangements available to the Customer. Nothing in this Schedule 2 constitutes a service level agreement, a guarantee, or a contractual commitment as to availability, response time, resolution time, or feature delivery. All targets, categories and timeframes set out below are operational guidelines, are indicative only, and are provided for informational purposes.
The Provider shall use commercially reasonable efforts to operate the Service on a reliable and continuous basis, consistent with industry-standard practices for multi-tenant SaaS platforms of similar scale and scope.
The Provider monitors the Service on a continuous basis and engages reputable third-party cloud and infrastructure providers selected for their reliability and security.
The Provider operates the Service with an internal operating target of high availability, but does not warrant or guarantee any specific level of availability. The Service is provided on an “as available” basis (see clause 11.3 of the Agreement).
There is no entitlement to service credits, refunds or other compensation in respect of any unavailability of the Service. The Customer's sole and exclusive remedy in respect of any sustained or material failure of the Service is to terminate the Agreement in accordance with clause 14.
The Provider may from time to time perform maintenance on the Service. Maintenance windows shall, where reasonably practicable, be scheduled outside UK business hours and notified in advance, but the Provider reserves the right to perform emergency maintenance at any time without prior notice where it considers, in its reasonable discretion, that such maintenance is necessary to protect the security or integrity of the Service.
Support is provided via the following channels:
(a) Email: [email protected]
(b) In-platform support form (where available)
Support is provided in English, on UK Business Days, between 09:00 and 18:00 UK time. There is no out-of-hours support.
For internal triage and prioritisation purposes only, the Provider categorises support requests as set out below. The categories and any associated timeframes are indicative only and do not constitute service level commitments.
| Category | Description | Indicative Approach |
|---|---|---|
| P1 | Service is wholly unavailable to all Authorised Users, or material data integrity issue affecting all customers | Investigated promptly on a continuous best-efforts basis until restoration |
| P2 | Major function unavailable; significant degradation, but a workaround exists | Investigated within UK business hours, prioritised after P1 |
| P3 | Minor function impaired; non-blocking | Investigated within UK business hours, scheduled into routine work |
| P4 | General questions, configuration support, feature requests, cosmetic | Addressed via email or scheduled into product roadmap at the Provider's discretion |
Feature requests submitted via support channels are governed by clause 3 of the Agreement. The Provider does not commit to any specific feature being implemented, nor to any particular timeframe for implementation.
The Provider takes encrypted backups of the platform databases on a regular basis as part of its standard operating practices. Backup configuration, retention period and recovery objectives are determined by the Provider from time to time and are not contractually committed levels. The Customer remains responsible for maintaining its own redundant copies of any Customer Data critical to its operations (see clause 4.3 of the Agreement).
The Provider implements technical and organisational measures appropriate to the nature of the Service, including network and application-layer protections, encryption in transit and at rest, role-based access controls, and audit logging. Detailed security measures are described in Schedule 4.
The Provider may communicate with the Customer regarding the Service (including maintenance notifications, security advisories and product updates) by email to the Customer's nominated administrator contacts and/or by in-platform notice.
This Acceptable Use Policy applies to all use of the Service by the Customer and its Authorised Users. Breach of this Policy is a material breach of the Agreement and may, at the Provider's discretion, result in suspension under clause 7 or termination under clause 14.
The Customer shall not upload to, store on, or transmit through the Service any content that:
(a) is unlawful, defamatory, obscene, threatening, harassing, hateful or discriminatory;
(b) infringes any third-party Intellectual Property Rights, privacy rights, or other rights;
(c) contains malware, viruses, ransomware, worms, trojans, spyware, or other malicious code;
(d) contains personal data of categories specified in Article 9 of the UK GDPR (special category data) without an appropriate lawful basis and notice to the Provider; or
(e) contains payment card data, government identification numbers, or other regulated data the Provider is not designed or contracted to receive.
The Customer shall not, and shall procure that its Authorised Users shall not:
(a) attempt to gain unauthorised access to the Service, any other customer's data, or any underlying infrastructure;
(b) probe, scan, penetration test, or otherwise test the security or vulnerability of the Service without the Provider's prior written consent;
(c) interfere with or disrupt the integrity, performance or availability of the Service or the data of other customers;
(d) reverse engineer, decompile, disassemble, scrape, or otherwise attempt to derive the source code, models, prompts, or trade secrets of the Service;
(e) use the Service to develop a competing product or service, or to benchmark the Service for the purpose of public comparison without the Provider's prior written consent;
(f) bypass, disable, or circumvent any access controls, rate limits, usage limits, or other technical limitations;
(g) use any automated means (including bots, scrapers, or crawlers) to access the Service except via APIs expressly made available by the Provider for that purpose;
(h) resell, sublicense, lease, or otherwise commercially exploit the Service or access to it; or
(i) use the Service in any manner that violates applicable law, including export controls and sanctions regulations.
The Customer shall not use the AI capabilities of the Service to:
(a) generate content for unlawful purposes, including fraud, harassment or impersonation;
(b) produce, train, or improve any third-party AI model;
(c) generate output that the Customer presents to regulators, auditors, courts, or other third parties without appropriate human review and verification; or
(d) make automated decisions producing legal or similarly significant effects on individuals without appropriate safeguards and human oversight.
The Customer shall promptly report to the Provider any actual or suspected breach of this Policy, security incident, or unauthorised use of the Service of which it becomes aware. The Customer shall cooperate reasonably with any investigation by the Provider into a suspected breach of this Policy.
The Provider may update this Policy from time to time in accordance with clause 17.2 of the Agreement.
This Schedule 4 forms part of the Agreement and sets out the terms on which the Provider (as Processor) processes personal data on behalf of the Customer (as Controller).
The Provider processes personal data for the purpose of providing the Service, including platform access, authentication, audit logging, support, AI-driven content generation, and reporting.
Processing continues for the Term of the Agreement and any post-termination data export period.
Authorised Users (employees, contractors and agents of the Customer Affiliates), and any natural persons whose personal data is uploaded by the Customer to the Service in the context of risk assessments, compliance records, training records or audit evidence.
Identity data (name, job title, work email, work telephone), authentication data, access and usage logs, role and permission metadata, training completion records, and any personal data contained within Customer-supplied evidence, risk assessments or policy artefacts.
The Provider shall: (a) process personal data only on the Customer's documented instructions, including with regard to international transfers, save where required by law (in which case the Provider shall, where lawful, notify the Customer); (b) ensure persons authorised to process personal data are bound by confidentiality; (c) implement appropriate technical and organisational measures, including access controls, encryption in transit and at rest, secure development practices, and audit logging; (d) assist the Customer to a reasonable extent in responding to data subject rights requests and in fulfilling its obligations under Articles 32–36 of the UK GDPR; (e) notify the Customer without undue delay of becoming aware of a personal data breach affecting Customer Data; (f) at the Customer's choice, delete or return all personal data on termination, subject to legal retention obligations; and (g) make available to the Customer information necessary to demonstrate compliance with this Schedule, on reasonable prior written notice.
The Customer's right to audit shall be satisfied, in the first instance, by the Provider's most recent third-party security assurance reports or certifications, where available. On-site or independent audits shall be permitted only on reasonable notice, no more than once per year (save in the event of a confirmed breach), at the Customer's cost, and subject to confidentiality.
The Customer authorises the Provider to engage the sub-processors listed below. The Provider shall give not less than thirty (30) days' notice of any addition or replacement, during which the Customer may object on reasonable grounds. If the Parties cannot agree on a substitute sub-processor, either Party may terminate this Agreement, with the Provider refunding any pre-paid Fees attributable to the unused remainder of the Term.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Edge compute, CDN, WAF and Workers runtime | Global; UK/EEA edge |
| Supabase, Inc. | Application database (PostgreSQL) and authentication | EU (Frankfurt or Dublin) |
| Anthropic, PBC | Large language model inference for generation and chat features | US, with EU routing where available |
| Stripe Payments Europe Ltd. | Subscription billing and payment processing | Ireland / UK |
Where personal data is transferred outside the United Kingdom or the European Economic Area, the Provider shall ensure that an appropriate transfer mechanism is in place, including the UK International Data Transfer Addendum to the EU Standard Contractual Clauses or the EU Standard Contractual Clauses, as applicable.
Liability under this Schedule 4 is subject to the limitations set out in clause 12 of the Agreement.