Vendorisk.ai // Legal & policy

Unreviewed draft // pending legal review

This document was drafted from the application's actual data flows and has not been reviewed by counsel. It is not yet legally binding and must be reviewed, completed (see the bracketed placeholders throughout, indexed under Placeholders to complete) and approved before Vendorisk.ai is offered to customers.

Document 02 // Contract

Terms of Service

These terms govern your use of Vendorisk.ai. The most important of them is section 03: Vendorisk.ai produces advisory research, not a compliance attestation, and it must not be the sole basis of a procurement or contractual decision. Please read that section even if you read nothing else.

Last drafted: 2026-07-31 · Version: draft 0.1 · Effective date: [Policy effective date]

01. Parties and acceptance

These terms are an agreement between [Legal entity name] of [Registered address]("Vendorisk.ai", "we") and the person or organisation using the service ("you"). By creating an account, signing in, or using any part of the service you accept them. If you accept them on behalf of an organisation, you confirm you are authorised to bind that organisation, and "you" means the organisation.

Where your organisation has signed a separate written agreement with us, that agreement prevails over these terms to the extent of any conflict.

02. What Vendorisk.ai is

Vendorisk.ai is a third-party risk research tool. You give it the name or domain of a software vendor; it searches the public web, retrieves candidate sources, uses a large language model to synthesise those sources into a structured dossier - company background, product, security and risk, recent news - and returns a risk tier, a risk score, a rationale and a recommendation, with citations to the underlying sources. Depending on your plan it also lets you save and watch vendors, record SIG-Lite style questionnaire answers, log approval or rejection decisions, and receive email digests.

Everything Vendorisk.ai produces is derived from material that was publicly available at the time of the run. Vendorisk.ai does not audit vendors, does not interview them, does not receive privileged information from them, and does not verify what they claim about themselves.

03. Advisory only - not an attestation

The disclaimer carried on every dossier

"AI-generated assessment based on publicly available sources. Verify critical findings before contractual reliance. Analysis is advisory, not a compliance attestation, and is subject to data availability."

That sentence is the operative limit on what the service is, and it is incorporated into these terms. Expanded, and without qualification:

  • A Vendorisk.ai dossier is not a compliance attestation, certification or audit report. It is not a SOC 2 report, an ISO 27001 certificate, a penetration test, an HECVAT, a CAIQ or an equivalent of any of them.
  • It is not a credit rating, a financial-stability opinion, an insurance underwriting assessment or a regulated benchmark.
  • It is not legal, regulatory, security or investment advice, and no professional relationship arises from your use of it.
  • It is not a warranty about the vendor assessed. Vendorisk.ai warrants nothing about any third party.
  • It must not be the sole basis of a procurement decision, a contract award, a contract termination, an insurance or credit decision, or any decision with a legal or significant effect on a person or company. Use it to focus your diligence, then verify material findings against primary sources before you rely on them.

If your regulator or your own customers require an attestation about a vendor, obtain that attestation from the vendor. Vendorisk.ai cannot supply it, and a Vendorisk.ai dossier will not satisfy such a requirement.

04. Accuracy of AI-generated content

The narrative sections, rationale and recommendation are generated by a large language model from retrieved source excerpts. Language models can misread a source, conflate two similarly named companies, restate an outdated fact as current, or produce a fluent statement that the cited source does not actually support. Retrieval can also simply miss material: a vendor with little public reporting will produce a thin dossier, and thin evidence can move a risk tier in either direction.

Consequently: risk tiers, risk scores and recommendations are probabilistic outputs and may be wrong; the absence of an adverse finding is not evidence of its absence in the world; citations are provided so that you can check the claim against the source, and you should; and where a dossier is marked as partial or as based on limited public data, that marking is material and should be treated as an instruction to verify rather than as a formality. Vendorisk.ai deliberately does not claim to provide continuous or real-time monitoring of vendors; where monitoring or digest features are enabled on your plan, they are periodic re-checks, not a guarantee of timely detection of any particular event.

05. If you are a vendor we profiled

If you are a company or an individual named in a Vendorisk.ai dossier and you believe an assessment is inaccurate, incomplete or unfair, we want to hear about it and we will correct genuine errors. Write to [Disputes contact email] or use the dispute route on the contact page.

What to include

  • The company name and the URL of the dossier in question.
  • The specific sentence, event, citation, risk tier or score you are disputing - not the dossier as a whole.
  • The public evidence that contradicts it: a published statement, a filing, a status-page history, a current certification, a corrected news report.

Where a claim is unsupported by its cited source, or the source has been corrected or withdrawn, we will amend or remove it and record the change. Where a claim accurately reports what a public source said, we will normally annotate rather than delete it, and will add your response. We do not remove accurate reporting of publicly documented incidents on request, and we do not accept payment to alter, suppress or improve an assessment - the assessment is not for sale in either direction.

06. Accounts, eligibility and workspaces

You must be at least 16 and using Vendorisk.ai for business purposes. Sign-in is by email magic link sent to your address; you are responsible for the security of that mailbox, because control of the mailbox is control of the account. Tell us promptly if you believe an account has been compromised.

Accounts belong to a workspace. Owners and admins can invite members. An invitation link remains valid for 14 days or until it is accepted, whichever comes first, and should not be forwarded. Workspace administrators can see the workspace's saved vendors, questionnaires, approval decisions and research history, including which member ran which investigation. If you use Vendorisk.ai through an employer's workspace, your employer administers that content.

07. Acceptable use

You agree not to:

  • scrape, crawl, bulk-export or systematically harvest the service, its dossiers or its citations, or use automated means to access it other than through an interface we provide for that purpose;
  • resell, sublicense, syndicate or republish dossiers to third parties except where your plan expressly permits it - the white-label and multi-seat capabilities of the higher tiers define what is permitted, and anything beyond them needs written agreement;
  • use the service, or its output, to defame, harass, intimidate or disparage any company or individual, or to present a Vendorisk.ai assessment as an audit, certification or finding of fact;
  • present Vendorisk.ai output as your own independent assessment while stripping the disclaimer and the citations from it;
  • use the service to make decisions about individuals - employment, credit, insurance, tenancy or similar. Vendorisk.ai assesses companies, and using it to assess a person is out of scope and prohibited;
  • attempt to circumvent credit limits, seat limits or rate limits; share credentials; or probe, scan or attack the service other than as permitted by our security disclosure policy;
  • upload into workspace notes or questionnaires any special category data, payment card data, credentials, or material you are not entitled to disclose.

08. Plans, credits and billing

Plans as currently configured in the application: Free at no charge with 25 investigation credits a month and a single seat; Pro at $49 a month with 200 credits and a single seat; Team at $149 a month with 1,000 credits and up to 10 seats; MSP at $499 a month with 5,000 credits, up to 50 seats and white-label branding. Prices are in US dollars and exclude any applicable sales tax or VAT, which is calculated at checkout. Plan contents and prices may change; we will give notice of a change before it applies to your renewal, and the plan shown at checkout governs your purchase.

Checkout, the customer portal, invoicing and subscription state are handled by Stripe. We store only your Stripe customer and subscription identifiers, your plan, your seat limit and your credit balance - card details never reach our servers. Subscriptions renew automatically each month until cancelled. You can cancel at any time from the billing page via the Stripe customer portal; cancellation takes effect at the end of the paid period and you keep access until then.

Credits are consumed when an investigation runs, are allotted monthly, and are not cash, not transferable and not redeemable. Unused credits do not carry over unless we say otherwise. Refunds: [Refund policy]. Failed payment may result in suspension of paid features after notice; seat counts above your plan's limit must be reduced or upgraded.

09. Intellectual property

We own the service and everything in it that we created: the application, the assessment methodology, the risk scoring, the structure of the dossier, and the synthesised text we generate. Subject to these terms and to your plan we grant you a non-exclusive, non-transferable, revocable licence to access dossiers and to use them and reasonable extracts of them internally, including in your own diligence records and reports to your management, provided you do not remove the disclaimer or the citations.

Source material stays with its publishers. Vendorisk.ai quotes and cites third-party material under applicable fair use, fair dealing and quotation exceptions; we assert no ownership over it, and a citation is not a licence for you to reproduce the source in full.

Your content stays yours. Questionnaire answers, approval decisions, notes, branding assets and saved lists that your organisation puts into Vendorisk.ai remain your organisation's. You grant us only the licence needed to host, process, back up and display that content in order to run the service for you. We may use aggregated, de-identified usage statistics to improve the service; we do not use your workspace content to train models.

10. Third-party sources and links

Dossiers link to third-party websites and reproduce excerpts from them. We do not control those sites, we do not endorse them, and we are not responsible for their content, availability or accuracy. Third-party providers used to deliver the service - including the search, enrichment, breach-catalogue, inference, email and payment providers listed in our privacy policy - operate under their own terms, and their availability affects ours.

11. Disclaimer of warranties

The service is provided "as is" and "as available". To the fullest extent permitted by law we disclaim all warranties, express or implied, including any implied warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy and quiet enjoyment. Specifically, and without limiting the foregoing, we do not warrant that any assessment, risk tier, risk score, recommendation, citation or event record is accurate, complete, current or fit for any decision you take; that the service will be uninterrupted, timely or error-free; or that any particular vendor, adverse event or vulnerability will be identified. Nothing in these terms excludes liability that cannot lawfully be excluded, including for death or personal injury caused by negligence or for fraud.

12. Limitation of liability

To the fullest extent permitted by law, neither party is liable for indirect, incidental, special, consequential or punitive damages, or for loss of profit, revenue, goodwill, anticipated savings, business opportunity or data, however caused. We are specifically not liable for any loss arising from a procurement, contractual, security or commercial decision that you took in reliance on an assessment, whether the assessment was accurate or not, given the advisory limits set out in section 03.

Our total aggregate liability arising out of or in connection with these terms is limited to [Liability cap] - the operator must set this figure, conventionally the greater of the fees you paid in the twelve months before the claim and a fixed floor amount. Free-tier use carries no fees and therefore attracts the floor amount only.

13. Indemnity

You will indemnify and hold us harmless against claims, losses and reasonable costs arising from your breach of these terms, your misuse of the service or its output, your republication of a dossier to a third party, any content you put into your workspace, and any claim that your use of the output defamed or otherwise harmed a third party. We will indemnify you against third-party claims that the service itself, as supplied by us and used in accordance with these terms, infringes that third party's intellectual property rights.

14. Suspension and termination

You may stop using the service at any time and cancel a paid plan through the billing page. We may suspend or terminate access immediately where we reasonably believe you have breached section 07, where required by law, or where continued access creates a security or legal risk; otherwise we will give reasonable notice. On termination your licence ends, and your workspace content is retained for [Data retention period] before deletion, during which you may ask us for a copy. Provisions that are intended to survive - the advisory limits, intellectual property, warranty disclaimer, liability, indemnity and governing law - survive termination. Note that no self-service export exists yet: an export is produced by us on request via the contact page.

15. Governing law and disputes

These terms are governed by, and construed in accordance with, [Governing law / jurisdiction], and the courts of that jurisdiction have exclusive jurisdiction over any dispute, subject to any mandatory consumer protections available to you locally. Before starting proceedings, please raise the matter with us at [Legal contact email] so that we can try to resolve it. If any provision is held unenforceable, the rest remains in force. Neither party is liable for failure to perform caused by events beyond its reasonable control. You may not assign these terms without our consent; we may assign them to a successor to our business. Notices to us go to [Legal contact email] or [Registered address]; notices to you go to the email address on your account.

16. Changes to these terms

We may change these terms. Where a change materially affects you we will notify account holders by email and update the drafted date at the head of this document before the change takes effect. Continued use after the effective date is acceptance. If you do not accept a change, cancel your plan before it takes effect. The version in force is the one published here, at /legal/terms; superseded versions are available on request.

99. Placeholders to complete

Every bracketed placeholder used on this page is listed below. Each one is a fact the application's source code cannot supply and the operator must fill in before this document is published as binding.

  • [Policy effective date]
  • [Legal entity name]
  • [Registered address]
  • [Legal contact email]
  • [Disputes contact email]
  • [Governing law / jurisdiction]
  • [Liability cap]
  • [Refund policy]
  • [Data retention period]