Legal & Compliance

Disclaimers

Important limitations, disclosures, and legal notices that govern your use of the AssurAI platform. Please read each section carefully before relying on any AI-generated output.

Effective: January 1, 2025 Last Updated: January 15, 2025 8 Sections
Please Read Carefully

By accessing or using the AssurAI platform, you acknowledge that you have read, understood, and agree to be bound by all limitations and disclosures described in these disclaimers. If you do not agree, you must immediately discontinue your use of the platform.

Section 01
AI Disclaimer
AI outputs do not constitute professional advice

AssurAI uses artificial intelligence — including models provided by Anthropic (Claude), Google (Gemini), and OpenAI (GPT-4o) — to analyse audit data and generate findings, test procedures, control assessments, risk ratings, and written summaries. AI-generated outputs are not professional advice of any kind.

Critical Limitation

All AI-generated findings, recommendations, and summaries must be independently reviewed and validated by a qualified professional before any reliance is placed upon them. Do not use AI outputs as the sole basis for opinions issued to management, boards, audit committees, or regulators.

AI systems have inherent limitations, including:

  • AI-generated content may contain factual errors, hallucinations, or logically incorrect conclusions that appear plausible.
  • AI models may not reflect recent regulatory changes, updated standards, or current industry guidance.
  • AI responses can vary between sessions for identical inputs — results are not deterministic.
  • AI cannot exercise professional judgment, assess qualitative context beyond what is explicitly presented, or bear legal or professional accountability.
  • AI models are trained on historical data and may not accurately reflect current market conditions, regulatory environments, or organizational circumstances.
  • Outputs may reflect biases present in training data, which could lead to systematic errors in risk assessments or findings.

AssurAI's AI-generated test procedures, control assessments, and findings are starting points for professional review only — not final audit conclusions. All substantive decisions, sign-offs, and professional opinions must be made by qualified human professionals who independently verify the AI-generated content.

Section 03
Regulatory Disclaimer
Not SEC, PCAOB, FinCEN, or regulatory body advice

The AssurAI platform has not been approved, endorsed, or authorized by the Securities and Exchange Commission (SEC), the Public Company Accounting Oversight Board (PCAOB), the Financial Crimes Enforcement Network (FinCEN), the Office of the Comptroller of the Currency (OCC), the Federal Deposit Insurance Corporation (FDIC), the Federal Reserve, the Institute of Internal Auditors (IIA), or any other regulatory, standard-setting, or professional body.

Use of AssurAI does not guarantee or imply compliance with:

  • Sarbanes-Oxley Act (SOX) — Sections 302, 404, 906, or otherwise
  • PCAOB auditing standards (AS 2201 and related standards)
  • Bank Secrecy Act (BSA) and Anti-Money Laundering (AML) requirements
  • SEC rules, regulations, or reporting obligations
  • SOC 2 Type I or Type II reporting requirements (AICPA Trust Services Criteria)
  • ISO/IEC 27001 information security management standards
  • NIST Cybersecurity Framework (CSF) or NIST SP 800-53
  • COBIT 2019 or other IT governance frameworks
  • IIA International Professional Practices Framework (IPPF)
  • GDPR, CCPA, or any other data privacy regulation
  • FDICIA annual report and management assessment requirements
BSA/AML Specific Notice

The BSA/AML module provides informational assistance only. It does not constitute a Suspicious Activity Report (SAR) filing recommendation, a regulatory opinion, or a substitute for the BSA Officer's professional judgment. All SAR decisions must be made by the designated BSA Officer and qualified compliance staff.

Users are solely responsible for ensuring their audit approach, documentation, and conclusions meet applicable professional and regulatory standards. Consult your external auditors and qualified compliance professionals before using AssurAI in work that may be relied upon by regulators or in formal regulatory submissions.

Section 04
Third-Party Disclaimer
No warranty on third-party integrations or services

AssurAI integrates with and relies upon third-party services for core platform functionality. AssurAI Inc. makes no representations or warranties regarding the availability, accuracy, security, or data practices of these third-party providers.

Third-party services used by the platform:

Supabase
Database & file storage (PostgreSQL)
supabase.io
Netlify
Application hosting & serverless functions
netlify.com
Anthropic
Claude AI API
anthropic.com
Google
Gemini AI API
ai.google.dev
OpenAI
GPT-4o API
openai.com
Stripe
Payment processing & billing
stripe.com

Evidence files, audit workpapers, and other data you upload to AssurAI are processed by third-party AI APIs (Anthropic, Google, OpenAI). Review each provider's data processing terms, privacy policy, and data residency documentation before uploading sensitive, confidential, or regulated data.

  • AssurAI is not responsible for third-party service outages, data breaches, or API errors.
  • Third-party service changes, deprecations, or discontinuations may affect platform functionality without prior notice.
  • Data handling by third-party services is governed solely by their respective terms of service and privacy policies.
  • AssurAI does not warrant that third-party integrations will be error-free, uninterrupted, or fit for any particular purpose.
Section 05
Limitation of Liability
Maximum extent permitted by applicable law

To the maximum extent permitted by applicable law, AssurAI Inc., its officers, directors, employees, contractors, agents, licensors, and successors shall not be liable for any damages or losses arising from or related to your use of the platform or reliance on its outputs.

Excluded damages include, without limitation:

  • Loss of data, audit evidence, workpapers, or records, however caused and regardless of the theory of liability.
  • Compliance failures, regulatory violations, sanctions, fines, penalties, or adverse regulatory actions.
  • Adverse audit outcomes, qualified audit opinions, or material weaknesses identified after reliance on the platform.
  • Errors, omissions, inaccuracies, or hallucinations in AI-generated findings, recommendations, risk ratings, or summaries.
  • Third-party service outages, disruptions, or failures (including Supabase, Netlify, Anthropic, Google, or OpenAI).
  • Decisions made by users, management, boards, or regulators in reliance on AI-generated content.
  • Indirect, incidental, consequential, special, exemplary, or punitive damages of any kind.
  • Loss of revenue, profits, business, goodwill, or anticipated savings.
  • Damage to reputation or brand resulting from use of or reliance on the platform.
Liability Cap

AssurAI Inc.'s total aggregate liability to you for all claims arising from or relating to these terms or your use of the platform shall not exceed the total fees paid by you to AssurAI Inc. in the twelve (12) calendar months immediately preceding the event giving rise to the claim.

Some jurisdictions do not allow the exclusion or limitation of certain categories of damages, so some of the above limitations may not apply to you. In such jurisdictions, AssurAI's liability is limited to the fullest extent permitted by applicable law.

Section 06
Indemnification
User obligations to hold AssurAI harmless

You agree to indemnify, defend, and hold harmless AssurAI Inc. and its officers, directors, employees, contractors, agents, licensors, successors, and assigns from and against any and all claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or relating to:

  • Your use of or access to the AssurAI platform, including any actions taken based on AI-generated outputs.
  • Your violation of these disclaimers, the Terms of Service, or any applicable law, regulation, or professional standard.
  • Your breach of any representation or warranty made in connection with your use of the platform.
  • Any data, content, workpapers, or information you submit to or through the platform, including any claims that such content infringes any third-party rights.
  • Any regulatory investigation, enforcement action, or legal proceeding arising from your reliance on AI-generated content without appropriate professional review.
  • Any claims by your clients, employers, auditors, or regulators arising from your use of AssurAI in the performance of professional services.
  • Any misuse of the platform or violation of any third-party's rights in connection with your use.

AssurAI reserves the right, at its own expense, to assume the exclusive defense and control of any matter otherwise subject to indemnification by you, in which event you will cooperate fully with AssurAI in asserting any available defenses.

Professional Services Reminder

If you are a professional services provider (CPA, CIA, attorney, consultant) using AssurAI to support client engagements, you remain solely responsible for the professional quality and adequacy of your work product. AssurAI is a tool — your professional obligations to your clients and licensing bodies are unaffected by your use of the platform.

Section 07
Data & Security
Data handling, encryption, and user responsibilities

AssurAI employs industry-standard security controls including AES-256 encryption at rest, TLS 1.3 in transit, and row-level security enforced at the database layer. The platform is hosted on Supabase (PostgreSQL) and Netlify infrastructure with SOC 2 Type II certified providers. However, no system is 100% secure, and AssurAI cannot guarantee absolute security of your data.

Users are solely responsible for:

  • Assessing the sensitivity and classification of data before uploading it to the platform.
  • Complying with their organization's data classification, handling, and retention policies.
  • Ensuring that upload of any data complies with applicable confidentiality agreements, professional standards, and data protection laws.
  • Not uploading data that is prohibited by law, regulation, contractual obligation, or internal policy from being processed by third-party AI services.
  • Ensuring an appropriate legal basis exists for any personal data (as defined under GDPR or applicable privacy law) processed through the platform.
  • Promptly notifying AssurAI of any suspected unauthorized access to their account or data.
  • Maintaining the security and confidentiality of their login credentials and API tokens.

AssurAI Inc. is not liable for unauthorized access to data resulting from user failure to maintain credential security, use of compromised devices, or any other factor within the user's control.

Section 08
Professional Responsibility
Obligations of licensed audit and compliance professionals

AssurAI is designed to augment — not replace the professional judgment, expertise, and accountability of licensed auditors, CPAs, CIAs, CISAs, attorneys, and other qualified professionals. Users who are licensed or credentialed professionals retain all their professional obligations regardless of their use of this platform.

Licensed professionals using AssurAI must:

  • Apply their professional judgment to independently validate all AI-generated content before incorporating it into workpapers, reports, or professional opinions.
  • Disclose their use of AI-assisted tools to their clients, employers, audit committees, and external auditors as required by applicable professional standards.
  • Notify audit committees, boards of directors, and external auditors of AI tool usage in audit procedures that may be relied upon by external auditors.
  • Comply with any restrictions imposed by external auditors, regulators, or professional licensing bodies regarding the use of AI tools in professional engagements.
  • Ensure that all work product meets applicable professional standards (AICPA, IIA, ISACA, ABA, or other relevant standards) regardless of how that work product was developed.
  • Maintain required documentation standards, including evidence that AI-generated content was reviewed and validated by a qualified human professional.
Audit Committee Notification Reminder

Before using AssurAI in work that may be relied upon by external auditors, consult your external auditors and disclose the nature and extent of AI assistance used. External auditors may have specific requirements regarding AI-assisted audit tools under applicable professional standards.

Nothing in these disclaimers, the Terms of Service, or your use of the platform diminishes, modifies, or waives any professional obligations, ethical duties, or standards of care applicable to you under your professional license or certification.

Governing Law. These disclaimers and any disputes arising from your use of the AssurAI platform shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict of law provisions. Any legal action or proceeding arising under these disclaimers shall be brought exclusively in the federal or state courts located in Delaware.

Severability. If any provision of these disclaimers is held to be invalid, illegal, or unenforceable, the remaining provisions shall continue in full force and effect.

Changes to Disclaimers. AssurAI Inc. reserves the right to modify these disclaimers at any time. Continued use of the platform after any modification constitutes acceptance of the updated disclaimers. The "Last Updated" date at the top of this page reflects the most recent revision.

Questions about these disclaimers?
Our legal team is available to address questions about platform limitations,
data handling, or your professional obligations when using AssurAI.