1. These terms
These terms govern your use of the AudiDesk platform and this website. By using either, you agree to them. If you are agreeing on behalf of an organization, you confirm you are authorised to do so, and “you” means that organization.
The contracting party is the operating company, to be named here, company number pending, registered at an address to be stated here.
These terms stand alone unless we have signed a separate written agreement with you covering the same subject matter. Where we have, that agreement takes precedence over these terms to the extent the two conflict, and these terms fill whatever it does not address.
2. What the service is
AudiDesk ingests software inventory data that you supply, normalises it, enriches it against public lifecycle and vulnerability catalogues, scores it with a deterministic rule engine, and produces findings, registers and reports. Later tiers add document evidence, live connectors and generated remediation drafts.
The service is provided over the internet. We do not install software on your machines.
3. Access is by invitation
There is no self-service registration. Accounts are created by invitation while early workspaces are onboarded, and we may decline or withdraw an invitation at our discretion. An invitation is personal to the address it was sent to and is not transferable.
4. Your account
You are responsible for the security of your credentials and for what is done under your account. Tell us promptly if you believe an account has been compromised. Workspace owners are responsible for who they invite and for the role they grant.
5. Your data
You keep all rights in the data you upload. You grant us the limited licence needed to host, process and display it in order to provide the service, and for no other purpose. We do not use your data to train models, and we do not use it to build products for anyone else.
You are responsible for having the right to upload what you upload, including any personal data it contains, and for telling the people it concerns as your own privacy obligations require. Where we process personal data on your behalf, our data processing agreement applies.
6. Acceptable use
You must not:
- upload data you have no right to hold or share, or that you know to be malicious;
- attempt to reach another customer’s workspace, or to test the isolation between workspaces without our prior written agreement;
- probe, scan, load-test or attempt to circumvent any security or rate-limiting control, except under an agreed disclosure process;
- resell, sublicense or provide the service to third parties other than by assessing your own clients within your own workspaces;
- reverse engineer the service or extract its rulesets, control library or templates for use in a competing product;
- use the service to send unsolicited mail, or to store material that is unlawful;
- misrepresent output of the service as a certification, an accreditation, or an audit opinion issued by a certification body.
We may suspend access where continued use presents a security risk or breaches this section, and we will tell you why.
7. Not a certification, and not legal advice
Output produced by AudiDesk is not an ISO/IEC 27001 certification and does not confer, imply or substitute for one. Certification against ISO/IEC 27001 can be issued only by an accredited certification body following its own audit. Nothing this platform generates is such an audit, and no report, score, control status or generated document should be presented as evidence that certification has been achieved.
Our ISO reporting is explicitly inventory-scoped. A software inventory evidences only a small subset of the Annex A controls; the remainder are reported as not assessed. A report that says a control was not assessed means exactly that, and must not be read as a statement that the control is satisfied.
Nothing produced by the service is legal advice. Generated policies, procedures and forms are drafts intended for review by a competent person in your organization. They are marked as drafts, they carry a disclaimer that cannot be removed, and they require a named human approver before they leave draft state. You remain responsible for whether a document is appropriate for your organization and lawful in your jurisdiction.
Assessment results depend on the completeness and accuracy of the data you provide. An inventory that omits systems produces an assessment that omits them too.
8. Third-party standards
ISO/IEC 27001 is a copyrighted standard licensed by its publisher. The platform references control identifiers and titles and provides original paraphrased guidance; it does not reproduce the text of the standard. You need your own licensed copy of any standard you are working against. The same applies to other frameworks referenced in the product, each under its own licence terms.
9. Availability and changes
We aim to keep the service available and will give reasonable notice of planned maintenance where we can. We may change or discontinue features. Where a change materially reduces functionality you rely on, we will tell you in advance.
10. Fees
The service is quoted per engagement. Fees, billing frequency and any usage limits are set out in the order or quotation agreed with you. Unless that document says otherwise, fees are exclusive of taxes and are non-refundable for a period already begun.
11. Intellectual property
The platform, its rule engine, its control library, its report templates and its brand remain ours. These terms grant you a non-exclusive, non-transferable right to use the service during the term. Reports and documents generated for you, and the data you put in, are yours to use.
12. Warranties
We provide the service with reasonable skill and care. Beyond that, and to the extent the law allows, the service is provided as is: we do not warrant that it will be uninterrupted or error free, that public catalogue data it relies on is complete, or that its output will satisfy any particular auditor, regulator or certification body.
13. Limitation of liability
Nothing in these terms limits liability that cannot lawfully be limited, including liability for death or personal injury caused by negligence, or for fraud.
Subject to that, neither party is liable for indirect or consequential loss, loss of profit, loss of business, loss of goodwill, or loss of anticipated savings. In particular, and given section 7, we are not liable for any regulatory finding, failed audit, refused certification or contractual loss arising from reliance on platform output as though it were a certification or legal advice.
Subject to the paragraphs above, each party's total liability arising out of or in connection with these terms is limited to the total fees you paid us in the twelve months immediately before the event giving rise to the claim.
That cap does not apply to your obligation to pay fees due, to either party's liability for a breach of the confidentiality obligations in section 11, or to liability that cannot lawfully be limited as described above.
14. Term and termination
These terms apply for as long as you use the service. Either party may terminate on notice as set out in the agreed order. We may terminate immediately for a material breach that is not remedied within a reasonable period after we have told you about it, or immediately where continued access presents a serious security risk.
On termination your access ends. You may export your data before the end of the term; after termination we delete or return it as set out in the data processing agreement. Sections 5, 7, 11, 12, 13 and 15 survive termination.
15. Governing law and jurisdiction
These terms are governed by the law of France, and the courts of Paris, France have exclusive jurisdiction over any dispute arising out of or in connection with them.
Nothing in this section removes a consumer's right to bring proceedings in their own place of residence where the law applying to them gives them that right.
16. Contact
Questions about these terms go to support@audidesk.com.