Back to Platform

FIVE S LLC · LEGAL

SaaS Subscription Agreement

Version 1.0 May 2026 Includes DPA (Exhibit A)

This Agreement is between AssurAI Inc., a Delaware C-Corporation ("Company"), and the entity accepting this Agreement electronically ("Customer"). By checking the acceptance box during signup, Customer agrees to be bound by this Agreement.
⚠️ AI DISCLAIMER: AssurAI outputs are AI-generated and require professional review. AssurAI is not a licensed audit firm and does not provide regulated professional services. All outputs must be reviewed by qualified professionals before reliance or submission to regulators.

1. Definitions

Platform

The AssurAI software-as-a-service application accessible at getassurai.com/app, including all features, tools, and AI-generated outputs.

Customer Data

All data, content, and information submitted by Customer or its Authorised Users through the Platform.

Authorised Users

Employees, contractors, or agents of Customer permitted to access the Platform under Customer's subscription.

Subscription Term

The monthly or annual period for which Customer has paid subscription fees.

2. Subscription and Access

Grant of Access

Subject to this Agreement and payment of all fees, Company grants Customer a non-exclusive, non-transferable right to access and use the Platform during the Subscription Term, solely for Customer's internal business purposes.

User Seats

Starter plan: up to 3 Authorised Users. Professional and Enterprise plans: unlimited Authorised Users within Customer's organisation.

Restrictions

Customer shall not: (a) sublicense, resell, or provide access to third parties; (b) reverse engineer or extract source code; (c) use the Platform to build a competing product; (d) remove proprietary notices; or (e) use in violation of applicable law.

Account Security

Customer is responsible for all activities under its account. Notify Company immediately of any unauthorised access at hello@getassurai.com.

3. Fees and Payment

Subscription Fees

All fees are in USD and non-refundable except as expressly stated. Fees are billed monthly or annually in advance. Payment is due within 7 days of invoice date.

Late Payment

Accounts more than 14 days past due may be suspended. Accounts more than 30 days past due may be terminated.

Price Changes

Company may change fees with 30 days written notice. Continued use after notice constitutes acceptance.

Taxes

Stripe Managed Payments handles automatic tax calculation and remittance. Fees are exclusive of any taxes not automatically managed by Stripe.

4. Customer Data and Privacy

Ownership

Customer retains all right, title, and interest in Customer Data. Company claims no ownership over Customer Data.

Data Processing

Company processes Customer Data as a data processor on Customer's instructions. The Data Processing Addendum (Exhibit A) governs all processing of personal data and is incorporated into this Agreement by reference.

Subprocessors & DPA Status

Company uses the following subprocessors, each bound by a Data Processing Agreement ensuring protection of Customer Data to no lesser standard than this Agreement:

Subprocessor Purpose DPA Basis
Anthropic PBCAI processing — Zero Data Retention confirmed. Customer data never used to train models.ZDR + Commercial DPA
Supabase Inc.PostgreSQL database hosted on AWS (United States)Signed DPA + SCCs
Netlify Inc.Hosting & deployment (SOC 2 Type II · ISO 27001)DPA in T&Cs + EU-US DPF
Cloudflare Inc.Security, proxy & API routingSigned DPA + SCCs
Stripe Inc.Payment processing only — no audit data accessAuto via T&Cs + EU-US DPF

Full DPA documentation and security posture: getassurai.com/security

AI Processing Disclosure

Anthropic does not use Customer Data to train AI models. Company has confirmed Zero Data Retention (ZDR) in writing with Anthropic. AI-generated outputs are produced in real-time and are not stored by Anthropic.

Data Security

Company implements TLS 1.2+ encryption in transit, AES-256 encryption at rest (via Supabase/AWS), access controls, row-level security, and audit logging. Company will notify Customer within 72 hours of any confirmed data breach affecting Customer Data.

Data Retention

Company retains Customer Data for the Subscription Term plus 60 days. Upon written request, Company will delete Customer Data within 30 days of Subscription termination. Customer may request a data export within 30 days of termination.

5. AI Outputs and Professional Disclaimer

ASSURAI OUTPUTS DO NOT CONSTITUTE PROFESSIONAL AUDIT, LEGAL, ACCOUNTING, OR COMPLIANCE ADVICE. ALL AI-GENERATED OUTPUTS MUST BE REVIEWED AND APPROVED BY QUALIFIED PROFESSIONALS BEFORE RELIANCE. COMPANY IS NOT A LICENSED AUDIT FIRM, ACCOUNTING FIRM, OR LEGAL PRACTICE.

AI-generated workpapers, risk assessments, and compliance outputs are provided for informational and efficiency purposes only. Customer assumes full responsibility for the use of AI-generated outputs, including any submission to regulators, external auditors, or boards.

6. Intellectual Property

Company IP

Company owns all right, title, and interest in the Platform, including all software, algorithms, AI models, user interfaces, and the AssurAI brand. "AssurAI" and "GetAssurAI" are trademarks of AssurAI Inc. (USPTO applications pending).

Customer IP

Customer owns all Customer Data and AI-generated outputs produced using Customer Data. Company claims no ownership of Customer's workpapers or reports.

7. Confidentiality

Each party agrees to keep confidential the other party's non-public information and use it only for the purposes of this Agreement. Company Confidential Information includes Platform technology and pricing. Customer Confidential Information includes Customer Data and audit findings.

8. Service Levels

Uptime

Company targets 99% monthly uptime, excluding scheduled maintenance.

Support Response Times

Starter: 48 business hours · Professional: 24 business hours · Enterprise: 4 business hours. Contact: hello@getassurai.com

9. Warranties and Disclaimers

EXCEPT AS EXPRESSLY STATED, THE PLATFORM IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. COMPANY DISCLAIMS ALL IMPLIED WARRANTIES INCLUDING MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.

10. Limitation of Liability

COMPANY'S TOTAL LIABILITY TO CUSTOMER SHALL NOT EXCEED THE TOTAL FEES PAID BY CUSTOMER IN THE 12 MONTHS PRECEDING THE CLAIM. NEITHER PARTY SHALL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES. These limitations are an essential element of this Agreement.

11. Term and Termination

By Customer

Customer may cancel at any time. Cancellation takes effect at end of the current billing period. No refunds for partial periods.

By Company

Company may terminate with 30 days notice, or immediately for material breach or non-payment after 30 days overdue.

12. General

Governing Law

Laws of the State of Delaware, USA.

Disputes

Binding arbitration under JAMS rules in Santa Clara County, California.

Entire Agreement

This Agreement plus the DPA (Exhibit A) constitutes the entire agreement between the parties.

Legal Notices

legal@getassurai.com · AssurAI Inc. · San Jose, CA, USA


Exhibit A — Data Processing Addendum

Customer is the data controller. AssurAI Inc. is the data processor. This DPA governs processing under GDPR, CCPA, and applicable privacy laws.

Processing Details

Purpose: Providing AssurAI Platform services. Data types: Names, email addresses, audit data, financial control information. Data subjects: Customer employees, control owners, auditors. Duration: Subscription Term plus 60 days.

Company Obligations as Processor

Process data only on Customer's documented instructions; ensure personnel confidentiality obligations; implement appropriate technical and organisational security measures; assist Customer with data subject rights within 30 days; notify Customer of data breaches within 72 hours; delete or return data upon termination.

Security Measures

TLS 1.2+ encryption in transit; AES-256 encryption at rest; access controls and authentication; audit logging; regular security assessments.

International Transfers

Customer Data is stored in the United States (AWS infrastructure via Supabase). For EU data subjects, transfers are made under Standard Contractual Clauses (SCCs) in accordance with GDPR Article 46.

Data Subject Rights

Company will assist Customer in fulfilling data subject rights requests (access, rectification, erasure, portability) within 30 days. Submit requests to privacy@getassurai.com.

CCPA

Company does not sell Customer personal information and processes data as a Service Provider under the California Consumer Privacy Act.

AssurAI Inc. (Company)

Signature
Name: Shakeel Hussain Khan
Title: Managing Member
Date

Customer

Signature
Name
Title / Organisation
Date

For enterprise agreements requiring wet signatures, contact legal@getassurai.com · DocuSign available on request.