Legal

Terms of Service

Effective September 10, 2026

These Terms of Service (“Terms”) govern access to and use of CyberGuardIntel AI (the “Service”), provided by Fabstech LLC (“Fabstech,” “we,” “us,” or “our”). By creating an account, starting a trial, or otherwise using the Service, you agree to these Terms on behalf of yourself and, if applicable, the organization you represent (“Customer,” “you”).

1. Acceptance of these Terms

By accessing or using the Service you confirm that you have the authority to bind your organization to these Terms and that you accept them. If you do not agree, do not use the Service. If we make material changes, we will let you know as described in Changes to the Service or these Terms.

2. The Service

CyberGuardIntel AI helps healthcare organizations and health-tech vendors get ready for HIPAA (and, on our roadmap, additional frameworks such as SOC 2 and PCI-DSS). The Service includes:

  • AI-assisted drafting of policies and risk assessments, which stay in draft status until a qualified person on your team reviews and approves them;
  • control-mapped evidence collection through integrations you configure and authorize;
  • a PHI system map, BAA tracker, and audit-package export for organizing your HIPAA compliance program; and
  • related dashboards, reminders, and reporting features.

The Service is a compliance-readiness tool, not a law firm, a certification body, or a substitute for your own compliance, security, or legal judgment. See AI-generated content below.

3. Accounts, organizations, and security

Accounts are created and authenticated through our identity provider, Clerk, including via Google, Microsoft, or GitHub sign-in. Multi-factor authentication is enforced on every account and every plan. You are responsible for:

  • keeping your login credentials and MFA methods secure;
  • all activity that occurs under your account or your organization’s account, including actions by members you invite; and
  • promptly removing access for members who should no longer have it (for example, employees who have left your organization).

Organization owners and admins can manage members, roles, and integrations for their organization. We are not responsible for disputes between members of the same organization about access or permissions.

4. Free trial

New organizations may start a 14-day free trial with no credit card required. We may change trial length, eligibility, or included features at any time, and may limit trials to one per organization or business to prevent abuse. At the end of a trial, continued use of paid features requires an active subscription.

5. Subscriptions and billing

Paid plans (currently Starter, Growth, Business, and Enterprise) are billed monthly or annually in advance through our payment processor, Stripe. We do not store your full payment card details; Stripe handles that on our behalf.

  • Subscriptions renew automatically at the end of each billing period unless cancelled before renewal.
  • Plan limits (seats, integrations, frameworks, policies) are described on our pricing page and may be enforced technically within the Service.
  • Upgrades take effect immediately, with a prorated charge for the remainder of the current period; downgrades take effect at the start of the next billing period.
  • Enterprise plans are quoted separately; contact sales@notifications.cyberguardintel.ai for a custom agreement, which controls over these Terms for that account where the two conflict.
  • Fees are exclusive of taxes; you are responsible for any applicable taxes other than our income tax.

6. Cancellation and refunds

You may cancel your subscription at any time from your organization’s billing settings. Cancellation takes effect at the end of your current billing period, and you will keep access to paid features until then. Except where required by applicable law, fees already paid are non-refundable, including for partial billing periods or unused seats.

7. Acceptable use

You agree not to, and not to permit others to:

  • use the Service to violate any law or the privacy or security rights of others;
  • upload content you do not have the right to upload, or that infringes a third party’s intellectual property rights;
  • attempt to gain unauthorized access to the Service, other accounts, or connected third-party integrations beyond the access you have configured and are authorized to use;
  • reverse engineer, decompile, or attempt to extract the source code of the Service, except where applicable law permits it despite this restriction;
  • probe, scan, or test the vulnerability of the Service or any connected system without our prior written consent;
  • use the Service to build a competing product, or to train a competing AI model on our outputs; or
  • interfere with or disrupt the integrity or performance of the Service.

8. Your data and content

As between you and us, you (or your organization) own the content you submit to the Service, including uploaded evidence files, policy drafts, risk assessments, PHI system map entries, and BAA records (“Customer Data”). You grant us a worldwide, non-exclusive license to host, process, transmit, and display Customer Data solely to provide, maintain, and improve the Service for you.

You are responsible for the accuracy, quality, and legality of Customer Data and for having the rights needed to submit it and to authorize the third-party integrations you connect. Evidence files are encrypted at rest (AES-256/SSE-KMS) in our cloud storage, and downloads use signed links that expire shortly after they are issued.

9. AI-generated content

Certain features use AI models (including third-party AI providers) to draft policies, risk assessments, and related content from information you provide. This AI-generated content:

  • is always created with a draft status and is never presented to auditors, regulators, or third parties as final until a qualified person at your organization reviews and approves it;
  • may be incomplete, out of date, or inaccurate, and is provided as a starting point only; and
  • does not constitute legal, medical, clinical, or compliance advice, and is not a substitute for review by qualified counsel or compliance personnel.

You are solely responsible for reviewing, editing, and approving any AI-generated content before relying on it or submitting it to any third party, auditor, or regulator.

10. Protected health information

The Service is designed to help you assess and document your organization’s HIPAA posture — for example, by mapping which systems touch protected health information (“PHI”) — rather than to store PHI itself. Unless we have agreed otherwise in writing (including under a Business Associate Agreement as described below), you agree not to upload actual PHI or other regulated patient data into free-text fields, evidence files, or any other part of the Service beyond what is reasonably necessary and clearly identified as such.

If your organization is a HIPAA Covered Entity or Business Associate and needs us to sign a Business Associate Agreement (“BAA”) covering PHI you process through the Service, contact legal@notifications.cyberguardintel.ai. The BAA Tracker feature, which helps you manage BAAs between your organization and your own vendors, is a separate, distinct arrangement from any BAA between you and Fabstech.

11. Third-party integrations

You may connect third-party services (cloud providers, identity providers, productivity, communication, storage, engineering, and security tools) to collect compliance-relevant evidence. You are responsible for having the authority to connect each integration and for complying with that provider’s own terms. We only access the scopes and metadata needed to map evidence to controls; we do not control, and are not responsible for, the availability, security, or practices of third-party services.

12. Intellectual property

Fabstech and its licensors own all right, title, and interest in the Service, including its software, design, and the “CyberGuardIntel AI” name and logo, excluding Customer Data. Nothing in these Terms transfers any of that intellectual property to you. If you send us feedback or suggestions, you grant us the right to use them without restriction or obligation to you.

13. Confidentiality

Each party may receive non-public information from the other (“Confidential Information”). Each party will use the other’s Confidential Information only to perform its obligations under these Terms, protect it with reasonable care, and not disclose it to third parties except to personnel, contractors, or service providers who need it and are bound by similar confidentiality obligations, or as required by law.

14. Disclaimers

The Service is provided “as is” and “as available,” without warranties of any kind, whether express, implied, or statutory, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service will be uninterrupted, error-free, or fully secure, or that using the Service will result in passing any audit or certification. We currently describe our security practices as HIPAA-aligned, and SOC 2 support is on our roadmap; neither is a certification unless we state otherwise in writing.

15. Limitation of liability

To the maximum extent permitted by law, neither party will be liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, or data, arising from these Terms or the Service, even if advised of the possibility. Each party’s total liability arising from these Terms will not exceed the amount you paid us in the twelve (12) months before the claim arose. These limits do not apply to a party’s indemnification obligations, confidentiality breaches, or liability that cannot be limited by law.

16. Indemnification

You will defend, indemnify, and hold Fabstech harmless from third-party claims arising from your Customer Data, your use of the Service in violation of these Terms, or your violation of applicable law. We will defend, indemnify, and hold you harmless from third-party claims that the Service, as provided by us, infringes that third party’s intellectual property rights.

17. Term, suspension, and termination

These Terms remain in effect while you use the Service. We may suspend or terminate access if you materially breach these Terms and do not cure the breach within a reasonable period after notice, or immediately if needed to prevent harm to the Service, other customers, or third parties. You may terminate by cancelling your subscription and discontinuing use of the Service.

Upon termination, your right to access the Service ends. We will make reasonable efforts to let you export Customer Data for a limited period after termination, after which we may delete it in accordance with our data retention practices.

18. Changes to the Service or these Terms

We may update the Service and these Terms from time to time. For material changes, we will provide notice by posting an updated “Effective” date on this page and, where appropriate, by emailing the account owner or showing an in-app notice. Continued use of the Service after changes take effect constitutes acceptance of the updated Terms.

19. Governing law and disputes

These Terms are governed by the laws of the State of Delaware, United States, without regard to conflict-of-laws principles. Any dispute not resolved informally will be brought exclusively in the state or federal courts located in Delaware, and each party consents to that jurisdiction and venue.

20. General provisions

  • Entire agreement. These Terms, together with any order form or enterprise agreement, are the entire agreement between you and Fabstech regarding the Service.
  • Assignment. You may not assign these Terms without our consent; we may assign them in connection with a merger, acquisition, or sale of assets.
  • Severability. If any provision is found unenforceable, the remaining provisions stay in effect.
  • No waiver. Failure to enforce a provision is not a waiver of it.
  • Force majeure. Neither party is liable for delays caused by events beyond its reasonable control.

21. Contact us

Questions about these Terms can be sent to legal@notifications.cyberguardintel.ai. Fabstech LLC is the operator of CyberGuardIntel AI.