SecurePledge Terms and Condition
Effective Date: [CONFIRM: effective date] Last Updated: [CONFIRM: last updated date]
Acceptance of Terms
These Terms and Conditions (“Terms“) govern access to and use of the website at [CONFIRM: website URL] (the “Site“) and the SecurePledge AI Interaction Security Platform, including the AI Gateway, the Sensitive Data Redactor, the Shadow AI Protector, and the Governance & Audit Layer (collectively, the “Service“), provided by [CONFIRM: exact registered legal entity name – believed to be StrategyWiz Consulting Private Limited] (“SecurePledge,” “we,” “us,” or “our“).
By accessing the Site, creating an account, or using the Service, you agree to be bound by these Terms on behalf of yourself and, if applicable, the organization you represent (the “Customer“). If you do not agree, do not use the Site or the Service.
Where your organization has signed a separate Order Form, Master Subscription Agreement, or Data Processing Agreement with us, the terms of that document will govern in the event of a conflict with these Terms.
Definitions
- “Service” – the SecurePledge platform, including its component modules (AI Gateway, Redactor, Protector, Governance & Audit Layer/Admin Console), as made available to a Customer.
- “Customer” – the organization that registers for or subscribes to the Service.
- “Authorized User” – an employee, contractor, or agent of a Customer who is permitted to access the Service.
- “Customer Data” – any data submitted to or processed by the Service by or on behalf of Customer or its Authorized Users, including prompts, documents, redaction outputs, and related metadata.
- “AI Provider” – a third-party foundation-model provider (such as OpenAI, Anthropic, or Google) that Customer configures the Service to route requests to, using Customer’s own credentials.
- “Order Form” – a document (online or signed) specifying the subscription plan, fees, and term for a Customer.
- “Documentation” – user guides and technical documentation we make available for the Service.
Description of the Service
SecurePledge is an AI interaction security platform that sits between an organization’s employees and the AI tools they use, applying a “detect → prevent → redirect → log → prove” model rather than after-the-fact monitoring alone. Depending on the plan and configuration selected, the Service may include:
- AI Gateway: a policy-governed access point that routes prompts to Customer-approved AI models, applies pre-AI sensitive-data detection and redaction, and enforces Customer-defined policies (allow / block / redact / warn).
- Sensitive Data Redactor: detects and masks PII, PHI, financial, and other sensitive data in text and documents, including a reversible-redaction capability for authorized in-session use.
- Shadow AI Protector: detects use of AI websites, intercepts prompts before submission, applies inline masking or warnings, and can redirect users to an approved AI access point.
- Governance & Audit Layer / Admin Console: policy configuration, audit logging, incident tracking, and compliance-oriented reporting.
Roadmap disclosure. Our product materials, pitch decks, and website describe both currently available features and features on our development roadmap (for example, certain desktop/native-application interception capabilities and advanced context-aware detection). The specific features available to Customer are those identified in the applicable Order Form and Documentation as of the order date, not every feature referenced in general marketing materials. We will be clear about what is generally available versus in development at the time of purchase.
Bring-your-own-key model. The Service is generally designed for Customer to supply its own credentials for the AI Providers it wishes to use. Customer, not SecurePledge, holds the direct account relationship, billing relationship, and applicable terms of service with each AI Provider it configures.
Eligibility
The Service is intended for business use by organizations and their Authorized Users, not for personal, household, or consumer use. By using the Service, you represent that you are at least 18 years old and are authorized to act on behalf of the Customer you represent.
Account Registration and Security
Customer and its Authorized Users must provide accurate registration information and are responsible for maintaining the confidentiality of login credentials and for all activity occurring under their accounts. Customer must notify us promptly of any suspected unauthorized access.
Subscriptions, Fees, and Payment
- Access to the Service is generally provided on a subscription basis (e.g., per-Authorized-User pricing), as set out in an Order Form or on the Site’s pricing page. [CONFIRM: current pricing model and whether tiers are Starter/Growth/Enterprise as referenced internally.]
- Fees are payable in advance for the applicable billing period unless otherwise stated in an Order Form. [CONFIRM: payment processor, invoicing cadence, and accepted currencies.]
- We may offer free trials or pilot programs at our discretion; unless otherwise stated, a trial or pilot converts to a paid subscription only with Customer’s affirmative action, and we will provide notice before any trial-to-paid transition where feasible. [CONFIRM: standard pilot/trial length and terms.]
- Fees are exclusive of applicable taxes (e.g., GST), which Customer is responsible for, except taxes on our net income.
- Except as required by law or expressly stated in an Order Form, fees are non-refundable.
Customer Responsibilities
Customer is responsible for:
- Supplying and maintaining valid credentials for any AI Provider it configures, and complying with that AI Provider’s own terms of use.
- Configuring the Service’s detection and policy rules appropriately for its own regulatory and business requirements. The Service is a tool to reduce risk, not a guarantee of legal or regulatory compliance – see Section 13.
- Providing appropriate notice to its own employees regarding monitoring, interception, and logging of AI interactions, to the extent required by applicable employment, privacy, or labor law in its jurisdiction.
- Ensuring its use of the Service, and the data it submits, complies with applicable law, including data protection and sector-specific regulation (e.g., healthcare or financial-services rules).
- Maintaining the confidentiality of any administrator credentials and promptly reporting suspected security issues.
Acceptable Use
Customer and its Authorized Users must not:
- Use the Service to violate applicable law, or to process data they are not legally permitted to process.
- Attempt to reverse-engineer, decompile, or circumvent the Service’s security or detection mechanisms, other than as permitted by law.
- Interfere with or disrupt the integrity or performance of the Service.
- Use the Service to build a competing product.
- Resell or sublicense the Service without our prior written consent, except as expressly permitted in an Order Form.
Third-Party AI Services
The Service is designed to route requests to third-party AI Providers selected and configured by Customer. We are not responsible for the availability, accuracy, outputs, security practices, or data-handling practices of any third-party AI Provider. Customer’s use of any AI Provider is subject to that provider’s own terms and privacy policy, and Customer is responsible for ensuring it has the right to send the data it submits to the AI Provider it selects.
Ownership and License
- Customer Data. As between the parties, Customer retains all rights to Customer Data. Customer grants us a limited license to access, process, transmit, and store Customer Data solely to provide, maintain, and support the Service, enforce Customer’s configured policies, and as otherwise permitted under this Agreement or a separate DPA.
- Model improvement. [CONFIRM: whether Customer Data is ever used, in any form, to improve, train, or evaluate our detection/redaction models. If yes, this requires explicit, clearly disclosed consent language here and in the Privacy Policy – it should not be assumed or left ambiguous.]
- SecurePledge IP. We and our licensors retain all rights, title, and interest in and to the Service, the Site, our Documentation, and all underlying technology, including the “SecurePledge” name and logo [CONFIRM: trademark registration status], excluding Customer Data. No rights are granted to Customer except as expressly stated in these Terms.
- Feedback. If Customer provides feedback or suggestions about the Service, we may use them without restriction or obligation to Customer.
Confidentiality
Each party agrees to protect the other’s confidential information disclosed in connection with the Service with at least the same degree of care it uses for its own confidential information of a similar nature, and not to disclose it except to personnel, contractors, or advisors with a need to know, or as required by law (with notice to the disclosing party where legally permitted).
Data Protection
Our collection and use of personal data in connection with the Service is described in our Privacy Policy. Where Customer’s use of the Service involves the processing of personal data on Customer’s behalf, the parties will enter into a Data Processing Agreement governing that processing, which will control over these Terms and the Privacy Policy with respect to such processing. [CONFIRM: whether a standard DPA currently exists – recommended before onboarding customers in regulated industries such as healthcare and BFSI.]
Disclaimer of Warranties; No Guarantee of Complete Detection
THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
Specific to a security and detection product, we want to be direct about the following: the Service uses automated, rule-based and machine-learning-assisted detection and redaction. No detection system is perfect. The Service may fail to identify some sensitive data (a false negative) or flag non-sensitive data (a false positive). Use of the Service reduces, but does not eliminate, the risk of sensitive data exposure, and does not by itself guarantee compliance with any law, regulation, or industry framework (including SOC 2, HIPAA, GDPR, or ISO 27001). Customer remains responsible for its own compliance obligations and for independently assessing whether the Service meets its regulatory requirements. As noted in our Privacy Policy, SecurePledge has not, as of the date of these Terms, completed independent third-party security certifications such as SOC 2.
Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW:
(A) NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR LOST PROFITS, REVENUE, OR DATA, EVEN IF ADVISED OF THE POSSIBILITY; AND
(B) OUR AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICE WILL NOT EXCEED THE FEES PAID BY CUSTOMER TO US IN THE [CONFIRM: e.g., “twelve (12) months”] PRECEDING THE EVENT GIVING RISE TO LIABILITY.
[CONFIRM with counsel: carve-outs are standard here – e.g., for breach of confidentiality, IP infringement, or a party’s indemnification obligations, liability caps are often excluded or set at a higher multiple. This should be tailored per deal size in enterprise MSAs rather than left as a single blanket cap.]
Nothing in these Terms limits liability that cannot be limited under applicable law.
Indemnification
Customer agrees to indemnify and hold us harmless from third-party claims arising from Customer’s breach of these Terms, misuse of the Service, or violation of applicable law, including claims relating to Customer Data it submits. We agree to indemnify Customer against third-party claims that the Service, as provided by us and used in accordance with these Terms, infringes a third party’s intellectual property rights, subject to customary exclusions (e.g., modified or misused versions of the Service, or combination with non-SecurePledge products). [CONFIRM with counsel: standard indemnification procedures – notice, control of defense, cooperation.]
Term and Termination
- These Terms remain in effect while Customer has an active account or subscription.
- Either party may terminate for the other’s material breach if not cured within [CONFIRM: e.g., “thirty (30) days”] of written notice.
- We may suspend or terminate access immediately for security reasons, suspected unlawful use, or non-payment, with notice where practicable.
- Upon termination, Customer’s right to access the Service ends. Customer may request export of its Customer Data within [CONFIRM: retrieval window, e.g., “30 days”] of termination, after which we may delete it in accordance with our data retention practices, except as required by law.
Changes to the Service
We may modify, update, or discontinue features of the Service from time to time. We will use reasonable efforts to provide advance notice of material changes that reduce core functionality for paying Customers.
Compliance with Laws; Export Control
Each party will comply with applicable laws in connection with its use of the Service, including applicable export control and sanctions laws.
Governing Law and Dispute Resolution
These Terms are governed by the laws of India, without regard to conflict-of-laws principles, and subject to the exclusive jurisdiction of the courts of [CONFIRM: city – Delhi is suggested given your initial Delhi NCR market focus, but this must be confirmed against your actual registered office and business preference]. [CONFIRM: whether arbitration is preferred over court litigation for commercial disputes – common in Indian B2B SaaS contracts, e.g., arbitration under the Arbitration and Conciliation Act, 1996, seated in a specified city.]
For Customers located outside India, [CONFIRM: whether a different governing-law/jurisdiction clause is needed, particularly for enterprise deals with international customers.]
Force Majeure
Neither party is liable for delay or failure to perform due to causes beyond its reasonable control, including natural disasters, war, labor disputes, internet or utility failures, or governmental action.
Assignment
Neither party may assign these Terms without the other’s prior written consent, except in connection with a merger, acquisition, or sale of substantially all assets, with notice to the other party.
Entire Agreement; Order of Precedence
These Terms, together with the Privacy Policy and any applicable Order Form and DPA, constitute the entire agreement between the parties regarding the Service. In case of conflict, the order of precedence is: (1) a signed Order Form or MSA, (2) a signed DPA (for data-processing matters), (3) these Terms, (4) the Privacy Policy.
Severability; Waiver; Notices
If any provision of these Terms is held unenforceable, the remaining provisions remain in effect. Failure to enforce a provision is not a waiver of future enforcement. Notices should be sent to the addresses specified in Section 24 or in the applicable Order Form.
Changes to These Terms
We may update these Terms from time to time. We will post the revised Terms with an updated “Last Updated” date and, for material changes affecting paying Customers, provide reasonable advance notice.
Contact Us
Questions about these Terms should be directed to:
[CONFIRM: Company legal name] [CONFIRM: registered address] Email: [CONFIRM: legal/contact email] Phone: [CONFIRM: phone number, optional]