Disclaimers — Virtosic
Effective Date: 9 August 2026
Last Updated: 9 August 2026
This document is incorporated into, and forms part of, the Terms of Service, and should be read together with the warranty disclaimers and limitation of liability in Sections 11 and 12 of those Terms.
1. Not Legal, Compliance-Certification, or Audit Advice
Virtosic is a decision-support tool, not a law firm, a licensed compliance professional, or an accredited certification body. Nothing generated by the Service — including risk assessments, draft policies, framework gap analyses, or reports — constitutes legal advice, and using the Service does not create an attorney-client relationship.
Virtosic does not certify, attest to, or guarantee that your organization satisfies the requirements of any regulatory framework or standard. The Service currently tracks six frameworks — SOC 2, HIPAA, GDPR, CMMC, ISO 27001, and PCI-DSS — and the same limit applies to each of them, and to any state privacy law or other standard referenced in the Service. Only an independent, accredited auditor or the relevant regulatory body can make that determination. Treat framework "completion percentage" and control status as a preparation and tracking aid, not a certification result.
2. AI-Generated Policies and Risk Content
Draft policies, risk register entries, and business-impact explanations are generated in whole or in part by artificial intelligence, based on the information you provide or connect. This content can be incomplete, generic, outdated relative to current law, or simply wrong for your specific circumstances.
A policy stays a draft until a person in your organization publishes it — the Service has no path that publishes one for you. It is your responsibility to review, edit, and formally approve any policy before publishing and relying on it, and to have policies with significant legal exposure reviewed by qualified counsel before adoption.
3. Document Intelligence and Extraction Accuracy
The Document Intelligence feature uses AI to extract structured data (questionnaire responses, evidence metadata, equipment details) from uploaded photographs and documents. Automated extraction can misread or misinterpret source material, particularly low-quality photographs, unusual formats, or non-English documents. Always review extracted data against the source document before confirming it — the Service requires that confirmation step precisely because extraction is not guaranteed to be accurate, and nothing extracted reaches your records without it.
4. Risk Acceptance Is Your Organization's Decision
When you formally "accept" a risk within the Service, that decision, its justification, and its approval chain are your organization's own risk-management record. Virtosic does not evaluate, endorse, or validate the adequacy of a risk acceptance decision — the feature exists to document your decision-making process, not to make the decision for you or to confirm it was the right one.
5. Human Advisor and Escalation Feature
Virtosic's Escalation Router identifies decisions that likely warrant human judgment and routes them to a person. Its rules are deterministic and written in code rather than left to a model, and it has no path by which it can resolve an escalation itself. This is a safety-oriented design choice, not a guarantee that every consequential decision will be correctly flagged, nor a substitute for your organization maintaining its own competent judgment about when to seek professional advice, regardless of whether the Service happens to surface an escalation for a given situation.
If you engage a third-party advisor (including through any partner directory Virtosic may offer), that advisor's services are provided under a separate engagement between you and the advisor; Virtosic is not responsible for the quality, accuracy, or outcome of that advisor's work, except where the advisor is directly employed by Virtosic and acting in that capacity.
6. Vendor Risk Assessments
A vendor risk score in Virtosic is a restatement of the answers you gave about that vendor, and nothing else. The score is calculated arithmetically in code from your questionnaire responses, so it is reproducible by reading the answers; the AI writes the accompanying explanation, and it does not do the scoring.
Virtosic does not monitor vendors. There is no breach feed, no security-ratings provider, and no financial-data source connected to the Service, and Virtosic will not generate such signals from a model's recollection of a company — a monitoring signal is a factual allegation about a named third party, and a recalled headline is not evidence. Where a vendor's monitoring feed appears empty in the Service, it is empty because nothing is watching, not because nothing has happened.
Virtosic does not independently audit third-party vendors and cannot verify that a vendor's actual practices match its questionnaire responses. Vendor risk information is a starting point for your own due diligence, not a substitute for it, and no vendor assessment is ever marked as verified.
7. Legacy and Operational-Technology (OT) Assets
The OT/legacy assessment module is not available in the Service. Your company profile records whether you operate legacy or operational-technology equipment, and that flag informs which compliance frameworks the Service recommends to you. Beyond that, the Service does not assess OT assets, does not suggest compensating controls for them, and does not perform network discovery of any kind — passive or otherwise. Nothing in Virtosic looks at your network to find devices.
For safety-critical or specialized OT/ICS environments, engage a qualified OT security engineer. Virtosic has nothing to offer on that question today, and will say so rather than generalize.
8. Third-Party Connected Systems
Virtosic reads data from systems and public records we do not own or control — today, the public DNS records for a domain you nominate. We are not responsible for the availability, accuracy, or security of any such system or record, or for changes a third party makes that affect our ability to read from it.
Connectors for cloud and identity providers are not available in the Service. Until you connect a domain, Virtosic has verified nothing about your environment independently, and every finding you see is a restatement of your own answers — which is why findings carry a confidence label rather than being presented uniformly.
9. Health Information
Virtosic is not a substitute for a HIPAA risk analysis performed or reviewed by a qualified compliance professional where one is legally required. See Section 5 of the Terms of Service and Section 5 of the Privacy Policy regarding the requirement for a Business Associate Agreement before submitting Protected Health Information.
10. Limitation of Liability Cross-Reference
The disclaimers in this document are subject to, and should be read together with, the warranty disclaimers and limitation of liability provisions in Sections 11 and 12 of the Virtosic Terms of Service.
Contact
Questions about this document should be directed to [email protected] — Virtosic, Houston, Texas, United States.
</content>