Terms of Service — Virtosic

Effective Date: 9 August 2026
Last Updated: 9 August 2026

These Terms of Service ("Terms") form a binding agreement between Virtosic, based in Houston, Texas ("Virtosic," "we," "us," or "our"), and the entity or person agreeing to these Terms ("Customer," "you," or "your"), governing your access to and use of the Virtosic AI virtual CISO and compliance platform, including all associated websites, applications, APIs, and services (collectively, the "Service").

By creating an account, clicking "I agree," or otherwise accessing or using the Service, you agree to be bound by these Terms. If you are entering into these Terms on behalf of a company or other legal entity, you represent that you have authority to bind that entity, in which case "you" refers to that entity. If you are a Managed Service Provider ("MSP") accessing the Service on behalf of your own clients, Section 16 (MSP Terms) also applies to you.


1. Eligibility and Account Registration

1.1 The Service is intended for business and organizational use only. You must be at least 18 years old and authorized to bind your organization.

1.2 You are responsible for the confidentiality of your credentials and for all activity under your account, and for the accuracy of information you provide, including your company profile (industry, size, and regulatory flags), which is used to tailor the risk assessments, policies, and framework recommendations the Service generates.


2. Description of the Service

2.1 Virtosic provides AI-agent-generated risk assessment, policy drafting, compliance-framework gap analysis, vendor risk assessment, and reporting, intended to help organizations without a dedicated security leader build and maintain a security program.

2.2 Virtosic works from information you provide directly (questionnaire responses, uploaded documents and photographs) and from the systems you connect. The completeness and accuracy of Virtosic's output depends directly on the completeness and accuracy of the information connected or provided.

2.2.1 One connector is available today: a read-only check of the public DNS and email-authentication records for a domain you nominate. It uses no credentials and reads only public records. Connectors for cloud and identity providers (such as AWS, Okta, or Entra ID) are intended but are not available in the Service, so unless you connect a domain, everything Virtosic tells you is a restatement of what you told it.

2.3 Certain outputs (draft policies, risk register entries, compliance status) are generated by AI. Policies remain drafts until a person in your organization publishes them, and data the Service extracts from an uploaded document is not applied to your records until a person confirms it. See Section 4 and the Disclaimers.

2.4 Virtosic's Escalation Router flags certain decisions for human review rather than resolving them autonomously. Its rules are deterministic and it has no path by which it can resolve an escalation itself. This is a design feature intended to support, not replace, your organization's own judgment and, where appropriate, professional advisors.

2.5 Vendor risk assessments are derived solely from the questionnaire answers you provide about a vendor. Virtosic does not subscribe to any breach feed, security-ratings provider, or financial-data source, and does not monitor vendors for outside news. See Section 6 of the Disclaimers.


3. Subscription, Fees, and Billing

3.1 Foundation is free. An organization is created on the Foundation plan and remains on it until you choose otherwise. There is no charge, no payment method required, and no time limit — it does not expire into a paid plan, and we will not ask you for a card to keep using it.

3.2 Plans (Foundation, Growth, Regulated, or an MSP wholesale arrangement, as applicable) determine your usage limits — frameworks tracked, vendors assessed, and team members — and those limits are enforced within the Service. Where a limit stops you doing something, the Service says which plan covers it.

3.3 Paid plans may be billed monthly or annually, at your choice. The annual price is ten months' equivalent; the saving is what buys the commitment to a year. The prices shown in the Service and on our website at the time you subscribe are the prices that apply to you.

3.4 Paid plans begin with a 14-day trial. A payment method is collected when you subscribe, and no charge is raised until the trial ends. Cancel before then and you are not charged at all. The trial applies to the first paid subscription for an organization.

3.5 Payment processing is not currently enabled in the Service. No charge can be raised against you today. Sections 3.3, 3.4, 3.6, 3.7 and 3.8 take effect for your organization only from the date you are notified that billing is active and you select a paid plan. Nothing in this section applies to the Foundation plan, which is free whether or not billing is enabled.

3.6 Once billing is enabled, fees are billed in advance through Stripe and are non-refundable except as required by law.

3.7 Once billing is enabled, subscriptions auto-renew for the same period unless canceled before renewal. You can cancel at any time from Manage billing in your settings, which opens Stripe's customer portal. Cancelling takes effect at the end of the period you have already paid for, and your organization returns to Foundation rather than losing access.

3.8 We may change fees with at least 30 days' notice for existing subscriptions. A price change never applies to a period you have already paid for.

3.9 If payment fails and is not cured after notice, we may suspend the account. We will not delete your risk register, policies, or compliance data during a billing dispute; suspension is limited to report generation and new assessments.

3.10 Nothing is deleted because you stopped paying. Cancelling, downgrading, or failing to pay does not remove your risk register, published policies, compliance records, or uploaded evidence. What changes is what you can add or generate, not what you already have.


4.1 The Service does not provide legal advice, and using the Service does not create an attorney-client relationship. Draft policies, risk assessments, and compliance-framework gap analyses generated by the Service are informational tools based on general practices and the information you provide; they are not a substitute for review by a licensed attorney or a qualified compliance professional, particularly for decisions with legal or regulatory consequences.

4.2 The Service does not certify, attest to, or guarantee that your organization meets the requirements of any compliance framework. The Service currently tracks six frameworks: SOC 2, HIPAA, GDPR, CMMC, ISO 27001, and PCI-DSS. Formal certification or attestation, where applicable, must be obtained from an independent, accredited auditor. Virtosic's framework tracking is a preparation and gap-tracking tool, not a certifying authority.

4.3 You are solely responsible for reviewing, editing as necessary, and formally approving/publishing any AI-drafted policy before treating it as your organization's operative policy, and for the accuracy of any compliance status you represent to a third party (customer, regulator, auditor, or insurer) based on Service output.


5. Health Information and Regulated Data

5.1 If you are a "Covered Entity" or "Business Associate" as defined under HIPAA, or otherwise intend to submit Protected Health Information ("PHI") to the Service, you must first enter into a separate Business Associate Agreement ("BAA") with us before submitting any PHI. Submitting PHI without an executed BAA in place is a violation of these Terms. Contact [email protected] to request a BAA.

5.2 The Document Intelligence feature may process photographs, specification sheets, and other material you upload about your organization, its equipment, and its environment. You represent that you have the right to upload and process this material and that doing so does not violate any third party's rights or any applicable law.


6. Risk Acceptance

6.1 The Service allows you to formally "accept" a risk within the Risk Register, with a documented justification and, for Regulated-tier organizations, a required second approver. A risk acceptance recorded in the Service reflects your organization's own risk-management decision; it is not, and should not be represented as, Virtosic's endorsement or validation of that decision.


7. Human Advisor / Escalation Feature

7.1 If you designate a human advisor (whether your own personnel, a third-party fractional CISO, or an advisor located through any Virtosic partner directory), Virtosic is not a party to, and assumes no responsibility for, the advice given or services performed by that advisor, except where the advisor is a direct Virtosic employee acting in that capacity under a separate engagement.

7.2 If you use a partner directory to locate a third-party advisor, that engagement is between you and the advisor; Virtosic's role is limited to facilitating the introduction and platform access, unless otherwise stated in a separate agreement.


8. Customer Data

8.1 "Customer Data" includes your company profile, risk register, policies, compliance status, vendor information, and any documents or data you connect or upload.

8.2 You retain all right, title, and interest in Customer Data. You grant Virtosic a limited license to access, process, and analyze Customer Data solely to provide the Service, including through AI models as described in the Privacy Policy.

8.3 We do not sell Customer Data and do not use it to train models for the benefit of any party outside your organization.

8.4 If you ask us to export or delete your Customer Data, we will do so. A self-service export window and an automatic deletion schedule following termination are intended, but are not implemented in the Service today, so we make no commitment here to a specific number of days. See Section 6 of the Privacy Policy for what the Service does with your data today.


9. Acceptable Use

You will not: (a) use the Service to generate compliance representations you know to be false; (b) use the Service to build a competing product; (c) attempt to reverse-engineer the Service; (d) upload data you do not have the right to process (including PHI without an executed BAA, per Section 5); or (e) use the Service in violation of applicable law.


10. Intellectual Property

10.1 Virtosic retains all right, title, and interest in the Service, excluding Customer Data. Policy templates and framework-control mappings, prior to your customization, remain Virtosic's intellectual property; the customized, published version incorporating your organization's specific content is your Customer Data.

10.2 We grant you a limited, non-exclusive, non-transferable license to use the Service during your subscription term for your internal business purposes (or, for MSPs, on behalf of your managed clients as described in Section 16).


11. Warranties and Disclaimers

EXCEPT AS EXPRESSLY STATED, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTIES OF ANY KIND, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL IDENTIFY ALL RISKS, THAT ANY GENERATED POLICY OR COMPLIANCE ASSESSMENT IS LEGALLY SUFFICIENT FOR YOUR SPECIFIC CIRCUMSTANCES, OR THAT USE OF THE SERVICE WILL RESULT IN A SUCCESSFUL AUDIT OR CERTIFICATION OUTCOME.


12. Limitation of Liability

12.1 NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR LOSS OF PROFITS, REVENUE, DATA, OR GOODWILL, ARISING OUT OF THESE TERMS OR THE SERVICE, REGARDLESS OF THE THEORY OF LIABILITY.

12.2 EACH PARTY'S TOTAL AGGREGATE LIABILITY WILL NOT EXCEED THE TOTAL FEES PAID OR PAYABLE BY CUSTOMER TO VIRTOSIC IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM. Counsel has not yet settled which claims are carved out of this cap; this section is one of the provisions flagged for attorney review at the head of this document.

12.3 This allocation of risk reflects that Virtosic is a decision-support and preparation tool, not a guarantor of compliance, certification, or security outcomes, and is a fundamental basis of the bargain.


13. Indemnification

13.1 You will indemnify and hold harmless Virtosic from third-party claims arising out of: your breach of these Terms; unauthorized use of the Service; Customer Data (including any PHI submitted without an executed BAA); representations you make to third parties based on Service output; or your violation of law.

13.2 We will indemnify you against third-party claims that the Service, as provided and used in accordance with these Terms, infringes such party's U.S. intellectual property rights, subject to standard exclusions to be finalized by counsel.


14. Term and Termination

14.1 These Terms remain in effect while you maintain an active account. Either party may terminate for uncured material breach after 30 days' written notice. We may suspend or terminate immediately for violations of Section 5, 9, or applicable law.

14.2 Sections 8.4, 10, 11, 12, 13, and 15 survive termination.


15. Governing Law and Dispute Resolution

15.1 These Terms are governed by the laws of the State of Texas, without regard to conflict-of-laws principles.

15.2 The parties consent to the exclusive jurisdiction and venue of the state and federal courts located in Harris County, Texas, except as otherwise required by applicable law.

15.3 No arbitration agreement or class-action waiver applies. Whether to add either is a question for counsel, and this section is flagged for that review.


16. MSP Terms

16.1 If you are an MSP managing client organizations through the Service, you are responsible for: obtaining each client's consent to be onboarded to the Service; ensuring your access to each client's data is authorized; and your own contractual relationship and pricing with each client.

16.2 You will not represent to any client that Virtosic is a party to your engagement with that client, or that Virtosic guarantees any outcome of your services to that client.

16.3 Each client organization's data is isolated at the database level by PostgreSQL row-level security, which also governs the MSP hierarchy: your access as an MSP reaches only the client organizations you have been granted access to. See Section 9 of the Privacy Policy.


17. Miscellaneous

17.1 Force Majeure. Neither party is liable for delay or failure to perform due to causes beyond its reasonable control.

17.2 Assignment. You may not assign these Terms without our prior written consent, except in connection with a merger, acquisition, or sale of substantially all assets. We may assign these Terms in connection with a similar transaction.

17.3 Severability. If any provision is found unenforceable, the remaining provisions remain in full effect.

17.4 Entire Agreement. These Terms, together with the Privacy Policy, the Disclaimers, any Business Associate Agreement (if applicable), and any order form or master service agreement executed by the parties, constitute the entire agreement between the parties regarding the Service.

17.5 Changes to These Terms. We may update these Terms; material changes will be notified via the Service or by email at least 30 days before taking effect.

17.6 Notices. Legal notices to Virtosic should be sent to [email protected] and are effective on delivery. A postal address for service is available on request to the same address. Notices to you are effective when sent to the email address on your account, so keep it current.


Contact

Virtosic
Houston, Texas, United States
[email protected] · [email protected]
</content>
</invoke>