Terms of Service

Policy approved: 2026
  1. Acceptance of Terms

These Terms of Service (“Terms”) govern your access to and use of the soc2audit.ai platform, marketing website at soc2audit.ai, and any related services (collectively, the “Service”) provided by Managed Security Services, LLC dba Cyber Security Services, an Ohio limited liability company (“Cyber Security Services,” “we,” “us,” or “our”).

By creating an account, accessing, or using the Service, you agree to be bound by these Terms and by our Privacy Policy at soc2audit.ai/privacy-policy. If you are entering into these Terms on behalf of a company or other legal entity, you represent that you have authority to bind that entity, and “you” and “your” refer to that entity.

If you do not agree to these Terms, you may not use the Service.

  1. The Service

soc2audit.ai is an AI-guided compliance platform that helps customers prepare for and manage SOC 2 attestation engagements. Features include AI-guided gap assessments, policy generation, user access reviews, vendor risk reviews, evidence collection, and an auditor portal for AICPA-licensed CPA firms.

2.1 What the Service is not

  • The Service is not an audit or attestation. SOC 2 reports are issued only by independent AICPA-licensed CPA firms operating under AT-C 105 and AT-C 205. Cyber Security Services does not perform SOC 2 audits.
  • The Service does not guarantee a passing audit. The Service prepares you for an audit; the outcome depends on your controls, your evidence, and the professional judgment of your auditor.
  • The Service is not legal advice. Nothing in the Service constitutes legal, accounting, or compliance advice specific to your circumstances.

2.2 AICPA partner audits

If you engage an AICPA-licensed CPA firm through our partner network, your audit contract is between you and that firm — not with Cyber Security Services. The audit firm is solely responsible for the conduct and outcome of the audit and for maintaining independence under AICPA standards.

2.3 Optional add-on services

Optional services (penetration testing, vulnerability management, virtual CISO) are delivered by Cyber Security Services under separate statement-of-work agreements. Add-on services are never required to use soc2audit.ai.

  1. Accounts

3.1 Registration

To use the Service you must create an account. You agree to provide accurate information, keep it updated, and safeguard your credentials.

3.2 Authorized users

You may permit employees, contractors, and your designated auditors to access the Service under your account. You are responsible for their compliance with these Terms.

3.3 Account security

You must notify us immediately at security@soc2audit.ai of any unauthorized access to your account. We may require multi-factor authentication for all users.

  1. Customer content and license

4.1 Ownership

You retain all rights, title, and interest in the content you upload to the Service (“Customer Content”), including policies, evidence, user lists, vendor lists, and gap assessment responses.

4.2 License to us

You grant Cyber Security Services a limited, worldwide, non-exclusive, royalty-free license to host, copy, process, transmit, and display Customer Content solely to (a) provide the Service to you, (b) enable your designated auditor to review your Service data, (c) improve the Service in aggregated and de-identified form, and (d) comply with legal obligations.

4.3 AI processing

You acknowledge that the Service uses AI models — including third-party large language model APIs — to process Customer Content. We do not use Customer Content to train foundation models. See our Privacy Policy Section 6 for details.

4.4 Your responsibilities for Customer Content

You represent that you have all rights necessary to upload Customer Content and that Customer Content does not violate any law, third-party right, or these Terms.

  1. Fees, subscriptions, and billing

5.1 Subscription fees

Access to the Service requires a paid subscription. Current pricing is published at soc2audit.ai/pricing. Fees are billed in advance on a monthly or annual basis depending on the plan selected.

5.2 Automatic renewal

Subscriptions automatically renew at the end of each term unless canceled before the renewal date. You can cancel from your account settings or by emailing billing@soc2audit.ai.

5.3 Price changes

We may change subscription fees. Any fee change will take effect at the start of your next billing period after we notify you (at least 30 days’ notice for material increases).

5.4 Audit fees and add-on fees are separate

Fees paid to AICPA-licensed CPA firms for the audit itself, and fees for optional add-on services from Cyber Security Services, are separate from soc2audit.ai subscription fees and are billed separately by those parties.

5.5 Refunds

Except where required by law, subscription fees are non-refundable. If you cancel mid-term, you may continue using the Service through the end of the paid term.

5.6 Taxes

Fees are exclusive of taxes. You are responsible for all applicable taxes other than taxes based on our net income.

5.7 Late payment

If payment is more than 15 days past due, we may suspend the Service. If more than 60 days past due, we may terminate your account and pursue collection.

  1. Acceptable use

You will not:

  • Use the Service to violate any law or third-party right
  • Attempt to gain unauthorized access to the Service, other accounts, or our systems
  • Reverse engineer, decompile, or attempt to derive the source code of the Service, except to the extent applicable law prohibits this restriction
  • Introduce malware, viruses, or other harmful code into the Service
  • Use automated means to access the Service in a way that degrades performance for other customers
  • Resell, rent, or sublicense access to the Service without our written consent
  • Use the Service to develop a competing product
  • Misrepresent your affiliation with any person or entity, including impersonating an auditor
  • Upload Customer Content that infringes intellectual property rights or contains sensitive categories of personal data (health, financial account credentials, government IDs) beyond what is necessary for a SOC 2 program

We reserve the right to suspend accounts that violate this section pending investigation.

  1. Auditor access and independence

Our Service allows you to grant access to your designated AICPA-licensed CPA audit firm. You acknowledge:

  • The audit firm operates independently under AICPA standards
  • Cyber Security Services does not direct, influence, or participate in the audit firm’s judgment
  • Auditor access is scoped, read-only where appropriate, and logged
  • Independence between soc2audit.ai (preparer) and the audit firm (attestor) is a core commitment of the Service

If you have reason to believe auditor independence has been compromised, report it immediately to independence@soc2audit.ai.

  1. Warranties and disclaimers

8.1 Our warranty

We warrant that we will provide the Service in a professional and workmanlike manner consistent with generally accepted industry standards. If we materially fail to meet this warranty, your exclusive remedy is repair of the Service or, if we cannot repair it within a reasonable time, termination and a pro-rata refund of prepaid fees for the affected period.

8.2 Disclaimer

EXCEPT FOR THE WARRANTY IN SECTION 8.1, THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE DISCLAIM ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.

WE DO NOT WARRANT THAT (A) THE SERVICE WILL BE UNINTERRUPTED OR ERROR-FREE, (B) AI-GENERATED OUTPUTS WILL BE COMPLETE OR ACCURATE, OR (C) USE OF THE SERVICE WILL RESULT IN A PASSING SOC 2 REPORT.

  1. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW:

9.1 Excluded damages

NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, LOST REVENUE, LOST DATA, OR BUSINESS INTERRUPTION, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

9.2 Cap on liability

EACH PARTY’S TOTAL AGGREGATE LIABILITY UNDER THESE TERMS WILL NOT EXCEED THE AMOUNT PAID BY YOU TO US IN THE 12 MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM.

9.3 Exceptions

The exclusions and caps in this Section 9 do not apply to (a) your payment obligations, (b) either party’s indemnification obligations under Section 11, (c) either party’s breach of confidentiality, or (d) liability that cannot be limited under applicable law.

  1. Confidentiality

Each party may disclose confidential information to the other in connection with the Service. The receiving party will (a) use the same care to protect confidential information as it uses for its own, but not less than reasonable care, (b) use it only to perform under these Terms, and (c) not disclose it to third parties except to employees, subprocessors, and advisors bound by similar obligations. Confidential information does not include information that is publicly known, independently developed, or lawfully received from a third party without confidentiality obligations.

Customer Content is your confidential information. Our proprietary software, pricing, and product roadmap are our confidential information.

  1. Indemnification

11.1 By us

We will defend you against any third-party claim alleging that your authorized use of the Service infringes a valid U.S. patent, copyright, or trademark, and will pay damages finally awarded (or settlement amounts we agree to), provided you (a) notify us promptly, (b) give us sole control of the defense, and (c) reasonably cooperate.

If use of the Service is enjoined, we may (i) obtain the right for you to continue using it, (ii) modify it to be non-infringing, or (iii) terminate the affected portion and refund prepaid fees.

We have no obligation for claims arising from (a) Customer Content, (b) your use of the Service in violation of these Terms, or (c) combination of the Service with third-party products we did not provide.

11.2 By you

You will defend Cyber Security Services against any third-party claim arising from (a) Customer Content, (b) your violation of these Terms, or (c) your violation of law, and will pay damages finally awarded or settlement amounts we agree to.

  1. Term and termination

12.1 Term

These Terms apply for as long as you have an active subscription.

12.2 Termination for convenience

Either party may cancel a subscription at any time via account settings or written notice. Cancellation takes effect at the end of the current paid term.

12.3 Termination for cause

Either party may terminate immediately for material breach if the other party fails to cure within 30 days of written notice. We may suspend or terminate immediately for security threats, non-payment beyond 60 days, or violations of Section 6 (Acceptable Use).

12.4 Effect of termination

Upon termination:

  • Your access to the Service ends
  • Prepaid fees are non-refundable except as provided in Section 8.1
  • You may export Customer Content for 30 days after termination
  • We will delete Customer Content within 90 days after termination, except where longer retention is required by law

12.5 Surviving sections

Sections 4 (to the extent of remaining licenses), 5.4–5.6, 8.2, 9, 10, 11, 13, 14, and 16 survive termination.

  1. Governing law and disputes

13.1 Governing law

These Terms are governed by the laws of the State of Ohio, without regard to conflict-of-laws principles. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

13.2 Venue

Any dispute not resolved through the process below will be brought exclusively in the state or federal courts located in Delaware County, Ohio, and both parties consent to the personal jurisdiction of those courts.

13.3 Informal resolution first

Before filing suit, the parties will attempt to resolve any dispute in good faith by meeting (in person or by video) within 30 days of written notice describing the dispute.

13.4 Class action waiver

Each party agrees to bring disputes only in an individual capacity, and not as a plaintiff or class member in any purported class or representative proceeding.

  1. Modifications to the Terms

We may update these Terms from time to time. If we make material changes, we will notify you by email or in-app notification at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance. If you do not agree to the changes, you may cancel your subscription before the effective date.

  1. Publicity

Unless you opt out in writing, you agree that we may identify you as a customer and display your name and logo on our marketing materials in a manner consistent with your brand guidelines. You may opt out by emailing marketing@soc2audit.ai.

  1. General
  • Entire agreement. These Terms, the Privacy Policy, and any order form or SOW constitute the entire agreement between the parties.
  • You may not assign these Terms without our written consent, except to a successor in a merger, acquisition, or sale of substantially all assets. We may assign these Terms to an affiliate or successor.
  • Force majeure. Neither party is liable for delays or failures caused by events outside their reasonable control.
  • We may give you notices via email, in-app message, or by posting on soc2audit.ai. You may give us notice at legal@soc2audit.ai.
  • Independent contractors. The parties are independent contractors. Nothing in these Terms creates a partnership, joint venture, or agency relationship.
  • No waiver. Failure to enforce any provision is not a waiver of that provision.
  • If any provision is held unenforceable, the remaining provisions remain in effect.
  • Export controls. You will comply with all applicable export laws.
  1. Contact

Managed Security Services, LLC dba Cyber Security Services

Attn: Legal

Westerville, Ohio, United States

Email: legal@soc2audit.ai