KoComplyAgentic Compliance
Back to KoComply
Legal

Terms of Service

These terms govern your use of KoComply's agentic compliance platform, including AI agents, integrations, reports and connected workflows.

Effective and last updated: 6 October 2026

01

Agreement and eligibility

These Terms of Service ("Terms") are a binding agreement between Kocomply Technologies ("KoComply", "we", "us" or "our") and the person or organisation using KoComply ("Customer" or "you"). They govern our websites, hosted platform, AI agents, integrations, reports, support and related services (collectively, the "Service").

By creating an account, accepting an order form, connecting an integration or using the Service, you accept these Terms. If you use KoComply for an organisation, you represent that you have authority to bind it. You must be at least 18 and legally capable of contracting. An order form, data processing addendum or other signed agreement controls if it expressly conflicts with these Terms.

02

The Service and changes

KoComply is an agentic compliance platform that helps teams organise and review controls, policies, evidence, risks, vendors, questionnaires, reports, readiness activities and audit workflows. Features, framework mappings, connectors and outputs may evolve. We may improve, replace or discontinue features, but will not materially reduce a paid Service during its committed term without reasonable notice or a suitable alternative, except where required for security, law or third-party availability.

Beta, preview, free and evaluation features may be changed or withdrawn at any time and are provided without service commitments.

03

Accounts and administrators

You must provide accurate information, keep credentials confidential, use multi-factor authentication where available and promptly remove users who no longer need access. Workspace administrators may invite or remove users, configure integrations, view activity and Customer Data, and make decisions for the organisation. You are responsible for your users, account activity and the security of devices and identity systems used to access KoComply. Notify us promptly at shanti@kocomply.com if you suspect compromise.

04

AI agents, outputs and human approval

The Service may use artificial intelligence to analyse context and evidence and draft compliance materials. Outputs may be incomplete, outdated or incorrect and may vary for similar inputs. They are suggestions, not legal, accounting, security, certification or audit opinions.

You must independently review and approve outputs before implementing, publishing or submitting them. You remain responsible for business decisions, control operation, regulatory compliance and the accuracy of representations made to auditors, customers, employees or authorities. KoComply does not autonomously bind you, file with regulators, certify your organisation or guarantee that an auditor will accept an output.

05

Integrations and connected systems

You may authorise KoComply to access third-party cloud, code, identity, workforce, device, ticketing, communication, customer-management and other systems. You represent that you have all rights and permissions needed to connect them and instruct us to process the resulting data. You must use least-privilege permissions, protect secrets and monitor connection scope.

KoComply may read, import and periodically refresh authorised metadata, configuration, evidence, users, assets, findings and other data. Unless a feature and consent screen expressly say otherwise, agents are review-first and do not make unapproved changes in connected systems. You may revoke a connector, but previously imported evidence and audit records may remain subject to retention obligations.

Third-party products are controlled by their providers. We are not responsible for their availability, changes, data practices or acts. API limits, provider outages, changed permissions or revoked credentials may interrupt an integration.

06

MCP and external AI clients

KoComply may expose tools through a protected Model Context Protocol endpoint. When you approve an external AI client, you authorise it to invoke the displayed KoComply tools within the approved account scope. You are responsible for the client you select, its instructions and its handling of results. Do not approve a client you do not trust. You may disconnect access, and we may restrict MCP use that risks security, privacy, platform integrity or excessive load.

07

Customer Data and permissions

You retain ownership of Customer Data. You grant KoComply and its subprocessors a worldwide, non-exclusive licence to host, copy, process, transmit, display and create technical derivatives of Customer Data only as needed to provide, secure, support and improve the Service and meet legal obligations.

You represent that Customer Data and your instructions comply with law and do not infringe another person's rights. You are responsible for notices, consents, legal bases, data accuracy, retention decisions and responding to individuals. We may use aggregated or de-identified information that does not identify you or any person to operate, secure, analyse and improve KoComply.

08

Acceptable use

You must not use the Service to:

  • break the law, violate rights, mislead an auditor or falsely claim certification or control operation;
  • upload malware, unlawfully obtained data, payment-card credentials, authentication secrets, or sensitive data unnecessary for the agreed service;
  • probe, disrupt, overload or bypass security, access controls, rate limits or account boundaries;
  • reverse engineer or copy the Service except where law cannot prohibit it;
  • use automated means to scrape the Service, build a competing product or train a model without written permission;
  • share access outside the authorised organisation or resell the Service unless agreed in writing; or
  • use outputs to make solely automated decisions with legal or similarly significant effects on individuals.

We may investigate violations and suspend affected access where reasonably necessary.

09

Confidentiality

Each party may receive non-public information identified as confidential or that reasonably should be understood as confidential. The receiving party will use it only to perform the agreement, protect it with reasonable care and disclose it only to personnel and providers who need it and owe confidentiality duties. These obligations do not cover information lawfully public, already known without restriction, independently developed or rightfully received from another source. Legally compelled disclosure is permitted after notice where lawful.

10

Privacy and security responsibilities

Our Privacy Policy explains our data practices. Where KoComply processes personal data for a Customer, an applicable data processing addendum may govern that processing. Each party will maintain reasonable safeguards appropriate to its responsibilities.

You are responsible for configuring access, integrations, sharing links, approvals and retention appropriately. Shareable reports and trust-centre materials may be accessible to recipients you select; gated access reduces but does not eliminate onward-disclosure risk.

11

Fees, subscriptions and taxes

Paid plans, included frameworks, usage limits, implementation work, audit support, term and payment schedule are stated in the checkout or order form. Unless stated otherwise, fees are non-cancellable and non-refundable, due in the stated currency and exclusive of applicable taxes. You are responsible for taxes other than taxes on our income.

Subscriptions renew for the period shown at purchase unless cancelled before renewal. We may change renewal pricing with reasonable advance notice. Overdue undisputed amounts may result in interest where lawful, collection costs or suspension after notice. Staged payment arrangements do not change the total committed fee unless agreed in writing.

12

Free access, trials and feature gates

Free or unpaid access may provide a limited readiness assessment, roadmap, view-only information or limited agent activity. Other features may remain disabled until payment or plan activation. Limits may include frameworks, integrations, users, evidence, exports, reports, support and agent actions. We may change free-plan limits or end a trial on notice. Data entered during free access remains subject to these Terms.

13

Auditors and professional partners

Independent auditors, certification bodies and other partners are separate organisations. Unless an order form expressly states otherwise, KoComply does not control their professional judgment, schedule, fees or decision. You authorise any information shared with a selected partner and remain responsible for verifying its scope and engagement terms. Readiness status does not guarantee certification, attestation, a clean report or completion by a particular date.

14

Intellectual property and feedback

KoComply and its licensors own the Service, software, interfaces, workflows, models, documentation, framework mappings and underlying technology. Subject to payment and these Terms, we grant you a limited, non-exclusive, non-transferable right to use the Service during the subscription term for your internal business purposes.

As between the parties, you may use outputs generated specifically from your Customer Data, subject to third-party rights and law. We retain our underlying technology, general know-how and reusable materials. If you provide feedback, you grant us a perpetual, worldwide right to use it without restriction or payment.

15

Disclaimers

To the maximum extent permitted by law, the Service, AI outputs, beta features and third-party integrations are provided "as is" and "as available". We disclaim implied warranties of merchantability, fitness for a particular purpose, title and non-infringement. We do not warrant uninterrupted or error-free operation, complete vulnerability detection, accurate regulatory interpretation, successful audit outcomes, certification, or that the Service alone will satisfy your legal or contractual duties. Nothing in the Service is legal advice.

16

Indemnity

You will defend and indemnify KoComply and its personnel against third-party claims, damages and reasonable costs arising from your unlawful Customer Data, your violation of these Terms, your misuse of the Service, or your representations based on unreviewed or altered outputs. We will promptly notify you and reasonably cooperate; you may not settle a claim in a way that admits our fault or imposes obligations on us without consent. This clause applies only to the extent permitted by law and may be modified by an order form.

17

Limitation of liability

To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, exemplary, punitive or consequential damages, or loss of profits, revenue, goodwill or data, even if advised of the possibility. KoComply's total liability arising from the Service will not exceed the fees paid or payable by Customer to KoComply for the affected Service during the 12 months before the event giving rise to liability.

These limits do not exclude liability that cannot legally be limited, and do not limit your payment obligations, misuse of our intellectual property, breach of acceptable use, or indemnity obligations. Some jurisdictions may not allow certain exclusions, in which case they apply only to the lawful extent.

18

Suspension, termination and data export

Either party may terminate for a material breach not cured within 30 days after written notice, or immediately if the breach cannot be cured. We may suspend access sooner where necessary to address a security threat, unlawful use, non-payment, risk to other customers or a third-party service restriction, and will use reasonable efforts to limit scope and restore access.

On termination, access ends and unpaid committed fees become due. Upon request made before termination or within 30 days after it, we will provide a reasonable opportunity to export available Customer Data using supported features, unless prohibited by law or suspension was for serious abuse. We may then delete Customer Data under our retention practices. Provisions intended by nature to survive will survive.

19

Governing law and disputes

These Terms are governed by the laws of India, without regard to conflict-of-law rules. The courts located in Mumbai, Maharashtra will have exclusive jurisdiction over disputes, and each party consents to those courts. Before filing a claim, the parties will attempt in good faith for 30 days to resolve it through written notice and business discussion. Either party may seek urgent injunctive relief to protect confidential information, security or intellectual property.

20

General terms

You may not assign these Terms without our consent, except in connection with a merger or sale of substantially all relevant assets; we may assign them as part of a reorganisation or sale. Neither party is liable for delay caused by events beyond reasonable control. The parties are independent contractors, and these Terms create no partnership, agency or third-party beneficiary. If a provision is unenforceable, it will be limited to the minimum extent necessary and the remainder stays effective. Failure to enforce is not a waiver. These Terms and incorporated documents are the entire agreement about the Service. Notices to KoComply must be sent to shanti@kocomply.com; we may notify you through the Service or the account email.

21

Changes to these Terms

We may update these Terms to reflect changes in the Service, integrations, risk or law. We will post the revised Terms and update the date above. For material changes affecting an active paid subscription, we will provide reasonable advance notice. Continued use after the effective date constitutes acceptance; if you object to a material change, you may stop using the Service and exercise any termination right available under your order form.