Phase 0 · Pre-launch. Commercial activity has not commenced.
SafeguardsMark ← Back to site

Terms of Service

Version 1.0 · Effective August 8, 2026


Effective Date: Phase-0 (pre-launch); commercial activity has not commenced.

These Terms of Service ("Terms") form a binding agreement between Ellis Intelligence LLC, a Colorado limited liability company doing business as SafeguardsMark ("SafeguardsMark", "we", "us"), and the customer subscribing to or using the Service ("Customer", "you").

The Service is for use by businesses — including auto dealerships, tax preparation firms, mortgage brokers, CPAs, and other small "financial institutions" under the Federal Trade Commission ("FTC") Safeguards Rule (16 CFR Part 314). The Service is not for use by consumers.


1. The Service

1.1 SafeguardsMark is a software-as-a-service application (the "Service") that helps businesses that are "financial institutions" under 16 CFR Part 314 (the FTC Safeguards Rule) document a Written Information Security Program (WISP) with the 9 elements required by §314.4(a)-(i). The Service guides the Customer through a 9-element WISP builder wizard, captures the Customer's risk assessment, service provider inventory, and incident response plan, and generates a SHA-256-sealed WISP PDF. The Service also includes a free FTC Safeguards Coverage Quiz (no account required), an annual assessment module, and a document vault for prior WISPs and risk assessments.

1.2 Tier-specific features and limits (including any request-volume or usage bands) are described at safeguardsmark.com/pricing. Tier names, and the figures behind them, live on that page and are never restated in these Terms. Tiers: Starter ($199/yr or $29/mo) · Standard ($249/yr or $36/mo) · Multi-Entity ($449/yr or $65/mo). Figures live at safeguardsmark.com/pricing and are never restated here.

1.3 Business Use Only. The Service is intended for use by businesses for business purposes.

1.4 SafeguardsMark Is Software, Not a Law Firm, Compliance Consultant, or FTC-Authorized Service. SafeguardsMark is a software vendor providing information security program documentation tooling. SafeguardsMark does NOT: - Constitute a law firm, compliance consultancy, or legal or professional advice service of any kind - Certify the Customer against any standard or regulatory requirement, including the FTC Safeguards Rule, 16 CFR Part 314, or any state data security laws and regulations - Conduct an independent audit of the Customer's information security practices, systems, or data handling - Conduct technical security testing, penetration testing, vulnerability scanning, or system scanning of any kind -- all inputs are self-reported by the Customer through the wizard - Provide a government-recognized compliance status or protect the Customer from FTC enforcement action - Guarantee that the generated WISP will satisfy the FTC's enforcement requirements in any specific case - Guarantee that the Customer is legally compliant with the FTC Safeguards Rule or any other law

The WISP is a documentation tool output generated from information the Customer declares through the wizard. See §6 for the full outputs-and-disclaimers language.

1.5 SafeguardsMark and the FTC Safeguards Rule. The FTC Safeguards Rule (16 CFR Part 314) is a regulation enforced by the Federal Trade Commission. Compliance with the Safeguards Rule is determined by the FTC based on the business's actual implementation of its information security program. Generating a WISP through SafeguardsMark does not constitute FTC compliance, does not constitute FTC registration, and does not create any government-recognized status.

1.6 No Affiliation, Endorsement, or Government Action. SafeguardsMark is not affiliated with, endorsed by, or sponsored by the FTC or the U.S. Government. SafeguardsMark does not predict, forecast, or represent how the FTC or any other regulator will assess, review, or act on any Customer's WISP or information security program, and SafeguardsMark does not act, and is not authorized to act, on behalf of the FTC or any other government agency in any capacity. Using SafeguardsMark does not create an FTC certification or any government-recognized status. The seal and all disclaimer language render as plain text/typography only -- no seal graphic, badge, ribbon, watermark, or certificate-style image anywhere, regardless of whether it references the FTC, so that the output never visually resembles a third-party validation mark.

2. Account

2.1 Account creation requires an authorized representative of the Customer entity.

2.2 Each seat is for a single named individual. Seat-sharing is prohibited. Team members are managed through the Settings -> Team flow under flat single-tenant membership.

3. Subscriptions, Pricing, Billing

3.1 Annual billing is the default and primary rate on all tiers; monthly billing is available at a higher anchor rate for Customers who prefer it.

3.2 Pricing at safeguardsmark.com/pricing. 30-day notice for material changes.

3.3 Billing via Stripe.

3.5 Refunds. Monthly fees are non-refundable for the current period except pro rata on our material breach or on discontinuation under §10.

3.6 No Service-Level Credits or Refunds. The Service carries no uptime or response-time commitment. No service credit, fee credit, refund, or other remedy arises from any delay, outage, missed response target, or unmet support expectation. The §12.1 limited-warranty remedy and the §10.2 pro-rata refund on our own discontinuation remain the only remedies.

4. Customer Data; Flat Multi-Tenancy -- each business is one tenant (Multi-Entity subscribers have up to three tenants)

4.1 Ownership. As between us, you own all Customer Data you submit ("Customer Data"), including your business name, business profile (Qualified Individual name and title, IR contact, business type), risk assessment inputs, service provider entries, and the WISPs the Service generates for you.

4.2 License to Us. You grant us a limited license to host, store, transmit, display, and process Customer Data solely to provide the Service (including generating your WISP, risk assessment output, and IR plan, running annual assessment reminders, and maintaining your document vault).

4.3 No Training / No Selling. We do not sell or share Customer Data, and we do not use it to train any model or to improve a Service used by other customers. See our Privacy Policy.

4.4 Flat Per-Tenant Isolation. Each business is one tenant (Multi-Entity subscribers have up to 3 tenants, one per entity). Single-level isolation is enforced: every tenant-scoped read and write routes through tenant-scoping helpers that raise if the scope is missing, so no tenant can access another tenant's data. There is no nested tenancy in v1.

5. Acceptable Use

5.1 No reverse engineering, no scraping, no building a competing product from the Service, no resale.

5.2 Accuracy of Declarations. Do not intentionally enter false or misleading information about your business's information security practices, Qualified Individual, service providers, or risk posture. A WISP generated from intentionally false inputs is a misrepresentation of your program; SafeguardsMark disclaims all liability for damages arising from the Customer's knowing misrepresentation. The Customer is solely responsible for the accuracy of the information declared in the Service.

5.3 No Misrepresentation of Certification or Compliance. You will not represent to any party (an FTC examiner, state regulator, auditor, insurer, or any other third party) that SafeguardsMark has certified, audited, or otherwise validated your compliance with the FTC Safeguards Rule or any other law, or that a WISP the Service generated constitutes FTC compliance, FTC registration, or any government-recognized status.

6. Service Outputs, WISP Scope, and Disclaimers

6.1 Documentation Tool, Not Legal Compliance. Every generated WISP includes, prominently in the document body, seal line, and footer, the following language (non-optional, hard-wired into the template):

"Written Information Security Program prepared by [Business Name] using SafeguardsMark, a documentation tool built on 16 CFR Part 314 (FTC Safeguards Rule). SafeguardsMark does not provide legal advice and does not guarantee your program will satisfy FTC enforcement requirements. You remain responsible for implementing the controls documented herein and for compliance with the FTC Safeguards Rule. Consult qualified legal or compliance counsel for your specific situation. Generated [date]. SHA-256: [hash]."

This language cannot be removed, modified, or watered down in any WISP the Service generates. The seal and this disclaimer language are rendered as plain text/typography only, on the document face and on every customer-facing surface -- no seal graphic, badge, ribbon, watermark, or certificate-style image is used anywhere, regardless of whether it references the FTC or any other body, so that the output never visually resembles a third-party validation mark.

6.2 Self-Reported Inputs Only. Every element of the generated WISP reflects information the Customer declared in the wizard and modules. SafeguardsMark does not invent, supplement, or improve upon declared inputs. The WISP's accuracy as a description of the Customer's information security program depends entirely on the accuracy of the Customer's inputs.

6.3 WISP Generation Gate. The Service enforces a hard generation gate: the WISP PDF cannot be generated until all 9 program elements (§314.4(a)-(i)) have status complete or not_applicable (with a documented reason for not_applicable status). The Customer's Qualified Individual name and title must be non-null. This gate is a hard engineering control -- it cannot be bypassed. A partial WISP (fewer than 9 complete elements) is not generated; a partial WISP implies a compliance posture the business has not implemented.

6.4 No Guarantee of FTC Compliance or Enforcement Protection. SafeguardsMark does not guarantee that any generated WISP will satisfy the FTC's enforcement requirements in any specific enforcement action, FTC examination, or regulatory proceeding. Compliance with the FTC Safeguards Rule depends on the Customer's actual implementation of the controls documented in the WISP, the Customer's ongoing program maintenance, and the FTC's enforcement posture -- none of which SafeguardsMark controls.

6.5 IR Plan -- Two Required Notification Provisions. The Service hard-wires both required incident response notification provisions (30-day customer notification and 30-day FTC notification per the 2023 Safeguards Rule amendments) into the generated WISP's incident response plan section (§314.4(f)). These provisions cannot be removed by the Customer. The Customer remains responsible for actually implementing the notification process in the event of a security incident.

6.6 Annual Assessment. The Service provides an annual assessment module and generates annual review reminders. The Customer is responsible for actually running the annual assessment and updating their WISP as required by §314.4(e) and (g). SafeguardsMark's reminder is a notification tool -- it does not perform the assessment on the Customer's behalf.

6.7 No Autonomous Notification or Distribution. SafeguardsMark itself does not send a customer notification or an FTC notification on your behalf in the event of a security incident, and does not transmit a WISP or any other Service output to the FTC, a regulator, or any third party on your behalf. Because a human -- you -- always takes the actual notification and distribution action, this sits in the standard disclaimer-plus-no-auto-action tier, not the stricter tier reserved for brands whose own output reaches a regulator or external party directly.

7. Immutable WISPs; Versioning

7.1 A WISP is immutable once issued. No modification path exists for an issued WISP; a new WISP may be generated (as a new version with a superseded link to the prior), but the prior WISP is not modified or deleted.

7.2 WISP versioning is displayed in the document vault. The SHA-256 hash is computed over the canonical content of the WISP at generation time; any post-issuance modification of the WISP PDF would produce a hash mismatch detectable by any third party.

8. Intellectual Property

8.1 Service IP. We own the Service and its contents, including the WISP Builder engine, the risk assessment module, the IR plan generator, and the SafeguardsMark platform. No rights are granted except as expressly set forth.

8.2 Feedback. Standard perpetual-license grant on feedback.

8.3 Customer References. We may identify you as a customer (name, logo) on the customers page unless you opt out.

8.4 IP & Assignment Rider. An IP & Assignment Rider addressing ownership and assignment of intellectual property is incorporated by reference into these Terms and controls over this §8 and over §15.4 on the subjects within its scope.

8.5 Present assignment of Derivative IP. To the extent any Derivative IP would otherwise vest in Customer — by operation of law, under any work-made-for-hire or commissioned-work doctrine, because Customer's use, Inputs, or Feedback contributed to it, or on any other basis — Customer hereby irrevocably and presently assigns to Company all right, title, and interest in and to that Derivative IP, effective automatically upon its creation and without further action or consideration.

9. Privacy and Data Processing

9.1 Privacy Policy at safeguardsmark.com/privacy. We are the controller for marketing-site visitors and Customer account/billing contacts, and the processor for the compliance data you place under your tenant. Where the Data Processing Addendum and these Terms conflict as to the processing of Customer Data, the DPA controls; this Privacy Policy is a notice, not a contracting instrument.

10. Suspension and Termination

10.1 By You. Cancel anytime; effective at the end of the paid monthly period. 10.2 By Us. Material breach, violation of §5 (Acceptable Use), or non-payment. 30 days' notice with pro rata refund for any discontinuation we initiate, paid within 30 days after the effective date of termination. 10.3 Effect. Customer Data deleted within 30 days of termination unless retention is required by law or export is requested. 10.4 Survival. Sections 4 (data), 6 (outputs/disclaimers), 8 (IP), 11 (Confidentiality), 12 (Warranties), 13 (Liability), 14 (Indemnification), 15 (General) survive.

11. Confidentiality

Treat all Customer Data as confidential information; standard confidentiality commitments; 5-year survival; trade-secret indefinite.

12. Warranties and Disclaimers

12.1 Limited Warranty. The Service performs substantially per documentation. Exclusive remedy: repair or pro rata refund.

12.2 Disclaimer. EXCEPT AS EXPRESSLY SET FORTH IN §12.1, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE." WE DISCLAIM ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, ACCURACY, COMPLETENESS, AND NON-INFRINGEMENT. WE MAKE NO WARRANTY THAT THE SERVICE WILL BE UNINTERRUPTED OR ERROR-FREE.

12.3 No Warranty of FTC Compliance or Enforcement Outcome. WE DO NOT WARRANT THAT ANY GENERATED WISP WILL SATISFY FTC ENFORCEMENT REQUIREMENTS, WILL CONSTITUTE A LEGAL DEFENSE AGAINST ANY CLAIM, OR WILL SATISFY ANY OTHER LEGAL OR REGULATORY OBLIGATION.

13. Limitation of Liability

13.1 TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, OR PUNITIVE DAMAGES, INCLUDING LOST PROFITS, LOST REVENUE, LOST DATA, OR ANY DAMAGES ARISING FROM A FAILED CONTRACT, DISQUALIFIED BID, REGULATORY ACTION, OR FCA PROCEEDING, EVEN IF ADVISED.

13.2 OUR TOTAL CUMULATIVE LIABILITY ARISING FROM OR RELATED TO THESE TERMS OR THE SERVICE WILL NOT EXCEED THE FEES YOU PAID US IN THE TWELVE MONTHS PRECEDING THE CLAIM.

13.3 No Liability for Regulatory or Enforcement Outcomes. WE SHALL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING ANY FINDING, INQUIRY, INVESTIGATION, OR ENFORCEMENT ACTION BY ANY REGULATORY, ADMINISTRATIVE, OR ENFORCEMENT BODY OF ANY KIND -- INCLUDING WITHOUT LIMITATION THE FTC -- ARISING FROM ANY GENERATED WISP OR OTHER SERVICE OUTPUT. This cap does not apply to either party's indemnification obligations under §14. This carve-out is stated as broadly as possible and applies uniformly regardless of the specific statute, regulation, or regulatory or enforcement body involved; a party asserting that this carve-out does not apply to a particular claim, statute, or regulatory or enforcement body bears the burden of establishing that, rather than us bearing the burden of having disclaimed each one individually.

14. Indemnification

14.1 Stated in the contract you execute. Both indemnities -- ours for IP infringement and yours -- are stated in full on the face of §6 of the SafeguardsMark Engagement & Tiers SOW ("6. Indemnification -- the executed-instrument provision"), together with the claim procedure. That §6 is the indemnification block carried on the face of the click-signed Order Form you accept, rendered above the agree control. Those provisions govern; this §14 is a cross-reference and does not restate them.

14.2 No separate indemnity. These Terms state no indemnification obligation separate from, additional to, or narrower than SOW §6, and nothing in these Terms enlarges or limits it. Where these Terms refer to the §14 indemnity (§10.4 survival), the reference is to SOW §6.

15. General Provisions

15.1 Governing Law. Colorado. The United Nations Convention on Contracts for the International Sale of Goods ("CISG") does not apply. 15.2 Disputes. Binding arbitration via JAMS in Boulder County, CO. Each party waives any right to a jury trial and to participation in any class, collective, or representative proceeding. Either party may seek injunctive relief in court for §5, §6, §8, or §11 breaches. 15.3 Notices, Force Majeure, Entire Agreement, Modifications (30-day), Severability, No Waiver, Independent Contractors. Standard. Written notice under these Terms (email to the billing contact or in-product notice) is deemed given when sent or first displayed; any notice period runs from that date, and failure to read a notice does not extend it. 15.4 Assignment; Change of Control. You may not assign, delegate, or transfer these Terms, in whole or in part, whether by operation of law, merger, or change of control, without our prior written consent; any attempted assignment in violation of this sentence is void. We may, without your consent and without notice except as any applicable data-protection law requires, assign or transfer these Terms and all of our rights and obligations under them, in whole or in part, (a) to a successor or acquirer in connection with a merger, acquisition, or sale of substantially all of our business or assets, or (b) to an affiliate, subsidiary, or newly formed entity in connection with a corporate conversion, reorganization, or contribution or drop-down of assets undertaken to effect a sale, reorganization, or transfer of the specific business line or product to which these Terms relate. Upon such an assignment, all of our rights under these Terms pass to the assignee, the assignee assumes our obligations arising after the assignment, and your continued use of the Service constitutes acknowledgment of the assignee as "SafeguardsMark" going forward. A change in our ownership, control, equity holders, or entity form is not a breach of, default under, or ground to terminate, suspend, renegotiate, or re-price these Terms, and does not trigger any right of termination, consent, first refusal, most-favored-nation, audit, or refund on your part. This §15.4 controls over any contrary term in a Customer purchase order or procurement addendum.

15.5 Regional and Supplemental Terms. No jurisdiction-specific supplemental term applies today. Where a supplemental jurisdiction-specific term applies, it controls over a conflicting general term of these Terms for that jurisdiction only.


16. Updates

30 days' email notice to the Customer billing contact for material changes. Notice is deemed given when sent; the 30-day period runs from the send date, and failure to read a notice does not extend it. Continued use after the effective date constitutes acceptance.

Contact

SafeguardsMark — Ellis Intelligence LLC Email: legal@ellisintel.com Address: 1500 N Grant St, Ste N, Denver, CO 80203, USA


SafeguardsMark is a product of Ellis Intelligence LLC. SafeguardsMark is software, not a law firm, compliance consultant, or FTC-authorized certifier; this is general information, not legal, compliance, or professional advice. See also our Privacy Policy. Questions about this document? Email legal@ellisintel.com.