Legal
Terms and Conditions
The agreement between your organization and Vigile AI, Inc. for the Vigile AI Enterprise platform. It covers what the Service does, what we do with the data your Microsoft environment makes available, what we expect of each other, and what happens when the subscription ends.
Effective 7 October 2026. Last updated 7 October 2026.
1. Agreement to these terms
These Terms and Conditions (the Terms) govern your access to and use of the Vigile AI Enterprise platform, any related application programming interfaces, exports, notifications and documentation, and any professional services we provide in connection with them (together, the Service). The Service is provided by Vigile AI, Inc. (Vigile AI, we, us or our).
By creating an account, connecting a Microsoft environment, or otherwise using the Service, you confirm that you have read and accept these Terms. If you are accepting on behalf of an organization, you confirm that you are authorized to bind that organization, and organization in these Terms means the entity on whose behalf you accept. If you do not accept these Terms, do not use the Service.
Where we have signed a separate written agreement, order form, or data processing addendum with your organization, that document controls to the extent of any conflict with these Terms.
2. The Service
The Service is an organization-wide security posture platform for Microsoft 365 and Microsoft Entra ID. It reads configuration, identity, sign-in and file metadata from the Microsoft environment you connect, identifies areas of risk and exposure, and presents findings, cases, reports and notifications so your team can act on them.
The Service depends on the licence tier of your Microsoft environment. Capabilities that your tier does not include are presented as labelled, unavailable panels that explain what unlocks them. They are not silently omitted, and they are not a defect in the Service.
We may improve, extend or adjust the Service over time. We will not materially reduce the core functionality of the Service during a paid subscription term without notice.
3. Accounts, access and administrator responsibilities
Access to the Service is controlled through the organization that connects the Microsoft environment. Organization owners and administrators are responsible for:
- Deciding who inside their organization is granted access, and at which role.
- Keeping membership and roles current, including removing access for people who leave.
- Maintaining the confidentiality of credentials, and enabling multi-factor authentication where available.
- Ensuring they have the authority to connect the Microsoft environment they connect, and to request the data the Service reads.
You are responsible for activity carried out under your organization's account. Tell us promptly at the contact address in section 17 if you become aware of unauthorized access.
4. Customer data and connected environments
As between you and us, your organization owns the data that originates in its Microsoft environment (Customer Data). We process Customer Data only to provide and support the Service, to secure it, and to comply with law. Our processing of personal data is described in our Privacy Policy, which forms part of these Terms.
The Service connects to Microsoft through a read-only integration. It does not write to, modify, delete or move data in your Microsoft environment, and it does not send mail or make configuration changes on your behalf.
Detection works on file contents in memory. Contents are not stored and are not displayed in the Service. What you see is the finding category, the count and a confidence indicator, not the underlying data. Private files are excluded from content detection by default unless an administrator deliberately extends the scan policy to include them.
Only an organization owner can connect or disconnect the Microsoft integration. The connection can be revoked at any time from your Microsoft admin portal, and revocation stops all further collection.
5. Acceptable use
You agree not to do, or permit anyone to do, any of the following:
- Use the Service to access data you are not lawfully entitled to access, or to monitor people without a lawful basis.
- Reverse engineer, decompile, disassemble or attempt to derive the source code of the Service, except where that restriction is prohibited by law.
- Resell, sublicense, or provide the Service to a third party as a service bureau without our written consent.
- Interfere with, overload, or attempt to gain unauthorized access to the Service, its infrastructure, or another customer's environment.
- Introduce malware, or use the Service to conduct offensive security testing against systems you are not authorized to test.
- Circumvent licence-tier checks, usage limits, or access controls.
We may suspend access where we reasonably believe use of the Service presents a security risk, breaches these Terms, or is unlawful. Where practicable, we will tell you first and limit the suspension to what is necessary.
6. Third party services and Microsoft licensing
The Service integrates with Microsoft 365 and Microsoft Entra ID. Your use of those services is governed by your own agreement with Microsoft, not by these Terms. You are responsible for holding the Microsoft licences and administrative rights needed to connect the environment and to receive the full benefit of the Service. We do not supply, resell or sublicense Microsoft licences.
The Service may also link to third party websites or services. We are not responsible for their content or their practices.
7. Fees, quotes and payment
The Service is priced per organization. A quote is prepared for your environment and reflects the scope of your setup, which may include the number of users and connected environments covered, the Microsoft licence tiers in use, the modules enabled, and the onboarding and support you require.
Fees, the billing period, and any renewal terms are set out in the quote or order form we agree with you in writing. Unless that document says otherwise:
- Invoices are payable within thirty (30) days of the invoice date.
- Fees are exclusive of taxes, which are added where applicable.
- Fees are non-refundable except where these Terms expressly provide otherwise.
- Subscriptions renew for the period stated in the order form unless either party gives notice of non-renewal before the end of the then-current term.
We may suspend the Service for invoices that remain unpaid more than thirty (30) days after the due date, after giving you notice and a reasonable opportunity to pay.
8. Intellectual property
We and our licensors own the Service, including its software, models, detection logic, user interface, documentation and all related intellectual property. Nothing in these Terms transfers ownership of the Service to you.
You receive a non-exclusive, non-transferable right to use the Service during your subscription term, for your organization's internal business purposes, in accordance with these Terms.
You own your Customer Data and any reports, exports or case records generated from it. We may use aggregated and de-identified information, from which no individual or organization can be identified, to operate, secure and improve the Service.
If you give us feedback about the Service, we may use it without restriction or obligation to you.
9. Confidentiality
Each party may receive information that the other treats as confidential. The receiving party will use that information only for the purposes of these Terms, will protect it with at least the care it applies to its own confidential information, and will not disclose it except to personnel and advisers who need it and are bound by confidentiality obligations.
These obligations do not apply to information that is or becomes public without breach, was already lawfully known to the receiving party, is independently developed without reference to the disclosing party's information, or must be disclosed by law, provided that the receiving party gives prompt notice where lawful.
10. Availability, changes and support
We work to keep the Service available and current. Data from a connected Microsoft environment refreshes automatically each day, and an authorized user can run an on-demand scan when a current picture is needed. Every page shows when it last refreshed.
We may perform maintenance, and we may release changes that alter the interface or add or remove capabilities. Any availability commitment, support window or service credit that applies to your organization is stated in your order form or a separate service level agreement.
Unless an order form or service level agreement states otherwise, the Service is provided without a contractual availability guarantee, and support is provided on a commercially reasonable efforts basis during our business hours.
11. Disclaimers
The Service identifies risk and exposure and helps you remediate it. It is not a guarantee that your environment is or will remain secure, and it does not replace professional judgement, your own security program, or your obligations under applicable law and regulation.
Findings depend on the data made available by your Microsoft environment and on the licence tier in use. Data may be delayed, incomplete, or reported with a confidence level rather than certainty. You are responsible for the decisions you take in response to a finding.
Except as expressly stated in these Terms, and to the maximum extent permitted by law, the Service is provided as is and as available, and we disclaim all implied warranties, including merchantability, fitness for a particular purpose and non-infringement. Nothing in these Terms excludes liability that cannot lawfully be excluded, including for fraud or for death or personal injury caused by negligence.
12. Limitation of liability
To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, lost revenue, lost data or business interruption, however arising and even if the possibility of such loss was known.
To the maximum extent permitted by law, each party's total aggregate liability arising out of or relating to these Terms is limited to the fees paid or payable by your organization for the Service in the twelve (12) months immediately preceding the event giving rise to the claim.
These limits apply regardless of the theory of liability, and they do not apply to your payment obligations, to either party's indemnification obligations, or to liability that cannot lawfully be limited.
13. Indemnification
We will defend your organization against a third party claim alleging that the Service, used as permitted by these Terms, infringes that third party's intellectual property rights, and we will pay damages finally awarded or agreed in settlement. If such a claim is made, we may procure the right for you to continue using the Service, modify it so it is no longer infringing, or terminate the affected subscription and refund prepaid fees for the unused remainder of the term. This does not apply where the claim arises from Customer Data, from your combination of the Service with something we did not supply, or from use outside these Terms.
You will defend us against a third party claim arising from Customer Data, from your use of the Service in breach of these Terms, or from your failure to hold the Microsoft licences or authorizations needed to connect your environment, and you will pay damages finally awarded or agreed in settlement.
The indemnified party must give prompt notice, allow the indemnifying party to control the defence, and provide reasonable cooperation. The indemnifying party may not settle in a way that imposes an admission or a non-monetary obligation on the indemnified party without its consent.
14. Term, suspension and termination
These Terms apply for as long as your organization uses the Service. Your subscription term is stated in the order form.
- Either party may terminate for material breach if the breach is not cured within thirty (30) days of written notice.
- Either party may terminate immediately if the other becomes insolvent or ceases to operate.
- We may suspend or terminate access immediately where continued provision would be unlawful or would create a security risk.
- You may stop using the Service at any time, and you may disconnect the Microsoft integration at any time from your Microsoft admin portal.
On termination, access to the Service ends. For thirty (30) days after termination, and on written request, we will make available an export of the reports, exports and case records held in your workspace. After that period we will delete or de-identify the workspace data in line with our Privacy Policy and our retention schedule.
15. Changes to these terms
We may update these Terms. When we do, we will change the date at the top of this page and, for a material change, we will give notice inside the Service or by email to organization owners before the change takes effect. Continuing to use the Service after the effective date means you accept the updated Terms.
16. Governing law and disputes
These Terms are governed by the laws of the State of California, United States, without regard to its conflict of laws rules. The state and federal courts located in San Francisco County, California have exclusive jurisdiction, and each party consents to venue there.
Before starting proceedings, the parties will attempt in good faith to resolve the dispute through discussion between senior representatives for at least thirty (30) days after written notice. Nothing in this section prevents either party from seeking urgent injunctive relief.
If any provision of these Terms is found unenforceable, the remaining provisions stay in force. These Terms, together with any order form and the Privacy Policy, are the entire agreement between the parties on this subject and replace any prior understanding.
17. Contact
Questions about these Terms, including notices, should be sent to the addresses below. Legal notices must also be sent by post to the registered address.
- General and contractual enquiries: support@vigile.ai
- Pricing, procurement and security questionnaires: sales@vigile.ai
- Registered address: Vigile AI, Inc., 1600 Bryant St #411447, San Francisco, CA 94141, United States
Questions about these terms?
Contracts, data processing addenda, security questionnaires and renewal terms all start with the same conversation. Ask, and we will answer in writing.

