Terms of Service
Effective date: August 4, 2026 · Last updated: August 4, 2026
1. Agreement to these terms
These Terms of Service (“Terms”) govern access to and use of GOVERNBOX.ai (“the Service”), operated by Gradient Descent LLC (“Gradient Descent,” “we,” “us”). By creating an account, starting a free trial, subscribing to a paid plan, or otherwise using the Service, you (“you,” “your organization”) agree to these Terms. If you are accepting these Terms on behalf of an organization, you represent that you have authority to bind that organization.
These Terms should be read together with our Privacy Policy and Data Usage Policy, which describe how we handle information.
2. The Service
The Service is a self-service web application that helps organizations build and maintain governance programs. It is organized into five modules:
- AI Governance. AI use case inventory, risk register, impact assessments, incident log, AI agent registry, training plans, AI project management, policy and document generation, and compliance crosswalks.
- Enterprise Risk Management. Organization-wide risk register and key risk indicators.
- IT Inventory & Management. Device, software subscription, system, and access registries.
- Data Management. Data inventory, data flows, retention schedules, and individual privacy request tracking.
- Privacy. Privacy-law framework mappings (HIPAA, GDPR, CCPA) and privacy policy generation. The Privacy module is included with the Professional and Agency plans and is not licensed separately.
Which modules and features are available depends on your subscription plan and module configuration, described on our Plans page. The Service also includes shared capabilities such as the quarterly Board Report, the employee attestation portal, the publishable Trust Page, and regulatory change monitoring.
The Service uses a proprietary control library and a third-party AI model to tailor and phrase governance language to your organization’s context. See our Data Usage Policy for how this works, and Section 8 below for important limitations on what generated output represents.
3. Frameworks and regulatory content
The Service references published regulatory frameworks and standards, including NIST AI RMF, ISO/IEC 42001 & 42005, the EU AI Act, U.S. federal and U.S. state AI laws and regulations as they become available and required, HIPAA, GDPR, and CCPA. Which frameworks are available depends on your plan.
Regulations change, sometimes abruptly, and sometimes are repealed or replaced before taking effect. We maintain our control library and regulatory monitoring on a commercially reasonable basis, but we do not warrant that our framework content is current, complete, or correct as of any given date, and you should not treat the Service as a substitute for monitoring the law that applies to you. Compliance-date information and regulatory summaries in the Service are provided for orientation only.
4. Accounts, access, and your responsibilities
You must provide accurate information when creating an account and keep credentials secure. Organization membership and administrative rights are managed through our identity provider’s administration interface, available in the Admin Console.
The Service distinguishes between administrators, who can manage the organization’s profile, membership, billing, data export, and account deletion, and members, who cannot. The organization’s administrator may restrict which members may create, edit, or delete governance records within the modules your organization licenses. Every such action is attributed to that individual in your organization’s permanent audit log. If your organization requires per-feature access restrictions, you should manage that through whom you invite, and you should not rely on the Service to enforce internal separation of duties.
You are responsible for the accuracy of the information your organization enters, for maintaining appropriate membership, and for all activity under your organization’s account.
You agree not to: use the Service to violate any law; attempt to access another organization’s data or bypass tenant isolation; reverse-engineer, scrape, or resell the Service or the control library without our written permission; upload malicious code; share document review links or attestation links with people who should not have them; or use the Service to generate content that is unlawful, discriminatory, or intended to evade a legitimate regulatory obligation.
5. Free trial, subscriptions, billing, and cancellation
5.1 Free trial. We offer a 15-day free trial. No payment method is required to start the trial. During the trial, certain capabilities are limited. These include a cap on the number of records per module and restrictions on document generation, compliance crosswalks, attestations, and Trust Page publishing.
You may cancel at any time during the trial at no charge.
5.2 Plans and modules. Paid subscriptions are sold as a combination of a plan tier (Starter, Professional, or Agency), which determines feature depth, framework availability, and included seats, and a module configuration over the four core modules: a single module, any two, or all four. Agency subscriptions include all four core modules; the Privacy module is included with Professional and Agency subscriptions and is not licensed separately. Starter subscriptions may be billed monthly or annually; Professional and Agency subscriptions are billed annually.
5.3 Billing. Paid plans are billed through Clerk Billing, which settles payment through Stripe. Fees are described at the time of purchase and are non-refundable except as required by law or as we expressly agree in writing. Subscriptions renew automatically at the end of each billing period unless cancelled beforehand through your organization’s billing settings.
5.4 Changes to pricing. We may change pricing prospectively; changes will not apply to a billing period you have already paid for. If a payment fails or a subscription lapses, we may downgrade your organization, which may restrict access to paid modules and features while your data is retained per our Data Usage Policy. A lapsed subscription also causes any published Trust Page to stop presenting your organization as currently verified (see Section 7).
5.5 Nonprofit discount. We offer discounted pricing to nonprofit organizations across our plan tiers. Because our billing platform does not currently support promotional codes, this discount is offered on an honor-system basis: by selecting a nonprofit-priced plan, you represent that your organization is a bona fide nonprofit entity. We reserve the right to request documentation confirming nonprofit status at any time, including after enrollment — such as your organization’s federal Employer Identification Number, IRS tax-exemption determination letter, or state nonprofit registration. If we cannot verify nonprofit status, or later determine your organization did not qualify, we may adjust your subscription to standard pricing and, where the discount was obtained through knowing misrepresentation, pursue the remedies in Section 14.
5.6 Special programs. We may offer invitation-only or limited programs such as founding-member pricing or an advisory board on separate written terms provided at the time of the offer. Where those terms conflict with these Terms, the program terms control for that program’s subject matter.
6. Personal information you upload about other people
Several features are designed to record information about individuals, including your staff, who are not users of the Service. These include the employee attestation roster, training completion records, IT access records, individual privacy request records, and any field where you name a responsible person.
With respect to that information:
- You are the controller and we are the processor. You determine whose information is entered and why. We process it on your instructions to provide the Service.
- You represent and warrant that you have the lawful basis and authority to provide that information to us, and have given any notice or obtained any consent required by law.
- You will direct individual requests to yourself, not to us. If a person whose information you entered contacts us seeking access, correction, or deletion, we will refer them to your organization and assist you in responding.
- You agree to indemnify us against claims arising from your failure to have the necessary rights or to provide the necessary notices.
- Certain records are permanent by design. Attestation signatures and audit log entries cannot be edited or deleted through the Service, because their purpose is evidentiary. If you have an obligation that conflicts with this, do not use those features without discussing it with us first.
If you require a Data Processing Addendum, contact us and we will provide one.
7. Publishing and sharing features
Two features publish or expose information at your election, and you control whether to use them:
- Trust Page and badge. Publishing a Trust Page makes a public web page available at an unlisted address showing your organization’s name and sector, governance maturity scores, selected framework names, counts and generic types of approved documents, the date of your most recent approval, and your attestation completion rate. It does not publish document contents or any individual’s name. You may unpublish at any time. If your subscription lapses, the page automatically ceases to present your organization as currently verified, so that it cannot be used to represent an inactive program as active.
- Document share links. Sharing a document generates an unlisted link that permits anyone holding it to read the full document and submit a comment. Treat these links as confidential. We cannot control redistribution of a link you share.
You are responsible for the accuracy of any claim you make using these features, including to funders, boards, regulators, or the public.
8. Not legal or compliance advice, human review required
The Service is a drafting and organizational tool, not a substitute for legal counsel or a compliance program. Every clause in a generated document is grounded in a control from our proprietary library and is required to cite that control, but the Service does not represent generated output as legal advice, and using it does not create an attorney-client relationship with Gradient Descent LLC or anyone else.
You are responsible for having a qualified person at your organization (and, where appropriate, outside counsel) review any generated document before adopting, publishing, or relying on it. The Service is designed to require this review step before a document can be marked approved or exported, and that requirement is a feature, not a formality.
The Service’s coverage analysis, gap identification, maturity scoring, and regulatory change alerts are advisory and informational. A high coverage percentage, a maturity score, or the absence of a flagged gap is not a determination that your organization complies with any law or standard, and must not be represented as one.
9. Your content and our intellectual property
You retain ownership of the information your organization enters into the Service (“your content”), and of the governance documents generated for your organization. You grant us a limited license to process your content solely to provide the Service to you, including retrieval, AI-assisted generation, verification, storage, export, and support, as described in our Data Usage Policy. We do not use your content to train AI models, and we do not sell it.
The control library, the regulatory requirement records and crosswalk mappings used for verification, the underlying software and documentation, and the GOVERNBOX.ai name, the “Governance in a Box” tagline, and related branding are the property of Gradient Descent LLC and are licensed, not sold, to you for use through the Service during your subscription. You may not extract, republish, or redistribute the control library or requirement records outside the Service.
Where you provide feedback or suggestions about the Service, including through any advisory program, you grant us a perpetual, royalty-free right to use it without obligation to you.
10. Multi-tenancy and data isolation
Your organization’s data is logically isolated from every other organization’s data using per-tenant access controls enforced in application code and at the database level, through a database account that cannot bypass those controls. A small number of authorized Gradient Descent staff may access your data on a cross-tenant basis strictly for support and platform-maintenance purposes; every such action is recorded in your organization’s own audit log.
11. Service availability and changes
Except as expressly provided in a program schedule your organization has entered into with us (such as the Partner Program Terms), we do not offer a service level agreement or uptime commitment. Where a program schedule provides service levels, those service levels are measured as described in that schedule, by an independent third-party monitoring service, and exclude maintenance announced in advance.
We may modify, add, or discontinue features. If we discontinue a feature your organization materially relies on, we will give reasonable advance notice to account Owners. We may perform maintenance that temporarily interrupts availability.
12. Disclaimers
THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. WE DO NOT WARRANT THAT GENERATED DOCUMENTS SATISFY ANY PARTICULAR LEGAL OR REGULATORY REQUIREMENT, THAT COVERAGE OR GAP ANALYSIS IS COMPLETE OR ACCURATE, THAT FRAMEWORK CONTENT REFLECTS CURRENT LAW, OR THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE.
Support for a framework within generated documents does not constitute certification of our own infrastructure.
13. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, GRADIENT DESCENT LLC WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, DATA, OR GOODWILL, ARISING FROM YOUR USE OF THE SERVICE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. OUR TOTAL LIABILITY FOR ANY CLAIM ARISING OUT OF THESE TERMS OR THE SERVICE WILL NOT EXCEED THE AMOUNT YOU PAID US IN THE TWELVE MONTHS PRECEDING THE CLAIM.
14. Termination
You may cancel your subscription at any time through your organization’s billing settings in the Admin Console; cancellation takes effect at the end of the current billing period. We may suspend or terminate access if you materially breach these Terms (including the acceptable-use restrictions in Section 4, the representations in Section 6, or a knowing misrepresentation of nonprofit status under Section 5.5) and do not cure after notice, or if required by law.
Upon termination, your data is handled as described in our Data Usage Policy’s retention and deletion provisions. Export your data before terminating. We recommend using the export function in the Admin Console while your account is still active.
15. Changes to these Terms
We may update the Service and these Terms from time to time. If we make material changes, we will notify account Owners by email or an in-app notice before the changes take effect. Continued use after changes take effect constitutes acceptance of the updated Terms.
16. Governing law and disputes
These Terms are governed by the laws of the State of Virginia, without regard to conflict-of-laws principles.
17. Independence from federal service
GOVERNBOX.ai is a product of Gradient Descent LLC, a privately held company that develops and operates software services. The Service is not sponsored, endorsed, funded, or supported in any manner by the United States Government or by any federal agency, and no such endorsement is stated or implied.
Gradient Descent LLC’s founder, Jim Tunnessen, serves separately as a federal Senior Executive. That service is entirely unrelated to this Service and to Gradient Descent LLC. All work on the Service is performed on personal time and in a personal capacity, and is connected to Gradient Descent LLC and not to any federal position or official duties. No federal government data, systems, facilities, funding, personnel, or official-duty information is used in, or informs, the Service. Any views expressed in or through the Service are those of Gradient Descent LLC and not of the United States Government or any federal agency.
Organizations using the Service are commercial customers of Gradient Descent LLC, governed solely by these Terms and your service agreement with Gradient Descent LLC.
18. Contact us
Gradient Descent LLC
Email: info@gradientdescent.biz
Web: gradientdescent.biz
Questions about these Terms can be sent through our Contact page or by email with the subject line “Terms of Service Question.”