Terms of service.
The rules for using this website and the IsoFort platform. Written to be read, not to be survived. If a negotiated agreement is in place between us, that agreement wins wherever the two disagree.
01 Who you are contracting with
IsoFort is a brand, platform and product line owned and operated by Evfiam Investment Group SRL, a limited liability company incorporated in Romania. Every reference to "IsoFort", "we", "us" or "our" in these terms means that company. "You" means the person or the organisation using this website or the platform.
Trade register number, tax identification code and registered office address are provided on request, and are stated in full in every contract we sign.
02 Scope and order of precedence
These terms cover two things: browsing this website, and using the IsoFort platform where no separately negotiated agreement is in force.
Where documents conflict, this is the order that applies, highest first:
- A signed master services agreement, order form or statement of work between us.
- The data processing agreement between us.
- These terms of service.
- Any product documentation or policy referenced from them.
By using the website or the platform you accept these terms. If you are accepting on behalf of an organisation, you confirm you are authorised to bind it. If you do not accept them, do not use the service.
03 Accounts and eligibility
IsoFort is a business to business service. Accounts are issued to organisations, and to named individuals within them. You must be at least 18 years old and legally able to enter a contract.
- Provide accurate registration details and keep them current.
- Credentials are personal. Do not share accounts, and do not create a shared login for a team.
- Multi-factor authentication is mandatory for privileged and administrative roles. We will not disable it on request.
- You are responsible for everything that happens under your accounts, and you must tell us at security@isofort.ai as soon as you suspect a credential has been compromised.
- Certain sensitive actions require approval from two different people. This is a control, not an inconvenience to be engineered around.
04 Trials, sandboxes and pilots
We offer a time limited trial of the platform, and a sandbox environment that returns synthetic data.
- A trial runs for the stated period, typically 30 days, and includes a stated volume allowance. It is the full product, not a crippled demo.
- When a trial expires without conversion, the account downgrades. It is not silently converted into a paid subscription, and we do not charge you for a trial you did not convert.
- Trial and sandbox use is provided as is. Service level commitments, support response targets and availability commitments do not apply to trials unless we agree otherwise in writing.
- Do not put real production personal data into the sandbox. It is designed for synthetic data.
- We can end a trial early if it is used outside these terms, and we will tell you why.
Pilot programme terms, including scope, success criteria and duration, are set out in the pilot agreement for that cohort.
05 Acceptable use
You may not, and may not permit anyone else to:
- Use the service for anything unlawful, or to facilitate financial crime rather than prevent it.
- Use outputs to discriminate against a person on a protected ground, or in any way that breaches consumer protection, fair lending or equal treatment law in your jurisdiction.
- Reverse engineer, decompile, or attempt to derive the models, features, weights, thresholds or scoring logic behind the platform, including by systematic probing designed to reconstruct them.
- Resell, sublicense, or provide the service to a third party as a bureau or scoring service, unless a partner or reseller agreement says you may.
- Scrape the platform, circumvent rate limits, or run load and penetration testing without our prior written consent. We are happy to schedule authorised testing.
- Upload malware, or attempt to gain access to data belonging to another customer.
- Publish a benchmark or comparative evaluation of the service without giving us the chance to review it for factual accuracy first.
- Remove or obscure any proprietary notice in the product or its outputs.
We may suspend access to stop an active breach, a security incident or an unlawful use. Where we can, we warn you first.
06 Your data and your obligations
You keep ownership of the data you send us. You grant us a limited licence to process it solely to provide the service to you, as set out in the privacy policy and the data processing agreement.
You are responsible for:
- Having a lawful basis to send us each category of data, and giving your own customers the notices the law requires.
- The accuracy and quality of what you send. Risk assessment inherits the quality of its input.
- Not sending special category data (health, biometrics, political opinions and the other Article 9 categories) unless we have agreed to it in writing.
- Configuring thresholds, policies and workflows appropriately for your risk appetite and your regulator.
We may generate aggregated and anonymised statistics about how the service performs. These never identify you, your customers or any individual, and we use them to improve the service and to report on it in aggregate. If you want a stricter arrangement, we will write it into your agreement.
07 What a risk score is, and is not
IsoFort produces a probabilistic assessment with the reasons behind it. It is decision support. It is not a decision, not a guarantee, not legal advice and not a certification that a person or a transaction is legitimate.
- No detection system catches everything. Fraud is adversarial and it adapts. We do not warrant that the service will identify every fraudulent transaction, every sanctioned party or every bad actor, and we do not warrant that legitimate activity will never be flagged.
- You own the decision. Approving, declining, holding, reporting or offboarding is your call, taken under your policy, by your people, with human review where it matters.
- Do not use a score as the sole basis for an adverse action where the law requires a reviewable decision, an explanation or a right of appeal. The product gives you the reason codes needed to explain and to contest. Use them.
- Third party data carries third party limits. Some signals come from external providers and public lists. We pass through what they publish, and we do not warrant the accuracy or completeness of data we did not create.
08 Regulatory responsibility
IsoFort is a technology supplier. We are not a bank, not a payment institution, not a credit reference agency, not a consumer reporting agency, and not your compliance function.
- You are the regulated entity. Licensing, registration, supervisory reporting, suspicious activity reporting, consumer disclosures and record keeping remain your obligations.
- Where a regulator requires oversight of a critical third party supplier, we will support your due diligence, your audit rights and your exit planning as set out in your agreement.
- Where your use of the service falls under a consumer credit or consumer reporting regime, you are responsible for meeting the obligations that regime places on you, including any adverse action notice.
- Where the EU AI Act or an equivalent regime applies to your deployment, you act as the deployer. We support you with the technical documentation, logging and human oversight features that role requires.
09 Intellectual property
The platform, the models, the scoring engine, the reason code taxonomy, the documentation, the brand and this website are ours, and stay ours. These terms grant you a limited, non exclusive, non transferable, revocable right to use the service during your subscription, for your own internal business purposes.
Nothing here transfers any right in our software, our models or our training corpora. Outputs generated for you may be used inside your business, including in your own regulatory filings, without restriction beyond these terms.
If you send us feedback, ideas or feature requests, we may use them freely to improve the product, with no obligation and no claim by you. We will not identify you as the source without asking.
10 Fees, billing and taxes
- Fees, metering units, minimums and the billing period are set in your order form. Usage above a committed volume is billed at the agreed overage rate.
- Invoices are payable within the period stated on the invoice. Late payment may attract statutory interest and, after notice, suspension.
- Fees are exclusive of VAT and any other applicable tax, which you pay in addition where it is due.
- Except where the law or your agreement says otherwise, fees already paid are not refundable. We do not charge for a trial that was never converted.
- We may change list pricing with at least 30 days notice, effective at your next renewal, never mid term.
11 Availability and support
We aim for high availability and we operate the platform accordingly, but no service is immune to failure. Availability commitments, support hours and response targets, where they apply to you, are set out in your agreement. Trials and sandbox environments carry none.
Planned maintenance is announced in advance where it is likely to be noticeable. Emergency maintenance to close a security issue may happen without notice, and we tell you afterwards.
Our incident response commitments, including how quickly affected customers are told about a serious incident, are published on the security page.
12 Confidentiality
Each side will protect the other side confidential information with at least reasonable care, use it only for the purpose it was shared, and disclose it only to people who need it and who are bound by equivalent obligations.
This does not cover information that is public through no breach, that was already lawfully known, or that is independently developed. Where disclosure is compelled by law, the disclosing side gives notice where it is legally permitted to do so.
Our detection methodology, our data source composition and our commercial supplier arrangements are confidential information. Your data, your configuration and your case material are yours.
13 Term, suspension and termination
- Subscriptions run for the term in the order form and renew as it specifies. Notice periods for non renewal are set there.
- Either side may terminate for material breach that is not cured within 30 days of written notice, or immediately on the other side insolvency.
- We may suspend access immediately to contain a security incident, an unlawful use or a serious breach of section 5. Suspension is proportionate, and we restore access once the cause is resolved.
- On termination, access ends. We delete or return your data within 30 days, except where retention is required by law. See the retention table.
- Sections on intellectual property, confidentiality, liability, and governing law survive termination.
14 Warranties and disclaimers
We warrant that we will provide the service with reasonable skill and care, in line with the documentation, and that we have the right to grant the rights in these terms.
Beyond that, and to the extent the law allows, the service is provided as is. We disclaim implied warranties of merchantability, fitness for a particular purpose and non infringement. We do not warrant that the service will be uninterrupted or error free, that every risk will be detected, or that results will meet a specific accuracy target unless that target is written into your agreement.
Nothing in these terms excludes liability that cannot lawfully be excluded, including liability for death or personal injury caused by negligence, for fraud, or for wilful misconduct.
15 Limitation of liability
To the extent permitted by law, neither side is liable to the other for indirect, incidental, special, consequential or punitive damages, nor for loss of profit, revenue, goodwill, business opportunity or anticipated savings, however caused.
Each side total aggregate liability arising out of or in connection with these terms is limited to the fees paid or payable by you to us in the 12 months preceding the event that gave rise to the claim. Where no fees have been paid, including during a free trial, that cap is zero and our liability is limited to correcting the service.
These caps do not apply to your obligation to pay fees, to either side breach of confidentiality, or to liability that cannot lawfully be capped.
Losses arising from a decision you took, or did not take, on the basis of an IsoFort output are governed by section 7. The decision is yours.
16 Governing law and general provisions
Governing law. These terms are governed by Romanian law, without regard to conflict of law rules. The competent courts of Romania have exclusive jurisdiction, save that either side may seek injunctive relief in any competent court to protect its intellectual property or confidential information. A negotiated enterprise agreement may specify a different governing law and forum, and where it does, it prevails.
Consumers. If you are a consumer in the EU, you keep the mandatory protections and the courts of your country of residence, whatever this section says.
Changes. We may update these terms. The version and effective date at the top change with them. For a material change affecting a paying customer, we give at least 30 days notice through the account contact on file. Continuing to use the service after the effective date means you accept the new version.
Assignment. Neither side may assign these terms without the other consent, except to a successor in a merger or a sale of substantially all assets, on notice.
Force majeure. Neither side is liable for a failure caused by an event beyond its reasonable control, provided it mitigates and communicates.
Severability and waiver. If a provision is unenforceable, the rest stands and the provision is read down to the minimum change needed. A failure to enforce a right is not a waiver of it.
Website content. The material on this website is provided for general information. It is not advice, and it does not create a contract or a commitment on our part. Product descriptions reflect the service as it stands and may change as it evolves.
Contact. Legal notices go to legal@isofort.ai and to the registered office above. Commercial questions go to pilot@isofort.ai.
Privacy and security,
in the same detail.
How we handle personal data, and the controls that stand behind these commitments.