Voltar ao Trust Center
Em vigor desde: 2026-07-26
Disponível apenas em inglês. Este documento jurídico é fornecido em inglês como versão oficial. A interface do Trust Center está traduzida para o seu idioma.

API Terms of Service, ISMS Copilot API

Effective Date: 2026-07-26.

These API Terms of Service (the "Terms") govern use of the ISMS Copilot API (the "API" or the "Service"), the OpenAI-compatible developer endpoint at api.ismscopilot.com. They are a click-through agreement: the entity that accepts them, identified in its ISMS Copilot API account, is the "Customer", and these Terms are effective on the Customer's acceptance. They incorporate the API Data Processing Agreement ("DPA") and the API Sub-processor List.

Scope. These Terms govern the ISMS Copilot API only, under which a Customer calls the OpenAI-compatible endpoint from its own applications. They are distinct from the terms that govern the ISMS Copilot chat product used directly by ISMS Copilot's own users (see the chat product Terms of Service and chat product DPA), and from the Partner Embed program. Where a Customer also uses the chat product or the Partner Embed, that use is governed by the applicable product's terms, not these Terms.

These Terms govern the relationship between ISMS Copilot and the Customer only and confer no rights on any third party (no third-party beneficiary; Art. 1205 Code civil), except rights granted to data subjects by the GDPR, by any applicable Standard Contractual Clauses, or by other mandatory law.

0. Definitions

"ISMS Copilot" means Better ISMS EURL, the entity operating the ISMS Copilot API. "Request" means a single call to the API. "Credit" means a unit of prepaid balance. "EU aliases" means the model aliases suffixed -eu; "bare aliases" means the model aliases without that suffix. "Global mode" and "EU mode" have the meanings in §3 and in the DPA. "Sub-processor" has the meaning given in the DPA. These Terms are effective on the Customer's acceptance.

1. The Service

1.1 ISMS Copilot provides an OpenAI-compatible HTTP API that answers information-security and GRC questions, enriched server-side with framework knowledge (for example ISO 27001, SOC 2, NIST CSF, DORA, and GDPR reference material) before the request reaches the model. The Customer calls the API from its own applications using an API key it creates in its account.

1.2 ISMS Copilot may improve or change the Service. A model alias is stable, but the underlying model it resolves to may be upgraded over time; a change that materially affects data handling is notified in advance per the DPA sub-processor-change procedure (DPA §3). ISMS Copilot may amend these Terms on 30 days' notice via the account and the trust center; continued use after the effective date constitutes acceptance, and a Customer that rejects a materially adverse change may terminate without penalty for the unused, prepaid balance.

2. AI output, no warranty, not advice

2.1 ISMS Copilot warrants that it will provide the Service with reasonable skill and care and in material conformity with its then-current documentation. This is the only warranty ISMS Copilot gives.

2.2 Separately, and without limiting §2.1, the content of API responses is machine-generated and provided "as is". Responses are not legal advice, not professional GRC consulting, not audit opinion, and not a compliance certification, and are not reviewed by a human before delivery. ISMS Copilot does not warrant that any response is accurate, complete, current, or fit for any purpose, including the injected framework knowledge; the Customer must independently verify any response before relying on it.

2.3 Downstream disclosure. Where the Customer surfaces API responses to its own end-users, the Customer is responsible for making clear to those end-users that the responses are AI-generated and are not legal, professional, audit, or compliance advice and are not a substitute for a qualified professional. The Customer's compliance with this clause is a condition of the licence in §11 and is covered by the indemnity in §12.

3. Processing modes selected by model alias

3.1 The API exposes two processing modes, and the Customer selects the mode per request by the model alias it calls.

  • EU mode (isms-fast-eu, isms-thinking-eu). The request is processed by Mistral AI in the EU (mistral-small-2603). Call these aliases where EU-based processing is required.
  • Global mode (isms-fast, isms-thinking), the default for the bare aliases. The request is first received by OpenRouter, Inc. (a United States company) and served by z-ai/glm-5.2 on a closed set of three inference hosts: two in the United States and one in the EU (Sub-processor List). Calling a bare alias transfers the request through a United States aggregator and may process it in the United States (or in the EU when served by Inceptron).

3.2 Global mode is enabled by default. As an exceptional operational kill switch, ISMS Copilot may disable global mode, in which case a bare-alias request is served on the EU/Mistral path instead (a more protective destination: EU, zero-retention). This is an override, not routine behavior: when it is in effect, the request's x-isms-processing-region header reports eu, the request is served and billed at the EU model it actually ran on, and ISMS Copilot will announce a sustained global-mode disablement. The -eu aliases are always EU-mode regardless.

3.3 Processing-region header. Every successful response carries an x-isms-processing-region header (eu or global) so the Customer can confirm which processing mode served the request and route or alert on it. The header confirms the selected mode, not the physical inference region, and it is returned with the response (after processing), so it is a monitoring signal, not a pre-processing gate.

3.4 The applicable AI sub-processor, data residency, transfer mechanism, and retention posture depend on the mode (Sub-processor List and DPA §4). The Customer's choice of alias ordinarily determines these, subject only to the exceptional global-mode kill switch in §3.2, which can move a bare-alias request to the more protective EU/Mistral path.

4. Customer responsibilities

4.1 API-key security. The Customer is responsible for securely storing its API keys and for all use made under them. The plaintext key is shown only once at creation and is stored by ISMS Copilot only as a SHA-256 hash. On suspected compromise the Customer shall revoke the key from its account immediately and may create a replacement; a revoked key is rejected on the next request.

4.2 Cost of authorized traffic. The API is prepaid (§6): a Request draws down the Customer's prepaid credit balance, and when the balance reaches zero the API rejects further Requests until the Customer tops up. The Customer is responsible for the cost of Requests its keys authorize, including where its own key was leaked or abused; the Customer's exposure in any period is bounded by its available prepaid balance and any per-key spending limit it sets. ISMS Copilot shall act in good faith and without undue delay to assist mitigation (key revocation, spending-limit tuning) on notice of suspected abuse.

4.3 Controller duties. The Customer is the Controller of the personal data it includes in Requests and is responsible for the lawful basis, for its own data-subject notices, and for data-subject-rights first response (DPA §6). ISMS Copilot processes that content as the Customer's Processor on the Customer's documented instructions.

4.4 Lawful and acceptable use. The Customer shall not use the Service unlawfully; shall not send special-category data (Art. 9 GDPR) or criminal-offence data (Art. 10 GDPR) except as expressly permitted under DPA §1.4 (default prohibition, lifted only on a notified lawful condition plus an executed written sub-processor addendum expressly covering the category); shall not attempt to access system prompts, injected knowledge, internal data, or underlying models other than through the documented API; and shall not abuse, overload, reverse-engineer, or circumvent the Service's authentication, credit, spending-limit, or rate-limit controls.

4.5 Professional capacity. The Customer represents that it contracts as a professional (not a consumer or non-professionnel) in the course of its business.

5. Customer representations

The Customer warrants that any statement it makes to its own end-users about the Service does not represent that the Service: gives legal or professional advice; is human-reviewed; guarantees accurate responses; or constitutes compliance certification.

Contractual acknowledgment (global-mode model origin). In global mode the Service uses z-ai/glm-5.2, an open-weights model of Chinese authorship, served only on a closed three-host set (Together AI and Fireworks AI, United States; and Inceptron AB, Sweden, EU) selected by the providers' documented footprint and an account-level ban on China-hosted inference, not on an absolute per-request region guarantee, under the disclosed controls; the data-path sub-processors are those hosts and the OpenRouter aggregator, not the model author. The Customer acknowledges this origin and hosting posture, shall not represent to any end-user or third party that the global-mode model has no China-origin authorship, and, where it discloses sub-processors to its own end-users, shall reflect the applicable data-path sub-processor by mode. A Customer requiring no China-authored model shall use the -eu aliases (Mistral, EU). This acknowledgment is a Customer acknowledgment of a disclosed fact and does not constitute a warranty by ISMS Copilot as to the model's provenance beyond the hosting posture described.

The Customer indemnifies ISMS Copilot, under §12.1, against any claim arising from the Customer's end-user-facing statements that misrepresent the Service, its sub-processors, or the nature of AI responses. Breach of this §5 is a material breach permitting suspension under §7.

6. Fees, prepaid credits, billing

6.1 Prepaid only. The API is prepaid. One Credit equals one US dollar (balances are held to six-decimal precision so a sub-cent Request can be debited precisely). The Customer buys Credits in advance and Requests draw them down; there is no subscription and no post-hoc invoicing. The published pricing schedule for the Service is the source of the per-model rates (per million input and output tokens) that apply to each model alias. Usage is metered from the provider-reported token counts, and the injected framework knowledge consumes, and is billed as part of, prompt tokens. Fees are exclusive of VAT and other applicable taxes (§10.4).

6.2 Billing basis. A Request debits Credits when it produces a billable usage record: when the Request reaches a complete or partial status (including a truncated or otherwise partial response that the Service meters). A Request that is rejected before processing (authentication, validation, quota, insufficient balance, or spending-limit failure), or that fails without producing a billable usage record, may be recorded for accounting where applicable but does not debit Credits. Each billable Request is charged once (the debit is ledger-idempotent per usage row).

The charge for a billable Request is computed from the served model (the model that actually ran, which is the EU/Mistral model when the global-mode kill switch in §3.2 is in effect) and the rates in the published pricing schedule at the time the Request is served, applied to the provider-reported token counts and rounded to the balance precision. The schedule may price a model under either of two methods, both disclosed in the schedule:

(a) Fixed schedule rates: stated input and output prices per million tokens for that model (decoupled from the underlying provider cost); or (b) Cost × published markup: the served model's raw provider cost for those tokens, multiplied by the published markup factor (currently 2.0 for models without fixed schedule rates).

Where the schedule states fixed rates for a model, those rates control; the markup factor does not re-price that model. The price of a Request is fixed at the time it is served; a later change to the pricing schedule or the markup factor applies only to subsequent Requests. A materially adverse change to published prices or to the markup factor is notified in advance per §1.2.

6.3 Top-up and limits. Credits are purchased via Stripe (one-off payment, minimum top-up as published). The Customer may set daily, weekly, or monthly spending limits per key; a Request that would exceed a limit is rejected with an explanatory error rather than billed. When the balance reaches zero, Requests are rejected until the Customer tops up.

6.4 No refund of consumed credits. Credits already consumed by billable Requests (complete or partial) are non-refundable. Unused prepaid balance is refundable on termination as set out in §8.2. A payment processor's own settlement timing does not relieve ISMS Copilot of its obligation to initiate and pay a refund due under §8.2 within the period stated there.

7. Suspension

ISMS Copilot may throttle or suspend a key or account for: repeated acceptable-use or lawful-use violations (§4.4), abuse of the pipeline (for example traffic that materially degrades the Service or attempts to circumvent its controls), or a failed or reversed payment. Suspension shall be proportionate to the issue and, except for active security threats or legal compulsion, preceded by notice and a reasonable opportunity to cure. Notice is via the account and email. ISMS Copilot shall lift a suspension promptly once the cause is resolved. Suspension does not itself terminate the agreement.

8. Term, termination, offboarding

8.1 Either party may terminate for convenience on 30 days' written notice. Either party may also terminate for the other's material breach that remains uncured 30 days after written notice specifying the breach (for the Customer's non-payment, the cure period may be shorter as stated in §7). The Customer may stop using the API and revoke its keys at any time from the account.

8.2 On termination, the retention and deletion model in DPA §7 applies. Unused prepaid balance, less any amount the Customer owes, is refunded as follows: where ISMS Copilot terminates for convenience, or the Customer terminates for ISMS Copilot's uncured material breach, ISMS Copilot refunds the unused balance automatically, without requiring a request, within 30 days of the effective termination date; in any other case the Customer may request the refund and ISMS Copilot pays it within 30 days of the request. ISMS Copilot is responsible for paying the refund within these periods regardless of any payment-processor delay (§6.4). Consumed Credits remain non-refundable (§6.4).

9. Liability

9.1 The cap limits established liability; it is not a payment promise. This §9 caps the amount ISMS Copilot may be required to pay for liability that is actually established; it is not a liquidated-damages sum, a guarantee, a credit, or a promise to pay. ISMS Copilot owes nothing unless and until a claimant proves, under applicable law, a breach, actual damage, and causation; the floor and ceiling then cap the proven amount, they do not create or presume any amount. Subject to the foregoing, to the maximum extent permitted by applicable law, ISMS Copilot's total aggregate liability arising out of or in connection with the Service, whether in contract, tort, or otherwise, in any 12-month period, shall not exceed the greater of (i) the total fees paid by the Customer for the Service in the 12 months preceding the event giving rise to the claim, and (ii) EUR 500 (the floor, so the cap is never nil). ISMS Copilot is not liable for indirect or consequential loss, or for the Customer's or its end-users' reliance on AI output; this exclusion does not swallow a Personal Data Breach or confidentiality claim (DPA §10.2).

9.2 Nothing in these Terms excludes or limits liability for dol (fraud), faute lourde (gross negligence), death or personal injury caused by negligence, liability under Art. 82 GDPR to a data subject, or any liability that cannot lawfully be excluded. The Art. 82(5) inter-party contribution recourse between controller and processor is inside the §9 / DPA §10.1 cap, per DPA §10.3.

10. Governing law and general

10.1 Governing law: French law. Venue: where both parties contract as commerçants, the competent Tribunal de commerce having jurisdiction over ISMS Copilot's registered seat (Art. 48 CPC). For a Customer established outside the EU, the governing law, venue, or an arbitration seat may be specified in the applicable order form.

10.2 Operative language: these Terms are provided in English as the authoritative version.

10.3 Order of precedence: an order form or master agreement signed by both parties prevails (for the matters it covers) over the DPA, which prevails (for the processing of Personal Data) over these Terms; these Terms otherwise govern.

10.4 General.

  • Severability. If any provision is held invalid or unenforceable, it is limited or severed to the minimum extent necessary and the remaining provisions continue in full force.
  • Entire agreement. These Terms, the DPA, the Sub-processor List, and any order form are the entire agreement between the parties on their subject matter and supersede prior discussions.
  • No waiver. A failure or delay in exercising a right is not a waiver of it.
  • Assignment. Neither party may assign these Terms without the other's consent, except to an affiliate or in connection with a merger, reorganisation, or sale of all or substantially all of its assets, on notice.
  • Notices. Notices to the Customer are given via the account and the account email; notices to ISMS Copilot are given to legal@ismscopilot.com.
  • Survival. Provisions that by their nature should survive termination (including §§2, 5, 9, 11, 12, 13, and 14, and accrued payment obligations) survive.
  • Taxes. Fees are exclusive of VAT and other applicable taxes, which the Customer pays in addition where due.

11. Intellectual property and licence

11.1 Ownership. ISMS Copilot (Better ISMS) retains all right, title, and interest in and to the Service (the API, its backend, the framework knowledge it injects, and its documentation) and all related intellectual property. The third-party AI models the Service operates (for example Mistral's and the Z.AI-authored open-weights model), their weights, and the third-party host infrastructure are the property of their respective owners and licensors; ISMS Copilot claims no title to them and makes them available to the Customer only as part of the Service. No rights are granted to the Customer other than the licence in §11.2.

11.2 Licence to the Customer. ISMS Copilot grants the Customer a non-exclusive, non-transferable, non-sublicensable, worldwide, revocable licence, for the term, to call the API and use its responses in the Customer's own applications, subject to these Terms.

11.3 Requests and AI outputs. As between the parties, the Customer owns the Request content it submits and, to the extent protectable and permitted by law, the AI outputs generated for it. ISMS Copilot claims no ownership of Customer Request content or outputs beyond the limited licence needed to operate the Service and meet its legal duties. ISMS Copilot gives no warranty that an output is original or non-infringing; the residual risk that an output resembles third-party protected text (for example standard wording) is allocated to the Customer and runs with the §12.1 indemnity.

11.4 Restrictions. The Customer shall not (a) use the Service or its outputs to train, fine-tune, distil, or benchmark a competing model or service; (b) reverse-engineer or attempt to derive source code or the injected knowledge except as permitted by non-waivable law; or (c) remove or obscure proprietary notices.

11.5 Feedback. ISMS Copilot may use any feedback the Customer provides without restriction or obligation.

12. Indemnification

12.1 By the Customer. The Customer shall defend and indemnify ISMS Copilot against third-party claims (including end-user claims) to the extent caused by the Customer's: misrepresentation of the Service to end-users (§5); unlawful use or use of special-category or criminal-offence data in breach of §4.4 / DPA §1.4; failure to make the downstream AI disclosure (§2.3); breach of these Terms; or negligent or unlawful acts in its own content or deployment of the Service. This indemnity is limited to claims caused by the matters listed and does not extend to loss caused by ISMS Copilot's own breach or negligence.

12.2 By ISMS Copilot (narrow). ISMS Copilot shall defend and indemnify the Customer against a third-party claim that the Service code itself (excluding AI output content, Customer content, and combinations with non-ISMS materials) infringes that third party's IP, subject to §9 and §12.4.

12.3 Procedure. The indemnified party gives prompt written notice, allows the indemnifying party sole conduct of the defence, and cooperates; no settlement that imposes a non-indemnified liability or admission on the other party is made without that party's consent (not unreasonably withheld).

12.4 Limits. The §9 cap limits ISMS Copilot's aggregate outbound liability, including its own indemnity to the Customer under §12.2; it does not cap the Customer's indemnification obligations under §12.1, which stand outside the §9 cap. Nothing here requires a party to indemnify the other for liability that cannot lawfully be shifted, or transfers either party's own non-excludable duties to a data subject or end-user.

13. Confidentiality

13.1 Confidential Information means non-public information disclosed by one party that is marked or reasonably understood as confidential, including each party's non-public technical, security, business, and pricing information.

13.2 Obligations. The receiving party shall protect Confidential Information with at least reasonable care, use it only to perform under these Terms, and disclose it only to personnel and contractors with a need to know who are bound by equivalent confidentiality.

13.3 API keys. The Customer's API keys are ISMS Copilot Confidential Information of the highest sensitivity and are also governed by §4.1.

13.4 Exclusions. The obligations do not apply to information that is or becomes public without breach, was lawfully known before disclosure, is independently developed, or is lawfully received from a third party; a party may disclose where legally compelled, giving prompt notice where lawful and disclosing only what is required.

13.5 Term. Confidentiality survives termination for three (3) years, and indefinitely for trade secrets and API keys.

14. Trade controls and sanctions

14.1 Compliance. Each party shall comply with applicable EU, US, and UN export-control and economic-sanctions laws in its use and provision of the Service.

14.2 Customer warranties. The Customer warrants that it is not established in, or ordinarily resident in, and will not make the Service available to a person or in a jurisdiction that is, subject to comprehensive EU/US/UN embargo or on an applicable denied or sanctioned-party list.

14.3 Suspension. Either party may suspend performance to the extent necessary to comply with sanctions or export-control law, without liability for the suspension.

15. EU AI Act allocation

Regulation (EU) 2024/1689 (the "AI Act") applies to the relevant obligations from their respective dates of application (the Art. 50 transparency obligations generally from 2 August 2026).

15.1 Roles are use-case dependent. In the default configuration, ISMS Copilot acts as the provider of an AI system built on a third-party general-purpose AI model, and the Customer acts as deployer when it integrates the Service into its own applications. This default allocation is not conclusive: roles under the AI Act follow the actual downstream integration, and a Customer that puts its own name or trademark on the Service, substantially modifies it, or changes its intended purpose may itself become a provider (including of a high-risk system) under Art. 25 and assume the corresponding obligations. Each party performs the obligations attaching to its actual role.

15.2 Transparency (Art. 50). The AI Act allocates the transparency duties by role:

  • Art. 50(1) (interaction notice): informing natural persons that they interact with an AI system is a provider design duty and a deployer duty. ISMS Copilot provides the technical means for the Service to be identifiable as AI (including the §2.3 disclosure); the Customer shall preserve that identification and shall itself inform its end-users where it surfaces the Service to them.
  • Art. 50(2) (marking of AI-generated content): marking the Service's text output as artificially generated in a machine-readable format, where Art. 50(2) applies, is the provider's obligation; ISMS Copilot is responsible for that marking for output the Service generates, and the Customer shall not remove or defeat it.
  • Art. 50(4) (public-interest / deep-fake disclosure): where a deployer publishes AI-generated or manipulated text to inform the public on matters of public interest, or other Art. 50(4) content, that disclosure obligation is the Customer's as deployer.

15.3 Use limits. A GRC and information-security assistant is intended as a transparency-obligation (limited-risk) use under the AI Act and is not a prohibited practice and not, on its face, a high-risk system under Annex III. The Customer shall not deploy the Service for a practice prohibited under the AI Act, and shall not integrate it into a high-risk use within the meaning of the AI Act, without a separate written allocation of the provider/deployer obligations and compliance package for that use; absent that, the high-risk deployer (and, where Art. 25 applies, provider) obligations that such use requires are the Customer's.


These API Terms are published by Better ISMS (ISMS Copilot) and are effective on Customer acceptance. Questions: legal@ismscopilot.com.