Platform Terms of Service & EULA
Legal liability disclaimers, IP protection, and data governance guidelines for the Epicpaths™ Compliance Engine.
Effective Date: September 12, 2026 | Document Version: 1.2.0
1. Scope of Agreement
This End User License Agreement (EULA) and Data Governance Agreement governs the use of the Epic Compliance Engine SaaS. These terms apply to all active subscribers, evaluators, agency co-admins, and testers, and specifically govern all Auditor, Enterprise Junior, Enterprise Editor, Enterprise Admin, and Enterprise Owner accounts.
2. The "Tool vs. Practitioner" Liability Boundary
The Epic Compliance Engine provides automated Web Content Accessibility Guidelines (WCAG) 2.2 Level AA/AAA testing ingestion, structural DOM mapping, and Voluntary Product Accessibility Template (VPAT/ACR) formatting. By utilizing the platform, you explicitly agree to the following statutory boundary:
"The Epic Compliance Engine is exclusively a diagnostic, organizational, and reporting workflow utility, and does not constitute a legal certification authority or statutory compliance guarantee. While the platform enforces structured Web Content Accessibility Guidelines (WCAG) 2.2 matrices and Section 508 / EN 301 549 reporting standards, the accuracy, completeness, and legal defensibility of the underlying audit data remain the sole legal responsibility of the evaluating practitioner or subscribing entity. Epic Compliance Engine bears zero liability for third-party litigation, regulatory fines, or statutory non-conformance claims arising from audits executed via the software."
3. Client Intellectual Property & Soft-Delete Archival
All target platform URLs, DOM selectors, accessibility issue descriptions, and remediation guidance entered into the workspace remain the exclusive intellectual property and confidential data of the subscribing organization.
"Users acknowledge that deleting an audit project or finding row initiates a thirty (30) day 'Pending Archival' soft-delete state. During this window, data is hidden from active workspaces but recoverable upon administrative request. At the conclusion of the 30-day window, system cron schedulers execute an irreversible physical purge. Epic Compliance Engine is not liable for data unrecovered after this 30-day pending window expires."
4. Organizational Continuity & "Break-Glass" Authority
For multi-seat Enterprise subscriptions, the contracting agency or corporate entity—not the individual email address of the initial registrant—is recognized as the primary legal account holder.
"In the event of primary owner incapacitation, employee termination, abandonment, or internal ownership dispute, Epic Compliance Engine reserves the legal right to execute an administrative 'Break-Glass' override. Upon receipt of verified corporate, legal, or judicial authority, system administrators may programmatically transfer primary tenant ownership, billing linkage, and child seat mappings to an authorized co-admin or corporate officer without prior consent of the unreachable or disputing primary user."
5. Right to be Forgotten & Hard Purge Verification
Epicpaths operates in strict compliance with global privacy frameworks, including the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
"Subscribers may submit a formal Data Destruction Request upon account termination. Within fourteen (14) business days of verification, system administrators will execute an irreversible physical SQL deletion across all active tables, staging environments, and database archives, bypassing the standard 30-day soft-delete window. The engine will generate an automated, timestamped Data Destruction Certificate as permanent legal verification of complete data eradication."
6. Acceptable Use & Platform Integrity
Subscribers agree to use the Epic Compliance Engine strictly for its intended purpose of accessibility auditing and reporting. To protect the security and integrity of the platform, you are explicitly prohibited from:
- Reverse-engineering, decompiling, or attempting to extract the proprietary source code or evaluation logic of the Matrix Engine.
- Bypassing or attempting to manipulate the Role-Based Access Control (RBAC) restrictions.
- Sharing individual user credentials across multiple team members to bypass per-seat licensing requirements.
- Deploying automated scraping tools, headless browsers, or aggressive API polling against the SaaS endpoints.
Violation of these integrity terms may result in immediate account suspension or termination without refund.
7. Security Firewalls & Automated Lockout Protocols
To ensure the uncompromising security of our infrastructure, Epicpaths employs active Web Application Firewalls (WAF) that continuously scan all uploaded vault files for malicious executable signatures, scripts, or unauthorized payloads.
The 3-Strike Escalation Protocol: Security violations are managed via a rigid, automated escalation path:
- Strike 1 (Educational Warning): The payload is destroyed, and the user receives a dashboard warning and email alert.
- Strike 2 (Critical Warning): The payload is destroyed, and a final warning is issued.
- Strike 3 (Software Lockout): The payload is destroyed, and the user's software access is instantly and automatically suspended pending administrative review.
"Rolling Window & Accidental Triggers: We recognize that automated diagnostic scanners may accidentally export raw executable code (such as <script> or <?php> tags) directly from a target website's DOM. If you receive a Strike 1 warning due to an accidental export, please sanitize your file before retrying. To protect users from permanent penalties for honest mistakes, all security strikes expire and are cleared from your record after a rolling 365-day window."
Seat-Level vs. Tenant-Level Lockouts: For Enterprise multi-seat accounts, a Strike 3 violation by an invited staff member (e.g., a Junior Tester or Editor) will result in an immediate Seat-Level Lockout, restricting that specific user's access while the parent organization's billing and primary workspace remain fully active. Conversely, Primary Account Owners and Solo Auditors who reach Strike 3 face a Tenant-Level Lockout, suspending the entire organizational subscription.
Disputes & Forfeiture: All automated lockouts are subject to administrative review. Account Administrators must contact security@epicpaths.com to resolve seat lockouts, dispute false positives, or request a manual strike reset. If an account or subscription is permanently terminated following a manual administrative review of a Strike 3 lockout, the termination is effective immediately, and the subscriber explicitly forfeits any right to a prorated or full refund for the remainder of their active billing cycle.
8. Payments, Subscriptions, and Access
All paid subscriptions are processed securely through our authorized Merchant of Record. Epicpaths does not directly process or store your credit card information. Subscription fees are billed in advance on a recurring schedule. If a payment method fails, your account access may be restricted or suspended until the balance is resolved. During any payment-related suspension, your data remains secure subject to our standard 30-day archival policy. We do not offer prorated refunds for mid-cycle cancellations.
9. Service Availability & "As-Is" Warranty
While we architect the platform for high availability and strive for 99.9% uptime, the Epic Compliance Engine is provided on an "As-Is" and "As-Available" basis. We do not warrant that the service will be entirely error-free or uninterrupted. Epicpaths reserves the right to perform scheduled maintenance, system upgrades, or emergency patching, which may result in temporary service interruptions. Epicpaths is not liable for any loss of revenue, delayed audits, or missed client deadlines resulting from platform downtime.
10. Limitation of SaaS Liability
To the maximum extent permitted by applicable law, Epicpaths' and Matthew Dempsey's total aggregate liability arising out of or related to your use of the Epic Compliance Engine—whether in contract, tort, or otherwise—shall not exceed the total amount paid by you (or your organization) for the SaaS subscription during the twelve (12) months immediately preceding the event giving rise to the claim.