Draft for solicitor review — published for transparency. Not legal advice. Enterprise customers should execute the MSA and DPA. Last updated: 2026-07-23.

Product Liability & Tooling Risks

Discovery, assessment, migration, and M&A IT platforms (including ACQI) do powerful things: they authenticate into real environments, read identity and infrastructure data, sometimes change systems during migration, and produce outputs people may use to price deals or cut over production. That power creates liability. This page states how ACQI allocates that risk, what you remain responsible for, and what no vendor in this category can honestly guarantee.

Placeholders pending
  • {{EFFECTIVE_DATE}} — to be confirmed before final publication
  • {{INSURANCE_AMOUNT_LIMIT}} — to be confirmed before final publication
  • {{LAST_UPDATED}} — to be confirmed before final publication

Page is published for transparency; founder will fill these before the final version goes out under counsel review.

# Product Liability & Tooling Risks

.Discovery, assessment, migration, and M&A IT platforms (including ACQI)

Effective date: {{EFFECTIVE_DATE}} Last updated: {{LAST_UPDATED}} Provider: ACQI.AI LTD

Plain English. Tools like ACQI, cloud migration assessors, CMDB/discovery platforms, and M&A diligence software do powerful things: they authenticate into real environments, read identity and infrastructure data, sometimes change systems during migration, and produce outputs people may use to price deals or cut over production. That power creates liability. This page states how ACQI allocates that risk, what you remain responsible for, and what no vendor in this category can honestly guarantee.

Public companion pages: Terms · Acceptable Use · Privacy · DPA · AI · Security · MSA

---

0.Executive risk map (read this first)

Risk class Who primarily bears it Why
Incomplete discovery / false negatives Customer (professional reliance) No scanner sees everything; outputs are assistive, not a warranty of completeness
False positives / wrong risk rankings Customer Heuristics and partial API data mislead; humans must validate
Deal pricing / go–no-go decisions Customer / advisers ACQI is not your financial adviser, auditor, or legal counsel
Personal data processing lawfulness Customer as controller (ACQI as processor only when contracted) You decide what estate to scan and on what legal basis
Credential theft from endpoint Customer (endpoint security) Desktop-first means secrets live where you run the client
Migration / cutover failure Customer (ops ownership); ACQI limited by MSA Production changes are high-stakes; software assists, does not own your estate
AI hallucination / bad advice Customer AI is assistive; mandatory human review
Clean-team / antitrust leakage Customer / deal counsel Tooling does not replace information barriers
Third-party API / cloud provider outages & ToS Shared; customer for provider relationship Microsoft/AWS/etc. terms and quotas apply to your tenants
Platform defects (bugs in our code) ACQI within contractual liability caps Subject to disclaimers, caps, and exclusions in Terms/MSA
ACQI IP infringement of third parties ACQI (IP indemnity in MSA, if signed) Standard software indemnity pattern
Regulatory fines (ICO, etc.) for customer estate Controller (usually customer) Fines follow the controller’s decisions and notices

Core rule: ACQI provides software tools and optional services. It does not assume the role of system owner, data controller of your IT estate (except as processor under a DPA), M&A adviser, auditor, or insurer of deal outcomes.

---

1.What this category of tooling actually does (liability-relevant)

1.1 Typical capabilities (ACQI and peers)

Capability Liability implication
Inventory of users, groups, devices, mailboxes, apps, VMs, policies, dependencies Creates personal data and commercially sensitive datasets
Risk / gap / licensing / posture signals Easy to over-trust; still estimates and heuristics
Migration planning, waves, gates, execution helpers Can touch production identity and workloads
AI co-pilot (ARIA-class) Can invent confident wrong answers from partial context
Governance / synergy / compliance workspaces Records decisions; does not discharge your legal duties

1.2 What the tooling is not

  • Not a substitute for legal due diligence, financial DD, or board advice
  • Not a penetration test or red-team engagement (unless separately scoped and authorised as such)
  • Not a guarantee that shadow IT, latent debt, licence exposure, or security gaps are fully known
  • Not insurance against post-close surprises
  • Not authorisation to access a target company’s systems without the target’s (or lawful) consent

---

2.Unauthorised access & computer misuse (highest criminal / civil exposure)

2.1 The risk

Discovery modules that log in, query directories, read configs, or pull inventories are access to computer systems. Without proper authorisation this can engage:

Jurisdiction (examples) Risk frame
US Computer Fraud and Abuse Act (CFAA) and state analogues; contract / tort
EU / other National cybercrime laws implementing Budapest Convention themes; civil liability

M&A nuance: Pre-signing diligence often wants target visibility. Wanting it is not the same as being authorised. Authority typically comes from the target, a signed diligence protocol, reverse diligence rights in a SPA, or your own estate post-close—not from buying a scanner.

2.2 Allocation (ACQI position)

  1. You warrant you have all rights and authorisations for every host, tenant, domain, and API you target.
  2. You warrant individual operators are permitted by your organisation (and by any target/client) to run scans.
  3. You indemnify ACQI against claims arising from unauthorised or excessive scanning, credential misuse, or scanning outside agreed scope.
  4. ACQI may suspend use if we reasonably believe the Services are being used for unlawful access.
  5. ACQI is not your counsel on whether a particular LOI/NDA permits technical scanning.

2.3 Operational controls you must implement

  • Written scope (systems, OUs, subscriptions, exclusions)
  • Named approver at customer and, where applicable, at target
  • Least-privilege service principals; time-boxed credentials; no shared personal admin passwords in chat
  • Logging of who ran what scan when
  • Clean-team segregation if antitrust / competitive sensitivity applies
  • Stop rules if production impact or lockouts appear

2.4 Website / contract language (canonical)

Customer is solely responsible for obtaining and documenting all authorisations required to access and process systems and data using the Services. Unauthorised use may be a criminal offence. ACQI does not authorise access to any third-party system.

---

3.Discovery incompleteness, false confidence, and deal reliance

3.1 Why “complete discovery” is not warrantable

Even broad tooling fails closed or blind when:

Limitation Example
Network segmentation / air gaps On-prem forests unreachable
API / licence gaps Graph permissions not granted
Shadow IT outside known IdPs Personal SaaS, rogue cloud accounts
Stale or partial inventory sources CMDB lies; DHCP churn
Timing Estate changes after the scan
Intentional concealment Target omits systems from scope
Product bugs or parser limits Edge-case objects skipped
Non-Microsoft / niche systems Coverage uneven by design

Industry truth: Post-close IT surprises remain common even with good tooling. Tools reduce uncertainty; they do not eliminate it. Marketing that implies elimination (“zero blind spots”) creates misrepresentation and warranty risk for the vendor—ACQI rejects that framing.

3.2 Allocation

Claim type ACQI liability stance
“We overpaid because discovery missed licence debt” Customer / adviser reliance risk; not ACQI’s deal economics
“Dashboard said green / low risk” Scores and heatmaps are indicative, not audit opinions
Undisputed software defect causing wrong export format when data was available May fall under ordinary product defect—subject to liability cap

3.3 Reliance disclaimer (canonical — use on product pages + Terms)

Outputs of the Services (including inventories, risk scores, licence estimates, dependency maps, readiness indicators, and AI-generated narratives) are provided for professional informational purposes only. They may be incomplete, outdated, or incorrect. You must independently verify material findings before making investment, valuation, signing, closing, cutover, security, employment, or compliance decisions. ACQI is not responsible for decisions made in reliance on the Services without such verification.

3.4 No auditor / no adviser

ACQI does not provide:

  • ISAE / SOC attestation of your environment
  • Legal opinions on GDPR/NIS2/DORA applicability
  • Fairness opinions on purchase price
  • “Clean bill of health” letters for lenders or boards

If customers need assurance, they engage counsel, Big4, or independent assessors—and may use ACQI as one input.

---

4.Personal data, confidentiality, and regulatory liability

4.1 What discovery often touches

Employee names, UPNs, emails, manager chains, device names, IPs, group memberships, MFA status, mailbox metadata, app assignments, sometimes more sensitive attributes depending on module and permissions.

That is typically personal data (UK GDPR / EU GDPR) and often confidential under NDA / employment obligations.

4.2 Role split (liability-critical)

Party Role Primary duties
ACQI (when we host/process that data) Processor under DPA Only on instructions; security; subprocessors; breach assist
ACQI (website leads, accounts) Controller Own privacy notice
Desktop-local only (data never to ACQI) Customer controls processing Customer’s policies dominate; ACQI still supplies software

Fines and data-subject claims for unlawful diligence scanning generally track the controller’s choices (scope, notice, retention, sharing with bidders). ACQI’s exposure is mainly: processor breach of DPA, security failure on systems we control, or acting outside instructions.

4.3 High-risk data classes (customer must gate)

Do not aim discovery tooling at the following without specialist legal + security design:

  • Unrestricted PHI / health records (HIPAA / UK health data)
  • Cardholder data environments (PCI)
  • Children’s data
  • Special category data (Art 9) unless strictly necessary and lawful
  • ITAR / export-controlled technical data
  • Content of mailboxes/files beyond metadata unless explicitly in scope and lawful

Default product posture: inventory and metadata-oriented diligence—not unrestricted content exfiltration.

4.4 Retention & spill risk

Discovery exports (CSV, JSON, screenshots, AI chats) become portable diligence files. Liability often arises from:

  • Leaving full AD exports on laptops or VDR without controls
  • Emailing inventories to too wide a deal list
  • Retaining target data after deal death / clean-team expiry

Customer owns retention decisions. ACQI DPA deletion assists for our copies only.

---

5.Credentials, secrets, and endpoint liability

5.1 Desktop-first model

ACQI is designed so target credentials remain on the operator endpoint (OS credential protection where available). That reduces ACQI-side secret custody risk but increases customer endpoint risk.

5.2 Allocation

Event Typical bearer
Phishing of operator who pastes secrets into AI chat Customer (and possible shared process failure)
ACQI cloud breach of hosted account data ACQI (within security obligations + caps)
Malware on endpoint capturing DPAPI material Customer environment
Over-privileged credential used for ransomware lateral movement after scan Customer ops / design of service accounts

5.3 Customer obligations (contractual)

  • Patch and encrypt endpoints
  • Prefer managed service principals over god-mode human admins
  • Rotate secrets after engagement
  • Never place production credentials in support tickets, screenshots, or AI prompts
  • Control who can install/run the client

---

6.Migration, cutover, and change-inducing features

6.1 Risk

Migration and remediation features (mailbox moves, identity mapping, policy changes, device actions, batch retries) can cause:

  • Data loss or dual-write inconsistency
  • Authentication outages
  • Licence / compliance breakage
  • Irreversible production impact
  • Missed rollback windows

6.2 Allocation

Principle Statement
No outcome warranty ACQI does not warrant successful migration of any object, user, or workload
Pre-production validation Customer must test in non-production where feasible
Third-party limits Graph throttling, provider bugs, and tenant misconfig are outside ACQI control
Stop authority Customer must be able to halt automation; operators must be trained
Professional services If ACQI staff assist, scope is SOW-bound; still not a takeover of your change board unless expressly written

6.3 Canonical disclaimer

Any migration, remediation, or write operation performed using the Services is executed under your direction and credentials. You are solely responsible for change control, backups, rollback plans, user communications, and verifying post-change state. ACQI is not liable for production outages, data loss, or business interruption arising from migration or configuration changes except to the extent caused by ACQI’s wilful misconduct or as non-excludable by law, and subject always to the liability cap in the applicable agreement.

---

7.AI co-pilot liability (ARIA-class features)

See also AI Features Disclosure.

Failure mode Liability stance
Suggested “delete / migrate / remediate” steps that break production Customer change control; AI is not an approver
Prompt injection from untrusted content in context Shared; customer controls what context is attached
Leak of secrets pasted into prompts to model provider Customer act; subprocessors process under DPA/config
Employment or redundancy suggestions treated as automated decision Customer Art 22 / employment law risk

Rule: AI outputs are draft assistance, not instructions you are entitled to trust blindly.

---

8.Competitive / clean-team / antitrust liability

In auctions and competitor deals, scanning and dashboards can create information hazards:

  • Buyer personnel seeing competitively sensitive target data outside clean team
  • Sharing heatmaps with too many people
  • Using target data for purposes beyond diligence (gun-jumping themes)

ACQI does not implement your antitrust protocol for you. Product features (access control, blackout windows where present) are aids—not legal clearance.

Customer counsel owns:

  • Clean-team agreements
  • Who may see which outputs
  • Sequencing of integration planning vs closing

---

9.Third-party platforms, licensing, and ToS

9.1 Cloud & SaaS providers

Your use of Microsoft, AWS, Google, VMware, security vendors, etc. is under their terms. Risks:

  • Violation of provider acceptable use by aggressive automation
  • API revocation / throttling
  • Audit findings that a service principal was over-privileged
  • Licence non-compliance revealed by tooling (the liability for under-licensing is usually already yours)

9.2 ACQI does not

  • Transfer provider licences to you
  • Warrant your licence position with Microsoft/Oracle/etc. (estimates are indicative)
  • Defend you in a vendor licence audit except as expressly agreed in a SOW

---

10.Security incidents and breach liability

Scenario Framework
Breach solely in customer environment / endpoint Customer incident
Joint contributory failure Fact-specific; contracts allocate via caps and indemnities
Vulnerability in ACQI software actively exploited ACQI security response; liability still capped unless fraud/wilful misconduct

No silent assumption of unlimited data-protection liability in public Terms; MSA negotiation may set a super-cap (e.g. 2–3× annual fees) per counsel—not uncapped by default for a tooling vendor.

---

11.Warranty stack (what we give / refuse)

11.1 Typical limited warranties (MSA / Terms)

  • Authority to grant the licence
  • Services provided with reasonable care and skill
  • Material conformity to Documentation for a limited remedy period (if MSA says so)

11.2 Expressly refused (category-standard; ACQI adopts)

Refused warranty Rationale
Fitness for a particular deal decision Customer’s investment judgement
Error-free / uninterrupted operation Software reality
Merchantability (to extent excludable) Standard
Third-party certification (SOC2/ISO) unless scheduled Honesty
Non-infringement of customer’s misuse patterns Customer indemnity
AI accuracy Model limits
Migration success Ops reality
Compliance of customer’s estate with law Customer controller duties

11.3 “As is” evaluation

Free/beta/evaluation use is as is, maximum disclaimer permitted by law, low liability cap (e.g. £100 or fees paid).

---

12.Liability caps & excluded damages (public Terms pattern)

Align website Terms and MSA:

Excluded (to max extent permitted by law): indirect, incidental, special, consequential, punitive damages; lost profits; lost revenue; lost goodwill; cost of substitute systems; deal value leakage; failed synergies; purchase-price adjustment; lost financing; reputational harm; cost of re-running diligence with third parties—even if advised of possibility.

Cap: fees paid in prior 12 months (or £100 if none), except:

  • Death/personal injury by negligence
  • Fraud / fraudulent misrepresentation
  • Other liability that English law does not allow to be limited
  • (MSA only) negotiated carve-outs: confidentiality breach, IP indemnity, data protection super-cap

Why deal-value damages are excluded: Allowing recovery of “we overpaid by £40m because module X missed a mainframe” would make tooling economics impossible and is not how this product category is sold.

---

13.Indemnities (direction of risk)

13.1 Customer → ACQI (required)

Customer indemnifies ACQI for third-party claims arising from:

  1. Unauthorised scanning or access
  2. Customer Data (IP, privacy, defamation, regulatory)
  3. Use outside AUP / law
  4. Combination of Services with customer’s unlawful instructions
  5. Employment / monitoring claims from employees in scanned estates
  6. Migration changes directed by customer

13.2 ACQI → Customer (MSA; not unlimited on website eval)

Typical:

  1. Third-party claim that the unmodified Platform IP infringes copyright/patent (with standard exclusions: customer mods, combo use, outdated versions)
  2. Not: indemnify for “you lost the deal” or “ICO fined you for lacking employee notice”

---

14.Insurance (operational, not a website promise)

Customers should maintain cyber, professional indemnity, and crime cover appropriate to M&A diligence. ACQI should maintain PI / cyber appropriate to SaaS+desktop tooling (amounts in MSA as {{INSURANCE_AMOUNT_LIMIT}}). Insurance is not a warranty and does not expand contractual liability.

---

15.Sector-specific liability notes

Sector Extra care
Healthcare BAA / UK health data rules before PHI-adjacent scans
Public sector Procurement, data residency, OFFICIAL handling
Defence / export Do not scan ITAR estates without licences
Multi-bidder M&A Clean team; purpose limitation

---

16.Competitor-category framing (for counsel & sales honesty)

Tools overlapping ACQI (Device42, Virima, Firefly, BMC Discovery, Azure Migrate, Quest, ShareGate, BitTitan, Axonius, Lansweeper, deal tech platforms with tech modules, consultancies’ scanners) share the same structural liabilities:

  1. They act under customer credentials
  2. They produce incomplete maps of complex estates
  3. Customers over-trust dashboards in deal heat
  4. Vendors that promise certainty create the worst liability

ACQI’s differentiation must never be “we eliminate liability.” Differentiation is depth + M&A workflow + desktop-first credential posture + honest limits.

---

17.Customer checklist (publish as “Responsible use”)

Before production scans:

  • [ ] Legal basis and authorisation documented (own estate vs target)
  • [ ] NDA / clean-team / SPA diligence rights reviewed by counsel
  • [ ] Scope written (inclusions/exclusions)
  • [ ] Least-privilege credentials issued and time-boxed
  • [ ] DPIA considered if large-scale employee monitoring/discovery
  • [ ] Data handling rules for exports (VDR, encryption, retention)
  • [ ] Named human owners for Go/No-Go on any write/migration action
  • [ ] AI features policy (what may be pasted)
  • [ ] Incident contacts and stop procedures
  • [ ] MSA + DPA executed if ACQI will receive personal data

---

18.Canonical clause pack (for counsel to drop into MSA/Terms)

18.1 High-risk activities acknowledgement

Customer acknowledges that the Services enable high-risk activities including authenticated access to IT systems, bulk extraction of configuration and identity data, automated analysis, optional AI assistance, and (where licensed) migration or configuration changes. Customer assumes operational and legal risk for those activities except as expressly allocated to ACQI in this Agreement.

18.2 No reliance for transaction decisions

Customer agrees that it will not rely solely on the Services for any merger, acquisition, investment, financing, valuation, signing, closing, or material remediation decision, and that ACQI has no liability for any purchase price, indemnity claim, earn-out, synergy shortfall, or similar economic outcome.

18.3 Professional users only

The Services are designed for use by trained IT, security, and M&A technology professionals. Customer shall ensure users are competent and supervised.

18.4 Mitigation duty

Customer shall take reasonable steps to mitigate loss, including maintaining backups before migration features are used and promptly notifying ACQI of suspected product defects.

---

19.What the public website should say (Luna — short page)

Recommended /legal/product-risks summary (link from Terms + Security + footer “Product risks”):

  1. You must be authorised to scan.
  2. Discovery is not complete by nature.
  3. Verify before you sign, close, or cut over.
  4. You own change control for migrations.
  5. AI is assistive only.
  6. Privacy roles: you control estate data; DPA when we process it.
  7. Liability caps and no deal-value damages apply.
  8. Full terms in Terms/MSA.

Do not turn this internal memo’s criminal-law discussion into scary marketing; keep the public page calm, clear, and firm.

---

20.Solicitor review flags (do not skip)

  1. Computer Misuse Act / CFAA wording—confirm jurisdiction coverage for your customer base.
  2. Whether unlimited vs super-cap DP liability is commercially viable (legal review already warned uncapped DP is dangerous for this product).
  3. UCTA / CRA reasonableness of caps for any non-enterprise users (B2B focus helps).
  4. Sector addenda (HIPAA BAA, DORA exhibits).
  5. Alignment of this page with final executed MSA after incorporation-pack defects are fixed.

---

21.Document control

Version Date Notes

Not legal advice. For ACQI.AI LTD internal + counsel use; public derivative at /legal/product-risks.

Entity block
ACQI.AI LTD
Private limited company registered in England and Wales
Company number: [to be confirmed]
Registered office: [to be confirmed]
Contact: hello@acqi.ai

The ACQI platform intellectual property is owned by ACQI HOLDINGS LTD and licensed to ACQI.AI LTD for customer delivery.