Product Liability & Tooling Risks
Discovery, assessment, migration, and M&A IT platforms (including ACQI) do powerful things: they authenticate into real environments, read identity and infrastructure data, sometimes change systems during migration, and produce outputs people may use to price deals or cut over production. That power creates liability. This page states how ACQI allocates that risk, what you remain responsible for, and what no vendor in this category can honestly guarantee.
{{EFFECTIVE_DATE}}— to be confirmed before final publication{{INSURANCE_AMOUNT_LIMIT}}— to be confirmed before final publication{{LAST_UPDATED}}— to be confirmed before final publication
Page is published for transparency; founder will fill these before the final version goes out under counsel review.
# Product Liability & Tooling Risks
.Discovery, assessment, migration, and M&A IT platforms (including ACQI)
Effective date: {{EFFECTIVE_DATE}} Last updated: {{LAST_UPDATED}} Provider: ACQI.AI LTD
Plain English. Tools like ACQI, cloud migration assessors, CMDB/discovery platforms, and M&A diligence software do powerful things: they authenticate into real environments, read identity and infrastructure data, sometimes change systems during migration, and produce outputs people may use to price deals or cut over production. That power creates liability. This page states how ACQI allocates that risk, what you remain responsible for, and what no vendor in this category can honestly guarantee.
Public companion pages: Terms · Acceptable Use · Privacy · DPA · AI · Security · MSA
---
0.Executive risk map (read this first)
| Risk class | Who primarily bears it | Why |
|---|---|---|
| Incomplete discovery / false negatives | Customer (professional reliance) | No scanner sees everything; outputs are assistive, not a warranty of completeness |
| False positives / wrong risk rankings | Customer | Heuristics and partial API data mislead; humans must validate |
| Deal pricing / go–no-go decisions | Customer / advisers | ACQI is not your financial adviser, auditor, or legal counsel |
| Personal data processing lawfulness | Customer as controller (ACQI as processor only when contracted) | You decide what estate to scan and on what legal basis |
| Credential theft from endpoint | Customer (endpoint security) | Desktop-first means secrets live where you run the client |
| Migration / cutover failure | Customer (ops ownership); ACQI limited by MSA | Production changes are high-stakes; software assists, does not own your estate |
| AI hallucination / bad advice | Customer | AI is assistive; mandatory human review |
| Clean-team / antitrust leakage | Customer / deal counsel | Tooling does not replace information barriers |
| Third-party API / cloud provider outages & ToS | Shared; customer for provider relationship | Microsoft/AWS/etc. terms and quotas apply to your tenants |
| Platform defects (bugs in our code) | ACQI within contractual liability caps | Subject to disclaimers, caps, and exclusions in Terms/MSA |
| ACQI IP infringement of third parties | ACQI (IP indemnity in MSA, if signed) | Standard software indemnity pattern |
| Regulatory fines (ICO, etc.) for customer estate | Controller (usually customer) | Fines follow the controller’s decisions and notices |
Core rule: ACQI provides software tools and optional services. It does not assume the role of system owner, data controller of your IT estate (except as processor under a DPA), M&A adviser, auditor, or insurer of deal outcomes.
---
1.What this category of tooling actually does (liability-relevant)
1.1 Typical capabilities (ACQI and peers)
| Capability | Liability implication |
|---|---|
| Inventory of users, groups, devices, mailboxes, apps, VMs, policies, dependencies | Creates personal data and commercially sensitive datasets |
| Risk / gap / licensing / posture signals | Easy to over-trust; still estimates and heuristics |
| Migration planning, waves, gates, execution helpers | Can touch production identity and workloads |
| AI co-pilot (ARIA-class) | Can invent confident wrong answers from partial context |
| Governance / synergy / compliance workspaces | Records decisions; does not discharge your legal duties |
1.2 What the tooling is not
- Not a substitute for legal due diligence, financial DD, or board advice
- Not a penetration test or red-team engagement (unless separately scoped and authorised as such)
- Not a guarantee that shadow IT, latent debt, licence exposure, or security gaps are fully known
- Not insurance against post-close surprises
- Not authorisation to access a target company’s systems without the target’s (or lawful) consent
---
2.Unauthorised access & computer misuse (highest criminal / civil exposure)
2.1 The risk
Discovery modules that log in, query directories, read configs, or pull inventories are access to computer systems. Without proper authorisation this can engage:
| Jurisdiction (examples) | Risk frame |
|---|---|
| US | Computer Fraud and Abuse Act (CFAA) and state analogues; contract / tort |
| EU / other | National cybercrime laws implementing Budapest Convention themes; civil liability |
M&A nuance: Pre-signing diligence often wants target visibility. Wanting it is not the same as being authorised. Authority typically comes from the target, a signed diligence protocol, reverse diligence rights in a SPA, or your own estate post-close—not from buying a scanner.
2.2 Allocation (ACQI position)
- You warrant you have all rights and authorisations for every host, tenant, domain, and API you target.
- You warrant individual operators are permitted by your organisation (and by any target/client) to run scans.
- You indemnify ACQI against claims arising from unauthorised or excessive scanning, credential misuse, or scanning outside agreed scope.
- ACQI may suspend use if we reasonably believe the Services are being used for unlawful access.
- ACQI is not your counsel on whether a particular LOI/NDA permits technical scanning.
2.3 Operational controls you must implement
- Written scope (systems, OUs, subscriptions, exclusions)
- Named approver at customer and, where applicable, at target
- Least-privilege service principals; time-boxed credentials; no shared personal admin passwords in chat
- Logging of who ran what scan when
- Clean-team segregation if antitrust / competitive sensitivity applies
- Stop rules if production impact or lockouts appear
2.4 Website / contract language (canonical)
Customer is solely responsible for obtaining and documenting all authorisations required to access and process systems and data using the Services. Unauthorised use may be a criminal offence. ACQI does not authorise access to any third-party system.
---
3.Discovery incompleteness, false confidence, and deal reliance
3.1 Why “complete discovery” is not warrantable
Even broad tooling fails closed or blind when:
| Limitation | Example |
|---|---|
| Network segmentation / air gaps | On-prem forests unreachable |
| API / licence gaps | Graph permissions not granted |
| Shadow IT outside known IdPs | Personal SaaS, rogue cloud accounts |
| Stale or partial inventory sources | CMDB lies; DHCP churn |
| Timing | Estate changes after the scan |
| Intentional concealment | Target omits systems from scope |
| Product bugs or parser limits | Edge-case objects skipped |
| Non-Microsoft / niche systems | Coverage uneven by design |
Industry truth: Post-close IT surprises remain common even with good tooling. Tools reduce uncertainty; they do not eliminate it. Marketing that implies elimination (“zero blind spots”) creates misrepresentation and warranty risk for the vendor—ACQI rejects that framing.
3.2 Allocation
| Claim type | ACQI liability stance |
|---|---|
| “We overpaid because discovery missed licence debt” | Customer / adviser reliance risk; not ACQI’s deal economics |
| “Dashboard said green / low risk” | Scores and heatmaps are indicative, not audit opinions |
| Undisputed software defect causing wrong export format when data was available | May fall under ordinary product defect—subject to liability cap |
3.3 Reliance disclaimer (canonical — use on product pages + Terms)
Outputs of the Services (including inventories, risk scores, licence estimates, dependency maps, readiness indicators, and AI-generated narratives) are provided for professional informational purposes only. They may be incomplete, outdated, or incorrect. You must independently verify material findings before making investment, valuation, signing, closing, cutover, security, employment, or compliance decisions. ACQI is not responsible for decisions made in reliance on the Services without such verification.
3.4 No auditor / no adviser
ACQI does not provide:
- ISAE / SOC attestation of your environment
- Legal opinions on GDPR/NIS2/DORA applicability
- Fairness opinions on purchase price
- “Clean bill of health” letters for lenders or boards
If customers need assurance, they engage counsel, Big4, or independent assessors—and may use ACQI as one input.
---
4.Personal data, confidentiality, and regulatory liability
4.1 What discovery often touches
Employee names, UPNs, emails, manager chains, device names, IPs, group memberships, MFA status, mailbox metadata, app assignments, sometimes more sensitive attributes depending on module and permissions.
That is typically personal data (UK GDPR / EU GDPR) and often confidential under NDA / employment obligations.
4.2 Role split (liability-critical)
| Party | Role | Primary duties |
|---|---|---|
| ACQI (when we host/process that data) | Processor under DPA | Only on instructions; security; subprocessors; breach assist |
| ACQI (website leads, accounts) | Controller | Own privacy notice |
| Desktop-local only (data never to ACQI) | Customer controls processing | Customer’s policies dominate; ACQI still supplies software |
Fines and data-subject claims for unlawful diligence scanning generally track the controller’s choices (scope, notice, retention, sharing with bidders). ACQI’s exposure is mainly: processor breach of DPA, security failure on systems we control, or acting outside instructions.
4.3 High-risk data classes (customer must gate)
Do not aim discovery tooling at the following without specialist legal + security design:
- Unrestricted PHI / health records (HIPAA / UK health data)
- Cardholder data environments (PCI)
- Children’s data
- Special category data (Art 9) unless strictly necessary and lawful
- ITAR / export-controlled technical data
- Content of mailboxes/files beyond metadata unless explicitly in scope and lawful
Default product posture: inventory and metadata-oriented diligence—not unrestricted content exfiltration.
4.4 Retention & spill risk
Discovery exports (CSV, JSON, screenshots, AI chats) become portable diligence files. Liability often arises from:
- Leaving full AD exports on laptops or VDR without controls
- Emailing inventories to too wide a deal list
- Retaining target data after deal death / clean-team expiry
Customer owns retention decisions. ACQI DPA deletion assists for our copies only.
---
5.Credentials, secrets, and endpoint liability
5.1 Desktop-first model
ACQI is designed so target credentials remain on the operator endpoint (OS credential protection where available). That reduces ACQI-side secret custody risk but increases customer endpoint risk.
5.2 Allocation
| Event | Typical bearer |
|---|---|
| Phishing of operator who pastes secrets into AI chat | Customer (and possible shared process failure) |
| ACQI cloud breach of hosted account data | ACQI (within security obligations + caps) |
| Malware on endpoint capturing DPAPI material | Customer environment |
| Over-privileged credential used for ransomware lateral movement after scan | Customer ops / design of service accounts |
5.3 Customer obligations (contractual)
- Patch and encrypt endpoints
- Prefer managed service principals over god-mode human admins
- Rotate secrets after engagement
- Never place production credentials in support tickets, screenshots, or AI prompts
- Control who can install/run the client
---
6.Migration, cutover, and change-inducing features
6.1 Risk
Migration and remediation features (mailbox moves, identity mapping, policy changes, device actions, batch retries) can cause:
- Data loss or dual-write inconsistency
- Authentication outages
- Licence / compliance breakage
- Irreversible production impact
- Missed rollback windows
6.2 Allocation
| Principle | Statement |
|---|---|
| No outcome warranty | ACQI does not warrant successful migration of any object, user, or workload |
| Pre-production validation | Customer must test in non-production where feasible |
| Third-party limits | Graph throttling, provider bugs, and tenant misconfig are outside ACQI control |
| Stop authority | Customer must be able to halt automation; operators must be trained |
| Professional services | If ACQI staff assist, scope is SOW-bound; still not a takeover of your change board unless expressly written |
6.3 Canonical disclaimer
Any migration, remediation, or write operation performed using the Services is executed under your direction and credentials. You are solely responsible for change control, backups, rollback plans, user communications, and verifying post-change state. ACQI is not liable for production outages, data loss, or business interruption arising from migration or configuration changes except to the extent caused by ACQI’s wilful misconduct or as non-excludable by law, and subject always to the liability cap in the applicable agreement.
---
7.AI co-pilot liability (ARIA-class features)
See also AI Features Disclosure.
| Failure mode | Liability stance |
|---|---|
| Suggested “delete / migrate / remediate” steps that break production | Customer change control; AI is not an approver |
| Prompt injection from untrusted content in context | Shared; customer controls what context is attached |
| Leak of secrets pasted into prompts to model provider | Customer act; subprocessors process under DPA/config |
| Employment or redundancy suggestions treated as automated decision | Customer Art 22 / employment law risk |
Rule: AI outputs are draft assistance, not instructions you are entitled to trust blindly.
---
8.Competitive / clean-team / antitrust liability
In auctions and competitor deals, scanning and dashboards can create information hazards:
- Buyer personnel seeing competitively sensitive target data outside clean team
- Sharing heatmaps with too many people
- Using target data for purposes beyond diligence (gun-jumping themes)
ACQI does not implement your antitrust protocol for you. Product features (access control, blackout windows where present) are aids—not legal clearance.
Customer counsel owns:
- Clean-team agreements
- Who may see which outputs
- Sequencing of integration planning vs closing
---
9.Third-party platforms, licensing, and ToS
9.1 Cloud & SaaS providers
Your use of Microsoft, AWS, Google, VMware, security vendors, etc. is under their terms. Risks:
- Violation of provider acceptable use by aggressive automation
- API revocation / throttling
- Audit findings that a service principal was over-privileged
- Licence non-compliance revealed by tooling (the liability for under-licensing is usually already yours)
9.2 ACQI does not
- Transfer provider licences to you
- Warrant your licence position with Microsoft/Oracle/etc. (estimates are indicative)
- Defend you in a vendor licence audit except as expressly agreed in a SOW
---
10.Security incidents and breach liability
| Scenario | Framework |
|---|---|
| Breach solely in customer environment / endpoint | Customer incident |
| Joint contributory failure | Fact-specific; contracts allocate via caps and indemnities |
| Vulnerability in ACQI software actively exploited | ACQI security response; liability still capped unless fraud/wilful misconduct |
No silent assumption of unlimited data-protection liability in public Terms; MSA negotiation may set a super-cap (e.g. 2–3× annual fees) per counsel—not uncapped by default for a tooling vendor.
---
11.Warranty stack (what we give / refuse)
11.1 Typical limited warranties (MSA / Terms)
- Authority to grant the licence
- Services provided with reasonable care and skill
- Material conformity to Documentation for a limited remedy period (if MSA says so)
11.2 Expressly refused (category-standard; ACQI adopts)
| Refused warranty | Rationale |
|---|---|
| Fitness for a particular deal decision | Customer’s investment judgement |
| Error-free / uninterrupted operation | Software reality |
| Merchantability (to extent excludable) | Standard |
| Third-party certification (SOC2/ISO) unless scheduled | Honesty |
| Non-infringement of customer’s misuse patterns | Customer indemnity |
| AI accuracy | Model limits |
| Migration success | Ops reality |
| Compliance of customer’s estate with law | Customer controller duties |
11.3 “As is” evaluation
Free/beta/evaluation use is as is, maximum disclaimer permitted by law, low liability cap (e.g. £100 or fees paid).
---
12.Liability caps & excluded damages (public Terms pattern)
Align website Terms and MSA:
Excluded (to max extent permitted by law): indirect, incidental, special, consequential, punitive damages; lost profits; lost revenue; lost goodwill; cost of substitute systems; deal value leakage; failed synergies; purchase-price adjustment; lost financing; reputational harm; cost of re-running diligence with third parties—even if advised of possibility.
Cap: fees paid in prior 12 months (or £100 if none), except:
- Death/personal injury by negligence
- Fraud / fraudulent misrepresentation
- Other liability that English law does not allow to be limited
- (MSA only) negotiated carve-outs: confidentiality breach, IP indemnity, data protection super-cap
Why deal-value damages are excluded: Allowing recovery of “we overpaid by £40m because module X missed a mainframe” would make tooling economics impossible and is not how this product category is sold.
---
13.Indemnities (direction of risk)
13.1 Customer → ACQI (required)
Customer indemnifies ACQI for third-party claims arising from:
- Unauthorised scanning or access
- Customer Data (IP, privacy, defamation, regulatory)
- Use outside AUP / law
- Combination of Services with customer’s unlawful instructions
- Employment / monitoring claims from employees in scanned estates
- Migration changes directed by customer
13.2 ACQI → Customer (MSA; not unlimited on website eval)
Typical:
- Third-party claim that the unmodified Platform IP infringes copyright/patent (with standard exclusions: customer mods, combo use, outdated versions)
- Not: indemnify for “you lost the deal” or “ICO fined you for lacking employee notice”
---
14.Insurance (operational, not a website promise)
Customers should maintain cyber, professional indemnity, and crime cover appropriate to M&A diligence. ACQI should maintain PI / cyber appropriate to SaaS+desktop tooling (amounts in MSA as {{INSURANCE_AMOUNT_LIMIT}}). Insurance is not a warranty and does not expand contractual liability.
---
15.Sector-specific liability notes
| Sector | Extra care |
|---|---|
| Healthcare | BAA / UK health data rules before PHI-adjacent scans |
| Public sector | Procurement, data residency, OFFICIAL handling |
| Defence / export | Do not scan ITAR estates without licences |
| Multi-bidder M&A | Clean team; purpose limitation |
---
16.Competitor-category framing (for counsel & sales honesty)
Tools overlapping ACQI (Device42, Virima, Firefly, BMC Discovery, Azure Migrate, Quest, ShareGate, BitTitan, Axonius, Lansweeper, deal tech platforms with tech modules, consultancies’ scanners) share the same structural liabilities:
- They act under customer credentials
- They produce incomplete maps of complex estates
- Customers over-trust dashboards in deal heat
- Vendors that promise certainty create the worst liability
ACQI’s differentiation must never be “we eliminate liability.” Differentiation is depth + M&A workflow + desktop-first credential posture + honest limits.
---
17.Customer checklist (publish as “Responsible use”)
Before production scans:
- [ ] Legal basis and authorisation documented (own estate vs target)
- [ ] NDA / clean-team / SPA diligence rights reviewed by counsel
- [ ] Scope written (inclusions/exclusions)
- [ ] Least-privilege credentials issued and time-boxed
- [ ] DPIA considered if large-scale employee monitoring/discovery
- [ ] Data handling rules for exports (VDR, encryption, retention)
- [ ] Named human owners for Go/No-Go on any write/migration action
- [ ] AI features policy (what may be pasted)
- [ ] Incident contacts and stop procedures
- [ ] MSA + DPA executed if ACQI will receive personal data
---
18.Canonical clause pack (for counsel to drop into MSA/Terms)
18.1 High-risk activities acknowledgement
Customer acknowledges that the Services enable high-risk activities including authenticated access to IT systems, bulk extraction of configuration and identity data, automated analysis, optional AI assistance, and (where licensed) migration or configuration changes. Customer assumes operational and legal risk for those activities except as expressly allocated to ACQI in this Agreement.
18.2 No reliance for transaction decisions
Customer agrees that it will not rely solely on the Services for any merger, acquisition, investment, financing, valuation, signing, closing, or material remediation decision, and that ACQI has no liability for any purchase price, indemnity claim, earn-out, synergy shortfall, or similar economic outcome.
18.3 Professional users only
The Services are designed for use by trained IT, security, and M&A technology professionals. Customer shall ensure users are competent and supervised.
18.4 Mitigation duty
Customer shall take reasonable steps to mitigate loss, including maintaining backups before migration features are used and promptly notifying ACQI of suspected product defects.
---
19.What the public website should say (Luna — short page)
Recommended /legal/product-risks summary (link from Terms + Security + footer “Product risks”):
- You must be authorised to scan.
- Discovery is not complete by nature.
- Verify before you sign, close, or cut over.
- You own change control for migrations.
- AI is assistive only.
- Privacy roles: you control estate data; DPA when we process it.
- Liability caps and no deal-value damages apply.
- Full terms in Terms/MSA.
Do not turn this internal memo’s criminal-law discussion into scary marketing; keep the public page calm, clear, and firm.
---
20.Solicitor review flags (do not skip)
- Computer Misuse Act / CFAA wording—confirm jurisdiction coverage for your customer base.
- Whether unlimited vs super-cap DP liability is commercially viable (legal review already warned uncapped DP is dangerous for this product).
- UCTA / CRA reasonableness of caps for any non-enterprise users (B2B focus helps).
- Sector addenda (HIPAA BAA, DORA exhibits).
- Alignment of this page with final executed MSA after incorporation-pack defects are fixed.
---
21.Document control
| Version | Date | Notes |
|---|
Not legal advice. For ACQI.AI LTD internal + counsel use; public derivative at /legal/product-risks.