Draft for solicitor review — published for transparency. Not legal advice. Enterprise customers should execute the MSA and DPA. Last updated: 2026-07-23.

1. Security principles

  1. Least privilege — discovery should use scoped service accounts / roles you approve.
  2. Desktop-first credentials — secrets intended to remain in OS-protected storage on the endpoint (e.g. DPAPI / safeStorage patterns).
  3. Customer control of estate data — minimise unnecessary export of personal data to ACQI-hosted systems.
  4. Honest claims — we do not display fake compliance badges.
  5. Defence in depth — transport encryption (TLS), access control, auditability, and secure development practices appropriate to stage.

2. Architecture snapshot

LayerDescription
ClientDesktop application (Electron) + PowerShell discovery modules for deep estate scanning
Identity to targetsCustomer-supplied credentials / app registrations against Azure, M365, AD, cloud, infra, security tools, etc.
OutputsInventories, reports, planning artefacts for M&A diligence and integration
Optional servicesAccount, licensing, support, and AI features that may use cloud subprocessors
GovernanceWave planning, gates, post-deal oversight modules as licensed

3. Data handling summary

Data typeTypical handling
Target-environment credentialsLocal endpoint; not required by design for upload to ACQI for standard discovery
Discovery resultsCustomer-controlled storage / export paths; processor terms if hosted by ACQI
Website leadsController processing under the Privacy Policy
AI promptsSent to model subprocessor only when AI features used — see AI disclosure

4. Technical & organisational measures (high level)

These reflect design goals and DPA Annex themes. Enterprise diligence should validate current state via questionnaire and demo — early-stage controls improve over time.

  • Encryption in transit (TLS 1.2+) for network communications
  • Encryption at rest for hosted data stores where used
  • Role-based access for ACQI personnel to production systems (need-to-know)
  • MFA for privileged ACQI access where implemented
  • Logging of security-relevant events for hosted components
  • Secure software development practices (code review, dependency hygiene)
  • Incident response process with customer notification commitments under the DPA
  • Confidentiality obligations for staff and contractors

Not claimed unless independently verified and listed here: SOC 2 Type I/II; ISO/IEC 27001; Cyber Essentials / Plus; FedRAMP; HIPAA attestation / BAA (available only under separate agreement if ever offered).

5. Customer responsibilities (shared model)

You (customer)ACQI
Authorise scans lawfullyBuild and maintain product security features
Harden endpoints running the clientSecure our hosted infrastructure
Least-privilege credentials & rotationProcess data only as instructed (processor role)
Review discovery outputs before deal decisionsNotify material breaches per DPA
Clean-team / antitrust controls in M&AMaintain subprocessors list
Configure AI feature data handlingProvide contractual DPAs
Own change control for any write/migration actionDocument product security posture honestly
Control retention of diligence exportsLiability caps as per Terms/MSA

Liability: Discovery/migration tooling creates material legal risk. Allocation is spelled out in Product risks & tooling liability and the Terms. ACQI is not your insurer against post-close IT surprises.

6. Vulnerability disclosure

If you believe you have found a security vulnerability in ACQI software or infrastructure:

  1. Email security@acqi.ai with a technical description and repro steps.
  2. Do not access data that is not yours or disrupt production systems.
  3. Allow reasonable time for assessment before public disclosure.

We do not offer a formal bug bounty unless announced.

7. Compliance context (product for M&A)

ACQI helps customers discover and assess IT estates that may be relevant to GDPR, NIS2, DORA, SOX ITGCs, and similar frameworks. Using ACQI does not make your organisation compliant. Outputs support professional judgement; they are not legal opinions or audit certifications.

8. Related legal documents