AssemblyWright
How it works The team Orchestration
Sign in Request access

Legal

Draft for attorney review — not yet in force.

AssemblyWright AI — Terms of Service

Effective date: [DATE]

These Terms of Service (the "Terms") are a binding agreement between Evadaroo & Company, LLC, a Pennsylvania limited liability company trading as "AssemblyWright AI" ("AssemblyWright", "we", "us"), and the person or entity that subscribes to or uses the Service ("you", "Customer").

By signing in, starting a Build, or connecting a CRM system, you accept these Terms. If you are accepting on behalf of a company, you represent that you have authority to bind it.


1. Definitions

  • Service — the AssemblyWright AI hosted software at app.assemblywright.ai (and the .com host that redirects to it), including the Build pipeline, the Wright roster, the Knowledge Base, the Delivery module, the connectors, the admin and operator consoles, and related documentation.
  • Workspace (in code, a "factory") — the isolated tenant in which your data lives. Entitlements, connections, and content are scoped to a Workspace.
  • Build — one run of a workflow through its stages, producing Deliverables. Builds are the unit of both value and metering.
  • Deliverable — a document produced by a Build: a solution design, user stories, a test plan, process documentation, and the rest of the catalogue.
  • Connected Org — a CRM instance (Salesforce, Microsoft Dynamics, or HubSpot) you connect using credentials you provide.
  • Customer Data — everything in your Workspace: Knowledge Base entries, imported org schema and metadata, Build inputs and outputs, Deliverables, delivery board content, and the credentials you store in the connections vault.
  • Order — the package and terms you subscribe to, in a written order form or in the product.
  • AUP — the Acceptable Use Policy, incorporated by reference.
  • DPA — the Data Processing Addendum, incorporated by reference where you are a controller of personal data.

2. Eligibility and accounts

2.1 You must be 18 or older. The Service is a business product, sold to organizations and to individuals acting professionally. It is not directed to children and we do not knowingly collect information from anyone under 18.

2.2 Sign-in. Accounts are managed through our identity provider. You are responsible for your users, their roles, and keeping credentials secure, and for telling us promptly if you believe an account is compromised.

2.3 Roles. The Service enforces per-Workspace roles (viewer, operator, admin, owner). Destructive, cost-bearing, and org-touching actions require an elevated role. Assigning roles correctly is your responsibility, and it is the primary control over who can change your Connected Org.

3. The Service

3.1 What it does. AssemblyWright runs a governed multi-agent review pipeline that produces CRM delivery deliverables. Work moves through stages with one owner and one deliverable each, past review gates at Advisory, Standard, or Rigorous depth, with human checkpoints and a rework policy. It can read from and, on your instruction, write to a Connected Org, with pre-flight warnings, a pre-deploy rollback snapshot, and a one-click undo.

3.2 Human review is the design, not a disclaimer. The Service is built to be directed by a practitioner. Review gates, human checkpoints, and approval steps exist so that a person decides. You are responsible for what you approve.

3.3 Changes. We add, improve, and occasionally retire features. Material retirements get reasonable notice.

3.4 Beta features. Anything labelled beta, preview, or new is provided as-is and excluded from the warranty in Section 13. Process Documentation is new and has not yet been run against a live production org; treat its output accordingly.

3.5 No uptime commitment. We do not currently offer a service-level agreement. We monitor health, deploy behind an automated smoke test with rollback, and will tell you about material incidents — but these Terms do not promise a percentage.

4. Your CRM systems — the important section

4.1 You supply the credentials, and you decide the scope. You connect a Connected Org with credentials you provide. Those credentials are stored in a connections vault, encrypted at rest as a whole snapshot, and are never returned by any interface — only field names are. You may disconnect at any time.

4.2 Least privilege is your control. Grant the Service the narrowest permissions that let it do the work you want. We can only do what your credentials permit.

4.3 Write access is opt-in per action, and gated by a person. Metadata deploys, bulk data updates, test data seeding, and release deploys each require an elevated role and an explicit instruction. We will never write to a Connected Org except on an instruction given by one of your authorized users through the product.

4.4 Sandbox first. We strongly recommend exercising any new workflow, deploy, or bulk operation in a sandbox, Developer Edition, or UAT org before a production org. Connections are role-tagged (sandbox / UAT / production) and the release flow warns when the tag does not match, but the warning is advisory — it does not stop you.

4.5 Rollback is real and it is not a guarantee. Metadata deploys snapshot pre-deploy state to a rollback artifact with a one-click undo, and bulk data updates capture the prior record values. What we cannot undo: downstream automation your change triggered in the Connected Org (flows, triggers, integrations, emails sent, webhooks fired), changes made by anyone else between the snapshot and the undo, and anything your own platform's retention has already aged out. You remain responsible for your own CRM backups.

4.6 Backup custody is your choice. Captured record values behind an undo are held either in our database (default) or as a file in your own Connected Org, with only a receipt and a checksum kept by us. Retention defaults to 30 days and is configurable per Workspace. A capture that cannot be stored under the chosen custody fails the job rather than running without a backup.

4.7 Your CRM vendor relationship is yours. Salesforce, Microsoft, and HubSpot are your vendors. Their terms, limits, and API governor rules apply to you. We are not responsible for their availability or for a charge they levy on your account.

5. Packages, Builds, fees, and overage

5.1 Packages. The Service is sold as a monthly subscription per Workspace. Our standard packages are:

PackagePrice
Starter$149 / month
Team$399 / month
Business$899 / month

Each package names the features included, a number of included Builds per month, and, where applicable, an overage rate per Build. Those numbers are stated in your Order and in the product; the price alone does not define them.

5.2 Metering. Usage is metered per Workspace per feature — Builds started, Maintenance Workflow fires, Guide answers, UI verifications, bulk updates, seed batches, release deploys — and is visible to you in the product.

5.3 Overage is billed only where your package defines it. If your Order names an overage rate per Build, Builds beyond the included allowance are billed at that rate in arrears. If your Order names no overage rate, no overage is charged — the allowance is a ceiling, not a meter, and further Builds are refused until the next period or until you move to a larger package. We will not invent a charge for a rate your Order does not state.

5.4 Spend controls. Every Build carries a token cap with graceful degradation and a per-Build dollar ceiling that warns at 80% and pauses for approval rather than running on. A Workspace-level budget brake sums actual usage and narrows lanes before it would ever touch a review gate. These protect both of us; they are not a promise that a Build will complete within a particular cost or number of model calls.

5.5 Trials. Where we grant a trial — of a package or of a specific feature — it runs to the date stated and then reverts to your package on its own. One trial per Workspace per feature.

5.6 Money-back. If you are not satisfied, tell us within 30 days of your first paid month at billing@assemblywright.ai and we will refund that month in full. Once per Customer, first paid month only.

5.7 Payment terms. Fees are charged in advance, in US dollars, through our payment processor, exclusive of taxes, which are your responsibility unless you provide a valid exemption certificate. A failed charge may lead to suspension of paid features after written notice and a 10-day cure period.

5.8 Price changes. We may change prices for a renewal term on 30 days' written notice before renewal. A term already paid is unaffected.

5.9 Downgrade behavior. Moving to a smaller package or ending a subscription restricts features — it does not delete Deliverables, Builds, or Knowledge Base content. Over-entitlement features become unavailable; your data stays and remains exportable.

6. Your content

6.1 You own it. Customer Data and the Deliverables produced for you are yours. Nothing here transfers ownership.

6.2 License to us. You grant us a worldwide, non-exclusive, royalty-free license to host, store, transmit, process, and display Customer Data solely to provide, secure, and support the Service for you, and to comply with law. It ends when the data is erased.

6.3 We do not train models on your content. We do not use Customer Data to train, fine-tune, or improve any model. Model providers process content only as set out in Section 7.

6.4 Deliverables and AI output. To the extent we hold any rights in a Deliverable, we assign them to you. We make no claim that AI output is original, and outputs generated by AI may not be eligible for copyright protection in every jurisdiction — a fact of law, not a term we can change. You are responsible for reviewing Deliverables before use.

6.5 Your responsibility. You represent that you have the rights to Customer Data and to connect the Connected Orgs you connect, and that doing so does not breach your agreement with your CRM vendor or your obligations to your own customers.

7. AI features and AI disclosure

7.1 The Service is AI-powered throughout. Deliverables, reviews, Guide answers, and proposals are produced by third-party AI models.

7.2 Outputs may be wrong. They can be inaccurate, incomplete, internally inconsistent, or confidently mistaken about your org. Every Deliverable must be reviewed by a competent person before it is relied on, published to a client, or deployed to a production system. The review gates and human checkpoints in the product exist for this; using them is your responsibility, not ours.

7.3 Where content goes. The production model path is Google Vertex AI (Gemini) in us-central1, reached through Google Cloud's enterprise terms. Vertex AI does not train on customer inputs. Where we route to another provider for a specific feature, it is named in the Privacy Policy and the DPA.

7.4 We do not send your content to a free consumer AI tier. Free-tier model endpoints that reserve the right to use inputs for model improvement are development-only by policy and are never pointed at production.

7.5 No professional advice. The Service does not provide legal, tax, accounting, medical, or other professional advice, and a Deliverable is not a substitute for a qualified practitioner's judgment.

8. Publishing to Profusia (optional)

If you connect it, AssemblyWright publishes your Deliverables into a Profusia AI workspace using an access key you supply. Profusia AI is another product of Evadaroo & Company, LLC, operated as a separate service with its own Terms, Privacy Policy, and DPA. Where you connect it, Profusia acts as a subprocessor for the content you publish, on the terms in our DPA. Nothing is published there unless you connect it.

9. Acceptable use

Your use is subject to the Acceptable Use Policy, part of these Terms. We may suspend a Workspace, a user, or a connection that violates it, with notice and a chance to cure where the violation does not present an ongoing risk of harm.

10. Privacy, security, and data protection

10.1 The Privacy Policy describes what we store, where, and for how long. Where you are a controller of personal data, the DPA applies and is incorporated by reference.

10.2 What we do. Workspace isolation is enforced in one place, at the data layer, so a query cannot omit it: reads outside a workspace scope return nothing and writes outside one are refused. Credential-shaped values are encrypted at rest; the connections vault encrypts the whole credential snapshot and never returns values. TLS with HSTS on every hostname. Privileged actions — settings changes, connect/disconnect, vault operations, snapshot restores, permanent deletes — are written to an admin audit trail recording actor, IP, action, and the field names touched, never the values. Rate limiting per IP; dependency pinning and vulnerability scanning. Daily database dumps to cloud storage plus daily disk snapshots, with a rehearsed restore runbook.

10.3 What we do not claim. We hold no SOC 2 report, no ISO 27001 certificate, no HIPAA attestation, and no third-party penetration test, and none is in progress. Isolation is logical, not physical. We have no dedicated security officer. Do not use the Service for protected health information, payment card data, or data whose handling requires a certification we do not hold.

10.4 Security incidents. We will notify you without undue delay, and in any event within 72 hours of becoming aware, of a breach affecting your Customer Data.

11. Confidentiality

Each party will use the other's non-public information only to perform under these Terms, protect it with at least reasonable care, and disclose it only to people who need it under equivalent obligations. Standard exceptions apply (public without fault, independently developed, lawfully received). A party compelled to disclose may do so after notice where legally permitted. Customer Data, and your org's schema and configuration, are your confidential information.

12. Term, suspension, and termination

12.1 Term. From first use until terminated.

12.2 Either party may terminate for convenience on 30 days' written notice. Your notice goes to billing@assemblywright.ai or is given in the product.

12.3 Immediate termination for breach, by either party, if the other materially breaches and fails to cure within 15 days — or immediately, without cure, for an AUP breach presenting an ongoing risk of harm.

12.4 Suspension. We may suspend to stop an active security threat, a legal violation, or non-payment after the cure period, telling you why and restoring promptly once resolved.

12.5 Your data on termination. Deliverables, Knowledge Base entries, and Build records remain available for export for 30 days after termination. Within that window you may also ask us to erase everything; we will do so and confirm. After the window we delete your Workspace data on our normal cycle, subject to backups expiring on their own schedule. Disconnecting a Connected Org does not remove anything already deployed into it — those changes are in your system and are yours to keep or reverse.

12.6 Survival. Sections 6.1, 10.3, 11, 13, 14, 15, and 16 survive.

13. Warranties and disclaimer

13.1 Our limited warranty. We will provide the Service with reasonable skill and care and in accordance with the security practices in Section 10.2.

13.2 Otherwise the Service is provided "AS IS" and "AS AVAILABLE". To the maximum extent permitted by law we disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose, title, and non-infringement. We do not warrant that the Service will be uninterrupted or error-free, that a Deliverable will be accurate, complete, or suitable, that a deployment to a Connected Org will succeed, or that a rollback will restore every downstream effect (see Section 4.5).

13.3 Your remedy for dissatisfaction in the first paid month is the refund in Section 5.6.

14. Indemnification

14.1 By us. We will defend you against a third-party claim that the Service as provided by us, used per these Terms, infringes a US patent, copyright, or trademark, and pay damages finally awarded or agreed. Excluded: claims arising from Customer Data, from a Deliverable's content, from your combination with anything we did not supply, or from use in breach of these Terms. We may procure the right to continue, modify, or terminate and refund prepaid unused fees.

14.2 By you. You will defend and indemnify us against third-party claims arising from Customer Data, from changes made to a Connected Org at your instruction, from your use in breach of these Terms or the AUP, or from your reliance on a Deliverable without review.

14.3 Prompt notice, control of the defense by the indemnifying party, and reasonable cooperation are conditions. No settlement admitting fault or imposing a non-monetary obligation without consent.

15. Limitation of liability

15.1 No indirect damages. Neither party is liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, business, or goodwill, even if advised of the possibility. This expressly includes loss arising from a change deployed to a Connected Org, from downstream automation that change triggered, and from reliance on a Deliverable.

15.2 Cap. Each party's total aggregate liability arising out of or relating to these Terms is limited to the greater of (a) the fees you paid us in the 12 months preceding the event giving rise to the claim, or (b) US $100.

15.3 Carve-outs. The limits in 15.1 and 15.2 do not apply to: (a) indemnification obligations under Section 14; (b) breach of Section 11 (Confidentiality); (c) your obligation to pay fees due; (d) gross negligence, willful misconduct, or fraud; or (e) liability that cannot be limited by law.

15.4 Basis of the bargain. These allocations are essential to the agreement and survive the failure of any limited remedy. They reflect the price: the Service writes to systems of record at your instruction, and the fees do not price the risk of what those systems hold.

16. Dispute resolution, governing law, and venue

16.1 Talk first — 30 days. Before filing anything, the complaining party will send a written description to the other (legal@evadaroo.com for us) and the parties will try in good faith to resolve it. No proceedings until 30 days after that notice, except a request for injunctive relief protecting intellectual property or confidential information. The period tolls any limitation period.

16.2 Governing law. The Commonwealth of Pennsylvania, without regard to conflict-of-laws rules. The UN Convention on Contracts for the International Sale of Goods does not apply.

16.3 Venue. The state and federal courts located in Pennsylvania, exclusively; both parties consent to jurisdiction and venue there. There is no arbitration clause and no class-action waiver in this agreement.

17. General

17.1 Entire agreement — these Terms, the AUP, the Privacy Policy, the DPA where applicable, and any Order. A purchase order's pre-printed terms have no effect.

17.2 Precedence — a signed Order, then these Terms, then the AUP, then the Privacy Policy.

17.3 Changes to these Terms — material changes get 30 days' notice by email and in the product; continued use after the effective date accepts them. If a material change is unacceptable, terminate before it takes effect and we will refund prepaid unused fees.

17.4 Assignment — not without consent, except to a successor in a merger, acquisition, or sale of substantially all assets, on notice.

17.5 Notices — to us: legal@evadaroo.com, copy to Evadaroo & Company, LLC, [REGISTERED OFFICE ADDRESS]. To you: the email on the Workspace owner's account, and in-product notice.

17.6 Force majeure — excluding payment obligations.

17.7 Export and sanctions — you will not use or export the Service in violation of US export control or sanctions law, and you are not a restricted party or ordinarily resident in an embargoed jurisdiction.

17.8 US government end users — commercial computer software under FAR 12.212 and DFARS 227.7202.

17.9 Publicity — we will not use your name or logo as a customer reference without your prior written consent.

17.10 Independent contractors — no partnership, agency, employment, or joint venture; no third-party beneficiaries.

17.11 Severability and waiver — an unenforceable provision is limited to the minimum extent necessary; a failure to enforce is not a waiver.

18. Contact

  • General and legal notice: legal@evadaroo.com
  • Billing: billing@assemblywright.ai
  • Support: support@assemblywright.ai
  • Security reports: security@assemblywright.ai

Evadaroo & Company, LLC · [REGISTERED OFFICE ADDRESS] · Pennsylvania, USA

← Back to AssemblyWright

AssemblyWright

A delivery department that works on day one.

How it works Workflows Orchestration Terms Privacy DPA Acceptable use Sign in hello@assemblywright.ai
© 2026 AssemblyWright