1. Platform & Service Provision
The Blue Iceberg provides an enterprise software platform for continuous compliance monitoring, automated audit proof collection, interactive system architecture mapping, and real-time AI gateway policy enforcement.
Services may be provisioned via tenant-isolated multi-tenant cloud sandboxes, dedicated VPCs, or sovereign on-premise private enclaves pursuant to an executed Order Form or Enterprise Service Agreement.
2. Customer Data Ownership & Zero Training Warranty
Ownership: You retain all right, title, and interest (including all intellectual property rights) in and to your system configurations, cloud credentials, code repositories, prompts, model responses, and audit evidence (“Customer Data”).
Zero AI Model Training: The Blue Iceberg covenants and agrees that Customer Data will never be used, logged, or processed to train, fine-tune, optimize, or evaluate any third-party or foundation artificial intelligence models.
3. Continuous Telemetry & Auditor Role Disclaimer
The Blue Iceberg Compliance & Trust OS executes continuous automated monitoring, cryptographic evidence sealing, and technical gap discovery across standards including AICPA SOC 2 Type II, ISO/IEC 27001:2022, HIPAA Security Rule, and EU GDPR.
While our platform prepares organizations for formal audits and provides cryptographic proof, The Blue Iceberg is a software and technology provider, not an accredited public accounting firm or certified ISO registrar. Formal certification remains subject to independent evaluation by accredited third-party auditors.
4. AI Guardrails & Policy Enforcement
The AI Compliance Gateway inspects and redacts prompts in real time according to rules configured in your AI Control Plane (such as PII masking, PHI redaction, and model egress locks). Customers remain responsible for configuring policies aligned with their internal risk thresholds, legal obligations, and applicable jurisdiction requirements.
5. Enterprise Confidentiality & Bilateral NDAs
Under our enterprise engagement standards, both parties agree to maintain strict confidentiality regarding proprietary system topologies, infrastructure configurations, model weights, and business strategies. Neither party will publicly disclose the other party's trade secrets or confidential architecture without prior written consent.
6. Security, Tenant Isolation & Incident Notification
The Blue Iceberg implements industry-standard technical and organizational security measures, including AES-256 encryption at rest, TLS 1.3 in transit, tenant isolation, and role-based access control.
In the event of a verified security incident affecting Customer Data, The Blue Iceberg will notify affected customer administrators without undue delay, and in all cases within forty-eight (48) hours of confirmation, in compliance with GDPR and HIPAA breach notification standards.
7. Acceptable Use & Compliance Sandbox
You agree not to use the platform to: (a) reverse engineer, decompile, or copy the underlying proprietary algorithms of the Compliance & Trust OS; (b) deliberately bypass AI safety guardrails to generate harmful or illegal content; or (c) launch security attacks against multi-tenant infrastructure.
8. Warranties & Limitation of Liability
Except as expressly provided in an executed Enterprise Agreement, the platform is provided on an “as is” and “as available” basis. To the maximum extent permitted by applicable law, neither party shall be liable for indirect, punitive, special, or consequential damages arising from service usage.
9. Contact & Legal Notices
Legal notices and contractual inquiries should be sent to legal@theblueiceberg.com or theblueiceberg@gmail.com.