Legal

Dash4Sec Additional Service Terms

Product- and feature-specific terms that supplement the Terms of Service.

Terakhir diperbarui: June 25, 2026 · Stack4Sec, LLCWyoming, USA

Language

This document is provided in English, which is the authoritative version; any translation is for convenience only and the English version prevails.

Overview

These Dash4Sec Additional Service Terms apply to access to and use of Dash4Sec, a cybersecurity maturity, compliance, evidence management, and reporting software-as-a-service platform provided by Stack4Sec, LLC, a Wyoming limited liability company.

Dash4Sec is a product, platform, service, brand, and/or trademark owned, operated, licensed, or controlled by Stack4Sec, LLC.

These Additional Service Terms supplement and are incorporated into the Stack4Sec Terms of Service. Use of Dash4Sec is also governed by all applicable Stack4Sec global policies, including the Stack4Sec Acceptable Use Policy, Copyright and Intellectual Property Policy, AI Features Terms, Privacy Policy, Cookie Policy, Data Processing Addendum, Security Policy / Trust Center, and any applicable Order Form.

Capitalized terms not defined in these Additional Service Terms have the meanings given in the Stack4Sec Terms of Service.

If there is a conflict between these Additional Service Terms and the Stack4Sec Terms of Service, these Additional Service Terms control only with respect to Dash4Sec.

Dash4Sec Service Description

Dash4Sec is a software-as-a-service platform designed to help customers organize, assess, monitor, and report cybersecurity maturity, cybersecurity compliance, framework alignment, control status, evidence, gaps, priorities, action plans, and related cybersecurity governance information.

Dash4Sec may include features such as cybersecurity framework assessments, maturity assessments, gap analysis, environment-based assessments, configurable frameworks, import and export of spreadsheets, control prioritization, action plan tracking, evidence management, AI-assisted evidence assessment, executive and detailed reports, configurable dashboards, role-based access control, multi-factor authentication, audit views, third-party risk or supplier assessment workflows, and other cybersecurity governance, risk, and compliance features.

Stack4Sec may add, modify, remove, rename, suspend, or discontinue Dash4Sec features at any time, subject to the applicable Order Form.

Decision-Support Nature of Dash4Sec

Dash4Sec is a decision-support platform. Dash4Sec does not provide legal advice, regulatory advice, audit opinions, certification, attestation, assurance, cybersecurity guarantees, managed security services, incident response, penetration testing, forensic analysis, insurance, or risk transfer.

Dash4Sec does not guarantee that Customer is secure, compliant, mature, audit-ready, certification-ready, breach-free, or free of cybersecurity gaps.

Customer is solely responsible for reviewing, validating, approving, rejecting, accepting, remediating, or escalating any assessment, recommendation, score, report, dashboard, evidence result, AI output, control status, or action plan generated or managed through Dash4Sec.

Frameworks and Control Libraries

Dash4Sec may provide assessment workflows aligned with cybersecurity, privacy, technology, regulatory, industry, and governance frameworks, as well as the ability to create, configure, or import custom assessment structures.

Dash4Sec may reference third-party framework names, versions, control identifiers, laws, regulations, standards, methodologies, and industry publications for identification, interoperability, mapping, assessment workflow, and customer configuration purposes only. Unless expressly stated in writing, Dash4Sec does not provide, reproduce, license, replace, certify, distribute, or grant rights in official third-party framework or standard materials.

Stack4Sec-created assessment questions, evidence guidance, implementation guidance, scoring methods, summaries, mappings, and recommendations are original Stack4Sec materials and are not official publications of any third-party framework owner, standards body, regulator, certification body, or industry organization. Customer is responsible for obtaining and using official or licensed framework materials where required and must validate requirements with authoritative sources and qualified advisors.

If Customer imports or uploads official or licensed framework content into Dash4Sec, Customer represents that it has all rights and permissions required for such use, including use within a SaaS platform, automation, AI-assisted workflows, reports, exports, and access by Authorized Users. Stack4Sec may remove, disable, or restrict such content if it appears to violate third-party rights or licensing restrictions.

Environments

Dash4Sec may allow Customer to create environments, business units, subsidiaries, legal entities, operational perimeters, IT environments, OT environments, cloud environments, third-party environments, or other assessment scopes.

Customer is solely responsible for defining environments accurately and ensuring that assessments reflect the actual scope being evaluated. Stack4Sec is not responsible for incorrect conclusions resulting from incomplete, inaccurate, misleading, or improperly scoped environments.

Maturity Scores, Gap Analysis, and Dashboards

Dash4Sec may generate maturity scores, compliance percentages, gap analysis results, dashboard visualizations, status distributions, historical trends, category-level views, and similar outputs.

These outputs are informational and depend on Customer Content, configuration, control status, evidence, assumptions, scoring logic, framework structure, and user inputs.

Customer acknowledges that maturity scores are not independent security ratings; maturity scores are not certifications; gap analysis results are not legal or audit conclusions; dashboards are not real-time security monitoring unless expressly stated; and outputs may be incomplete, inaccurate, outdated, or misleading if Customer Content is incomplete, inaccurate, outdated, or misleading.

Customer must independently validate all outputs before using them for management, audit, board, customer, regulator, investor, insurer, or third-party purposes.

Evidence Management

Dash4Sec may allow Customer to upload, store, organize, classify, review, and manage evidence related to cybersecurity controls.

Customer is solely responsible for ensuring that evidence is accurate, complete, lawful, current, and appropriate; ensuring that evidence does not contain data Customer is not authorized to upload; reviewing evidence before submission to auditors, regulators, customers, insurers, or other third parties; maintaining original records outside Dash4Sec where required; applying retention, legal hold, confidentiality, and access control requirements; and deleting or redacting sensitive information where appropriate.

Stack4Sec does not guarantee that evidence uploaded to Dash4Sec will be accepted by any auditor, regulator, certification body, customer, insurer, investor, or third party.

AI-Assisted Evidence Assessment

Dash4Sec may include AI-assisted evidence assessment features, including functionality that reviews evidence against a control and suggests a quality, relevance, sufficiency, or compliance-related verdict.

These features are subject to the Stack4Sec AI Features Terms. Customer acknowledges that AI-assisted evidence assessment is automated and may be inaccurate; AI outputs are suggestions only; AI outputs do not replace human review; AI outputs do not constitute audit, legal, regulatory, or cybersecurity advice; Customer must validate AI outputs before relying on them; Customer is responsible for deciding whether evidence is acceptable; and Customer must not submit evidence to AI Features unless Customer is authorized to share that content with applicable subprocessors.

AI-assisted evidence assessment must not be used with official third-party framework text or licensed standards content unless Customer has all necessary rights and permissions for that AI-related use. Where official framework text is not licensed for use in Dash4Sec, AI-assisted evidence assessment should rely on Stack4Sec original assessment content, Customer Content, permitted references, and Customer-approved context.

Stack4Sec is not liable for decisions made based on AI outputs.

Reports and Exports

Dash4Sec may allow Customer to generate executive reports, detailed reports, spreadsheets, exports, dashboards, summaries, and other outputs.

Customer is solely responsible for reviewing reports before distribution, ensuring reports are accurate and current, controlling external sharing, ensuring reports are not misleading, ensuring reports are not presented as certifications, audit opinions, legal opinions, assurance reports, or regulatory approvals, and ensuring that exports do not expose confidential, regulated, or personal data improperly.

Customer must not present Dash4Sec reports, exports, dashboards, or outputs as official framework materials or as reproductions, replacements, certifications, approvals, or licensed copies of third-party standards or control catalogs.

Stack4Sec disclaims liability for Customer's use, interpretation, modification, distribution, or reliance on reports and exports.

Third-Party Risk and Supplier Assessments

Dash4Sec may support third-party risk, supplier assessment, vendor compliance, or external assessment workflows.

Customer is solely responsible for obtaining authorization before assessing, inviting, or requesting information from third parties; ensuring that third-party data is lawfully collected and processed; validating third-party responses; determining third-party risk ratings, approvals, exceptions, and remediation requirements; and complying with contractual, procurement, privacy, confidentiality, and regulatory obligations.

Dash4Sec does not independently verify third-party responses unless expressly agreed in a separate professional services agreement.

Role-Based Access Control and Audit Users

Dash4Sec may offer role-based access control, including administrative, standard user, audit, read-only, environment-specific, or other roles.

Customer is responsible for assigning roles appropriately and reviewing permissions regularly. Stack4Sec is not responsible for unauthorized disclosure or modification resulting from Customer's permission settings, user management, account sharing, weak authentication practices, or failure to revoke access.

Import and Export of Spreadsheets

Dash4Sec may allow Customer to import and export spreadsheets or other structured files.

Customer is responsible for validating imported data, reviewing mappings, checking formulas, verifying field accuracy, and ensuring that imported files do not contain malicious, unlawful, confidential, personal, or regulated data that Customer is not authorized to upload.

Stack4Sec is not liable for errors caused by imported files, incorrect mappings, malformed data, user mistakes, spreadsheet formatting issues, or third-party spreadsheet software.

Customer Content Specific to Dash4Sec

Dash4Sec Customer Content may include environments, framework assessments, control statuses, evidence files, comments, maturity data, action plans, reports, supplier data, user data, audit logs, and other cybersecurity governance information.

Customer acknowledges that Dash4Sec Customer Content may be sensitive and may reveal security posture, control gaps, business risks, vendor exposure, audit status, and compliance information.

Customer is solely responsible for classifying, protecting, limiting, and controlling access to such content.

Sensitive and Regulated Data

Unless expressly permitted in writing, Customer must not upload to Dash4Sec payment card data subject to PCI DSS cardholder data requirements, protected health information subject to HIPAA, classified information, controlled unclassified information requiring special handling, government secrets, export-controlled technical data, children's data, highly sensitive personal data not required for the intended use, passwords, private keys, seed phrases, secrets, production credentials, malware samples, or exploit code.

Customer should redact or minimize sensitive content before uploading evidence.

Customer Use of Dash4Sec Outputs

Customer may use Dash4Sec outputs for internal cybersecurity governance, management reporting, audit preparation, compliance tracking, maturity tracking, third-party risk workflows, board reporting, and similar internal business purposes.

Customer may not misrepresent Dash4Sec outputs as independent certifications; state or imply that Stack4Sec certified Customer's compliance or security posture; state or imply that Dash4Sec guarantees compliance with any framework, law, regulation, or standard; use outputs to deceive auditors, regulators, customers, investors, insurers, or other third parties; or remove required disclaimers from reports where such disclaimers are included.

Dash4Sec Plans and Limits

Dash4Sec plans may include limits on environments, users, frameworks, evidence storage, reports, AI assessments, exports, suppliers, dashboards, API calls, support, or other features.

Stack4Sec may enforce plan limits technically or contractually. If Customer exceeds applicable limits, Stack4Sec may require Customer to upgrade, reduce usage, pay additional fees, or suspend excess usage.

Free Access and Legacy Promotional Access

Stack4Sec may offer free, trial, beta, promotional, or legacy access to Dash4Sec. Unless expressly stated in a signed agreement, free access may be changed, limited, suspended, or discontinued; features included in free plans may change; Stack4Sec may introduce paid plans; Stack4Sec may migrate free users to limited plans; and Stack4Sec has no obligation to maintain free access indefinitely.

Any promotional commitment must be documented in the applicable Order Form, subscription notice, or written communication from Stack4Sec.

Data Retention in Dash4Sec

Dash4Sec may retain Customer Content during the active Subscription Term and for a limited period after termination or expiration, subject to the Stack4Sec Terms of Service, Privacy Policy, DPA, and applicable law.

Customer is responsible for exporting Customer Content before termination or expiration. Stack4Sec may delete or anonymize Customer Content after the applicable retention period unless legally required to retain it.

Product Availability

Dash4Sec may be unavailable from time to time due to maintenance, updates, incidents, third-party outages, infrastructure issues, security events, or events beyond Stack4Sec's control.

Unless expressly provided in a signed SLA, Stack4Sec does not guarantee uptime, availability, response time, resolution time, or uninterrupted access.

Product-Specific Disclaimers

Customer acknowledges and agrees that Dash4Sec is not a vulnerability scanner, penetration testing platform, security rating agency, managed security service, incident response provider, legal or regulatory advisory service, or independent verification service.

Dash4Sec does not guarantee audit, certification, regulatory, insurance, customer, or board acceptance.

Product-Specific Support

Dash4Sec support may vary by plan. Support may include documentation, email support, in-product support, onboarding assistance, enterprise support, or other channels depending on the applicable subscription.

Stack4Sec may decline support for issues caused by misuse, unsupported configurations, third-party services, Customer infrastructure, Customer Content, imported files, or use outside Documentation.

Relationship to Other Stack4Sec Policies

Use of Dash4Sec is also governed by the Stack4Sec Terms of Service, Stack4Sec Acceptable Use Policy, Stack4Sec Copyright and Intellectual Property Policy, Stack4Sec AI Features Terms, Stack4Sec Privacy Policy, Stack4Sec Cookie Policy, Stack4Sec Data Processing Addendum, Stack4Sec Security Policy / Trust Center, and any applicable Order Form.

Contact

Legal notices and inquiries may be sent to:

Stack4Sec, LLC 30 N Gould St, STE R Sheridan, WY 82801 United States Email: legal@stack4sec.com

Stack4Sec, LLC · Wyoming, USA · contact@stack4sec.com