Firmus logo

Firmus

firmus.ai
Moderate Risk
Updated August 20, 2026

Firmus is a B2B SaaS construction design risk mitigation platform governed by subscription Terms of Service (New York law, order-form based) and a Privacy Policy last updated April 8, 2024. The Terms are relatively customer-favorable on ownership: the customer retains title to its Customer Data and Output Data, and Firmus's license to that data is limited to providing the Service. However, Firmus reserves the right to aggregate and de-identify Customer Data and Output Data ('Anonymized Data') and use it to improve its platform, the Privacy Policy is thin and silent on most enterprise-grade privacy/security assurances, and there are no named compliance certifications (no SOC 2, ISO, GDPR attestation), which is a notable gap for an enterprise tool. A corporate-naming inconsistency (Firmus AI Inc. in the Terms vs. Firmus Ltd. in the Privacy Policy) and the absence of a DPA or security page increase uncertainty. Overall moderate risk: review before submitting sensitive or proprietary project data without a negotiated DPA and security addendum.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Low Risk

The Terms explicitly confirm the customer retains all right, title and intellectual property rights in its Customer Data, and Firmus receives only a limited license to use it to provide the Service. This is a user-favorable ownership position.

Confidence
85%

Output Data Ownership

Low Risk

The Terms state the customer holds all right, title and intellectual property rights in Output Data generated by the Service. This clearly assigns AI output ownership to the customer.

Confidence
85%

Training Data Usage

Moderate Risk

Firmus does not train on raw Customer Data, but it reserves the right to aggregate and de-identify Customer Data and Output Data into 'Anonymized Data' and use that for internal business purposes including platform enhancement. There is no explicit no-training commitment and no consumer-facing opt-out from this anonymized use, though its scope is limited to de-identified data.

Confidence
70%

Data Retention & Deletion

Moderate Risk

The Privacy Policy states an approximate 7-year retention period plus further retention for legal obligations, and the Terms provide for return/destruction of Confidential Information within 30 days of termination on request. However, there is no user-facing deletion self-service mechanism, no deletion SLA for Customer Data specifically, and no security-related retention schedule (e.g., audit logs).

Confidence
60%

Third-Party Data Sharing

Moderate Risk

The Privacy Policy commits not to share information except in disclosed scenarios, and names specific service providers (Wix, Calendly, Google Analytics, Hubspot, Hotjar, AWS and 'AI tools') restricted to providing services to Firmus. Disclosure is reasonable, but the reference to unspecified 'AI tools' sub-processors is vague, and there is no data-broker or advertising sale, which is favorable.

Confidence
65%

Opt-Out Rights

Moderate Risk

The Privacy Policy provides an explicit opt-out from marketing communications by email, which is a positive. However, there is no opt-out from the anonymized-data usage for platform improvement, and no described mechanism for opting out of analytics/cookies beyond the cookie banner.

Confidence
60%

Compliance & Certifications

High Risk

No specific compliance frameworks or certifications (SOC 2, ISO 27001/27018, GDPR, CCPA, EU AI Act) are named or attested anywhere in the supplied documents. The Terms assert only a general 'comprehensive information security program that complies with applicable laws,' and the Privacy Policy states a general commitment to data protection laws — both are unsubstantiated claims without third-party attestation, which is a significant gap for an enterprise SaaS product.

Confidence
70%

Model Explainability & Auditability

High Risk

The documents provide no transparency into model behavior, no explainability commitments, and no enterprise audit rights. The Terms notably position the Platform as a decision-support tool requiring professional judgment but offer no mechanism to inspect or audit how outputs are derived.

Confidence
55%

Security Practices & Breach History

Moderate Risk

The documents disclose only generic security assurances: a 'comprehensive information security program' and storage on secure AWS servers, with an explicit acknowledgement that security is not absolute. There is no mention of encryption at rest/in transit, penetration testing, bug bounty, incident response, breach notification, or a trust center/security page, and no breach history is disclosed.

Confidence
60%

Enterprise vs. Consumer Risk Delta

Moderate Risk

Firmus is a B2B subscription product with an Evaluation Service (30-day trial) offered 'AS IS' with no maintenance, support, or indemnification, versus the full Subscription Service which carries warranties and indemnities. This creates a material tier delta, though it concerns support/warranty rather than data handling, which appears uniform.

Confidence
55%

Human Review of User Inputs

Moderate Risk

The Terms grant Firmus a license to use, store, process, analyze, and display Customer Data and Output Data to provide the Service, and Firmus may employ technological measures to detect abuse — implying access — but the documents do not explicitly state whether staff read prompts or content. This silence, combined with a broad processing license, is ambiguous.

Confidence
45%

Regulatory & Litigation Exposure

Moderate Risk

The Privacy Policy discloses that Firmus will disclose information to competent authorities when required by a binding request, and the Terms address disclosure pursuant to court/agency orders with a notice-and-contest provision. No pending litigation, government data-request volumes, or law enforcement statistics are disclosed. Governing law and exclusive jurisdiction are set to New York.

Confidence
55%

PII & SPI Data Inventory

Moderate Risk

Firmus collects moderate PII: login credentials, email, full name, company name, role, IP address, device/browser type, and usage actions, plus uploaded documents and construction drawings that may contain third-party personal information. The policy discloses categories reasonably but pushes responsibility for any embedded personal data onto the user, and does not detail SPI handling controls.

Confidence
65%

Policy–Product Currency

Moderate Risk

The Privacy Policy is dated April 8, 2024 — within roughly 28 months of the analysis date, placing it just past the 24-month window on recency, while the Terms carry no discoverable effective date (Effective Date defers to the Order Form). The product markets itself as an AI platform and the Privacy Policy references 'AI tools' as sub-processors, but coverage of AI/ML processing, model training, and specific third-party model providers is thin. The product marketing copy also indicates the tool 'is now part of Bluebeam,' a corporate change the supplied policies do not reflect.

Confidence
50%

Cross-Document Consistency

Moderate Risk

Two documents were supplied, enabling a cross-document check. There are no license/retention/opt-out contradictions between them, but there is a corporate-identity inconsistency: the Terms are issued by 'Firmus AI Inc.' while the Privacy Policy names the operator as 'Firmus Ltd.' — a minor but notable discrepancy about which legal entity controls the data. No material or critical conflicts were found.

Confidence
55%

You've read all 15 risk ratings for Firmus. Create a free account to see the exact policy wording behind each rating.