Firmus
firmus.aiFirmus is a B2B SaaS construction design risk mitigation platform governed by subscription Terms of Service (New York law, order-form based) and a Privacy Policy last updated April 8, 2024. The Terms are relatively customer-favorable on ownership: the customer retains title to its Customer Data and Output Data, and Firmus's license to that data is limited to providing the Service. However, Firmus reserves the right to aggregate and de-identify Customer Data and Output Data ('Anonymized Data') and use it to improve its platform, the Privacy Policy is thin and silent on most enterprise-grade privacy/security assurances, and there are no named compliance certifications (no SOC 2, ISO, GDPR attestation), which is a notable gap for an enterprise tool. A corporate-naming inconsistency (Firmus AI Inc. in the Terms vs. Firmus Ltd. in the Privacy Policy) and the absence of a DPA or security page increase uncertainty. Overall moderate risk: review before submitting sensitive or proprietary project data without a negotiated DPA and security addendum.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The Terms explicitly confirm the customer retains all right, title and intellectual property rights in its Customer Data, and Firmus receives only a limited license to use it to provide the Service. This is a user-favorable ownership position.
Output Data Ownership
The Terms state the customer holds all right, title and intellectual property rights in Output Data generated by the Service. This clearly assigns AI output ownership to the customer.
Training Data Usage
Firmus does not train on raw Customer Data, but it reserves the right to aggregate and de-identify Customer Data and Output Data into 'Anonymized Data' and use that for internal business purposes including platform enhancement. There is no explicit no-training commitment and no consumer-facing opt-out from this anonymized use, though its scope is limited to de-identified data.
Data Retention & Deletion
The Privacy Policy states an approximate 7-year retention period plus further retention for legal obligations, and the Terms provide for return/destruction of Confidential Information within 30 days of termination on request. However, there is no user-facing deletion self-service mechanism, no deletion SLA for Customer Data specifically, and no security-related retention schedule (e.g., audit logs).
Third-Party Data Sharing
The Privacy Policy commits not to share information except in disclosed scenarios, and names specific service providers (Wix, Calendly, Google Analytics, Hubspot, Hotjar, AWS and 'AI tools') restricted to providing services to Firmus. Disclosure is reasonable, but the reference to unspecified 'AI tools' sub-processors is vague, and there is no data-broker or advertising sale, which is favorable.
Opt-Out Rights
The Privacy Policy provides an explicit opt-out from marketing communications by email, which is a positive. However, there is no opt-out from the anonymized-data usage for platform improvement, and no described mechanism for opting out of analytics/cookies beyond the cookie banner.
Compliance & Certifications
No specific compliance frameworks or certifications (SOC 2, ISO 27001/27018, GDPR, CCPA, EU AI Act) are named or attested anywhere in the supplied documents. The Terms assert only a general 'comprehensive information security program that complies with applicable laws,' and the Privacy Policy states a general commitment to data protection laws — both are unsubstantiated claims without third-party attestation, which is a significant gap for an enterprise SaaS product.
Model Explainability & Auditability
The documents provide no transparency into model behavior, no explainability commitments, and no enterprise audit rights. The Terms notably position the Platform as a decision-support tool requiring professional judgment but offer no mechanism to inspect or audit how outputs are derived.
Security Practices & Breach History
The documents disclose only generic security assurances: a 'comprehensive information security program' and storage on secure AWS servers, with an explicit acknowledgement that security is not absolute. There is no mention of encryption at rest/in transit, penetration testing, bug bounty, incident response, breach notification, or a trust center/security page, and no breach history is disclosed.
Enterprise vs. Consumer Risk Delta
Firmus is a B2B subscription product with an Evaluation Service (30-day trial) offered 'AS IS' with no maintenance, support, or indemnification, versus the full Subscription Service which carries warranties and indemnities. This creates a material tier delta, though it concerns support/warranty rather than data handling, which appears uniform.
Human Review of User Inputs
The Terms grant Firmus a license to use, store, process, analyze, and display Customer Data and Output Data to provide the Service, and Firmus may employ technological measures to detect abuse — implying access — but the documents do not explicitly state whether staff read prompts or content. This silence, combined with a broad processing license, is ambiguous.
Regulatory & Litigation Exposure
The Privacy Policy discloses that Firmus will disclose information to competent authorities when required by a binding request, and the Terms address disclosure pursuant to court/agency orders with a notice-and-contest provision. No pending litigation, government data-request volumes, or law enforcement statistics are disclosed. Governing law and exclusive jurisdiction are set to New York.
PII & SPI Data Inventory
Firmus collects moderate PII: login credentials, email, full name, company name, role, IP address, device/browser type, and usage actions, plus uploaded documents and construction drawings that may contain third-party personal information. The policy discloses categories reasonably but pushes responsibility for any embedded personal data onto the user, and does not detail SPI handling controls.
Policy–Product Currency
The Privacy Policy is dated April 8, 2024 — within roughly 28 months of the analysis date, placing it just past the 24-month window on recency, while the Terms carry no discoverable effective date (Effective Date defers to the Order Form). The product markets itself as an AI platform and the Privacy Policy references 'AI tools' as sub-processors, but coverage of AI/ML processing, model training, and specific third-party model providers is thin. The product marketing copy also indicates the tool 'is now part of Bluebeam,' a corporate change the supplied policies do not reflect.
Cross-Document Consistency
Two documents were supplied, enabling a cross-document check. There are no license/retention/opt-out contradictions between them, but there is a corporate-identity inconsistency: the Terms are issued by 'Firmus AI Inc.' while the Privacy Policy names the operator as 'Firmus Ltd.' — a minor but notable discrepancy about which legal entity controls the data. No material or critical conflicts were found.
You've read all 15 risk ratings for Firmus. Create a free account to see the exact policy wording behind each rating.