1. Scope and limitations
Each Assessment Report ("Report") presents the results of automated adversarial testing of the AI system designated by the Customer (the "Subject System"), as described in the applicable Statement of Work or sign-up form and Rules of Engagement.
The findings reflect the state of the Subject System as of the Assessment Date(s) shown in the Report, evaluated against the specific test methodologies (cookbooks, probes, scenarios) listed in the Report. Findings are based on the input prompts, evaluation rubrics, and threshold rules in effect at the time of testing.
2. The Report is NOT
- A regulatory certification or attestation
- A legal opinion
- A guarantee of safety, fitness, or compliance
- A representation to any party other than the Customer
- Persistent after material changes to the Subject System made post-Assessment
3. The Report IS prepared for the Customer's use
The Customer may share the Report with:
- The Customer's regulators (e.g., MAS, IMDA, PDPC)
- The Customer's internal and external auditors
- The Customer's reinsurers / insurance underwriters
- The Customer's internal governance committees
Such sharing is solely for the Customer's own compliance and risk-management purposes.
4. No reliance by third parties
AgentSure makes no representation to any party other than the Customer and assumes no obligation to support any third-party reliance on the Report. Any reliance by a non-party requires a separately executed Reliance Letter with AgentSure. Contact legal@agentsure.tech for the Reliance Letter procedure (currently SGD 500–2,000 per relying party, depending on use case).
5. Methodology disclosure
AgentSure conducts Assessments using its proprietary Quantify Test Suite, based on then-current frameworks including:
- IMDA AI Verify and its testing toolkit (Moonshot)
- IMDA Model AI Governance Framework (MGF) and the MGF Agentic risk taxonomy
- MAS Notices on AI Risk Management (including the 2026 GenAI Circular)
- NIST AI Risk Management Framework (RMF)
- OWASP LLM Top 10
These frameworks evolve. Findings may be superseded by future framework revisions, new threat techniques, or material changes to underlying LLM providers.
6. Regulator inquiries
If a regulator (including MAS or IMDA) contacts AgentSure directly about a specific Report, AgentSure will (where legally permitted):
- Notify the Customer within 2 business days
- Limit its response to confirming Report authenticity and methodology disclosure
- Not interpret findings for the regulator
- Not act as an expert witness without a separate engagement and fee
7. PASS, WARN, FAIL — what these mean
| Status | What it means | What it does NOT mean |
|---|---|---|
| PASS | Metric exceeded the threshold rule defined for this control in this test methodology, at this point in time. | Your AI is safe / compliant / certified in any general sense. |
| WARN | Metric is in a borderline band; investigate further. | Your AI is broken; the threshold is set conservatively. |
| FAIL | Metric did not meet the threshold for this control in this test methodology. | Your AI is unsafe across all dimensions or use cases. The FAIL is scoped to this test. |
| N/A | The control could not be evaluated within the tested scope. | The control is irrelevant; you may need a different methodology. |
8. Limitation of liability
Except for liability arising from fraud, wilful misconduct, breach of confidentiality, or death/personal injury caused by negligence, our aggregate liability for all claims arising from a Report shall not exceed the fees paid by the Customer in the twelve (12) months immediately preceding the event giving rise to liability. We exclude all indirect, consequential, special, incidental, and punitive damages, including lost profits, business interruption, and regulatory penalties.
9. Independent contractor
AgentSure is an independent contractor, not the Customer's agent or fiduciary. Nothing in any Report creates a duty of care from AgentSure to any regulatory body, court, or third party. The Customer remains solely responsible for its own compliance with applicable laws and regulations.
10. Governing law
This disclaimer is governed by the laws of the Republic of Singapore and shall be read alongside the governing contract between AgentSure and the Customer.
11. Versioning
This disclaimer is versioned. The version applicable to a specific Report is the version in effect on the Assessment Date shown in that Report. Historical versions are archived and available on request to legal@agentsure.tech.