Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · usedefinite.com

Definite

Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskLOWReviewed 2026-07-20
Creator: low · GRC: low · Counsel: low
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

Exhibit A · Privacy Policy · verbatim

We use the data above to run the checks you configure, investigate exceptions, assemble filings and evidence packages, operate and secure the platform, provide support, and meet our own legal obligations. Agent-assisted investigation runs against your tenant's data only. We do not train models on your data and we do not share it across tenants.

highest-risk verified finding on training use — tap for the citation
11 verified findings5 policy surfaces1/1 core docs verified

Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.

Risk triage

Watch: subprocessors data sharing

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
1
medium
2
low
1/1
docs
Trains on your data?
No training on your content by default
from 1 cited finding
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Definite's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Partially verifiedWorkflow & Automation

Partially verified — Privacy Policy — Verified (read in full, 11 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.

Why partial?

Terms not yet captured

AIRIN has not yet captured a gate-verified Terms of Service document for this platform.

Document status
  • Privacy Policy
    Verified - read in full - 11 citationsLast captured 2026-07-20
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Privacy & data use

This clause defines the operator's legal identity (Ledgix Inc. d/b/a Definite), describes the platform's purpose and scope, identifies the primary privacy contact, and specifies which properties the policy covers — establishing the foundational definitions for the entire policy.

" Ledgix Inc., doing business as Definite ("Definite", "we", "us"), operates a verification platform for regulated financial reporting. Definite checks a financial institution's books against published regulatory rules and internal rulebooks..."
📍 § 1 (Who we are)Jump to exact text →

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 1
Tier-specific - 0
Total citations - 11
Severity
Surface
Document
Tier
Subprocessors & data sharing
High
" We share data only with the subprocessors needed to run the service, such as cloud infrastructure, authentication, and email providers, each bound by data protection terms. We do not sell personal data. We may disclose data if required by law, and we will notify you where legally permitted."
§ 7 (Sharing and subprocessors)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This clause restricts data sharing to necessary subprocessors (cloud, authentication, email providers) bound by data protection terms, prohibits sale of personal data, and conditions any legally required disclosure on notifying the customer where legally permitted — a user-favorable limitation on third-party data flows.

AI-generated interpretation, not legal advice.

Training on your content
High
" We use the data above to run the checks you configure, investigate exceptions, assemble filings and evidence packages, operate and secure the platform, provide support, and meet our own legal obligations. Agent-assisted investigation runs against your tenant's data only. We do not train models on your data and we do not share it across tenants."
§ 3 (How we use data)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This clause explicitly prohibits training models on customer data and prohibits cross-tenant data sharing — both user-favorable restrictions; it also describes permitted uses of data (running checks, investigations, filing assembly, support, legal obligations) limited to the customer's own tenant.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Definite is a B2B platform. We do not sell or rent customer data, we do not run third-party advertising, and we do not use the data you connect to Definite for anything other than providing the service described here."
Privacy Policy › “Privacy Policy - Tywin – AI-Powered Developer Tool Template”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This clause restricts the operator from selling or renting customer data, prohibits third-party advertising use, and limits data use exclusively to providing the described service — all user-favorable prohibitions on data monetization.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Ledgix Inc., doing business as Definite ("Definite", "we", "us"), operates a verification platform for regulated financial reporting. Definite checks a financial institution's books against published regulatory rules and internal rulebooks, investigates exceptions, and produces verifiable evidence for filings such as the FFIEC Call Report, NCUA 5300, and related regulatory returns. Our primary point of contact for privacy matters is contact@usedefinite.com . This policy applies to the Definite platform, including the customer console at app.usedefinite.com and our website at usedefinite.com. It does not apply to third-party services your organization connects to Definite."
§ 1 (Who we are)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This clause defines the operator's legal identity (Ledgix Inc. d/b/a Definite), describes the platform's purpose and scope, identifies the primary privacy contact, and specifies which properties the policy covers — establishing the foundational definitions for the entire policy.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Account and organization data. When you create an account or accept an invitation, we collect your email address, your organization name, and the authentication credentials required to log in. If your organization configures SSO, your identity provider shares the claims required to authenticate you. Connected source data. The core function of Definite is to check your institution's books. When you connect a data source, Definite takes read-only snapshots of the exports you configure, such as core banking exports, general ledger and subledger extracts, capital schedules, loan-level files, and spreadsheets. Each snapshot is hashed on arrival and stored in your tenant's isolated environment. Depending on what your institution exports, these files may contain personal data about your customers, such as borrower names, account identifiers, and loan attributes. For this data we act as a processor on your instructions. Check results and receipts. Every deterministic check writes a receipt that records the rule, the rule version, hashes of the inputs, the verdict, timestamps, and cryptographic proof artifacts. Receipts are designed around hashes and references rather than raw customer values. Public filings data. We retrieve publicly available regulatory data, such as prior Call Reports and peer filings, from sources like the FFIEC CDR, NCUA, FDIC, and OSFI. This data is already public. Support and contact data. If you contact us through the site or by email, we keep the correspondence and the contact details you provide."
§ 2 (What data we collect)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This clause defines the categories of data collected, including account credentials, SSO identity claims, and read-only financial source data (core banking exports, ledger extracts, etc.), establishing what information is subject to the policy's downstream obligations.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" For account, billing, and support data, Definite is the controller. For the financial records and personal data contained in your connected sources, your institution is the controller and Definite processes that data solely on your instructions under our agreement with you."
§ 4 (Controller and processor roles)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This clause defines the controller/processor roles: the operator is controller for account and billing data, while the customer institution is controller for financial and personal data in connected sources, with the operator processing that data solely on the customer's instructions under their agreement — establishing legal responsibility allocation.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Every connection to your systems is read-only. Definite cannot write back to your source systems and cannot initiate transactions. Tenant data is stored in an isolated per-tenant environment, encrypted in transit and at rest. Snapshots are hashed on arrival, and receipts are hash-chained so any alteration is detectable. Access by Definite personnel is limited, logged, and used only for support you request or operations of the service. Deployment options include single-tenant hosting in our cloud or deployment inside your own environment."
§ 5 (Security and where data lives)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This clause imposes obligations on the operator regarding security architecture: read-only connections, per-tenant isolated storage, encryption in transit and at rest, hash-chaining of snapshots for integrity, and limiting personnel access to logged support and operations use — establishing protective data handling requirements.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" If we make material changes, we will update this page and notify account administrators by email before the changes take effect."
§ 9 (Changes to this policy)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This clause establishes the procedure for policy changes: the operator must update the policy page and notify account administrators by email before material changes take effect — imposing an advance-notice obligation that protects users from unannounced modifications.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Ledgix Inc. d/b/a Definite. Email: contact@usedefinite.com ."
§ 10 (Contact)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This clause identifies the operator's legal name and contact email for privacy matters, completing the identification information necessary to exercise rights or escalate privacy concerns established elsewhere in the policy.

AI-generated interpretation, not legal advice.

Data retention
High
" Connected source snapshots are retained according to your tenant's configured retention policy. Receipts and evidence packages are append-only records and are retained for the life of your agreement, and you can export them at any time. Account data is retained while your account is active and deleted or anonymized within a reasonable period after closure, except where law requires longer retention."
§ 6 (Retention)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This clause establishes retention obligations: source snapshots are retained per the customer's configured policy; receipts and evidence packages are retained for the life of the agreement and exportable at any time; account data is deleted or anonymized within a reasonable period after closure except where law requires longer retention — defining the operator's retention duties and the customer's export right.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
" Depending on your jurisdiction, you may have rights to access, correct, delete, or export personal data we hold about you. For data contained in your institution's connected sources, direct your request to your institution and we will assist it as processor. For anything else, email contact@usedefinite.com ."
§ 8 (Your rights)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This clause grants individuals jurisdiction-dependent rights to access, correct, delete, or export personal data held by the operator, and establishes a procedure for directing requests related to institution-sourced data through the institution (as controller) with the operator assisting as processor.

AI-generated interpretation, not legal advice.

Common questions about Definite's policies

Does Definite train its AI models on your data?
No training on your content by default — based on 1 verified finding from Definite's published policy. Informational only, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Definite's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in Definite's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in Definite's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What Definite requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in Definite's published policies yet.

What the policies actually cover

0 topics

None of Definite's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Cross-clause notes

Cross-reference

Two verified clauses intersect on the same subject matter: the Privacy Policy, § 6 (Retention) addresses how long content is retained, and the Privacy Policy, § 3 (How we use data) addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.

Automated cross-reference against the published rubric — not legal advice.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

11
clauses
4
patterns
4
stances
privacy sharing · 3training use · 1
privacy sharingHIGHPrivacy Policy › “Privacy Policy - Tywin – AI-Powered Developer Tool Template”

The clause permits sale of personal data or information.

Definite is a B2B platform. We do not sell or rent customer data, we do not run third-party advertising, and we do not use the data you connect to Definite for anything other than providing the service described here.
Open source citation
privacy sharingHIGH§ 7 (Sharing and subprocessors)

The clause permits sale of personal data or information.

We share data only with the subprocessors needed to run the service, such as cloud infrastructure, authentication, and email providers, each bound by data protection terms. We do not sell personal data. We may disclose data if required by law, and we will notify you where legally permitted.
Open source citation
privacy sharingMEDIUM§ 7 (Sharing and subprocessors)

The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.

We share data only with the subprocessors needed to run the service, such as cloud infrastructure, authentication, and email providers, each bound by data protection terms. We do not sell personal data. We may disclose data if required by law, and we will notify you where legally permitted.
Open source citation
training useLOW§ 3 (How we use data)

The clause says submitted content is not used for model training or model/service improvement.

We use the data above to run the checks you configure, investigate exceptions, assemble filings and evidence packages, operate and secure the platform, provide support, and meet our own legal obligations. Agent-assisted investigation runs against your tenant's data only. We do not train models on your data and we do not share it across tenants.
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersprivacy data useworsensHIGH1
All applicable tierssubprocessors data sharingworsensHIGH2
All applicable tierstraining useimprovesLOW1

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Jul 20, 2026data sharingHIGH

Latest stance: sale or sell on privacy data use

Definite is a B2B platform. We do not sell or rent customer data, we do not run third-party advertising, and we do not use the data you connect to Definite for anything other than providing the service described here.
Open timeline citation
Jul 20, 2026data sharingHIGH

Latest stance: sale or sell on subprocessors data sharing

We share data only with the subprocessors needed to run the service, such as cloud infrastructure, authentication, and email providers, each bound by data protection terms. We do not sell personal data. We may disclose data if required by law, and we will notify you where legally permitted.
Open timeline citation
Jul 20, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on subprocessors data sharing

We share data only with the subprocessors needed to run the service, such as cloud infrastructure, authentication, and email providers, each bound by data protection terms. We do not sell personal data. We may disclose data if required by law, and we will notify you where legally permitted.
Open timeline citation
Jul 20, 2026model trainingLOW

Latest stance: no training claim on training use

We use the data above to run the checks you configure, investigate exceptions, assemble filings and evidence packages, operate and secure the platform, provide support, and meet our own legal obligations. Agent-assisted investigation runs against your tenant's data only. We do not train models on your data and we do not share it across tenants.
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

11 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Definite's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Know where the missing document lives?

We haven't yet verified Definite's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.

Every finding above is a verbatim quote from Definite's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.