Definite
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
“We use the data above to run the checks you configure, investigate exceptions, assemble filings and evidence packages, operate and secure the platform, provide support, and meet our own legal obligations. Agent-assisted investigation runs against your tenant's data only. We do not train models on your data and we do not share it across tenants.”
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Watch: subprocessors data sharing
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
This clause restricts data sharing to necessary subprocessors (cloud, authentication, email providers) bound by data protection terms, prohibits sale of personal data, and conditions any legally required disclosure on notifying the customer where legally permitted — a user-favorable limitation on third-party data flows.
This clause restricts the operator from selling or renting customer data, prohibits third-party advertising use, and limits data use exclusively to providing the described service — all user-favorable prohibitions on data monetization.
This clause explicitly prohibits training models on customer data and prohibits cross-tenant data sharing — both user-favorable restrictions; it also describes permitted uses of data (running checks, investigations, filing assembly, support, legal obligations) limited to the customer's own tenant.
How to read this page: Overall risk rates what Definite's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 11 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 11 citationsLast captured 2026-07-20
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
This clause defines the operator's legal identity (Ledgix Inc. d/b/a Definite), describes the platform's purpose and scope, identifies the primary privacy contact, and specifies which properties the policy covers — establishing the foundational definitions for the entire policy.
" Ledgix Inc., doing business as Definite ("Definite", "we", "us"), operates a verification platform for regulated financial reporting. Definite checks a financial institution's books against published regulatory rules and internal rulebooks..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" We share data only with the subprocessors needed to run the service, such as cloud infrastructure, authentication, and email providers, each bound by data protection terms. We do not sell personal data. We may disclose data if required by law, and we will notify you where legally permitted."
This clause restricts data sharing to necessary subprocessors (cloud, authentication, email providers) bound by data protection terms, prohibits sale of personal data, and conditions any legally required disclosure on notifying the customer where legally permitted — a user-favorable limitation on third-party data flows.
AI-generated interpretation, not legal advice.
" We use the data above to run the checks you configure, investigate exceptions, assemble filings and evidence packages, operate and secure the platform, provide support, and meet our own legal obligations. Agent-assisted investigation runs against your tenant's data only. We do not train models on your data and we do not share it across tenants."
This clause explicitly prohibits training models on customer data and prohibits cross-tenant data sharing — both user-favorable restrictions; it also describes permitted uses of data (running checks, investigations, filing assembly, support, legal obligations) limited to the customer's own tenant.
AI-generated interpretation, not legal advice.
" Definite is a B2B platform. We do not sell or rent customer data, we do not run third-party advertising, and we do not use the data you connect to Definite for anything other than providing the service described here."
This clause restricts the operator from selling or renting customer data, prohibits third-party advertising use, and limits data use exclusively to providing the described service — all user-favorable prohibitions on data monetization.
AI-generated interpretation, not legal advice.
" Ledgix Inc., doing business as Definite ("Definite", "we", "us"), operates a verification platform for regulated financial reporting. Definite checks a financial institution's books against published regulatory rules and internal rulebooks, investigates exceptions, and produces verifiable evidence for filings such as the FFIEC Call Report, NCUA 5300, and related regulatory returns. Our primary point of contact for privacy matters is contact@usedefinite.com . This policy applies to the Definite platform, including the customer console at app.usedefinite.com and our website at usedefinite.com. It does not apply to third-party services your organization connects to Definite."
This clause defines the operator's legal identity (Ledgix Inc. d/b/a Definite), describes the platform's purpose and scope, identifies the primary privacy contact, and specifies which properties the policy covers — establishing the foundational definitions for the entire policy.
AI-generated interpretation, not legal advice.
" Account and organization data. When you create an account or accept an invitation, we collect your email address, your organization name, and the authentication credentials required to log in. If your organization configures SSO, your identity provider shares the claims required to authenticate you. Connected source data. The core function of Definite is to check your institution's books. When you connect a data source, Definite takes read-only snapshots of the exports you configure, such as core banking exports, general ledger and subledger extracts, capital schedules, loan-level files, and spreadsheets. Each snapshot is hashed on arrival and stored in your tenant's isolated environment. Depending on what your institution exports, these files may contain personal data about your customers, such as borrower names, account identifiers, and loan attributes. For this data we act as a processor on your instructions. Check results and receipts. Every deterministic check writes a receipt that records the rule, the rule version, hashes of the inputs, the verdict, timestamps, and cryptographic proof artifacts. Receipts are designed around hashes and references rather than raw customer values. Public filings data. We retrieve publicly available regulatory data, such as prior Call Reports and peer filings, from sources like the FFIEC CDR, NCUA, FDIC, and OSFI. This data is already public. Support and contact data. If you contact us through the site or by email, we keep the correspondence and the contact details you provide."
This clause defines the categories of data collected, including account credentials, SSO identity claims, and read-only financial source data (core banking exports, ledger extracts, etc.), establishing what information is subject to the policy's downstream obligations.
AI-generated interpretation, not legal advice.
" For account, billing, and support data, Definite is the controller. For the financial records and personal data contained in your connected sources, your institution is the controller and Definite processes that data solely on your instructions under our agreement with you."
This clause defines the controller/processor roles: the operator is controller for account and billing data, while the customer institution is controller for financial and personal data in connected sources, with the operator processing that data solely on the customer's instructions under their agreement — establishing legal responsibility allocation.
AI-generated interpretation, not legal advice.
" Every connection to your systems is read-only. Definite cannot write back to your source systems and cannot initiate transactions. Tenant data is stored in an isolated per-tenant environment, encrypted in transit and at rest. Snapshots are hashed on arrival, and receipts are hash-chained so any alteration is detectable. Access by Definite personnel is limited, logged, and used only for support you request or operations of the service. Deployment options include single-tenant hosting in our cloud or deployment inside your own environment."
This clause imposes obligations on the operator regarding security architecture: read-only connections, per-tenant isolated storage, encryption in transit and at rest, hash-chaining of snapshots for integrity, and limiting personnel access to logged support and operations use — establishing protective data handling requirements.
AI-generated interpretation, not legal advice.
" If we make material changes, we will update this page and notify account administrators by email before the changes take effect."
This clause establishes the procedure for policy changes: the operator must update the policy page and notify account administrators by email before material changes take effect — imposing an advance-notice obligation that protects users from unannounced modifications.
AI-generated interpretation, not legal advice.
" Ledgix Inc. d/b/a Definite. Email: contact@usedefinite.com ."
This clause identifies the operator's legal name and contact email for privacy matters, completing the identification information necessary to exercise rights or escalate privacy concerns established elsewhere in the policy.
AI-generated interpretation, not legal advice.
" Connected source snapshots are retained according to your tenant's configured retention policy. Receipts and evidence packages are append-only records and are retained for the life of your agreement, and you can export them at any time. Account data is retained while your account is active and deleted or anonymized within a reasonable period after closure, except where law requires longer retention."
This clause establishes retention obligations: source snapshots are retained per the customer's configured policy; receipts and evidence packages are retained for the life of the agreement and exportable at any time; account data is deleted or anonymized within a reasonable period after closure except where law requires longer retention — defining the operator's retention duties and the customer's export right.
AI-generated interpretation, not legal advice.
" Depending on your jurisdiction, you may have rights to access, correct, delete, or export personal data we hold about you. For data contained in your institution's connected sources, direct your request to your institution and we will assist it as processor. For anything else, email contact@usedefinite.com ."
This clause grants individuals jurisdiction-dependent rights to access, correct, delete, or export personal data held by the operator, and establishes a procedure for directing requests related to institution-sourced data through the institution (as controller) with the operator assisting as processor.
AI-generated interpretation, not legal advice.
Common questions about Definite's policies
- Does Definite train its AI models on your data?
- No training on your content by default — based on 1 verified finding from Definite's published policy. Informational only, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Definite's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in Definite's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in Definite's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat Definite requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Definite's published policies yet.
What the policies actually cover
0 topicsNone of Definite's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Cross-clause notes
Two verified clauses intersect on the same subject matter: the Privacy Policy, § 6 (Retention) addresses how long content is retained, and the Privacy Policy, § 3 (How we use data) addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause permits sale of personal data or information.
“Definite is a B2B platform. We do not sell or rent customer data, we do not run third-party advertising, and we do not use the data you connect to Definite for anything other than providing the service described here.”Open source citation
The clause permits sale of personal data or information.
“We share data only with the subprocessors needed to run the service, such as cloud infrastructure, authentication, and email providers, each bound by data protection terms. We do not sell personal data. We may disclose data if required by law, and we will notify you where legally permitted.”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“We share data only with the subprocessors needed to run the service, such as cloud infrastructure, authentication, and email providers, each bound by data protection terms. We do not sell personal data. We may disclose data if required by law, and we will notify you where legally permitted.”Open source citation
The clause says submitted content is not used for model training or model/service improvement.
“We use the data above to run the checks you configure, investigate exceptions, assemble filings and evidence packages, operate and secure the platform, provide support, and meet our own legal obligations. Agent-assisted investigation runs against your tenant's data only. We do not train models on your data and we do not share it across tenants.”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | privacy data use | worsens | HIGH | 1 |
| All applicable tiers | subprocessors data sharing | worsens | HIGH | 2 |
| All applicable tiers | training use | improves | LOW | 1 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: sale or sell on privacy data use
“Definite is a B2B platform. We do not sell or rent customer data, we do not run third-party advertising, and we do not use the data you connect to Definite for anything other than providing the service described here.”Open timeline citation
Latest stance: sale or sell on subprocessors data sharing
“We share data only with the subprocessors needed to run the service, such as cloud infrastructure, authentication, and email providers, each bound by data protection terms. We do not sell personal data. We may disclose data if required by law, and we will notify you where legally permitted.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“We share data only with the subprocessors needed to run the service, such as cloud infrastructure, authentication, and email providers, each bound by data protection terms. We do not sell personal data. We may disclose data if required by law, and we will notify you where legally permitted.”Open timeline citation
Latest stance: no training claim on training use
“We use the data above to run the checks you configure, investigate exceptions, assemble filings and evidence packages, operate and secure the platform, provide support, and meet our own legal obligations. Agent-assisted investigation runs against your tenant's data only. We do not train models on your data and we do not share it across tenants.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
11 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Definite's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Definite's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Definite's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.