Audit Rights, Compliance Verification, and Security Assurance
Last updated: 7 September 2026
MugatuAI LLC (“MugatuAI”, “we”, “us”) — publisher of MugatuAI Signal.
This addendum describes the audit rights, compliance verification procedures, and security assurance commitments available to MugatuAI Signal enterprise customers.
W.1 Third-Party Certifications and Reports
Mugatu AI shall maintain independent verification of its technical, operational, and administrative security controls. Upon Customer’s written request (no more than once per twelve (12) month period), Mugatu AI shall provide Customer with a copy of its then-current third-party security assurance artifacts, which may include:
- an executive summary of its most recent System and Organization Controls (SOC) 2 Type II report (or equivalent industry-standard certification, such as ISO/IEC 27001); and
- an executive summary or attestation letter of its most recent annual third-party network penetration test and vulnerability assessment, sanitized to remove sensitive architectural vulnerabilities or exploits.
All such reports and certifications constitute Mugatu AI Confidential Information and shall be treated with the highest degree of confidentiality pursuant to Section 4 (Mutual Confidentiality & Trade Secrets).
W.2 Information Security Inquiries
To satisfy Customer’s regulatory or vendor risk-management obligations, Customer may submit one (1) standard information security questionnaire (e.g., SIG, CAIQ, or Customer’s internal equivalent) per twelve (12) month period. Mugatu AI shall provide complete, accurate, and prompt written responses within thirty (30) calendar days of receipt.
W.3 Limited Customer Audit Rights
Customer shall rely primarily on the third-party audit reports and security attestations provided under Section W.1 to confirm compliance with this Agreement. If Customer reasonably demonstrates that the reports provided under Section W.1 are insufficient to satisfy a mandatory statutory audit requirement or an inquiry directed by a supervisory regulatory authority having jurisdiction over Customer, Customer (or an independent, certified third-party auditor approved in writing by Mugatu AI, excluding any direct or indirect competitor of Mugatu AI) may conduct a limited audit of Mugatu AI’s compliance with the data protection and security terms of this Agreement, subject to the following strict conditions:
- Notice and Timing. Customer must provide Mugatu AI with at least thirty (30) business days’ prior written notice detailing the proposed scope, regulatory necessity, and duration of the audit. Audits shall occur solely during normal business hours and shall not unreasonably disrupt Mugatu AI’s commercial or engineering operations.
- Frequency. Any such audit shall occur no more than once per calendar year, unless explicitly compelled by an active, written directive from a competent regulatory authority or following an actual, confirmed Security Incident affecting Customer Data.
- Scope and Protections. Customer and its auditors shall have no right to access, inspect, copy, or view:
- any source code, algorithms, model architectures, weights, or proprietary software components;
- any data, telemetry, or confidential materials belonging to other Mugatu AI customers; or
- Mugatu AI’s internal production systems, continuous integration/continuous deployment (CI/CD) pipelines, or raw administrative vaults.
- Confidentiality and Protocols. Prior to commencement, any third-party auditor must execute a non-disclosure agreement directly with Mugatu AI on terms substantially similar to this Agreement. The auditor must adhere to all Mugatu AI security, physical access, and facility rules while on premises or logged into review portals.
W.4 Costs of Audit
Customer shall bear all third-party and internal costs incurred by Customer in conducting any audit under this Section W. If an audit requires Mugatu AI to expend substantial engineering, technical, or administrative resources exceeding forty (40) hours of personnel time, Mugatu AI reserves the right to invoice Customer for such excess support at Mugatu AI’s then-current standard professional services hourly rates, unless the audit definitively uncovers a material, willful failure by Mugatu AI to maintain the security commitments expressly set forth in this Agreement.
W.5 Remediation
If an audit or third-party assessment conducted under this Section W identifies a material non-compliance by Mugatu AI with the security specifications of this Agreement, Mugatu AI shall, at its sole cost:
- evaluate the findings; and
- prepare and implement a commercially reasonable remediation roadmap within a mutually agreed, risk-proportionate timeframe (not to exceed sixty (60) days for critical vulnerabilities).