Legal

Terms of Service

The terms on which organisations subscribe to and use Rukn ERM. Written to be read — your data stays yours, and we say plainly what we do and do not promise.

Effective: 26 August 2026  ·  Last updated: 14 September 2026

These Terms of Service (“Terms”) govern access to and use of the Rukn ERM enterprise risk management platform (the “Platform” or “Service”), provided by Hassan Moubarak, sole proprietor and operator of Rukn ERM, of 30 Mohamed El Makreef, Cairo, Egypt (the “Provider”, “we”, “us”).

By subscribing to, accessing, or using the Platform, the customer (“Customer”, “you”) agrees to these Terms. If you accept these Terms on behalf of an organisation, you confirm that you have authority to bind that organisation.

These Terms should be read together with our Privacy Policy, which explains how we handle personal data, and our security page, which describes the controls protecting the Platform.

1. Definitions

  • Account — the Customer’s organisation-level account on the Platform.
  • Authorised User — an employee, officer, contractor or other individual the Customer permits to use the Platform under its subscription.
  • Customer Data — everything submitted to or generated within the Platform by or for the Customer: risk registers, assessments, controls, key risk indicators, incidents, actions, policies, committees, compliance mappings, audit findings, comments, attachments, reports and configuration.
  • Subscription — the Customer’s paid subscription to a plan, for the applicable term.
  • Third-Party Services — infrastructure, hosting, storage, email, analytics and model providers we use to operate the Platform.

2. Acceptance

2.1 These Terms are a binding agreement between the Provider and the Customer.

2.2 The Customer accepts them by creating an Account, signing an order form or quotation, or otherwise using the Platform.

2.3 Where a separate signed agreement exists between the Provider and the Customer, that agreement prevails over these Terms to the extent of any conflict.

2.4 We may update these Terms. Material changes will be notified through the Platform, by email to the Customer’s administrative contact, or by other reasonable means, and the “last updated” date above will change.

2.5 Continued use after an update takes effect constitutes acceptance, except where applicable law requires express acceptance.

3. What the Platform does

3.1 Rukn ERM is a software-as-a-service platform that helps organisations record, assess, monitor, report and communicate risk. It is aligned to the COSO ERM 2017 framework and available in Arabic and English, on mobile and in a browser.

3.2 Depending on the subscribed plan, the Platform includes:

  • A risk register with inherent and residual 5×5 scoring and a heat map;
  • Key risk indicators with thresholds and status;
  • Risk appetite statements measured against actual exposure;
  • A controls library linked to the risks it mitigates;
  • Incident recording and mitigating action tracking;
  • Governance — committees, meetings and policy management;
  • Compliance mapping and audit finding management;
  • Monte Carlo quantification;
  • Reporting to Excel, PowerPoint and PDF;
  • File attachments on risks, incidents, policies and findings;
  • An activity log recording changes made within the Account;
  • User and role management, optional multi-factor authentication and a biometric app lock;
  • An AI risk assistant, subject to section 5; and
  • Other functionality we introduce from time to time.

3.3 We may modify, improve, replace or retire individual features, provided we do not materially reduce the core functionality of a subscribed plan. Where a retirement materially affects a Customer’s use, we will give reasonable notice and, where appropriate, an alternative.

3.4 The Platform is an information system, not a decision-maker. It does not replace the Customer’s professional judgement, management decisions, internal controls, audit processes, legal advice or regulatory obligations. See section 16.

4. Subscription and licence

4.1 Subject to payment of the applicable fees and compliance with these Terms, the Provider grants the Customer a limited, non-exclusive, non-transferable, non-sublicensable right to access and use the Platform during the subscription term.

4.2 The subscription is a right of access. It is not a sale or transfer of ownership of the Platform.

4.3 The Customer may permit Authorised Users to access the Platform within the user limit of its plan.

4.4 The Customer shall not: copy, resell, lease, sublicense or commercially exploit the Platform; reverse engineer, decompile or attempt to derive its source code except where applicable law expressly permits; create derivative works; circumvent security or access controls; use the Platform to build a competing product; access it for benchmarking or competitive analysis without our prior written consent; attempt to reach another customer’s account or data; introduce malicious code; or use the Platform unlawfully.

5. The AI risk assistant

5.1 Plans that include the AI risk assistant allow Authorised Users to ask questions about their own register in natural language.

5.2 To answer, the Platform sends a summary of the Customer’s register to a third-party AI model provider. That summary may include risk titles and descriptions, scores, categories, owners, controls, indicators, incidents, actions and audit findings. It does not include file attachments.

5.3 We use the model provider under terms that do not permit Customer Data to be used to train their models.

5.4 Answers are generated by a language model and may be incomplete or wrong. They are a starting point for a person who knows the register, not an authoritative statement about it, and section 16 applies to them in full.

5.5 Answers reflect the register as at the point the Platform last read it, which may be up to an hour earlier. The Platform states this alongside each answer.

5.6 Assistant usage is metered and each plan includes an allowance. Where an allowance is exhausted, the feature may be unavailable until the next monthly period.

5.7 A Customer that does not wish its data to be sent to a model provider should not use this feature; the rest of the Platform functions without it.

6. Accounts and user responsibilities

6.1 The Customer is responsible for the accuracy of the information it provides when establishing its Account.

6.2 The Customer is responsible for: keeping account credentials confidential; controlling which individuals are Authorised Users; ensuring Authorised Users comply with these Terms; promptly disabling accounts of people no longer entitled to access; and activity conducted through its Account, except where caused by our own proven unauthorised access.

6.3 The Customer must notify us promptly on suspecting unauthorised access, compromised credentials or a security incident affecting its Account.

6.4 We may suspend an Account where reasonably necessary to protect the Platform, other customers, or the security of the Service. See section 20.

7. Customer Data and ownership

7.1 The Customer owns its Customer Data. Nothing in these Terms transfers ownership of it to the Provider.

7.2 The Customer grants us a limited right to host, store, process, transmit and reproduce Customer Data only so far as necessary to provide, maintain, secure and support the Platform.

7.3 The Customer is responsible for having the rights, permissions and lawful grounds to submit Customer Data to the Platform, and for its accuracy, completeness and legality.

7.4 We do not assess whether any risk, score, control, treatment or management decision recorded by the Customer is appropriate or sufficient.

7.5 We do not sell Customer Data, and we do not use it for advertising.

8. Hosting, security and third-party services

8.1 The Platform runs on third-party cloud infrastructure. Customer Data is stored and processed on infrastructure operated by those providers on our behalf.

8.2 We implement reasonable technical and organisational measures designed to protect Customer Data against unauthorised access, alteration, disclosure, loss or destruction. These currently include per-tenant scoping of every request, role-based access control, optional multi-factor authentication, an optional biometric app lock, encryption in transit, and an activity log of changes made within an Account. Our security page describes these in more detail.

8.3 No internet-based system can be guaranteed completely secure. We do not warrant that the Platform will be immune from every possible attack, vulnerability or unauthorised access event.

8.4 The Customer is responsible for security on its own side: device security, password management, and controlling who holds credentials.

8.5 We will notify affected Customers of confirmed security incidents involving their Customer Data where required by applicable law or our contractual obligations.

8.6 We may change infrastructure or third-party providers where reasonably necessary to operate, secure or improve the Platform. We are not responsible for failures originating solely from a third-party service and outside our reasonable control.

9. Backups, availability and maintenance

9.1 We maintain backups of Customer Data as part of operating the Platform. Backups exist to support service recovery; they are not an archival service on the Customer’s behalf.

9.2 We will use commercially reasonable efforts to restore Customer Data from available backups after a material failure, but do not guarantee that every item can be recovered after every possible event.

9.3 We will use commercially reasonable efforts to keep the Platform available. It may be unavailable for scheduled or emergency maintenance, software updates, infrastructure or third-party failures, security incidents, telecommunications failures, or events outside our reasonable control. Where practicable, scheduled maintenance is notified in advance.

9.4 These Terms do not commit us to a specific uptime percentage, response time, recovery point or recovery time. A Customer requiring those commitments should agree them in a separate written service level agreement.

10. Fees, invoicing and renewal

10.1 Access to the Platform is provided in exchange for the subscription fees for the selected plan.

10.2 Fees, billing frequency, user limits and included functionality are set out in the applicable quotation or order form. Prices are quoted per organisation.

10.3 Billing is by invoice. The Platform does not store payment card details and does not charge a payment method automatically. Invoices are payable within the period stated on them.

10.4 Fees are exclusive of VAT and any other applicable taxes or duties, which are added on the invoice. The Customer is responsible for taxes associated with its subscription.

10.5 Each plan begins with a 30-day free trial. No fees are payable during the trial and no payment details are required to start one.

10.6 Where an invoice is overdue we may give notice and, where permitted by applicable law, suspend access until it is settled.

10.7 Fees already paid for a period are non-refundable, except where applicable law requires otherwise or we have agreed otherwise in writing.

10.8 A subscription continues for successive periods unless either party gives notice not to renew before the end of the current period. Because billing is by invoice, no charge is taken without one being issued.

10.9 We may change pricing on reasonable advance notice. Changes apply from the next renewal period, not mid-term.

11. Export, retention and deletion

11.1 During an active subscription the Customer may export its Customer Data using the Platform’s reporting and export functionality.

11.2 After a subscription ends we retain Customer Data for 90 days, so that the Customer can export it and so we can meet legal, security and operational obligations.

11.3 After that period we may permanently delete Customer Data. Once deleted, it cannot be recovered.

11.4 The Customer is responsible for completing any export it needs before the 90 days expire. We will remind the Customer’s administrative contact before deletion, but the responsibility remains the Customer’s.

12. Personal data

12.1 We process personal data in accordance with our Privacy Policy.

12.2 Where the Customer puts personal data about its employees, suppliers or others into the Platform, the Customer is the controller of that data and is responsible for ensuring the processing and its disclosure to us are lawful.

12.3 Where applicable, the parties may enter into a separate data processing agreement. If one is signed, it prevails over these Terms on personal-data processing to the extent of any conflict.

12.4 The Customer should not submit special-category or otherwise highly sensitive personal information to the Platform unless we have agreed in writing that it is designed for that purpose.

13. Confidentiality

13.1 Each party may receive confidential information belonging to the other. Each will protect it using reasonable measures, use it only in connection with this relationship, and not disclose it to unauthorised third parties.

13.2 Confidential information does not include information that is public without breach of these Terms, was lawfully known before disclosure, is independently developed without use of it, or is lawfully received from a third party without restriction.

13.3 Either party may disclose confidential information where required by law, regulation or court order, subject to applicable legal requirements.

14. Intellectual property

14.1 The Platform — its software, source code, interface, design, workflows, documentation, trademarks and underlying technology — is owned by or licensed to the Provider. No intellectual property rights in it transfer to the Customer beyond the limited right of use granted in section 4.

14.2 The Customer retains ownership of Customer Data, as stated in section 7.

14.3 We may use feedback and suggestions from the Customer to improve the Platform, provided doing so does not disclose the Customer’s confidential information or identify the Customer without permission.

15. Aggregated and de-identified information

15.1 We generate statistical and operational information about how the Platform is used — performance, error rates, capacity, feature usage.

15.2 We may use aggregated or de-identified information to improve and secure the Service, plan capacity and develop the product.

15.3 Such information will not identify the Customer or disclose its confidential information, and we do not sell Customer Data as a data product.

16. What the Platform does not do

16.1 The Platform is a tool that supports risk management. It does not provide legal, accounting, audit, investment, insurance, regulatory, financial or cybersecurity advice.

16.2 Risk scores, classifications, control assessments, dashboards, reports, alerts and AI assistant answers are outputs of what the Customer has entered and of the model applied to it. They are not a substitute for professional judgement.

16.3 The Customer is solely responsible for decisions made using information held in the Platform.

16.4 We do not guarantee that using the Platform will identify every risk, prevent losses or fraud, ensure regulatory compliance, ensure a successful audit, eliminate operational failures, or prevent security incidents.

16.5 The Customer remains responsible for its own risk management framework, governance, internal controls, policies, procedures, regulatory obligations and management decisions.

17. Warranties

17.1 We warrant that we will provide the Platform with reasonable care and skill.

17.2 Except for warranties expressly stated in these Terms or a signed agreement, and to the maximum extent permitted by applicable law, the Platform is provided “as is” and “as available”, and implied warranties are excluded.

17.3 We do not warrant that the Platform will be uninterrupted or error-free, that every feature will meet every requirement, that it will be compatible with every third-party system, or that it will prevent every possible security incident.

18. Limitation of liability

18.1 Exclusion of consequential damages. To the maximum extent permitted by law, the Provider shall not be liable for any indirect, incidental, special, consequential, punitive or exemplary damages, including damages for loss of profits, revenue, goodwill, use, data, business interruption or other intangible losses, even if the Provider has been advised of the possibility of such damages.

18.2 Specific exclusions. The Provider is not liable for losses arising from: misuse of the Platform; incorrect or incomplete Customer Data; decisions the Customer makes based on Platform outputs; failure to maintain appropriate credentials; unauthorised activity by the Customer’s own personnel; third-party services outside our reasonable control; internet or telecommunications failures; or events beyond our reasonable control.

18.3 Cap on liability. The Provider’s total cumulative liability to the Customer for all claims arising out of or relating to these Terms or the Service, whether in contract, tort (including negligence), strict liability or any other theory, shall not exceed the greater of: (a) the total amount of fees paid by the Customer to the Provider in the twelve (12) months immediately preceding the event giving rise to liability; or (b) five hundred United States dollars (US$500). This limitation applies regardless of whether any remedy fails of its essential purpose.

18.4 Essential basis. The Customer acknowledges that the limitations of liability and disclaimers of warranty in these Terms represent a reasonable allocation of risk and form an essential basis of the bargain between the parties. The Provider would not be able to provide the Service at the applicable price without them.

18.5 Exceptions. Nothing in these Terms limits or excludes liability that cannot be limited or excluded under applicable law, including liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) gross negligence or wilful misconduct; or (d) any other liability that cannot be limited under the governing law specified in section 25.

19. Indemnity

19.1 To the extent permitted by applicable law, the Customer will indemnify and hold harmless the Provider and its officers, employees and contractors against claims, losses, damages, liabilities and reasonable expenses arising from: Customer Data that breaches applicable law or third-party rights; unlawful use of the Platform; breach of these Terms; unauthorised use of the Customer’s Account caused by its failure to maintain appropriate security; or decisions and actions the Customer takes based on its use of the Platform.

20. Suspension and termination

20.1 We may temporarily suspend access where reasonably necessary to protect the security or integrity of the Platform, prevent unlawful or abusive activity, comply with legal requirements, prevent harm to other customers, or address material non-payment. Where practicable we will give notice first and an opportunity to remedy.

20.2 Either party may terminate the subscription in accordance with the applicable order form or these Terms.

20.3 We may terminate or suspend where the Customer materially breaches these Terms and does not remedy the breach within 30 days of written notice, or immediately where required by law or where continued operation would create a significant security or legal risk.

20.4 On termination: access to the Platform ceases; outstanding fees become due where permitted by applicable law; the Customer may export its Customer Data during the retention period in section 11; and Customer Data is then deleted in accordance with that section.

21. Survival

Sections concerning Customer Data ownership, confidentiality, intellectual property, payment obligations, limitation of liability, indemnity, retention and deletion, governing law and dispute resolution, and any provision that by its nature should survive, remain in effect after termination.

22. Force majeure

We are not liable for failure or delay in performing our obligations where it results from circumstances beyond our reasonable control, including natural disasters, war, terrorism, civil unrest, government action, widespread internet disruption, telecommunications or cloud infrastructure failure, epidemics, strikes, power failures or major cybersecurity incidents.

23. Audit and compliance

23.1 The Customer is responsible for determining whether the Platform is appropriate for its regulatory, contractual and internal-control requirements.

23.2 Where a Customer’s regulatory obligations require it, we will provide reasonable information about our security and operational controls, subject to confidentiality and reasonable restrictions.

23.3 Any formal audit, penetration test or customer-specific assurance activity is subject to prior written agreement between the parties.

24. Communications and notices

24.1 We may contact the Customer’s authorised contacts about account administration, subscription and invoicing, security notifications, availability and maintenance, product updates, and material changes to these Terms.

24.2 The Customer is responsible for keeping its administrative contact details accurate.

24.3 Formal notices concerning termination, material breach or legal claims should be sent to support@rukn-erm.com and to the address above.

25. Governing law and disputes

25.1 These Terms are governed by and interpreted in accordance with the laws of the Arab Republic of Egypt, without regard to conflict-of-law principles.

25.2 The parties will first attempt in good faith to resolve any dispute through negotiation between authorised representatives.

25.3 If a dispute is not resolved within 30 days, it shall be submitted to the courts of the Arab Republic of Egypt, unless the parties agree in writing to arbitration or another mechanism.

26. General

26.1 Entire agreement. These Terms, with any applicable order form, quotation, data processing agreement, service level agreement and the policies referenced here, form the agreement between the parties concerning the Service.

26.2 Severability. If any provision is found invalid or unenforceable, the rest remains in effect.

26.3 Waiver. Not enforcing a provision does not waive it.

26.4 Assignment. The Customer may not assign its rights or obligations without our prior written consent, except as part of a merger, acquisition or reorganisation.

26.5 Independent parties. Nothing here creates a partnership, joint venture, agency, employment or fiduciary relationship.

26.6 No third-party beneficiaries. These Terms do not create rights for third parties unless expressly stated.

27. Contact

For questions about these Terms or the Platform:

Last updated: 14 September 2026