Skip to Content

ENTERPRISE LEGAL FRAMEWORK


The following legal framework is designed as a production-ready enterprise-grade Terms & Conditions ecosystem for YARBIS, intended for deployment within the YARBIS platform and public website infrastructure throughout the United States.

ARTICLE 1. ELIGIBILITY, KYB VERIFICATION & LICENSING

1.1 Regulatory Licensing Prerequisite

Access to and utilization of the YARBIS multi-tenant Software-as-a-Service platform is strictly conditioned upon the Subscriber maintaining an active, valid, and unencumbered professional license issued by appropriate federal and state regulatory authorities throughout the entire duration of this Agreement. Any lapse, suspension, limitation, or revocation of a required license constitutes a material breach of this Agreement.

1.2 Mandatory Identity & License Mapping

Prior to account activation, and continuously throughout the duration of this Agreement, Subscribers operating within the mortgage lending sector shall provide their verified Nationwide Multistate Licensing System (NMLS) unique identifier. Subscribers operating within the real estate brokerage sector shall provide their active state-issued Real Estate Broker or Salesperson license number. YARBIS reserves the right to conduct periodic verification of licensing status against applicable regulatory databases.

1.3 Account Suspension for Regulatory Non-Compliance

YARBIS reserves a commercially reasonable right — consistent with applicable law and internal compliance procedures — to suspend or terminate platform access upon confirmation that a Subscriber's professional licensing status has lapsed, been suspended, or been permanently revoked. YARBIS shall use commercially reasonable efforts to provide advance written notice of such suspension where feasible and where such notice does not conflict with regulatory obligations or risk management requirements. Any prepaid subscription fees remaining at the time of such suspension shall be evaluated and, where applicable, credited or refunded in accordance with applicable law.

1.4 Enhanced Kyb Authority Verification

Subscriber represents, warrants, and covenants on an ongoing basis that:

(a) Subscriber is a legally existing entity validly organized and in good standing under the laws of its jurisdiction of formation;

(b) the individual accepting this Agreement possesses full legal authority to bind Subscriber contractually;

(c) Subscriber possesses all licenses, approvals, registrations, permits, lending authorities, servicing authorities, broker licenses, and regulatory authorizations required for Subscriber's business operations and intended use of the YARBIS platform;

(d) Subscriber is not acting on behalf of, controlled by, or substantially owned by any sanctioned individual, blocked person, prohibited entity, or restricted jurisdiction under applicable sanctions laws;

(e) Subscriber shall promptly notify YARBIS of any suspension, revocation, lapse, investigation, consent order, regulatory enforcement action, or material licensing deficiency affecting Subscriber's regulated operations.

YARBIS reserves the right to request commercially reasonable documentary evidence supporting Subscriber's compliance with this Article, including beneficial ownership information, licensing records, regulatory registrations, and corporate authorization documentation.

1.5 Enterprise Legal Framework Hierarchy

The Enterprise Legal Framework ("ELF") consists of the Master SaaS Agreement and all incorporated policies, addenda, disclosures, schedules, frameworks, and governance documents referenced therein.

 

Unless expressly stated otherwise, the order of precedence in the event of conflict shall be:

 

(a) executed Order Forms;

(b) negotiated enterprise amendments expressly signed by both parties;

(c) this Master SaaS Agreement;

(d) the Data Processing Addendum;

(e) the Binding Arbitration Agreement;

(f) regulatory compliance addenda;

(g) security and operational policies;

(h) all remaining incorporated governance documents.

 

No policy, framework, operational document, security procedure, or incorporated exhibit shall expand YARBIS liability beyond the limitations expressly established under this Agreement unless explicitly stated in writing by authorized legal representatives of YARBIS.

ARTICLE 2. DATA LIFECYCLE MANAGEMENT & 90-DAY PURGE PROTOCOL

2.1 Data Minimization Architecture

In furtherance of YARBIS's compliance obligations under the Gramm-Leach-Bliley Act (GLBA), applicable state financial privacy statutes, and sound cybersecurity risk management principles, YARBIS maintains a structured, automated data lifecycle management protocol designed to minimize unnecessary retention of Nonpublic Personal Information (NPI) and sensitive financial documentation.

2.2 Automated Deletion Triggers

YARBIS shall execute commercially reasonable deletion protocols, consistent with industry-standard cloud infrastructure practices, upon the earliest occurrence of any of the following: (a) successful completion of the mortgage intelligence review cycle and export of the final structured digital package; (b) ninety (90) consecutive calendar days of operational inactivity on an individual borrower file; or (c) technical obsolescence of underlying financial documents rendering the file non-processable.

2.3 Technical Deletion Standards

Deletion procedures shall be executed using industry-standard data erasure protocols applied to primary data stores accessible to YARBIS. Subscriber acknowledges that cloud infrastructure inherently involves distributed redundancy mechanisms, backup systems, and archival logs maintained by third-party infrastructure providers, and that YARBIS cannot warrant instantaneous elimination from all such layers. YARBIS shall use commercially reasonable efforts consistent with its infrastructure agreements to cascade deletion requests.

2.4 Subscriber Retention Obligations

Subscriber expressly acknowledges and agrees that YARBIS does not function as a permanent document repository, Electronic Document Management System (EDMS), or regulatory Loan Origination System (LOS) storage solution. Subscriber bears an affirmative, independent, and continuous duty to download, verify, and securely archive all required transactional records within its local, licensed institutional infrastructure prior to the applicable deletion window. YARBIS shall not be liable for loss of data resulting from Subscriber's failure to comply with this obligation.

ARTICLE 2.5 — DATA RETENTION, PRESERVATION & LEGAL HOLD OVERRIDE

YARBIS maintains commercially reasonable data minimization and deletion protocols intended to reduce unnecessary retention of non-public personal information ("NPI") and sensitive financial records.

Unless otherwise required by applicable law, executed enterprise agreement, regulatory preservation requirement, litigation hold, subpoena, governmental inquiry, civil investigative demand, or documented Subscriber instruction, YARBIS may delete Subscriber-submitted documents and associated sensitive data following expiration of the applicable retention period established under YARBIS operational policies.

Notwithstanding the foregoing, all automated deletion, purge, archival destruction, anonymization, or lifecycle expiration procedures shall immediately suspend upon:

(a)    actual or reasonably anticipated litigation;

(b)    arbitration demand;

(c)    subpoena;

(d)    governmental inquiry;

(e)    regulatory investigation;

(f)     preservation request from Subscriber;

(g)    internal legal hold determination by YARBIS legal counsel.

YARBIS shall maintain documented legal hold procedures reasonably designed to preserve relevant electronically stored information ("ESI"), audit logs, metadata, transactional records, model-interaction logs, and security evidence potentially relevant to pending or anticipated disputes.

No deletion policy shall operate in a manner inconsistent with applicable preservation obligations under federal, state, or international law.

ARTICLE 3. LIMITATION OF LIABILITY

3.1 Exclusion of Consequential Damages

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, YARBIS, ITS AFFILIATES, OFFICERS, DIRECTORS, DEVELOPERS, AND AGENTS SHALL NOT BE LIABLE UNDER ANY CONTRACT, TORT, STRICT LIABILITY, OR NEGLIGENCE THEORY FOR ANY INDIRECT, INCIDENTAL, PUNITIVE, SPECIAL, OR CONSEQUENTIAL DAMAGES, INCLUDING WITHOUT LIMITATION LOSS OF PROFITS, LOSS OF MORTGAGE ORIGINATION VOLUME, EXPIRATION OF RATE-LOCK AGREEMENTS, LOSS OF GOODWILL, OR BUSINESS INTERRUPTION.

3.2 Mandatory Carve-Outs (Non-Excludable Liability)

Notwithstanding Section 3.1, the exclusions set forth therein shall not apply to: (a) gross negligence or willful misconduct by YARBIS; (b) fraud or fraudulent misrepresentation; (c) liabilities arising from YARBIS's material breach of its data security obligations under the DPA; (d) death or personal injury caused by YARBIS's negligence; or (e) any other liability that cannot be legally excluded under applicable federal or state law.

3.3 Limitation Of Liability

EXCEPT FOR:

(A) Fraud;

(b) Willful misconduct;

(c) Gross negligence;

(d) Breaches of confidentiality obligations involving non-public personal information;

(e) Intellectual property misappropriation;

(f) Sanctions violations;

(g) Payment obligations;

(h) Indemnification obligations expressly stated herein,

 

The aggregate liability of yarbis arising out of or relating to this agreement shall not exceed the greater of:

(i) The total subscription fees paid by subscriber during the twelve (12) months preceding the event giving rise to the claim; or

(ii) The available proceeds of applicable cyber liability or technology errors & omissions insurance maintained by yarbis for the relevant claim category.

 

For claims arising from confirmed security incidents involving non-public personal information, yarbis's aggregate liability shall not exceed three (3) times the total subscription fees paid during the preceding twelve (12) months.

 

In no event shall either party be liable for indirect, incidental, special, exemplary, punitive, or consequential damages except to the extent such damages are payable to an unaffiliated third party under a covered indemnification claim.

3.4 Cross-Indemnification

Subscriber agrees to defend, indemnify, and hold harmless YARBIS, its corporate parents, subsidiaries, officers, directors, and engineering teams from and against any third-party claims, lawsuits, administrative enforcement actions, regulatory fines, or legal defense fees resulting from: (a) Subscriber's deployment or misinterpretation of YARBIS analytics in violation of federal lending statutes including RESPA, TRID, TILA, HMDA, or ECOA; (b) predatory lending, discriminatory profiling, or financial malpractice conducted by Subscriber's personnel; or (c) intentional or negligent uploading of falsified, unauthorized, or compromised documentation into the platform.

3.5 Indemnification Procedures

The indemnifying party shall:

(a) assume control of the defense through counsel reasonably acceptable to the indemnified party;

(b) keep the indemnified party reasonably informed regarding material developments;

(c) not enter into any settlement admitting liability, imposing injunctive obligations, or creating ongoing operational restrictions upon the indemnified party without prior written consent;

(d) reimburse reasonable documented defense costs incurred prior to assumption of the defense;

(e) mitigate duplicative legal expenses where commercially reasonable.

 

The indemnified party may participate in the defense through separate counsel at its own expense where reasonably necessary due to conflict of interest, regulatory exposure, reputational risk, or privilege considerations.

3.6 Limitation of Regulatory Damages

To the maximum extent permitted by Applicable Law, YARBIS shall not be liable for any:

(a) governmental fines;

(b) regulatory penalties;

(c) supervisory findings;

(d) consent orders;

(e) enforcement actions;

(f) licensing restrictions;

(g) investor repurchase demands;

(h) loan buyback obligations;

(i) secondary-market losses;

(j) underwriting deficiencies;

(k) fair lending claims;

(l) consumer disclosure violations; or

(m) regulatory remediation costs,

 

arising from:

(i) Subscriber conduct;

(ii) Subscriber regulatory obligations;

(iii) Subscriber operational decisions;

(iv) Subscriber lending determinations;

(v) Subscriber data inputs;

(vi) Subscriber failure to independently validate outputs; or

(vii) Subscriber misuse of the Platform.

 

Subscriber acknowledges that YARBIS functions solely as a technology provider and does not assume responsibility for Subscriber regulatory compliance obligations.

ARTICLE 4. SUBSCRIPTION, BILLING & PAYMENT

4.1 License Grant

In consideration for timely payment of applicable subscription fees, YARBIS grants Subscriber a limited, non-exclusive, non-transferable, revocable commercial license to access its multi-tenant platform strictly for lawful business purposes related to mortgage workflow analysis, financial data organization, and business intelligence optimization. This Agreement does not convey any title, property rights, ownership interests, or intellectual property rights in the underlying software, source code, or AI systems.

4.2 Fees, Non-Refundability & Exceptions

All subscription fees are denominated in United States Dollars (USD) and are exclusive of applicable taxes, which remain the sole responsibility of Subscriber. Except where required by applicable law, all subscription payments are non-refundable upon processing. Notwithstanding the foregoing, YARBIS will evaluate refund or credit requests on a case-by-case basis where service unavailability caused by YARBIS infrastructure failures materially impairs Subscriber's access during a paid period.

4.3 Chargeback Policy

Subscriber agrees not to initiate frivolous, bad-faith, or unauthorized chargeback disputes with Subscriber's financial institution regarding fees properly charged under this Agreement. Nothing in this Agreement eliminates or waives any chargeback rights that cannot be contractually disclaimed under applicable banking regulations, card network rules, or consumer protection law.

4.4 Automatic Renewal

Subscriptions automatically renew unless Subscriber formally cancels via the administrative control panel at least seventy-two (72) hours before the applicable renewal date. YARBIS will send renewal reminder notifications in accordance with commercially reasonable practices.

4.5 Payment Failure & Suspension

In the event of payment failure, YARBIS may suspend access to the platform after providing Subscriber reasonable notice and an opportunity to cure. YARBIS shall not be liable for operational disruptions experienced by Subscriber or third parties arising from a payment-triggered suspension where Subscriber failed to cure within the notice period. YARBIS's right to withhold access during a payment default period is expressly reserved.

ARTICLE 5. INTELLECTUAL PROPERTY

5.1 YARBIS Ownership

YARBIS and its licensors exclusively own and retain all right, title, and interest in and to:

(a) the platform;

(b) software code;

(c) APIs;

(d) system architecture;

(e) orchestration logic;

(f) AI/ML models;

(g) model weights;

(h) embeddings;

(i) prompt orchestration systems;

(j) scoring methodologies;

(k) derived analytics;

(l) security telemetry;

(m) usage intelligence;

(n) audit architectures;

(o) interfaces;

(p) trade secrets;

(q) proprietary documentation;

(r) operational metadata;

(s) de-identified and aggregated system intelligence generated through operation of the platform.

 

No rights are granted except those expressly stated in this Agreement.

5.2 Subscriber Data

Subscriber retains all right, title, and interest in Subscriber Data uploaded to the platform. Subscriber grants YARBIS a limited, non-exclusive license to process, store, and transmit Subscriber Data solely to perform its obligations under this Agreement.

5.3 De-Identified & Aggregated Data

YARBIS may generate, use, retain, analyze, and disclose de-identified and aggregated information derived from operation of the platform solely for:

 

(a) security improvement;

(b) platform optimization;

(c) service analytics;

(d) fraud prevention;

(e) model performance evaluation;

(f) operational benchmarking.

 

YARBIS shall implement commercially reasonable technical and organizational measures designed to ensure that such information:

 

(i) cannot reasonably be linked to an identified or identifiable natural person;

(ii) is not used to re-identify individuals;

(iii) is maintained separately from direct identifiers where commercially feasible.

 

YARBIS shall not sell Subscriber-specific non-public personal information.

ARTICLE 6. GOVERNING LAW & DISPUTE RESOLUTION

6.1 Governing Law

This Agreement and any dispute, claim, controversy, or cause of action arising out of or relating to the YARBIS platform, the services provided, or the relationship between the parties shall be governed by and construed in accordance with the laws of the State of [INSERT STATE], without regard to conflict-of-law principles that would require application of another jurisdiction’s laws.

 

The parties expressly acknowledge that the Federal Arbitration Act (“FAA”) governs the interpretation and enforcement of all arbitration provisions incorporated into this Agreement.

6.2 Binding Arbitration

Except as otherwise expressly provided herein, all disputes arising out of or relating to this Agreement, the platform, or the services provided by YARBIS shall be resolved exclusively through binding arbitration pursuant to the Binding Arbitration Agreement incorporated into this Enterprise Legal Framework.

 

The arbitration provisions contained in Document 10 (Binding Arbitration Agreement) are incorporated herein by reference as though fully restated herein.

6.3 Equitable Relief

Notwithstanding the arbitration obligations contained herein, YARBIS reserves the right to seek temporary, preliminary, or permanent injunctive relief, equitable relief, or protective orders in any court of competent jurisdiction for matters involving:

(a) intellectual property infringement;

(b) unauthorized access;

(c) cybersecurity threats;

(d) misuse of confidential information;

(e) sanctions violations;

(f) fraud;

(g) abuse of platform infrastructure; or

(h) violations of the Acceptable Use Policy.

6.4 Survival

The provisions of this Article survive termination, suspension, expiration, or discontinuation of the Subscriber relationship.

ARTICLE 7. SECURITY GOVERNANCE

7.1 Commercially Reasonable Security Program

YARBIS maintains a commercially reasonable information security program designed to protect platform integrity, confidentiality, availability, and operational resilience consistent with the nature of the platform and applicable operational risks.

 

Such safeguards may include administrative, technical, organizational, and physical security controls.

7.2 No Absolute Security Guarantee

Subscriber acknowledges that no system, infrastructure environment, cybersecurity program, or technical safeguard can guarantee absolute protection against all cyber threats, unauthorized access, operational failures, or malicious activity.

 

YARBIS does not warrant that the platform will be immune from cybersecurity incidents, infrastructure outages, or evolving threat vectors.

7.3 Shared Responsibility Model

Subscriber acknowledges that cybersecurity is a shared responsibility and that Subscriber-controlled systems, devices, personnel, credentials, integrations, and operational practices materially affect overall platform security.

 

Subscriber remains solely responsible for maintaining appropriate internal cybersecurity controls within Subscriber’s own environment.

7.4 Security Incident Cooperation

Subscriber agrees to cooperate with YARBIS in connection with commercially reasonable cybersecurity investigations, incident-response activities, forensic preservation efforts, and remediation procedures relating to actual or suspected security events affecting the platform or Subscriber accounts.

7.5 Incorporated Security Documents

The following documents are incorporated into this Agreement by reference:

(a) Information Security Policy;

(b) Incident Response & Breach Notification Framework;

(c) Data Processing Addendum;

(d) Acceptable Use Policy;

(e) Third-Party Integrations, APIs & External Services Policy; and

(f) Enterprise Operational, Regulatory, Security & Platform Reliance Framework.

 

In the event of conflict between this Article and the Information Security Policy, Incident Response & Breach Notification Framework, or Enterprise Operational, Regulatory, Security & Platform Reliance Framework, the more restrictive security, preservation, or compliance obligation shall govern to the maximum extent permitted by Applicable Law.

7.6 Survival

The provisions of this Article survive termination to the extent necessary to protect legal rights, preserve evidence, enforce security obligations, or comply with applicable law.

ARTICLE 8. GENERAL PROVISIONS

8.1 Severability

If any provision of this Agreement is determined unenforceable or invalid under applicable law, the remaining provisions shall remain in full force and effect to the maximum extent permitted by law.

8.2 Entire Agreement

This Enterprise Legal Framework constitutes the entire agreement between the parties concerning the subject matter herein and supersedes all prior or contemporaneous understandings, communications, representations, or agreements relating thereto.

8.3 Amendment

YARBIS may modify this Agreement from time to time in accordance with commercially reasonable notice procedures.

 

Continued use of the platform following the effective date of updated terms constitutes acceptance of the revised Agreement, to the extent permitted by applicable law.

8.4 Assignment

Subscriber may not assign or transfer this Agreement without prior written consent from YARBIS.

 

YARBIS may assign this Agreement in connection with a merger, acquisition, corporate restructuring, financing transaction, or sale of substantially all assets.

8.5 Electronic Notices

Subscriber consents to receiving legal notices, disclosures, operational communications, compliance notifications, and platform-related communications electronically through commercially reasonable communication channels designated by YARBIS.

8.6 No Waiver

Failure by YARBIS to enforce any provision of this Agreement shall not constitute a waiver of any right or provision.

8.7 Relationship of the Parties

Nothing in this Agreement creates any partnership, joint venture, agency, fiduciary, employment, or lender-borrower relationship between the parties.

 

YARBIS operates solely as a technology platform provider.

8.8 Survival

Any provisions which by their nature should survive termination shall survive termination, including but not limited to provisions relating to:

(a) confidentiality;

(b) intellectual property;

(c) indemnification;

(d) arbitration;

(e) limitation of liability;

(f) payment obligations;

(g) legal holds;

(h) audit rights; and

(i) cybersecurity cooperation.

8.9 No Partnership, Joint Venture, Agency, or Joint Enterprise

Nothing in this Agreement or in the operation of the Platform shall be construed to create any partnership, joint venture, agency relationship, fiduciary relationship, employment relationship, joint enterprise, apparent authority relationship, or similar legal association between YARBIS and Subscriber.

 

Neither Party shall have authority to bind the other Party in any manner whatsoever, including with respect to:

(a) lending activities;

(b) consumer communications;

(c) underwriting determinations;

(d) regulatory representations;

(e) contractual obligations; or

(f) supervisory or compliance activities.

 

Subscriber acknowledges that YARBIS operates solely as an independent technology provider and does not participate in the Subscriber’s regulated lending, underwriting, servicing, compliance, brokerage, or financial operations.

1.1 Data Controller / Data Processor Designation

Subscriber acts as the Data Controller with respect to consumer and borrower personal data uploaded to the platform. YARBIS acts as a Data Processor processing such data solely on behalf of and under the instructions of Subscriber, except where YARBIS is independently required to process data under applicable law.

1.2 Processing Instructions

YARBIS shall process personal data only: (a) in accordance with Subscriber's documented instructions; (b) as necessary to perform obligations under the MSA; (c) as required by applicable law. YARBIS shall promptly notify Subscriber if, in YARBIS's reasonable opinion, an instruction violates applicable data protection law.

ARTICLE 2. DATA SECURITY MEASURES

2.1 Technical & Organizational Safeguards

YARBIS maintains commercially reasonable administrative, technical, and organizational safeguards designed to protect the confidentiality, integrity, and availability of personal data against unauthorized access, disclosure, alteration, or destruction. Such safeguards include: encryption of data at rest using AES-256 standards; encryption of data in transit using TLS 1.3; role-based access controls (RBAC); multi-factor authentication (MFA) for administrative access; audit logging; and security awareness programs for personnel.

2.2 No Absolute Security Warranty

YARBIS does not warrant that its security measures will be impenetrable, uninterrupted, or that unauthorized access, disclosure, or destruction of data will never occur. No internet-based system can guarantee absolute security. YARBIS's obligations are to maintain commercially reasonable safeguards, not to guarantee perfect security outcomes.

2.3 Personnel Obligations

YARBIS shall ensure that personnel authorized to process personal data are subject to appropriate confidentiality obligations and receive relevant data protection training.

ARTICLE 3. SUBPROCESSORS

3.1 Authorization to Engage Subprocessors

Subscriber authorizes YARBIS to engage subprocessors for purposes of delivering platform services, subject to the requirements of this Article. YARBIS shall maintain a current Subprocessor Disclosure Schedule (Document 8), which is incorporated herein.

YARBIS shall maintain a commercially reasonable mechanism through which Subscriber may request current information regarding categories of authorized subprocessors involved in processing regulated or sensitive data.

3.2 Subprocessor Obligations

YARBIS shall impose written contractual obligations upon subprocessors materially requiring:

(a) confidentiality protections;

(b) security safeguards appropriate to the nature of the processed data;

(c) restrictions on unauthorized processing;

(d) incident notification obligations;

(e) legally required cooperation relating to regulatory compliance obligations applicable to YARBIS.

Where commercially reasonable and appropriate based upon risk level, YARBIS may conduct vendor diligence procedures relating to subprocessors handling sensitive financial information, non-public personal information, authentication data, or regulated operational workflows.

3.3 Notification of Changes

YARBIS shall provide Subscriber with advance written notice of at least thirty (30) days prior to adding or replacing a material subprocessor that processes personal data. Subscriber may object to a new subprocessor within fifteen (15) days of such notice on the basis of reasonable data protection concerns.

Subscriber acknowledges that certain subprocessors may operate infrastructure, hosting, AI-processing, analytics, authentication, communications, cybersecurity, or operational support services necessary for delivery of the platform.

YARBIS shall remain responsible for the acts and omissions of subprocessors to the extent required under applicable data protection laws, subject to the limitations of liability otherwise established under the Enterprise Legal Framework.

3.4 Subprocessor Objection Procedure

Subscriber may object in writing to a newly appointed subprocessor on reasonable documented grounds relating to:

(a)    material cybersecurity concerns;

(b) sanctions exposure;

(c) data residency conflicts;

(d) regulatory incompatibility;

(e) material confidentiality risks.

 Subscriber shall provide such objection within fifteen (15) days following commercially reasonable notice from YARBIS.

 Upon receipt of a valid objection, the parties shall cooperate in good faith to evaluate commercially reasonable alternatives, mitigation measures, or operational accommodations.

 Nothing herein obligates YARBIS to disclose confidential trade secrets, security-sensitive vendor architecture, or privileged internal risk assessments.

 3.5 International Subprocessing

To the extent subprocessors process Personal Data outside the jurisdiction in which such data originated, YARBIS shall implement commercially reasonable safeguards intended to support lawful international data transfer mechanisms where required under applicable privacy laws.

 Such safeguards may include contractual transfer clauses, encryption measures, access restrictions, regional hosting controls, or other supplementary protections reasonably appropriate to the nature of the transferred data.

ARTICLE 4. BREACH NOTIFICATION

4.1 Incident Detection & Reporting

YARBIS maintains commercially reasonable administrative, technical, and operational procedures designed to detect, investigate, contain, mitigate, document, and respond to Security Incidents.

 Upon becoming aware of a confirmed Security Incident involving unauthorized access to, acquisition of, disclosure of, alteration of, loss of, or destruction of Subscriber Personal Data maintained within YARBIS-controlled systems, YARBIS shall provide notice to affected Subscriber(s) without unreasonable delay and, where commercially reasonable and legally permissible, within seventy-two (72) hours following confirmation of the Security Incident.

 Notification obligations under this Section shall not be construed to require disclosure of:

 (a) information protected by attorney-client privilege;

(b) information that would materially impair an ongoing forensic investigation;

(c) confidential information relating to other customers;

(d) information prohibited from disclosure by law enforcement or governmental authorities;

(e) sensitive internal security procedures, threat-detection methodologies, or cybersecurity defense mechanisms.

 YARBIS may delay notification where reasonably necessary to:

 (i) prevent further compromise;

(ii) preserve forensic evidence;

(iii) comply with law enforcement requests;

(iv) mitigate ongoing operational or cybersecurity threats;

(v) determine the scope and impact of the Security Incident.

 YARBIS shall document material Security Incident response activities in accordance with its internal security governance procedures.

4.2 Notification Content

To the extent reasonably available and legally permissible at the time of notification, YARBIS's Security Incident notification may include:

(a) a general description of the nature and scope of the Security Incident;

(b) categories of affected information reasonably believed to be involved;

(c) the approximate number of affected records or individuals, where reasonably ascertainable;

(d) contact information for the designated YARBIS security or privacy contact;

(e) the reasonably anticipated operational or privacy-related consequences of the Security Incident;

(f) containment, remediation, mitigation, recovery, or investigative measures implemented or proposed by YARBIS;

(g) recommended mitigation measures that Subscriber may consider implementing.

 Subscriber acknowledges that information relating to Security Incidents may evolve during the course of investigation and remediation activities, and supplemental notifications may be provided as additional information becomes reasonably available.

4.3 Assistance with Regulatory Notifications

Where reasonably necessary and legally permissible, YARBIS shall provide commercially reasonable cooperation relating to Subscriber's compliance with applicable breach notification obligations arising under:

(a) the Gramm-Leach-Bliley Act (GLBA);

(b) applicable state breach notification laws;

(c) CFPB guidance;

(d) FTC safeguards requirements;

(e) applicable privacy and cybersecurity regulations.

 Such cooperation may include provision of reasonably available information relating to:

(i) incident scope;

(ii) affected data categories;

(iii) containment activities;

(iv) remediation efforts;

(v) forensic findings reasonably appropriate for disclosure.

 Nothing herein shall require YARBIS to:

(A) waive attorney-client privilege or work-product protections;

(B) disclose confidential security architecture;

(C) disclose information relating to other customers;

(D) provide unrestricted access to forensic reports;

(E) assume Subscriber's independent regulatory obligations.

 Subscriber remains solely responsible for determining whether legal or regulatory notification obligations apply to Subscriber under applicable law.

 4.4 Ransomware, Cyber Extortion & Operational Disruption

Security Incidents may include ransomware events, cyber extortion attempts, denial-of-service attacks, unauthorized encryption activities, operational disruptions, or malicious interference with platform availability.

 YARBIS may implement commercially reasonable emergency response measures intended to:

(a) contain malicious activity;

(b) isolate affected systems;

(c) preserve forensic evidence;

(d) maintain operational continuity;

(e) restore affected services;

(f) coordinate with law enforcement, insurers, cybersecurity consultants, or governmental authorities.

 Nothing herein guarantees uninterrupted availability, complete prevention of cybersecurity incidents, or successful recovery from every malicious attack scenario.

4.5 No Admission of Liability

Any Security Incident notification, investigation activity, remediation effort, forensic review, cooperation measure, or operational response undertaken by YARBIS shall not constitute:

 (a) an admission of fault;

(b) an admission of legal liability;

(c) a representation regarding regulatory violation;

(d) a waiver of defenses;

(e) a concession regarding causation or damages.

ARTICLE 5. DATA SUBJECT RIGHTS

Where Subscriber receives a request from a consumer, borrower, applicant, authorized agent, or data subject seeking to exercise applicable privacy or data protection rights, including rights relating to:

(a) access;

(b) deletion;

(c) correction;

(d) portability;

(e) restriction of processing;

(f) objection to processing;

(g) opt-out rights;

(h) appeal rights under applicable privacy laws,

 YARBIS shall provide commercially reasonable cooperation reasonably necessary to assist Subscriber in responding to such requests, to the extent:

(i) technically feasible;

(ii) legally permissible;

(iii) proportionate to the nature of the request;

(iv) consistent with YARBIS operational infrastructure and security obligations.

 Subscriber remains solely responsible for:

(A) validating the identity and authority of the requesting party;

(B) determining whether a legal obligation to respond exists;

(C) preparing legally required consumer-facing responses;

(D) maintaining required consumer-notice procedures.

 YARBIS may reject, limit, or defer assistance relating to requests that are:

(1) fraudulent;

(2) abusive;

(3) repetitive;

(4) technically infeasible;

(5) legally prohibited;

(6) likely to compromise platform security, confidentiality obligations, or rights of other persons.

 Nothing herein requires YARBIS to disclose trade secrets, privileged information, confidential security procedures, proprietary algorithms, or information relating to other customers.

ARTICLE 6. INTERNATIONAL DATA TRANSFER

YARBIS primarily processes Personal Data within the United States unless otherwise agreed in writing.

To the extent Personal Data subject to applicable international privacy laws is transferred across national borders, YARBIS may implement commercially reasonable transfer safeguards, including:

(a) Standard Contractual Clauses approved by the European Commission;

(b) the UK International Data Transfer Addendum;

(c) supplementary technical and organizational safeguards;

(d) encryption measures;

(e) access restrictions;

(f) data minimization procedures;

(g) regional hosting accommodations where commercially feasible.

Any authorized international transfer of Personal Data shall remain subject to applicable law, contractual safeguards, security controls, and the Subprocessor Disclosure Schedule.

 nless prohibited by applicable law, YARBIS may use commercially reasonable efforts to notify Subscriber of governmental, judicial, or regulatory requests seeking access to Subscriber Personal Data prior to disclosure.

 Nothing herein guarantees immunity from governmental access requests, cross-border legal process, lawful surveillance authorities, or evolving international regulatory requirements.

ARTICLE 7. DATA RETURN, RETENTION & DELETION

Upon termination or expiration of the applicable services, Subscriber may request:

 (a) return of certain Subscriber data in a commercially reasonable portable format; or

(b) deletion of Subscriber data maintained within YARBIS-controlled production environments.

 Unless otherwise required by applicable law, litigation preservation obligations, regulatory requirements, fraud-prevention obligations, legal hold procedures, or ongoing dispute-resolution processes, YARBIS may initiate deletion procedures following expiration of the applicable post-termination retrieval period.

 Where commercially reasonable and technically feasible, Subscriber requests relating to data return shall be submitted within thirty (30) days following termination.

 Residual data contained within encrypted backup systems, disaster recovery environments, security archives, logging systems, or operational continuity infrastructure may remain temporarily retained pursuant to standard backup lifecycle procedures, provided such retained data remains subject to applicable confidentiality and security obligations.

 Any deletion certification provided by YARBIS shall reflect commercially reasonable completion of applicable deletion procedures within YARBIS-controlled systems and shall not constitute:

 (i) a guarantee of absolute data destruction;

(ii) a representation regarding third-party systems;

(iii) a waiver of legal preservation obligations;

(iv) a certification regarding immutable logs, forensic archives, or legally retained records.

ARTICLE 1. NATURE OF AI OUTPUTS

1.1 Advisory Status — Not Decisional Authority

All outputs generated by YARBIS's artificial intelligence and machine learning systems — including Borrower Readiness Scores, DTI calculations, document extraction results, and risk assessments — constitute advisory informational metrics only. Under no circumstances shall any YARBIS output be construed as, or operate as: a loan commitment; a credit approval or denial; a binding pre-qualification determination; an official Automated Underwriting System (AUS) determination; or a guarantee to lock interest rates.

1.2 Mandatory Human Review

Subscriber acknowledges that all YARBIS outputs require independent professional review and verification by qualified, licensed mortgage professionals before being relied upon in any credit decision, regulatory filing, borrower communication, or underwriting submission. YARBIS outputs are intended to assist — not replace — professional judgment.

1.3 AI Output Limitations Disclosure

Subscriber acknowledges that AI/ML systems, including those deployed by YARBIS: (a) may produce outputs containing inaccuracies, approximations, or incomplete interpretations; (b) are probabilistic rather than deterministic in nature and may not perfectly replicate human professional analysis; (c) are subject to performance degradation when encountering data inputs materially outside the training distribution; and (d) should not be treated as legal, financial, tax, or underwriting advice.

ARTICLE 2. FAIR LENDING & ANTI-BIAS FRAMEWORK

2.1 Prohibited Inputs

The algorithmic logic governing YARBIS's scoring and assessment functions is designed to exclude protected characteristics as prohibited basis factors under ECOA (Regulation B) and the Fair Housing Act. The platform is architected to evaluate only objective, verifiable financial factors including: asset capitalization metrics; verifiable income streams via IRS documentation; verified debt obligations (DTI calculations); and collateral exposure ratios. Race, color, religion, national origin, sex, gender identification, marital status, familial status, age, and consumer reliance on public assistance programs are not inputs into YARBIS's scoring logic.

2.2 No Guarantee of Regulatory Compliance

Notwithstanding the foregoing anti-bias architecture, YARBIS does not warrant that its outputs are free from all potential disparate impact or that the platform's use will automatically ensure Subscriber's compliance with fair lending laws. Subscriber remains solely responsible for monitoring, auditing, and ensuring compliance with ECOA, HMDA, the Fair Housing Act, and applicable state fair lending statutes in connection with Subscriber's lending activities and use of YARBIS analytics.

2.3 Explainable AI (XAI) Commitment

YARBIS is committed to maintaining explainable algorithmic outputs. Upon request, YARBIS will provide Subscriber with a general description of the primary factors contributing to a given Borrower Readiness Score, consistent with Regulation B's adverse action notice requirements applicable to Subscriber. This commitment does not require YARBIS to disclose proprietary model architecture or trade secrets.

ARTICLE 3. AI LIABILITY ALLOCATION

3.1 YARBIS Responsibility Scope

YARBIS accepts responsibility for: (a) maintaining commercially reasonable engineering standards in AI/ML model development and maintenance; (b) disclosing material model limitations relevant to mortgage workflow use cases; (c) implementing reasonable bias testing protocols; and (d) updating models in response to identified systemic errors that materially impair platform functionality.

3.2 Subscriber Responsibility Scope

Subscriber accepts sole responsibility for: (a) the professional judgment underlying any credit or lending decision, irrespective of YARBIS analytics; (b) ensuring YARBIS outputs are properly contextualised before regulatory submission; (c) any violation of ECOA, HMDA, or fair lending law arising from Subscriber's use of YARBIS data; (d) any liability arising from Subscriber's failure to conduct required human review of AI outputs.

3.3 Model Drift & Update Policy

YARBIS reserves the right to update, retrain, and modify its AI models at any time to improve accuracy, address bias concerns, adapt to regulatory changes, or improve performance. YARBIS shall use commercially reasonable efforts to notify Subscribers of material changes to model behavior. Subscriber's continued use of the platform after notification of material model changes constitutes acceptance thereof.

ARTICLE 4. AI AUDITABILITY & TRACEABILITY

4.1 Audit Logging & Traceability

Where commercially reasonable and technically feasible, YARBIS may maintain internal records relating to:

 (a) AI interaction events;

(b) model versioning;

(c) override events;

(d) confidence scoring;

(e) escalation events;

(f) operational anomaly detection;

(g) prompt abuse indicators.

 Nothing herein guarantees exhaustive retention of every AI interaction or output.

4.2 Human Review Logging

Where AI-assisted outputs are subject to mandatory or optional human review workflows, YARBIS may maintain commercially reasonable records regarding:

(a) reviewer acknowledgment events;

(b) manual override actions;

(c) escalation decisions;

(d) rejection or approval events;

(e) workflow reassignment actions;

(f) timestamped review confirmations; and

(g) operational review metadata reasonably necessary to support platform integrity, dispute resolution, compliance investigations, fraud prevention, cybersecurity operations, or internal governance processes.

 Subscriber acknowledges that human-review logging mechanisms may vary depending on platform configuration, Subscriber workflow customization, system integrations, infrastructure availability, user permissions, operational settings, and evolving technical architecture.

 YARBIS does not warrant uninterrupted availability, immutable preservation, or indefinite retention of all human-review records unless otherwise expressly required under applicable law or separately agreed in writing.

4.3 Model Version Traceability

YARBIS may maintain commercially reasonable internal documentation regarding material AI model lifecycle events, including:

 (a) model deployment dates;

(b) material retraining events;

(c) major configuration changes;

(d) infrastructure migration events;

(e) explainability framework updates;

(f) bias-mitigation modifications;

(g) confidence-threshold adjustments;

(h) risk-classification recalibrations; and

(i) significant operational tuning activities.

Subscriber acknowledges that AI systems may evolve dynamically over time through commercially reasonable maintenance, retraining, optimization, security hardening, infrastructure changes, vendor dependency modifications, and operational adjustments intended to improve platform functionality, stability, cybersecurity posture, fraud prevention, explainability, or regulatory alignment.

 Nothing in this Agreement shall obligate YARBIS to disclose proprietary model architecture, source code, training methodologies, weights, parameters, prompts, inference logic, confidential security controls, trade secrets, or protected intellectual property except where disclosure is expressly required by applicable law or valid legal process.

4.4 AI Incident Escalation Records

YARBIS may maintain commercially reasonable records relating to AI-governance incidents, operational anomalies, security escalations, suspected abuse patterns, output irregularities, model-behavior investigations, fraud-related indicators, compliance escalations, or internal governance reviews.

 Such records may include:

(a) incident classification metadata;

(b) escalation timestamps;

(c) internal remediation actions;

(d) containment measures;

(e) workflow restrictions;

(f) user access restrictions;

(g) confidence suppression events;

(h) anomaly investigation notes; and

(i) operational mitigation activities.

 AI-governance escalation records may be used by YARBIS for purposes including cybersecurity defense, fraud prevention, platform integrity protection, legal compliance, regulatory cooperation, enterprise risk management, internal investigations, litigation defense, and operational governance.

 Nothing herein shall obligate YARBIS to disclose internal investigative materials, privileged assessments, proprietary security procedures, internal escalation logic, threat-detection methodologies, or protected governance documentation except where disclosure is required by applicable law, regulatory order, subpoena, court order, or binding legal process.

4.5 Retention of AI Governance Records

AI governance records, audit logs, escalation records, operational metadata, model-management records, anomaly-detection records, and related governance documentation shall be retained in accordance with YARBIS's internal retention schedules, legal-hold procedures, cybersecurity requirements, disaster-recovery protocols, evidentiary preservation obligations, and commercially reasonable operational governance practices.

 YARBIS reserves the right to delete, archive, aggregate, de-identify, compress, rotate, overwrite, anonymize, restrict access to, or operationally retire AI governance records in accordance with:

(a) infrastructure limitations;

(b) cybersecurity requirements;

(c) operational governance needs;

(d) legal retention obligations;

(e) litigation hold requirements;

(f) disaster recovery policies;

(g) storage optimization procedures; and

(h) commercially reasonable data lifecycle management practices.

 Nothing in this Agreement shall be interpreted as creating an obligation for perpetual retention, exhaustive preservation, or immutable storage of all AI-related records, prompts, outputs, interactions, metadata, or operational logs unless otherwise expressly required under applicable law or binding legal preservation obligations.

ARTICLE 5. NO AI WARRANTY & EVOLVING REGULATORY ENVIRONMENT

5.1 No Warranty of AI Accuracy

YARBIS does not warrant, represent, certify, or guarantee that any AI-generated output, recommendation, score, classification, prediction, workflow suggestion, risk indicator, prioritization logic, or automated analytical result generated through the platform will be accurate, complete, error-free, uninterrupted, bias-free, regulator-approved, or suitable for any particular underwriting, lending, compliance, operational, legal, or business purpose.

 AI-generated outputs are probabilistic analytical tools designed to assist human decision-making processes and shall not constitute deterministic conclusions, regulatory determinations, underwriting decisions, legal advice, compliance certifications, credit decisions, or independently sufficient grounds for any lending or consumer-related action.

 Subscriber acknowledges that machine-learning systems and large-language-model technologies inherently involve probabilistic reasoning, non-deterministic outputs, evolving model behavior, data-quality dependencies, statistical limitations, false positives, false negatives, hallucinations, incomplete contextual interpretation, and model drift risks that cannot be fully eliminated through commercially reasonable technical safeguards.

5.2 Regulatory Evolution Reservation

Subscriber acknowledges that laws, regulations, regulatory guidance, supervisory expectations, enforcement priorities, consent orders, interpretive bulletins, agency advisories, industry standards, and judicial interpretations governing artificial intelligence, algorithmic decision-making, automated underwriting support systems, explainability requirements, bias mitigation obligations, consumer disclosures, model governance, automated communications, and financial-services technology may evolve materially over time.

 YARBIS reserves the right to modify, suspend, restrict, replace, recalibrate, retrain, discontinue, supplement, or operationally alter AI-related platform functionality, governance controls, output-generation methodologies, confidence thresholds, explainability mechanisms, monitoring systems, escalation procedures, or model-management protocols as commercially reasonably necessary to address evolving legal, regulatory, operational, cybersecurity, infrastructure, ethical, reputational, or compliance requirements.

5.3 No Guarantee of Regulatory Acceptance

YARBIS does not represent or warrant that use of the platform, its AI-assisted workflows, scoring systems, prioritization tools, explainability features, audit logs, or governance controls will independently satisfy any federal, state, local, international, agency-specific, investor-specific, warehouse-lender-specific, secondary-market, prudential, supervisory, or enterprise compliance obligation applicable to Subscriber.

 Subscriber acknowledges that ultimate responsibility for compliance with applicable laws and regulations — including but not limited to ECOA, FHA, HMDA, FCRA, TILA, RESPA, GLBA, state lending laws, unfair or deceptive acts or practices statutes, fair lending requirements, model governance expectations, and AI-related regulatory obligations — remains solely with Subscriber and Subscriber's licensed compliance, legal, underwriting, operational, and regulatory personnel.

5.4 Subscriber Validation Obligations

Subscriber shall maintain commercially reasonable human-review, quality-control, compliance-validation, escalation, audit, and override procedures before relying upon AI-generated outputs in connection with consumer-facing actions, lending-related determinations, underwriting workflows, borrower communications, regulatory reporting, adverse-action decisions, fraud determinations, operational prioritization, or material business decisions.

 Subscriber further agrees to independently validate the appropriateness, legality, fairness, operational suitability, and regulatory permissibility of all AI-assisted outputs prior to implementation, reliance, dissemination, or operational execution.

 Failure by Subscriber to maintain commercially reasonable review and validation procedures shall constitute a material allocation-of-responsibility factor in evaluating liability associated with AI-assisted operational outcomes.

5.5 AI Output Confidence & Escalation Reservation

YARBIS reserves the right to implement confidence thresholds, escalation triggers, anomaly detection systems, output suppression controls, fallback logic, human-review checkpoints, risk-prioritization mechanisms, or automated operational safeguards intended to reduce material AI-governance, cybersecurity, fraud, compliance, or reputational risks.

 Subscriber acknowledges that certain outputs, recommendations, or workflows may be delayed, restricted, escalated for review, suppressed, flagged, deprioritized, or prevented from automated execution where YARBIS reasonably determines that elevated operational, compliance, legal, cybersecurity, or reputational risks may exist.

5.6 No Fiduciary, Underwriting, Legal, or Compliance Relationship

Nothing within the YARBIS platform, including any AI-generated output, recommendation, workflow assistance, prioritization logic, risk indicator, document analysis, communication assistance, or operational suggestion, shall be interpreted as establishing:

(a) a fiduciary relationship;

(b) an underwriting authority relationship;

(c) a legal advisory relationship;

(d) a compliance consultancy relationship;

(e) a licensed lending relationship;

(f) a financial advisory relationship; or

(g) any delegated regulatory responsibility relationship between YARBIS and Subscriber.

 YARBIS functions solely as a technology service provider offering software-enabled analytical and operational support tools.

ARTICLE 6. HIGH-RISK AI REGULATORY RESERVATION

6.1 Regulatory Classification Reservation

YARBIS reserves the right to classify, reclassify, limit, suspend, modify, or restrict AI-assisted functionality where evolving regulatory guidance, supervisory expectations, litigation trends, or applicable law may classify certain AI-assisted systems as "high-risk," "regulated," or operationally sensitive systems.

6.2 Subscriber Responsibility for Lending Decisions

Subscriber remains solely responsible for all underwriting, lending, credit, adverse-action, pricing, compliance, consumer-notification, and regulated financial decisions irrespective of AI-assisted recommendations generated through the Platform.

6.3 Regulatory Suspension Authority

YARBIS may suspend, modify, disable, restrict, or geographically limit AI-assisted functionality where commercially reasonable to address regulatory developments, enforcement actions, sanctions restrictions, supervisory expectations, cybersecurity concerns, or operational risk exposure.

1.1 Encryption Standards

YARBIS utilizes commercially standard encryption protocols including AES-256 encryption for data at rest and Transport Layer Security (TLS) 1.3 for data in transit within the YARBIS platform environment. These standards represent current enterprise-grade commercial security practices and are subject to update as industry standards evolve.

1.2 Access Controls

Access to YARBIS production environments containing personal data is controlled through multi-factor authentication (MFA), role-based access controls (RBAC), and audit logging. Access privileges are subject to periodic review and the principle of least privilege.

1.3 Vulnerability Management

YARBIS maintains a vulnerability management program that includes periodic security assessments, penetration testing by qualified personnel, and timely remediation of identified material vulnerabilities.

1.4 Audit Logging

YARBIS maintains cryptographically protected transaction logs capturing user authentication events, document submission actions, and material platform interactions, for purposes of operational integrity and forensic auditability. Log retention periods are governed by YARBIS's internal retention policies and applicable legal requirements.

ARTICLE 2. EMAIL & EXTERNAL TRANSMISSION SECURITY

2.1 Platform Security Boundary

YARBIS's security controls apply within the YARBIS platform environment. Data transmitted outside the platform via standard email protocols, third-party messaging applications, or other external transmission mechanisms operates beyond YARBIS's direct security perimeter.

2.2 Email Transmission Risk Acknowledgment

Subscriber acknowledges that standard electronic mail is an inherently open transmission medium subject to interception, spoofing, and business email compromise (BEC) risks. YARBIS is not liable for security incidents arising from data transmitted outside the YARBIS platform by Subscriber or third parties, except where such incidents are directly caused by YARBIS's failure to maintain commercially reasonable security controls within its own infrastructure.

2.3 Security Recommendations

YARBIS recommends that Subscribers: implement organizational email security protocols including SPF, DKIM, and DMARC; deploy endpoint MFA across their organizations; train personnel on phishing and BEC recognition; and avoid transmitting NPI outside secured platform channels where technically feasible.

ARTICLE 3. SECURITY INCIDENT CLASSIFICATION

For purposes of this Policy and the Incident Response Framework (Document 7), a 'Security Incident' means any confirmed unauthorized access to, disclosure of, use of, alteration of, or destruction of personal data processed by YARBIS on Subscriber's behalf. Security Incidents are classified by severity (Low, Medium, High, Critical) based on the nature and volume of affected data, regulatory notification obligations triggered, and potential harm to affected individuals.

ARTICLE 4. NO ABSOLUTE SECURITY GUARANTEE

YARBIS implements commercially reasonable safeguards intended to reduce foreseeable cybersecurity risks; however, no platform, software environment, infrastructure provider, cybersecurity program, AI-enabled system, or electronic transmission mechanism can be guaranteed fully secure, uninterrupted, error-free, or immune from evolving cyber threats at all times.

ARTICLE 5. BUSINESS CONTINUITY & DISASTER RECOVERY

5.1 Operational Continuity Framework

YARBIS maintains commercially reasonable business continuity, operational resilience, disaster recovery, and infrastructure restoration procedures intended to support continued platform operations during cybersecurity incidents, infrastructure failures, cloud-service disruptions, denial-of-service events, data corruption events, ransomware incidents, natural disasters, telecommunications failures, utility outages, third-party vendor interruptions, and other operational disruption scenarios.

 Business continuity measures may include redundancy architecture, encrypted backups, infrastructure segmentation, failover procedures, restoration testing, geographically distributed infrastructure components, cloud redundancy strategies, incident escalation procedures, and recovery prioritization protocols reasonably appropriate for YARBIS's operational scale and risk profile.

5.2 Disaster Recovery Objectives

YARBIS may establish internal recovery-time objectives (RTOs), recovery-point objectives (RPOs), backup schedules, restoration targets, and operational recovery priorities based upon commercially reasonable risk-management practices, infrastructure capabilities, cybersecurity considerations, vendor dependencies, and operational constraints.

 Unless expressly agreed in a separately executed enterprise service-level agreement, no specific recovery timeline, uninterrupted availability guarantee, or immutable restoration capability is guaranteed under this Agreement.

5.3 Backup & Restoration Limitations

Subscriber acknowledges that backup systems, disaster recovery environments, redundancy systems, archival infrastructure, and restoration mechanisms may involve:

(a) replication delays;

(b) synchronization intervals;

(c) incomplete restoration risks;

(d) infrastructure dependencies;

(e) third-party cloud-provider limitations;

(f) temporary service degradation;

(g) partial operational outages; and

(h) cybersecurity containment restrictions.

 YARBIS shall not be liable for temporary operational interruptions, restoration delays, partial data loss, infrastructure failover limitations, or service degradation resulting from commercially reasonable disaster recovery operations, cybersecurity containment measures, or operational continuity procedures.

5.4 Subscriber Continuity Responsibilities

Subscriber remains solely responsible for maintaining commercially reasonable internal business continuity, data preservation, regulatory retention, contingency operations, workforce continuity, and operational resiliency procedures appropriate for Subscriber's own regulated business activities.

 YARBIS's operational continuity measures do not eliminate Subscriber's independent obligations to maintain regulatory-compliant continuity, retention, backup, consumer servicing, underwriting, compliance, or operational recovery procedures.

ARTICLE 6. SECURITY TESTING & ASSESSMENTS

6.1 Security Testing Program

YARBIS may perform commercially reasonable cybersecurity testing activities intended to evaluate platform integrity, infrastructure resilience, authentication security, vulnerability exposure, access-control effectiveness, logging integrity, and operational security posture.

 Such testing activities may include vulnerability scanning, penetration testing, endpoint security assessments, configuration reviews, dependency analysis, threat modeling, credential exposure analysis, infrastructure hardening reviews, log monitoring, anomaly detection analysis, and security validation procedures.

6.2 Third-Party Security Assessments

YARBIS may engage qualified third-party security professionals, consultants, auditors, infrastructure providers, managed security vendors, or cybersecurity assessment firms to assist with commercially reasonable security evaluations, monitoring activities, incident response support, infrastructure testing, compliance validation, or operational risk-management activities.

 Third-party security activities may be subject to confidentiality obligations, data-access limitations, operational safeguards, and scope restrictions reasonably designed to protect Subscriber data and platform integrity.

6.3 No Security Warranty

Cybersecurity testing, vulnerability assessments, monitoring activities, penetration testing, infrastructure reviews, or security audits do not constitute a representation, certification, or warranty that the YARBIS platform is invulnerable, breach-proof, immune from cyberattack, free from exploitable conditions, or compliant with every evolving cybersecurity framework, regulator expectation, or threat landscape scenario.

 Subscriber acknowledges that no commercially available technology environment can guarantee absolute cybersecurity protection or uninterrupted operational security.

6.4 Restrictions on Unauthorized Security Testing

Subscriber shall not conduct or permit any unauthorized penetration testing, vulnerability scanning, denial-of-service testing, exploit simulation, reverse engineering, credential attacks, stress testing, malware testing, infrastructure probing, or cybersecurity assessment activities against the YARBIS platform without YARBIS's prior written authorization.

 Unauthorized security-testing activities may constitute material breaches of this Agreement and may result in immediate suspension, legal action, forensic investigation, or referral to law enforcement authorities.

ARTICLE 7. ACCESS GOVERNANCE & AUTHENTICATION

7.1 Credential Security Obligations

Subscriber shall maintain commercially reasonable credential-management and access-control practices, including protection of usernames, passwords, authentication tokens, API credentials, multi-factor authentication devices, session credentials, and privileged-access mechanisms used in connection with the YARBIS platform.

 Subscriber shall promptly notify YARBIS upon becoming aware of any suspected credential compromise, unauthorized access event, insider misuse, account takeover risk, suspicious authentication activity, or unauthorized system access.

7.2 Multi-Factor Authentication Reservation

YARBIS reserves the right to require, enforce, modify, or operationally mandate multi-factor authentication (MFA), adaptive authentication controls, device-verification mechanisms, risk-based authentication procedures, session-expiration controls, identity-verification checkpoints, or enhanced access-security requirements where commercially reasonable or operationally necessary to mitigate cybersecurity, fraud, compliance, or operational risks.

7.3 Access Restriction Authority

YARBIS reserves the right to suspend, restrict, terminate, quarantine, isolate, or conditionally limit platform access where YARBIS reasonably determines that:

(a) unauthorized access risks exist;

(b) cybersecurity threats are suspected;

(c) sanctions or fraud concerns arise;

(d) account compromise indicators are detected;

(e) abusive automation activity is identified;

(f) anomalous behavior patterns exist; or

(g) operational integrity may be materially impacted.

Such actions may be taken on an emergency basis without prior notice where reasonably necessary to preserve platform security, operational stability, legal compliance, or infrastructure integrity.

7.4 Least-Privilege & Administrative Access

YARBIS may implement commercially reasonable least-privilege access principles, administrative-access segmentation, role-based access controls, privileged-access restrictions, audit monitoring, session logging, and administrative authorization controls intended to reduce unauthorized access risks and operational exposure.

ARTICLE 8. SECURITY GOVERNANCE RESERVATION

8.1 Evolving Security Standards

Subscriber acknowledges that cybersecurity standards, threat landscapes, attack methodologies, infrastructure risks, regulatory expectations, industry frameworks, encryption standards, authentication practices, and operational security requirements evolve continuously over time.

 YARBIS reserves the right to modify, replace, supplement, harden, restrict, upgrade, reconfigure, or operationally alter its cybersecurity controls, infrastructure architecture, authentication systems, monitoring procedures, logging practices, access restrictions, encryption methodologies, infrastructure vendors, or operational safeguards as commercially reasonably necessary to address evolving operational, legal, cybersecurity, compliance, or infrastructure risks.

8.2 No Guarantee of Regulatory Immunity

Implementation of commercially reasonable security safeguards does not guarantee immunity from cybersecurity incidents, unauthorized access events, regulatory investigations, enforcement actions, litigation exposure, operational disruption, fraud events, infrastructure failures, insider threats, or evolving threat-vector exploitation.

 Subscriber acknowledges that cybersecurity risk can be reduced but cannot be completely eliminated.

8.3 Security Framework References

Where YARBIS references cybersecurity frameworks, standards, guidelines, or industry practices — including but not limited to NIST, ISO 27001, SOC 2, CIS Controls, OWASP, PCI DSS, or similar standards — such references are intended solely to describe general operational alignment objectives and shall not constitute representations of formal certification, guaranteed compliance, or legally binding warranties unless expressly stated in a separately executed written agreement.

8.4 No Cybersecurity Certification or Compliance Warranty

Unless expressly stated in a separately executed written agreement signed by authorized representatives of YARBIS, YARBIS does not certify, warrant, guarantee, or represent that the Platform, services, infrastructure, operational controls, or security program:

(a) satisfies any specific cybersecurity framework;

(b) guarantees compliance with NIST, ISO, SOC, GLBA, FTC Safeguards Rule, state cybersecurity laws, or any other regulatory framework;

(c) guarantees Subscriber regulatory compliance;

(d) eliminates cybersecurity risk;

(e) prevents all unauthorized access events; or

(f) satisfies all legal, operational, investor, insurer, or supervisory expectations applicable to Subscriber.

 Any references to security frameworks, standards, certifications, assessments, controls, or industry practices are provided solely for general informational and operational reference purposes and shall not constitute a warranty, certification, legal opinion, or guarantee of compliance.

ARTICLE 9. CYBER INSURANCE & RISK TRANSFER

9.1 Insurance Reservation

YARBIS may maintain cybersecurity, technology errors & omissions, privacy liability, cyber extortion, business interruption, or related insurance coverage in amounts determined commercially reasonable by YARBIS.

9.2 No Insurance Guarantee

Nothing herein guarantees the existence, availability, applicability, collectability, sufficiency, or coverage scope of any insurance policy for any specific Subscriber loss, incident, claim, or regulatory event.

9.3 Subscriber Insurance Responsibility

Subscribers are solely responsible for maintaining their own commercially appropriate cybersecurity, E&O, fidelity bond, regulatory liability, business interruption, and operational insurance coverage appropriate for their business activities and regulatory exposure.

ARTICLE 1. PERMITTED USE

The YARBIS platform may be used solely for lawful business purposes directly related to mortgage origination workflow management, financial data organization, business intelligence analysis, and related licensed mortgage and real estate professional activities.

ARTICLE 2. PROHIBITED CONDUCT

2.1 Financial & Identity Fraud

•        Uploading, processing, or submitting falsified, fraudulent, altered, counterfeit, or unauthorized documents, tax returns, identification materials, or financial records.

•        Facilitating synthetic identity fraud, straw borrower schemes, or any mortgage fraud scheme.

•        Misrepresenting borrower financial information, income, assets, or employment status.

2.2 Regulatory Violations

•        Using platform analytics to support discriminatory lending practices in violation of ECOA, the Fair Housing Act, or HMDA.

•        Submitting YARBIS outputs directly as AUS determinations, official loan estimates, or binding credit decisions.

•        Using platform data in connection with predatory lending practices.

2.3 Sanctions & Export Violations

•        Processing transactions involving persons or entities on OFAC Specially Designated Nationals (SDN) lists.

•        Facilitating transactions involving jurisdictions subject to U.S. economic sanctions.

•        Circumventing export control regulations applicable to AI software and data.

2.4 Cybersecurity Violations

•        Attempting to gain unauthorized access to YARBIS systems, infrastructure, or other users' data.

•        Uploading malware, ransomware, viruses, trojans, or malicious code to the platform.

•        Conducting denial-of-service attacks, scraping, or automated data extraction without authorization.

•        Attempting to reverse-engineer, decompile, or extract YARBIS proprietary algorithms or source code.

2.5 Account Integrity

•        Sharing login credentials or platform access with unauthorized personnel.

•        Creating multiple accounts to circumvent subscription limitations or enforcement actions.

•        Misrepresenting organizational identity, licensing status, or regulatory standing.

ARTICLE 3. ENFORCEMENT

YARBIS reserves the right to investigate potential violations of this AUP and to suspend or terminate platform access for accounts found to be engaged in prohibited conduct. YARBIS may report suspected illegal activity to law enforcement or regulatory agencies where required or appropriate. YARBIS shall not be liable for any business disruption, loss of data, or financial consequences resulting from enforcement actions taken pursuant to this AUP.

ARTICLE 4. PROHIBITED AI SECURITY ACTIVITIES

Subscriber shall not, and shall not permit any user or third party to:

 (a) engage in prompt injection attacks;

(b) attempt model extraction;

(c) reverse engineer AI orchestration systems;

(d) conduct adversarial testing without authorization;

(e) bypass output restrictions;

(f) automate credential attacks;

(g) generate fraudulent financial documentation;

(h) facilitate synthetic identity creation;

(i) interfere with platform integrity or operational stability.

 Unauthorized security testing, vulnerability scanning, automated scraping, or penetration testing activities are prohibited absent prior written authorization from YARBIS. 

ARTICLE 1. INFORMATION COLLECTED

YARBIS processes the following categories of personal data submitted by or on behalf of consumers through licensed Subscriber channels:

•        Identity Data: Full legal names, Social Security Numbers (SSN), ITINs, government-issued identification, dates of birth, marital status.

•        Financial Data: IRS Forms 1040, W-2s, 1099s, bank statements, asset verifications, investment account records, profit and loss statements.

•        Employment Data: Paystubs, verification of employment documentation, employer information.

•        Transaction Data: Real estate purchase agreements, property appraisal reports, geographic and census tract data.

•        Technical Data: IP addresses, device information, session logs, authentication events.

ARTICLE 2. LAWFUL BASIS & PURPOSE OF PROCESSING

YARBIS processes personal data for the following purposes: (a) performing mortgage workflow analysis, document extraction, and financial data organization under contract with licensed Subscriber institutions; (b) computing indicative loan readiness metrics for professional review; (c) generating structured data outputs in MISMO 3.4 XML format for underwriter review; (d) operating and improving the YARBIS platform; and (e) complying with applicable legal obligations. YARBIS processes personal data only as directed by Subscriber Data Controllers and as permitted by applicable law.

ARTICLE 3. DATA SHARING & NO-SALE POLICY

YARBIS does not sell, rent, lease, or commercially exploit personal data or consumer financial profiles to third-party marketing agencies, lead-generation platforms, unauthorized credit bureaus, or data brokers. YARBIS may share data only: (a) with authorized subprocessors as disclosed in Document 8; (b) as required by applicable law, court order, or regulatory investigation; (c) with Subscriber at Subscriber's instruction; or (d) in connection with a merger, acquisition, or sale of substantially all assets, subject to confidentiality obligations.

ARTICLE 4. STATE PRIVACY RIGHTS COMPLIANCE

4.1 California (CCPA / CPRA)

California residents retain rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including rights to: know what personal information is collected; access, delete, and correct personal information; opt out of sale or sharing of personal information; limit use of sensitive personal information; and non-discrimination for exercising privacy rights. YARBIS processes consumer financial data as a service provider under CCPA. Privacy rights requests may be directed to [INSERT PRIVACY CONTACT EMAIL].

4.2 Other State Privacy Rights

Residents of states with enacted general privacy statutes — including but not limited to Colorado (CPA), Virginia (CDPA), Connecticut (CTDPA), Utah (UCPA), and Texas (TDPSA) — may exercise applicable rights including access, deletion, correction, portability, and opt-out of targeted advertising and profiling. YARBIS does not engage in targeted advertising based on consumer financial data. Privacy rights requests are processed subject to applicable exemptions including those applicable to financial institutions and data subject to federal privacy law (GLBA).

4.3 GLBA & Federal Preemption

To the extent personal data is subject to the Gramm-Leach-Bliley Act (GLBA), GLBA's privacy and security requirements govern YARBIS's treatment of such data. State privacy law rights may be limited to the extent superseded by federal financial privacy law.

ARTICLE 5. SECURITY SUMMARY

YARBIS implements commercially reasonable administrative, technical, and organizational safeguards to protect personal data, as described in detail in the Information Security Policy (Document 4). No security measure is absolute. YARBIS does not warrant freedom from all possible security incidents.

ARTICLE 6. AMENDMENTS

YARBIS reserves the right to modify this Privacy Policy to reflect changes in applicable law, regulatory guidance, or YARBIS's data practices, with advance notice to affected parties where required by law.

ARTICLE 7. LEGAL & REGULATORY DISCLOSURES

YARBIS may disclose information where reasonably necessary to:

(a) comply with applicable law;

(b) respond to legally valid governmental requests;

(c) protect platform security;

(d) investigate fraud;

(e) enforce contractual rights;

(f) prevent unlawful activity;

(g) protect users, customers, or the public from harm.

ARTICLE 1. INCIDENT RESPONSE PROGRAM

YARBIS maintains a formal Incident Response Program that includes: (a) documented incident detection and classification procedures; (b) defined escalation protocols; (c) containment and remediation procedures; (d) post-incident review and lessons-learned processes; and (e) annual testing and revision of the program.

ARTICLE 2. INCIDENT CLASSIFICATION

Level

Definition

Response Timeline

Low

No confirmed unauthorized access to personal data

72 hours — internal investigation, no external notification required

Medium

Suspected unauthorized access; limited personal data exposure

48 hours — investigation, subscriber notification within 72 hours of confirmation

High

Confirmed unauthorized access to NPI data (SSNs, financial records)

24 hours — executive escalation, subscriber notification within 72 hours, regulatory assessment

Critical

Large-scale confirmed breach of sensitive financial and identity data

Immediate — CISO escalation, subscriber notification within 72 hours, regulatory counsel engagement

 

ARTICLE 3. SUBSCRIBER NOTIFICATION OBLIGATIONS

Upon confirming a Security Incident affecting Subscriber data, YARBIS shall notify the Subscriber's designated security contact without unreasonable delay. Notification shall include, to the extent ascertainable: nature and scope of the incident; categories of data affected; preliminary containment actions taken; and YARBIS's security contact for ongoing coordination.

3.1 Regulatory Notification Cooperation

YARBIS shall reasonably cooperate with Subscriber's compliance with applicable breach notification laws, including GLBA Financial Privacy Notification Rule, state breach notification statutes (including but not limited to California Civil Code § 1798.29, Texas Business & Commerce Code § 521, New York SHIELD Act, and similar multistate requirements), and CFPB breach notification guidance.

3.2 Forensic Cooperation

YARBIS shall cooperate with reasonable forensic investigations by Subscriber, qualified cybersecurity professionals retained by Subscriber, and regulatory authorities with lawful investigative authority, subject to applicable confidentiality obligations and YARBIS's own legal counsel's direction.

ARTICLE 4. SUBSCRIBER SECURITY OBLIGATIONS

Subscriber is responsible for securing its own computing environment, including: endpoint security; credential management; employee security training; MFA deployment; and ensuring that YARBIS platform access credentials are not shared or compromised. YARBIS shall not be liable for Security Incidents caused primarily by Subscriber's failure to maintain appropriate endpoint security controls.

ARTICLE 5. PRIVILEGED INCIDENT RESPONSE MATERIALS

To the extent permitted by applicable law, incident investigations, forensic reviews, legal assessments, remediation analyses, and cybersecurity response materials may be conducted under direction of legal counsel for purposes of preserving applicable privileges and protections.

ARTICLE 1. SUBPROCESSOR CATEGORIES

YARBIS may engage subprocessors in the following categories to deliver its platform services:

 

Category

Nature of Processing

Data Categories Potentially Processed

Geographic Processing Region

Transfer Mechanism

Criticality Classification

Core Safeguards

Retention Exposure

Cloud Infrastructure Providers

Data storage, compute, redundancy, disaster recovery

Customer Data, Logs, Metadata, Authentication Records

Primarily United States

SCCs / Contractual Safeguards

Critical

ISO 27001; SOC 2 Type II; Encryption; DPAs

Backup & disaster recovery retention

AI / ML Infrastructure Providers

OCR, document parsing, LLM inference, AI orchestration

Prompt Inputs, AI Outputs, Metadata

Primarily United States

SCCs / Contractual Safeguards

Critical

NPI non-ingestion restrictions; isolated environments; confidentiality obligations

Temporary processing & logging exposure

Transactional Messaging Providers

SMS/MMS delivery, email relay, WhatsApp messaging

Contact Data, Messaging Metadata

United States / Regional Routing

SCCs / Contractual Safeguards

High

Limited metadata processing; DPA restrictions

Carrier and routing retention exposure

Payment Processing Providers

Subscription billing, ACH processing, tokenization

Billing Data, Transaction Metadata

United States

PCI / Contractual Safeguards

High

PCI DSS compliance; tokenization; restricted access

Financial transaction retention

Security & Monitoring Vendors

SIEM logging, monitoring, scanning, threat detection

Logs, Security Metadata, Incident Data

Primarily United States

Contractual Safeguards

Critical

Confidentiality restrictions; scoped access; security controls

Security-event retention

Database Infrastructure Providers

Structured/unstructured data storage

Customer Records, Application Data, Metadata

Primarily United States

SCCs / Contractual Safeguards

Critical

Encryption at rest; access controls; DPA protections

Database backup retention

 

Subprocessor ecosystems, processing activities, hosting arrangements, routing configurations, infrastructure dependencies, and operational vendors may evolve over time based upon operational requirements, security considerations, scalability needs, legal obligations, regulatory requirements, or commercially reasonable business considerations.

ARTICLE 2. SPECIFIC NAMED SUBPROCESSORS

YARBIS may maintain internal records identifying specific subprocessors, infrastructure providers, cloud providers, AI-service providers, telecommunications vendors, monitoring vendors, payment processors, and operational service providers used in connection with delivery of the Services.

Named subprocessor disclosures may be provided to eligible enterprise Subscribers upon commercially reasonable request and subject to appropriate confidentiality obligations, non-disclosure protections, security restrictions, operational limitations, and legitimate compliance-related business justification.

YARBIS reserves the right to add, replace, suspend, remove, or modify subprocessors, infrastructure providers, routing providers, hosting providers, AI providers, or operational vendors where reasonably necessary to support:

(a) operational continuity;

(b) cybersecurity requirements;

(c) scalability;

(d) legal compliance;

(e) regulatory obligations;

(f) incident response activities;

(g) fraud prevention;

(h) service availability.

Nothing within this Schedule constitutes:

(i) a representation regarding uninterrupted availability of third-party services;

(ii) a warranty regarding third-party infrastructure;

(iii) a guarantee that every subprocessor processes all categories of Subscriber data;

(iv) a representation that subprocessors are immune from governmental access requests, lawful process, infrastructure failures, or cybersecurity incidents.

Subscriber acknowledges that certain subprocessors may independently retain logs, metadata, routing information, authentication records, billing records, or security-related information pursuant to their own legal, regulatory, operational, or cybersecurity obligations.

ARTICLE 3. INTERNATIONAL TRANSFER & CROSS-BORDER PROCESSING RESERVATION

Certain subprocessors, infrastructure providers, routing providers, cloud environments, AI providers, or telecommunications vendors may process, route, transmit, replicate, store, cache, monitor, or support operational activities across multiple jurisdictions depending upon infrastructure design, redundancy architecture, network routing, disaster recovery procedures, cybersecurity operations, or operational resiliency measures.

Where commercially reasonable and legally required, YARBIS may implement contractual safeguards, transfer mechanisms, access restrictions, encryption measures, or supplementary technical safeguards intended to support lawful cross-border processing activities.

FORCE MAJEURE & BUSINESS CONTINUITY

ARTICLE 1. FORCE MAJEURE EVENTS

YARBIS shall not be liable for, nor deemed in breach of this Agreement for, any delay or failure in performance resulting from causes beyond YARBIS's reasonable control, including without limitation: (a) acts of God, natural disasters, or severe weather events; (b) government-mandated shutdowns, regulatory orders, or emergency declarations; (c) third-party cloud infrastructure outages or failures (including AWS, Azure, Google Cloud, or equivalent providers); (d) AI model provider infrastructure outages (including but not limited to OpenAI, Anthropic, or equivalent enterprise AI providers); (e) widespread internet disruptions, BGP routing failures, or DNS infrastructure attacks; (f) nation-state cyberattacks, distributed denial-of-service (DDoS) attacks, or ransomware events targeting YARBIS's infrastructure despite commercially reasonable security measures; (g) pandemic, epidemic, or public health emergency; or (h) any other event beyond YARBIS's reasonable control.

ARTICLE 2. NOTICE & MITIGATION

In the event of a Force Majeure Event, YARBIS shall: (a) promptly notify affected Subscribers of the nature and anticipated duration of the disruption; (b) use commercially reasonable efforts to restore service as quickly as technically feasible; and (c) maintain and invoke business continuity and disaster recovery procedures consistent with commercial cloud infrastructure standards.

ARTICLE 3. SUBSCRIBER RIGHTS DURING EXTENDED OUTAGE

If a Force Majeure Event results in continuous platform unavailability exceeding five (5) consecutive business days, Subscriber may request a pro-rata credit for the affected period. If unavailability exceeds thirty (30) consecutive days, Subscriber may terminate the Agreement upon written notice and receive a pro-rated refund of prepaid fees.

ARTICLE 4. NO FORCE MAJEURE FOR PAYMENT OBLIGATIONS

Force Majeure Events do not excuse Subscriber's obligation to make timely subscription payments unless the Force Majeure Event directly prevents Subscriber from accessing banking infrastructure necessary to process payments.

ARTICLE 5. TECHNOLOGY DEPENDENCY EVENTS

Force majeure events may include commercially significant failures, outages, interruptions, or degradation involving:

(a) cloud infrastructure providers;

(b) telecommunications providers;

(c) AI model providers;

(d) hosting environments;

(e) cybersecurity incidents;

(f) internet backbone disruptions;

(g) coordinated cyberattacks;

(h) governmental internet restrictions.

BINDING ARBITRATION AGREEMENT

ARTICLE 1. GOVERNING LAW

This Agreement and all disputes arising hereunder shall be governed by the internal laws of [INSERT STATE — Delaware or Texas recommended] without regard to conflicts of law principles. This Arbitration Agreement is governed by the Federal Arbitration Act (9 U.S.C. §§ 1 et seq.) ('FAA'), and the FAA's provisions shall supersede any state law that would otherwise limit the enforceability of this Agreement.

ARTICLE 2. MUTUAL AGREEMENT TO ARBITRATE

YARBIS and Subscriber mutually agree that any and all disputes, controversies, or claims arising out of or relating to this Agreement, including any dispute concerning its breach, termination, enforcement, interpretation, validity, or the scope of this Arbitration Agreement itself (including any question regarding whether a particular matter is subject to arbitration) shall be resolved by final and binding arbitration administered by the American Arbitration Association (AAA) in accordance with its Commercial Arbitration Rules then in effect.

2.1 Delegation Clause

The parties expressly delegate to the arbitrator the exclusive authority to resolve any dispute relating to the interpretation, applicability, enforceability, or scope of this Arbitration Agreement, including any claim that this Agreement is void or voidable. The arbitrator's jurisdiction includes all threshold arbitrability determinations.

2.2 Place of Arbitration

The seat of arbitration shall be [INSERT CITY, STATE]. Proceedings may be conducted telephonically or via video conference upon the request of either party and agreement of the arbitrator.

2.3 Arbitrator Authority

The arbitrator shall have authority to grant any remedy or relief that a court of competent jurisdiction could grant under applicable law, including injunctive relief, declaratory relief, and monetary damages. The arbitrator shall not have authority to consolidate claims of multiple parties without their consent, or to award damages in excess of any limitations set forth in this Agreement.

ARTICLE 3. EXCEPTIONS TO MANDATORY ARBITRATION

Notwithstanding Section 2, either party may seek emergency injunctive relief or temporary restraining orders from a court of competent jurisdiction: (a) to prevent irreparable harm pending arbitration; (b) to enforce intellectual property rights; or (c) in connection with security incidents requiring immediate court-ordered relief. Such emergency relief shall not be deemed a waiver of the right to arbitration on the underlying merits.

ARTICLE 4. CLASS ACTION & JURY WAIVER

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW: (a) SUBSCRIBER AND YARBIS MUTUALLY AND IRREVOCABLY WAIVE THE RIGHT TO PARTICIPATE IN ANY CLASS, COLLECTIVE, OR REPRESENTATIVE ACTION PROCEEDING; (b) BOTH PARTIES IRREVOCABLY WAIVE THE RIGHT TO A TRIAL BY JURY WITH RESPECT TO ANY MATTER NOT SUBJECT TO ARBITRATION UNDER THIS AGREEMENT; AND (c) ALL CLAIMS MUST BE BROUGHT IN THE PARTIES' INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF, CLASS MEMBER, OR REPRESENTATIVE IN ANY PURPORTED CLASS, COLLECTIVE, OR REPRESENTATIVE PROCEEDING. The validity of this class action waiver shall be determined exclusively by the arbitrator.

ARTICLE 5. FEES & COSTS

AAA filing fees, administrative fees, and arbitrator compensation shall be allocated in accordance with the AAA Commercial Arbitration Rules, except that YARBIS shall advance Subscriber's share of AAA filing fees for claims with a value not exceeding $10,000 where Subscriber demonstrates financial hardship. Each party shall bear its own attorneys' fees except as otherwise required by applicable law or AAA rules.

ARTICLE 6. SURVIVAL

This Arbitration Agreement shall survive: the termination or expiration of this Agreement; any bankruptcy proceeding; the Subscriber's cessation of business; and any transfer or assignment of the Agreement. This Arbitration Agreement is binding upon Subscriber's successors, assigns, and legal representatives.

ARTICLE 7. MASS ARBITRATION PROCEDURES

Where twenty-five (25) or more substantially similar arbitration demands are filed against YARBIS by coordinated parties or counsel, the parties agree that such proceedings may be administered through staged batch arbitration procedures intended to improve efficiency, reduce duplicative costs, and preserve procedural fairness.

ARTICLE 8. CONFIDENTIALITY OF ARBITRATION

8.1 Confidential Proceedings

To the maximum extent permitted by applicable law, arbitration proceedings, filings, testimony, discovery materials, expert reports, arbitration awards, settlement discussions, and related materials shall remain confidential except where disclosure is required by law, court order, regulatory obligation, or enforcement necessity.

8.2 Protective Orders

The arbitrator may issue confidentiality orders, protective orders, discovery restrictions, sealing directives, and commercially reasonable safeguards designed to protect confidential information, trade secrets, security materials, proprietary systems, and regulated information.

ARTICLE 1. PURPOSE & REGULATORY SCOPE

1.1 Purpose

This Regulatory Retention Matrix establishes the commercially reasonable records-retention framework applicable to YARBIS and its Subscribers in connection with mortgage, lending, consumer-financial, AI-governance, cybersecurity, compliance, and operational records processed through the YARBIS platform.

 The retention periods identified herein are intended to assist Subscribers in satisfying applicable federal and state record-preservation obligations. Subscriber remains solely responsible for determining the legal sufficiency of any retention period applicable to Subscriber’s specific jurisdiction, licensing status, business model, or regulatory obligations.

1.2 No Independent Legal Advice

Nothing contained in this Matrix constitutes legal advice, regulatory certification, or a guarantee of compliance with any federal, state, international, or industry-specific retention requirement.

 Subscribers are strongly encouraged to consult independent legal counsel and compliance professionals regarding retention obligations applicable to their operations..

ARTICLE 2. REGULATORY RETENTION MATRIX

Regulation / Agency

Record Type

Standard Retention Period

Responsible Party

Preservation Override Trigger

Backup / Archive Retention

Legal Hold Eligible

Notes

RESPA (12 C.F.R. § 1024)

Loan origination files, HUD-1, GFE

3 Years

Subscriber / Lender

Litigation, CFPB Inquiry, Audit

Up to 90 Days Additional

Yes

Subject to lender preservation duties

TILA / TRID (12 C.F.R. § 1026)

Loan Estimate, Closing Disclosure, application records

3 Years Post-Consummation

Subscriber / Lender

Regulatory Investigation / Dispute

Up to 90 Days Additional

Yes

Consumer-finance sensitivity

ECOA / Reg B (12 C.F.R. § 202)

Applications, adverse action notices, appraisal reports

25 Months Post-Action

Subscriber / Lender

Fair Lending Investigation

Up to 180 Days Additional

Yes

Fair-lending litigation exposure

HMDA (12 C.F.R. § 1003)

LAR data, application data, disposition records

3 Years

Subscriber / Lender

CFPB / DOJ Investigation

Up to 180 Days Additional

Yes

Regulatory reporting sensitivity

GLBA Safeguards Rule

NPI processing records, security governance records

Program Lifecycle + Applicable Retention

Subscriber + YARBIS (Scoped)

Security Incident / Regulatory Inquiry

Up to 365 Days Additional

Yes

Security governance relevance

Fannie Mae Selling Guide

Complete loan file documentation

7 Years Post-Sale

Subscriber / Servicer

Repurchase Demand / Litigation

Up to 365 Days Additional

Yes

Secondary-market obligations

Freddie Mac Guide

Origination documentation

7 Years Post-Sale

Subscriber / Servicer

Enforcement / Repurchase Review

Up to 365 Days Additional

Yes

Servicing oversight

FHA / HUD (24 C.F.R.)

FHA-insured loan files

7 Years

Subscriber / Lender

HUD Investigation

Up to 365 Days Additional

Yes

Government-insured loan exposure

IRS Regulations

Tax documentation used in underwriting

3–7 Years (Varies)

Subscriber / Tax Advisor

Tax Audit / Investigation

Up to 180 Days Additional

Yes

Tax-sensitive records

State-Specific Requirements

Licensing, disclosure, origination records

2–10 Years (Varies by Jurisdiction)

Subscriber / Lender

State Enforcement Action

Up to 180 Days Additional

Yes

Jurisdiction-dependent

TCPA / Communications Compliance

SMS consent records, communication logs

5 Years

Subscriber + YARBIS (Scoped)

Consumer Complaint / Litigation

Up to 180 Days Additional

Yes

Consent defensibility

Arbitration / Dispute Records

Arbitration demands, rulings, settlement records

7 Years

YARBIS

Active Dispute / Appeal

Up to 365 Days Additional

Yes

Litigation preservation

Security Incident Records

Incident logs, forensic records, remediation records

7 Years

YARBIS

Ongoing Investigation

Up to 365 Days Additional

Yes

Cybersecurity defensibility

AI Interaction & Audit Logs

AI interactions, escalation events, operational logs

12–24 Months Operationally Determined

YARBIS

AI Investigation / Dispute / Regulatory Review

Up to 180 Days Additional

Yes

AI governance support

ARTICLE 3. LEGAL HOLD & PRESERVATION OVERRIDE

3.1 Legal Hold Supremacy

Notwithstanding any retention or deletion schedule contained in this Matrix or elsewhere within the Enterprise Legal Framework, YARBIS may suspend deletion, destruction, anonymization, archival rotation, or purge procedures where commercially reasonable and necessary to comply with:

(a) litigation hold obligations;

(b) subpoena preservation requirements;

(c) governmental investigations;

(d) regulatory examinations;

(e) cybersecurity forensic investigations;

(f) sanctions-related inquiries;

(g) fraud investigations; or

(h) other legal preservation obligations under Applicable Law.

3.2 Subscriber Preservation Responsibility

Subscriber remains solely responsible for issuing preservation instructions, litigation hold notices, and document retention directives applicable to Subscriber-controlled records, legal matters, regulatory proceedings, or investigations.

 YARBIS shall not be liable for preservation failures arising from Subscriber’s failure to timely issue appropriate legal hold instructions.

3.3 Preservation Scope Limitations

YARBIS does not guarantee indefinite retention of all operational logs, AI interaction metadata, system telemetry, temporary cache files, transient processing artifacts, backup snapshots, or infrastructure-level records unless expressly required by Applicable Law or a valid legal preservation order.

ARTICLE 4. NO INDEFINITE RETENTION OBLIGATION

4.1 Commercially Reasonable Retention Standards

YARBIS implements commercially reasonable retention and deletion practices designed to balance regulatory compliance, cybersecurity minimization principles, storage efficiency, privacy obligations, and operational necessity.

 Nothing in this Matrix shall be interpreted to require perpetual retention of records unless expressly mandated by Applicable Law.

4.2 Secure Deletion Reservation

Following expiration of applicable retention periods and absent any active preservation obligation, YARBIS may securely delete, anonymize, archive, overwrite, or destroy records using commercially reasonable deletion procedures consistent with operational, security, and infrastructure practices.

4.3 Regulatory Evolution Reservation

Retention obligations may evolve based upon future regulatory guidance, amendments to Applicable Law, CFPB directives, FTC guidance, state privacy legislation, AI-governance requirements, or cybersecurity regulations.

 YARBIS reserves the right to update this Matrix periodically to address evolving legal and operational requirements.

ARTICLE 1. CONSENT TO ELECTRONIC TRANSACTIONS

By accessing, registering for, using, authenticating into, electronically accepting, clicking assent mechanisms, or otherwise interacting with the YARBIS platform, Subscriber expressly agrees and consents to conduct transactions electronically to the fullest extent permitted under applicable law, including under the Electronic Signatures in Global and National Commerce Act ("ESIGN"), applicable Uniform Electronic Transactions Acts ("UETA"), and other applicable electronic-transactions laws.

 Subscriber acknowledges and agrees that electronic signatures, electronic records, click-through acceptances, digital acknowledgements, authentication events, electronic workflows, and electronic assent mechanisms may possess the same legal validity, enforceability, and evidentiary effect as physical signatures and paper records.

 Subscriber further represents that:

(a) Subscriber has authority to enter into electronic transactions;

(b) Subscriber intends to be legally bound by electronically executed actions;

(c) electronic actions performed by authorized users, administrators, delegates, employees, agents, contractors, or representatives associated with Subscriber accounts may be attributable to Subscriber;

(d) Subscriber is responsible for maintaining appropriate internal authorization controls relating to account access and delegated user permissions.

ARTICLE 2. AUDIT TRAIL ARCHITECTURE

YARBIS may maintain commercially reasonable transaction logging, authentication records, audit metadata, and integrity verification controls intended to support operational integrity, fraud prevention, dispute resolution, evidentiary preservation, and electronic transaction validation.

 Audit-related records may include:

 (a) authentication identifiers;

(b) document integrity hashes;

(c) originating IP addresses;

(d) routing metadata;

(e) UTC-synchronized timestamps;

(f) session activity records;

(g) device or browser metadata;

(h) transaction event records.

 Such records may be used for operational, evidentiary, security, compliance, fraud-prevention, or dispute-resolution purposes.

 Nothing herein constitutes:

(i) a guarantee of uninterrupted logging;

(ii) a representation that every transaction event will be permanently retained indefinitely;

(iii) a warranty regarding admissibility under every jurisdiction or evidentiary standard.

ARTICLE 3. HARDWARE & SOFTWARE REQUIREMENTS

To access, review, execute, store, or retain electronic records through YARBIS, Subscriber may require:

(a) internet-connected computing devices;

(b) a modern supported web browser;

(c) software capable of rendering PDF, HTML, or similar electronic records;

(d) functional electronic mail capability;

(e) sufficient storage capability for record retention.

 YARBIS does not guarantee compatibility with:

(f) legacy systems;

(g) unsupported browser versions;

(h) modified operating environments;

(i) third-party software conflicts;

(j) telecommunications interruptions;

(k) external infrastructure failures.

ARTICLE 4. WITHDRAWAL OF ELECTRONIC CONSENT

Subscriber may withdraw consent to electronic transactions where permitted by applicable law by delivering commercially reasonable notice to YARBIS through designated operational channels.

 Because the Services are delivered primarily through electronic means, withdrawal of electronic consent may:

(a) limit or terminate platform functionality;

(b) restrict access to certain Services;

(c) delay transactions or communications;

(d) require alternative processing methods;

(e) result in suspension or termination of platform access where electronic delivery is operationally necessary.

 Subscriber is responsible for downloading, retaining, and archiving records that Subscriber determines necessary for legal, operational, tax, regulatory, servicing, underwriting, compliance, or evidentiary purposes.

ARTICLE 5. ELECTRONIC DELIVERY LIMITATIONS

5.1 Availability of Electronic Delivery

YARBIS does not guarantee uninterrupted availability of electronic delivery systems, including email transmission systems, SMS infrastructure, internet connectivity, mobile carrier routing, cloud delivery infrastructure, or third-party communication services.

Electronic communications may be delayed, filtered, blocked, quarantined, or rendered inaccessible due to circumstances outside YARBIS’s commercially reasonable control.

5.2 Subscriber Responsibility

Subscriber is solely responsible for maintaining accurate contact information, monitoring electronic communications, maintaining internet access, updating compatible software, and ensuring continued accessibility to electronic records delivered through the platform.

5.3 No Guarantee of Receipt

Transmission of electronic records by YARBIS does not guarantee actual receipt, review, acknowledgment, or comprehension by the intended recipient.

ARTICLE 6. RECORD RETENTION & ELECTRONIC ACCESS

6.1 Record Preservation

Subscriber is responsible for downloading, retaining, archiving, and preserving copies of electronically delivered agreements, disclosures, notices, and transaction records that Subscriber determines necessary for legal, operational, compliance, evidentiary, or regulatory purposes.

6.2 Retention Limitations

YARBIS does not guarantee indefinite retention or perpetual accessibility of electronically stored records, audit logs, transactional metadata, or communication histories unless otherwise required under Applicable Law or an active legal preservation obligation.

6.3 Access After Termination

Following termination, suspension, expiration, or closure of a Subscriber account, access to electronic records may be restricted, limited, archived, or permanently deleted in accordance with YARBIS retention policies and the Enterprise Legal Framework.

ARTICLE 7. REGULATORY EVOLUTION RESERVATION

7.1 Evolving Electronic Signature Laws

Electronic signature, electronic records, consumer-consent, digital-authentication, and remote-transaction regulations may evolve over time across federal, state, and international jurisdictions.

YARBIS reserves the right to modify electronic signature procedures, consent workflows, authentication controls, audit logging standards, or delivery mechanisms as reasonably necessary to maintain operational, legal, or regulatory compliance.

7.2 Additional Verification Requirements

YARBIS may require additional authentication procedures, identity verification measures, multi-factor authentication, re-consent workflows, or supplemental acknowledgments where commercially reasonable or required under Applicable Law.

ARTICLE 8. NO LEGAL ADVICE OR REGULATORY GUARANTEE

8.1 No Legal Advice

Nothing within this Disclosure constitutes legal advice regarding the enforceability of electronic signatures, digital records, consumer-consent procedures, or evidentiary sufficiency under any specific jurisdiction.

8.2 No Guarantee of Enforceability

YARBIS does not guarantee that any electronic signature, consent mechanism, disclosure workflow, or audit trail will be deemed enforceable in every jurisdiction, regulatory proceeding, judicial forum, or factual circumstance.

ARTICLE 1. NATURE OF COMMUNICATIONS

YARBIS may facilitate automated, application-generated, transactional, operational, informational, servicing-related, authentication-related, security-related, or workflow-related communications through SMS, MMS, WhatsApp, email, push notification, or similar electronic communication channels in connection with platform operations and Subscriber-authorized workflows.

 Such communications may include:

(a) mortgage-processing updates;

(b) document deficiency notifications;

(c) authentication or verification requests;

(d) workflow status notifications;

(e) servicing-related alerts;

(f) fraud-prevention notifications;

(g) operational support communications;

(h) account-security notifications.

 YARBIS does not intend to use these communication channels for unsolicited telemarketing campaigns or mass-marketing solicitations unless expressly disclosed otherwise through separate consent mechanisms where legally required.

ARTICLE 2. EXPRESS WRITTEN CONSENT

Where required by applicable law, YARBIS or Subscriber shall obtain prior express consent or prior express written consent before initiating automated, prerecorded, autodialed, or regulated electronic communications to mobile telephone numbers or electronic messaging accounts.

 Consent mechanisms may include:

(a) click-through acceptance mechanisms;

(b) electronic signature workflows;

(c) checkbox acknowledgements;

(d) account-registration workflows;

(e) recorded authorizations;

(f) Subscriber-managed consent collection systems.

 Subscriber acknowledges that certain transactional, servicing-related, fraud-prevention, authentication, compliance-related, or security-related communications may be operationally necessary for effective use of the Services.

 Subscriber further acknowledges that consent obligations may vary based upon:

(g) jurisdiction;

(h) communication channel;

(i) message purpose;

(j) evolving regulatory interpretations;

(k) carrier requirements.

ARTICLE 3. OPT-OUT MECHANICS & REVOCATION PROCEDURES

Recipients may revoke consent or opt out of automated communications using commercially reasonable methods made available through applicable communication channels, including replying "STOP" where operationally supported.

 YARBIS or Subscriber may send a limited confirmation message acknowledging processing of the revocation request.

Operational, fraud-prevention, security-related, legally required, authentication-related, or account-protection communications may continue where reasonably necessary notwithstanding certain communication preferences.

 Reasonable operational processing time may be required to implement revocation requests across systems, carriers, routing providers, integrations, or communication environments.

 Subscriber remains responsible for honoring legally required revocation requests relating to Subscriber-initiated communications.

ARTICLE 4. SUBSCRIBER COMMUNICATION COMPLIANCE OBLIGATIONS

Where Subscribers utilize YARBIS communication functionalities, integrations, workflows, APIs, automations, messaging capabilities, or operational communication tools, Subscriber remains solely responsible for:

 (a) obtaining legally sufficient consent;

(b) maintaining consent records;

(c) honoring revocation requests;

(d) managing reassigned-number compliance risks;

(e) complying with TCPA requirements;

(f) complying with FCC regulations;

(g) complying with state telemarketing laws;

(h) complying with mini-TCPA statutes;

(i) complying with WhatsApp Business policies;

(j) ensuring communication content complies with applicable law.

 YARBIS does not provide legal advice regarding Subscriber communication practices and shall not be responsible for Subscriber-generated communications, recipient lists, consent collection procedures, campaign configuration, dialing methodologies, targeting decisions, or regulatory compliance failures arising from Subscriber-controlled activities.

ARTICLE 5. CARRIER & THIRD-PARTY DELIVERY LIMITATIONS

Delivery of SMS, MMS, WhatsApp, telecommunications, authentication, or messaging communications may depend upon third-party carriers, routing providers, internet infrastructure, telecommunications providers, device configurations, operating systems, or third-party applications beyond YARBIS's reasonable control.

 YARBIS does not guarantee uninterrupted, timely, error-free, or universally successful delivery of every electronic communication or notification.

ARTICLE 6. MESSAGE & DATA RATES

Standard message, data, carrier, roaming, or telecommunications charges may apply depending upon recipient mobile plans, carrier arrangements, device configurations, or regional telecommunications practices.

 Recipients are solely responsible for charges imposed by telecommunications providers or messaging platforms.

ARTICLE 7. EVOLVING REGULATORY ENVIRONMENT

Subscriber acknowledges that laws, regulations, regulatory guidance, carrier policies, telecommunications standards, platform policies, and judicial interpretations governing electronic communications may evolve over time.

 YARBIS does not represent that any specific communication workflow, consent mechanism, automation configuration, or messaging practice will satisfy all legal requirements in every jurisdiction or regulatory environment.

ARTICLE 1. EXPORT CONTROL COMPLIANCE

The YARBIS platform, including software, AI-enabled functionalities, workflows, technical configurations, APIs, orchestration systems, machine-learning components, technical data, encryption technologies, operational documentation, and related technologies may be subject to applicable export-control laws and regulations, including the U.S. Export Administration Regulations ("EAR"), sanctions regulations, anti-boycott laws, and other applicable trade-control requirements.

 Subscriber shall not directly or indirectly:

(a) access;

(b) export;

(c) re-export;

(d) transfer;

(e) provide access to;

(f) make available;

(g) route through restricted intermediaries;

(h) permit unauthorized use of;

 the Services, software, technical data, AI-enabled systems, or controlled technologies in violation of applicable export-control laws or sanctions restrictions.

 Subscriber remains solely responsible for obtaining licenses, authorizations, governmental approvals, or internal compliance reviews required for Subscriber's intended use of the Services.

ARTICLE 2. OFAC SANCTIONS COMPLIANCE

Subscriber represents, warrants, and agrees that neither Subscriber, nor to Subscriber's knowledge any beneficial owner, controller, affiliate, intermediary, agent, administrator, or authorized user associated with Subscriber:

(a) is identified on sanctions or restricted-party lists maintained by OFAC, BIS, the U.S. Department of State, the United Nations, the European Union, the United Kingdom, or other applicable governmental authorities;

(b) is owned or controlled by sanctioned persons;

(c) will use the Services for transactions involving sanctioned persons, restricted jurisdictions, embargoed territories, or prohibited end uses;

(d) will use the Services in connection with unlawful export activities, prohibited financial activities, sanctions evasion, money laundering, terrorist financing, or prohibited trade activities;

(e) will circumvent or attempt to circumvent applicable sanctions, export-control restrictions, or geographic access restrictions.

 Subscriber shall promptly notify YARBIS upon becoming aware of any sanctions-related compliance concern relating to Subscriber's use of the Services.

ARTICLE 3. SANCTIONS SCREENING & COMPLIANCE CONTROLS

YARBIS may implement commercially reasonable compliance controls intended to support applicable sanctions, export-control, fraud-prevention, cybersecurity, anti-abuse, and regulatory compliance obligations.

 Such measures may include:

(a) sanctions screening;

(b) geographic access restrictions;

(c) IP-based controls;

(d) transactional reviews;

(e) account verification procedures;

(f) fraud monitoring;

(g) enhanced due diligence procedures;

(h) service restrictions or suspensions.

 YARBIS reserves the right to suspend, restrict, investigate, refuse, or terminate access to the Services where reasonably necessary to address:

(i) sanctions concerns;

(j) export-control risks;

(k) cybersecurity threats;

(l) governmental directives;

(m) fraud-prevention concerns;

(n) regulatory compliance obligations.

ARTICLE 4. INDEMNIFICATION FOR EXPORT-CONTROL & SANCTIONS VIOLATIONS

Subscriber shall defend, indemnify, and hold harmless YARBIS and its affiliates, officers, directors, employees, contractors, licensors, service providers, and agents from and against claims, penalties, fines, liabilities, enforcement actions, governmental investigations, damages, costs, or expenses (including reasonable attorneys' fees) arising from:

(a) Subscriber's violation of export-control laws;

(b) sanctions violations;

(c) unlawful international transfers;

(d) prohibited end-use activities;

(e) Subscriber's failure to obtain legally required authorizations;

(f) Subscriber's misuse of the Services in connection with restricted jurisdictions, sanctioned persons, prohibited technologies, or unlawful activities.

ARTICLE 5. GEOGRAPHIC & JURISDICTIONAL RESTRICTIONS

Access to the Services may be restricted, suspended, degraded, blocked, monitored, or prohibited in certain jurisdictions based upon:

(a) sanctions restrictions;

(b) export-control obligations;

(c) cybersecurity risks;

(d) infrastructure limitations;

(e) governmental directives;

(f) operational risk considerations;

(g) fraud-prevention concerns.

YARBIS does not guarantee availability of the Services in every jurisdiction.

ARTICLE 6. AI & RESTRICTED TECHNOLOGY CONTROLS

Subscriber shall not use, export, provide access to, or facilitate access to AI-enabled functionalities, technical workflows, orchestration systems, automation capabilities, or platform technologies in connection with:

 (a) prohibited military end uses;

(b) unlawful surveillance activities;

(c) prohibited weapons activities;

(d) restricted governmental activities;

(e) unlawful cyber activities;

(f) prohibited export-controlled activities.

 Subscriber acknowledges that certain AI-enabled technologies may become subject to evolving export-control restrictions, licensing requirements, or governmental regulations over time.

ARTICLE 7. NO LEGAL ADVICE OR COMPLIANCE CERTIFICATION

YARBIS does not provide legal advice regarding export-control laws, sanctions compliance, anti-money laundering obligations, anti-boycott restrictions, telecommunications regulations, or international trade requirements.

 Subscriber remains solely responsible for obtaining independent legal advice and implementing Subscriber-specific compliance procedures appropriate for Subscriber's operations, jurisdictions, counterparties, and regulatory obligations.

ARTICLE 1. INTELLECTUAL PROPERTY OWNERSHIP

All right, title, and interest in and to the Services, platform, software, APIs, orchestration systems, AI-enabled functionalities, machine-learning systems, workflows, scoring methodologies, prompt orchestration logic, model configurations, trade secrets, databases, compilations, user interfaces, documentation, visual elements, trademarks, service marks, copyrights, derivative works, technical architectures, operational methods, and related intellectual property rights are and shall remain the exclusive property of YARBIS, Inc. and/or its licensors.

 Except for the limited rights expressly granted under the Enterprise Legal Framework, no rights are granted to Subscriber by implication, estoppel, exhaustion, waiver, or otherwise.

 Subscriber shall not acquire ownership rights, derivative rights, training rights, model rights, commercialization rights, or residual rights relating to the Services or YARBIS intellectual property through use of the platform, provision of feedback, operational interaction, configuration activity, workflow participation, or exposure to AI-generated outputs.

ARTICLE 2. PROHIBITED ACTIVITIES

Subscriber shall not, and shall not permit any third party to:

(a) reverse engineer, decompile, disassemble, decode, extract, scrape, or attempt to derive source code, models, prompts, architectures, workflows, training methodologies, datasets, trade secrets, or proprietary logic from the Services;

(b) create derivative works, competing systems, substitute products, benchmark studies, comparative analyses, training datasets, synthetic datasets, or commercial substitutes derived from the Services;

(c) use automated tools, bots, crawlers, harvesting systems, scraping systems, extraction systems, or automated querying mechanisms against the Services except where expressly authorized in writing;

(d) remove, alter, bypass, disable, interfere with, or circumvent security controls, access restrictions, telemetry systems, watermarking systems, attribution systems, or proprietary notices;

(e) use outputs, workflows, or platform behavior to train external machine-learning systems, language models, ranking systems, or AI systems;

(f) publish performance benchmarks, stress-test results, comparative analyses, or security-testing results without prior written authorization;

(g) access the Services for purposes of developing competing products or services;

(h) exploit interoperability exceptions, statutory exemptions, fair-use theories, or reverse-engineering defenses beyond the minimum extent strictly permitted under non-waivable applicable law.

ARTICLE 3. SUBSCRIBER DATA & LIMITED LICENSE

Subscriber retains ownership of Subscriber-provided data, documents, records, prompts, workflows, configurations, and authorized content submitted to the Services ("Subscriber Content"), subject to the limited rights granted herein.

 Subscriber grants YARBIS a limited, non-exclusive, non-transferable (except as necessary for service delivery), sublicensable solely to authorized subprocessors, revocable (subject to operational necessity), license to host, process, transmit, store, reproduce, analyze, index, display internally, and use Subscriber Content solely as reasonably necessary to:

(a) provide the Services;

(b) maintain platform functionality;

(c) support cybersecurity operations;

(d) perform fraud prevention;

(e) comply with legal obligations;

(f) enforce contractual rights;

(g) support operational integrity.

 Except where expressly authorized in writing, YARBIS shall not intentionally use Subscriber-provided non-public data for generalized public model training purposes.

 Subscriber represents and warrants that Subscriber possesses all rights, authorizations, notices, and consents necessary to provide Subscriber Content to YARBIS.

ARTICLE 4. DMCA & COPYRIGHT COMPLAINT PROCEDURES

YARBIS respects intellectual property rights and intends to comply with the Digital Millennium Copyright Act ("DMCA"), 17 U.S.C. § 512, and other applicable intellectual-property laws.

 Copyright complaints relating to allegedly infringing materials accessible through the Services may be directed to YARBIS's designated DMCA agent at:

 DMCA ENTITY:

Yarbis Mortgage Tech LLC

Legal Compliance Department

Attn: DMCA Designated Agent.

Wilmington, Delaware, United States

dmca@yarbis.app

 A compliant notification should include:

(a) identification of the copyrighted work claimed to be infringed;

(b) identification of the allegedly infringing material;

(c) reasonably sufficient location information;

(d) contact information of the complaining party;

(e) a good-faith statement regarding unauthorized use;

(f) a statement made under penalty of perjury regarding claimed accuracy;

(g) a physical or electronic signature of the complaining party.

 YARBIS reserves the right to remove, restrict, disable, investigate, preserve, or review allegedly infringing materials where reasonably necessary to address intellectual-property claims, legal obligations, operational integrity, abuse prevention, or platform security.

ARTICLE 5. COUNTER-NOTIFICATION PROCEDURES

YARBIWhere permitted by applicable law, users subject to copyright complaints may submit counter-notifications containing information reasonably sufficient to evaluate the disputed claim.

 YARBIS reserves the right to:

(a) request additional verification;

(b) reject incomplete submissions;

(c) preserve evidence;

(d) maintain restrictions during investigation;

(e) comply with court orders or legal process.

 YARBIS does not adjudicate ownership disputes between private parties and may rely upon facially valid notices or legal process in administering intellectual-property complaints.

ARTICLE 6. ENFORCEMENT & EQUITABLE RELIEF

If Subscriber, users, administrators, agents, or representatives provide suggestions, enhancements, recommendations, corrections, ideas, workflows, feedback, or proposed modifications relating to the Services, YARBIS may use such feedback without restriction or compensation unless expressly agreed otherwise in writing.

 Subscriber shall not submit confidential third-party intellectual property, export-controlled information, or unlawfully obtained materials as feedback..

ARTICLE 7. OPEN-SOURCE & THIRD-PARTY COMPONENTS

Certain components of the Services may incorporate open-source software, third-party libraries, APIs, infrastructure services, or externally licensed technologies subject to separate license terms.

Nothing within this Policy shall be interpreted as granting Subscriber rights beyond those expressly permitted under applicable third-party licenses.

 To the extent required by applicable open-source licenses, relevant notices or attributions may be made available by YARBIS through commercially reasonable means.

ARTICLE 8. FEEDBACK & SUGGESTIONS

If Subscriber, users, administrators, agents, or representatives provide suggestions, enhancements, recommendations, corrections, ideas, workflows, feedback, or proposed modifications relating to the Services, YARBIS may use such feedback without restriction or compensation unless expressly agreed otherwise in writing.

 Subscriber shall not submit confidential third-party intellectual property, export-controlled information, or unlawfully obtained materials as feedback.

ARTICLE 9. REPEAT INFRINGER POLICY

YARBIS may suspend, restrict, terminate, investigate, preserve, or limit access to accounts associated with repeated intellectual-property complaints, repeated infringement allegations, abusive content practices, repeated unauthorized use claims, or repeated violations of applicable intellectual-property laws.

 YARBIS reserves the right to determine, in its commercially reasonable discretion, whether conduct constitutes repeated infringement, abusive intellectual-property conduct, fraudulent notices, or misuse of the Services.

ARTICLE 10. AI TRAINING & MODEL INGESTION RESTRICTIONS

10.1 No Unauthorized AI Training Use

Subscriber Data, regulated information, confidential information, mortgage records, consumer information, or uploaded materials shall not be used for generalized AI model training, public foundation-model ingestion, or unrelated model-development purposes except where expressly authorized in writing by Subscriber.

10.2 Isolated Enterprise Processing Reservation

YARBIS may utilize isolated, access-restricted, commercially reasonable AI-processing environments necessary for operational functionality, security monitoring, fraud detection, workflow automation, or service delivery consistent with applicable agreements and privacy obligations.

ARTICLE 1. PURPOSE & GOVERNANCE SCOPE

This Policy governs content moderation, platform governance, user-generated content controls, abuse prevention measures, operational review procedures, evidence preservation practices, and enforcement activities relating to use of the YARBIS platform and Services.

 This Policy applies to:

(a) Subscriber-submitted materials;

(b) uploaded documents;

(c) communications transmitted through the Services;

(d) AI-generated outputs;

(e) workflow-generated content;

(f) integrations;

(g) platform interactions;

(h) operational metadata;

(i) user conduct associated with platform usage.

ARTICLE 2. USER-GENERATED CONTENT RESPONSIBILITY

Subscriber remains solely responsible for all content, documents, records, communications, prompts, workflows, data, images, attachments, uploads, or materials submitted to, transmitted through, stored within, processed by, or generated through Subscriber-controlled use of the Services ("UGC").

Subscriber represents and warrants that Subscriber possesses all rights, permissions, authorizations, disclosures, notices, and lawful bases necessary for submitted UGC.

 Subscriber shall not submit, upload, transmit, generate, distribute, store, or process content that:

(a) violates applicable law;

(b) infringes intellectual-property rights;

(c) violates privacy rights;

(d) contains unlawful financial information usage;

(e) contains malicious code;

(f) facilitates fraud;

(g) facilitates sanctions evasion;

(h) facilitates unlawful surveillance;

(i) facilitates harassment, abuse, threats, or unlawful conduct;

(j) violates export-control laws;

(k) violates applicable consumer-finance laws.

ARTICLE 3. CONTENT MODERATION AUTHORITY

YARBIS reserves the right, but not the obligation, to review, monitor, preserve, investigate, restrict, remove, disable, quarantine, suspend, escalate, report, or otherwise take action regarding content, accounts, workflows, integrations, or platform activity where reasonably necessary to:

(a) comply with legal obligations;

(b) address cybersecurity risks;

(c) investigate fraud;

(d) preserve evidence;

(e) enforce contractual rights;

 (f) comply with governmental requests;

(g) prevent abuse;

(h) maintain operational integrity;

(i) protect platform security;

(j) investigate intellectual-property complaints;

(k) address suspected unlawful conduct.

 YARBIS may take such actions with or without prior notice where reasonably necessary for security, compliance, operational, legal, or investigative purposes.

ARTICLE 4. NO DUTY TO MONITOR, SUPERVISE, VERIFY, OR PREVENT

YARBIS does not undertake, assume, or accept any continuous, proactive, comprehensive, or fiduciary obligation to:

(a) monitor Subscriber activity;

(b) supervise lending decisions;

(c) review all platform usage;

(d) verify regulatory compliance;

(e) validate borrower information;

(f) detect fraud;

(g) prevent cybersecurity incidents;

(h) review communications;

(i) monitor all AI-generated outputs;

(j) ensure legal compliance of Subscriber conduct;

(k) investigate all suspicious activity;

(l) prevent misconduct by Subscriber personnel, administrators, agents, contractors, borrowers, or third parties.

 Any moderation systems, fraud-detection systems, AI monitoring systems, anomaly-detection systems, cybersecurity systems, compliance tools, review workflows, escalation mechanisms, or automated safeguards implemented by YARBIS are provided solely as commercially reasonable operational support measures and shall not create:

(i) a legal duty to monitor;

(ii) a fiduciary obligation;

(iii) supervisory liability;

(iv) regulatory oversight responsibility;

(v) underwriting responsibility;

(vi) continuous review obligations;

(vii) a guarantee of fraud prevention;

(viii) a guarantee of regulatory compliance;

(ix) a guarantee of cybersecurity detection;

(x) a guarantee of operational accuracy.

 Failure to detect, remove, restrict, escalate, investigate, flag, suspend, report, prevent, or remediate particular conduct, content, communications, transactions, AI outputs, cybersecurity events, fraud indicators, suspicious activities, or regulatory violations shall not constitute:

(A) approval;

(B) authorization;

(C) endorsement;

(D) assumption of responsibility;

(E) waiver of rights;

(F) negligence per se;

(G) acceptance of supervisory duties;

(H) acceptance of regulatory obligations.

 Subscriber acknowledges that automated systems, AI systems, moderation tools, fraud-detection systems, cybersecurity systems, compliance systems, and operational review mechanisms may produce false positives, false negatives, incomplete detections, delayed detections, operational inaccuracies, unavailable outputs, or inconsistent results.

 Subscriber remains solely responsible for all regulated activities, lending decisions, underwriting determinations, legal compliance obligations, borrower interactions, regulatory supervision requirements, fraud investigations, cybersecurity governance obligations, and operational decision-making associated with Subscriber’s business activities.

ARTICLE 5. AI-GENERATED OUTPUTS

AI-generated outputs, recommendations, summaries, classifications, workflow suggestions, automated decisions, risk scores, document analyses, or generated content produced through the Services may contain inaccuracies, omissions, hallucinations, incomplete information, outdated information, or unintended results.

Subscriber remains solely responsible for independently reviewing, validating, approving, and verifying AI-generated outputs before reliance, distribution, regulatory usage, underwriting usage, consumer communication, legal reliance, or operational implementation.

YARBIS does not guarantee:

(a) factual accuracy;

(b) legal sufficiency;

(c) underwriting compliance;

(d) regulatory compliance;

(e) merchantability of AI outputs;

(f) uninterrupted model behavior;

(g) error-free AI operation.

ARTICLE 6. EVIDENCE PRESERVATION & INVESTIGATIONS

YARBIS may preserve logs, metadata, communications, uploaded materials, routing records, authentication records, AI interactions, operational telemetry, audit trails, and related electronic records where reasonably necessary for:

(a) litigation preservation;

(b) fraud investigations;

(c) cybersecurity investigations;

(d) regulatory inquiries;

(e) sanctions investigations;

(f) abuse investigations;

(g) intellectual-property disputes;

(h) contractual enforcement.

 Preserved records may remain retained notwithstanding ordinary deletion schedules, retention expiration periods, anonymization workflows, or Subscriber deletion requests where preservation is reasonably necessary under applicable law or operational requirements.

ARTICLE 7. GOVERNMENTAL & LEGAL REQUESTS

YARBIS may respond to subpoenas, court orders, governmental directives, lawful process, law-enforcement requests, regulatory inquiries, preservation requests, or other legal demands where reasonably necessary or legally required.

Where legally permissible and operationally appropriate, YARBIS may provide notice to affected Subscribers regarding such requests.

 YARBIS reserves the right to preserve, disclose, restrict, suspend, or investigate content or account activity in connection with legal or regulatory obligations.

ARTICLE 8. REPEAT ABUSE & ENFORCEMENT POLICY

YARBIS may suspend, restrict, investigate, terminate, preserve, escalate, or permanently disable accounts associated with:

(a) repeated policy violations;

(b) repeated intellectual-property complaints;

(c) repeated fraud indicators;

(d) abusive platform conduct;

(e) unlawful automation;

(f) scraping activities;

(g) cybersecurity abuse;

(h) sanctions-related concerns;

(i) repeated unlawful-content submissions.

 YARBIS reserves the right to determine, in its commercially reasonable discretion, whether conduct constitutes abusive, fraudulent, unlawful, malicious, harmful, or operationally dangerous activity.

ARTICLE 9. AUTOMATED ENFORCEMENT SYSTEMS

YARBIS may utilize automated systems, AI-enabled moderation systems, fraud-detection systems, behavioral analytics, anomaly-detection systems, abuse-prevention systems, cybersecurity tooling, or algorithmic enforcement systems to support platform governance and operational integrity.

 Automated systems may result in temporary restrictions, delayed access, content quarantining, account reviews, authentication challenges, or enforcement actions.

 Subscriber acknowledges that automated systems may not always operate perfectly and may require human review, escalation, or correction.

ARTICLE 10. PLATFORM GOVERNANCE RESERVATION

YARBIS reserves the right to modify, update, supplement, enhance, suspend, replace, or evolve moderation procedures, governance controls, abuse-detection methodologies, AI-governance controls, security systems, platform rules, operational restrictions, or enforcement practices as reasonably necessary to:

(a) address evolving threats;

(b) comply with legal obligations;

(c) support operational resiliency;

(d) improve cybersecurity posture;

(e) address abuse patterns;

(f) comply with regulatory expectations;

(g) maintain platform integrity.

ARTICLE 11. NO LIABILITY FOR MODERATION ACTIVITIES

To the fullest extent permitted by applicable law, YARBIS shall not be liable for good-faith moderation decisions, enforcement activities, content restrictions, account suspensions, removals, quarantines, investigations, escalations, abuse-prevention measures, fraud-prevention actions, or platform-governance decisions undertaken pursuant to this Policy.

 Subscriber acknowledges that moderation and enforcement decisions may involve operational judgment, security considerations, legal considerations, automated systems, incomplete information, evolving threats, or time-sensitive risk assessments. 

ARTICLE 1. PURPOSE & GOVERNANCE OBJECTIVES

This Charter establishes the governance, compliance-management, operational-risk, cybersecurity-governance, AI-governance, vendor-governance, legal-oversight, and escalation-management framework applicable to the YARBIS Enterprise Legal Framework and associated operational systems.

 The objectives of this Charter include:

(a) establishing governance accountability;

(b) supporting enterprise operational maturity;

(c) supporting defensible compliance governance;

(d) supporting cybersecurity oversight;

(e) supporting AI-governance controls;

(f) supporting vendor-risk governance;

(g) supporting litigation defensibility;

(h) supporting regulatory readiness;

(i) supporting institutional lender and enterprise onboarding requirements.

ARTICLE 2. GOVERNANCE STRUCTURE

YARBIS may establish governance functions, committees, officers, managers, advisors, consultants, or operational designees responsible for overseeing legal compliance, cybersecurity, privacy operations, AI governance, vendor governance, operational resiliency, and enterprise risk management.

 Governance responsibilities may include:

(a) policy approval;

(b) compliance oversight;

(c) operational escalation;

(d) incident governance;

(e) audit coordination;

(f) vendor review;

(g) AI governance review;

(h) sanctions compliance review;

(i) legal-risk review;

(j) cybersecurity oversight.

 Governance responsibilities may be assigned internally or through external consultants, managed-service providers, legal counsel, or specialized compliance advisors.

ARTICLE 3. COMPLIANCE AUTHORITY & RESPONSIBILITY

YARBIS may designate personnel, advisors, consultants, service providers, or governance leads responsible for:

(a) legal compliance;

(b) privacy governance;

(c) cybersecurity oversight;

(d) AI-governance administration;

(e) sanctions compliance;

(f) vendor-management oversight;

(g) incident-response coordination;

(h) operational resiliency management;

(i) records-retention governance;

(j) litigation-hold administration.

 

Assigned personnel or governance leads may possess authority to recommend, implement, escalate, review, suspend, restrict, or coordinate compliance-related operational measures reasonably necessary to support legal, regulatory, cybersecurity, operational, or governance objectives.

ARTICLE 4. ENTERPRISE RISK MANAGEMENT

YARBIS may implement commercially reasonable enterprise risk-management procedures intended to identify, assess, prioritize, monitor, mitigate, document, escalate, and review operational, cybersecurity, legal, AI-governance, privacy, sanctions, vendor-management, infrastructure, fraud, and regulatory risks.

 

Risk-management activities may include:

(a) risk assessments;

(b) vendor-risk reviews;

(c) security assessments;

(d) compliance audits;

(e) AI-governance reviews;

(f) infrastructure reviews;

(g) operational resiliency reviews;

(h) incident simulations;

(i) governance reviews;

(j) remediation tracking.

 

Risk prioritization may consider likelihood, severity, operational impact, legal exposure, reputational impact, regulatory exposure, and infrastructure criticality.

ARTICLE 5. CYBERSECURITY GOVERNANCE

YARBIS may maintain cybersecurity governance procedures intended to support confidentiality, integrity, availability, resiliency, operational continuity, incident response, fraud prevention, infrastructure protection, and regulatory compliance.

 

Cybersecurity governance measures may include:

(a) access controls;

(b) logging systems;

(c) encryption controls;

(d) vulnerability management;

(e) penetration testing;

(f) security monitoring;

(g) endpoint protection;

(h) backup procedures;

(i) disaster-recovery planning;

(j) incident-response procedures.

 

Cybersecurity governance procedures may evolve periodically in response to operational requirements, cybersecurity developments, regulatory guidance, or emerging threats.

ARTICLE 6. AI GOVERNANCE & MODEL OVERSIGHT

YARBIS may implement AI-governance procedures intended to support responsible operational use of AI-enabled systems, workflow automation systems, scoring systems, classification systems, orchestration systems, and machine-learning functionalities.

 

AI-governance activities may include:

(a) human-review checkpoints;

(b) model documentation;

(c) hallucination monitoring;

(d) output review procedures;

(e) model-change tracking;

(f) operational validation procedures;

(g) bias-review procedures;

(h) AI incident escalation procedures;

(i) audit logging;

(j) AI-governance reviews.

 

YARBIS does not guarantee that AI-enabled systems will operate error-free, bias-free, uninterrupted, or fully compliant with evolving regulatory interpretations.

ARTICLE 7. VENDOR & SUBPROCESSOR GOVERNANCE

YARBIS may maintain governance procedures relating to subprocessors, vendors, cloud providers, infrastructure providers, messaging providers, AI providers, security providers, payment providers, and other operational service providers.

 

Vendor-governance activities may include:

(a) vendor due diligence;

(b) contractual reviews;

(c) DPA reviews;

(d) sanctions screening;

(e) security reviews;

(f) operational reviews;

(g) business-continuity reviews;

(h) vendor-risk reassessments;

(i) incident coordination procedures.

 

ARTICLE 8. INCIDENT ESCALATION & GOVERNANCE

YARBIS may establish operational escalation procedures for cybersecurity incidents, data breaches, sanctions concerns, operational disruptions, infrastructure failures, fraud events, intellectual-property disputes, AI incidents, vendor incidents, litigation holds, or regulatory inquiries.

 

Escalation procedures may include:

(a) severity classifications;

(b) response coordination;

(c) preservation procedures;

(d) legal review procedures;

(e) notification procedures;

(f) remediation coordination;

(g) operational containment measures;

(h) executive escalation procedures.

ARTICLE 9. TRAINING & AWARENESS

YARBIS may conduct commercially reasonable training, awareness, onboarding, operational-guidance, governance-review, cybersecurity-awareness, privacy-awareness, sanctions-awareness, or AI-governance training activities for personnel, contractors, consultants, or operational administrators as reasonably necessary to support enterprise governance objectives.

ARTICLE 10. AUDIT, REVIEW & DOCUMENTATION

10.1 Governance Documentation & Operational Records

YARBIS may maintain governance records, audit documentation, remediation records, incident records, policy archives, governance reviews, operational evidence, compliance mappings, security documentation, testing summaries, access-control records, training records, vendor oversight documentation, AI governance records, and related materials reasonably necessary to support operational governance, enterprise onboarding, legal defensibility, cybersecurity reviews, internal risk management, insurance requirements, or regulatory readiness activities.

 

Governance records may be retained pursuant to operational retention procedures, litigation holds, regulatory requirements, contractual obligations, insurance obligations, internal governance practices, or compliance-related operational needs.

10.2 No Regulatory Audit Certification

YARBIS does not represent, warrant, or certify that any governance documentation, operational review, compliance mapping, audit record, assessment activity, security review, policy review, or internal governance process satisfies all legal, regulatory, supervisory, licensing, examination, underwriting, investor, banking, cybersecurity, privacy, AI-governance, or compliance requirements applicable to Subscriber.

 

No internal governance activity performed by YARBIS shall be interpreted as:

(a) a legal opinion;

(b) a regulatory certification;

(c) an independent audit opinion;

(d) a SOC certification guarantee;

(e) a cybersecurity certification;

(f) a compliance attestation;

(g) a supervisory approval;

(h) a guarantee of examination readiness.

10.3 Subscriber Audit Responsibility

Subscriber remains solely responsible for:

(a) conducting its own legal reviews;

(b) obtaining independent compliance assessments;

(c) performing regulatory gap analyses;

(d) maintaining records required under Applicable Law;

(e) responding to governmental examinations;

(f) satisfying investor due diligence requests;

(g) conducting independent cybersecurity reviews;

(h) validating regulatory retention obligations;

(i) maintaining required licensing documentation;

(j) performing internal audit procedures appropriate for Subscriber’s regulated operations.

 

Subscriber acknowledges that YARBIS operates as a technology provider and not as Subscriber’s auditor, compliance officer, supervisory authority, law firm, cybersecurity assessor, examination consultant, or regulated financial institution.

10.4 Regulatory Cooperation Reservation

YARBIS may cooperate with commercially reasonable Subscriber audit requests, investor diligence requests, regulatory inquiries, supervisory examinations, or security questionnaires, subject to:

(a) confidentiality restrictions;

(b) privilege protections;

(c) operational feasibility;

(d) security limitations;

(e) reimbursement of extraordinary costs;

(f) protection of proprietary information;

(g) third-party confidentiality obligations;

(h) cybersecurity risk considerations.

 

Nothing herein obligates YARBIS to disclose:

(i) privileged materials;

(ii) proprietary AI systems;

(iii) source code;

(iv) penetration testing results;

(v) confidential security architecture;

(vi) trade secrets;

(vii) third-party confidential information;

(viii) internal legal analyses.

ARTICLE 11. DOCUMENT VERSION CONTROL

YARBIS may periodically revise, supplement, replace, enhance, retire, consolidate, or update Enterprise Legal Framework documents, governance policies, operational procedures, or compliance controls.

 

Material revisions may include:

(a) effective dates;

(b) version identifiers;

(c) change summaries;

(d) responsible reviewers;

(e) implementation status;

(f) dependency tracking.

ARTICLE 12. REGULATORY & LEGAL MONITORING

YARBIS may monitor evolving laws, regulations, regulatory guidance, enforcement trends, litigation developments, cybersecurity developments, privacy developments, sanctions developments, AI-governance developments, and industry standards relevant to the Services and operational environment.

 

Governance procedures may be updated periodically in response to evolving legal, operational, cybersecurity, or regulatory developments.

ARTICLE 13. NO GUARANTEE OF REGULATORY IMMUNITY

Implementation of governance procedures, compliance measures, operational safeguards, AI-governance controls, cybersecurity procedures, vendor-management procedures, or legal frameworks does not guarantee immunity from litigation, cybersecurity incidents, operational failures, regulatory inquiry, governmental investigation, evolving legal interpretations, or enforcement actions.

 

The governance framework is intended to materially reduce legal, operational, cybersecurity, and regulatory risk exposure using commercially reasonable enterprise governance practices.

ARTICLE 14. GOVERNANCE RESERVATION

YARBIS reserves the right to evolve, modify, enhance, replace, suspend, supplement, consolidate, or operationalize governance procedures, compliance controls, cybersecurity measures, AI-governance procedures, operational safeguards, or risk-management methodologies as reasonably necessary to support operational resiliency, enterprise governance, cybersecurity integrity, legal compliance, fraud prevention, or evolving regulatory obligations.


 

ARTICLE 1. PURPOSE & INTERPRETIVE SCOPE

This Legal Notice, Interpretation, Enforceability & Severability Framework ("Interpretation Framework") governs the interpretation, construction, hierarchy, enforceability, survivability, and operational integration of the Enterprise Legal Framework ("ELF") and all related agreements, policies, appendices, schedules, disclosures, operational notices, governance documents, onboarding records, acknowledgments, clickwrap flows, and incorporated materials issued by YARBIS.

 This Interpretation Framework is intended to:

(a) establish interpretive consistency;

(b) reduce ambiguity risk;

(c) support contractual enforceability;

(d) support arbitration survivability;

(e) reduce cross-document conflicts;

(f) support enterprise governance consistency;

(g) support operational scalability;

(h) support litigation defensibility.

ARTICLE 2. DOCUMENT HIERARCHY & ORDER OF PRECEDENCE

Unless expressly stated otherwise in a specific written agreement executed by authorized representatives of both parties, the following order of precedence shall govern in the event of conflict, inconsistency, ambiguity, overlap, or interpretive dispute among Enterprise Legal Framework documents:

(1) executed enterprise order forms or negotiated enterprise amendments;

(2) Master SaaS Agreement (Document 1);

(3) Binding Arbitration Agreement (Document 10);

(4) Data Processing Addendum (Document 2);

(5) AI Governance Policy & Liability Framework (Document 3);

(6) Information Security Policy (Document 4);

(7) Consumer & Business Privacy Policy (Document 6);

(8) Incident Response & Breach Notification Framework (Document 7);

(9) Force Majeure & Business Continuity Clause (Document 9);

(10) Export Controls, OFAC & Sanctions Policy (Document 14);

(11) DMCA & Intellectual Property Policy (Document 15);

(12) Acceptable Use Policy (Document 5);

(13) Electronic Signature & ESIGN Compliance Disclosure (Document 12);

(14) SMS / WhatsApp / TCPA Consent Framework (Document 13);

(15) Subprocessor Disclosure Schedule (Document 8);

(16) Regulatory Retention Matrix (Document 11);

(17) Corporate Compliance, Governance & Risk Management Charter (Document 17);

(18) appendices, schedules, operational notices, onboarding disclosures, implementation records, and supporting governance materials.

 Specific provisions expressly governing regulated subject matter shall control over generalized provisions relating to the same subject matter.

ARTICLE 3. INCORPORATION BY REFERENCE

All Enterprise Legal Framework documents referenced, linked, incorporated, attached, presented through onboarding flows, acknowledged electronically, delivered operationally, or otherwise made available by YARBIS are incorporated by reference into the governing contractual relationship to the maximum extent permitted under applicable law.

 Subscriber acknowledges that operational policies, governance procedures, onboarding disclosures, acceptable-use restrictions, privacy notices, arbitration provisions, AI-governance procedures, and cybersecurity procedures may collectively govern platform use and operational interactions.

ARTICLE 4. INTERPRETIVE PRINCIPLES

The Enterprise Legal Framework shall be interpreted:

(a) as a commercially negotiated enterprise technology framework;

(b) consistent with commercially reasonable SaaS governance practices;

(c) consistent with operational scalability principles;

(d) consistent with applicable financial-services regulatory expectations;

(e) consistent with enterprise cybersecurity governance standards;

(f) consistent with commercially reasonable AI-governance principles;

(g) in a manner intended to preserve enforceability where reasonably possible.

 The parties acknowledge that the Enterprise Legal Framework is intended to allocate risk proportionately within a commercial business relationship and should not be interpreted using presumptions applicable exclusively to consumer adhesion agreements where not otherwise required by applicable law.

ARTICLE 5. SEVERABILITY

If any provision, clause, sentence, limitation, waiver, exclusion, disclaimer, arbitration term, remedy limitation, or operational restriction contained within the Enterprise Legal Framework is determined by a court, arbitrator, regulatory authority, or tribunal of competent jurisdiction to be invalid, unenforceable, unlawful, unconscionable, or otherwise defective under applicable law, such provision shall be modified, limited, construed, or severed only to the minimum extent necessary to preserve the maximum permissible enforceability of the remaining provisions.

 The remaining provisions of the Enterprise Legal Framework shall remain in full force and effect to the maximum extent permitted by applicable law.

ARTICLE 6. SURVIVAL

Any provisions which by their nature reasonably should survive suspension, expiration, termination, cancellation, operational discontinuation, or expiration of the contractual relationship shall survive, including but not limited to:

(a) confidentiality obligations;

(b) intellectual-property protections;

(c) indemnification obligations;

(d) arbitration obligations;

(e) liability limitations;

(f) records-retention obligations;

(g) audit rights;

(h) sanctions compliance obligations;

(i) payment obligations accrued prior to termination;

(j) dispute-resolution obligations;

(k) data-deletion obligations;

(l) legal-hold obligations.

ARTICLE 7. NO WAIVER

Failure by YARBIS to enforce any provision, restriction, limitation, requirement, governance control, operational procedure, compliance measure, or contractual right shall not constitute a waiver of such provision or any future enforcement right.

 Any waiver must be expressly documented in writing by an authorized representative of YARBIS.

ARTICLE 8. REGULATORY EVOLUTION & FUTURE LAW

The parties acknowledge that laws, regulations, regulatory guidance, enforcement priorities, cybersecurity standards, AI-governance requirements, privacy frameworks, sanctions requirements, financial-services regulations, and operational expectations may evolve over time.

 YARBIS reserves the right to modify, supplement, replace, revise, operationalize, or update Enterprise Legal Framework documents, governance controls, operational safeguards, or compliance procedures as reasonably necessary to address evolving legal, regulatory, operational, cybersecurity, or infrastructure requirements.

ARTICLE 9. CONSTRUCTION AGAINST DRAFTER WAIVER

To the maximum extent permitted by applicable law, the parties acknowledge that the Enterprise Legal Framework shall not be construed presumptively against YARBIS solely because YARBIS participated in drafting, preparing, structuring, organizing, or operationalizing the governing documentation.

 The parties further acknowledge that the Enterprise Legal Framework reflects a commercially negotiated enterprise governance structure intended to allocate risk proportionately between sophisticated commercial parties.

ARTICLE 10. ELECTRONIC RECORD ENFORCEABILITY

Electronic acknowledgments, clickwrap acceptances, electronic signatures, onboarding confirmations, digital assent mechanisms, authentication records, audit logs, system timestamps, cryptographic verification records, and electronic transaction records maintained by YARBIS may constitute legally admissible evidence of assent, authorization, delivery, acknowledgment, notice, acceptance, or agreement formation to the maximum extent permitted by applicable law.

ARTICLE 11. HEADINGS & ORGANIZATIONAL REFERENCES

Headings, titles, labels, organizational references, numbering conventions, article captions, table references, and descriptive summaries are included solely for organizational convenience and shall not independently modify, expand, restrict, or interpret substantive contractual obligations unless expressly stated otherwise.

ARTICLE 12. GOOD-FAITH OPERATIONAL INTERPRETATION

The parties acknowledge that certain operational, technical, cybersecurity, AI-governance, infrastructure, or compliance-related provisions may require commercially reasonable operational interpretation in light of evolving technologies, operational requirements, regulatory expectations, and cybersecurity conditions.

Operational implementation decisions made in good faith for purposes of security, compliance, fraud prevention, operational resiliency, legal compliance, infrastructure integrity, or enterprise governance shall be interpreted consistent with commercially reasonable enterprise operational practices.

ARTICLE 13. THIRD-PARTY BENEFICIARY DISCLAIMER

Except where expressly required by applicable law or expressly stated otherwise in a written agreement executed by authorized representatives of YARBIS, the Enterprise Legal Framework is intended solely for the contractual relationship between YARBIS and the applicable Subscriber.

 No third party shall possess independent beneficiary rights, enforcement rights, reliance rights, or implied contractual rights arising from the Enterprise Legal Framework.

ARTICLE 14. ENTIRE AGREEMENT FRAMEWORK

The Enterprise Legal Framework, together with applicable order forms, incorporated documents, enterprise amendments, onboarding acknowledgments, disclosures, operational notices, and incorporated policies, constitutes the entire agreement framework governing the relationship between YARBIS and Subscriber regarding the Services and supersedes prior or contemporaneous oral or written understandings relating to the same subject matter.

 No oral representations, informal communications, sales statements, marketing descriptions, or generalized operational discussions shall independently modify the governing contractual framework unless expressly incorporated into a written agreement executed by authorized representatives of both parties.

ARTICLE 15. RESERVATION OF DEFENSIVE INTERPRETATION RIGHTS

YARBIS expressly reserves the right to assert any contractual defense, statutory defense, equitable defense, arbitration defense, limitation-of-liability defense, evidentiary defense, jurisdictional defense, procedural defense, regulatory defense, or operational defense available under applicable law.

 Nothing within the Enterprise Legal Framework shall be interpreted as a waiver of defenses except where expressly and unequivocally stated in writing.

 ARTICLE 16. EFFECTIVE DATES & VERSION GOVERNANCE

16.1 Effective Date Control

Each document comprising the YARBIS Enterprise Legal Framework ("ELF") shall become effective on the effective date identified within the applicable document, amendment notice, Subscriber onboarding flow, click-through acceptance mechanism, enterprise order form, executed amendment, or other legally sufficient assent mechanism utilized by YARBIS.

 Where multiple effective dates may apply, the most recent validly adopted version governing the applicable subject matter shall control unless otherwise expressly stated in writing.

16.2 Version Control & Amendment Governance

YARBIS reserves the right to modify, amend, supplement, consolidate, replace, retire, restate, reorganize, or operationally update any portion of the Enterprise Legal Framework where commercially reasonable or operationally necessary to address:

(a) evolving legal requirements;

(b) regulatory developments;

(c) cybersecurity risks;

(d) operational changes;

(e) infrastructure modifications;

(f) AI-governance developments;

(g) platform functionality changes;

(h) enterprise compliance requirements;

(i) litigation-risk mitigation; or

(j) business continuity considerations.

 Material modifications shall become effective following commercially reasonable notice procedures, including electronic publication, onboarding disclosures, click-through acknowledgment mechanisms, contractual amendment notices, platform notifications, email communications, or updated effective-date publication.

16.3 Archived Version Preservation

YARBIS may maintain archived historical versions of Enterprise Legal Framework documents for purposes including:

(a) evidentiary preservation;

(b) dispute resolution;

(c) litigation defense;

(d) regulatory response;

(e) audit support;

(f) operational governance;

(g) enterprise diligence;

(h) forensic review; and

(i) compliance documentation.

 Archived versions may be maintained electronically and need not remain publicly accessible following supersession or retirement.

16.4 Subscriber Responsibility to Review Updates

Subscriber acknowledges responsibility for periodically reviewing updated versions of the Enterprise Legal Framework, including all incorporated policies, disclosures, governance documents, appendices, and operational compliance frameworks.

Continued access to or use of the YARBIS platform following implementation of updated framework provisions may constitute acceptance of such revisions to the extent permitted under applicable law.

16.5 Conflict Between Historical Versions

In the event of conflict between historical versions of Enterprise Legal Framework documents, the version in effect at the time of the applicable transaction, dispute, operational event, data-processing activity, or platform interaction shall control unless superseded by mandatory applicable law or express written agreement.

ARTICLE 17. CROSS-DOCUMENT LEGAL HOLD PRIORITY

17.1 Legal Hold Supremacy

Notwithstanding any deletion schedule, purge protocol, retention limitation, backup rotation policy, archival limitation, anonymization workflow, de-identification process, operational deletion mechanism, or data lifecycle management provision contained within the Enterprise Legal Framework, YARBIS may suspend deletion, destruction, anonymization, or modification of relevant records where reasonably necessary to comply with:

(a) litigation hold obligations;

(b) preservation duties;

(c) court orders;

(d) subpoenas;

(e) regulatory investigations;

(f) law enforcement requests;

(g) arbitration preservation obligations;

(h) cybersecurity investigations;

(i) fraud investigations; or

(j) other legally binding preservation requirements.

17.2 Cross-Document Preservation Authority

Legal hold obligations and preservation directives shall supersede any inconsistent provision contained within:

(a) the Master SaaS Agreement;

(b) the Data Processing Addendum;

(c) the Incident Response Framework;

(d) the Regulatory Retention Matrix;

(e) the Privacy Policy;

(f) the AI Governance Framework;

(g) the Information Security Policy; or

(h) any other incorporated governance document comprising the Enterprise Legal Framework.

17.3 Preservation Scope

Preservation obligations may apply to:

(a) subscriber records;

(b) audit logs;

(c) AI governance records;

(d) access logs;

(e) cybersecurity investigation materials;

(f) communication records;

(g) transactional metadata;

(h) authentication records;

(i) backup archives;

(j) incident response documentation;

(k) governance records; and

(l) operational system data reasonably relevant to the applicable preservation obligation.

17.4 No Waiver of Privilege

Nothing within this Framework shall require YARBIS to waive attorney-client privilege, attorney work-product protection, cybersecurity investigative privilege, trade-secret protections, confidential security procedures, or other legally recognized protections applicable to preserved materials.

17.5 Commercially Reasonable Preservation Limitations

YARBIS shall implement commercially reasonable preservation measures consistent with operational feasibility, infrastructure capabilities, proportionality principles, cybersecurity considerations, and the scope of the applicable preservation obligation.

 Nothing herein shall require technically impossible restoration efforts, disproportionate forensic reconstruction, perpetual preservation of all operational records, or extraordinary preservation measures beyond commercially reasonable and legally required standards.

ARTICLE 1. PURPOSE & INTERPRETIVE SCOPE

1.1 Interpretive Purpose

This Definitions & Interpretive Terminology Framework ("Definitions Framework") establishes the controlling definitions, interpretive standards, terminology harmonization rules, and construction principles applicable to the entire YARBIS Enterprise Legal Framework ("ELF").

 This Definitions Framework shall apply to and govern all documents incorporated into the ELF unless a specific document expressly provides an alternative definition applicable solely within that document.

1.2 Hierarchical Authority

In the event of ambiguity, conflict, inconsistency, interpretive overlap, or definitional dispute between this Definitions Framework and another ELF document, this Definitions Framework shall control unless:

(a) the conflicting document expressly states that its definition supersedes this Framework for a specific purpose; or

(b) mandatory applicable law requires a different interpretation.

1.3 Commercially Reasonable Interpretation Standard

All provisions within the ELF shall be interpreted according to commercially reasonable enterprise SaaS, cybersecurity, fintech, AI-governance, and regulated-data operational standards rather than hyper-technical, isolated, disproportionate, punitive, or commercially impractical interpretations.

ARTICLE 2. CORE DEFINITIONS

2.1 “YARBIS”

"YARBIS" means YARBIS, Inc., together with its affiliates, subsidiaries, contractors, successors, assigns, service providers, authorized personnel, infrastructure operators, and operational representatives acting within the scope of authorized platform operations.

2.2 “Subscriber”

"Subscriber" means the legal entity, lender, mortgage broker, enterprise customer, business organization, or authorized user entity accessing or utilizing the YARBIS platform pursuant to the applicable agreement, onboarding flow, enterprise order form, or authorized access mechanism.

2.3 “Platform”

"Platform" means the YARBIS software environment, APIs, interfaces, AI-assisted systems, infrastructure, dashboards, workflows, operational systems, communications systems, analytical tools, integrations, databases, security architecture, hosted services, and related technology components made available by YARBIS.

2.4 “Subscriber Data”

"Subscriber Data" means information, documents, files, records, consumer information, loan-related information, metadata, communications, uploaded materials, or other data submitted, transmitted, uploaded, processed, stored, or made available by Subscriber through the Platform.

2.5 “De-Identified Data”

"De-Identified Data" means data processed in a manner reasonably designed to prevent identification of an individual consumer, borrower, or natural person consistent with commercially reasonable de-identification methodologies, applicable privacy laws, and operational safeguards.

2.6 “AI Output”

"AI Output" means any recommendation, prediction, score, classification, prioritization, workflow suggestion, analysis, communication assistance, generated content, inferred result, automated insight, or probabilistic analytical result generated in whole or in part through AI-assisted functionality within the Platform.

2.7 “Security Incident”

"Security Incident" means an actual confirmed unauthorized access to, acquisition of, disclosure of, destruction of, compromise of, or material interference with Subscriber Data, Platform systems, operational integrity, or regulated information maintained within the Platform.

 Security Incident shall not include unsuccessful intrusion attempts, blocked scans, unsuccessful phishing attempts, denied connection attempts, isolated malware detections without material compromise, or other events that do not result in confirmed unauthorized compromise.

2.8 “Confidential Information”

"Confidential Information" means non-public information disclosed by either party that is designated as confidential or that reasonably should be understood to be confidential based upon the nature of the information and surrounding circumstances, including trade secrets, security procedures, source code, operational documentation, business plans, pricing information, consumer information, proprietary workflows, AI governance materials, and technical architecture.

2.9 “Force Majeure Event”

"Force Majeure Event" means any event beyond the commercially reasonable control of the affected party, including cybersecurity attacks, infrastructure failures, internet outages, cloud-service interruptions, natural disasters, labor disputes, war, terrorism, governmental actions, utility failures, telecommunications failures, supply-chain disruptions, pandemics, civil unrest, sanctions restrictions, or failures of third-party infrastructure providers.

2.10 “Applicable Law”

"Applicable Law" means all federal, state, local, international, administrative, regulatory, supervisory, judicial, and governmental laws, regulations, rules, ordinances, directives, consent orders, agency guidance, enforcement standards, and legally binding obligations applicable to the relevant party or operational activity.

ARTICLE 3. AI & CYBERSECURITY DEFINITIONS

3.1 “Human Review”

"Human Review" means commercially reasonable review, validation, oversight, escalation, approval, rejection, or intervention performed by an authorized human operator before or after reliance upon AI-assisted outputs.

3.2 “Model Drift”

"Model Drift" means degradation, deviation, recalibration, evolution, or altered performance characteristics of AI or machine-learning systems over time resulting from operational, statistical, infrastructural, data-related, environmental, or technical factors.

3.3 “Commercially Reasonable Security Measures”

"Commercially Reasonable Security Measures" means technical, administrative, organizational, operational, and cybersecurity safeguards reasonably appropriate for a similarly situated enterprise SaaS provider operating within comparable industries, threat environments, infrastructure scales, and regulatory contexts.

3.4 “Operational Metadata”

"Operational Metadata" means system-generated technical information associated with Platform operation, including timestamps, authentication logs, routing information, infrastructure telemetry, API activity, workflow events, audit records, security events, and usage analytics.

ARTICLE 4. INTERPRETIVE PRINCIPLES

4.1 No Strict Construction Against Drafter

The parties expressly waive application of any doctrine requiring strict construction against the drafter, including contra proferentem, to the maximum extent permitted under applicable law.

4.2 Headings for Convenience Only

Headings, titles, numbering structures, captions, and organizational references are included solely for convenience and shall not independently alter substantive interpretation.

4.3 Singular & Plural

Words used in the singular include the plural and vice versa where commercially reasonable and contextually appropriate.

4.4 Including / Includes

The terms "including," "includes," and similar phrases shall mean "including without limitation."

4.5 Regulatory Evolution

References to statutes, regulations, frameworks, industry standards, or regulatory guidance shall include amendments, successor regulations, revised interpretations, replacement frameworks, and evolving supervisory expectations unless context clearly requires otherwise.

ARTICLE 5. NO ABSOLUTE WARRANTIES OR GUARANTEES

5.1 Commercial Reasonableness Standard

Unless expressly stated otherwise in a separately executed written agreement, no provision within the ELF shall be interpreted as creating guarantees of:

(a) uninterrupted availability;

(b) absolute cybersecurity;

(c) perfect AI accuracy;

(d) regulatory immunity;

(e) error-free operation;

(f) exhaustive fraud prevention;

(g) complete compliance assurance; or

(h) technically impossible outcomes.

5.2 Operational Limitations Recognition

The parties acknowledge that enterprise SaaS environments, AI systems, cybersecurity infrastructure, cloud platforms, and regulated operational systems inherently involve technical limitations, infrastructure dependencies, evolving threat environments, operational constraints, third-party dependencies, and probabilistic risks that cannot be completely eliminated.

ARTICLE 6. SURVIVAL & ENFORCEABILITY

6.1 Survival

This Definitions Framework shall survive termination, suspension, expiration, migration, or discontinuation of the Platform to the extent reasonably necessary to support interpretation, dispute resolution, regulatory response, litigation defense, preservation obligations, audit review, or enforcement of surviving obligations.

6.2 Severability

If any provision within this Definitions Framework is determined unenforceable, invalid, or unlawful, the remaining provisions shall remain enforceable to the maximum extent permitted under applicable law.

1.1 Governance Purpose

This Regulatory Communications, Government Requests & Legal Process Policy ("Regulatory Policy") establishes the governance framework applicable to governmental inquiries, supervisory examinations, subpoenas, civil investigative demands, law-enforcement requests, regulatory communications, legal process handling, and official information requests directed to YARBIS in connection with operation of the Platform.

 This Policy is intended to support commercially reasonable regulatory-response governance, preservation obligations, legal-process handling procedures, cybersecurity investigation coordination, and enterprise compliance management consistent with applicable law.

1.2 Scope of Application

This Policy applies to all governmental, regulatory, supervisory, judicial, administrative, arbitral, law-enforcement, investigatory, or legally compelled requests relating to:

(a) Subscriber Data;

(b) operational records;

(c) AI governance records;

(d) audit logs;

(e) cybersecurity incidents;

(f) authentication records;

(g) communications records;

(h) transactional metadata;

(i) infrastructure records;

(j) compliance documentation; and

(k) Platform operational activities.

ARTICLE 2. GOVERNMENT REQUEST RESPONSE AUTHORITY

2.1 Legal Process Evaluation

YARBIS reserves the right to evaluate, review, validate, challenge, narrow, reject, escalate, comply with, or respond to any governmental request, subpoena, court order, civil investigative demand, administrative inquiry, arbitration order, law-enforcement request, regulatory inquiry, preservation request, or legally compelled disclosure obligation based upon:

(a) legal sufficiency;

(b) jurisdictional authority;

(c) authenticity verification;

(d) scope proportionality;

(e) preservation obligations;

(f) privilege protections;

(g) confidentiality obligations;

(h) cybersecurity risks;

(i) operational feasibility; and

(j) applicable law.

2.2 No Obligation to Voluntarily Disclose

Except where required by applicable law, binding legal process, emergency disclosure authority, or valid regulatory obligation, YARBIS shall have no obligation to voluntarily disclose Subscriber information, operational records, confidential business information, AI governance records, cybersecurity materials, trade secrets, or proprietary operational information to governmental or third-party entities.

2.3 Preservation & Litigation Hold Authority

YARBIS may suspend deletion, anonymization, destruction, purge schedules, retention limitations, or operational deletion workflows where reasonably necessary to comply with preservation obligations associated with:

(a) litigation;

(b) arbitration;

(c) regulatory examinations;

(d) subpoenas;

(e) governmental investigations;

(f) cybersecurity investigations;

(g) fraud investigations; or

(h) legally binding preservation obligations.

ARTICLE 3. SUBSCRIBER NOTIFICATION PROCEDURES

3.1 Notification Reservation

Unless prohibited by applicable law, court order, regulatory directive, emergency disclosure authority, law-enforcement restriction, preservation order, confidentiality obligation, or investigatory requirement, YARBIS may use commercially reasonable efforts to notify affected Subscribers regarding governmental requests seeking disclosure of Subscriber-related information.

3.2 Delayed Notification

YARBIS reserves the right to delay, restrict, condition, or withhold Subscriber notification where YARBIS reasonably determines that notification may:

(a) violate applicable law;

(b) interfere with investigations;

(c) create cybersecurity risks;

(d) compromise law-enforcement activities;

(e) violate confidentiality obligations;

(f) create fraud risks; or

(g) expose operational security procedures.

ARTICLE 4. REGULATORY EXAMINATIONS & SUPERVISORY COOPERATION

4.1 Regulatory Cooperation

YARBIS may cooperate with commercially reasonable lawful requests from applicable governmental authorities, financial-services regulators, supervisory agencies, data-protection authorities, cybersecurity agencies, consumer-protection authorities, or law-enforcement entities to the extent required under applicable law.

4.2 No Regulatory Partnership

Nothing within this Policy shall be interpreted as creating:

(a) a delegated regulatory relationship;

(b) an agency relationship;

(c) supervisory authority;

(d) fiduciary obligations;

(e) governmental partnership status; or

(f) regulatory responsibility transfer between YARBIS and any governmental authority.

4.3 Examination Materials Reservation

Regulatory examination materials, audit responses, supervisory correspondence, cybersecurity assessments, internal governance materials, privileged analyses, legal memoranda, operational remediation plans, and compliance investigation records may constitute confidential, privileged, proprietary, or protected materials and may be withheld, redacted, restricted, or protected to the maximum extent permitted under applicable law.

4.4 Regulatory Cooperation Reservation

Any cooperation, communication, coordination, disclosure, preservation activity, examination participation, or informational exchange conducted by YARBIS with any governmental authority, regulator, supervisory body, law enforcement authority, investor, auditor, or administrative agency shall not:

(a) create a fiduciary duty;

(b) establish a supervisory relationship;

(c) constitute assumption of Subscriber regulatory obligations;

(d) constitute legal, regulatory, underwriting, or compliance certification;

(e) create agency authority;

(f) create joint enterprise liability; or

(g) constitute endorsement of Subscriber operational practices or compliance status.

 

YARBIS reserves the right to cooperate with governmental authorities in a commercially reasonable manner while maintaining its independent status as a technology provider.

ARTICLE 5. EMERGENCY DISCLOSURE AUTHORITY

5.1 Emergency Circumstances

YARBIS may disclose information without prior notice where YARBIS reasonably determines disclosure is necessary to:

(a) prevent imminent harm;

(b) respond to cybersecurity threats;

(c) address fraud events;

(d) comply with emergency disclosure laws;

(e) preserve operational integrity;

(f) protect Platform security;

(g) mitigate criminal activity; or

(h) comply with legally authorized emergency governmental requests.

5.2 Good-Faith Reliance

YARBIS may rely in good faith upon the apparent validity of court orders, subpoenas, warrants, preservation requests, emergency disclosure requests, governmental certifications, or law-enforcement directives reasonably believed to be legally authorized.

ARTICLE 6. CROSS-BORDER REGULATORY REQUESTS

6.1 Jurisdictional Review

YARBIS reserves the right to evaluate cross-border governmental requests, foreign subpoenas, international data-access demands, foreign regulatory directives, and extraterritorial disclosure requests based upon applicable jurisdictional limitations, data-protection laws, sanctions restrictions, international transfer obligations, sovereignty concerns, and conflict-of-law principles.

6.2 International Disclosure Restrictions

YARBIS may refuse, narrow, challenge, delay, condition, or seek clarification regarding international governmental disclosure requests where compliance may reasonably create conflicts with:

(a) privacy laws;

(b) sanctions laws;

(c) export controls;

(d) cybersecurity obligations;

(e) contractual confidentiality duties;

(f) legal privilege protections; or

(g) cross-border transfer restrictions.

ARTICLE 7. COST RECOVERY & ADMINISTRATIVE BURDEN

7.1 Extraordinary Request Costs

Where legally permissible, YARBIS reserves the right to recover commercially reasonable costs associated with responding to extraordinary governmental requests, subpoenas, discovery demands, preservation obligations, forensic retrieval efforts, large-scale document production requests, expedited compliance demands, or disproportionate administrative burdens imposed by Subscriber-related investigations or proceedings.

7.2 No Obligation for Disproportionate Efforts

Nothing within this Policy shall require YARBIS to perform technically impossible reconstruction, disproportionate forensic recovery, exhaustive archival restoration, perpetual preservation, extraordinary engineering work, or commercially unreasonable compliance efforts beyond those required under applicable law.

ARTICLE 8. NO LEGAL ADVICE OR COMPLIANCE GUARANTEE

8.1 No Legal Advice

Nothing within this Policy constitutes legal advice, regulatory advice, compliance certification, supervisory assurance, or governmental approval regarding Subscriber operations, lending activities, consumer communications, AI governance practices, cybersecurity obligations, or regulatory responsibilities.

8.2 No Guarantee of Regulatory Outcome

YARBIS does not guarantee that any regulatory authority, governmental agency, supervisory body, arbitrator, court, or law-enforcement authority will accept Subscriber's operational practices, compliance posture, lending activities, AI governance controls, cybersecurity measures, or regulatory interpretations.

ARTICLE 9. SURVIVAL & ENFORCEABILITY

9.1 Survival

This Policy shall survive termination, suspension, expiration, migration, discontinuation, or cessation of Platform services to the extent reasonably necessary to support regulatory response obligations, litigation defense, arbitration proceedings, preservation obligations, audit requirements, cybersecurity investigations, or legal-process compliance.

9.2 Severability

If any provision within this Policy is determined unenforceable, invalid, or unlawful, the remaining provisions shall remain enforceable to the maximum extent permitted under applicable law.

ARTICLE 1. PURPOSE & GOVERNANCE SCOPE

1.1 Governance Purpose

This Third-Party Integrations, APIs & External Services Policy ("Integration Policy") establishes the governance framework applicable to third-party integrations, APIs, external platforms, cloud providers, messaging providers, AI infrastructure providers, authentication systems, webhook systems, external data processors, and interconnected services utilized in connection with operation of the YARBIS Platform.

1.2 Scope of Application

This Policy applies to:

(a) APIs;

(b) external integrations;

(c) cloud infrastructure services;

(d) AI/ML infrastructure providers;

(e) authentication providers;

(f) messaging providers;

(g) LOS integrations;

(h) CRM integrations;

(i) payment processors;

(j) webhook systems;

(k) external databases;

(l) analytics services;

(m) communication services;

(n) third-party software dependencies; and

(o) interconnected operational systems.

ARTICLE 2. THIRD-PARTY SERVICES DISCLAIMER

2.1 External Service Dependency

The Platform may depend upon third-party infrastructure, software, APIs, telecommunications providers, hosting services, authentication systems, cloud services, messaging networks, artificial intelligence infrastructure, payment processors, internet providers, and external operational systems not owned or directly controlled by YARBIS.

2.2 No Responsibility for Third-Party Services

YARBIS does not control and shall not be responsible for the availability, legality, security, performance, uptime, interoperability, operational continuity, regulatory compliance, acts, omissions, or failures of third-party providers except to the extent non-waivable liability is imposed under applicable law.

2.3 Third-Party Terms Applicability

Subscriber acknowledges that use of certain Platform functionality may be subject to additional third-party agreements, API restrictions, infrastructure-provider terms, telecommunications rules, AI-provider restrictions, payment-network requirements, or external service policies imposed by third-party providers.

ARTICLE 3. API ACCESS & USAGE GOVERNANCE

3.1 Authorized API Usage

Subscribers may access YARBIS APIs solely through authorized credentials, approved authentication methods, documented interfaces, commercially reasonable rate limits, and operational parameters approved by YARBIS.

3.2 Prohibited API Activities

Subscriber shall not:

(a) abuse API rate limits;

(b) circumvent authentication controls;

(c) scrape Platform systems;

(d) conduct denial-of-service activities;

(e) attempt unauthorized data extraction;

(f) interfere with operational integrity;

(g) reverse engineer APIs;

(h) bypass usage limitations;

(i) exploit undocumented endpoints; or

(j) use APIs for unlawful, fraudulent, competitive-intelligence, or prohibited operational activities.

3.3 API Modification Reservation

YARBIS reserves the right to modify, suspend, restrict, replace, discontinue, throttle, version, deprecate, or terminate APIs, integrations, authentication methods, webhook structures, technical specifications, or interoperability mechanisms at any time for operational, cybersecurity, legal, regulatory, or commercial reasons.

ARTICLE 4. THIRD-PARTY AI & EXTERNAL MODEL PROVIDERS

4.1 External AI Infrastructure

Certain AI-assisted functionality may utilize third-party AI infrastructure providers, hosted model environments, inference systems, OCR systems, machine-learning infrastructure, language-model systems, or cloud-based AI processing environments.

4.2 No Public AI Training Authorization

Subscriber Data, regulated information, mortgage records, confidential information, or non-public operational data shall not be intentionally disclosed by YARBIS to public generalized AI training environments except where expressly authorized by Subscriber or required for operational functionality disclosed under applicable agreements.

4.3 AI Provider Operational Dependency

AI-assisted functionality may be affected by third-party provider limitations, inference latency, external infrastructure failures, model updates, service interruptions, token limitations, regional restrictions, API changes, cybersecurity events, or operational modifications imposed by external AI providers.

ARTICLE 5. SECURITY & CYBERSECURITY BOUNDARIES

5.1 Shared Responsibility Model

Cybersecurity within integrated environments constitutes a shared-responsibility model involving YARBIS, Subscribers, cloud providers, infrastructure vendors, authentication providers, telecommunications providers, external software providers, and other interconnected operational participants.

5.2 External Vulnerability Exposure

YARBIS shall not be responsible for vulnerabilities, exploits, breaches, outages, credential compromise, operational failures, malware events, API abuse, or unauthorized access arising from:

(a) Subscriber systems;

(b) third-party integrations;

(c) external applications;

(d) insecure Subscriber configurations;

(e) compromised Subscriber credentials;

(f) external vendor failures;

(g) inherited third-party vulnerabilities; or

(h) operational misuse outside the Platform security boundary.

5.3 Integration Suspension Authority

YARBIS reserves the right to suspend, restrict, disconnect, disable, quarantine, throttle, revoke, or terminate integrations, APIs, credentials, webhooks, or external connectivity mechanisms where commercially reasonable to protect operational integrity, cybersecurity, regulatory compliance, infrastructure stability, or Platform security.

ARTICLE 6. WEBHOOKS, AUTOMATION & DATA ROUTING

6.1 Webhook Risks

Subscriber acknowledges that webhook systems, automation systems, middleware environments, external routing systems, automation platforms, and integration workflows inherently involve transmission risks, dependency risks, delivery failures, timing inconsistencies, operational interruptions, and third-party infrastructure dependencies.

6.2 Subscriber Configuration Responsibility

Subscriber bears sole responsibility for:

(a) external integration configurations;

(b) API credential security;

(c) webhook endpoint security;

(d) routing logic;

(e) external automation logic;

(f) third-party workflow controls;

(g) downstream operational decisions; and

(h) validation of externally routed data.

ARTICLE 7. DATA TRANSFERS & EXTERNAL PROCESSING

7.1 Cross-System Processing

Subscriber acknowledges that Platform functionality may involve transmission, routing, caching, temporary processing, logging, redundancy operations, infrastructure balancing, or operational handling across interconnected systems and third-party infrastructure environments.

7.2 International Infrastructure Reservation

Certain infrastructure providers, telecommunications providers, AI providers, CDN systems, cloud providers, or external operational systems may involve geographically distributed infrastructure environments subject to applicable data-transfer disclosures, subprocessors schedules, or applicable privacy frameworks.

ARTICLE 8. THIRD-PARTY OUTAGES & FORCE MAJEURE INTERDEPENDENCY

8.1 External Dependency Failures

Third-party infrastructure failures, API outages, telecommunications interruptions, cloud-service disruptions, authentication-provider failures, AI-provider outages, internet failures, utility disruptions, or interconnected service interruptions may affect Platform functionality and may constitute Force Majeure Events under applicable agreements.

8.2 No Guaranteed Interoperability

YARBIS does not guarantee uninterrupted interoperability, perpetual compatibility, or continuous operational synchronization between the Platform and third-party systems, integrations, APIs, external applications, or infrastructure providers.

ARTICLE 9. COMPLIANCE & REGULATORY RESERVATIONS

9.1 Subscriber Compliance Responsibility

Subscriber remains solely responsible for ensuring that its use of third-party integrations, APIs, automations, external messaging systems, AI-assisted systems, and interconnected operational workflows complies with applicable law, licensing obligations, regulatory requirements, consumer-protection laws, privacy laws, financial-services regulations, sanctions laws, and cybersecurity obligations.

9.2 No Certification of Third-Party Compliance

YARBIS does not certify, warrant, guarantee, or represent that any third-party provider, API provider, cloud provider, telecommunications provider, AI provider, or external service provider complies with Subscriber-specific regulatory, operational, legal, cybersecurity, or enterprise governance requirements.

ARTICLE 10. LIMITATION OF LIABILITY FOR EXTERNAL SERVICES

10.1 Third-Party Service Limitation

To the maximum extent permitted under applicable law, YARBIS shall not be liable for damages, losses, claims, penalties, operational interruptions, regulatory exposure, business losses, data delays, interoperability failures, or cybersecurity events caused in whole or in part by third-party integrations, APIs, infrastructure providers, external systems, telecommunications providers, cloud vendors, or external operational dependencies.

10.2 No Guarantee of External Service Availability

YARBIS does not guarantee the availability, continuity, uptime, operational integrity, latency, response times, routing accuracy, compatibility, security, or operational performance of third-party services or infrastructure providers.

ARTICLE 11. SURVIVAL & ENFORCEABILITY

11.1 Survival

This Policy shall survive termination, suspension, expiration, migration, discontinuation, or cessation of Platform services to the extent reasonably necessary to support cybersecurity investigations, regulatory obligations, litigation defense, audit review, preservation obligations, operational disputes, or enforcement of surviving contractual provisions.

11.2 Severability

If any provision within this Policy is determined unenforceable, invalid, or unlawful, the remaining provisions shall remain enforceable to the maximum extent permitted under applicable law.

ARTICLE 1. PURPOSE, GOVERNANCE SCOPE & ENTERPRISE POSITIONING

1.1 Governance Purpose

This Enterprise Operational, Regulatory, Security & Platform Reliance Framework (“Framework”) establishes the operational boundaries, risk allocation architecture, enterprise governance principles, and platform-use limitations applicable to all use of the YARBIS platform and related services.

 This Framework is intended to:

(a) clarify the nature of YARBIS’s role as a technology provider;

(b) define the allocation of operational, regulatory, underwriting, cybersecurity, and compliance responsibilities;

(c) establish enterprise-grade governance expectations for Subscribers;

(d) define platform availability and operational limitation standards;

(e) allocate responsibility for third-party infrastructure dependencies;

(f) establish legally defensible cybersecurity limitation language; and

(g) reinforce the separation between software enablement and regulated lending activity.

1.2 Enterprise Software Classification

YARBIS operates solely as:

(a) a software-as-a-service (SaaS) platform provider;

(b) a mortgage workflow intelligence platform;

(c) a data-processing and analytical technology provider;

(d) an AI-assisted operational support platform; and

(e) a decision-support infrastructure provider.

 

YARBIS does not operate as:

(a) a lender;

(b) a mortgage broker;

(c) a loan originator;

(d) a depository institution;

(e) a bank;

(f) an underwriting authority;

(g) a financial advisor;

(h) a law firm;

(i) a compliance consulting firm;

(j) a fiduciary;

(k) a consumer reporting agency;

(l) a credit repair organization; or

(m) a governmental or regulatory authority.

1.3 No Delegation of Regulated Obligations

Use of the YARBIS platform does not transfer, delegate, reduce, or replace any legal, regulatory, licensing, underwriting, servicing, disclosure, or compliance obligations imposed upon Subscribers under applicable law.

 Subscribers remain solely responsible for all regulated business activities conducted through or in connection with the platform.

 ARTICLE 2. REGULATED ENTITY RESPONSIBILITY ALLOCATION

2.1 Subscriber Regulatory Responsibility

Subscriber retains sole responsibility for:

(a) mortgage licensing compliance;

(b) underwriting decisions;

(c) loan approvals and denials;

(d) adverse action notices;

(e) ECOA compliance;

(f) FCRA compliance;

(g) HMDA compliance;

(h) RESPA compliance;

(i) TILA/TRID compliance;

(j) fair lending compliance;

(k) servicing compliance;

(l) AML/KYC obligations;

(m) OFAC screening obligations;

(n) investor overlays;

(o) warehouse lending requirements;

(p) secondary-market eligibility determinations; and

(q) all legally required consumer disclosures.

2.2 No Guarantee of Loan Approval or Investor Acceptance

Use of YARBIS does not guarantee:

(a) mortgage approval;

(b) underwriting success;

(c) AUS approval;

(d) pricing eligibility;

(e) investor acceptance;

(f) secondary-market saleability;

(g) warehouse lender acceptance;

(h) fair lending compliance;

(i) regulatory approval;

(j) servicing transfer eligibility; or

(k) any particular business, financial, operational, or lending outcome.

2.3 Subscriber Validation Obligations

Subscribers are solely responsible for independently reviewing, validating, confirming, and approving:

(a) AI outputs;

(b) borrower evaluations;

(c) risk classifications;

(d) loan recommendations;

(e) operational workflows;

(f) document completeness;

(g) regulatory disclosures; and

(h) all final lending decisions.

2.4 No Reliance on Platform Outputs

Subscriber acknowledges and agrees that the Platform, including any AI Outputs, automated workflows, alerts, recommendations, scoring systems, compliance indicators, risk classifications, operational automations, integrations, or analytical features, is provided solely as a supplemental enterprise technology tool and not as a substitute for independent professional, legal, underwriting, compliance, lending, financial, operational, cybersecurity, or regulatory judgment.

 Subscriber further acknowledges that it does not and shall not rely exclusively upon the Platform or any AI Output when making:

(a) lending decisions;

(b) underwriting determinations;

(c) consumer eligibility determinations;

(d) regulatory compliance decisions;

(e) disclosure obligations;

(f) fraud determinations;

(g) risk assessments;

(h) investor-related determinations; or

(i) operational or supervisory decisions.

 Subscriber remains solely responsible for independently validating all outputs, workflows, automations, recommendations, and operational results generated through the Platform.

 YARBIS expressly disclaims any duty to independently verify the legal, regulatory, factual, underwriting, financial, or operational accuracy of Subscriber decisions derived from use of the Platform.

ARTICLE 3. SERVICE AVAILABILITY, OPERATIONAL LIMITATIONS & PLATFORM DEPENDENCIES

3.1 No Guaranteed Availability

Unless expressly stated in a separately executed written enterprise service-level agreement signed by authorized representatives of YARBIS, the platform is provided on a commercially reasonable availability basis only.

 YARBIS does not guarantee:

(a) uninterrupted availability;

(b) continuous uptime;

(c) error-free operation;

(d) uninterrupted AI functionality;

(e) real-time delivery of communications;

(f) compatibility with all third-party systems;

(g) uninterrupted API access; or

(h) permanent feature availability.

3.2 Maintenance & Operational Suspension

YARBIS reserves the right to:

(a) perform scheduled maintenance;

(b) implement emergency maintenance;

(c) suspend services for cybersecurity purposes;

(d) restrict platform access during incidents;

(e) throttle usage;

(f) modify APIs;

(g) disable features;

(h) rotate infrastructure providers; or

(i) temporarily suspend functionality for operational, legal, regulatory, or security reasons.

3.3 Beta Features & Experimental Systems

Certain platform features, AI systems, automations, analytics modules, or integrations may be designated as beta, preview, experimental, or limited-release functionality.

 Such functionality may contain defects, inaccuracies, interruptions, or operational instability and is provided without any guarantee of production readiness.

3.4 Third-Party Infrastructure Dependency

Platform functionality may depend upon third-party:

 (a) cloud providers;

(b) AI infrastructure providers;

(c) telecommunications carriers;

(d) API vendors;

(e) hosting providers;

(f) email infrastructure;

(g) SMS delivery providers;

(h) WhatsApp infrastructure;

(i) DNS services;

(j) payment processors; and

(k) cybersecurity vendors.

 YARBIS is not responsible for failures caused by external infrastructure providers beyond YARBIS’s commercially reasonable operational control.

 ARTICLE 4. ENTERPRISE CUSTOMER SECURITY SHARED RESPONSIBILITY MODEL

4.1 Shared Responsibility Structure

Cybersecurity is a shared responsibility between YARBIS and Subscriber.

 Subscriber acknowledges that the security of Subscriber systems, personnel, devices, credentials, and operational environments materially affects platform security outcomes.

4.2 Subscriber Security Responsibilities

Subscriber remains solely responsible for:

(a) endpoint security;

(b) employee security training;

(c) phishing prevention;

(d) password governance;

(e) credential rotation;

(f) API credential protection;

(g) access termination procedures;

(h) administrator account governance;

(i) device management;

(j) internal network security;

(k) browser security;

(l) email account compromise prevention;

(m) webhook configuration;

(n) integration security;

(o) vendor access governance; and

(p) employee misconduct prevention.

4.3 Compromised Credentials & Social Engineering

YARBIS shall not be responsible for losses arising from:

(a) compromised Subscriber credentials;

(b) phishing attacks;

(c) business email compromise;

(d) social engineering;

(e) SIM swap attacks;

(f) credential reuse;

(g) endpoint malware;

(h) insider misuse; or

(i) unauthorized access resulting from Subscriber-controlled systems or personnel.

 ARTICLE 5. EMPLOYEE, ADMINISTRATOR & INSIDER MISUSE

5.1 Insider Threat Recognition

Subscriber acknowledges that cybersecurity incidents may arise from:

(a) employee misconduct;

(b) contractor misconduct;

(c) privileged administrator misuse;

(d) negligent credential handling;

(e) insider fraud;

(f) unauthorized data extraction; or

(g) compromised privileged accounts.

5.2 Administrative Access Responsibility

Subscriber bears sole responsibility for managing:

(a) internal administrative privileges;

(b) employee role assignments;

(c) offboarding procedures;

(d) privileged access review;

(e) credential revocation; and

(f) internal monitoring of Subscriber personnel.

5.3 YARBIS Administrative Safeguards

YARBIS may implement commercially reasonable:

(a) privilege restrictions;

(b) audit logging;

(c) access segmentation;

(d) authentication controls;

(e) anomaly detection systems; and

(f) administrative monitoring procedures.

 Nothing herein guarantees prevention of all insider-related events.

ARTICLE 6. DATA CLASSIFICATION & INFORMATION GOVERNANCE

6.1 Data Classification Categories

YARBIS may classify information into categories including:

(a) Public Information;

(b) Internal Information;

(c) Confidential Information;

(d) Restricted Non-Public Information (“NPI”);

(e) Regulated Consumer Data; and

(f) Security-Sensitive Information.

6.2 Subscriber Responsibility for Data Classification

Subscriber remains solely responsible for:

(a) determining applicable legal classifications;

(b) identifying regulated information;

(c) restricting unauthorized disclosures;

(d) implementing internal access controls; and

(e) complying with applicable privacy and financial regulations.

6.3 No Guarantee of Classification Sufficiency

Data classification systems represent operational governance tools only and do not guarantee regulatory sufficiency, legal privilege preservation, or immunity from unauthorized disclosure.

ARTICLE 7. CYBERSECURITY SAFE HARBOR & EVOLVING THREAT ENVIRONMENT

7.1 No Absolute Cybersecurity Guarantee

No cybersecurity framework, safeguard, monitoring system, infrastructure environment, or security control can guarantee prevention, detection, mitigation, or elimination of all cyber events.

7.2 Evolving Threat Environment

Subscriber acknowledges that cyber threats continuously evolve and may include:

(a) ransomware;

(b) zero-day exploits;

(c) AI-assisted attacks;

(d) insider threats;

(e) nation-state attacks;

(f) credential compromise;

(g) supply-chain attacks;

(h) cloud infrastructure attacks; and

(i) social engineering schemes.

7.3 Commercially Reasonable Security Standard

YARBIS implements commercially reasonable safeguards appropriate to the nature of the platform and operational environment but does not warrant that the platform will be immune from all cybersecurity incidents.

7.4 No Warranty of Detection or Prevention

YARBIS does not warrant:

(a) detection of every threat;

(b) prevention of every intrusion;

(c) uninterrupted monitoring;

(d) immediate incident identification; or

(e) complete elimination of operational risk.

ARTICLE 8. AI TRAINING DATA, MODEL EVOLUTION & OUTPUT VARIABILITY

8.1 AI Model Evolution

AI systems may evolve over time through:

(a) model updates;

(b) infrastructure modifications;

(c) parameter tuning;

(d) prompt engineering changes;

(e) third-party model changes;

(f) retrieval architecture modifications; or

(g) operational optimization.

 Accordingly, outputs may vary over time.

8.2 No Deterministic Consistency Guarantee

YARBIS does not guarantee that identical prompts, inputs, workflows, or operational conditions will always produce identical outputs.

8.3 Third-Party AI Infrastructure

Certain AI functionality may depend upon third-party infrastructure providers or model vendors.

 YARBIS does not control all aspects of third-party AI model architecture, training methodology, infrastructure operations, or service continuity.

8.4 No Authorization for External AI Training

Except as expressly authorized in writing, Subscriber shall not use YARBIS content, outputs, workflows, interfaces, documentation, or proprietary materials to train external AI systems, machine-learning systems, or competing technologies.

 ARTICLE 9. SURVIVAL MATRIX

9.1 Survival of Obligations

The following obligations survive termination, suspension, expiration, or discontinuation of platform access:

(a) confidentiality obligations;

(b) intellectual property protections;

(c) indemnification obligations;

(d) arbitration obligations;

(e) payment obligations;

(f) preservation obligations;

(g) audit rights;

(h) limitation of liability provisions;

(i) cybersecurity cooperation obligations;

(j) regulatory cooperation obligations;

(k) legal hold obligations; and

(l) dispute-resolution provisions.

9.2 Survival Duration

Surviving obligations remain enforceable for the period permitted under applicable law or for so long as reasonably necessary to protect legitimate legal, operational, regulatory, evidentiary, or commercial interests.

ARTICLE 10. CENTRALIZED LEGAL NOTICE & REGULATORY CONTACT FRAMEWORK

10.1 Official Legal Contact Channels

YARBIS may designate official communication channels for:

(a) legal notices;

(b) arbitration notices;

(c) DMCA notices;

(d) privacy requests;

(e) security incident reporting;

(f) subpoena responses;

(g) governmental requests;

(h) regulatory examinations;

(i) OFAC inquiries;

(j) consumer rights requests; and

(k) litigation hold notices.

10.2 Subscriber Responsibility

Subscriber bears sole responsibility for:

 (a) maintaining current contact information;

(b) monitoring designated legal communication channels;

(c) promptly responding to official notices; and

(d) ensuring authorized personnel can receive compliance-related communications.

10.3 Electronic Notice Validity

To the maximum extent permitted by applicable law, notices delivered electronically through designated channels may constitute legally effective notice.

ARTICLE 11. BOARD-LEVEL CORPORATE SEPARATION & GOVERNANCE POSITIONING

11.1 Technology Provider Separation

YARBIS maintains operational and governance separation between:

(a) technology enablement functions; and

(b) regulated lending decision-making activities conducted by Subscribers.

11.2 No Lending Authority

YARBIS does not:

(a) originate loans;

(b) approve loans;

(c) deny loans;

(d) issue adverse action notices;

(e) establish underwriting criteria for Subscribers; or

(f) act as a creditor under applicable lending laws.

11.3 Enterprise Governance Intent

The governance architecture of YARBIS is designed to support operational defensibility, enterprise risk management, and commercially reasonable compliance practices without assuming regulated financial-institution status.

11.4 No Banking, Brokerage, Credit Decisioning, or Consumer Reporting Agency Status

YARBIS is not a bank;

not a mortgage lender;

not a broker;

not a credit repair organization;

not a CRA under FCRA;

not a fiduciary;

not an underwriting authority;

not acting as agent of subscriber borrowers.

ARTICLE 12. SURVIVAL & ENFORCEABILITY

12.1 Survival

This Framework survives termination of the Subscriber relationship to the extent necessary to enforce legal rights, preserve evidence, allocate liability, or comply with applicable law.

12.2 Severability

If any provision of this Framework is determined unenforceable, the remaining provisions remain in full force and effect to the maximum extent permitted by applicable law.

ARTICLE 1. GOVERNANCE PURPOSE

This Appendix constitutes an internal legal-governance, remediation-tracking, litigation-defensibility, and compliance-management framework intended to document identified legal risks, remediation activities, governance controls, operational dependencies, and implementation status associated with the Enterprise Legal Framework.

Risk ID

Original Defect

Risk Category

Severity

Legal / Regulatory Exposure

Remediation Applied

Residual Risk After Remediation

Dependent Documents

Responsible Owner

Validation Requirement

Regulatory Mapping

Status

LR-001

“Unrestricted right” to terminate

Unconscionability / Arbitrary enforcement

High

Contract invalidation

Replaced with commercially reasonable termination language

Low

MSA

Legal

Annual legal review

UCC / State contract law

Implemented

LR-002

Undefined liquidated damages

Penalty clause invalidation

High

Voidability risk

Replaced with administrative-cost framework

Low

MSA

Legal + Finance

Contract review

UCC

Implemented

LR-003

“Beyond technical possibility of recovery”

Misrepresentation / deceptive practices

High

FTC / cyberlitigation

Replaced with commercially reasonable deletion protocols

Low

MSA + DPA

Legal + Security

Security audit

FTC / GLBA

Implemented

LR-004

No retention carve-out

Spoliation / CFPB exposure

Critical

Regulatory sanctions

Added retention governance & legal hold language

Medium

MSA + Doc 11

Legal + Compliance

Annual retention audit

CFPB / GLBA

Implemented

LR-005

No consequential damages carve-outs

Limitation-of-liability invalidation

Critical

Unlimited damages exposure

Added gross negligence & willful misconduct carve-outs

Medium

MSA

Legal

Contract audit

UCC

Implemented

LR-006

No indemnification procedures

Unenforceable indemnity

High

Defense-cost exposure

Added notice & defense-control procedures

Low

MSA

Legal

Litigation audit

Contract law

Implemented

LR-007

“100% non-refundable”

Consumer-protection exposure

Medium

AG enforcement

Added applicable-law qualifier

Low

MSA

Legal

State-law review

CA / NY consumer law

Implemented

LR-008

Chargeback waiver language

Card-network noncompliance

High

Payment processor disputes

Replaced with bad-faith chargeback language

Low

MSA

Finance + Legal

Payments audit

Visa / Mastercard rules

Implemented

LR-009

Unilateral arbitration

Arbitration invalidation

Critical

FAA enforceability risk

Full bilateral arbitration rewrite

Medium

Doc 10

Legal

Arbitration review

FAA

Implemented

LR-010

No delegation clause

Court-side arbitrability litigation

High

Forum disputes

Added delegation clause

Low

Doc 10

Legal

Arbitration audit

FAA

Implemented

LR-011

No breach framework

GLBA violation exposure

Critical

Regulatory penalties

Created incident-response framework

Medium

Doc 7

Security + Compliance

Incident-response testing

GLBA / FTC

Implemented

LR-012

“Military-grade” security claims

Misrepresentation litigation

Critical

FTC deceptive-practices risk

Replaced with commercially reasonable safeguards

Low

Doc 4

Legal + Security

Marketing/legal review

FTC

Implemented

LR-013

No state privacy framework

State privacy violations

Critical

Multi-state enforcement

Added multi-state privacy rights

Medium

Doc 6

Privacy Counsel

Annual privacy audit

CCPA / CPRA / CPA / VCDPA

Implemented

LR-014

No subprocessor disclosure

Enterprise procurement failure

High

Vendor-management rejection

Created subprocessor schedule

Low

Doc 8

Compliance

Vendor audit

GDPR / enterprise procurement

Implemented

LR-015

No AI governance framework

AI litigation exposure

Critical

Hallucination liability

Created AI governance framework

Medium

Doc 3

AI Governance Lead

AI audit

EU AI Act

Implemented

LR-016

No force majeure protections

Infrastructure breach liability

High

SLA disputes

Added BCP & force majeure framework

Low

Doc 9

Operations + Legal

BCP testing

Contract law

Implemented

LR-017

No AUP

Abuse / fraud exposure

High

Fraud & sanctions exposure

Created Acceptable Use Policy

Medium

Doc 5

Compliance

Abuse monitoring

OFAC / fraud compliance

Implemented

LR-018

No export-control framework

EAR / OFAC violations

Critical

Federal enforcement

Created sanctions & export-control framework

Medium

Doc 14

Compliance

Annual sanctions audit

EAR / OFAC

Implemented

LR-019

No DMCA protections

IP enforcement weakness

High

IP litigation exposure

Created DMCA & IP framework

Medium

Doc 15

Legal

IP audit

DMCA / Copyright Act

Implemented

LR-020

Perpetual metadata license

Privacy & ownership conflict

High

Privacy litigation

Limited de-identified metadata license

Low

MSA

Legal + Privacy

Data-governance review

Privacy law

Implemented

LR-021

No content-governance framework

UGC liability exposure

Critical

Section 230 & moderation exposure

Created moderation & UGC governance policy

Medium

Doc 16

Compliance + Trust & Safety

Governance audit

CDA §230 / DMCA

Implemented

LR-022

No repeat-infringer policy

DMCA safe harbor weakness

Critical

Loss of §512 protection

Added repeat-infringer framework

Low

Doc 15 + Doc 16

Legal

DMCA audit

DMCA §512

Implemented

LR-023

No AI training restrictions

AI/IP contamination exposure

Critical

Model contamination litigation

Added AI-training prohibitions

Medium

Doc 15

AI Governance Lead

AI governance audit

EU AI Act / IP law

Implemented

ARTICLE 2. NO GUARANTEE OF ABSOLUTE COMPLIANCE

Implementation of remediation measures, governance controls, contractual protections, compliance frameworks, or operational safeguards does not guarantee immunity from litigation, regulatory inquiry, enforcement activity, cybersecurity incidents, contractual disputes, operational failures, or evolving legal interpretations.

The Enterprise Legal Framework is intended to materially reduce legal and operational risk exposure using commercially reasonable governance practices consistent with enterprise SaaS, fintech, AI-governance, and regulated-data industry standards.

ARTICLE 3. PERIODIC LEGAL REVIEW

YARBIS may periodically review, update, supplement, revise, replace, or enhance the Enterprise Legal Framework, remediation controls, governance procedures, operational safeguards, compliance mappings, and associated legal documentation in response to:

(a) evolving law;

(b) regulatory guidance;

(c) judicial developments;

(d) cybersecurity threats;

(e) AI-governance developments;

(f) operational changes;

(g) infrastructure changes;

(h) litigation trends.

ARTICLE 1. PURPOSE & GOVERNANCE SCOPE

This Appendix establishes the operational implementation, governance, compliance activation, risk-management, audit-readiness, and deployment roadmap associated with the Enterprise Legal Framework.

The roadmap is intended to support enterprise operational maturity, defensible compliance governance, cybersecurity preparedness, AI-governance controls, vendor-management readiness, and institutional onboarding requirements applicable to regulated financial-services environments.

Phase

Governance Objective

Required Actions

Responsible Owner

Validation Requirement

Deliverables

Target Timeline

Residual Risk if Delayed

Phase 1 — Legal Finalization

Establish enforceable legal baseline

Retain external counsel; complete all placeholders; finalize governing law; finalize arbitration venue; finalize named subprocessors; finalize sanctions architecture; finalize DMCA registration

Legal Counsel

Legal review certification

Executed ELF v1.0

0–30 days

Critical

Phase 2 — Contractual Integration

Integrate enforceable disclosures into platform UX

Deploy clickwrap flows; integrate T&C, DPA, Privacy Policy, ESIGN Consent, AUP, TCPA disclosures; implement acknowledgment logging

Product + Legal + Engineering

UX/legal audit

Enforceable onboarding architecture

30–60 days

Critical

Phase 3 — Security Governance Activation

Operationalize cybersecurity governance

Appoint security lead/CISO; implement WISP; establish incident-response procedures; establish escalation matrix; configure audit logging

Security + Compliance

Security governance audit

Operational security program

30–60 days

Critical

Phase 4 — Regulatory Compliance Activation

Implement privacy & financial compliance controls

Build DSAR intake workflows; map regulated data flows; audit subprocessors; establish retention governance; deploy legal-hold procedures

Privacy Counsel + Compliance

Compliance audit

Multi-state privacy governance

60–120 days

High

Phase 5 — AI Governance Operationalization

Establish defensible AI governance

Implement HITL review checkpoints; create model documentation; implement AI audit logging; establish hallucination review procedures; establish AI change management

AI Governance Lead

AI governance review

AI governance framework

60–120 days

Critical

Phase 6 — Vendor & Infrastructure Governance

Establish third-party governance controls

Conduct vendor risk assessments; review cloud providers; review DPAs; validate sanctions compliance; validate infrastructure redundancy

Compliance + Security

Vendor audit

Vendor governance program

60–120 days

High

Phase 7 — Operational Readiness Testing

Validate operational resilience

Conduct tabletop incident simulations; breach simulations; ransomware response testing; arbitration workflow testing; legal hold testing

Security + Legal + Operations

Simulation reports

Operational readiness validation

90–150 days

High

Phase 8 — Documentation & Evidence Governance

Establish defensible audit posture

Create compliance evidence repository; retention schedules; governance archives; policy versioning system

Compliance + Legal

Governance audit

Evidence preservation architecture

90–150 days

High

Phase 9 — Enterprise Readiness Certification

Prepare for institutional onboarding

Conduct internal legal audit; security audit; AI governance review; procurement readiness review; SOC readiness review

Executive Compliance Committee

Readiness certification

Enterprise onboarding readiness

120–180 days

Critical

Phase 10 — Ongoing Governance & Monitoring

Maintain continuous compliance posture

Annual reviews; regulatory monitoring; sanctions review; AI governance updates; incident-response testing; privacy-law updates

Compliance + Legal + Security

Annual governance review

Continuous governance lifecycle

Ongoing

Medium

ARTICLE 2. COMPLIANCE OWNERSHIP & ESCALATION

YARBIS should establish internal governance ownership for legal compliance, cybersecurity, AI governance, privacy operations, vendor management, incident response, and operational risk management.

Material incidents, regulatory inquiries, cybersecurity events, sanctions concerns, data breaches, litigation holds, or material governance failures should be escalated through documented operational escalation procedures.

ARTICLE 3. PERIODIC TESTING REQUIREMENTS

YARBIS should periodically conduct operational testing, including:

(a) cybersecurity tabletop exercises;

(b) breach-notification simulations;

(c) ransomware-response simulations;

(d) legal-hold validation testing;

(e) disaster-recovery testing;

(f) backup restoration testing;

(g) AI-governance review exercises;

(h) vendor-risk reassessments.

Testing activities should be documented and retained pursuant to applicable governance and retention procedures.

ARTICLE 4. DOCUMENT VERSION GOVERNANCE

YARBIS should maintain version-control procedures for all Enterprise Legal Framework documents, governance policies, compliance records, operational procedures, audit artifacts, and regulatory mappings.

Material revisions should be documented with:

(a) revision dates;

(b) responsible reviewers;

(c) change summaries;

(d) legal rationale;

(e) implementation status;

(f) dependency tracking.

ARTICLE 5. NO GUARANTEE OF ABSOLUTE COMPLIANCE

Implementation of the Enterprise Legal Framework and associated governance procedures does not guarantee immunity from litigation, cybersecurity incidents, operational failures, regulatory inquiry, enforcement actions, evolving legal interpretations, or emerging regulatory obligations.

The roadmap is intended to materially improve operational maturity and reduce legal and regulatory exposure using commercially reasonable enterprise governance practices.

The Enterprise Legal Framework ("ELF") has been architected to materially improve the contractual defensibility, operational governance posture, regulatory readiness, cybersecurity governance posture, AI-governance posture, vendor-management maturity, and enterprise deployment readiness of YARBIS within a regulated mortgage-technology and financial-services operational environment.

The ELF is intended to establish a commercially reasonable, litigation-conscious, operationally scalable, and institutionally defensible governance framework designed to reduce material legal, operational, cybersecurity, privacy, sanctions, intellectual-property, AI-governance, and regulatory risk exposure associated with enterprise SaaS deployment.

The framework incorporates governance principles intended to align with commercially reasonable enterprise practices relevant to:

(a) regulated financial-services operations;

(b) mortgage-technology environments;

(c) GLBA-regulated operational contexts;

(d) enterprise SaaS governance expectations;

(e) AI-enabled operational systems;

(f) cybersecurity governance expectations;

(g) vendor-management governance;

(h) enterprise procurement review standards;

(i) institutional due-diligence expectations.

The framework further reflects a deliberate replacement of excessive contractual absolutism with commercially reasonable standards intended to improve judicial defensibility, enforceability posture, arbitration survivability, operational scalability, and regulatory credibility.

The ELF is not intended to guarantee immunity from:

(i) litigation;

(ii) cybersecurity incidents;

(iii) regulatory inquiry;

(iv) governmental investigations;

(v) operational failures;

(vi) evolving legal interpretations;

(vii) AI-governance developments;

(viii) privacy-law developments;

(ix) sanctions developments;

(x) infrastructure disruptions.

The effectiveness of the ELF materially depends upon:

(1) proper implementation;

(2) operational enforcement;

(3) governance oversight;

(4) infrastructure security;

(5) policy maintenance;

(6) incident-response maturity;

(7) vendor-management procedures;

(8) legal review;

(9) periodic updates;

(10) ongoing compliance operations.The following implementation items remain mandatory prior to production deployment and institutional onboarding readiness:

• Governing-law selection and arbitration seat must be finalized in consultation with qualified litigation counsel.

• DMCA Designated Agent registration must be completed with the United States Copyright Office.

• Privacy-rights intake infrastructure and monitored compliance contact channels must be operationalized.

• Effective dates, implementation notices, version histories, and deployment records must be finalized and retained.

• Named subprocessors, vendor classifications, and vendor-governance records must be finalized and periodically reviewed.

• Enterprise Subscriber onboarding workflows, acknowledgment logging, DPA execution workflows, and consent-record systems must be operationalized.

• AI-governance controls, human-review checkpoints, audit logging, and model-governance procedures must be operationalized prior to deployment of AI-enabled production workflows.

• Incident-response escalation procedures, legal-hold procedures, evidence-preservation controls, and breach-notification procedures must be operationalized and periodically tested.

• Governance ownership responsibilities, escalation procedures, and compliance-management functions must be assigned and documented.The ELF should be periodically reviewed and updated in response to:

(A) evolving law;

(B) regulatory guidance;

(C) judicial developments;

(D) cybersecurity developments;

(E) AI-governance developments;

(F) operational changes;

(G) infrastructure modifications;

(H) enforcement trends;

(I) vendor changes;

(J) enterprise risk-management developments.

The ELF should be reviewed periodically by qualified legal counsel familiar with:

• SaaS transactions;

• enterprise technology contracting;

• cybersecurity governance;

• financial-services regulation;

• AI-governance frameworks;

• privacy compliance;

• arbitration enforceability;

• sanctions compliance;

• regulated operational environments.

 Implementation of the ELF materially improves YARBIS's legal defensibility, enterprise readiness posture, operational governance maturity, cybersecurity defensibility posture, AI-governance readiness, and institutional onboarding readiness when compared against conventional early-stage SaaS legal architectures lacking integrated governance controls.