Skip to main content
Blue Ridge FederalBuilt for government contractors
Business line: (917) 412-1478sales@blue-ridge-federal.com
  • Solutions & Capabilities
  • Pricing
  • Demo
  • Security
  • Company
  • Client sign in
System Notice: Assessment databases are actively synced with current NDAA, FCC, and Consolidated Screening List rulings.
Home / Terms of Service

Blue Ridge Federal LLC

Terms of Service

Effective October 8, 2026 · Version 2026-10-08

These Terms govern account creation, authorized use, purchases, and services provided by Blue Ridge Federal LLC. Read them before accepting or ordering services. A separately executed agreement may control the services it covers.

Privacy PolicySecurity & TrustPermanent link to this version
Contents · 36 sections
  1. Acceptance of Terms and Evidence of Agreement
  2. Scope and Description of Services
  3. No Legal Financial Engineering or Regulatory Determination
  4. Pre Contract Submissions and Prohibited Information
  5. Security CMMC SPRS and Authorization Boundaries
  6. Intellectual Property and Ownership
  7. Acceptable Use and User Conduct
  8. Third Party Services Sources and Integrations
  9. DISCLAIMER OF WARRANTIES
  10. EXCLUSION OF INDIRECT AND CONSEQUENTIAL DAMAGES
  11. LIMITATION OF LIABILITY
  12. Indemnification and Defense Procedures
  13. Government Contracting and Teaming Agreements
  14. Force Majeure
  15. Changes to Terms Services and Prices
  16. Suspension Termination and Access Restrictions
  17. Governing Law and Dispute Resolution
  18. Severability and Waiver
  19. Contact Information and Legal Notices
  20. Eligibility Organizational Authority and Account Security
  21. Orders Quotes Fees Taxes and Activation
  22. Automatic Renewal and Cancellation
  23. Usage Allowances Metering and Overage
  24. Free Previews and One Time Report Purchases
  25. Refunds Billing Errors Failed Payments and Disputes
  26. Customer Data Processing License and Confidentiality
  27. Privacy AI Assistance and External Processing
  28. Retention Archives Deletion and Downloads
  29. Output Limitations Human Review and Permitted Reliance
  30. Monitoring Scope Alerts and Changing Sources
  31. Enterprise Licensing and Deployment Responsibilities
  32. Delivery Acceptance Support and Service Levels
  33. Export Controls Sanctions and Restricted Uses
  34. Security Incidents and Cooperation
  35. Entire Agreement and Order of Precedence
  36. Electronic Communications Assignment and Survival

1. Acceptance of Terms and Evidence of Agreement

1.1 Contracting parties and scope

These Terms of Service ("Terms") are an agreement between Blue Ridge Federal LLC ("BRF," "we," "us," or "our") and the person or organization accepting them ("you" or "Customer"). They govern blue-ridge-federal.com, BRF client portals, demonstrations, application programming interfaces ("APIs"), and the software and services provided under them (collectively, the "Services"). If you accept for an organization, that organization is the Customer and you represent that you have authority to bind it.

1.2 Affirmative acceptance

You accept these Terms when, after receiving conspicuous notice of them, you select an acceptance control, complete a purchase that expressly incorporates them, sign an agreement incorporating them, or take another action the interface expressly identifies as acceptance. An authorized administrator may accept for the Customer and its authorized users. Electronic acceptance records may include the accepted version, account, and date. If you do not agree, do not activate or use the operational Services.

1.3 Public browsing

Viewing public information or a portfolio does not by itself purchase a service, create a software license beyond ordinary website access, authorize a data submission, or establish a government contracting relationship. We provide public materials for their stated informational purposes. Contractual restrictions in these Terms apply to visitors to the extent those visitors have validly accepted them; ownership rights and applicable law apply independently.

1.4 Applicable Orders

An "Applicable Order" is a checkout order, accepted written quotation, enterprise order, statement of work ("SOW"), or other service agreement accepted by both parties. The Applicable Order identifies the purchased Services and their scope. Section 35 governs conflicts among contractual documents.

2. Scope and Description of Services

2.1 Available services

BRF provides informational materials and operational Services that may include software development, document extraction, product and SKU mapping, bill of materials ("BOM") screening, sourced reports, monitoring, listing-package assistance, systems integration, and enterprise deployment. A reference to a capability does not mean it is included in every plan, enabled for your organization, or available in every deployment.

2.2 Purchased scope

Your Applicable Order determines the deliverables, supported formats, data sources, rulesets, usage limits, deployment, and review or support work included. Professional services, specialist review, integrations, archives, and software licenses may be priced separately. Requests for briefings, quotations, or enterprise access do not activate paid processing or obligate either party to proceed.

2.3 Government and other affiliations

BRF is an independent business. References to government programs, procurement systems, regulatory lists, ERP products, standards, or manufacturers describe the relevant work or sources. They do not represent sponsorship, endorsement, certification, partnership, or approval by those organizations.

3. No Legal Financial Engineering or Regulatory Determination

3.1 Purpose of outputs

Reports, screening findings, proposed classifications, mappings, examples, and consultations support informed review. They do not independently constitute legal or financial advice, an engineering approval, a customs ruling, an export classification or license, a cybersecurity authorization, a government certification, or permission to procure or operate equipment.

3.2 Your decisions

You are responsible for obtaining qualified advice when needed and for decisions involving procurement, contracting, import or export, engineering suitability, and regulatory representations. A proposed substitute requires review of its specifications, interfaces, safety, and intended use. Listing-package assistance does not guarantee eligibility, listing, an award, or assessor approval.

3.3 Express obligations preserved

These qualifications do not eliminate a specific deliverable, warranty, or service obligation expressly included in an Applicable Order. BRF remains responsible for performing its agreed work; Customer review does not excuse a failure to deliver that work.

4. Pre Contract Submissions and Prohibited Information

4.1 Initial inquiries and demonstrations

Use only public information or synthetic examples in public forms, general email, and demonstrations. Redacted examples are acceptable only if restricted information has been effectively removed and you have authority to disclose the remaining material. Removing a label does not change the underlying information restrictions.

4.2 Prohibited information

Do not submit classified information, Controlled Unclassified Information ("CUI"), covered defense information, export-controlled technical data, passwords, private keys, full payment-card details, or other information you are not authorized to disclose through public forms, general email, demos, or the ordinary commercial cloud Service. Federal Contract Information and other contract-restricted information may be submitted only within an expressly approved scope.

4.3 Approved commercial channels

Confidential commercial data may be submitted through an authorized customer workflow subject to Section 26 and any applicable confidentiality or data-processing agreement. An account, subscription, nondisclosure agreement, or encrypted connection alone does not authorize controlled government or export-controlled data.

4.4 Controlled workflows and mistaken submissions

Controlled information requires a separate written agreement, a specifically approved system boundary and data flow, verified applicable controls, and all required legal and contractual authorizations before transfer. If you suspect a prohibited submission, stop the transfer and promptly contact us using Section 19 without retransmitting the material. We may isolate, restrict, preserve, or remove it as required for lawful handling and incident response.

5. Security CMMC SPRS and Authorization Boundaries

5.1 Scope of security representations

BRF will use reasonable administrative and technical safeguards appropriate to the authorized Services and will honor specific safeguards agreed in writing. No system or transmission method is guaranteed to be completely secure. A security representation applies only to the system, configuration, period, and scope it expressly identifies.

5.2 Assessment status

These Terms do not represent that BRF has a particular current Cybersecurity Maturity Model Certification ("CMMC") status, assessment score, certification, or Supplier Performance Risk System ("SPRS") affirmation. Customers requiring such status must obtain current, verified assessment and affirmation information for the relevant system before contracting for controlled work. SPRS access, assessment submission, affirmation, and third-party certification are distinct matters; a self-assessment is not a C3PAO certification.

5.3 Authorization before processing

Neither these Terms nor a purchase authorizes CUI, classified, or export-controlled processing. The parties must establish the applicable contract requirements, permitted users and locations, assessment scope, authorized providers, and system readiness in a separate agreement before any such work. Deployment on customer premises or in GovCloud does not itself establish authorization or compliance.

5.4 Mandatory responsibilities

You are responsible for following submission restrictions and identifying applicable restrictions on your data. BRF remains responsible for its own obligations under applicable law and executed contracts. Prohibited submissions do not create automatic immunity from mandatory safeguarding, preservation, or reporting duties. Section 34 governs incident cooperation and notification.

6. Intellectual Property and Ownership

6.1 BRF materials

BRF and its licensors retain their rights in the Services, software, APIs, methodologies, screening workflows, templates, website materials, branding, and preexisting tools. Except for rights expressly granted in these Terms or an Applicable Order, no intellectual property rights are transferred by access, payment, or delivery.

6.2 Customer materials

You retain your rights in the files, source materials, data, and original content you submit ("Customer Content"). BRF receives only the rights described in Section 26 and the Applicable Order. This section does not transfer ownership of Customer Content to BRF.

6.3 Purchased outputs

After payment of the applicable fees, BRF grants you a nonexclusive right to download, reproduce, use, and share purchased reports, mappings, and other delivered outputs for your business, compliance, procurement, and contracting purposes. You may share them with authorized personnel, advisers, auditors, customers, primes, subcontractors, and government reviewers who have a legitimate need, subject to applicable confidentiality and third-party rights. Do not misrepresent an output as a BRF or government certification, remove material qualifications, or resell the Services as your own without written authorization. Lawfully downloaded outputs remain usable after subscription cancellation, subject to these restrictions.

6.4 Custom work and third-party rights

An Applicable Order must expressly address any assignment of custom deliverables. In the absence of an express assignment, BRF retains its tools and software and grants the rights specified for the delivered work. Mandatory government rights and agreed government contract clauses control where applicable. Third-party materials and open-source components remain subject to their applicable licenses; BRF does not claim ownership of them.

6.5 Feedback

You may provide nonconfidential suggestions voluntarily. BRF may use those suggestions without payment or attribution, but this permission does not extend to Customer Content, confidential information, or a separate deliverable you have not authorized us to use.

7. Acceptable Use and User Conduct

7.1 Permitted use

Use the Services for lawful purposes within your authorization, purchased scope, and applicable documentation. Legitimate sales inquiries, teaming requests, and authorized API integrations are permitted. You must not:

7.2 Prohibited conduct

  • Access another organization's data, share individual sign-in credentials, or disclose API or license keys to unauthorized persons.
  • Bypass authentication, payment, licensing, rate, usage, or security controls, or interfere with another user's access.
  • Scrape, mine, harvest, or systematically extract content without authorization, except through approved APIs or as otherwise legally permitted.
  • Upload malicious code, exploit vulnerabilities, disrupt systems, or conduct penetration testing without prior written authorization.
  • Impersonate another party, make fraudulent procurement representations, or falsely claim government affiliation or authority.
  • Reverse engineer, decompile, or disassemble protected software except to the extent an Applicable Order or nonwaivable law permits.
  • Use outputs to facilitate unlawful procurement, sanctions evasion, unauthorized exports, infringement, or other illegal conduct.

7.3 Enforcement

We may investigate suspected misuse and take proportionate action under Section 16. Report suspected vulnerabilities privately through Section 19; do not access or disclose data beyond what is necessary to identify and report the concern lawfully.

8. Third Party Services Sources and Integrations

8.1 External dependencies

The Services may depend on hosting, authentication, payment, catalog, model, communication, government, and enterprise-system providers. Source records may be incomplete, inaccurate, delayed, restricted, or unavailable. Links and interoperability references do not constitute endorsement or establish an agency relationship.

8.2 Third-party terms

Where you establish a direct account or connection with a third party, you are responsible for its applicable terms, credentials, permissions, and charges. We will identify material restrictions on included third-party content or functions when they affect the agreed use. You must not use an integration to exceed the rights granted by either provider.

8.3 Responsibility

BRF does not control independent third-party systems or warrant their performance. Availability and source limitations may affect the Services. This does not excuse BRF from safeguards, confidentiality duties, express service commitments, or other obligations it has accepted, including appropriate management of its own service providers.

9. DISCLAIMER OF WARRANTIES

9.1 General disclaimer

EXCEPT FOR EXPRESS WARRANTIES IN THESE TERMS OR AN APPLICABLE ORDER, AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE WEBSITE, DEMOS, SOFTWARE, APIS, REPORTS, AND OTHER SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE." BRF DISCLAIMS IMPLIED AND STATUTORY WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NONINFRINGEMENT.

9.2 Accuracy and availability

EXCEPT AS EXPRESSLY AGREED, BRF DOES NOT WARRANT UNINTERRUPTED OR ERROR-FREE OPERATION, COMPLETE SOURCE COVERAGE, RESOLUTION OF EVERY RECORD, OR THAT ANY FINDING WILL SATISFY A PARTICULAR REGULATORY, PROCUREMENT, ENGINEERING, OR GOVERNMENT REQUIREMENT. SAMPLES, ESTIMATES, AND HISTORICAL PERFORMANCE RESULTS DO NOT GUARANTEE YOUR RESULTS.

9.3 Preserved rights

NOTHING IN THIS SECTION DISCLAIMS AN EXPRESS CONTRACTUAL WARRANTY, BRF'S AGREED CONFIDENTIALITY OR SECURITY OBLIGATIONS, OR A WARRANTY OR RIGHT THAT APPLICABLE LAW DOES NOT ALLOW THE PARTIES TO EXCLUDE. SECTION 32 DESCRIBES BRF'S SERVICE PERFORMANCE OBLIGATION.

10. EXCLUSION OF INDIRECT AND CONSEQUENTIAL DAMAGES

10.1 Excluded damages

SUBJECT TO SECTION 11.2 AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, BRF AND ITS OFFICERS, EMPLOYEES, AGENTS, AND LICENSORS WILL NOT BE LIABLE TO YOU UNDER THESE TERMS FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES. THIS INCLUDES LOST PROFITS, REVENUE, BUSINESS OPPORTUNITIES, BUSINESS INTERRUPTION, PROCUREMENT DELAYS, LOST GOVERNMENT OR COMMERCIAL CONTRACTS, AND CONSEQUENTIAL LOSS OR CORRUPTION OF DATA.

10.2 Application

THIS EXCLUSION APPLIES REGARDLESS OF THE LEGAL THEORY, INCLUDING CONTRACT, TORT, OR NEGLIGENCE, EVEN IF THE POSSIBILITY OF SUCH DAMAGES WAS DISCLOSED. IT DOES NOT RECLASSIFY DIRECT DAMAGES AS CONSEQUENTIAL, LIMIT A NONPARTY'S INDEPENDENT LEGAL RIGHTS, OR ELIMINATE AN EXPRESS REFUND OBLIGATION OR A REMEDY PRESERVED BY AN APPLICABLE ORDER.

11. LIMITATION OF LIABILITY

11.1 Aggregate cap

SUBJECT TO SECTION 11.2 AND UNLESS AN APPLICABLE ORDER EXPRESSLY PROVIDES OTHERWISE, BRF'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS OR THE AFFECTED SERVICES WILL NOT EXCEED THE GREATER OF US $100 OR THE FEES YOU PAID BRF FOR THE AFFECTED SERVICES DURING THE TWELVE MONTHS BEFORE THE FIRST EVENT GIVING RISE TO THE CLAIM. MULTIPLE CLAIMS ARISING FROM THE SAME OR RELATED EVENTS DO NOT MULTIPLY THE CAP.

11.2 Exceptions and preserved obligations

SECTIONS 10 AND 11.1 DO NOT EXCLUDE OR LIMIT LIABILITY FOR FRAUD, WILLFUL MISCONDUCT, GROSS NEGLIGENCE, DEATH OR PERSONAL INJURY TO THE EXTENT CAUSED BY CONDUCT FOR WHICH LIABILITY CANNOT LAWFULLY BE LIMITED, OR ANY OTHER LIABILITY THAT APPLICABLE LAW DOES NOT PERMIT TO BE EXCLUDED OR LIMITED. THEY DO NOT REDUCE REFUNDS EXPRESSLY OWED UNDER THESE TERMS, ALTER A DIFFERENT LIMIT EXPRESSLY AGREED IN AN APPLICABLE ORDER, OR WAIVE MANDATORY GOVERNMENT OR REGULATORY OBLIGATIONS.

11.3 Allocation of risk

THESE LIMITATIONS FORM PART OF THE PARTIES' ALLOCATION OF RISK AND APPLY TO THE EXTENT ENFORCEABLE. THEY DO NOT IMPOSE A CONTRACTUAL LIMIT ON THE AUTHORITY OF A REGULATOR OR THE INDEPENDENT RIGHTS OF A PERSON WHO IS NOT BOUND BY THESE TERMS.

12. Indemnification and Defense Procedures

12.1 Customer obligations

To the extent permitted by law, you will defend BRF and its officers and employees against a third-party claim alleging that Customer Content you supplied infringes that party's intellectual property rights, that you lacked authority to supply it, or that your unlawful use of the Services or material breach of Sections 4, 7, or 33 caused harm to that party. You will pay resulting damages and reasonable costs awarded by a court or included in a settlement you approve. This obligation applies only to the extent the claim arises from your conduct and excludes the portion caused by BRF's breach, negligence, or other wrongful conduct.

12.2 Procedure

BRF must promptly notify you of a covered claim, provide reasonable cooperation at your expense, and allow you to control the defense with competent counsel. Delayed notice reduces your obligation only to the extent it materially prejudices the defense. BRF may participate with its own counsel at its own expense. A settlement may not admit BRF fault, impose nonmonetary duties on BRF, or fail to release BRF fully without its prior written consent, which will not be unreasonably withheld.

12.3 Separate undertakings

Any indemnity undertaken by BRF, including an intellectual property indemnity for enterprise software, must be expressly stated in an Applicable Order. This section does not create a duty to indemnify BRF for its own wrongdoing or for an unrelated third-party dispute.

13. Government Contracting and Teaming Agreements

13.1 Separate authority and agreement

Public materials, inquiries, account creation, briefings, or demonstrations do not establish a teaming agreement, subcontract, exclusivity commitment, fiduciary duty, procurement representation, or authority to act for either party. Government work requires an agreement accepted by authorized representatives defining the work and applicable government requirements.

13.2 Flow-downs and data rights

Sending a solicitation, purchase order, or proposed FAR or DFARS clause does not by itself constitute BRF's acceptance. Applicable mandatory requirements and clauses incorporated in an executed agreement remain effective according to law and that agreement. Any treatment of government technical data, software rights, records, personnel, or reporting must be agreed for the relevant work.

13.3 No award guarantee

BRF does not guarantee an award, source approval, listing, assessment outcome, government payment, or acceptance by a prime contractor. You remain responsible for the accuracy and timeliness of representations and submissions made in your name unless an Applicable Order expressly assigns a particular task to BRF.

14. Force Majeure

14.1 Qualifying events

Neither party is responsible for a delay or failure to perform caused by an event beyond its reasonable control that it could not reasonably avoid or overcome, including a natural disaster, war, government shutdown or order, widespread utility or network failure, or a qualifying third-party infrastructure interruption. A cyber incident qualifies only to the extent these conditions are met; it is not automatically excused.

14.2 Mitigation and prolonged interruption

The affected party must give prompt notice when practicable and use reasonable efforts to mitigate and resume performance. This section does not excuse accrued payment obligations, reasonable safeguarding, or mandatory incident and preservation duties. If a qualifying event prevents material operation of a paid Service for thirty consecutive days, either party may terminate the affected order by notice. BRF will refund prepaid fees for the unused terminated subscription period and paid work not performed, without duplicating another refund.

15. Changes to Terms Services and Prices

15.1 Revisions

We may update these Terms by posting a dated version. We will give reasonable advance notice of material changes affecting an existing paid relationship, ordinarily at least thirty days, subject to any different notice or consent required by law. Changes apply prospectively and do not rewrite an accrued claim or reduce a purchased fixed-term commitment retroactively.

15.2 Consent and choice

Where affirmative consent is required, we will request it before applying the change. Continued browsing alone does not authorize new charges or an expanded use of Customer Content. If you do not accept a proposed change, you may decline renewal or discontinue the affected Service. Your existing order remains governed by its accepted terms for its current period unless the parties validly agree otherwise.

15.3 Service and price changes

We may improve or modify features, sources, or technical interfaces. Material reductions to a paid Service during its committed term require an agreed alternative or a right to end the affected Service and receive a prorated refund of unused prepaid fees. Price changes apply to a future purchase or renewal after appropriate notice and any required consent. We may make urgent changes needed for security or law, with notice as soon as practicable. Mandatory renewal, cancellation, and price-change rules control over a different general notice period in this section.

16. Suspension Termination and Access Restrictions

16.1 Protective suspension

We may restrict affected access promptly where reasonably necessary to address a security threat, prohibited data, suspected fraud, unlawful use, or a legal requirement. We will limit the restriction where practicable, give notice unless prohibited or unsafe, and restore access when the reason is resolved. Suspension does not automatically authorize permanent deletion or continued renewal charges.

16.2 Breach and nonpayment

Either party may terminate an affected order for a material breach that remains uncured thirty days after written notice describing it. We may suspend paid processing for overdue undisputed fees after notice and a reasonable opportunity to pay, or act immediately for a breach that cannot reasonably be cured or that threatens security or lawful operation.

16.3 Other termination

You may cancel recurring Services under Section 22. BRF may discontinue a free Service at any time. If BRF ends a paid Service for convenience, it will ordinarily give at least thirty days' notice and refund unused prepaid subscription fees and fees for work not performed. If you terminate for BRF's uncured material breach, the same refund principle applies. Termination for your breach does not create a refund right except where law or an Applicable Order requires one.

16.4 Consequences

New processing and access rights end when termination takes effect, subject to any agreed transition. Accrued fees remain due. We will provide a reasonable opportunity to download available paid outputs before a planned termination where lawful and technically practicable, subject to existing retention deadlines. Termination does not extend an expired retention period. Confidentiality, retention, and survival obligations continue as specified in these Terms.

17. Governing Law and Dispute Resolution

17.1 Governing law and courts

New York law governs these Terms, without applying conflict-of-laws rules that would select another jurisdiction's law. Subject to mandatory law and a different dispute provision in an Applicable Order, the parties consent to exclusive jurisdiction and venue in the state courts located in Queens County, New York, or the United States District Court for the Eastern District of New York where federal jurisdiction exists.

17.2 Resolving concerns

Before filing an ordinary contractual claim, each party will try in good faith to resolve the concern through written notice and discussion for thirty days. This does not prevent urgent equitable relief, a timely filing needed to preserve a claim, or a complaint to a regulator. It does not shorten a statutory limitation period or require a party to abandon a nonwaivable remedy.

17.3 Mandatory rules

These Terms do not require arbitration or contain a class-action waiver. Nonwaivable consumer protections and government-contract dispute procedures remain applicable where they govern. A government agency is not bound to a forum, indemnity, or other provision its authorized representative lacks power to accept.

18. Severability and Waiver

18.1 Severability

If a provision is held unenforceable, it will be enforced only to the extent permitted, or severed if it cannot lawfully be enforced. The remaining provisions continue in effect unless that result would defeat the agreement's essential purpose. A court may modify a provision only to the extent it has authority to do so.

18.2 Waiver

A failure or delay to enforce a right does not waive it. A waiver applies only to the particular matter identified and must be made by an authorized representative. A waiver of one breach does not waive another.

19. Contact Information and Legal Notices

19.1 Contact

Blue Ridge Federal LLC 2504 Ditmars Blvd Astoria, NY 11105-3121, United States Email: jbenson@blue-ridge-federal.com Telephone: +1 917 412 1478 Website: https://blue-ridge-federal.com

19.2 Notices

Send contractual, billing, privacy, security, and intellectual property notices to the email address above unless an Applicable Order specifies another contact. Identify the account or order and describe the concern without including prohibited information. We may send contractual notices to your verified account email or another agreed notice address. A formal notice is effective on documented receipt; a bounce or known delivery failure is not receipt. Legally required delivery methods take precedence. This provision does not constitute consent to service of legal process by ordinary email.

20. Eligibility Organizational Authority and Account Security

20.1 Eligible users

The operational Services are intended for business and government use. Individual users must be at least eighteen years old and legally able to enter the agreement, or act under a lawful organizational arrangement expressly approved in writing. You must have authority to act for the identified Customer and to submit its information.

20.2 Account administration

Provide accurate account and organization information and keep it current. Customer owners and administrators are responsible for assigning and removing permissions, approving optional processing, maintaining appropriate authentication, and managing authorized users and API keys. Do not share an individual sign-in. The Customer is responsible for authorized users' activity within its control; this does not make it responsible for a compromise caused by BRF's own failure.

20.3 Compromised access

Promptly report suspected unauthorized activity, revoke affected credentials where possible, and cooperate in containment. We may verify identity and authority before changing ownership, restoring access, or disclosing account information. You are responsible for maintaining suitable devices, connectivity, and permissions for your use.

21. Orders Quotes Fees Taxes and Activation

21.1 Price and scope

The price, currency, billing interval, included work, and selected options shown in an accepted checkout or Applicable Order govern that purchase. Public price ranges and preliminary estimates are invitations to discuss scope, unless expressly offered as binding. Optional data packs, archives, monitoring, custom integrations, and professional services are included only when selected or agreed.

21.2 Payment and taxes

Unless the Applicable Order states otherwise, prices are in United States dollars, subscriptions are charged in advance, and authorized metered charges are billed in arrears. You are responsible for applicable transaction taxes and duties other than taxes on BRF's net income. We will disclose applicable charges before purchase or invoice them as legally required. Provide valid tax-exemption documentation before the relevant charge when available.

21.3 Activation and errors

Paid processing rights activate after payment confirmation and any applicable organization approval. A payment-return page or pending payment does not itself activate access. If a material pricing or order error is discovered, we will notify you and seek an agreed correction or cancel the affected unperformed order and refund the affected payment; we will not silently charge a higher amount. An order is limited to the scope accepted by both parties.

22. Automatic Renewal and Cancellation

22.1 Recurring authorization

A subscription renews automatically for the monthly or annual period selected at checkout unless canceled before the next renewal. By affirmatively accepting the recurring offer, you authorize the disclosed initial and recurring charges using your selected payment method. We will provide a retainable confirmation stating the amount, frequency, cancellation mechanism, and any applicable deadline. A separate one-time report charge is not a recurring subscription.

22.2 Annual billing

An annual SKU plan charges the disclosed annual amount in advance and supplies twelve separate monthly SKU allowances. Annual Watch pricing follows its own disclosed annual offer and may differ from twelve monthly Watch payments. Neither type converts an unused monthly allowance into a pooled annual allowance unless the order expressly says so.

22.3 Cancellation

Cancel through the relevant Usage and billing or subscription-management interface before renewal. If the interface is unavailable or you need assistance, email us at the address in Section 19; we will honor a timely, verifiable cancellation request without imposing an unnecessary barrier. Unless a refund or earlier termination right applies, cancellation stops the next renewal and access continues through the paid period. Stopping monitoring of one BOM is different from canceling the Watch subscription.

22.4 Required notices and rights

We will provide renewal reminders, material-change and price-change notices, and cancellation options required by applicable law, including legally required delivery methods for qualifying business contracts. Where law requires new affirmative consent to a price change, we will obtain it or provide the legally required alternative. No provision of these Terms limits a mandatory cancellation, refund, or withdrawal right.

23. Usage Allowances Metering and Overage

23.1 SKU allowances

The Applicable Order specifies the monthly SKU allowance and optional packs. Allowances reset each month, including on annual SKU plans, and unused units do not roll over unless expressly agreed. Attempted rows count toward usage even if a part remains unresolved. A job canceled before processing or marked by BRF as not processed is released from usage to the extent it was not attempted.

23.2 Overage

Processing above an included allowance requires your explicit authorization and activation of metered billing for the organization. The checkout or order must disclose the per-attempted-SKU rate and selected pack charges. Without activation and consent, the included allowance remains the limit. Any agreed spending cap also applies. We will make usage information available and investigate substantiated counting errors.

23.3 Separate entitlements

Report purchases, Watch coverage, enterprise licenses, SKU subscriptions, and archive purchases confer their respective rights only. Watch portfolio limits concern enrolled BOMs and lines; they do not create a legacy SKU allowance. Additional or revised work may consume further usage when requested and disclosed. Payment or usage holds may temporarily prevent new processing.

24. Free Previews and One Time Report Purchases

24.1 Preview scope

A free preview may process an eligible BOM and display a limited selection of findings, such as up to five flagged examples. It does not include a full matrix, paid exports, an audit opinion, or a compliance clearance unless expressly offered. No flags, unresolved records, or an unavailable source do not establish compliance.

24.2 Purchased revision

A one-time report purchase unlocks the identified delivered BOM revision and the outputs specified at checkout. It does not purchase perpetual monitoring, unlimited revisions, unlimited part lookup, or a guarantee that every line resolves. A revised BOM, new screening run, or additional scope may require another purchase or allowance. The stored report reflects its identified ruleset, sources, and screening date; downloading it does not automatically refresh its findings.

24.3 Access deadline

Download purchased files before the stated retention deadline. A report purchase alone does not extend retention. A payment first confirmed after deletion or expiry must be reviewed for a deliverable or refund; it does not silently restore an unavailable report. Rights in lawfully downloaded reports are governed by Section 6.

25. Refunds Billing Errors Failed Payments and Disputes

25.1 General rule and exceptions

Except as required by law, expressly stated in an Applicable Order, or provided in these Terms, completed one-time work and elapsed subscription periods are nonrefundable. Cancellation alone does not create a prorated refund for unused allowance or an unused portion of a paid period. We will correct duplicate or unauthorized BRF charges and refund a paid deliverable we cannot supply if you do not accept an appropriate replacement. Sections 14, 15, and 16 provide additional refund rights.

25.2 Billing concerns

Contact us promptly with the order reference and explanation of a suspected billing error, preferably within thirty days of discovering it. This requested notice period does not waive a longer legal right. Pay undisputed amounts when due. A failed or pending payment does not activate a new paid allowance or coverage period; we may retry an authorized payment as permitted by your payment agreement and applicable law.

25.3 Reversals and review

A refund, charge reversal, or payment dispute may revoke the corresponding unpaid entitlement or place related processing under review. We will limit restrictions to what is reasonably necessary and reconcile partial refunds, credits, and resolved disputes rather than treating a replayed payment event as automatic restoration. A legitimate billing dispute does not waive your legal rights, authorize unrelated data deletion, or excuse BRF's confidentiality obligations.

26. Customer Data Processing License and Confidentiality

26.1 Authority and limited license

You represent that you have the rights and permissions needed to supply Customer Content and direct its processing. You grant BRF and its authorized service providers a limited right to host, copy, transmit, transform, and otherwise process that content only to provide the ordered Services, perform authorized support, secure the Services, and comply with law. This is not an assignment of ownership or permission to publish your content.

26.2 Mutual confidentiality

Each party will protect the other's nonpublic information that is identified as confidential or should reasonably be understood to be confidential. It will use that information only for the relationship, limit disclosure to persons with a legitimate need who are bound by appropriate duties, and use at least reasonable care. Customer Content is confidential to the extent nonpublic. Routine BRF staff review of client files requires an authorized, time-limited support grant; exceptional access must be legally permitted and limited to necessary security, incident, or legal handling.

26.3 Exceptions and compelled disclosure

These duties do not cover information the recipient can demonstrate was lawfully known without restriction, becomes public without breach, is received lawfully without a confidentiality duty, or is developed independently. A recipient may disclose information when legally required, giving advance notice where lawful and reasonably practicable and limiting disclosure to what is required.

26.4 Duration and publicity

Confidentiality continues for five years after the relationship ends, for trade secrets while they remain protected as such, and for retained Customer Content or personal data for as long as applicable duties require. BRF will not publish your confidential work, name, logo, or a customer case study without permission. An applicable nondisclosure agreement may provide stronger or different protection.

27. Privacy AI Assistance and External Processing

27.1 Privacy roles

Our Privacy Policy at https://blue-ridge-federal.com/privacy explains how we handle account, contact, website, billing, and usage information. Processing of personal data on your behalf is also subject to any applicable data-processing agreement and mandatory law. Acceptance of these Terms is not a substitute for a separately required privacy consent or lawful international-transfer mechanism. The parties must establish required processing terms before a workflow that needs them.

27.2 External catalog queries

Authorized supplier lookups may send manufacturer part numbers and supplier codes to configured sources. Optional catalogs and model assistance require the relevant organization owner's or administrator's authorization. Do not enable a provider path that is inconsistent with your data restrictions. Authorization does not permit a prohibited submission under Section 4.

27.3 AI data flows

AI assistance is optional and disabled by default unless expressly included and authorized for the relevant workflow. Supplier-evidence requests use limited identifiers; optional intake mapping may transmit column headers and selected sample rows, and optional document reading may transmit the document you choose. These uses must be disclosed before authorization. Response-storage settings do not necessarily eliminate provider abuse-monitoring retention. Provider, location, and retention requirements must be verified where material to your order.

27.4 Restrictions on secondary use

BRF will not use Customer Content, or authorize its providers to use that content, to train general-purpose AI models. We may use operational counts and information that does not identify a customer or reveal its confidential information to administer and improve the Services. We will not treat removal of obvious identifiers alone as sufficient where the underlying information remains identifiable or confidential.

28. Retention Archives Deletion and Downloads

28.1 Standard retention

Unless an authorized extension or separate agreement applies, standard processing inputs and result files are scheduled for deletion thirty days after the job finishes. Earlier customer deletion is available through supported controls or a verified request. Canceling a job before processing removes its source files under the applicable workflow. A paid report alone does not extend this period.

28.2 Watch extensions

Each watched revision requires explicit owner consent to the applicable retention extension. Watch retention ends thirty days after the earliest applicable event: stopping that BOM's enrollment, ending the subscription, or expiry of its paid coverage. If another purchased archive authorizes a later deadline, that later authorized deadline applies. Retention does not itself confer active processing or monitoring rights.

28.3 Purchased archives

An optional encrypted archive retains eligible files from purchased periods for the selected one-, three-, or seven-year term after completion, as described in the order. Ending the subscription does not by itself cancel an already purchased archive term. An authorized earlier deletion request may end availability sooner, subject to required preservation. An archive is not a promise to retain material outside its purchased scope or a substitute for your own records.

28.4 Records and preservation

Billing and job metadata, file fingerprints, access logs, reviewer decisions, and encrypted review notes may be retained separately for audit, security, support, and legal purposes. They are not all deleted when the source file is deleted. Necessary legal holds and incident-preservation duties take precedence over routine deletion. Residual protected backup copies, where maintained, are removed under their normal retention cycle and are not used to restore ordinary access to deleted content.

28.5 Your records

Maintain copies you need and download outputs before expiry. BRF does not promise recovery after deletion. If the agreed retention arrangements do not meet a legal or contracting recordkeeping requirement, arrange an appropriate archive or separate agreement before processing.

29. Output Limitations Human Review and Permitted Reliance

29.1 Findings and evidence

An output reflects the input, configured sources, ruleset, and processing date identified for that work. Catalog matches and country-of-origin evidence require attention to exact identifiers and configurations. Headquarters, ownership, plant locations, or a manufacturer name alone do not establish where a specific part was made. Unresolved or conflicting evidence remains a review issue.

29.2 Compliance and performance

A no-findings result means the screened data did not trigger the included checks; it is not universal clearance. List membership, listing absence, and potential name matches must be interpreted within the applicable rule and scope. Match confidence describes a method or score, not necessarily empirical accuracy. Samples and benchmarks apply to their documented populations and conditions.

29.3 Review before use

You must have a qualified person review material findings, unknowns, proposed alternatives, classifications, and field mappings before making a regulatory representation, purchasing or substituting equipment, or importing into a production system. A reviewer sign-off records that reviewer's decision; a blank signature block is not a completed approval. AI-generated or extracted text may require correction. This review duty does not eliminate BRF's express obligations.

30. Monitoring Scope Alerts and Changing Sources

30.1 Covered portfolio

Monitoring applies only to eligible, explicitly enrolled BOM revisions within active paid coverage and the selected BOM and line limits. The order identifies the monitoring scope and frequency. Daily monitoring, when offered and activated, is periodic checking and does not mean continuous real-time detection. A material BOM change may require a new revision and enrollment.

30.2 Findings and notification

A source may change between checks, publish late, or be unavailable. We will use reasonable efforts to perform the agreed checks and address interruptions. Alerts indicate a change for review; they do not decide its legal or engineering consequence. Email delivery may fail, so use the private workspace as the primary record and keep owner contacts current. Monitoring does not replace your procurement deadlines or required independent reviews.

30.3 Coverage changes

Nonpayment, payment holds, exceeded portfolio capacity, stopped enrollment, or expired coverage may pause monitoring. We will identify material access issues where practicable. Stopping a BOM releases its enrollment but does not automatically cancel the recurring subscription. Monitoring and retention rights are separate and follow Sections 22, 23, and 28.

31. Enterprise Licensing and Deployment Responsibilities

31.1 License scope

Customer-hosted, on-premises, and GovCloud deployments require an Applicable Order identifying the licensed entity, deployment, term, authorized use, support, and any limits. The license is nonexclusive and limited to that scope unless expressly agreed otherwise. Do not transfer license credentials, distribute the software, offer it as a hosted service to others, or exceed licensed use without authorization. Expiry ends authorization for new work; permitted completion of existing work follows the issued license and order.

31.2 Shared responsibilities

The deployment agreement allocates responsibility for infrastructure, operating systems, identity, encryption keys, credentials, patching, backups, restoration, logging, monitoring, retention, and support access. Unless BRF expressly undertakes a task, the Customer controls and is responsible for those elements in its environment. BRF remains responsible for the tasks and software commitments it accepts.

31.3 Boundaries and egress

A local or GovCloud engine does not automatically relocate the public portal, identity service, or other external components. Supplier queries and optional provider calls may leave the customer boundary. Approve each data flow before processing restricted data, including identifiers that themselves may be controlled. Deployment templates and default images do not establish FIPS validation, FedRAMP authorization, CMMC status, or ITAR compliance. Required controls must be implemented and verified for the actual system.

32. Delivery Acceptance Support and Service Levels

32.1 Performance and delivery

BRF will perform agreed professional services with reasonable care and skill and provide the deliverables expressly described in the Applicable Order. Delivery occurs when the agreed output is made available through the authorized channel, unless the order states otherwise. An email is a notification and is not required to start a clearly disclosed file-retention period.

32.2 Acceptance and correction

Custom acceptance criteria, milestones, dependencies, and review periods must be stated in the order. There is no automatic deemed acceptance merely from downloading a file unless expressly agreed. Notify us promptly of a material failure to meet an agreed requirement and provide enough nonrestricted information to investigate. We will use reasonable efforts to correct it; if agreed work cannot be supplied, Section 25 and any order-specific remedy apply. A requested scope change may require an agreed adjustment to price and schedule.

32.3 Support and service levels

Send support requests to the contact in Section 19 or in your order. Unless expressly purchased, the Services do not include round-the-clock support, a guaranteed response or completion time, guaranteed uptime, service credits, or a dedicated specialist. An applicable service-level agreement governs any such commitment. Test mappings and integrations in an appropriate environment before production use.

33. Export Controls Sanctions and Restricted Uses

33.1 Legal compliance

Each party must comply with export, reexport, sanctions, end-user, end-use, and access restrictions applicable to its activities. You must not provide controlled technical information or permit access by a person where doing so requires an authorization that has not been obtained. This applies to uploads, APIs, remote support, screenshots, logs, diagnostic material, and outside-provider requests.

33.2 Representations and restrictions

You represent that your use and receipt of the Services are not prohibited by applicable sanctions or export restrictions and that you will not use the Services to evade them. We may require information reasonably needed to verify permitted use and may restrict access where law requires it. A screening report is not an export license, a binding jurisdiction determination, or permission to transact with a restricted party.

33.3 Safety and defense uses

Lawful government and defense work may be agreed within an authorized scope. Outputs must not be the sole basis for a safety-critical or operational decision requiring validated engineering, legal authorization, or specialized review. Such review and any additional assurances must be expressly scoped.

34. Security Incidents and Cooperation

34.1 Reporting and containment

Report suspected compromise or prohibited disclosure promptly to the contact in Section 19 without attaching further restricted data. The parties will cooperate reasonably in containment, credential revocation, assessment, and preservation. Each party remains responsible for reports, notifications, and approvals assigned to it by law or contract; cooperation does not transfer those duties.

34.2 Customer notification

BRF will notify the affected Customer owners without undue delay and no later than seventy-two hours after confirming that Customer data was affected by a security incident, unless an earlier or different legally required deadline applies. We will provide available material facts, mitigation steps, recommended customer actions, and a contact, and update the notice as appropriate. We need not disclose another customer's confidential information or information whose disclosure would unlawfully compromise an investigation.

34.3 Earlier clocks and evidence

A legal or government-contract reporting clock may begin on discovery or another trigger before confirmed customer impact. Such requirements control and must not wait for complete certainty or the notice deadline above. Necessary evidence preservation may temporarily limit deletion. Incident access and disclosures must be limited to the lawful response and protection of affected parties.

35. Entire Agreement and Order of Precedence

35.1 Contract documents

These Terms and the Applicable Orders they govern constitute the agreement for the relevant Services and replace prior discussions on that subject. A separate agreement signed by authorized representatives controls the Services it covers where it expressly supersedes or conflicts with these Terms. Existing enterprise or government agreements are not silently replaced by publication of these Terms.

35.2 Resolving conflicts

Mandatory law controls first. Expressly agreed government requirements and negotiated contractual amendments then control their stated scope. An applicable data-processing agreement controls a conflict concerning personal-data processing. An Applicable Order controls service scope, deliverables, price, term, and billing, but changes a liability limit, warranty, indemnity, or dispute provision only when it expressly identifies that change. These Terms govern remaining matters. Technical documentation explains operation but does not silently expand a purchase or reduce an express contractual commitment.

35.3 Additional terms

Terms placed in a purchase order, customer portal, or other unilateral document do not modify the agreement unless BRF expressly accepts them through an authorized representative. Fulfillment, payment, or acknowledgment alone is not acceptance of additional legal terms. Amendments must be accepted by both parties or validly made under Section 15.

36. Electronic Communications Assignment and Survival

36.1 Electronic records

To the extent legally permitted, the parties may use electronic signatures, acceptance records, invoices, and notices for the Services. Keep your notice details current and retain copies of accepted orders. Electronic communication does not replace a separately required delivery method or a legally required consent to electronic records.

36.2 Assignment

Neither party may assign the agreement without the other's written consent, not to be unreasonably withheld, except to a successor in a merger, reorganization, or sale of substantially all relevant assets that assumes the obligations and can lawfully perform them. An assignment does not permit an unauthorized data transfer, reduce confidentiality or security duties, or override government assignment restrictions. We will give notice of a permitted assignment affecting the relationship.

36.3 Relationship and beneficiaries

The parties are independent contractors. These Terms create no partnership, joint venture, employment, agency, or authority to bind the other party. Except for the persons expressly protected by Sections 10 and 11, there are no intended third-party beneficiaries. Those persons receive only the protections expressly stated.

36.4 Survival

Provisions that by their nature should continue survive termination, including ownership and permitted use of delivered outputs, accrued payment and refund obligations, confidentiality, lawful retained-data handling, liability allocation, applicable indemnification, dispute resolution, and the general contractual provisions. Survival does not extend a processing license or retention period beyond its agreed scope. No provision waives a right or obligation that cannot lawfully be waived.

Published versions

  • Terms of Service · 2026-10-08
Back to top ↑

Company

  • Solutions & Capabilities
  • Company information
  • Contact
  • Client sign in
  • Security & Trust
  • Incident response plan
  • Privacy Policy
  • Terms of Service
  • Accessibility

Resources

  • NDAA §848 lookup
  • FCC Covered List lookup
  • DoD §1260H lookup
  • Blue UAS lookup
  • SAM.gov entity registration
  • NIST SP 800-171 Rev. 3
  • CMMC Program
  • DFARS 252.211-7003: Item Unique Identification
  • FAR Part 19: Small Business Programs
  • Section 508 standards

© 2026 Blue Ridge Federal LLC | UEI RFZ3TK7E35P6 | CAGE 19PB1

Blue Ridge Federal

Software by Blue Ridge Federal LLC