Skip to main content
Aizen Agentry
Readiness AuditPrivate Off-Grid AI for LawInsightsLearn AI
Request an Audit
Readiness AuditPrivate Off-Grid AI for LawInsightsLearn AIRequest an Audit

Technical risk allocation

Risk and Technical Services Disclaimer

Aizen builds and sets up technical systems within a signed scope. The client remains responsible for the premises, custody, operation, lawful use, professional judgment, maintenance, insurance, and risks placed under its control.

Effective and last updated: 2026-07-12

Important legal notice.

This document is written for the Philippine legal context and the current Aizen website. It does not replace advice from qualified Philippine counsel, a privacy professional, or a signed engagement agreement tailored to the actual deployment. Aizen should have counsel review it before relying on it for client contracting.

Read this before commissioning a system

A private or off-grid system changes the risk boundary. It does not eliminate risk.

The purpose of this disclaimer is to make the boundary visible. Aizen can build, configure, test, document, and hand over a technical system. The client controls what happens inside its premises and operating environment after delivery, except for duties Aizen expressly accepts in a signed agreement.

Contents

  1. Nature of Aizen's role
  2. Included and excluded scope
  3. Handover and transfer of custody
  4. Theft, loss, seizure, and physical damage
  5. Cybersecurity and unauthorized access
  6. Data, privacy, and privilege
  7. AI and professional-use limitations
  8. Power, environment, backup, and maintenance
  9. Liability limits and mandatory law
  10. Client acceptance checklist

1. Nature of Aizen's role

Aizen Agentry is a technical services provider. Subject to a signed agreement, Aizen may design architecture, source or recommend components, configure software, install systems, connect approved knowledge, establish access controls, run agreed tests, prepare documentation, and train designated users.

Aizen is not the client's law firm, legal adviser, insurer, security agency, property custodian, data owner, records-management authority, business-continuity operator, managed security operations center, or permanent system administrator unless a signed agreement expressly assigns a defined service to Aizen.

Marketing phrases such as "private," "local," "on-premises," "isolated," "off-grid," or "air-gapped" describe possible technical postures. They are not guarantees of absolute secrecy, invulnerability, continuous availability, legal compliance, or freedom from human error.

2. The signed scope controls

Aizen is responsible only for deliverables and duties stated in the signed master services agreement, statement of work, change order, support agreement, or acceptance document. A website page, meeting, demonstration, proposal idea, or informal recommendation does not expand the signed scope.

A proper statement of work should identify:

  • hardware and software included or excluded;
  • deployment boundary and allowed network connections;
  • approved data sources, collections, and users;
  • installation site and environmental requirements;
  • acceptance tests, known limitations, and failure criteria;
  • handover date and transfer of credentials or administrative control;
  • warranty, support, patching, monitoring, and response periods;
  • backup, recovery, retention, and deletion responsibilities;
  • privacy roles and security-incident reporting duties;
  • fees, third-party costs, insurance, liability limits, and exclusions; and
  • the person authorized to accept the system for the client.

3. Handover and transfer of custody

Risk changes when the client receives the hardware, keys, credentials, documentation, premises access, or administrative control. Unless a signed agreement says otherwise, the client assumes custody and operational responsibility at the earlier of documented acceptance, delivery to the agreed site, transfer of administrative control, or productive use by client-authorized users.

After that point, the client must protect the equipment, credentials, data, model files, backups, removable media, and access paths under its control. Aizen's attendance at later training, support, or maintenance does not by itself transfer custody back to Aizen.

Acceptance should be documented. If the parties need a different risk-transfer point, they must state it clearly in the signed agreement.

4. Theft, robbery, burglary, loss, seizure, and physical damage

Once custody has transferred, Aizen does not control the client's building, guards, locks, surveillance, visitor access, storage rooms, transport, fire protection, environmental controls, or insurance. To the fullest extent permitted by law and subject to the signed agreement, Aizen is not responsible for loss arising from:

  • theft, robbery, burglary, pilferage, mysterious disappearance, or unauthorized removal;
  • loss or damage during client-controlled transport, relocation, storage, or disposal;
  • confiscation, seizure, impoundment, or access by a person or authority acting outside Aizen's control;
  • vandalism, sabotage, tampering, accidental impact, liquid damage, pests, dust, corrosion, or improper handling;
  • fire, smoke, flood, earthquake, typhoon, lightning, electrical surge, excessive heat, humidity, or another casualty;
  • failure by the client to maintain locks, restricted rooms, visitor logs, asset records, surveillance, or insurance; and
  • acts or omissions of the client's employees, lawyers, contractors, landlords, security personnel, visitors, or other third parties.

The client should maintain appropriate property, equipment, cyber, crime, business interruption, and professional-liability insurance. Aizen does not insure client property merely because it designed or installed the system.

5. Cybersecurity and unauthorized access

Isolation reduces some exposure paths, but no configuration removes every vulnerability. Risk may arise from insiders, stolen credentials, removable media, maintenance laptops, supply-chain compromise, malicious updates, unpatched software, misconfiguration, weak passwords, social engineering, physical access, hidden network paths, or newly discovered vulnerabilities.

Unless the signed scope includes a continuing managed service, the client is responsible for:

  • user approval, removal, role changes, least-privilege access, and periodic access review;
  • passwords, multi-factor authentication, encryption keys, recovery keys, and administrator credentials;
  • network segmentation, firewall policy, wireless access, remote access, and removable-media control;
  • security monitoring, log review, vulnerability management, patching, anti-malware, and incident response;
  • testing third-party updates before introducing them into an isolated environment; and
  • promptly notifying Aizen when the client requests support for a suspected incident.

Aizen is not liable for an intrusion or data loss merely because it previously configured the system. Liability requires the legal and contractual elements applicable to the actual conduct, scope, cause, and loss.

6. Data, privacy, privilege, and records responsibility

The client decides which documents, matters, personal data, privileged communications, and institutional knowledge may lawfully enter the system. The client must establish a lawful basis, access policy, retention schedule, legal hold process, privilege protocol, data classification, and deletion process appropriate to its work.

Aizen does not determine whether a client's collection, use, disclosure, retention, or deletion is lawful unless a signed scope expressly requires a defined privacy service and qualified advisers are involved. A technical permission does not create legal authority.

When Aizen processes personal data under client instruction, the parties should sign appropriate data-processing terms. The client ordinarily remains responsible for the lawfulness of its instructions and data sources, while Aizen remains responsible for duties it accepts as a processor and duties imposed directly by applicable law.

Private deployment does not automatically preserve attorney-client privilege, work-product protection, confidentiality, or admissibility. The firm's authorized lawyers must decide how professional and evidentiary rules apply.

7. AI output and professional-use limitations

AI systems can produce inaccurate, incomplete, outdated, biased, fabricated, inconsistent, or insecure output. Retrieval may miss a document, select the wrong version, misread OCR, omit context, cite an irrelevant source, or answer confidently when evidence is weak.

Every consequential output remains draft work until an authorized professional verifies the source and exercises independent judgment. Aizen does not guarantee legal accuracy, litigation outcome, regulatory acceptance, commercial outcome, model behavior, or fitness for an untested use case.

The client must prevent the system from making an unsupervised final decision involving:

  • legal advice, court filings, formal opinions, deadlines, settlements, or client commitments;
  • employment, credit, insurance, health, criminal, disciplinary, or similarly consequential matters;
  • access to privileged, confidential, or sensitive information; or
  • another activity requiring a licensed professional, human approval, or specific legal authority.

8. Power, environment, connectivity, backup, and continuity

An on-premises or off-grid system depends on the client's operating environment. Unless the signed scope assigns the duty to Aizen, the client is responsible for adequate electrical capacity, grounding, surge protection, uninterruptible power, generator procedures, ventilation, cooling, humidity control, fire protection, physical space, network equipment, and safe shutdown.

The client must maintain tested backups and a recovery plan appropriate to the value of the data and the required recovery time. A backup that has not been restored and tested should not be treated as proven. Off-grid systems may require manual update, media-transfer, and recovery procedures, which the client must staff and follow.

Aizen does not guarantee continuous availability during power failure, component failure, maintenance, disaster, cyber incident, model update, supplier delay, or another event outside the agreed service commitment.

9. Third-party hardware, software, models, and open-source components

Deployments may include third-party hardware, operating systems, model runtimes, AI models, databases, OCR tools, libraries, drivers, and open-source software. Each component remains subject to its provider's license, warranty, support policy, export restrictions, security updates, and technical limits.

Aizen does not control a third party's discontinuation, license change, vulnerability, defect, update schedule, supply shortage, model change, or support decision. Aizen may help assess alternatives if included in scope, but cannot guarantee continued availability or compatibility of a third-party component.

10. Client changes and unsupported configurations

Aizen is not responsible for failure caused by unauthorized modification, added software, changed firewall rules, connected devices, altered prompts, replaced models, modified permissions, deleted logs, disabled safeguards, unsupported updates, or maintenance by another provider after handover.

A material change should pass through documented change control and renewed acceptance testing. Aizen may decline support until the system is restored to a supportable state or a new scope is agreed.

11. Incident response and notification

The client must maintain an incident-response contact and immediately preserve relevant evidence when theft, unauthorized access, data loss, malware, credential compromise, or another incident is suspected. The client should avoid altering logs or affected systems before qualified responders advise on preservation, containment, and recovery.

The client, as system owner and usually as personal information controller, is responsible for deciding whether to notify affected individuals, the National Privacy Commission, law enforcement, insurers, clients, courts, regulators, or professional bodies. Aizen will perform only the notification or response duties stated in a signed agreement or imposed directly by law.

Philippine breach-notification requirements can involve a 72-hour period in qualifying circumstances. The parties should establish reporting contacts and escalation duties before production use.

12. No automatic compliance or certification

Technical configuration may support privacy, security, governance, or professional-duty requirements. It does not by itself make the client compliant with the Data Privacy Act, court rules, professional rules, cybersecurity standards, client contracts, sector rules, retention duties, or another legal requirement.

Aizen does not issue a legal compliance opinion, penetration-test certification, information-security certification, or insurance assurance unless a signed scope identifies a qualified provider authorized to do so. The client should obtain independent legal, privacy, cybersecurity, tax, and insurance advice appropriate to the deployment.

13. Liability allocation and Philippine mandatory law

To the fullest extent permitted by Philippine law and subject to the signed agreement, Aizen is not responsible for theft, loss, seizure, physical damage, cyberattack, insider misuse, unauthorized access, client negligence, third-party conduct, unapproved change, business interruption, lost profit, lost opportunity, reputational harm, or data loss when the relevant event and control fall outside Aizen's accepted scope.

A website disclaimer alone does not replace a properly drafted contract. Any monetary cap, exclusion of damages, warranty, indemnity, risk-transfer date, or service-level commitment must be stated in the signed agreement and reviewed for enforceability in the actual facts.

Nothing in this disclaimer waives liability for future fraud, excuses willful misconduct, overrides a duty that cannot lawfully be excluded, or removes liability that a competent court or regulator determines under mandatory law. Under the Civil Code, contracts must be performed in good faith, future fraud cannot be waived, and liability for negligence may be regulated according to the circumstances.

Where Aizen directly causes loss through a proven breach of an expressly assumed duty, the signed agreement and applicable law determine responsibility. The client must also take reasonable steps to prevent, contain, insure, and mitigate loss.

14. Events beyond reasonable control

Subject to the signed agreement and applicable law, Aizen is not responsible for delay or failure caused by an event beyond its reasonable control, including natural disaster, widespread outage, war, civil disturbance, government action, supply interruption, carrier failure, labor disruption, epidemic, or failure of a third-party platform that Aizen could not reasonably prevent. The affected party should give notice and take reasonable steps to reduce the effect of the event.

15. Contract hierarchy

The following order applies unless a signed agreement states a lawful alternative:

  1. mandatory Philippine law;
  2. the signed master services or principal agreement;
  3. the signed statement of work and approved change orders;
  4. the signed data-processing, support, warranty, and acceptance documents; and
  5. this public disclaimer and other website terms.

The more specific signed term controls over a general website statement for the same subject, provided the term is lawful.

16. Minimum client acceptance checklist

Before production use, the client should be able to answer yes to each applicable item:

  • The approved use case, source set, users, and prohibited uses are documented.
  • The client has named the system owner, privacy owner, security owner, and professional reviewer.
  • The room, rack, locks, visitor access, transport, and asset inventory are controlled.
  • Credentials, keys, administrator access, and account-recovery procedures are secured.
  • Power, cooling, fire protection, surge protection, and shutdown procedures are adequate.
  • Backups have been restored and tested, and offline copies are protected.
  • Access boundaries, source traceability, failure behavior, and recovery tests have passed.
  • The client has reviewed privacy, privilege, retention, legal-hold, and professional-duty requirements.
  • Incident contacts, evidence preservation, notification decisions, and escalation paths are documented.
  • Insurance and contractual risk allocation match the value of the equipment, data, and business interruption exposure.
  • Users understand that AI output remains draft work until an authorized person verifies it.
  • The acceptance record identifies open issues, known limitations, and the support period.

17. Questions and review

Technical-scope questions may be sent tomari@aizenagentry.com. Before signing a client agreement, both parties should ask qualified Philippine counsel to review the risk-transfer, limitation, insurance, privacy, privilege, and professional-responsibility terms against the actual deployment.

Philippine legal reference points

  • Civil Code of the Philippines, including Articles 1159, 1170 to 1174, and 1306
  • Data Privacy Act of 2012, Republic Act No. 10173
  • Implementing Rules and Regulations of the Data Privacy Act
  • Cybercrime Prevention Act of 2012, Republic Act No. 10175
  • Electronic Commerce Act of 2000, Republic Act No. 8792
Aizen Agentry

Private knowledge and controlled AI for Philippine law firms.

Offer

Private Off-Grid AI for LawLearn AI

Start

Readiness AuditHow Aizen worksAizen Insights

Connect

Email AizenRequest an audit

DISCLAIMER: Aizen Agentry provides technical design, configuration, installation, testing, and handover only within the signed scope. After custody or acceptance, the client controls physical security, access, power, backups, maintenance, lawful use, and insurance. To the fullest extent permitted by Philippine law, Aizen is not responsible for theft, loss, misuse, unauthorized access, environmental damage, or third-party acts outside its control. Signed agreements and mandatory law prevail.

Editorial StandardsTerms & ConditionsPrivacy PolicyRisk Disclaimer

We use cookies

We use optional analytics cookies to understand how visitors use the site and improve your experience. You can accept or reject analytics cookies. Read ourPrivacy Policy.