Express Underwriter: Terms of Use Policy

Effective Date: December 4, 2025

Jurisdiction: State of Maryland, United States

Operator: Express Underwriter, Inc. (referred to as "Company," "we," "us," or "our")

1. Acceptance and Scope of Service

1.1. Agreement to Terms

By accessing or using the Express Underwriter platform, including all related APIs, mobile applications, and software services (collectively, the "Service"), you ("User," "Client," or "you") agree to be bound by these Terms of Use ("Terms"). If you are accepting these Terms on behalf of an entity, you represent and warrant that you have the authority to bind that entity to these Terms. IF YOU DO NOT AGREE TO THESE TERMS, YOU MAY NOT ACCESS OR USE THE SERVICE.

1.2. Purpose of Service

The Service is a specialized financial software platform designed to facilitate the application and underwriting process for commercial loans, including Small Business Administration (SBA) loans, by connecting Borrower clients with Lender clients. The Service provides tools for secure data ingestion, validation, and a structured decision-support workflow. THE SERVICE IS A TECHNOLOGY PLATFORM AND NOT A LENDER OR FINANCIAL ADVISOR. We do not issue loans or provide financial advice, and any suggested decision or outcome is purely the result of automated processing integrity and risk-scoring analysis.

1.3. Eligibility and Licensing Disclosure

  • Capacity: The Service is available only to individuals who can form legally binding contracts under applicable law and are at least 18 years of age.
  • Regulatory Compliance (Maryland): Where required by the Maryland Financial Institutions Article or other applicable statutes (for example, as a sales finance company or mortgage broker), the Company or the respective Lender client shall conspicuously display its unique identifier and a link to the NMLS Consumer Access website on the website and within the software application.

2. Data and Content Ownership, License, and Restrictions

2.1. Client Data Ownership

As between the parties, you (or your respective organization) retain all ownership rights and Intellectual Property Rights in and to all data, content, and information you submit to the Service, including PII, SPI, and Application Data ("Client Data"). Client Data specifically includes all financial information and PII (for example, EIN, SSN) provided in the borrowers and applications collections of the Service's database schema.

2.2. License to Client Data (Limited Scope)

You grant the Company a worldwide, royalty-free, and non-exclusive license to use, copy, transmit, store, and display the Client Data solely as necessary to:

  • Provide, maintain, and improve the Service.
  • Facilitate and complete the requested loan underwriting and matching services.
  • Comply with legal, audit, and regulatory requirements, including the mandatory retention and archiving of audit logs.

This license does NOT grant the Company the right to sell, sublicense, or publicly exploit Client Data (especially Application Data) for marketing or third-party commercial purposes outside of the core Service function and anonymized aggregation.

2.3. Data Segregation (Multi-Tenancy)

You acknowledge that the Service operates on a multi-tenant SaaS architecture (Enhanced Strategy A). While data is physically housed in a shared or logically separated database (assignedDatabaseId), the Service employs strict, role-based access controls and Security Rules to ensure that your Client Data is logically isolated and accessible only by authorized users within your assigned organizationId.

3. Data Security, Privacy, and Confidentiality

3.1. SOC 2 and Security Architecture

The Company maintains security controls and operational procedures aligned with the SOC 2 Type II Trust Services Criteria, specifically Security, Availability, Confidentiality, and Processing Integrity.

3.2. Encryption of Sensitive Data

You understand and agree that, in compliance with SOC 2 requirements for Confidentiality, the Service employs encryption for specific fields of Sensitive Personal Information (SPI) and Personally Identifiable Information (PII) at rest. This includes, but is not limited to, tax identification numbers (ein), social security numbers (ssn), and third-party financial access tokens (plaidAccessToken, intuitAccessToken). While data transfer over networks may involve interim processing steps, SPI and PII are never permanently stored in plaintext.

3.3. Immutable Audit Logs

You acknowledge and agree that your actions and transactions within the Service (including creation, update, deletion, and viewing of core entity data) are recorded in an immutable audit trail (activity_logs). These logs are subject to a Write Once, Read Many (WORM) policy and are automatically archived to secured cloud storage with a defined retention policy to meet regulatory non-repudiation requirements.

4. Third-Party Financial Integrations

4.1. Account Connection and Authorization

The Service provides optional integration features with third-party financial data aggregators (for example, Plaid, Intuit) to automatically retrieve, verify, and incorporate financial data into loan applications (plaid_connections, intuit_connections). By using these features, you expressly authorize the Company to access and retrieve your financial information from the Integration Providers' servers on your behalf, and you agree to abide by the Integration Providers' respective terms of service.

4.2. Disclaimer of Integration Accuracy

THE COMPANY IS NOT RESPONSIBLE FOR THE ACCURACY, COMPLETENESS, OR TIMELINESS OF DATA RETRIEVED FROM INTEGRATION PROVIDERS. We provide the data "as is" and disclaim all liability for any loan decision or underwriting outcome based on inaccurate or incomplete data received from an Integration Provider.

4.3. User Indemnification for Third-Party Claims

You agree to indemnify, defend, and hold harmless the Company against any third-party claims, liabilities, damages, or expenses (including reasonable attorneys' fees) arising out of or related to:

  • Your breach of any agreement with an Integration Provider (for example, Plaid, Intuit).
  • Any claim that your provision of third-party account credentials or data to the Service violates the rights of any third party or Integration Provider.

5. Warranties, Disclaimers, and Limitation of Liability

5.1. Limited Warranty

The Company warrants that the Service will perform materially in accordance with its published documentation and maintain the security and confidentiality standards defined in Section 3.

5.2. General Disclaimer

EXCEPT FOR THE LIMITED WARRANTY ABOVE, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE," without warranty of any kind, express or implied, including, but not limited to, the implied warranties of merchantability, fitness for a particular purpose, or non-infringement. We make no warranty that the Service will be uninterrupted, timely, secure, or error-free.

5.3. Disclaimer of Loan Outcome

WE DO NOT WARRANT OR GUARANTEE ANY SPECIFIC LOAN OUTCOME, APPROVAL, OR FUNDING. The Service's decision support or approval status is strictly a technical assessment based on the input data and specified lending criteria and does not constitute a legal or binding offer to lend by any Lender or the Company.

5.4. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, IN NO EVENT SHALL THE COMPANY BE LIABLE FOR ANY INDIRECT, PUNITIVE, INCIDENTAL, SPECIAL, OR CONSEQUENTIAL DAMAGES arising out of or in any way connected with the use of the Service, whether based in contract, tort, strict liability, or otherwise, even if the Company has been advised of the possibility of such damages. THE TOTAL LIABILITY OF THE COMPANY TO YOU FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THESE TERMS SHALL NOT EXCEED THE AMOUNT PAID BY YOU TO THE COMPANY FOR THE SERVICE IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM.

6. General Provisions

6.1. Governing Law

These Terms shall be governed by, and interpreted and enforced in accordance with, the laws of the State of Maryland, without regard to its conflict of law principles.

6.2. Dispute Resolution

Any dispute, claim, or controversy arising out of or relating to these Terms or the Service shall be subject to the exclusive jurisdiction of the state and federal courts located in Anne Arundel County, Maryland.

6.3. Termination

We may terminate or suspend your access to the Service immediately, without prior notice or liability, for any reason whatsoever, including without limitation if you breach the Terms. Upon termination, your right to use the Service will immediately cease.

6.4. Entire Agreement and Severability

These Terms, along with the Privacy Policy and any applicable Service Level Agreements (SLAs), constitute the entire agreement between you and the Company with respect to the Service. If any provision of these Terms is deemed invalid or unenforceable by a court of competent jurisdiction, the remaining provisions will remain in effect.