Audit Otter Provider-Specific Terms
Last updated: September 1, 2026
These Provider-Specific Terms apply to the Audit Otter application offered by Abrega Inc. through the Atlassian Marketplace. They supplement the Bonterms Standard End User Agreement (Version 1.0) adopted for the applicable listing. Capitalized terms not defined here have the meanings given in that agreement.
1. Provider and product
The provider is Abrega Inc., doing business as Audit Otter. The product is the Audit Otter cloud application for Atlassian Jira and Confluence, including its compliance-program, evidence, policy, questionnaire, risk, vendor, audit, integration, and Trust Center features, as described in the Documentation. Provider notice: legal@auditotter.com.
2. Governing law and courts
For purposes of Section 19.2 of the Standard Agreement, Governing Law means the laws of the State of Delaware, without regard to its conflict-of-law rules. Courts means the state and federal courts located in Delaware.
3. Subscription and feature availability
The applicable Order and Documentation identify the features included in a Subscription. If Provider permits use without a paid Marketplace license, that use is limited to the features identified as available without charge. Provider currently identifies CAIQ Lite and the CAIQ-focused Trust Center as available without a paid license. SOC 2, ISO/IEC 27001, and other paid features require the applicable paid Marketplace license.
Provider may add features to the no-charge offering. Provider may discontinue or materially reduce a no-charge feature on reasonable prior notice, but that change will not reduce features included in a then-current paid Subscription.
4. Compliance outputs and customer review
The Product organizes information, evaluates configured checks, prepares drafts, and helps Customer manage compliance work. Auditors, certification bodies, customers, regulators, and other independent parties determine whether Customer satisfies their requirements. The Product does not guarantee an audit result, certification, attestation, regulatory determination, security outcome, or acceptance of a questionnaire response.
Customer is responsible for reviewing and approving evidence, mappings, policies, questionnaire responses, risk decisions, Trust Center disclosures, and other Product output before relying on or publishing it. The Product and Documentation do not provide legal, audit, accounting, certification, or other professional advice. This Section does not limit the Performance Warranty in Section 6.2 of the Standard Agreement.
5. Atlassian Rovo
The Product may provide a user-initiated action that opens or pre-populates Atlassian Rovo using information selected from Customer's Audit Otter workspace. Rovo is an Atlassian service made available under Customer's agreement with Atlassian. Provider does not operate Rovo or select its underlying model providers. Customer controls Rovo through Atlassian administration settings. The Documentation identifies the information an Audit Otter action sends to Rovo and applicable limits.
For clarity, the Bonterms Standard AI Addendum is not incorporated into the Agreement. This Section does not reduce Provider's responsibility for the Audit Otter functionality that selects and transmits information to Rovo.
6. Data Processing Agreement
The Audit Otter Data Processing Agreement is incorporated into the Agreement and applies when Provider processes personal data on Customer's behalf. The DPA controls in a conflict concerning data-protection matters. A separately signed DPA controls instead of the published DPA.
7. Security measures
The technical and organisational measures in Annex 2 of the DPA are the Security Measures for purposes of Section 3.2 of the Standard Agreement.
8. Support and SLA
Customer may request Support through the Audit Otter support portal. No Service Level Agreement applies unless Provider expressly identifies one in the Listing, an Order, or a written agreement signed by the parties.
9. Order of precedence
These Provider-Specific Terms and the DPA are Provider-Specific Terms under the Standard Agreement. The order of precedence in Section 1.4 of the Standard Agreement applies, subject to the DPA's precedence for data-protection matters.