Comptroller Guidance scan — Sample Terms of Service
Executive summary
Heuristic compliance review of “Sample Terms of Service” against Comptroller Guidance (Financial / Banking). 4 potential gaps identified. Re-run with AI Gateway enabled for a fuller evidence-based audit.
Decision-support only — review each finding against your compliance layer before acting.
Findings & solutions
- 01highCoverage
Insufficient source coverage
The extracted target text is short, so omissions may be overstated and coverage limited.
Analyzed ~266 characters from Sample Terms of Service.
Recommended solution
Provide a fuller document (complete policy, contract, or multi-page site section) and re-run the scan.
- 02highPrivacy
Limited privacy / personal data disclosure
The target text does not clearly address personal data handling relative to the selected compliance layer. Framework: Comptroller Guidance.
Related guidance: Comptroller Guidance
Recommended solution
Add a clear privacy section covering data categories, purposes, retention, and contact paths for requests.
- 03mediumSecurity
Security commitments underspecified
Security controls or incident response commitments are not clearly described. Framework: Comptroller Guidance.
Related guidance: Comptroller Guidance
Recommended solution
Summarize access control, encryption, monitoring, and incident notification expectations without overclaiming.
- 04infoSystem
Heuristic mode active
AI Gateway analysis was unavailable, so this report used rule-based gap detection against the selected compliance layer.
Recommended solution
Configure Vercel AI Gateway (OIDC or AI_GATEWAY_API_KEY) for deeper, evidence-grounded findings.
Source excerpt analyzed
These Terms of Service govern use of our banking app. We may change these terms at any time without notice. Fees may apply. We are not responsible for any losses. Your data may be shared with partners. Governing law is Delaware. Contact support@example.com for help.