Legal & disclaimers

Not legal advice. This page summarizes how the MVP is intended to behave. Have counsel review before production use, especially for defense-adjacent listings and international users.

Nature of the service

Parallax is operated as a B2B marketing, discovery, and analytics product. We help organizations surface and compare vendor information and buyer intent signals—we do not broker the sale or transfer of goods, execute government procurements, or act as an exporter, broker, or freight forwarder for controlled items.

The product is a research and discovery surface. It does not process payments for physical products, run procurements on your behalf, or guarantee the accuracy of third-party or ingested data. Listings may be unverified or sourced from public references until a supplier claims and validates content.

Product ingestion, provenance & supplier claims

Product rows may be seeded from operator-curated imports (for example CSV or a single public page fetch), always with a stored source URL or notes where applicable. Ingestion is intended for public pages you have a right to reference—not logins, paywalled extranet content, or bulk scraping that violates site terms or robots.txt. Automated tools in this repo honor User-agent: * rules unless an operator explicitly disables that check for local testing.

Rows without a linked supplier organization appear as unclaimed listings. An authorized supplier admin may claima listing to associate it with their organization, subject to your enforcement and dispute process. Claiming does not by itself make specifications “validated”; platform review and evidence workflows apply separately where implemented.

Data you should not submit

Do not use free-text fields, uploads, or messages to store or transmit classified information, export-controlled technical data you are not authorized to share with our subprocessors, or other material your policies treat as restricted, unless you have a separate written agreement that explicitly covers this platform and those data types.

Export control & compliance

Geographic visibility rules and “government verified” badges are business controls, not export licenses, jurisdiction determinations, or end-user checks. Suppliers remain responsible for lawful marketing of controlled technology. Buyers and governments must follow their own organizational and jurisdictional requirements. Nothing on this site constitutes legal, export, or compliance advice.

Security practices (summary)

We apply standard web application measures appropriate to a SaaS discovery product: authenticated access, security-oriented HTTP headers, TLS in production, bounded session lifetime, rate limiting on sensitive endpoints, optional network restrictions for platform administration, structured audit logging for key operator actions, and upload checks that reduce obviously mismatched file types.

Operator-oriented detail is documented in SECURITY.md in the application source repository (TLS and secrets, optional admin IP allowlisting, webhooks, rate-limit scaling caveats, and subprocessors). For vulnerability reports, use the security contact your organization publishes for this deployment.

Subprocessors & analytics

Depending on configuration, the service may process data through identity (email/password authentication), payments (Stripe), your database and hosting provider, and optional document extraction (e.g. OpenAI). Product analytics and event instrumentation may be used to improve discovery features and to show suppliers aggregate usage. Maintain an accurate subprocessor list for your deployment and privacy disclosures.

AI (when enabled)

Any assistant features are decision support only, grounded in platform data with citations where implemented. Outputs are not official procurement advice—verify with your organization.

The ParallaxAI (verified buyer workspaces with premium access) retrieves a limited keyword snapshot of listings visible to your organization—including validated specifications only when country rules allow—and sends that text to a configured model. Prompt and answer snippets may be logged for abuse monitoring and quota enforcement; do not paste classified or export-controlled technical data into the chat.

Privacy

Sign-in uses email and password credentials. Trial and evaluation requests create structured leads shared with the relevant supplier organization. Minimize sensitive personal data in free-text fields; do not submit classified or unlawfully restricted content.

The public waitlist stores the email and optional fields you submit so we can contact you about early access; we do not sell waitlist data. You can ask to be removed by contacting the operator for your deployment.

For supplier and government workspaces, a sales or onboarding representative may contact you to confirm organization details before accounts are provisioned.