Pre-launch preview, Polestar GRC is not live yet. Signups, billing, and email are not operational.
Skip to main content

Legal & Compliance

The documents that govern using Polestar GRC, readable here, downloadable for your records.

Terms of Service
The agreement governing your use of Polestar GRC
Privacy Policy
How we collect, use, and protect your data, including our subprocessors and cookies
Acceptable Use Policy
What you may and may not do with the platform
Refund Policy
When payments are refunded, including the 30-day window for annual plans, and how fast we pay
Business Associate Agreement
For HIPAA covered entities: Polestar GRC as your business associate. Accept it electronically from the BAA Tracker
Subcontractor Business Associate Agreement
For customers that are themselves business associates: Polestar GRC as your subcontractor under 45 CFR 164.504(e)(5)
Data Protection Agreement
For organizations outside HIPAA: Polestar GRC's data protection commitments under state consumer health data and breach laws
Working with PHI? Start with the BAA.

If your organization stores Protected Health Information in the platform, put the right agreement in place before you upload it. Polestar selects the document from your organization's HIPAA role:

In HIPAA mode the platform does not accept new file uploads or incident narrative text until an administrator accepts the agreement, and the prompt that explains the block lets an administrator accept it in place.

  1. Covered entities (providers, health plans, clearinghouses) accept the Business Associate Agreement.
  2. Business associates and their subcontractors accept the Subcontractor Business Associate Agreement.
  3. Organizations outside HIPAA accept the Data Protection Agreement.
  4. Accept it electronically from the BAA Tracker in your dashboard. Your executed copy, with an execution record and document fingerprint, is stored there for download anytime, and we email you a notice with a link to it.

Need a countersigned PDF or changes to the text? Write to legal@polestargrc.com before accepting.

Security, in plain terms
  • Encryption in transit (TLS 1.2 or higher) and at rest (AES-256 on our database volumes, file storage and backups)
  • Role-based, organization-scoped access controls and security audit logging
  • TOTP multi-factor authentication, with org-wide enforcement available
  • Time-limited, access-controlled file links for evidence and reports
  • AI features run only on Anthropic Claude models on Amazon Bedrock in US AWS regions, under our AWS business associate agreement. Text is sent after automated, pattern-based identifier redaction, which can miss identifiers; PDF files and images that AI features analyze are sent as uploaded, without redaction; prompts and outputs are not stored in our AWS account and are not used to train models
  • Security incidents affecting your data: notice without unreasonable delay and no later than 7 calendar days after we discover one
  • Insurance: we do not yet carry general liability, cyber liability or technology errors and omissions insurance in our own name (BAA Section 11.5)

Full details in the Privacy Policy; PHI handling is governed by the BAA, and state-mode data by the Data Protection Agreement. More on our Security page.

Accessibility

We aim for the Web Content Accessibility Guidelines (WCAG) 2.1, Level AA, on this website and in the Polestar GRC app. Polestar GRC does not fully meet it yet. These are the gaps we know of, and we are working on them.

Known limitations

  • Some buttons and drop-down menus in the app have no text label for screen readers: the filter menus on the Activity Log and Compliance Posture pages, the vendor menu on the configuration upload page, the email frequency setting, the policy picker on Compare Versions, and the icon button that cancels a team invitation.
  • Some grey, green and amber text in the app has less contrast than WCAG asks for, for example the times in the Activity Log and the locked rows in the policy library.
  • On the policy pages, bulleted lines are not marked up as lists, so screen readers announce them wrongly.
  • The monthly training calendar scrolls but cannot be reached with the keyboard.
  • The charts that show your score over time have no text description.
  • Some status is shown by color alone, for example the colored edge on summary tiles.
  • The tabs on the Settings page are announced as tabs but do not work like tabs for screen readers.
  • Some actions are icons with no visible text, for example copy, open and revoke on Audit Room cards.
  • On phones, some tables are wider than the screen (the vendor list), the policy outline links are small to tap, and the chat button can cover buttons and text.
  • PDF documents the app creates, such as reports and signed agreements, have not been checked with a screen reader.

Report a problem

If something is hard to use, or you need a document we provide in an accessible format, email support@polestargrc.com and tell us the page and what happened. We reply within one business day, Monday to Friday. If your organization needs our accessibility information for an obligation of its own, ask us at the same address.

Last reviewed October 9, 2026, from an automated check (axe) and a manual review of the app.

Earlier versions
A customer that accepted an earlier version stays bound by it until the newer version takes effect for that customer. Each one is kept here unchanged.

Questions? Contact us.