Milemarker added terms for AI tools that access client data.
In August 2026, Milemarker added a new article to its Terms & Conditions on third-party systems that connect to or retrieve client data. It names MCP servers, AI providers such as Anthropic and OpenAI, and BI tools, and adds an indemnification clause.
In September 2026, its Enterprise Security page added a SOC 2 Type II statement, a commitment to notify affected clients within 72 hours of confirming a breach, and a statement that clients can export their data in full.
Its Terms & Conditions also reserve the right to subcontract duties to subcontractors, agents, partners or affiliates.
What Milemarker’s documents say about client data.
Quoted from the current version of each document. The right-hand column shows how many of the 75 vendors we monitor have a matching clause.
Sharing data with third parties
Addressed“Milemarker™ reserves the right to subcontract any of its duties or obligations hereunder (including, without limitation, the provision of any Services) to one or more subcontractors, agents, partners or Affiliates …”
What changed, and when.
Notable changes since monitoring began in April 2026, newest first. Each is written from our automated comparison of the before and after versions, then reviewed by a person.
Added a 72-hour breach notification commitment and SOC 2 statement
Also states encryption in transit and at rest, and that clients can export their data in full, including on exit.
Added an article on third-party and AI systems accessing client data
Covers MCP servers, AI providers such as Anthropic and OpenAI, and BI tools. Adds definitions and an indemnification clause.
+ 6 other updates detected, such as formatting, page layout and wording changes.
- Sep 15, 2026: Enterprise Security
- Sep 15, 2026: Terms & Conditions
- Sep 8, 2026: Enterprise Security
- Sep 4, 2026: Terms & Conditions
- Aug 4, 2026: Privacy Policy
3 Milemarker documents.
Milemarker terms: common questions.
When did Milemarker last change its terms?
Its Enterprise Security page changed on September 4, 2026, adding a 72-hour breach notification commitment. Its Terms & Conditions changed on August 11, 2026, adding an article on third-party systems that access client data.
Does Milemarker’s contract cover AI tools that access client data?
Yes. Since August 2026, its Terms & Conditions include an article on third-party systems, such as MCP servers, AI providers and BI tools, that connect to or retrieve client data.
How quickly does Milemarker say it will report a breach?
Its Enterprise Security page, updated in September 2026, commits to notifying affected clients within 72 hours of confirming a breach involving their data.