This is a print-friendly report. Click Print and choose “Save as PDF” in the destination dropdown to download.
SaaSGuard Risk Report
Brex
brex.com
Generated May 4, 2026
Grade D
Score: 46 / 100
Executive summary
We analyzed Brex’s Terms of Service across 8 risk dimensions and found 14 flagged clauses across 7 categories.
Flagged clauses by category
Auto-renewal traps (1)
Severity 3 · notable
“To withdraw the debit authorization from all of your Linked Accounts (including your Brex Business Account), you must provide us 30 days’ notice and pay all amounts owed under your Brex Account, including those set forth in an Order Form, immediately, including Charges (as defined in the Brex Card Program Terms), Fees, Fines, and other amounts.”
Brex requires 30 days' notice to close your account, and you must pay everything you owe immediately, including any outstanding charges and fees.
You can't just stop using Brex and walk away; you have to actively close your account and settle all debts first.
Surprise price hikes (1)
Severity 3 · notable
“We may add new Fees or increase existing Fees upon 30 days' Notice to you, or earlier as provided by applicable Service-Specific Terms.”
Brex can increase fees or add new ones with just 30 days' notice.
Your costs can go up significantly with very little warning, impacting your budget.
Matches Netflix Price Hike Class Action (2023)
Data residency (1)
Severity 3 · notable
“We may share this information with Service Partners and Third-Party Service Providers for these purposes.”
Brex shares your information with partners and third-party providers.
Your sensitive business data could be accessed by multiple external companies.
Matches Irish DPC v. Meta Platforms Ireland — settled for $1300M (2023)
Termination friction (2)
Severity 4 · material
“In addition to the termination rights provided for in Section 3.9 below, Brex has the right to terminate this Platform Agreement at any time and for any reason with thirty (30) days notice to you.”
Brex can terminate your agreement for any reason with 30 days' notice.
Brex can end your service unexpectedly, forcing you to find a new provider on short notice.
Matches PayPal Account Hold / Freeze Class Action — settled for $4M (2021)
Severity 3 · notable
“You may ask us to terminate this Platform Agreement by ceasing to use the Services, paying all amounts owed to Brex (including, but not limited to, all Fee commitments under any Order Form), and providing notice to us. We may decline to terminate this Platform Agreement or close your Brex Account if you have a negative balance in respect of any Service, have Fees that remain owing to Brex under the term of any Order Form, if any funds that we are holding on your behalf are subject to a hold, lien or other restriction, if there are pending transactions, or if we believe that the Brex Account is being closed to evade any legal or regulatory requirement or investigation.”
You can close your account by stopping use and paying all dues, but Brex can refuse to close it if you owe money, have pending transactions, or if they suspect you're trying to evade rules.
Brex can keep your account open and potentially continue charging you if they find any reason to suspect issues.
Liability caps (3)
Severity 4 · material
“Brex’s liability to you is limited with respect to your Brex Account and the Services. Brex is not liable to you for consequential, indirect, special, exemplary, treble or punitive damages or lost profits or revenue, reputational harm, physical injury, or property damage arising from or related to (i) your Brex Account; (ii) Brex’s Services, including Cards and the Brex Empower platform; (iii) your use of or inability to use Services, Cards or the Brex Empower platform, or (iv) this Platform Agreement any other written agreement between you and Brex, including Service Specific Terms and any Order Form(s), and any terms, agreements, or policies incorporated therein by reference, whether or not we were advised of their possibility by you or third parties, unless prohibited by applicable law.”
Brex is not liable for indirect, special, or punitive damages, lost profits, or reputational harm related to your account or their services.
If Brex's service causes you significant financial loss or reputational damage, they won't cover those costs.
Matches Yahoo! Customer Data Security Breach Settlement — settled for $118M (2019)
Severity 4 · material
“BREX DISCLAIMS ALL WARRANTIES AND DOES NOT GUARANTEE THAT (A) SERVICES AND DATA PROVIDED UNDER THIS PLATFORM AGREEMENT ARE ACCURATE OR ERROR-FREE; (B) THE SERVICES WILL MEET YOUR SPECIFIC NEEDS OR REQUIREMENTS; (C) THE SERVICES WILL BE USABLE BY COMPANY, ADMINISTRATORS, OR USERS AT ANY PARTICULAR TIME OR LOCATION; (D) SPECIFIC MERCHANTS WILL PERMIT PURCHASES USING CARDS ISSUED BY AN ISSUER; (E) SERVICES WILL BE UNINTERRUPTED, SECURE, OR FREE FROM HACKING, VIRUSES, OR MALICIOUS CODE; AND (F) ANY DEFECTS IN THE SERVICES WILL BE CORRECTED, EVEN WHEN WE ARE ADVISED OF SUCH DEFECTS.”
Brex disclaims all warranties and does not guarantee that their services are accurate, error-free, or will meet your needs.
You are using Brex's services at your own risk, and they are not responsible if the service is inaccurate or fails.
Severity 4 · material
“Our maximum liability to you arising from or related to (i)-(iv) above is limited to the total amount of Fees actually paid by you to Brex in the twelve months preceding the event that is the basis of your claim. These limitations apply regardless of the legal theory on which your claim is based, unless prohibited by applicable law.”
Brex's total liability to you is capped at the amount of fees you paid them in the 12 months before your claim.
If Brex's mistake costs you more than you paid them last year, you won't be fully compensated for your losses.
Matches Capital One Data Breach Class Action — settled for $190M (2022)
Indemnification (1)
Severity 4 · material
“You agree to indemnify, defend, and hold harmless Brex, Service Partners, and Third-Party Service Providers (including their respective affiliates, directors, employees, agents, and representatives), from and against all losses, liabilities, claims, demands, or expenses, including reasonable attorney’s fees, arising out of or related to any third party claims alleging or involving: (i) Company or an Entity’s breach or alleged breach of this Platform Agreement or any other agreements with Brex; (ii) acts or omissions of Users or other persons associated with Company or Entity that violate a contractual or legal obligation owed to Brex or others; or (iii) Company’s or an Entity’s actual or alleged infringement of a third party’s intellectual property rights.”
You must defend Brex against any third-party claims that arise from your breach of agreement, your actions, or your infringement of intellectual property rights.
You could be responsible for paying legal fees and damages if a third party sues Brex because of something you did.
Matches T-Mobile Data Breach Settlement — settled for $350M (2022)
Right to silently change terms (5)
Severity 4 · material
“We may eliminate, amend, or add to Service-Specific Terms at any time subject to any provisions governing termination or amendments.”
Brex can change the specific terms for individual services at any time.
The rules for specific Brex features can be altered without a full agreement amendment, creating uncertainty.
Matches X Corp. Verified User Class Action (2024)
Severity 4 · material
“We may update the lists of Prohibited Activities or Restricted Activities at any time by posting a revised version to our website. The revised version will be immediately effective upon posting and it is your responsibility to ensure you do not violate these terms.”
Brex can update its lists of prohibited or restricted activities at any time by posting them online, and you must check them regularly.
You could unknowingly violate Brex's rules and face consequences because they changed without direct notification.
Matches Italian DPA (Garante) v. WhatsApp — settled for $6M (2022)
Severity 4 · material
“We may add Services or modify existing Services at any time. Some Services, such as payment-related services, may be provided only by specific Brex entities such as Brex Payments LLC.We do not guarantee that each of the Services will always be offered or available to you. Services will change from time to time, and certain Services may be discontinued.”
Brex can add or modify services at any time, and they don't guarantee that all services will always be available to you.
Services you rely on could be changed or removed with little notice, disrupting your operations.
Matches X Corp. Verified User Class Action (2024)
Severity 4 · material
“Continued use of or access to a Brex Account or any Services, through the actions of any Administrator or User, after any amended Platform Agreement or Service-Specific Terms becomes effective as to you constitutes acceptance of the amended agreement/terms.”
Continuing to use Brex after they update the terms means you accept the new terms, even if you don't actively agree.
You could be bound by new terms you haven't read or don't agree with simply by continuing to use the service.
Matches Italian DPA (Garante) v. WhatsApp — settled for $6M (2022)
Severity 4 · material
“We reserve the right to amend this Platform Agreement and any Service-Specific Terms, including by deleting, modifying, or adding provisions, at any time by posting the amended version of this Platform Agreement or Service-Specific Terms to the Brex website. The amended version will be effective at the time we post it, unless otherwise noted.”
Brex can change the main agreement or specific service terms at any time by posting updates on their website.
The terms governing your use of Brex can be changed unilaterally, and you might not be directly notified.
Methodology
SaaSGuard uses an automated pipeline: a daily Playwright crawler captures each vendor’s public Terms of Service, Privacy Policy, and DPA. Google’s Gemini 2.5 Flash classifies each clause into one of 8 risk categories with a severity score (1–5). Clauses are cross-referenced against a curated database of real lawsuits and FTC actions via embedding-based similarity matching. Grades are computed from per-category max severity; full source code is available on request.