Last updated: January 1, 2026
This Master Services Agreement (“MSA”) governs all Services provided by ThreatGrid. In the event of conflict, the following order of precedence applies: (1) Executed Order Form; (2) Statement of Work (SOW); (3) Service Level Agreement (SLA); (4) Data Processing Addendum (DPA); (5) this MSA.
Services include TLINK tools, APIs, monitoring services, managed security services (MSSP), advisory services, and related technology offerings.
Customer represents and warrants it has lawful authority to test, scan, or monitor any systems submitted to the Services.
Customer shall not use the Services for unlawful, abusive, fraudulent, or malicious purposes, including denial-of-service activity or exploitation attempts without authorization.
API access is subject to rate limits and fair use thresholds. ThreatGrid may throttle, suspend, revoke credentials, or block IP addresses for excessive or abusive usage.
ThreatGrid maintains an information security program aligned with industry best practices. Controls include:
• Encryption in transit
• Role-based access controls
• Logging and monitoring
• Vulnerability management and patching
• Secure development lifecycle practices
• Segregation of customer data where applicable
Enterprise customers may receive uptime commitments as defined in an executed SLA. Service credits are the exclusive remedy for SLA breaches.
ThreatGrid maintains documented continuity and disaster recovery procedures designed to support operational resilience and periodic testing.
Where personal data is processed, a DPA applies. ThreatGrid may utilize subprocessors under contractual data protection obligations consistent with applicable law.
In the event of a confirmed security incident affecting Customer data, ThreatGrid shall notify affected enterprise customers without undue delay and, where applicable, within seventy-two (72) hours of confirmation.
Each party shall protect confidential information using safeguards no less protective than those used to protect its own confidential information.
Customer shall indemnify ThreatGrid against claims arising from unauthorized or unlawful use of Services. ThreatGrid shall indemnify Customer against third-party intellectual property infringement claims caused by the Services.
ThreatGrid maintains commercially reasonable levels of commercial general liability, professional liability, and cyber liability insurance coverage.
Enterprise customers may request reasonable documentation of security controls. On-site audits shall require reasonable notice and must not disrupt operations.
Except for indemnification and confidentiality breaches, aggregate liability shall not exceed fees paid in the twelve (12) months preceding the claim. Neither party shall be liable for indirect or consequential damages.
Customer agrees to comply with applicable export control and sanctions laws. Services may not be used in restricted jurisdictions.
Disputes shall be resolved through binding arbitration unless otherwise required by law. Governing law shall be defined in the applicable Order Form.
Neither party shall be liable for delays or failures due to events beyond reasonable control.
Customer may not assign this Agreement without prior written consent. ThreatGrid may assign in connection with merger or acquisition.
Confidentiality, indemnification, limitation of liability, and dispute resolution provisions survive termination.
This Agreement constitutes the entire agreement between the parties unless superseded by executed enterprise documentation.