ThreatGrid Logo

Master Services Agreement

Last updated: January 1, 2026

1. Contract Structure

This Master Services Agreement (“MSA”) governs all Services provided by ThreatGrid. In the event of conflict, the following order of precedence applies: (1) Executed Order Form; (2) Statement of Work (SOW); (3) Service Level Agreement (SLA); (4) Data Processing Addendum (DPA); (5) this MSA.

2. Scope of Services

Services include TLINK tools, APIs, monitoring services, managed security services (MSSP), advisory services, and related technology offerings.

3. Authorized Use & Legal Compliance

Customer represents and warrants it has lawful authority to test, scan, or monitor any systems submitted to the Services.

4. Acceptable Use Policy

Customer shall not use the Services for unlawful, abusive, fraudulent, or malicious purposes, including denial-of-service activity or exploitation attempts without authorization.

5. API Usage & Rate Limits

API access is subject to rate limits and fair use thresholds. ThreatGrid may throttle, suspend, revoke credentials, or block IP addresses for excessive or abusive usage.

6. Security Program & Controls

ThreatGrid maintains an information security program aligned with industry best practices. Controls include:

• Encryption in transit
• Role-based access controls
• Logging and monitoring
• Vulnerability management and patching
• Secure development lifecycle practices
• Segregation of customer data where applicable

7. Service Levels

Enterprise customers may receive uptime commitments as defined in an executed SLA. Service credits are the exclusive remedy for SLA breaches.

8. Business Continuity & Disaster Recovery

ThreatGrid maintains documented continuity and disaster recovery procedures designed to support operational resilience and periodic testing.

9. Data Processing & Subprocessors

Where personal data is processed, a DPA applies. ThreatGrid may utilize subprocessors under contractual data protection obligations consistent with applicable law.

10. Breach Notification

In the event of a confirmed security incident affecting Customer data, ThreatGrid shall notify affected enterprise customers without undue delay and, where applicable, within seventy-two (72) hours of confirmation.

11. Confidentiality

Each party shall protect confidential information using safeguards no less protective than those used to protect its own confidential information.

12. Indemnification

Customer shall indemnify ThreatGrid against claims arising from unauthorized or unlawful use of Services. ThreatGrid shall indemnify Customer against third-party intellectual property infringement claims caused by the Services.

13. Insurance

ThreatGrid maintains commercially reasonable levels of commercial general liability, professional liability, and cyber liability insurance coverage.

14. Audit Rights

Enterprise customers may request reasonable documentation of security controls. On-site audits shall require reasonable notice and must not disrupt operations.

15. Limitation of Liability

Except for indemnification and confidentiality breaches, aggregate liability shall not exceed fees paid in the twelve (12) months preceding the claim. Neither party shall be liable for indirect or consequential damages.

16. Export Compliance

Customer agrees to comply with applicable export control and sanctions laws. Services may not be used in restricted jurisdictions.

17. Arbitration & Governing Law

Disputes shall be resolved through binding arbitration unless otherwise required by law. Governing law shall be defined in the applicable Order Form.

18. Force Majeure

Neither party shall be liable for delays or failures due to events beyond reasonable control.

19. Assignment

Customer may not assign this Agreement without prior written consent. ThreatGrid may assign in connection with merger or acquisition.

20. Survival

Confidentiality, indemnification, limitation of liability, and dispute resolution provisions survive termination.

21. Entire Agreement

This Agreement constitutes the entire agreement between the parties unless superseded by executed enterprise documentation.