Master SaaS Agreement
The click-through agreement that governs an organization's subscription to the Frostbridge platform.
Frostbridge AI | Legal Terms
Frostbridge AI | Master SaaS Agreement
MASTER SAAS AGREEMENT
This Master SaaS Agreement (the "Agreement") is entered into by and between Frostbridge AI, Inc., a Delaware corporation with offices at 202 S Parker St, Tampa, FL 33606 ("Frostbridge," "Company," "we," "us," or "our"), and the company, organization, or other legal entity on whose behalf the Services are accessed or ordered ("Customer," "you," or "your"). This Agreement governs access to and use of the Frostbridge AI security platform, including related software, hosted services, APIs, dashboards, endpoint agents, connectors, documentation, support, and professional services, if any (collectively, the "Services").
By clicking "I Agree," creating an account, selecting a plan, adding seats, providing payment details, connecting a Customer environment, installing an agent, or otherwise accessing or using the Services, the person taking that action represents that they have authority to bind Customer and agrees to this Agreement on Customer's behalf.
1 Definitions
"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a party.
"Authorized Users" means Customer employees, contractors, consultants, service providers, and other users authorized by Customer to access the Services for Customer's internal business purposes.
"Customer Data" means data, content, credentials, prompts, responses, logs, telemetry, configurations, security findings, metadata, events, files, records, and other information submitted to, uploaded to, generated through, or otherwise processed by the Services on behalf of Customer, including data collected through connectors, APIs, endpoint agents, browser extensions, identity systems, cloud environments, code repositories, communication tools, AI tools, SaaS applications, and other Customer systems.
"Customer Systems" means Customer's devices, endpoints, networks, cloud accounts, SaaS applications, AI workspaces, source code repositories, identity systems, databases, wallets, secrets stores, communication tools, and other environments connected to or monitored by the Services.
"Documentation" means Company's then-current user documentation, technical instructions, onboarding materials, and policy descriptions for the Services.
"Subscription Record" means the electronic record generated or maintained by Company through the Services, checkout flow, billing system, account settings, invoices, receipts, usage records, or written confirmation that reflects Customer's then-current plan, subscription term, billing cycle, number of seats, licensed capacity, usage limits, add-ons, overage rates, fees, payment method, and billing contact. A Subscription Record is not a negotiated amendment to this Agreement and may change from time to time as Customer changes plans, adds or removes seats, enables or disables add-ons, or consumes usage-based features.
"Seat" means an individual Authorized User license, unless the applicable Documentation or Subscription Record defines capacity differently for a specific Service.
"Subscription Term" means the period during which Customer has an active paid, trial, beta, or free subscription to the Services, as reflected in the Services or applicable Subscription Record.
"Usage Data" means operational and technical data about the configuration, use, performance, security, and operation of the Services, excluding Customer Data except in aggregated or de-identified form.
2 Click-Through Acceptance; Electronic Contracting
2.1 Online Acceptance. This Agreement is formed when Customer accepts it electronically, including by clicking an acceptance button or checkbox, creating or using an account, selecting a plan, adding seats, providing payment details, connecting a Customer System, installing Company software, or otherwise accessing or using the Services. The individual accepting this Agreement represents that they are at least 18 years old and have authority to bind Customer. If the individual is accepting for an employer or other entity, "Customer" means that entity.
2.2 Electronic Records and Signatures. Customer agrees to transact electronically and consents to the use of electronic records and electronic signatures for this Agreement, Subscription Records, notices, invoices, amendments, and related records. Customer should download or print a copy of this Agreement for its records. Company may retain evidence of acceptance and subscription changes, including account identifiers, timestamps, IP addresses, user information, accepted version, plan selections, seat changes, payment events, and related logs.
2.3 Precedence. If there is a conflict, the following order of precedence applies: (a) a mutually signed written amendment; (b) the DPA or Security Addendum solely for privacy/security matters; (c) Product-Specific Terms, if any; (d) the applicable Subscription Record solely for commercial details such as plan, Seats, Subscription Term, usage limits, add-ons, fees, payment method, and billing cycle; (e) this Agreement; and (f) Documentation, the AUP, and other incorporated policies. No purchase order, vendor portal term, procurement document, or Customer-provided term will modify this Agreement unless signed by Company.
2.4 Updates to Online Terms. Company may update this Agreement from time to time by posting a new version or providing notice through the Services or by email. Updates will apply to new subscriptions, plan changes, add-ons, and renewals immediately or as stated in the notice, and to existing subscriptions at renewal or after at least thirty (30) days' notice. If an update materially reduces Customer's rights or materially increases Customer's obligations during an active paid Subscription Term, Customer may terminate the affected paid Services by written notice before the update becomes effective and receive a pro rata refund of prepaid unused fees for the terminated portion, unless the update is required by law, security, third-party provider requirements, or to address misuse.
2.5 Standard Online Terms; Subscription Records. This Agreement is intended to be a standard online agreement for customers who subscribe through the Services. Customer-specific commercial details are captured in Subscription Records and in the Services, not in a customer-specific section of this Agreement. Customer agrees that the then-current Subscription Record maintained by Company is the operative record for plan, Seats, usage, Subscription Term, fees, billing cycle, and subscription changes unless Customer can show a material error. Customer is responsible for ensuring that only authorized account owners, administrators, billing managers, or similar users can manage subscriptions, Seats, add-ons, payment methods, and billing settings; their actions bind Customer.
3 Services; Accounts; Support
3.1 Access Rights. Subject to this Agreement and the applicable Subscription Record, Company grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the Subscription Term to access and use the Services solely for Customer's internal business security, governance, compliance, and operational purposes, including monitoring and managing Customer's authorized AI usage, AI agents, data flows, SaaS usage, cloud assets, endpoints, and related security risks.
3.2 Authorized Users. Customer is responsible for all activity under its accounts, credentials, API keys, connectors, and Authorized Users. Customer will keep credentials confidential, promptly disable access for users who no longer need access, and promptly notify Company of any suspected unauthorized access to the Services.
3.3 Connectors, Agents, and Customer Systems. Customer authorizes Company and the Services to access, collect, transmit, analyze, and process Customer Data from Customer Systems that Customer connects, configures, or authorizes. Customer is solely responsible for ensuring it has all rights, permissions, notices, consents, policies, and approvals necessary to connect Customer Systems, deploy endpoint or browser agents, monitor users or devices, inspect AI usage, collect prompts/responses or telemetry, and enable automated actions. Company is not responsible for Customer's internal employment, labor, privacy, works-council, BYOD, sector-specific, or monitoring-law obligations.
3.4 Automated and Recommended Actions. The Services may generate alerts, recommendations, classifications, risk scores, policy suggestions, or automated actions such as blocking, quarantining, notifying, revoking tokens, changing configurations, or initiating workflows. Customer is responsible for configuring approval levels, validating recommendations, and deciding whether to enable or execute any action. Company is not responsible for consequences caused by Customer configurations, approvals, integrations, permissions, or instructions.
3.5 Changes to Services. Company may modify, enhance, suspend, discontinue, or replace features from time to time, provided that Company will not materially reduce the core functionality of paid Services during an active Subscription Term without providing a substantially equivalent replacement or reasonable notice.
3.6 Support. Company will provide support in accordance with the applicable Subscription Record, support plan, or Company's standard support practices. Unless a Subscription Record or separate support plan states otherwise, Company does not commit to specific response times, uptime credits, or service levels.
3.7 Beta and Trial Services. Company may offer beta, preview, free, pilot, trial, or evaluation features ("Beta Services"). Beta Services are optional, experimental, may be changed or discontinued at any time, may not be supported, and are provided "as is" without warranties, indemnities, service levels, credits, or liability obligations beyond those that cannot be excluded by law.
4 Customer Responsibilities and Restrictions
4.1 Permitted Use. Customer will use the Services only in accordance with this Agreement, Subscription Records, Documentation, the Acceptable Use Policy, and applicable laws. Customer will ensure that Authorized Users comply with this Agreement.
4.2 Restrictions. Customer will not, and will not permit any third party to:
- copy, modify, translate, adapt, or create derivative works of the Services, except as permitted in the Documentation;
- reverse engineer, decompile, disassemble, or attempt to discover source code, object code, models, prompts, rules, detection logic, algorithms, or underlying structure of the Services, except to the extent restrictions are prohibited by law;
- use the Services to build or benchmark a competing product or to provide a service bureau, managed security, resale, or MSP offering for third parties unless expressly allowed in Product-Specific Terms or a Subscription Record;
- remove proprietary notices, bypass usage limits, interfere with service integrity, scrape the Services, or conduct security testing except as permitted in Company's written security-testing policy;
- submit malware, exploit code, regulated data, highly sensitive data, or third-party data except as necessary for the intended security use case and only where Customer has legal authority to do so;
- use the Services for unlawful surveillance, discriminatory monitoring, illegal interception, harassment, or unauthorized access to any system or data;
- use the Services in a way that violates export controls, sanctions, AI safety rules, privacy laws, employment laws, or rights of others.
4.3 Customer Environments. Customer is responsible for maintaining Customer Systems, accounts, configurations, network connectivity, identity providers, API permissions, third-party licenses, and endpoint deployment prerequisites. Company is not responsible for failures caused by Customer Systems, third-party platforms, internet outages, misconfigurations, unavailable APIs, rate limits, or revoked permissions.
4.4 Sensitive and Regulated Data. Unless expressly agreed in writing, Customer will not submit data subject to special legal or contractual handling requirements, including payment card data, protected health information, classified data, ITAR-controlled technical data, biometric identifiers, children's data, or data requiring Company to comply with sector-specific laws beyond generally applicable data protection laws. Customer is responsible for using available configuration controls to minimize collection of unnecessary data.
4.5 MSP and Multi-Tenant Use. If Customer is an MSP, MSSP, consultant, reseller, or similar provider, Customer may use the Services for third-party clients only if Product-Specific Terms or the applicable Subscription Record expressly permits multi-tenant or managed-service use. Customer remains responsible for its clients, client permissions, client data, and all activity in client environments.
5 Fees, Taxes, and Payment
5.1 Fees. Customer will pay fees based on the plan, Seats, add-ons, usage, billing cycle, and other commercial details reflected in the applicable Subscription Records and Company's checkout, pricing page, or written confirmation at the time of purchase or change. Fees are non-cancelable and non-refundable except as expressly stated in this Agreement or required by law. Usage above plan limits may result in overage fees, throttling, required plan upgrades, or suspension of excess usage.
5.2 Seat and Plan Changes. Customer may add Seats, increase licensed capacity, enable add-ons, or upgrade plans through the Services. Unless the Services state otherwise, additions and upgrades take effect immediately and may be charged on a prorated basis for the remainder of the then-current billing cycle or Subscription Term. Customer may remove Seats, reduce capacity, disable add-ons, or downgrade plans through the Services; unless the Services state otherwise, reductions take effect at the end of the then-current billing cycle or Subscription Term and do not create refunds or credits for unused time. Customer is responsible for charges incurred by account owners, administrators, billing managers, and other users permitted to manage subscriptions.
5.3 Payment Method and Invoicing. Customer authorizes Company and its payment processors to charge the payment method on file for fees, taxes, renewals, overages, and seat or plan changes. If Company approves invoice billing, invoices are due within thirty (30) days of invoice date unless the applicable Subscription Record states otherwise. Late amounts may accrue interest at 1.5% per month or the maximum rate permitted by law, whichever is lower, plus collection costs.
5.4 Taxes. Fees are exclusive of taxes, levies, duties, VAT, GST, withholding, and similar governmental assessments. Customer is responsible for all taxes associated with the Services other than taxes based on Company's net income. If Customer is required to withhold taxes, Customer will gross up payments so Company receives the full amount invoiced.
5.5 Payment Disputes. Customer must notify Company in writing of any good-faith invoice dispute within thirty (30) days after invoice date and must pay undisputed amounts on time. The parties will work in good faith to resolve disputes promptly.
5.6 Suspension for Nonpayment. Company may suspend or limit Services if amounts are more than ten (10) days overdue after notice, or immediately if payment fails, Customer exceeds credit limits, or Company reasonably believes continued access creates security, legal, or business risk.
6 Customer Data; Privacy; Data Processing
6.1 Ownership of Customer Data. As between the parties, Customer owns Customer Data. Customer grants Company and its Affiliates, personnel, contractors, subprocessors, and service providers a worldwide, non-exclusive right to host, access, use, transmit, process, copy, display, and create technical derivatives of Customer Data as necessary to provide, secure, support, troubleshoot, improve, and operate the Services; comply with law; prevent abuse; and perform this Agreement.
6.2 Data Processing Addendum. If Customer Data includes personal data governed by applicable data protection laws, Company's Data Processing Addendum at /legal/dpa is incorporated into this Agreement. For such personal data, Customer is the controller/business and Company is the processor/service provider, except where applicable law requires another role. Customer is responsible for providing notices, obtaining consents, responding to data subject requests, and establishing a lawful basis for monitoring and processing.
6.3 Security Measures. Company will implement and maintain administrative, technical, and organizational safeguards designed to protect Customer Data against unauthorized access, destruction, loss, alteration, or disclosure. Company's current security measures may be described at /security. Company may update safeguards over time, provided they do not materially reduce overall protection during an active paid term.
6.4 Subprocessors and Third-Party Providers. Customer authorizes Company to use subprocessors and third-party providers, including hosting, infrastructure, telemetry, observability, support, payment, email, analytics, and AI model providers, to provide the Services. Company will remain responsible for subprocessors' processing of Customer Data as required by the DPA. A current subprocessor list should be maintained at /legal/subprocessors.
6.5 AI Model Providers and Training. Unless Customer expressly authorizes otherwise in the Services, a Subscription Record, an SOW, or the DPA, Company will not use Customer Data to train public, general-purpose third-party foundation models. Company may use Customer Data to provide Customer-specific detections, policies, summaries, recommendations, and other Service functionality for Customer.
6.6 Data Export and Deletion. During the Subscription Term, Customer may export Customer Data using available Service functionality. After termination or expiration, Company will make Customer Data available for export for thirty (30) days if reasonably practicable, after which Company may delete or anonymize Customer Data in accordance with its retention practices, except for backups, audit logs, security records, legal records, and data Company is required or permitted to retain.
6.7 Usage Data. Company may collect and use Usage Data to operate, secure, measure, support, improve, and market the Services, and to create aggregated or de-identified analytics. Company will not disclose Usage Data in a manner that identifies Customer as the source unless permitted by this Agreement or Customer consents.
7 AI and Cybersecurity-Specific Disclaimers
7.1 No Security Guarantee. The Services are intended to help detect, prioritize, govern, and respond to security, AI, data, and operational risks. Customer acknowledges that no product can guarantee prevention, detection, containment, or remediation of all unauthorized access, misuse, prompt leakage, shadow AI, malicious AI agents, vulnerabilities, malware, data loss, misconfiguration, insider threats, or other security incidents. Customer remains responsible for its security program, incident response, backups, access controls, legal compliance, and business decisions.
7.2 Probabilistic AI Features. AI-enabled features may generate probabilistic, incomplete, inaccurate, duplicative, or non-unique outputs. Outputs, classifications, summaries, recommendations, and scores are not legal, compliance, financial, or professional advice. Customer must independently review and validate outputs before relying on them or taking action.
7.3 Third-Party Tools and Integrations. The Services may interoperate with third-party products, APIs, platforms, AI tools, cloud providers, identity providers, endpoints, and data sources. Company does not control and is not responsible for third-party services, their availability, changes, pricing, data handling, outputs, terms, security, or Customer's use of them.
7.4 High-Risk Use. Customer may not use the Services as the sole control for life-safety, emergency, critical infrastructure, nuclear, aviation, medical, or other high-risk environments where failure could lead to death, serious injury, severe environmental damage, or catastrophic property damage.
8 Confidentiality
8.1 Confidential Information. "Confidential Information" means non-public information disclosed by one party to the other that is marked confidential or should reasonably be understood as confidential given its nature and circumstances. Company Confidential Information includes the Services, non-public features, roadmap, security architecture, pricing, product plans, models, detection logic, prompts, algorithms, Documentation, and Usage Data. Customer Confidential Information includes Customer Data and non-public information about Customer Systems.
8.2 Protection and Use. The receiving party will use the disclosing party's Confidential Information only to perform this Agreement and will protect it using at least reasonable care. The receiving party may disclose Confidential Information only to personnel, Affiliates, contractors, advisors, subprocessors, and service providers who need to know it and are bound by confidentiality obligations at least as protective as this Agreement.
8.3 Exclusions. Confidential Information does not include information that the receiving party can show: (a) is publicly available without breach; (b) was known without restriction before receipt; (c) was independently developed without use of the Confidential Information; or (d) was lawfully received from a third party without confidentiality restrictions.
8.4 Compelled Disclosure. The receiving party may disclose Confidential Information to the extent required by law, subpoena, or court order, provided it gives reasonable notice if legally permitted and cooperates with efforts to seek confidential treatment.
8.5 Duration. Confidentiality obligations apply during the Term and for five (5) years after disclosure, except that trade secrets and highly sensitive security information remain protected for as long as they remain protected under applicable law.
9 Intellectual Property; Feedback
9.1 Company IP. Company and its licensors own all right, title, and interest in and to the Services, Software, Documentation, models, workflows, agents, connectors, dashboards, detection logic, software, technology, APIs, designs, know-how, improvements, and intellectual property rights. No rights are granted except as expressly stated in this Agreement.
9.2 Customer Outputs. Subject to Company's ownership of Company IP and Customer's obligations under this Agreement, Customer may use reports, findings, alerts, summaries, and other outputs generated by the Services for Customer's internal business purposes. Company does not assign ownership of underlying Company IP, generic recommendations, templates, algorithms, detection logic, or platform improvements.
9.3 Feedback. If Customer provides suggestions, ideas, requests, improvements, or feedback, Company may use them without restriction, attribution, or compensation. Customer grants Company a perpetual, irrevocable, worldwide, royalty-free license to use feedback for any purpose.
9.4 Open Source and Third-Party Components. The Services may include or interoperate with open-source or third-party components subject to separate terms. Nothing in this Agreement limits rights Customer may have under applicable open-source licenses.
10 Term, Renewal, Suspension, and Termination
10.1 Term. This Agreement begins when Customer first accepts it or accesses the Services and continues until all subscriptions expire or are terminated. Each paid subscription continues for the Subscription Term reflected in the Services or applicable Subscription Record.
10.2 Renewal and Cancellation. Unless the applicable Subscription Record states otherwise, paid subscriptions automatically renew for successive terms equal to the expiring term or for the billing cycle selected in the Services. Customer may cancel renewal through the Services or by written notice at least thirty (30) days before the renewal date for annual subscriptions and before the next billing date for monthly subscriptions. Cancellation stops future renewals but does not create refunds for the current Subscription Term unless expressly stated in this Agreement or required by law.
10.3 Termination for Cause. Either party may terminate an affected subscription or this Agreement if the other party materially breaches and fails to cure within thirty (30) days after written notice. Company may terminate or suspend immediately if Customer materially breaches payment, security, usage restrictions, or legal compliance obligations, or if continued access creates material risk.
10.4 Effect of Termination. Upon termination or expiration, Customer's access to the affected Services ends, Customer must stop using Company software and Documentation, and Customer must pay all outstanding amounts. Termination does not relieve Customer of fees accrued before termination. Sections intended to survive will survive, including payment, confidentiality, data retention/deletion, intellectual property, warranty disclaimers, indemnities, limitations of liability, and miscellaneous provisions.
11 Warranties and Disclaimers
11.1 Mutual Authority. Each party represents that it has the legal power and authority to enter into this Agreement.
11.2 Company Warranty. For paid Services, Company warrants that the hosted Services will materially conform to the applicable Documentation during the Subscription Term. Customer's exclusive remedy and Company's sole obligation for breach of this warranty is for Company to use commercially reasonable efforts to correct the nonconformity or, if Company cannot reasonably do so, allow Customer to terminate the affected Subscription Record and receive a pro-rata refund of prepaid unused fees for the affected Services.
11.3 Customer Warranty. Customer represents and warrants that it has all rights, permissions, notices, consents, and authorizations necessary to provide Customer Data, connect Customer Systems, install agents, monitor Authorized Users and devices, use the Services, and permit Company to process Customer Data as described in this Agreement.
11.4 Disclaimer. EXCEPT AS EXPRESSLY STATED IN THIS AGREEMENT, THE SERVICES, SOFTWARE, DOCUMENTATION, OUTPUTS, BETA SERVICES, SUPPORT, AND PROFESSIONAL SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW, COMPANY DISCLAIMS ALL WARRANTIES, EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, AVAILABILITY, SECURITY, ERROR-FREE OPERATION, AND RESULTS. COMPANY DOES NOT WARRANT THAT THE SERVICES WILL DETECT OR PREVENT ALL SECURITY INCIDENTS, MISUSE, VULNERABILITIES, AI RISKS, OR DATA LOSS.
12 Indemnification
12.1 Company IP Indemnity. For paid Services, Company will defend Customer against any third-party claim alleging that Customer's authorized use of the Services infringes a U.S. patent, copyright, or trademark, or misappropriates a trade secret, and will pay damages and costs finally awarded or settlements approved by Company. Company has no obligation for claims arising from: Customer Data or Customer Systems; third-party products; Customer instructions or specifications; modifications not made by Company; combinations not provided by Company; use outside this Agreement; continued allegedly infringing use after Company provides a workaround; open-source components; Beta Services; or free/trial use.
12.2 IP Remedies. If the Services may be or are alleged to be infringing, Company may, at its option: (a) procure the right for Customer to continue use; (b) modify or replace the Services to be non-infringing without materially reducing functionality; or (c) terminate the affected Services or subscription and refund prepaid unused fees for the terminated portion.
12.3 Customer Indemnity. Customer will defend Company and its Affiliates, personnel, contractors, officers, directors, service providers, and licensors against third-party claims arising from: Customer Data; Customer Systems; Customer's use of the Services; Customer's violation of law or this Agreement; Customer's monitoring, employee, user, client, or third-party consent obligations; Customer's configurations, instructions, automated actions, or approvals; or allegations that Customer lacked rights to provide data, connect systems, monitor users, or deploy agents. Customer will pay damages, costs, and reasonable attorneys' fees finally awarded or settlements approved by Customer.
12.4 Procedure. The indemnified party must promptly notify the indemnifying party, provide reasonable assistance, and allow the indemnifying party to control the defense and settlement. Failure to give prompt notice relieves obligations only to the extent prejudiced. The indemnifying party may not settle a claim in a manner that admits fault or imposes non-monetary obligations on the indemnified party without prior written consent, not to be unreasonably withheld.
13 Limitation of Liability
13.1 Exclusion of Damages. TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, PUNITIVE, OR ENHANCED DAMAGES, OR FOR LOST PROFITS, LOST REVENUE, LOST GOODWILL, BUSINESS INTERRUPTION, LOSS OF DATA, COST OF SUBSTITUTE SERVICES, OR SECURITY INCIDENT REMEDIATION COSTS, WHETHER IN CONTRACT, TORT, STRICT LIABILITY, OR OTHERWISE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
13.2 General Cap. EXCEPT FOR EXCLUDED CLAIMS, EACH PARTY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT WILL NOT EXCEED THE AMOUNTS PAID OR PAYABLE BY CUSTOMER TO COMPANY FOR THE AFFECTED SERVICES IN THE TWELVE (12) MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY. FOR FREE, TRIAL, OR BETA SERVICES, COMPANY'S TOTAL LIABILITY WILL NOT EXCEED ONE HUNDRED U.S. DOLLARS (US $100).
13.3 Enhanced Security/Confidentiality Cap. For claims arising from Company's breach of Section 6.3 (Security Measures) or Section 8 (Confidentiality), Company's total aggregate liability will not exceed two (2) times the amounts paid or payable by Customer to Company for the affected Services in the twelve (12) months before the event giving rise to liability, unless a Subscription Record states a different cap.
13.4 Excluded Claims. The liability caps do not apply to Customer's payment obligations, Customer's breach of usage restrictions, either party's indemnification obligations, infringement or misappropriation of Company IP, or liability that cannot be limited by law. The exclusions of damages in Section 13.1 apply to all claims, including excluded claims, to the extent permitted by law.
14 Compliance; Export; Sanctions
14.1 Compliance with Laws. Each party will comply with laws applicable to its performance under this Agreement. Customer is responsible for laws applicable to Customer Data, Customer Systems, Authorized Users, monitoring, employment, procurement, sector-specific regulation, and Customer's use of the Services.
14.2 Export and Sanctions. Customer may not access or use the Services in violation of U.S. or other applicable export control, sanctions, or anti-corruption laws. Customer represents that it and its Authorized Users are not located in, organized under the laws of, or ordinarily resident in a sanctioned jurisdiction; are not on any denied-party list; and are not owned or controlled by any sanctioned person or entity.
14.3 Government Use. The Services and Documentation are commercial products developed solely at private expense. If Customer is a government entity or contractor, the Services are provided with only the commercial rights granted in this Agreement.
15 Professional Services
15.1 Statements of Work. Company may provide implementation, onboarding, integration, training, custom configuration, or other professional services under a written statement of work or in-product professional-services purchase ("Professional Services"). Company will perform Professional Services in a professional and workmanlike manner.
15.2 Deliverables. Unless a written statement of work expressly states otherwise, Company owns all deliverables, configurations, scripts, templates, workflows, know-how, and materials created in connection with Professional Services, and Customer receives a limited right to use them solely with the Services during the Subscription Term.
15.3 Customer Dependencies. Customer will provide timely cooperation, access, information, approvals, credentials, personnel, and systems needed for Professional Services. Company is not responsible for delays or failures caused by Customer dependencies.
16 Publicity
16.1 Customer Name and Logo. Company may identify Customer as a customer and use Customer's name and logo in customer lists, pitch decks, websites, and marketing materials, unless Customer opts out by written notice to legal@frostbridge.ai. Any press release, case study, or detailed public reference requires Customer's prior approval.
17 Miscellaneous
17.1 Assignment. Customer may not assign or transfer this Agreement without Company's prior written consent, except to a successor in connection with a merger, reorganization, or sale of substantially all assets if the successor is not a competitor of Company and assumes all obligations. Company may assign this Agreement to an Affiliate or successor in connection with a merger, reorganization, financing, change of control, or sale of substantially all assets.
17.2 Notices. Company may provide notices through the Services, by email to Customer's account or billing contact, or by posting to Company's website. Legal notices to Company must be sent to legal@frostbridge.ai and 202 S Parker St, Tampa, FL 33606, USA. Notices are deemed given when delivered, when electronically confirmed, or, for posted notices, when made available.
17.3 Governing Law; Venue. This Agreement is governed by the laws of the State of Delaware, excluding conflict-of-law rules. The parties consent to exclusive jurisdiction and venue in the state and federal courts located in Delaware for disputes arising out of or relating to this Agreement. Either party may seek injunctive or equitable relief in any court of competent jurisdiction to protect intellectual property, Confidential Information, or security interests.
17.4 Force Majeure. Neither party is liable for delay or failure to perform caused by events beyond its reasonable control, including natural disasters, war, terrorism, labor disputes, government actions, internet or utility failures, cloud provider outages, cyberattacks, epidemics, supply shortages, or other force majeure events. This does not excuse Customer's payment obligations.
17.5 Independent Contractors. The parties are independent contractors. This Agreement does not create a partnership, agency, joint venture, fiduciary, franchise, or employment relationship.
17.6 No Waiver; Severability. Failure to enforce a provision is not a waiver. If any provision is unenforceable, it will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions will remain in effect.
17.7 Entire Agreement. This Agreement, Subscription Records, the DPA, Security Addendum, AUP, Product-Specific Terms, and incorporated online policies are the entire agreement between the parties regarding the Services and supersede all prior or contemporaneous agreements on that subject. Any waiver or amendment must be in writing and signed by both parties, except for online updates permitted by this Agreement and subscription changes made through the Services. Customer purchase orders, vendor portal terms, or procurement terms are rejected and have no effect even if accepted for administrative convenience.
17.8 Interpretation. Headings are for convenience only. "Including" means "including without limitation." The word "or" is not exclusive. A reference to "written" or "in writing" includes electronic form. This Agreement will be interpreted fairly and not against either party as drafter.
EXHIBIT A
ACCEPTABLE USE POLICY
This Acceptable Use Policy is incorporated into the Agreement. Customer must not use the Services, and must not permit any third party to use the Services, to engage in any activity that Company reasonably believes is unlawful, harmful, abusive, or inconsistent with the purpose of the Services.
- Unauthorized access: accessing, scanning, monitoring, testing, or collecting data from systems, users, devices, accounts, or third-party services without proper authorization.
- Abuse or harm: transmitting malware, exploit code, spam, phishing content, credential theft, harmful automation, or content designed to bypass security or privacy controls, except for authorized defensive testing in accordance with Documentation and law.
- Platform interference: disrupting, overloading, probing, scraping, reverse engineering, or impairing the Services or attempting to bypass rate limits, metering, authentication, or security controls.
- Unlawful monitoring: using the Services for surveillance, employee monitoring, AI monitoring, or device monitoring without required legal authority, notices, consents, or approvals.
- Illegal or regulated data: submitting data that Customer is not legally permitted to process through the Services or data requiring special contractual terms not agreed by Company.
- Model or AI misuse: using AI features to generate or facilitate unlawful content, unauthorized access, credential theft, evasion of security controls, or harmful automation.
- Resale/MSP misuse: using the Services for third parties or client environments unless Product-Specific Terms or a Subscription Record expressly authorizes that use.
Company may investigate suspected violations and may suspend or restrict access where reasonably necessary to protect the Services, Company, Customer, users, or third parties.
EXHIBIT B
SUPPORT AND SERVICE LEVEL TERMS
Unless a Subscription Record includes a separate support plan or SLA, the following default terms apply.
B.1 Support Channels. Customer may submit support requests through the support channels made available by Company, such as in-product support or support@frostbridge.ai. Company will use commercially reasonable efforts to respond during normal business hours.
B.2 No Default SLA Credits. Unless a Subscription Record or separate support plan expressly includes uptime commitments and service credits, the Services do not include service-level credits. Company will use commercially reasonable efforts to maintain availability, excluding planned maintenance, emergency maintenance, Customer-caused issues, third-party services, force majeure events, beta features, and misuse.
B.3 Maintenance. Company may perform maintenance and updates from time to time. Company will use reasonable efforts to provide advance notice of scheduled maintenance likely to materially affect paid Services.
B.4 Customer Cooperation. Customer will provide information reasonably needed to diagnose issues, including logs, configurations, reproduction steps, screenshots, affected users, affected systems, and permission to access relevant environments where necessary.
