Adaptive Master Subscription Agreement
Last Updated: 09/04/2026
This Master Subscription Agreement (“MSA”) is entered into between TeamGuard AI, Inc. d/b/a Adaptive Security (“Adaptive”) and the entity or individual identified on the applicable Order Form (“Customer” and, together with Adaptive, the “Parties”, each a “Party”). This MSA is effective as of the date of last signature on the first Order Form between the Parties (the “Effective Date”).
This MSA, each mutually executed ordering document that references it (each, an “Order Form”), the Product Exhibits attached to this MSA (each, a “Product Exhibit”), the DPA if applicable (defined below), and any other document signed by both Parties that incorporates this MSA together constitute the “Agreement”. If there is a conflict among these documents, the following order of precedence applies, in each case solely to the extent of the conflict: (1) the Order Form; (2) the applicable Product Exhibit (as to the product it covers); (3) the body of this MSA; and (4) the DPA if applicable (except that, where it applies, the DPA controls as to the processing of Personal Information).
1. Definitions.
“Authorized Users” means the employees and independent contractors of Customer (and, if specified in an Order Form, of Customer’s affiliates) whom Customer authorizes to access and use the Platform.
“Customer Information” means all data, content, and materials uploaded, submitted, or otherwise provided by or on behalf of Customer or its Authorized Users to the Platform, or collected or received by Adaptive for Customer under the Agreement, including Customer Inputs (defined in Section 2.4) and any Personal Information contained in the foregoing.
“Documentation” means Adaptive’s then-current user documentation describing the features and functionality of the Platform.
“DPA” means the data processing addendum, if any, that applies under Section 4.2, which is incorporated into the Agreement by this reference.
“Personal Information” means information processed under the Agreement that identifies or can reasonably be used to identify an individual and, if a DPA applies, as further defined in the DPA. Business contact information of Customer personnel used to administer the Agreement is not by itself Personal Information.
“Order Form” means each mutually executed ordering document that references this MSA.
“Platform” means the Adaptive products, services, and platforms identified in an Order Form or otherwise provided by Adaptive to Customer under the Agreement, including the products described in the Product Exhibits and the Documentation.
“Product Exhibit” means each product-specific exhibit attached to this MSA, including Exhibit A (Security Awareness Training Products), Exhibit B (Email Security Product), and Exhibit C (AI Governance Products).
“Term” means the period commencing on the Effective Date and continuing until the expiration or termination of all Order Forms, as further described in Section 7.1.
2. Platform Access and Use.
2.1 License. Subject to this Agreement, Adaptive grants Customer a non-exclusive, non-transferable (except as permitted in Section 13.3), non-sublicensable license during the Term to access and use the Platform identified in each Order Form solely for Customer’s internal business purposes and subject to any usage limits set forth in the applicable Order Form.
2.2 Product Exhibits. If Customer purchases access to the products described in a Product Exhibit, the terms of that Product Exhibit apply to Customer’s access and use of those products: Exhibit A (Security Awareness Training Products); Exhibit B (Email Security Product); and Exhibit C (AI Governance Products). Each product described in a Product Exhibit is part of the Platform for all purposes under the Agreement.
2.3 Restrictions. Customer shall not, and shall not permit any third party to: (a) copy, modify, translate, or create derivative works of the Platform; (b) reverse engineer, decompile, or otherwise attempt to derive the source code, underlying ideas, or algorithms of the Platform, except to the extent this restriction is prohibited by applicable law; (c) sell, resell, rent, lease, or otherwise make the Platform available to anyone other than Authorized Users; (d) interfere with or disrupt the integrity or performance of the Platform or attempt to gain unauthorized access to the Platform or its related systems; (e) use the Platform in violation of applicable law or third-party rights; (f) access the Platform to benchmark it for publication, build a competitive product or service, or copy its features or user interface; or (g) use the Platform to harass, cause harm to, or violate the rights of any third party.
2.4 Customer Inputs; Platform Outputs. Customer may submit content to be processed by the Platform (“Customer Inputs”) and receive outputs generated by the Platform (“Platform Outputs”). Customer is responsible for its Customer Inputs and its use of Platform Outputs, and should review Platform Outputs and exercise its own judgment before relying on them.
2.5 Authorized Users; Credentials. Customer is responsible for its Authorized Users’ compliance with the Agreement and for safeguarding access credentials. Any act or omission of an Authorized User that would breach the Agreement if taken by Customer is deemed Customer’s breach. Customer authorizes Adaptive to administer Customer’s and its Authorized Users’ accounts as reasonably needed to operate and secure the Platform and comply with law.
2.6 Support. Adaptive will provide standard support for the Platform via support@adaptivesecurity.com.
2.7 Availability. Adaptive will use commercially reasonable efforts to make the Platform available during the Term, excluding scheduled maintenance and unavailability caused by Force Majeure Events, third-party networks or services including telecommunications carrier restrictions applicable to SMS and voice features, internet or network issues between Adaptive and Customer, email or SMS delivery delays, misuse or unauthorized use of the Platform, Customer’s fraud, gross negligence, or willful misconduct, or Customer’s or its Authorized Users’ acts, omissions, or breach of the Agreement.
2.8 Third-Party Services. The Platform may connect to third-party products or services that Customer connects, enables, or directs Adaptive to use (“Third-Party Services”). Customer’s use of Third-Party Services is governed by its agreements with those providers. By connecting or enabling a Third-Party Service, Customer authorizes Adaptive to exchange Customer Information with them as needed to provide the Platform. Adaptive is not responsible for Third-Party Services or for any unavailability, acts, or omissions of their providers.
2.9 Early Access Features. Adaptive may identify features as beta, preview, pilot, early access, or similar (“Early Access Features”). Early Access Features are provided AS IS and AS AVAILABLE, are excluded from Section 2.6 (Support), Section 2.7 (Availability), and Section 8.2 (Adaptive Performance Warranty), and may be modified, suspended, or discontinued by Adaptive at any time without liability. Adaptive’s total aggregate liability arising out of or relating to Early Access Features will not exceed the Fees paid for them.
3. Intellectual Property and Ownership.
3.1 Customer Information Ownership. Customer owns all right, title, and interest in and to Customer Information. Customer grants Adaptive a limited, non-exclusive, worldwide, royalty-free license during the Term to use or process Customer Information to provide the Platform and as otherwise expressly permitted in the Agreement.
3.2 Adaptive Intellectual Property. Adaptive owns all right, title, and interest in and to the Platform and the Documentation, and to all software, models, algorithms, know-how, threat intelligence, and other technology and materials used to provide the Platform, together with all improvements, enhancements, and derivative works of the foregoing, including any developed or trained using Feedback, or as set forth in a Product Exhibit.
3.3 Platform Outputs. Subject to Adaptive’s rights in the Platform, Adaptive grants Customer a perpetual, non-exclusive, royalty-free license to use, retain, and reproduce the Platform Outputs generated for Customer through its permitted use of the Platform for Customer’s internal business purposes. This Section does not transfer any right, title, or interest in the Platform or any other Adaptive intellectual property.
3.4 Aggregated Anonymized Data. Adaptive may create data derived from Customer’s or its Authorized Users’ use of the Platform that has been aggregated and/or de-identified so that it does not identify, and cannot reasonably be used to identify, Customer or any individual (“Aggregated Anonymized Data”), and may use it to provide, secure, maintain, and improve its products and services. As between the Parties, Adaptive owns all right, title, and interest (including all intellectual property rights) in and to Aggregated Anonymized Data.
3.5 Feedback. If Customer or its Authorized Users provide suggestions, enhancement requests, or other feedback regarding the Platform (“Feedback”), Customer assigns to Adaptive all right, title, and interest in and to that Feedback, and Adaptive may use it for any purpose without restriction, attribution, or obligation to Customer. To the extent any such assignment is not permitted under applicable law, Customer grants Adaptive a perpetual, irrevocable, worldwide, royalty-free, fully paid, sublicensable license to use the Feedback for any purpose. Feedback does not include Customer Information.
4. Data Protection.
4.1 Adaptive Data Commitments. Adaptive shall: (a) not sell Customer Information; (b) not use Customer Information to train artificial intelligence or machine learning models, except (i) models deployed solely for Customer, or (ii) as expressly permitted in an applicable Product Exhibit with respect to Aggregated Anonymized Data, Threat Signals, Malicious Emails, or Risk Signals (each as defined in the applicable Product Exhibit); (c) when using third-party large language model providers, use only configurations under which the provider does not retain Customer Information or use it for training (“zero data retention”); (d) maintain administrative, technical, and physical safeguards appropriate to the nature of the Customer Information, including encryption of Customer Information in transit and at rest; (e) limit access to Customer Information to personnel and service providers who need it to provide and support the Platform; (f) not re-identify or attempt to re-identify Aggregated Anonymized Data, and contractually require its subprocessors not to do so; and (g) notify Customer without undue delay, and in any event within seventy-two (72) hours, after confirming any breach of security leading to unauthorized access to or acquisition of Customer Information and, if a DPA applies, as further described in the DPA.
4.2 DPA. If applicable data protection law requires a written agreement governing Adaptive’s processing of Personal Information on Customer’s behalf, Adaptive’s standard data processing addendum available at www.adaptivesecurity.com/dpa applies and is incorporated into the Agreement by this reference, unless the Parties have executed a separate written data processing addendum, in which case that addendum governs. Where the DPA applies, it governs the Parties’ obligations with respect to Personal Information. Where no DPA applies, Sections 4.1, 4.3, and 5 govern Adaptive’s processing of Customer Information.
4.3 Subprocessors. Customer authorizes Adaptive to engage subprocessors to process Customer Information in accordance with the DPA, if applicable, and in each case under written terms at least as protective as those in the Agreement. Adaptive remains responsible for its subprocessors’ performance.
5. Confidentiality. “Confidential Information” means information disclosed by one Party (“Discloser”) to the other (“Recipient”) that the Recipient knows or reasonably should know is confidential, including, for Adaptive, non-public specifications, Documentation, and technical information, and, for Customer, all Customer Information. Confidential Information excludes information that: (a) is or becomes publicly available through no fault of the Recipient; (b) was known to the Recipient before disclosure, as established by documentary evidence; (c) is received from a third party without breach of a confidentiality obligation; or (d) is independently developed by the Recipient without use of the Discloser’s Confidential Information, as established by documentary evidence. The Recipient shall use the Discloser’s Confidential Information only to exercise its rights and perform its obligations under the Agreement, protect it with at least reasonable care, and limit disclosure to its employees, contractors, professional advisors, bona fide potential investors, and prospective acquirers who need to know it and are bound by confidentiality obligations at least as protective as this Section. The Recipient is responsible for those persons’ compliance. The Recipient may disclose Confidential Information to the extent required by law or legal process, provided it gives the Discloser prompt notice (where legally permitted) and discloses only what is required. Upon the Discloser’s written request, the Recipient will return or destroy the Discloser’s Confidential Information, except for archival copies retained under standard backup procedures or as required by law, which remain subject to this Section. Each Party acknowledges that breach of this Section may cause irreparable harm for which the Discloser may seek injunctive relief in addition to other remedies.
6. Fees; Payment.
6.1 Fees. Customer shall pay the fees set forth in each Order Form (“Fees”) in accordance with its payment terms. All Fees are non-cancellable and non-refundable except as expressly provided in the Agreement or an applicable Order Form. Payments are due in U.S. Dollars unless the Order Form states otherwise. If any undisputed invoiced amount is not received by Adaptive by the due date, the Fees may accrue interest at 1.5% per month or the maximum rate permitted by law, whichever is lower, and Customer shall reimburse Adaptive’s reasonable costs of collection. If Customer disputes an invoice in good faith, it must notify Adaptive of the dispute in reasonable detail prior to the due date, pay all undisputed amounts, and work with Adaptive in good faith to resolve the dispute promptly.
6.2 Overage. If Customer’s use of the Platform exceeds the seats, licenses, or other usage limits set forth in the applicable Order Form, Customer shall promptly notify Adaptive of such excess use. Adaptive may invoice Customer for the excess use at Adaptive’s then-current list rates (or the rates in the applicable Order Form, if higher), retroactive to the date such excess use began, and Customer shall pay such invoice in accordance with Section 6.1. Continued use of the Platform in excess of the purchased limits without Adaptive’s consent is a material breach of this Agreement.
6.3 Taxes. Fees are exclusive of taxes, levies, and duties, including sales, use, value-added, and withholding taxes (“Taxes”). Customer is responsible for all Taxes on its purchases other than Adaptive’s income tax. If withholding is required, Customer shall gross up its payment so Adaptive receives the full Fees. If Adaptive is required to collect Taxes, it will invoice them unless Customer provides a valid exemption certificate.
7. Term; Termination; Suspension.
7.1 Term. The Agreement starts on the Effective Date and continues until the expiration or termination of all Order Forms (the “Term”), unless otherwise terminated as permitted in this Agreement.
7.2 Termination for Cause. Either Party may terminate the Agreement or an affected Order Form on written notice if (i) the other Party materially breaches the Agreement and fails to cure within thirty (30) days after receiving written notice of the breach; or (ii) the other Party ceases to conduct business, becomes insolvent, makes a general assignment for the benefit of creditors, files or has filed against it a petition under any bankruptcy or insolvency law, or has a receiver, trustee, or similar officer appointed over a substantial part of its assets, and in the case of an involuntary filing such filing is not dismissed within sixty (60) days.
7.3 Suspension. Adaptive may suspend or limit Customer’s or an Authorized User’s access to the Platform, and may restrict, disable, or quarantine Customer Information if: (a) undisputed amounts remain unpaid more than fifteen (15) days after Adaptive’s notice of delinquency; (b) Customer or an Authorized User breaches Section 2.3; (c) Customer or an Authorized User makes unauthorized or fraudulent use of the Platform; (d) where reasonably necessary for security, to prevent unlawful activity, or to comply with applicable law; or (e) suspension is reasonably necessary to prevent material harm to the Platform or others. Adaptive will give prior notice where practicable, limit any suspension in scope and duration to what is reasonably necessary, and promptly restore access once the cause is resolved. Suspension does not limit Adaptive’s termination rights or Customer’s payment obligations.
7.4 Effect of Termination. Upon expiration or termination of the Agreement or an Order Form the applicable licenses end, Customer shall cease use of the affected Platform, and all Fees owed for the affected Order Form become due; provided that if Customer terminates the Agreement or an Order Form under Section 7.2 for Adaptive’s uncured material breach, Adaptive will refund any prepaid, unused Fees for the period after the effective date of termination. Any continued use of the Platform after expiration will be billed at Adaptive’s standard rates and remains subject to the Agreement.
7.5 Data Export and Deletion. During the Term and for sixty (60) days after expiration or termination of the applicable Order Form, Adaptive will, within a reasonable time after Customer’s request, make the applicable Customer Information available to Customer for export through the Platform or Adaptive’s then-standard export process, in a commonly used, machine-readable format. Adaptive will delete the applicable Customer Information from its production systems within thirty (30) days after Customer’s written request, except to the extent retention is (a) required by applicable law, (b) necessary for an active and documented security investigation, in which case Adaptive will notify Customer unless prohibited by law, limit the retained information to what is reasonably necessary for that investigation, and delete it promptly on conclusion, (c) otherwise agreed by the Parties, or (d) in accordance with its standard backup or archival policies, in which case the information will remain protected under the Agreement. On Customer’s written request, Adaptive will confirm completion of production deletion.
7.6 Survival. Any provision that by its nature should survive expiration or termination of the Agreement survives, including Sections 1, 2.3, 3, 4, 5, 6, 7.4, 7.5, 7.6, 8.4, 9, 10, 12, and 13, the surviving portions of the Product Exhibits, and all associated definitions.
8. Representations and Warranties.
8.1 Mutual Warranty. Each Party represents and warrants that: (a) it has the right, power, and authority to enter into this Agreement; and (b) it will comply with applicable laws in performing the Agreement.
8.2 Adaptive Performance Warranty. Adaptive warrants that during each subscription term: (a) the Platform will perform materially in accordance with the applicable Documentation; and (b) Adaptive will not materially decrease the overall functionality of the Platform purchased under the applicable Order Form, provided that this clause (b) does not apply to Early Access Features (as defined in Section 2.9) or to modifications, deprecations, or discontinuations of Platform features made on reasonable prior notice as part of Adaptive’s ordinary product lifecycle management. For breach of this warranty, Adaptive will use commercially reasonable efforts to repair the non-conformity, and if Adaptive fails to do so within thirty (30) days of Customer’s written notice, Customer may terminate the affected Order Form and receive a pro-rata refund of prepaid, unused Fees for the terminated portion, notwithstanding Section 6.1. Customer must report a breach of warranty in reasonable detail within thirty (30) days of discovering the issue. This is Customer’s exclusive remedy, and Adaptive’s sole liability, for breach of this Section 8.2.
8.3 Customer. Customer represents, warrants, and covenants that: (a) it owns or has sufficient rights in Customer Information to grant the rights in the Agreement; and (b) it has obtained, and will maintain during the Term, all rights, consents, notices, and legal bases required under applicable law to provide Customer Information to Adaptive and to authorize the processing described in the Agreement and each applicable Product Exhibit.
8.4 Disclaimer. EXCEPT AS EXPRESSLY SET FORTH IN THE AGREEMENT, THE PLATFORM IS PROVIDED “AS IS,” AND ADAPTIVE DISCLAIMS ALL OTHER WARRANTIES, EXPRESS, IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, TITLE, NON-INFRINGEMENT, AND FITNESS FOR A PARTICULAR PURPOSE. EXCEPT AS EXPRESSLY SET FORTH IN THE AGREEMENT, ADAPTIVE DOES NOT WARRANT THAT THE PLATFORM WILL IDENTIFY, PREVENT, OR REMEDIATE EVERY SECURITY THREAT OR THAT IT WILL BE ERROR-FREE OR UNINTERRUPTED.
9. Indemnification.
9.1 By Adaptive. Adaptive shall defend Customer, its affiliates, and their respective officers, directors, and employees against any third-party claim alleging that the Platform, as provided by Adaptive and used in accordance with the Agreement, infringes or misappropriates a third party’s intellectual property rights, and shall indemnify and hold them harmless against all damages, costs, and reasonable attorneys’ fees finally awarded or agreed in settlement of such claim (“Losses”). Adaptive has no obligation under this Section to the extent a claim arises from: (i) infringement or misappropriation of a third party’s rights by Customer Information; (ii) modifications not made by Adaptive or combinations of the Platform with items not provided by Adaptive, where the Platform alone would not infringe; (iii) use in material breach of the Agreement; or (iv) failure to implement updates, modifications, or replacements issued by Adaptive to the Platform. If the Platform becomes, or in Adaptive’s reasonable opinion is likely to become, the subject of a claim described in this Section 9.1, Adaptive will, at its expense, procure the right for Customer to continue using the Platform or replace or modify the Platform to be non-infringing without material reduction in functionality; if neither option is commercially practicable, either Party may terminate the affected Order Form and Adaptive will refund prepaid, unused Fees for the terminated portion. Subject to the foregoing, this Section 9.1 states Adaptive’s entire liability, and Customer’s exclusive remedy, for third-party infringement claims.
9.2 By Customer. Customer shall defend Adaptive, its affiliates, and their respective officers, directors, and employees against any third-party claim alleging that Customer Information infringes or misappropriates a third party’s intellectual property rights, or arising from (a) Customer’s breach of Section 8.3, (b) Customer’s or its Authorized Users’ use of the Platform in violation of Section 2.3 or applicable law, or (c) Simulations (as defined in Exhibit A) or other simulated cybersecurity content generated or delivered at the direction of Customer or its Authorized Users, except to the extent the claim arises from Adaptive’s material deviation from the campaign parameters directed or approved by Customer, and shall indemnify and hold them harmless against Losses. Customer has no obligation under this Section to the extent a claim arises from Adaptive’s material breach of the Agreement or Adaptive’s gross negligence or willful misconduct.
9.3 Procedures. The party seeking indemnification shall give the indemnifying party prompt written notice of the claim, reasonable cooperation at the indemnifying party’s expense, and sole control of the defense and settlement, provided that any settlement that does not consist solely of money paid by the indemnifying party, or that includes an admission of liability by or imposes any obligation on the indemnified party, requires the indemnified party’s prior written consent, not to be unreasonably withheld, and any settlement must include an unconditional release of the indemnified party from all liability with respect to the claim. The indemnified party may participate in the defense with its own counsel at its own expense.
10. Limitation of Liability.
10.1 Exclusion of Certain Damages. EXCEPT FOR THE EXCLUDED CLAIMS, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, OR CONSEQUENTIAL DAMAGES, OR FOR LOST PROFITS, REVENUES, OR BUSINESS OPPORTUNITIES, ARISING OUT OF OR RELATED TO THE AGREEMENT, HOWEVER CAUSED AND UNDER ANY THEORY OF LIABILITY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
10.2 Liability Cap. EXCEPT FOR THE EXCLUDED CLAIMS, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THE AGREEMENT WILL NOT EXCEED THE FEES PAID OR DUE AND PAYABLE TO ADAPTIVE IN THE TWELVE (12) MONTHS PRECEDING THE FIRST EVENT GIVING RISE TO LIABILITY.
10.3 Excluded Claims. “EXCLUDED CLAIMS” MEANS: (A) A PARTY’S FRAUD, GROSS NEGLIGENCE, OR WILLFUL MISCONDUCT; (B) A PARTY’S INDEMNIFICATION OBLIGATIONS UNDER SECTION 9 (OR UNDER A PRODUCT EXHIBIT); (C) EITHER PARTY’S INFRINGEMENT OR MISAPPROPRIATION OF THE OTHER PARTY’S INTELLECTUAL PROPERTY RIGHTS; (D) CUSTOMER’S PAYMENT OBLIGATIONS; (E) CUSTOMER’S BREACH OF SECTION 8.3(B) (CONSENT AND LEGAL BASES); AND (F) EITHER PARTY’S BREACH OF SECTION 5 (CONFIDENTIALITY).
11. Insurance. During the Term, Adaptive will maintain commercially reasonable insurance coverage consistent with industry practice for companies of comparable size, including technology errors and omissions and cyber liability insurance, and will provide certificates of insurance upon Customer’s written request.
12. Publicity. Neither Party will issue a press release or public announcement regarding the Agreement without the other Party’s prior written consent. Adaptive may identify Customer by name and logo in customer lists and marketing materials solely to identify Customer as an Adaptive customer and Customer may revoke this permission at any time by written notice.
13. General.
13.1 Notices. Notices under the Agreement must be in writing and are deemed given: (a) upon delivery by courier or certified mail (return receipt requested) to the address in the Order Form; or (b) upon delivery by email (to legal@adaptivesecurity.com for Adaptive, and to Customer’s email address in the Order Form). Either Party may update its notice address by notice.
13.2 Governing Law; Venue. The Agreement is governed by the laws of the State of New York, without regard to conflict of laws principles. The state and federal courts located in New York, New York have exclusive jurisdiction over disputes arising out of or relating to the Agreement, and each Party consents to their jurisdiction and venue.
13.3 Assignment. Neither Party may assign the Agreement without the other Party’s prior written consent, except that either Party may assign it without consent to a successor in connection with a merger, acquisition, reorganization, or sale of all or substantially all of its assets or of the business to which the Agreement relates. Any other attempted assignment is void. The Agreement binds and benefits the Parties’ permitted successors and assigns.
13.4 Export; Sanctions. Customer shall not access, use, or make the Platform available in any country or region subject to comprehensive U.S. sanctions, or to or by any person or entity on any applicable U.S. government restricted party list, and shall comply with applicable export control laws.
13.5 Force Majeure. Neither Party is liable for failure or delay in performance (other than payment obligations) caused by circumstances beyond its reasonable control, including acts of God, natural disasters, war, terrorism, civil unrest, government action, epidemics, telecommunications or power failures, and cyber-attacks (each, a “Force Majeure Event”), provided the affected Party gives prompt notice and uses commercially reasonable efforts to mitigate. If a Force Majeure Event continues for more than thirty (30) consecutive days, either Party may terminate the affected Order Form on written notice.
13.6 Entire Agreement. The Agreement is the entire agreement between the Parties regarding its subject matter and supersedes all prior and contemporaneous communications and agreements. The terms of any Customer purchase order or vendor portal are administrative only and shall not modify this Agreement.
13.7 Updates. Adaptive may modify this MSA from time to time. If a modification materially impacts the Agreement, Adaptive will use reasonable efforts to notify Customer through the Platform, Adaptive’s website, and/or in accordance with Section 13.1 (Notices). Any changes to this MSA posted on Adaptive’s website will be effective if Customer assents to such changes or upon the commencement of Customer’s next renewal term under an Order Form, except that changes required by law or necessary for new features will become effective immediately to the extent necessary to comply with such law or to permit use of such new features, provided such changes do not materially diminish Customer’s rights with respect to the Platform already purchased. If Customer objects to the updated MSA, as Customer’s exclusive remedy and without penalty, Customer may decline to renew, or cancel any automatic renewal of, the applicable Order Form in accordance with Section 7.1 (Term). Customer’s continued use of the Platform after the effective date of an update constitutes acceptance of the updated MSA.
13.8 Severability; Waiver. If any provision of the Agreement is held unenforceable, the remaining provisions remain in full force. A waiver is effective only if in writing and signed by the waiving Party, and no failure or delay in exercising a right is a waiver of it.
13.9 Relationship; No Third-Party Beneficiaries. The Parties are independent contractors. There are no third-party beneficiaries to the Agreement, except that the Adaptive and Customer indemnitees expressly identified in Section 9 may enforce the indemnities in Section 9.
13.10 Counterparts. The Agreement (including any Order Form) may be executed in counterparts, including by electronic signature, each of which is deemed an original.
EXHIBIT A — SECURITY AWARENESS TRAINING PRODUCTS
This Exhibit A applies if Customer purchases access to Adaptive’s security awareness training and simulation products under an Order Form (the “SAT Products”), including the features described in this Section 1. Customer acknowledges that the SAT Products use artificial intelligence. References in this Exhibit to Sections “of this Exhibit” are to this Exhibit A, and references to Sections “of the MSA” are to the body of the MSA. As to the SAT Products, this Exhibit controls over any conflicting provision of the body of the MSA.
1. Definitions.
“Simulations” means features that deliver simulated cybersecurity attacks targeting Customer’s business and personnel as directed by Customer, including simulated phishing (email), smishing (SMS), vishing (voice), and deepfake video, audio, and video-conference simulations.
“Phish Reporting” means features that enable Authorized Users to report suspected phishing or other suspicious emails for classification as safe or malicious. The SAT Products also include features that allow Customer to generate AI personas, deepfake content, and custom training modules.
2. SAT Authorization; Data.
2.1 Authorization. By opting-in to receive or otherwise utilizing the SAT Products on the Platform, Customer authorizes Adaptive to access, process, and use data generated through Customer’s and its Authorized Users’ use of the SAT Products, including emails submitted through Phish Reporting, for purposes of providing the Platform. Customer controls the targeting, scope, content parameters, and timing of Simulations.
2.2 Reported Emails. Emails reported through Phish Reporting that are classified as malicious may also be retained and used to improve detection efficacy and threat intelligence in accordance with the safeguards in Section 4.1 of the MSA. If such an email is reclassified as safe, Adaptive will treat it as Customer Information.
2.3 Customer Training Content. This Exhibit does not grant Adaptive any improvement or training rights in training materials, security policies, or other content Customer uploads to the Platform for its internal business purposes, which Adaptive will use solely to provide the Platform to Customer.
3. AI Personas; Likeness Materials.
3.1 Persona Content; Consents. The SAT Products can generate AI personas and deepfake content that replicate the name, image, voice, or likeness of real individuals (for example, Customer executives or IT personnel) from source images, audio, or video provided or designated by Customer (“Likeness Materials”, and such generated content, “Persona Content”). Customer represents, warrants, and covenants that, before providing or designating Likeness Materials or directing the creation of Persona Content depicting an individual, it has obtained all consents, authorizations, and releases from that individual required under applicable law, including biometric privacy, voice-replication, and right-of-publicity laws.
3.2 Adaptive Commitments. Adaptive shall use Likeness Materials and Persona Content solely to provide the SAT Products to Customer and treat them as Customer Information. Adaptive shall delete Likeness Materials and Persona Content within thirty (30) days of Customer’s written request.
4. SMS and Voice Features. SMS- and voice-based Simulations depend on telecommunications carrier networks and are subject to carrier availability, filtering, and restrictions. Customer acknowledges that carriers and devices may block, filter, flag, delay, or route Simulation calls or messages (including to voicemail or spam), and Adaptive does not warrant the delivery, completion, or answer rate of any SMS or voice Simulation. Adaptive is not responsible for unavailability or delivery failures caused by carrier networks, restrictions, or recipient device settings. SMS and voice Simulations may be subject to usage-based fees as set forth in the applicable Order Form.
5. Simulation Waiver. Customer waives all claims against Adaptive arising from Simulations that Adaptive executes materially in accordance with the campaign parameters directed or approved by Customer.
6. Product Disclaimer. THE SAT PRODUCTS ARE TRAINING AND SIMULATION TOOLS. ADAPTIVE DOES NOT WARRANT THAT TRAINING OR SIMULATIONS WILL PREVENT ANY ACTUAL SECURITY INCIDENT OR THAT PERSONNEL WILL DETECT OR RESIST ACTUAL ATTACKS, AND ADAPTIVE IS NOT LIABLE FOR LOSSES ARISING FROM ACTUAL CYBERSECURITY INCIDENTS AFFECTING CUSTOMER.
7. Indemnification. In addition to Section 9.2 of the MSA, Customer shall defend and indemnify the Adaptive indemnitees described in Section 9.2 of the MSA against Losses arising out of any third-party claims resulting from: (a) Customer’s breach of Section 3.1 of this Exhibit; (b) the targeting, content, or delivery of any Simulation directed or approved by Customer; or (c) Customer’s use of the SAT Products in violation of applicable law or the Agreement, except to the extent the claim arises from Adaptive’s material deviation from the campaign parameters directed or approved by Customer, or Adaptive’s gross negligence or willful misconduct.
EXHIBIT B — EMAIL SECURITY PRODUCT
This Exhibit B applies if Customer purchases access to Adaptive’s email security products or any features involving automated scanning, analysis, or processing of Customer emails (the “Email Security Product”) under an Order Form. Customer acknowledges that the Email Security Product uses artificial intelligence. As to Email Data and the Email Security Product, this Exhibit controls over any conflicting provision of the body of the MSA. References in this Exhibit to Sections “of this Exhibit” are to this Exhibit B, and references to Sections “of the MSA” are to the body of the MSA.
1. Definitions.
“Email Data” means incoming, outgoing, and internal emails, including their content, metadata, and attachments, that the Email Security Product accesses or processes. Email Data is Customer Information.
“Malicious Email” means Email Data that the Email Security Product classifies as malicious, fraudulent, or otherwise harmful. If Customer marks an email “Safe” through Platform settings, it ceases to be a Malicious Email and Adaptive will use commercially reasonable efforts to implement such changes to email classifications within sixty (60) days.
“Threat Signals” means the indicators, scores and other numerical signals generated by the Email Security Product for threat detection purposes, that cannot reasonably be used to identify Customer or any individual other than a threat actor, or to reconstruct Email Data. Threat Signals are owned by Adaptive.
2. License. Adaptive grants Customer, during the term of the applicable Order Form, the license described in Section 2.1 of the MSA to use the Email Security Product, including for the Authorized Users to whom Customer elects to provide access (each, an “Email Security User”).
3. Processing of Email Data. Adaptive processes Email Data to detect, analyze, classify, and seek to remediate potential security threats and to otherwise provide and support the Email Security Product. Adaptive may use Malicious Emails to improve its security products and threat-detection capabilities subject to Section 4 of this Exhibit. Adaptive may also derive Threat Signals and collect technical and usage data on the Email Security Product’s operation. Upon expiration or termination of the Agreement, Adaptive will delete all Email Data within sixty (60) days, subject to the exceptions in Section 6 of this Exhibit. On Customer’s written request made before, or within thirty (30) days after, expiration or termination, Adaptive will make Customer’s threat-detection and quarantine records available for export in a commonly used electronic format.
4. Safeguards. In exercising its rights under these Terms, Adaptive shall comply with the information security and data protection obligations set forth in the MSA, including: encrypting Email Data in transit and at rest; not selling Email Data or using it for advertising or marketing; using only zero-data-retention configurations with third-party large language model providers; not using safe Email Data to improve its threat-detection capabilities except as instructed by Customer for customer-specific AI model offerings; and limiting internal access to Email Data content to personnel who need it to provide and support the Email Security Product, to investigate threats, or to review classifications, and maintaining records of such access, which Adaptive will make available to Customer on reasonable request. Adaptive may use service providers (including hosting, observability, security operations, and support providers) to process Email Data solely to provide and support the Email Security Product, subject to obligations at least as protective as this Exhibit, and Adaptive remains responsible for their compliance.
5. Privacy. To the extent Email Data includes Personal Information, Section 4.2 of the MSA and the DPA, if applicable, govern Adaptive’s processing of such Personal Information and control over this Exhibit as to Personal Information.
6. Deletion Requests. Customer may request deletion of its Email Data at any time through Platform settings or by written request. Adaptive will delete the requested Email Data within thirty (30) days and provide written confirmation, except to the extent retention is required by law or legal process or is necessary for an active, documented security investigation in which case Adaptive will complete deletion promptly after the conclusion of that investigation. Residual copies in Adaptive’s standard backup systems will be deleted in the ordinary course of Adaptive’s backup cycles and remain subject to this Exhibit until deleted.
7. Customer Responsibilities. In addition to Section 8.3 of the MSA, Customer represents, warrants, and covenants that: (a) it has the legal authority, and has obtained and will maintain all rights, consents, and authorizations required under applicable law (including privacy, data protection, communications, wiretap, and employment laws), to collect, transmit, and make Email Data available to Adaptive for the processing described in this Exhibit, including providing all legally required notices to, and obtaining all legally required consents from, its Email Security Users; and (b) its use of the Email Security Product will comply with applicable law in each jurisdiction where it is deployed.
8. Product Disclaimer. THE EMAIL SECURITY PRODUCT RELIES ON AUTOMATED DETECTION METHODOLOGIES, INCLUDING AI-BASED CLASSIFICATION AND RISK SCORING, WHICH MAY PRODUCE FALSE POSITIVES OR FALSE NEGATIVES. EXCEPT AS EXPRESSLY SET FORTH IN THE AGREEMENT, ADAPTIVE IS NOT LIABLE FOR LOSSES ARISING FROM ANY FALSE POSITIVE OR FALSE NEGATIVE OR ANY FAILURE OF THE PLATFORM TO DETECT, PREVENT, OR REMEDIATE ANY SECURITY THREAT, MALICIOUS COMMUNICATION, OR DATA EXPOSURE.
9. Indemnification. In addition to Section 9.2 of the MSA, Customer shall defend and indemnify the Adaptive indemnitees described in Section 9.2 of the MSA against Losses arising out of any third-party claims resulting from: (a) Customer’s breach of Section 7 of this Exhibit; or (b) Customer’s use of the Email Security Product in violation of applicable law or the Agreement.
EXHIBIT C — AI GOVERNANCE PRODUCTS
This Exhibit C applies if Customer purchases access to Adaptive’s AI governance products under an Order Form, including Adaptive’s browser extension and on-device application that monitor web and on-device activity for security risks and unauthorized interactions with tools, together with any administrative portal, dashboards, and reporting features (the “AI Governance Products”). Customer acknowledges that the AI Governance Products use artificial intelligence and machine learning technology. As to Device Data and the AI Governance Products, this Exhibit controls over any conflicting provision of the body of the MSA. References in this Exhibit to Sections “of this Exhibit” are to this Exhibit C, and references to Sections “of the MSA” are to the body of the MSA.
1. Definitions.
“Risk Signals” means the risk signals, classification labels, sensitivity scores, threat intelligence, de-identified usage patterns, and plain-language risk summaries generated by the AI Governance Product’s proprietary technology. Risk Signals are owned by Adaptive and are not Customer Information.
“Device Data” means data sent to, from, or within Customer’s web browsing and/or on-device environment that the AI Governance Products access and process, including downloaded and uploaded data, website information and interactions, browser information, plugins, and settings, device information, and interactions with locally installed applications and AI tools.
“Device Metadata” means structured, non-content data collected by the AI Governance Products about a user’s browsing session or on-device activity (for example, page-level metadata, navigation and referral data, file transfer event data, and device context), excluding the substantive content of web pages, user inputs, and files.
“Raw Device Data” means unprocessed Device Data prior to aggregation, anonymization, or derivation.
2. License. Adaptive grants Customer, during the term of the applicable Order Form, the license described in Section 2.1 of the MSA to: (a) deploy and enable the AI Governance Products on the devices of those Authorized Users whose activity Customer elects to monitor (each, an “AI Governance User”); and (b) designate AI Governance Users to use the administrative portal, dashboards, and reporting features to monitor activity for security risks, manage unauthorized application usage, and enforce policies governing interactions with tools.
3. Processing of Data. Customer acknowledges and agrees that the AI Governance Products will access and process Device Data to provide the AI Governance Products, including detecting, analyzing, classifying, and seeking to remediate potential security threats. Device Data is Customer Information. Adaptive may retain, analyze, annotate, and use Device Metadata as necessary to detect, investigate, remediate, and prevent security threats and to improve its security products and threat detection capabilities, subject to Section 5 of this Exhibit. Upon expiration or termination of the Agreement, Adaptive will delete all Raw Device Data and Device Metadata within sixty (60) days, subject to the exceptions in Section 5 of this Exhibit. On Customer’s written request made before, or within thirty (30) days after, expiration or termination, Adaptive will provide written confirmation of such deletion.
4. Safeguards. In exercising its rights under this Exhibit, Adaptive shall comply with Section 4.1 of the MSA, including: encrypting Device Data in transit and at rest; not selling Device Data; using only zero-data-retention configurations with third-party large language model providers; not using Raw Device Data to train AI models, except as instructed by Customer for customer-specific AI model offerings; and limiting internal access to Raw Device Data to personnel who need it to provide and support the AI Governance Products. Adaptive may use service providers (including hosting, observability, security operations, and support providers) to process Device Data solely to provide and improve the AI Governance Products, subject to this Exhibit.
5. Deletion Requests. Customer may request deletion of its Raw Device Data or Device Metadata at any time by written request. Adaptive will delete the requested data within thirty (30) days and provide written confirmation, except to the extent retention is required by law or legal process, necessary for an active, documented security investigation, or technically infeasible.
6. Customer Responsibilities. In addition to Section 8.3 of the MSA, Customer represents, warrants, and covenants that: (a) it has the legal authority, and has obtained and will maintain all rights, consents, and authorizations required under applicable law, including data protection, privacy, employment, labor, works council, and workplace monitoring laws in connection with its use of the AI Governance Products and to collect, transmit, and make Device Data available to Adaptive for the processing described in this Exhibit; and (b) it is solely responsible for providing all legally required notices to, and obtaining all legally required consents from, its AI Governance Users regarding Customer’s monitoring of their activity through the AI Governance Products.
7. Product Disclaimer. THE AI GOVERNANCE PRODUCTS RELY ON AUTOMATED DETECTION METHODOLOGIES, INCLUDING AI-BASED CLASSIFICATION AND RISK SCORING, WHICH MAY PRODUCE FALSE POSITIVES OR FALSE NEGATIVES. PLATFORM OUTPUTS GENERATED BY THE AI GOVERNANCE PRODUCTS ARE FOR INFORMATIONAL PURPOSES ONLY AND ARE NOT LEGAL, COMPLIANCE, OR EMPLOYMENT ADVICE. CUSTOMER IS SOLELY RESPONSIBLE FOR REVIEWING PLATFORM OUTPUTS BEFORE TAKING ANY ACTION BASED ON THEM, INCLUDING ANY EMPLOYMENT, DISCIPLINARY, OR ACCESS-RELATED DECISION. EXCEPT AS EXPRESSLY SET FORTH IN THE AGREEMENT, ADAPTIVE IS NOT LIABLE FOR LOSSES ARISING FROM ANY FALSE POSITIVE OR FALSE NEGATIVE OUTPUT, ANY ACTION TAKEN OR NOT TAKEN BY CUSTOMER IN RELIANCE ON PLATFORM OUTPUTS, OR ANY FAILURE OF THE AI GOVERNANCE PRODUCTS TO DETECT, PREVENT, OR REMEDIATE ANY SECURITY THREAT, UNAUTHORIZED APPLICATION USAGE, OR DATA EXPOSURE.
8. Indemnification. In addition to Section 9.2 of the MSA, Customer shall defend and indemnify the Adaptive indemnitees described in Section 9.2 of the MSA against Losses arising out of any third-party Action resulting from: (a) Customer’s breach of Section 6 of this Exhibit; (b) claims by AI Governance Users or other individuals arising from Customer’s failure to provide legally required notices or obtain legally required consents, or from employment, disciplinary, or access-related decisions made by Customer; or (c) Customer’s deployment or use of the AI Governance Products in violation of applicable law or the Agreement.