CANIMA, INC.
MASTER SUBSCRIPTION AGREEMENT
PLEASE READ THESE TERMS AND CONDITIONS (“TERMS”) CAREFULLY BEFORE USING THE SERVICES OFFERED BY CANIMA, INC. (“COMPANY”). THIS MASTER SUBSCRIPTION AGREEMENT IS INCORPORATED BY REFERENCE INTO EACH ORDER FORM EXECUTED BY CUSTOMER AND CANIMA. BY EXECUTING AN ORDER FORM THAT REFERENCES THIS AGREEMENT, YOU (“CUSTOMER”) AGREE TO BE BOUND BY THESE TERMS (TOGETHER WITH ALL ORDER FORMS, THE “AGREEMENT”) TO THE EXCLUSION OF ALL OTHER TERMS. CUSTOMER’S EXECUTION OF AN ORDER FORM CONSTITUTES CUSTOMER’S ACCEPTANCE OF THIS AGREEMENT AS IT EXISTS AT THE TIME THE ORDER FORM IS EXECUTED. THE CURRENT VERSION OF THIS AGREEMENT IS AVAILABLE AT HTTPS://CANIMA.COM/LEGAL/MSA.
IF YOU ARE ENTERING INTO THIS AGREEMENT ON BEHALF OF AN ENTITY, THEN YOU REPRESENT AND WARRANT THAT YOU ARE AUTHORIZED TO BIND SUCH ENTITY TO THE TERMS OF THIS AGREEMENT.
1. DEFINITIONS
1.1 "Authorized User". means Customer’s employees, consultants, contractors, and agents: (i) who are authorized by Customer to access and use the Service under this Agreement; and (ii) for whom access to the Service has been purchased hereunder.
1.2 "Company IP". means the Service, the Platform, the Company Technology, the Documentation, and any and all intellectual property provided to Customer or any Authorized User in connection with the foregoing, including without limitation all patents (whether pending, issued, or to be filed), patent applications, copyrights, trademarks, trade secrets, know-how, and other intellectual property rights therein. For the avoidance of doubt, Company IP includes Company Usage Data, Company Technology, Derived Data, and any information, data, or other content derived from Company’s provision of the Service, but does not include Customer Data.
1.3 "Company Technology". means Company’s proprietary and patent-pending technology, including without limitation: (i) all artificial intelligence and machine learning models, algorithms, neural networks, training methodologies, and model weights; (ii) all autonomous AI agent architectures, decision trees, attack chains, exploitation techniques, reconnaissance methods, and lateral movement logic; (iii) all scanning engines, vulnerability detection methods, proof-of-concept generation techniques, and safe exploitation methodologies; (iv) all software code, APIs, data structures, system architectures, and user interfaces; (v) all threat intelligence databases, vulnerability databases, dark web monitoring capabilities, and CVE correlation engines; and (vi) all inventions, methods, processes, and techniques embodied in or related to the foregoing, whether or not patentable, and all improvements, modifications, derivative works, and enhancements thereof.
1.4 "Customer Data". means information, data, and other content, in any form or medium, that is submitted, posted, or otherwise transmitted by or on behalf of Customer or an Authorized User through the Service, including but not limited to network configurations, IP addresses, domain names, application URLs, and any other information provided for the purpose of conducting penetration testing engagements.
1.5 "Derived Data". means any anonymized, aggregated, de-identified, statistical, or derivative data generated by or through the operation of the Service, including without limitation: (i) generalized vulnerability patterns, attack path analytics, and threat landscape intelligence derived from the Service’s operation across its customer base; (ii) improvements to AI models, detection algorithms, or exploitation techniques resulting from the Service’s processing of environments; (iii) performance metrics, benchmark data, and operational analytics; and (iv) any other data that does not identify Customer or Customer’s specific environment. For the avoidance of doubt, Derived Data is Company IP and is not Customer Data.
1.6 "Documentation". means Company’s end user documentation, guides, and knowledge base articles relating to the Service, as updated from time to time.
1.7 "Findings". means any vulnerability reports, proof-of-concept evidence, exploitation results, security assessments, and related outputs generated by the Service during testing engagements that are specific to Customer’s environment and assets.
1.8 "Harmful Code". means any software, hardware, or other technology, device, or means, including any virus, worm, malware, or other malicious computer code, the purpose or effect of which is to permit unauthorized access to, or to destroy, disrupt, disable, distort, or otherwise harm or impede in any manner any computer, software, firmware, hardware, system, or network.
1.9 "Order Form". means a written ordering document for Service(s) executed by Customer that incorporates this Agreement by reference, specifying the subscription tier, scope, fees, and Subscription Period. Customer’s execution of an Order Form constitutes acceptance of this Agreement as published at https://canima.com/legal/msa as of the date of such execution.
1.10 "Personal Information". means any information that, individually or in combination, does or can identify a specific individual or by or from which a specific individual may be identified, contacted, or located, including all data considered "personal data," "personally identifiable information," or similar under applicable data privacy laws, rules, or regulations.
1.11 "Platform". means Company’s proprietary AI-powered penetration testing platform, including all autonomous AI agents, scanning engines, reconnaissance modules, and exploitation capabilities, as made available via the Service.
1.12 "Sensitive Data". means: (i) special categories of data enumerated in European Union Regulation 2016/679, Article 9(1) or any successor legislation; (ii) protected health information as defined in HIPAA; (iii) payment cardholder information or financial account information; (iv) social security numbers, driver’s license numbers, or other government identification numbers; (v) other information subject to regulation under specific laws such as COPPA or GLBA; or (vi) any data similar to the above protected under applicable laws.
1.13 "Service". means Company’s AI-powered penetration testing products and services as specified in applicable Order Form(s), which may include External Penetration Testing & Attack Surface Management, Internal Penetration Testing, and/or Web Application Penetration Testing, and as made available to Authorized Users from time to time.
1.14 "Subscription Period". means the time period identified on the Order Form during which Customer’s Authorized Users may access and use the Service.
1.15 "Testing Scope". means the specific targets, assets, IP ranges, domains, subdomains, URLs, and/or applications that Customer has authorized Company to test, as defined in the Order Form or Platform configuration.
1.16 "Third Party Integrations". means any third-party products provided with, integrated with, or incorporated into the Service.
1.17 "Usage Limitations". means the usage limitations set forth in this Agreement and the Order Form, including without limitation any limitations on the number of Authorized Users, IP addresses, domains, web applications, and the applicable product, pricing, and support tiers.
2. ACCESS AND USE
2.1 Order Forms; License Grant. Upon Customer’s execution of an Order Form, each Order Form shall be incorporated into and form a part of the Agreement. Subject to Customer’s compliance with the terms and conditions of this Agreement (including any Usage Limitations), Company grants Customer a nonexclusive, limited, nonsublicensable, nontransferable right and license to internally access and use the Service during the applicable Subscription Period for Customer’s internal business purposes, only as provided herein and in accordance with the Documentation. Use of the Service is limited to the features, functionalities, and scope specified in the Order Form.
2.2 Account Setup and Authorized Users. Each Authorized User must have a unique account for accessing the Service. Authorized Users may not share their account credentials with one another or any third party. Customer will be responsible for all acts and omissions of its Authorized Users in connection with this Agreement and for all use of Authorized Users’ accounts. Customer shall use reasonable efforts to make all Authorized Users aware of this Agreement’s provisions.
2.3 Use Restrictions. Except as expressly set forth in this Agreement, Customer shall not (and shall not permit any third party to), directly or indirectly: (i) reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code, object code, or underlying structure, ideas, algorithms, AI models, training methodologies, or decision logic of the Service or any Company Technology; (ii) modify, translate, or create derivative works based on the Service or any Company Technology; (iii) copy, rent, lease, distribute, pledge, assign, sublicense, publish, or otherwise transfer or encumber rights to the Service; (iv) use the Service for the benefit of a third party or make the Service available to any third party; (v) remove or otherwise alter any proprietary notices, patent markings, or labels from the Service; (vi) use the Service, the Findings, the Company Technology, or any knowledge or insights gained from the Service to build, train, improve, or contribute to any application, product, service, artificial intelligence model, or technology that is competitive with any Company product or service; (vii) interfere or attempt to interfere with the proper working of the Service; (viii) bypass any measures Company may use to prevent or restrict access to the Service; (ix) use the Service to test, scan, or probe any system, network, or application not within the authorized Testing Scope; (x) use the Findings or Service output to disparage, defame, or publicly criticize Company; (xi) attempt to extract, replicate, reverse engineer, or derive Company’s AI models, machine learning algorithms, training data, model weights, attack methodologies, or any other Company Technology through the use of the Service, analysis of Findings, or any other means; (xii) use the Service or any outputs thereof as training data for any machine learning model, artificial intelligence system, or automated system not owned by Company; or (xiii) benchmark the Service against competing products or services and disclose the results thereof without Company’s prior written consent.
2.4 Suspension. Company may temporarily suspend Customer’s access to any portion or all of the Service if: (i) there is a threat or attack on the Service; (ii) Customer’s use disrupts or poses a security risk to the Service or other customers; (iii) Customer is using the Service for fraudulent or illegal activities; (iv) Customer has ceased to continue its business in the ordinary course or become the subject of any bankruptcy proceeding; (v) Company’s provision of the Service is prohibited by applicable law; or (vi) Customer’s account is more than ten (10) days past due. Company shall use commercially reasonable efforts to provide written notice of any suspension and to resume providing access as soon as reasonably possible after the event is cured.
3. CUSTOMER OBLIGATIONS
3.1 Authorization and Testing Scope. Customer represents and warrants that: (i) Customer owns or has obtained all necessary authorizations, consents, and permissions to conduct penetration testing on all systems, networks, applications, and assets within the Testing Scope; (ii) the Testing Scope accurately reflects only those assets that Customer is legally authorized to test; and (iii) Customer has reviewed and approved the Testing Scope prior to initiating any testing engagement through the Service. Customer shall indemnify and hold harmless Company from any liabilities, damages, and expenses arising out of or resulting from Customer’s failure to obtain proper authorization for testing.
3.2 Customer Systems. Customer has and will retain sole responsibility for: (i) all information, instructions, and materials provided by or on behalf of Customer in connection with the Service; (ii) Customer’s information technology infrastructure; (iii) the security and use of Customer’s and its Authorized Users’ access credentials; and (iv) ensuring that production environments are appropriately backed up and that Customer understands the risks inherent in penetration testing activities.
3.3 Customer Data. Customer shall retain all right, title, and interest in and to the Customer Data, including all intellectual property rights therein. Customer represents and warrants that it has all rights necessary to provide the Customer Data to Company as contemplated hereunder. Customer hereby grants to Company a non-exclusive, royalty-free, worldwide license to reproduce, distribute, and otherwise use the Customer Data as may be necessary for Company to provide the Service.
3.4 Compliance. Customer shall use the Service in compliance with all applicable local, state, national, and foreign laws, treaties, and regulations, including those related to data privacy, computer fraud and abuse, international communications, export laws, and the transmission of technical or personal data.
3.5 Sensitive Data. Customer acknowledges and agrees that: (i) the Service is not designed to store Sensitive Data; and (ii) Customer will not use the Service to store Sensitive Data and will not deliberately submit, post, or otherwise transmit as Customer Data any material that includes or constitutes Sensitive Data. The parties acknowledge that authorized penetration testing may result in the incidental discovery of Sensitive Data within Customer’s environment. Such incidental discovery is not a breach of this Section. Company shall handle any Sensitive Data so encountered in accordance with the DPA and shall retain it only for so long as necessary to evidence and remediate the associated finding; Customer shall handle it in accordance with Acceptable Use Policy Section 5.
4. COMPANY OBLIGATIONS
4.1 Service Delivery. Upon payment of applicable fees set forth in each Order Form, Company shall provide the Service in accordance with the Documentation and the terms of this Agreement. Company shall use commercially reasonable efforts to maintain the availability and performance of the Service.
4.2 Support and Maintenance. During the Subscription Period, subject to Customer’s payment of all applicable fees, Company will provide support, maintenance, and uptime for the Service in accordance with the support package selected by Customer on the applicable Order Form. Unless otherwise specified in an Order Form, Company shall provide standard email-based support during business hours.
4.3 Service Updates. From time to time, Company may provide upgrades, patches, enhancements, or fixes for the Service to its customers generally without additional charge ("Updates"), and such Updates will become part of the Service and subject to this Agreement; provided that Company shall have no obligation to provide any such Updates. Company may make improvements and modifications to the Service at any time in its sole discretion; provided that Company shall use commercially reasonable efforts to give Customer reasonable prior notice of any material changes.
4.4 Security. Company shall use commercially reasonable efforts to maintain the security and integrity of the Service and the Customer Data, including implementing and maintaining appropriate technical and organizational measures designed to protect against unauthorized access, destruction, loss, alteration, or disclosure of Customer Data.
4.5 Safe Testing Practices. Company’s Platform utilizes AI-driven agents that employ safe exploitation techniques designed for production environments. Company shall use commercially reasonable efforts to ensure that the Service does not intentionally cause disruption, data loss, or permanent damage to Customer’s systems within the authorized Testing Scope. Customer may configure risk tolerance levels per engagement through the Platform interface.
5. FEES AND PAYMENT
5.1 Fees. Customer shall pay Company the fees as set forth in each Order Form ("Fees"). Unless otherwise specified in an Order Form: (i) all Fees shall be invoiced annually in advance; (ii) the first invoice issued under the first Order Form executed by Customer is payable in full prior to provisioning of the Service, and each subsequent invoice is payable in U.S. dollars within thirty (30) days from the date of invoice; and (iii) all Fees paid are non-refundable and are not subject to set-off or deduction.
5.2 Taxes. All Fees and other amounts payable by Customer under this Agreement are exclusive of taxes and similar assessments. Customer is responsible for all sales, use, and excise taxes, and any other similar taxes, duties, and charges of any kind imposed by any governmental or regulatory authority on any amounts payable by Customer hereunder, other than any taxes imposed on Company’s income.
5.3 Overages. If Customer exceeds any Authorized User or usage limitations set forth on an Order Form, Company shall invoice Customer for such additional usage at the overage rates set forth on the Order Form (or if no overage rates are set forth, at Company’s then-current standard rates), on a pro-rata basis from the first date of such excess usage through the end of the applicable Subscription Period.
5.4 Late Payment. If Customer fails to make any payment when due, without limiting Company’s other rights and remedies: (i) Company may charge interest on the past due amount at the rate of 1.5% per month, calculated daily and compounded monthly or, if lower, the highest rate permitted under applicable law; (ii) Customer shall reimburse Company for all reasonable costs incurred in collecting any late payments, including attorneys’ fees; and (iii) if such failure continues for ten (10) days or more, Customer may be subject to a Service Suspension.
6. INTELLECTUAL PROPERTY
6.1 Company Ownership of Company IP. As between the parties, Company is and shall remain the sole and exclusive owner of all right, title, and interest (including without limitation all patent rights, copyrights, trademarks, trade secrets, and all other intellectual property rights) in and to: (i) the Service, the Platform, and all Company Technology; (ii) all software, AI models, machine learning algorithms, autonomous agent architectures, attack chain methodologies, exploitation techniques, and related technology embodied in or used to provide the Service; (iii) all Derived Data; (iv) all Company Usage Data; (v) the Documentation; (vi) any and all improvements, modifications, derivative works, and enhancements to any of the foregoing, regardless of whether such improvements result from Company’s processing of Customer’s environment or data; and (vii) all patent applications (whether pending or granted), copyrights, trade secrets, trademarks, and other intellectual property rights relating to the foregoing (collectively, the "Company Materials"). No rights or licenses are granted to Customer with respect to any Company Materials, including by implication, waiver, estoppel, exhaustion, or otherwise, except as expressly and unambiguously set forth in this Agreement.
6.2 Patent-Pending Technology. Customer acknowledges and agrees that the Service and Platform incorporate patent-pending technology and proprietary inventions owned by Company. Customer further acknowledges that Company has filed and may continue to file patent applications covering the methods, systems, processes, algorithms, and techniques embodied in the Service and Company Technology. Nothing in this Agreement shall be construed as granting Customer any license, right, or interest in or to any patent, patent application, or patent-pending technology of Company, whether currently existing or hereafter developed, except for the limited right to use the Service as expressly set forth in this Agreement.
6.3 AI and Machine Learning IP. Customer acknowledges and agrees that: (i) Company’s AI models, machine learning algorithms, neural networks, model weights, training data, training methodologies, decision logic, autonomous agent architectures, and all related technology are the exclusive property of Company and constitute Company’s most valuable trade secrets; (ii) the operation of the Service in Customer’s environment may result in the refinement, optimization, or improvement of Company’s AI models and algorithms, and all such refinements, optimizations, and improvements are and shall remain the sole and exclusive property of Company; (iii) no right, title, or interest in any AI model, algorithm, or Company Technology is transferred to Customer by virtue of the Service processing Customer’s data or environment; and (iv) Customer shall not attempt to extract, replicate, distill, or derive any AI model, algorithm, training data, or Company Technology from the Service or its outputs.
6.4 Derived Data and Aggregated Intelligence. Company shall own all right, title, and interest in and to all Derived Data. Customer hereby irrevocably assigns to Company any and all right, title, and interest Customer may have in Derived Data. Company may use Derived Data for any lawful purpose, including without limitation: (i) improving and enhancing the Service and Company Technology; (ii) training, retraining, and optimizing AI models and machine learning algorithms; (iii) developing new products, features, and services; (iv) generating threat intelligence, benchmarking data, and industry reports; and (v) any other purpose that does not identify Customer or Customer’s specific environment.
6.5 Customer Findings. Subject to Company’s ownership of the Company Materials, Company Technology, and Derived Data, Customer shall own the Findings generated from the testing of Customer’s specific environment and assets, solely to the extent such Findings contain information specific to Customer’s identified vulnerabilities and environment. For the avoidance of doubt, Customer’s ownership of Findings does not include: (i) the underlying testing methodologies, attack chains, exploitation techniques, or AI-driven logic used to generate such Findings, which are Company Technology; (ii) any generalized vulnerability patterns, threat intelligence, or aggregated insights, which are Derived Data; or (iii) the format, templates, or presentation structure of the Findings, which are Company IP.
6.6 No Challenge / Non-Assertion. Customer agrees that it shall not, and shall cause its affiliates and Authorized Users not to, directly or indirectly: (i) challenge, contest, or assist any third party in challenging or contesting the validity, enforceability, or ownership of any Company intellectual property rights, including any patents (pending or granted), patent applications, trademarks, copyrights, or trade secrets; (ii) file or cause to be filed any patent application or patent claim that covers or claims any invention, method, system, or process that is embodied in, derived from, or substantially similar to any Company Technology; (iii) assert any claim that Customer has acquired any ownership interest in any Company IP or Company Technology by virtue of this Agreement or Customer’s use of the Service; or (iv) register or attempt to register any trademark, domain name, or other identifier that is confusingly similar to any Company trademark or trade name.
6.7 Feedback. Customer may provide suggestions, comments, or other feedback to Company with respect to the Service ("Feedback"). Customer hereby irrevocably assigns to Company all right, title, and interest (including all intellectual property rights) in and to the Feedback, and to the extent such assignment is not enforceable, Customer hereby grants to Company a nonexclusive, worldwide, perpetual, irrevocable, transferable, sublicensable, royalty-free, fully paid-up license to use, reproduce, modify, create derivative works from, and exploit the Feedback for any purpose. Customer waives any moral rights or similar rights in the Feedback to the fullest extent permitted by law.
6.8 Reservation of Rights. The Service (including any software made available hereunder) is only licensed, and no title in or to the Service or any Company Technology passes to Customer. Any rights not expressly granted herein are hereby reserved by Company and its licensors. Customer shall not acquire any right, title, or interest in any Company IP except for the limited subscription rights expressly granted under this Agreement. For the avoidance of doubt, nothing in this Agreement shall be construed as a sale or transfer of any Company IP or Company Technology to Customer.
6.9 Injunctive Relief for IP Violations. Customer acknowledges and agrees that any breach of this Section 6 or of the use restrictions in Section 2.3 would cause Company irreparable harm for which monetary damages would be inadequate. Accordingly, in addition to any other remedies available at law or in equity, Company shall be entitled to seek injunctive or other equitable relief to prevent or restrain any such breach, without the requirement of posting a bond or proving actual damages.
7. CONFIDENTIALITY
7.1 Confidential Information. From time to time, either party may disclose or make available to the other party information about its business affairs, products, confidential intellectual property, trade secrets, and other sensitive or proprietary information that: (i) is marked or designated as "confidential" or something similar; or (ii) would be considered confidential by a reasonable person given the nature of the information or the circumstances of its disclosure (collectively, "Confidential Information"). Confidential Information does not include information that: (a) is or becomes publicly available through no fault of the receiving party; (b) was known to the receiving party prior to disclosure; (c) is rightfully obtained from a third party on a non-confidential basis; or (d) is independently developed by the receiving party without reference to or use of the disclosing party’s Confidential Information. For the avoidance of doubt, the following are deemed Confidential Information of Company without any marking or designation requirement: all Company Technology, Company IP, Company Materials, AI models, algorithms, patent-pending technology, source code, system architecture, and Derived Data. The Findings, Customer Data, and all pricing and payment terms shall also be considered Confidential Information of the respective disclosing party.
7.2 Obligations. The receiving party shall not use the disclosing party’s Confidential Information except to perform its obligations and exercise its rights hereunder, nor shall it disclose such Confidential Information to any person or entity except to the receiving party’s employees, contractors, and agents who have a need to know ("Representatives"). The receiving party will be responsible for all acts and omissions of its Representatives relating to Confidential Information. Each party may disclose Confidential Information to the limited extent required to comply with a court order or applicable law, provided that the party making the disclosure shall, if legally permitted, first give written notice to the other party.
7.3 Return of Confidential Information. Upon expiration or termination of the Agreement, the receiving party shall promptly return or destroy all copies of the disclosing party’s Confidential Information and, upon request, certify in writing that such information has been returned or destroyed. Each party’s obligations of non-use and non-disclosure with regard to Confidential Information will expire five (5) years from the date of termination or expiration; provided that with respect to any Confidential Information that constitutes a trade secret (including without limitation all Company Technology, AI models, algorithms, and patent-pending technology), such obligations of non-disclosure and non-use will survive in perpetuity or until such information ceases to qualify as a trade secret under applicable law through no wrongful act or omission of the receiving party, whichever is longer.
8. DATA PROTECTION
8.1 Personal Information Processing. Company’s rights and obligations with respect to Personal Information collected from individuals are set forth in Company’s Privacy Policy available at https://canima.com/privacy-policy. To the extent that Customer Data includes any Personal Information subject to applicable data protection laws (including GDPR and CCPA), the Data Processing Addendum ("DPA") available at https://canima.com/legal/dpa shall apply and is hereby incorporated by reference into this Agreement.
8.2 Usage Data. Company may collect and process usage data in connection with Customer’s use of the Service ("Usage Data"), including data used to identify the source and destination of communications, activity logs, and data used to optimize and maintain performance of the Service. As between Company and Customer, all right, title, and interest in Usage Data is owned solely and exclusively by Company.
8.3 Data Security. Company shall implement and maintain appropriate technical and organizational measures designed to protect Customer Data against unauthorized access, alteration, disclosure, or destruction, in accordance with industry best practices and applicable law.
9. TERM AND TERMINATION
9.1 Term. This Agreement shall commence upon the effective date of the first Order Form and, unless earlier terminated, shall last until the expiration of all Order Form Subscription Periods (the "Term"). For each Order Form, unless otherwise specified therein, the Subscription Period shall begin as of the effective date set forth on such Order Form and shall continue for the initial Subscription Period specified therein.
9.2 Renewal. Unless otherwise specified in an Order Form, each Order Form shall automatically renew for successive periods of one (1) year (each, a "Renewal Period"), unless either party provides written notice of non-renewal at least sixty (60) days prior to the expiration of the then-current Subscription Period. Fees for any Renewal Period may be increased by up to seven percent (7%) of the fees in the immediately preceding Subscription Period.
9.3 Termination for Breach. Either party may terminate this Agreement by providing written notice to the other party if the other party commits a material breach and fails to cure such breach within thirty (30) days of receipt of written notice specifying the material breach; provided that for payment defaults, such cure period will be ten (10) days.
9.4 Effect of Termination. Upon termination of this Agreement for any reason: (i) the license granted hereunder shall automatically terminate; (ii) Customer shall cease all access and use of the Service; (iii) Customer shall permanently delete any Company Confidential Information; and (iv) all outstanding Fees that accrued as of termination will become immediately due and payable. All fees due under an Order Form are non-cancellable and non-refundable, except where Customer terminates for Company’s material breach, in which case Customer shall be entitled to a pro-rated refund of prepaid, unutilized Fees. Sections 2.3 (Use Restrictions), 6 (Intellectual Property), 7 (Confidentiality), 8 (Data Protection), 10 (Warranties and Disclaimer), 11 (Limitation of Liability), 12 (Indemnification), and 13 (Miscellaneous) shall survive termination. For the avoidance of doubt, Company’s intellectual property rights under Section 6, Customer’s obligations under Sections 2.3 and 6.6, and Company’s ownership of Company IP, Company Technology, and Derived Data shall survive termination of this Agreement in perpetuity.
10. WARRANTIES AND DISCLAIMER
10.1 Company Warranty. Company warrants that the Service will be performed in a professional and workmanlike manner and will substantially conform in all material respects with the Documentation. Any warranty claim under this Section must be made in writing within thirty (30) days after performance of the nonconforming Service. Company’s sole obligation and Customer’s exclusive remedy is to re-perform the nonconforming Service or, at Company’s sole discretion, to terminate this Agreement and refund a prorated portion of prepaid Fees.
EXCEPT AS EXPRESSLY SET FORTH HEREIN, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF TITLE, NON-INFRINGEMENT, MERCHANTABILITY, AND FITNESS FOR A PARTICULAR PURPOSE. COMPANY DOES NOT WARRANT THAT THE SERVICE WILL IDENTIFY ALL VULNERABILITIES, THAT CUSTOMER’S SYSTEMS WILL BE SECURE AFTER USING THE SERVICE, OR THAT THE FINDINGS WILL BE COMPLETE, ACCURATE, OR ERROR-FREE. THE SERVICE IS A TOOL TO ASSIST WITH SECURITY ASSESSMENT AND IS NOT A GUARANTEE OF SECURITY.
11. LIMITATION OF LIABILITY
11.1 EXCLUSION OF CERTAIN DAMAGES. EXCEPT FOR (A) THE PARTIES’ INDEMNIFICATION OBLIGATIONS, (B) CUSTOMER’S BREACH OF SECTION 2.3 (USE RESTRICTIONS) OR SECTION 6 (INTELLECTUAL PROPERTY), (C) A PARTY’S BREACH OF ITS CONFIDENTIALITY OBLIGATIONS, OR (D) CUSTOMER’S BREACH OF ITS OBLIGATIONS UNDER SECTION 3.1 (AUTHORIZATION AND TESTING SCOPE), IN NO EVENT SHALL EITHER PARTY, NOR ITS DIRECTORS, EMPLOYEES, AGENTS, PARTNERS, SUPPLIERS, OR CONTENT PROVIDERS, BE LIABLE UNDER CONTRACT, TORT, STRICT LIABILITY, NEGLIGENCE, OR ANY OTHER LEGAL OR EQUITABLE THEORY FOR ANY LOST PROFITS, DATA LOSS, COST OF PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES, OR SPECIAL, INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES OF ANY KIND WHATSOEVER.
11.2 CAP ON LIABILITY. EXCEPT FOR (A) CUSTOMER’S BREACH OF SECTION 2.3 (USE RESTRICTIONS) OR SECTION 6 (INTELLECTUAL PROPERTY), (B) CUSTOMER’S BREACH OF SECTION 3.1 (AUTHORIZATION AND TESTING SCOPE), AND (C) CUSTOMER’S PAYMENT OBLIGATIONS, IN NO EVENT WILL EITHER PARTY’S AGGREGATE LIABILITY FOR ANY DIRECT DAMAGES ARISING OUT OF OR RELATED TO THIS AGREEMENT EXCEED THE FEES PAID (OR PAYABLE) BY CUSTOMER TO COMPANY HEREUNDER IN THE TWELVE (12) MONTHS PRIOR TO THE EVENT GIVING RISE TO THE CLAIM.
11.3 CUSTOMER IP BREACH LIABILITY. NOTWITHSTANDING THE FOREGOING, CUSTOMER’S LIABILITY FOR BREACH OF SECTION 2.3 (USE RESTRICTIONS), SECTION 6 (INTELLECTUAL PROPERTY), OR SECTION 6.6 (NO CHALLENGE / NON-ASSERTION) SHALL NOT BE SUBJECT TO THE LIMITATIONS SET FORTH IN SECTIONS 11.1 AND 11.2. COMPANY SHALL BE ENTITLED TO SEEK ALL AVAILABLE REMEDIES AT LAW AND IN EQUITY FOR SUCH BREACHES, INCLUDING WITHOUT LIMITATION INJUNCTIVE RELIEF, ACTUAL DAMAGES, CONSEQUENTIAL DAMAGES, AND DISGORGEMENT OF PROFITS.
12. INDEMNIFICATION
12.1 Company Indemnification. Company shall indemnify, defend, and hold harmless Customer from and against any losses, damages, liabilities, and costs (including reasonable attorneys’ fees) ("Losses") incurred by Customer resulting from any third-party claim alleging that the Service infringes or misappropriates such third party’s intellectual property rights; provided that Customer promptly notifies Company, cooperates with Company, and allows Company sole authority to control the defense and settlement. If such a claim is made or appears possible, Company may: (i) modify or replace the Service to make it non-infringing; or (ii) obtain the right for Customer to continue use. If neither alternative is commercially available, Company may terminate this Agreement and provide a prorated refund of prepaid Fees.
12.2 Customer Indemnification. Customer shall indemnify, defend, and hold harmless Company from and against any Losses resulting from any third-party claim: (i) alleging that Customer Data infringes such third party’s rights; (ii) arising from Customer’s use of the Service in a manner not authorized by this Agreement; (iii) arising from Customer’s failure to obtain proper authorization for penetration testing activities; or (iv) arising from Customer’s use of the Service in combination with systems, data, software, or technology not provided by Company.
12.3 Sole Remedy. THIS SECTION 12 SETS FORTH CUSTOMER’S SOLE REMEDIES AND COMPANY’S SOLE LIABILITY FOR ANY ACTUAL, THREATENED, OR ALLEGED CLAIMS THAT THE SERVICE INFRINGES, MISAPPROPRIATES, OR OTHERWISE VIOLATES ANY INTELLECTUAL PROPERTY RIGHTS OF ANY THIRD PARTY.
13. MISCELLANEOUS
13.1 Entire Agreement. This Agreement (including all Order Forms, the DPA, the Acceptable Use Policy, and the Privacy Policy) represents the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior or contemporaneous communications and proposals. In the event of any conflict between these Terms and an Order Form, the Order Form shall control.
13.2 Governing Law. This Agreement shall be governed by and construed in accordance with the laws of the State of Delaware, excluding its conflicts of law rules. The parties consent to exclusive jurisdiction and venue in the state and federal courts located in Wilmington, Delaware.
13.3 Assignment. Neither party may assign any of its rights or obligations hereunder without the other party’s consent; provided that either party may assign all of its rights and obligations without such consent to a successor-in-interest in connection with a merger, acquisition, or sale of substantially all of such party’s business relating to this Agreement.
13.4 Force Majeure. Except for payment obligations, neither party shall be liable for any failure to perform its obligations hereunder where such failure results from causes beyond such party’s reasonable control, including natural disasters, pandemics, acts of God, war, terrorism, riots, power failure, denial of service attacks, Internet failure, or acts of government.
13.5 Notices. All notices under this Agreement shall be in writing and shall be deemed given when received, if personally delivered or sent by certified or registered mail, or the day after it is sent if sent by recognized overnight delivery service or by email with confirmation of receipt. Notices must be sent to the contacts set forth on the Order Form.
13.6 Publicity. Customer agrees that Company may use Customer’s name and logo to refer to Customer as a customer of Company on its website and in marketing materials, unless Customer provides written notice to the contrary, which Customer may give at any time to [email protected]. Where Customer accesses the Service on behalf of its own clients, this Section grants Company no right to identify those clients, and Company shall not do so without the prior written consent of the client concerned. Any case study, testimonial, or other material describing Customer’s business outcomes, deployment details, or security posture requires Customer’s prior written approval for each such use.
13.7 Waiver and Severability. No failure or delay in exercising any right hereunder will operate as a waiver thereof. If any provision of this Agreement is held to be unenforceable, such provision shall be reformed only to the extent necessary to make it enforceable, and the remaining provisions shall remain in full force and effect.
13.8 Independent Contractors. The relationship of the parties is solely that of independent contractors. Nothing in this Agreement shall be construed to create an employer-employee, agency, partnership, or joint venture relationship.
13.9 Export Compliance. Customer represents and warrants that it is not a resident of a country embargoed by the U.S. government and is not listed on any applicable trade sanctions list. Customer shall not transfer, export, or re-export the Service in violation of any export or re-export control laws and regulations.
13.10 Counterparts. This Agreement is accepted by Customer upon execution of an Order Form referencing it. No separate signature on this Agreement is required. Order Forms may be executed in counterparts, each of which will be considered an original, but all of which together will constitute one and the same instrument. Electronic signatures on Order Forms shall have the same legal effect as original signatures.
Last Updated: 07/27/2026
This Agreement does not require a separate signature. Customer’s execution of an Order Form that references this Agreement constitutes Customer’s acceptance of all terms herein as of the date of such execution. The current version of this Agreement is available at https://canima.com/legal/msa.