End-User License Agreement
This agreement governs the general terms of use, licensing, and security boundaries for the ThreatModeler software.
Which deployment model applies to you?
Select Cloud/SaaS if you access the ThreatModeler platform hosted in our secure cloud environment. Select On-Premise if you download and install the ThreatModeler software directly on your own internal servers.
Which region applies to you?
Select North America (NA) if your company is located in the United States or Canada. Select International (INT) if your company is located anywhere else in the world (such as Europe, UK, APAC, or LATAM).
This ThreatModeler Cloud Subscription Agreement (this “Agreement”) governs the access to and use of ThreatModeler’s cloud-based threat modeling platform and related services (the “Product”). This Agreement entered into by and between ThreatModeler Software, Inc., a Delaware corporation with its principal place of business at 101 Hudson Street, 21st Floor Jersey City, New Jersey 07302, USA (“ThreatModeler”); and the entity or individual identified as the customer in an applicable Order Form or that otherwise downloads, installs, or uses the Software (“Customer”). This Agreement takes effect on the date of the initial Order Form, or the date on which Customer first downloads or accesses the Software, whichever is earlier (the “Effective Date”).
BY EXECUTING AN ORDER FORM THAT REFERENCES THIS AGREEMENT, BY CLICKING “I AGREE,” OR BY ACCESSING OR USING THE PRODUCT, CUSTOMER AGREES TO BE BOUND BY THIS AGREEMENT. IF YOU ARE ENTERING INTO THIS AGREEMENT ON BEHALF OF A COMPANY OR OTHER LEGAL ENTITY, YOU REPRESENT THAT YOU HAVE THE AUTHORITY TO BIND SUCH ENTITY TO THIS AGREEMENT.
1. DEFINITIONS
1.1. "Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where "control" means direct or indirect ownership of more than fifty percent (50%) of the voting interests of the subject entity.Notwithstanding the foregoing, an "Affiliate" shall not include any entity that is a direct competitor of ThreatModeler. ThreatModeler reserves the right, in its reasonable business judgment, to determine whether an entity qualifies as a direct competitor.
1.2. "Core AI Functionality" means any features, models, or autonomous agents within the Product that utilize machine learning or artificial intelligence technologies to analyze, generate, or automate threat models, security requirements, and design content. The Core AI Functionality operates in: (a) "Default AI Mode," where ThreatModeler processes data using its designated third-party AI subprocessors, or (b) "BYOAI Mode," where Customer configures the Product to process data using its own designated third-party AI provider.
1.3. "Authorized User" means a specific, uniquely identified individual (an employee or contractor of Customer or its Affiliates) who has been authorized by Customer to access and use the Product. Each Authorized User must be assigned unique user credentials (e.g., a unique user ID and password), and a user license may not be shared or used by more than one individual. However, user licenses may be permanently reassigned to a new individual replacing one who has terminated their employment or contract, or otherwise changed job status or function and no longer requires access to the Product. Customer is fully responsible for all acts and omissions of its Authorized Users.
1.4. "Confidential Information" means all information disclosed by a party ("Disclosing Party") to the other party ("Receiving Party"), whether orally or in writing, that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure. "Confidential Information" includes, without limitation: (a) For ThreatModeler: The Product and Services in their entirety, including their underlying technology, source code, AI prompts, rules, agent workflows, telemetry, performance data, security reports, product roadmaps, and pricing; (b) For Customer: The Customer Data (Inputs), and any Customer-specific system vulnerabilities, security gaps, or proprietary architectural details contained within any generated Outputs; (c) For Both Parties: The terms and conditions of this Agreement and all Order Forms. Confidential Information does not include any information that: (i) is or becomes generally known to the public without breach of any obligation owed to the Disclosing Party; (ii) was known to the Receiving Party prior to its disclosure by the Disclosing Party without breach of any obligation; (iii) is received from a third party without breach of any obligation; or (iv) was independently developed by the Receiving Party without use of or reference to the Disclosing Party's Confidential Information.
1.5. "Customer Data" means any proprietary information, data, or materials uploaded, submitted, or inputted into the Product by Customer or its Authorized Users ("Inputs"). For the avoidance of doubt, Customer Data does not include any threat libraries, security controls, templates, rules, or threat modeling intelligence pre-existing within or generated by the Product ("ThreatModeler Content").
1.6. "Documentation" means ThreatModeler's official, generally available technical and functional documentation for the applicable Product, as made available on ThreatModeler's support portal or other designated website. For the avoidance of doubt, "Documentation" specifically excludes any and all marketing materials, websites, press releases, proposals, or non-technical blog posts, and shall not be construed as a warranty or commitment for the development or delivery of any future functionality or features.
1.7. "Feedback" means any suggestion, enhancement request, recommendation, correction, or other feedback provided by Customer or its Authorized Users relating to the operation or functionality of the Product.
1.8. "Intellectual Property Rights" means any and all registered and unregistered rights granted, applied for, or otherwise now or hereafter in existence under or related to any patent, copyright, trademark, trade secret, database protection, or other intellectual property law, and all similar or equivalent rights or forms of protection, in any part of the world. This includes, without limitation:(a) all rights in and to inventions (whether patentable or not), discoveries, and improvements; (b) all rights in and to works of authorship, including copyrights, mask work rights, and moral rights; (c) all rights in and to trade names, logos, trademarks, and service marks (together with all of the goodwill associated therewith); (d) all rights in and to confidential information, know-how, and trade secrets; and (e) all rights in and to domain names, website designs, and user interface designs.
1.9. "Order" means the binding transactional document for the purchase of Products. An Order is formed when: (a) Customer executes a "Quote" or "Order Form" issued by ThreatModeler; or (b) ThreatModeler accepts, in writing or by beginning performance, a "Purchase Order" or "PO" issued by Customer against a valid Quote. A PO issued by Customer becomes a binding Order only upon ThreatModeler's written acceptance. For the avoidance of doubt, any Purchase Order issued by Customer is accepted by ThreatModeler solely for the purpose of administrative convenience, invoicing, and billing; any pre-printed, standard, or conflicting terms and conditions contained in or attached to such Customer-issued PO are hereby expressly rejected by ThreatModeler and shall be null, void, and of no legal force or effect, as set forth in Section 14.13(c).
1.10. "Product(s)" means the commercially available offerings of ThreatModeler subscribed to by Customer as identified in an applicable Order. Unless otherwise specified in an Order, the core "Product" subscription consists of the following components: (a) A subscription to access and use the "Platform," which refers to ThreatModeler's proprietary cloud-based software, including its integrated "Core AI Functionality"; (b) Any "Updates" to the Platform that ThreatModeler makes generally available to its subscribed customers; (c) The applicable tier of "Support Services," as set forth in Section 1.14; (d) Access to the official "Documentation." For the avoidance of doubt, Professional Services and Training are not included as part of the standard Product subscription and must be purchased separately pursuant to an Order and governed by a Statement of Work (SOW). The term "Product" explicitly excludes any third-party software, hardware, or services required by Customer to access or use the offering.
1.11. "Professional Services" means expert services provided by ThreatModeler to Customer, which are separate from the subscribed Product and are governed by a Statement of Work ("SOW"). Professional Services are purchased on a project or time-and-materials basis and may include, but are not limited to, implementation assistance, system configuration, dedicated training, and custom content or report creation. Unless otherwise expressly agreed in a SOW, all Professional Services are provided on a non-"work-for-hire" basis. All intellectual property rights in any deliverables, tools, or methodologies used or created by ThreatModeler in the course of providing Professional Services shall remain the exclusive property of ThreatModeler, subject to the limited license rights granted to Customer in the applicable SOW or Section 13.4 of this Agreement. The successful delivery of Professional Services is dependent on Customer's timely cooperation and fulfillment of its responsibilities as outlined in the applicable SOW.
1.12."Scope of Use" means the specific usage limits, tiers, and metrics for the purchased Product subscription, as expressly set forth in the applicable Order. Common metrics include, but are not limited to, the number of Authorized Users and the number of Threat Models. Customer's use of the Product must not exceed the Scope of Use.
1.13. "Subscription Term" means the initial term for the subscription to the Services as specified in an Order, and any subsequent renewal terms.
1.14."Support Services" means the technical support, maintenance, and service level commitments provided by ThreatModeler for the subscribed Product. The specific scope, support channels, response times, and uptime commitments for the Support Services are detailed in the ThreatModeler Support Services Policy and Service Level Agreement ("SLA") available at threatmodeler.ai/legal/support-program.
2. LICENSE, SUPPORT, AND UPDATES
2.1. Subscription and Access Rights. Subject to Customer’s full and timely payment of all applicable fees and its continuous compliance with the terms of this Agreement, ThreatModeler grants Customer a subscription for its Authorized Users to access and use the subscribed Product during the applicable Subscription Term. This subscription includes a limited, non-exclusive, non-transferable, and non-sublicensable right to access and use the Product, solely for Customer's internal business purposes and strictly within the Scope of Use defined in the applicable Order. Customer agrees that no user license will be provided to any employee or contractor of an Affiliate that is a direct competitor of ThreatModeler, as determined in accordance with Section 1.1.
2.2. Support, Maintenance, and Updates. ThreatModeler will provide technical support and maintenance for the Product in accordance with the Support Services Policy and SLA referenced in Section 1.14. ThreatModeler reserves the right to update the Support Services Policy from time to time, provided that any such update will not result in a material and adverse decrease of the Support Services or SLA commitments during Customer's then-current Subscription Term.
2.3. Product Modifications. Customer acknowledges that the Product is an evolving, subscription-based offering. ThreatModeler reserves the right to enhance or modify the Product from time to time. However, ThreatModeler will not, during an active Subscription Term, make any changes that result in a material diminution of the overall functionality and value of the Product as it existed at the beginning of that Term.
3. ACCEPTABLE USE AND CUSTOMER OBLIGATIONS
3.1. General Responsibilities. Customer is and shall remain solely responsible and liable for:
(a) Authorized User Conduct: All activities conducted by its Authorized Users within the Product, and for ensuring their compliance with the terms of these . A breach by an Authorized User is deemed a breach by Customer.
(b) Customer Data: The accuracy, legality, quality, and integrity of all Customer Data, including obtaining all necessary rights, consents, and permissions to provide, use, and process the Customer Data as contemplated by this Agreement.
(c) Account Security: Maintaining the security and confidentiality of all Authorized User account credentials and for promptly notifying ThreatModeler of any unauthorized access or use.
(d) Compliance with Laws: Ensuring that its use of the Product complies with all applicable local, state, federal, and international laws and regulations.
3.2. Use Restrictions. Customer shall not, and shall not permit any Authorized User or any third party to, perform any of the following actions:
(a) Resale and Sublicensing: Sell, resell, lease, sublicense, or otherwise provide access to the Product to any third party, or use the Product to provide service bureau, timesharing, or other managed services for the benefit of any third party.
(b) Modification and Derivative Works: Modify, translate, adapt, or create derivative works based upon the Product or any part thereof.
(c) Reverse Engineering: Reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code, underlying ideas, or non-public APIs of the Product, except to the extent such a restriction is expressly prohibited by applicable law.
(d) Interference: Interfere with, disrupt, or create an undue burden on the integrity, performance, or security of the Product or the data contained therein.
(e) Security Testing: Conduct any security assessments, penetration tests, vulnerability scans, or load testing on the Product or its infrastructure without the prior express written consent and coordination of ThreatModeler.
(f) Malicious Use: Use the Product to store or transmit any viruses, worms, Trojan horses, or other malicious code, or to engage in any phishing, spamming, or denial-of-service attacks.
(g) Unlawful or Infringing Content: Use the Product to store or transmit any content that is infringing, libelous, or otherwise unlawful or tortious, or that violates the privacy or intellectual property rights of any third party.
(h) Public Benchmarking: Publicly disseminate any performance information, analysis, or competitive benchmarks of the Product without ThreatModeler's prior written consent.
(i) Circumvention: Attempt to circumvent any Scope of Use restrictions or other license control mechanisms within the Product.
(j) Multiplexing and Pooling: Use any technology, software, script, or automated agent to pool connections, redirect requests, or "multiplex" access to the Product in a manner that bypasses the Authorized User license limits, or allows unlicensed individuals to indirectly access, query, or utilize the Product's functionalities.
3.3. High-Risk Activities Prohibition. The Product is not designed, manufactured, or intended for use in hazardous environments requiring fail-safe performance, including but not limited to the operation of nuclear facilities, aircraft navigation or communication systems, air traffic control, direct life-support machines, or weapons systems ("High-Risk Activities"). Customer expressly agrees that it will not use, or permit the use of, the Product for any High-Risk Activities. ThreatModeler and its suppliers expressly disclaim any express or implied warranty of fitness for such purposes.
3.4. Prohibition on Sensitive Personal Information. Customer agrees that it shall not upload or process any "Sensitive Data" in the Product. Customer acknowledges that the Product is not designed for such data and ThreatModeler has no liability for any Sensitive Data processed in violation of this section.
"Sensitive Data" includes any data that requires heightened protection under applicable law, including, but not limited to, health information (HIPAA), financial information (GLBA, PCI DSS), government-issued IDs, and "special categories of personal data" under GDPR.
Customer shall indemnify, defend, and hold harmless ThreatModeler from any damages, losses, and costs arising from or related to Customer's breach of this Section 3.4.
4. FEES, PAYMENT, AND AUDITS
4.1. Fees. Customer shall pay all fees specified in all applicable Orders ("Fees"). Except as expressly provided in this Agreement, all payment obligations are non-cancellable and all Fees paid are non-refundable. The Fees are based on the Product subscription purchased and not on actual usage.
4.2. Invoicing and Payment. Unless otherwise specified in an Order Form, all Fees will be invoiced annually in advance. All invoices are due and payable net thirty (30) days from the invoice date, without offset or deduction. Late payments will accrue interest at a rate of 1.5% per month or the maximum rate permitted by law, whichever is lower.
4.3. Taxes.
a) Fees are stated exclusive of any taxes, levies, duties, or similar governmental assessments, including value-added, sales, use, or withholding taxes (collectively, "Taxes"). Customer is responsible for paying all Taxes associated with its purchases hereunder.
b) If ThreatModeler has the legal obligation to pay or collect Taxes for which Customer is responsible, the appropriate amount shall be invoiced to and paid by Customer, unless Customer provides ThreatModeler with a valid tax exemption certificate.
c) If Customer is required by law to withhold any Taxes from its payments to ThreatModeler, Customer must provide ThreatModeler with an official tax receipt or other appropriate documentation. Customer agrees to increase the payment to ThreatModeler by the amount necessary to ensure that ThreatModeler receives a net amount equal to the full amount of the Fees it would have received without the deduction.
4.4. Suspension of Service and Termination. If any invoiced amount is more than thirty (30) days overdue, ThreatModeler may, without limiting its other rights and remedies: (a) suspend Customer's access to the Product upon ten (10) days' written notice until such amounts are paid in full, and (b) if the failure to pay continues for sixty (60) days or more, terminate this Agreement for cause under Section 5.3.
4.5. Invoice Disputes. Customer must notify ThreatModeler in writing of any good-faith dispute with respect to an invoice within fifteen (15) days of the invoice date. If Customer fails to do so, Customer is deemed to have waived its right to dispute that invoice, and the invoice will be considered final and payable.
4.6. Usage Verification. Customer acknowledges and agrees that the Product includes a self-auditing function that electronically monitors and reports on Customer’s usage metrics (e.g., number of Authorized Users, number of Threat Models). ThreatModeler shall have the right to use this reporting data to verify Customer's compliance with the Scope of Use.
If Customer's use of the Product exceeds its purchased entitlement as set forth in the applicable Order, ThreatModeler will invoice Customer for such overage at ThreatModeler's then-current list prices for the entire period of non-compliance. Customer agrees to pay such invoice in accordance with Section 4.2 of this Agreement.
5. TERM AND TERMINATION
5.1. Agreement Term. The term of this Agreement commences on the Effective Date and continues as long as a Subscription Term for any Product is in effect, unless terminated earlier in accordance with its terms.
5.2. Subscription Term and Auto-Renewal. Each Subscription Term will automatically renew for additional periods equal to the expiring term (or one year, if the expiring term is longer than one year), unless either party gives the other written notice of non-renewal at least sixty (60) days before the end of the then-current Subscription Term. ThreatModeler reserves the right to increase the fees for any renewal term by providing notice thereof at least fifteen (15) days prior to the end of the current term.
5.3. Termination for Cause. A party may terminate this Agreement for cause: (i) upon thirty (30) days' written notice to the other party of a material breach if such breach remains uncured at the expiration of such period, or (ii) if the other party becomes the subject of a petition in bankruptcy or any other proceeding relating to insolvency, receivership, or assignment for the benefit of creditors.
5.4. Termination for Convenience by Customer. Customer may terminate this Agreement for its convenience at any time by providing ninety (90) days' prior written notice to ThreatModeler. Upon such termination, Customer shall not be entitled to any refund, credit, or pro-rata return of any Fees paid upfront (as all payment obligations are non-cancellable and all Fees paid are non-refundable under Section 4.1). Any unpaid Fees associated with the remaining duration of the committed Subscription Term shall become immediately due and payable.
5.5. Effect of Termination. Upon any termination or expiration of this Agreement: (a) all rights and subscriptions granted to Customer hereunder shall immediately terminate and Customer shall cease all use of the Product; (b) Customer shall immediately pay any unpaid fees accrued prior to the effective date of termination, as well as any future fees that become due under Section 5.4; and (c) each party will, upon request, promptly return or securely destroy all Confidential Information of the other party.
5.6. Data Portability and Deletion. Upon Customer's written request made within thirty (30) days after the effective date of termination, ThreatModeler will make Customer Data available for export. After this 30-day period, ThreatModeler will have no further obligation to maintain any Customer Data and will thereafter delete it in accordance with its standard policies.
5.7. Survival. The following sections shall survive any termination or expiration of this Agreement: Section 1 (Definitions), 4 (Fees, Payment, and Audits), 5.5 (Effect of Termination), 5.7 (Survival), 6 (Confidentiality), 7 (Intellectual Property Rights), 9 (Mutual Indemnification), 10 (Limitation of Liability), and 14 (General Provisions).
5.8. Reinstatement of Lapsed Subscription. If any subscription for a Product expires or is terminated, and Customer seeks to reinstate such subscription at a later date, such reinstatement shall be subject to ThreatModeler's then-current policies. At a minimum, reinstatement will require Customer to pay: (a) a reinstatement fee; (b) all subscription fees that would have been payable during the period of the lapse; and (c) the subscription fees for the new Subscription Term.
6. DATA PROTECTION AND SECURITY
6.1. Security Program and Safeguards. ThreatModeler will implement and maintain a comprehensive written information security program, which includes administrative, physical, and technical safeguards aligned with accepted industry standards. This program is designed to protect the security, confidentiality, and integrity of Customer Data against accidental or unlawful destruction, loss, alteration, or unauthorized access, use, or disclosure. ThreatModeler will not materially decrease the overall security of the Product during a Subscription Term.
6.2. Data Processing, DPA, and Subprocessors.
(a) Data Processing Addendum. The parties acknowledge and agree that with respect to the processing of "Personal Data", ThreatModeler acts as a "Processor" or "Service Provider" and Customer is the "Controller" or "Business". All processing of Personal Data is subject to and governed by ThreatModeler's Data Processing Addendum ("DPA"), located at threatmodeler.ai/legal/dpa, which is hereby incorporated by reference.
(b) Subprocessors. Customer acknowledges that ThreatModeler uses third-party subprocessors to provide the Product. A current list of ThreatModeler's subprocessors is maintained at threatmodeler.ai/legal/subprocessors (the "Subprocessor List").
(c) New Subprocessors and Right to Object. ThreatModeler will provide Customer with at least thirty (30) days' prior written notice of any new subprocessor appointment by updating the Subprocessor List and notifying Customer of such update. Customer may, within fifteen (15) days of such notice, object in writing to the new subprocessor on reasonable, data protection-related grounds. If the parties cannot resolve the objection, Customer may, as its sole and exclusive remedy, terminate the applicable subscription for cause.
6.3. Security Incident Response.
(a) Notification. ThreatModeler will notify Customer without undue delay upon becoming aware of a "Security Incident," which is defined as the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Customer Data processed by ThreatModeler.
(b) Cooperation. ThreatModeler will provide reasonable cooperation to Customer in the investigation of the Security Incident, including providing any relevant information reasonably requested by Customer regarding the nature of the incident, the categories of data affected, and the corrective actions being taken.
6.4. Customer's Security Responsibilities. Customer acknowledges that its security responsibilities are a critical component of overall data protection. Customer is solely responsible for: (a) securely managing all Authorized User account credentials; (b) configuring and using the Product in a secure manner in accordance with the Documentation; and (c) ensuring the security of its own systems and devices used to access the Product and (d) notifying ThreatModeler of any known or suspected security breach originating from its own systems or involving its Authorized User account credentials.
7. CONFIDENTIALITY
7.1. Obligation of Confidentiality. The Receiving Party shall:
(a) use the same degree of care that it uses to protect the confidentiality of its own confidential information of like kind (but in no event less than a reasonable degree of care);
(b) not use any Confidential Information of the Disclosing Party for any purpose outside the scope of this Agreement; and
(c) except as otherwise authorized by the Disclosing Party in writing, limit access to Confidential Information to those of its and its Affiliates’ employees, contractors, and agents who have a legitimate "need to know" for purposes consistent with this Agreement and who are bound by confidentiality obligations containing protections no less stringent than those herein. The Receiving Party shall be liable for any breach of this Section 7 by its representatives.
7.2. Compelled Disclosure. A Receiving Party may disclose Confidential Information of the Disclosing Party to the extent compelled by law or a valid court order to do so, provided the Receiving Party gives the Disclosing Party prior written notice of the compelled disclosure (to the extent legally permitted) and reasonable assistance, at the Disclosing Party's cost, if the Disclosing Party wishes to contest or seek a protective order for the disclosure.
7.3. Injunctive Relief. The parties agree that a breach of this Section 7 may cause irreparable harm for which monetary damages would not be an adequate remedy. Accordingly, the Disclosing Party shall be entitled to seek injunctive or other equitable relief to prevent or curtail any such breach, without the necessity of posting a bond.
8. INTELLECTUAL PROPERTY RIGHTS
8.1. ThreatModeler's Intellectual Property.
As between the Parties, ThreatModeler and its licensors exclusively own and retain all right, title, and interest in and to the Product, including the Platform, all generated threat models, reports, security requirements, and outputs (collectively, "Outputs"), and all underlying software, threat libraries, and technology.
Subject to Customer's payment of all Fees, ThreatModeler hereby grants Customer a non-exclusive, non-transferable, non-sublicensable license to use, copy, and distribute the Outputs solely for Customer's internal business and compliance purposes during the applicable Subscription Term, provided that Customer shall retain all rights in its proprietary Inputs contained within such Outputs.
8.2. Customer's Intellectual Property.
As between the parties, Customer exclusively owns and retains all right, title, and interest in and to the Customer Data, including all intellectual property rights therein.
8.3. License from Customer to Provide the Product.
Customer hereby grants ThreatModeler and its Affiliates a worldwide, limited-term, non-exclusive, royalty-free license to host, copy, transmit, process, and display Customer Data as reasonably necessary for ThreatModeler to provide, maintain, and support the Product for Customer in accordance with this Agreement. This license terminates upon the deletion of Customer Data as described in Section 5.6.
8.4. Ownership of Feedback.
Customer acknowledges and agrees that any suggestions, enhancement requests, recommendations, corrections, or other feedback provided by Customer or its Authorized Users relating to the operation of the Product ("Feedback") shall be owned by ThreatModeler. Customer hereby assigns to ThreatModeler all right, title, and interest in and to any Feedback, without any right to compensation. ThreatModeler is under no obligation to use or implement any Feedback.
8.5. ThreatModeler's Rights to Use Non-Identifiable Data.
(a) Data Collection and Ownership. Customer acknowledges and agrees that ThreatModeler has the right to collect, analyze, and use technical, operational, and telemetry data relating to the provision, use, and performance of the Product, including data derived from Customer Data (collectively, "Usage Data"). For the avoidance of doubt, ThreatModeler shall exclusively own all right, title, and interest in and to the Usage Data.
(b) Permitted Uses. Provided that such Usage Data is in an aggregated and de-identified format that does not, and cannot be used to, identify Customer, its Affiliates, or any individual ("Anonymized Data"), ThreatModeler shall have the perpetual, irrevocable, worldwide, royalty-free right to use, reproduce, modify, and create derivative works of such Anonymized Data for any lawful business purpose.
(c) Illustrative Examples of Permitted Uses. Without limiting the generality of the foregoing, these business purposes include, but are not limited to:
i. Product Improvement: Analyzing usage patterns to enhance and optimize the Product's performance, security, and usability.
ii. New Feature Development: Using insights from Anonymized Data to inform the development of new features, products, and services.
iii. Benchmarking and Industry Analysis: Creating and publishing aggregated statistical reports, industry trend analyses, and benchmarks (e.g., "average number of threats identified in the financial services sector").
(d) Clarification on Customer Data. For the absolute avoidance of doubt, ThreatModeler will not use Customer's un-anonymized, identifiable Customer Data for any purpose other than providing the Product to Customer as described in this Agreement.
8.6. API and Integration Intellectual Property.
To the extent that Customer develops any custom connectors, scripts, or software integrations designed to connect Customer’s internal tools or IDEs to the Product via ThreatModeler’s Application Programming Interfaces (APIs) or the Model Context Protocol (MCP) Server (collectively, "Integrations"), Customer shall retain ownership of its custom code for such Integrations.
However, Customer acknowledges and agrees that: (a) such Integrations shall not be construed as creating any joint intellectual property rights, (b) ThreatModeler retains exclusive ownership of the underlying APIs, the MCP Server technology, and the platform architecture, and (c) nothing in this Agreement shall restrict ThreatModeler from independently developing, licensing, or commercializing similar integrations, connectors, or features for its other customers.
9. WARRANTIES AND DISCLAIMERS
9.1. Mutual Warranties. Each party represents and warrants that it has the legal power and authority to enter into this Agreement and that it will comply with all applicable laws in its performance hereunder.
9.2. Limited Performance Warranty. ThreatModeler warrants that, during an applicable Subscription Term, the Product will perform materially in accordance with the applicable Documentation. For any breach of this warranty, Customer's sole and exclusive remedy shall be the Service Credits as specified in the Support Services Policy located at threatmodeler.ai/legal/support-program.
9.3. WARRANTY DISCLAIMER. EXCEPT FOR THE EXPRESS WARRANTIES PROVIDED IN SECTION 9.2 AND SECTION 13 OF THIS AGREEMENT, AND TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE PRODUCT AND ANY SERVICES ARE PROVIDED "AS IS". WHILE THREATMODELER WARRANTS IT WILL USE COMMERCIALLY REASONABLE SKILL AND CARE IN PROVIDING THE PRODUCT, IT EXPRESSLY DISCLAIMS ALL OTHER WARRANTIES AND REPRESENTATIONS, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. CUSTOMER ACKNOWLEDGES THAT ANY OUTPUTS, SUGGESTIONS, OR CONTENT GENERATED BY THE CORE AI FUNCTIONALITY ARE PROVIDED FOR INFORMATIONAL PURPOSES ONLY, WITHOUT WARRANTY OF ANY KIND, AND CUSTOMER IS SOLELY RESPONSIBLE FOR REVIEWING, VALIDATING, AND TESTING THE ACCURACY AND APPROPRIATENESS OF ANY SUCH OUTPUTS. THREATMODELER DOES NOT WARRANT THAT THE USE OF THE PRODUCT WILL BE UNINTERRUPTED OR ERROR-FREE. CUSTOMER ACKNOWLEDGES AND AGREES THAT THREATMODELER SHALL NOT BE LIABLE FOR DELAYS, INTERRUPTIONS, SERVICE FAILURES, OR OTHER PROBLEMS INHERENT IN THE USE OF THE INTERNET AND ELECTRONIC COMMUNICATIONS OR OTHER SYSTEMS OUTSIDE THE REASONABLE CONTROL OF THREATMODELER.
10. INDEMNIFICATION
10.1. Indemnification by ThreatModeler. ThreatModeler will defend Customer against any third-party claim, demand, suit, or proceeding ("Claim") alleging that Customer's use of the Product, as delivered by ThreatModeler and used in accordance with this Agreement, directly infringes a valid U.S. patent, copyright, or registered trademark of such third party. ThreatModeler will indemnify Customer for any damages, attorney fees, and costs finally awarded against Customer as a result of, or for amounts paid by Customer under a court-approved settlement of, such a Claim.
10.2. Mitigation and Remedy. If the Product becomes, or in ThreatModeler's opinion is likely to become, the subject of an infringement Claim, ThreatModeler may, at its option and expense:
(a) procure for Customer the right to continue using the Product;
(b) replace or modify the Product with a non-infringing but functionally equivalent alternative; or
(c) if options (a) and (b) are not commercially reasonable, terminate Customer's subscription for the infringing Product and provide a pro-rata refund of any prepaid fees for the remainder of the terminated Subscription Term.
10.3. Exclusions. ThreatModeler's obligations under Section 10.1 will not apply to any Claim to the extent it arises from: (a) use of the Product in combination with hardware, software, or data not provided by ThreatModeler; (b) Customer Data; (c) any modification to the Product not made by ThreatModeler; or (d) Customer's use of a version of the Product other than the then-current version, if the infringement would have been avoided by use of the current version made available to Customer.
10.4. Indemnification by Customer. Customer will defend ThreatModeler against any Claim made or brought against ThreatModeler by a third party arising from or related to: (i) the Customer Data, including any allegation that the Customer Data infringes or misappropriates the rights of a third party; or (ii) Customer’s use of the Product in breach of this Agreement or applicable law. Customer will indemnify ThreatModeler for any damages, attorney fees, and costs finally awarded against ThreatModeler as a result of, or for amounts paid by ThreatModeler under a court-approved settlement of, such a Claim.
10.5. Indemnification Procedure. The indemnifying party's obligations are contingent upon the indemnified party: (a) promptly giving written notice of the Claim; (b) giving the indemnifying party sole control of the defense and settlement of the Claim (provided that the indemnifying party may not settle any Claim unless the settlement unconditionally releases the indemnified party of all liability and does not include a statement as to, or an admission of, fault, culpability, or failure to act by or on behalf of the indemnified party); and (c) providing all reasonable assistance, at the indemnifying party's expense.
10.6. Exclusive Remedy. This Section 9 states the indemnifying party's sole liability to, and the indemnified party's exclusive remedy against, the other party for any type of third-party infringement claim described in this section.
11. LIMITATION OF LIABILITY
11.1. DISCLAIMER OF INDIRECT AND CONSEQUENTIAL DAMAGES.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL EITHER PARTY OR ITS SUPPLIERS HAVE ANY LIABILITY TO THE OTHER PARTY FOR ANY LOST PROFITS, LOST DATA, LOSS OF USE, BUSINESS INTERRUPTION, COSTS OF PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES, OR FOR ANY INDIRECT, SPECIAL, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES, HOWEVER CAUSED AND, WHETHER IN CONTRACT, TORT OR UNDER ANY OTHER THEORY OF LIABILITY, AND WHETHER OR NOT THE PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
11.2. LIMITATION OF AGGREGATE LIABILITY.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL EITHER PARTY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT, WHETHER IN CONTRACT, TORT OR UNDER ANY OTHER THEORY OF LIABILITY, EXCEED THE TOTAL AMOUNT OF FEES ACTUALLY PAID BY CUSTOMER TO THREATMODELER HEREUNDER IN THE TWELVE (12) MONTHS PRECEDING THE DATE OF THE FIRST INCIDENT GIVING RISE TO THE LIABILITY.
11.3. EXCLUSIONS FROM LIMITATIONS ("UNLIMITED LIABILITY CARVE-OUTS").
THE LIMITATIONS SET FORTH IN SECTIONS 11.1 AND 11.2 SHALL NOT APPLY TO:
(a) A PARTY'S INDEMNIFICATION OBLIGATIONS UNDER SECTION 10;
(b) A VIOLATION OF THE OTHER PARTY'S INTELLECTUAL PROPERTY RIGHTS;
(c) CUSTOMER'S UNPAID PAYMENT OBLIGATIONS FOR FEES DUE UNDER ANY ORDER FORM; OR
(d) LIABILITY ARISING FROM A PARTY'S GROSS NEGLIGENCE OR WILLFUL MISCONDUCT.
11.4. Allocation of Risk. The parties acknowledge and agree that the essential purpose of this Section 11 is to allocate the risks under this Agreement between the parties and that the fees have been set and this Agreement entered into in reliance upon these limitations of liability.
12. CORE AI FUNCTIONALITY
12.1. General and Disclaimer of Warranties. The Product includes Core AI Functionality designed to enhance the threat modeling process. Customer retains full control over the use of this functionality and is solely responsible for reviewing, validating, and accepting any output generated by it. CUSTOMER ACKNOWLEDGES AND AGREES THAT AI-GENERATED OUTPUTS ARE SUBJECT TO MACHINE LEARNING LIMITATIONS AND MAY OCCASIONALLY CONTAIN ERRORS, OMISSIONS, OR INCORRECT THREAT PREDICTIONS ("HALLUCINATIONS"). ALL AI-GENERATED OUTPUT IS PROVIDED STRICTLY "AS IS," WITHOUT WARRANTY OF ANY KIND, AND ITS USE IS AT CUSTOMER'S SOLE RISK AND DISCRETION.
12.2. Default AI Mode and Data Processing. Unless Customer configures the BYOAI Mode, the Product will operate in Default AI Mode, using ThreatModeler's designated AI subprocessor as listed on its Subprocessor List. In this mode, ThreatModeler will process Customer Data, including Inputs and Outputs, solely to provide the Core AI Functionality.
12.3. BYOAI Mode. If Customer subscribes to and configures the "Bring Your Own AI" (BYOAI) functionality, Customer may connect its own third-party AI provider account. In BYOAI Mode, Customer acknowledges that:
(a) All AI-related processing will occur directly between ThreatModeler and Customer's designated AI provider, under the terms of the agreement between Customer and that provider.
(b) Customer's AI provider is not a subprocessor of ThreatModeler. Customer is solely responsible for the security, privacy, and compliance of its relationship with its AI provider.
12.4. Optional AI Model Improvement Program.
(a) Participation. To improve the accuracy, relevance, and performance of ThreatModeler’s proprietary AI models, Customer agrees that ThreatModeler may utilize Anonymized Data (as defined in Section 8.5(b)) derived from Customer’s Inputs and Outputs to train, validate, and improve such models by default.
(b) Right to Opt-Out. Customer’s participation in the AI model improvement program is entirely voluntary. Customer may, at any time during the Subscription Term, opt-out of this program by submitting a written request via email to privacy@threatmodeler.com.
(c) Effect of Opt-Out. Upon receipt of such opt-out request, ThreatModeler shall ensure that the Customer’s tenant configuration is set to restrict any data extraction for AI training, and shall immediately cease using any new Anonymized Data derived from Customer’s account for AI model training purposes.
(d) No Training Without Consent. For the avoidance of doubt, unless Customer participates in the default Anonymized Data program or provides explicit consent, ThreatModeler will never use any un-anonymized, identifiable Customer Data (Inputs) to train, fine-tune, or develop any general or publicly available artificial intelligence models.
13. PROFESSIONAL SERVICES
13.1. Scope and Governance. ThreatModeler will provide Customer with the Professional Services, if any, as described in one or more mutually executed Statements of Work ("SOWs"). Each SOW will detail the specific scope, deliverables, timelines, fees, and any other terms applicable to a particular project. Each SOW is hereby incorporated by reference into this Agreement. In the event of a direct conflict between the terms of a SOW and this Agreement, the terms of this Agreement shall prevail, unless the SOW expressly identifies the conflicting provision of this Agreement and states its intent to override it for that specific project.
13.2. Performance Warranty. ThreatModeler warrants that all Professional Services will be performed in a professional and workmanlike manner, in all material respects in accordance with the specifications set forth in the applicable SOW. For any breach of this warranty, Customer's sole and exclusive remedy shall be for ThreatModeler, at its option, to either: (a) re-perform the non-conforming Professional Services at no additional charge; or (b) if re-performance is not commercially feasible, terminate the applicable SOW and provide a pro-rata refund of the fees paid for the non-conforming portion of the Professional Services. To receive this remedy, Customer must report the non-conformity in writing within thirty (30) days of the completion of the services.
13.3. Customer Cooperation. Customer acknowledges that the successful and timely delivery of Professional Services requires its good-faith cooperation. Customer agrees to provide ThreatModeler with timely access to its personnel, facilities, and any necessary information or materials. ThreatModeler shall not be liable for any delay or failure in performance to the extent caused by Customer's failure to meet its responsibilities. Any delays caused by Customer may result in additional fees and adjustments to the project timeline.
13.4. Intellectual Property.
(a) ThreatModeler's Pre-Existing IP. ThreatModeler shall retain all right, title, and interest in and to any of its pre-existing tools, methodologies, know-how, and other intellectual property used or provided in the course of performing the Professional Services ("ThreatModeler Background IP").
(b) Deliverables. Upon Customer's payment in full of all applicable fees, any custom reports, configurations, or other deliverables created specifically for Customer as described in a SOW ("Deliverables") are licensed to Customer for its internal use only during its active Subscription Term for the related Product. ThreatModeler retains ownership of all intellectual property rights in and to the Deliverables.
(c) No Work for Hire. For the avoidance of doubt, all Professional Services are provided on a non-"work-for-hire" basis.
13.5. Personnel and Expenses. ThreatModeler will determine the personnel assigned to perform the Professional Services. Unless otherwise specified in the applicable SOW, Customer will reimburse ThreatModeler for all reasonable, pre-approved travel and out-of-pocket expenses incurred in connection with the provision of Professional Services.
14. GENERAL PROVISIONS
14.1. Governing Law, Jurisdiction, and Venue. This Agreement shall be governed by and construed in accordance with the laws of the State of Delaware, USA, without regard to its conflict of law principles. The parties irrevocably agree to the exclusive jurisdiction and venue of the state and federal courts located in the State of Delaware for the resolution of any dispute arising out of or relating to this Agreement. The United Nations Convention on Contracts for the International Sale of Goods does not apply to this Agreement.
14.2. Notices. All notices under this Agreement shall be sent exclusively by email to legal@threatmodeler.com (for ThreatModeler) and to the primary email address associated with Customer’s account or specified in the most recent Order Form (for Customer). Notices are deemed received upon successful transmission, provided no delivery failure is returned. Customer is solely responsible for keeping its email address current and operational.
14.3. Relationship of the Parties. The parties are independent contractors. This Agreement does not create a partnership, franchise, joint venture, agency, fiduciary, or employment relationship between the parties.
14.4. No Third-Party Beneficiaries. This Agreement is for the sole benefit of the parties hereto and their respective successors and permitted assigns and nothing herein, express or implied, is intended to or shall confer upon any other person or entity any legal or equitable right, benefit, or remedy of any nature whatsoever.
14.5. Subcontracting. ThreatModeler may use affiliates or other third-party contractors in the performance of its obligations hereunder, including for the provision of Support Services and Professional Services, provided that ThreatModeler shall remain fully responsible for the performance of any such subcontractor and for their compliance with all terms of this Agreement.
14.6. Assignment. Neither party may assign any of its rights or obligations hereunder, whether by operation of law or otherwise, without the other party's prior written consent (not to be unreasonably withheld). Notwithstanding the foregoing, either party may assign this Agreement in its entirety, without the other party's consent, to its Affiliate or in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of its assets.
14.7. Force Majeure. Neither party shall be liable for any failure or delay in performance (except for payment obligations) due to a "Force Majeure Event," meaning causes beyond its reasonable control, including but not limited to acts of God, war, terrorism, riots, strikes, or natural disasters.
14.8. Export Compliance. The Product and related technology are subject to U.S. export control and economic sanctions laws. Customer is solely responsible for ensuring its compliance with all such laws. Customer represents and warrants that it is not located in any U.S. embargoed country and is not named on any U.S. government restricted or denied-party list. Customer shall not permit any Authorized User to access or use the Product in violation of any U.S. export law or regulation.
14.9. U.S. Government End Users. If Customer is an agency or instrumentality of the United States Government ("USG"), the Product and Documentation qualify as "commercial items" as defined at Federal Acquisition Regulation (“FAR”) 48 C.F.R. 2.101. The use, duplication, and disclosure of the Product by the USG is subject to the restrictions set forth in this Agreement, consistent with FAR 12.212 and DFARS 227.7202. To the extent any provision of this Agreement conflicts with applicable federal law, such provision shall be deemed amended to be consistent with federal law.
14.10. Publicity. Neither party shall use the other party's name or logo in any press release, marketing materials, or other public announcement without the other party's prior written consent. However, ThreatModeler may identify Customer by name in its customer lists.
14.11. Severability. If any provision of this Agreement is held by a court of competent jurisdiction to be contrary to law, the provision will be deemed null and void, and the remaining provisions of this Agreement will remain in effect.
14.12. Waiver. No failure or delay by either party in exercising any right under this Agreement will constitute a waiver of that right or any other right.
14.13. Entire Agreement, Order of Precedence, and Supremacy.
(a) Entire Agreement. This Agreement, including all Order Forms, SOWs, and Exhibits, constitutes the entire agreement between the Parties and supersedes all prior understandings, oral or written. Any amendment must be in writing and signed by both Parties.
(b) Order of Precedence. In the event of a conflict, the documents shall control in the following order: (1) this Agreement, (2) the SOW, (3) the Order Form. Notwithstanding the foregoing, a specific provision in an Order Form or SOW may supersede a conflicting provision in this Agreement only if it explicitly identifies the section number it intends to override (e.g., "Notwithstanding Section 11.2 of the Agreement...") and is counter-signed by an authorized representative of ThreatModeler.
(c) Supremacy over Customer Forms. This Agreement and any ThreatModeler-issued Order Form shall prevail over any terms in a Customer-issued purchase order (PO), vendor portal, or other business form. All such Customer-provided terms are hereby rejected, null, and void. ThreatModeler’s delivery of the Product or acceptance of payment shall not be construed as acceptance of Customer's terms, regardless of whether such Customer forms are signed by ThreatModeler.
This ThreatModeler Cloud Subscription Agreement (this “Agreement”) governs the access to and use of ThreatModeler’s cloud-based threat modeling platform and related services (the “Product”). This Agreement entered into by and between ThreatModeler Software, S.L., a Spanish limited liability company, and its principal place of business at Parque Tecnológico Walqa, Ctra. Zaragoza N-330A, Km. 566, 22197 Cuarte (Huesca, Aragon), Spain (“ThreatModeler”); and the entity or individual identified as the customer in an applicable Order Form or that otherwise downloads, installs, or uses the Software (“Customer”). This Agreement takes effect on the date of the initial Order Form, or the date on which Customer first downloads or accesses the Software, whichever is earlier (the “Effective Date”).
BY EXECUTING AN ORDER FORM THAT REFERENCES THIS AGREEMENT, BY CLICKING “I AGREE,” OR BY ACCESSING OR USING THE PRODUCT, CUSTOMER AGREES TO BE BOUND BY THIS AGREEMENT. IF YOU ARE ENTERING INTO THIS AGREEMENT ON BEHALF OF A COMPANY OR OTHER LEGAL ENTITY, YOU REPRESENT THAT YOU HAVE THE AUTHORITY TO BIND SUCH ENTITY TO THIS AGREEMENT.
1. DEFINITIONS
1.1. "Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where "control" means direct or indirect ownership of more than fifty percent (50%) of the voting interests of the subject entity. Notwithstanding the foregoing, an "Affiliate" shall not include any entity that is a direct competitor of ThreatModeler. ThreatModeler reserves the right, in its reasonable business judgment, to determine whether an entity qualifies as a direct competitor.
1.2. "Core AI Functionality" means any features, models, or autonomous agents within the Product that utilize machine learning or artificial intelligence technologies to analyze, generate, or automate threat models, security requirements, and design content. The Core AI Functionality operates in: (a) "Default AI Mode," where ThreatModeler processes data using its designated third-party AI subprocessors, or (b) "BYOAI Mode," where Customer configures the Product to process data using its own designated third-party AI provider.
1.3. "Authorized User" means a specific, uniquely identified individual (an employee or contractor of Customer or its Affiliates) who has been authorized by Customer to access and use the Product. Each Authorized User must be assigned unique user credentials (e.g., a unique user ID and password), and a user license may not be shared or used by more than one individual. However, user licenses may be permanently reassigned to a new individual replacing one who has terminated their employment or contract, or otherwise changed job status or function and no longer requires access to the Product. Customer is fully responsible for all acts and omissions of its Authorized Users.
1.4. "Confidential Information" means all information disclosed by a party ("Disclosing Party") to the other party ("Receiving Party"), whether orally or in writing, that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure. "Confidential Information" includes, without limitation: (a) For ThreatModeler: The Product and Services in their entirety, including their underlying technology, source code, AI prompts, rules, agent workflows, telemetry, performance data, security reports, product roadmaps, and pricing; (b) For Customer: The Customer Data (Inputs), and any Customer-specific system vulnerabilities, security gaps, or proprietary architectural details contained within any generated Outputs; (c) For Both Parties: The terms and conditions of this Agreement and all Order Forms. Confidential Information does not include any information that: (i) is or becomes generally known to the public without breach of any obligation owed to the Disclosing Party; (ii) was known to the Receiving Party prior to its disclosure by the Disclosing Party without breach of any obligation; (iii) is received from a third party without breach of any obligation; or (iv) was independently developed by the Receiving Party without use of or reference to the Disclosing Party's Confidential Information.
1.5. "Customer Data" means any proprietary information, data, or materials uploaded, submitted, or inputted into the Product by Customer or its Authorized Users ("Inputs"). For the avoidance of doubt, Customer Data does not include any threat libraries, security controls, templates, rules, or threat modeling intelligence pre-existing within or generated by the Product ("ThreatModeler Content").
1.6. "Documentation" means ThreatModeler's official, generally available technical and functional documentation for the applicable Product, as made available on ThreatModeler's support portal or other designated website. For the avoidance of doubt, "Documentation" specifically excludes any and all marketing materials, websites, press releases, proposals, or non-technical blog posts, and shall not be construed as a warranty or commitment for the development or delivery of any future functionality or features.
1.7. "Feedback" means any suggestion, enhancement request, recommendation, correction, or other feedback provided by Customer or its Authorized Users relating to the operation or functionality of the Product.
1.8. "Intellectual Property Rights" means any and all registered and unregistered rights granted, applied for, or otherwise now or hereafter in existence under or related to any patent, copyright, trademark, trade secret, database protection, or other intellectual property law, and all similar or equivalent rights or forms of protection, in any part of the world. This includes, without limitation:(a) all rights in and to inventions (whether patentable or not), discoveries, and improvements; (b) all rights in and to works of authorship, including copyrights, mask work rights, and moral rights; (c) all rights in and to trade names, logos, trademarks, and service marks (together with all of the goodwill associated therewith); (d) all rights in and to confidential information, know-how, and trade secrets; and (e) all rights in and to domain names, website designs, and user interface designs.
1.9. "Order" means the binding transactional document for the purchase of Products. An Order is formed when: (a) Customer executes a "Quote" or "Order Form" issued by ThreatModeler; or (b) ThreatModeler accepts, in writing or by beginning performance, a "Purchase Order" or "PO" issued by Customer against a valid Quote. A PO issued by Customer becomes a binding Order only upon ThreatModeler's written acceptance. For the avoidance of doubt, any Purchase Order issued by Customer is accepted by ThreatModeler solely for the purpose of administrative convenience, invoicing, and billing; any pre-printed, standard, or conflicting terms and conditions contained in or attached to such Customer-issued PO are hereby expressly rejected by ThreatModeler and shall be null, void, and of no legal force or effect, as set forth in Section 14.12(c).
1.10. "Product(s)" means the commercially available offerings of ThreatModeler subscribed to by Customer as identified in an applicable Order. Unless otherwise specified in an Order, the core "Product" subscription consists of the following components: (a) A subscription to access and use the "Platform," which refers to ThreatModeler's proprietary cloud-based software, including its integrated "Core AI Functionality."; (b) Any "Updates" to the Platform that ThreatModeler makes generally available to its subscribed customers; (c) The applicable tier of "Support Services," as set forth in Section 1.14; (d) Access to the official "Documentation." For the avoidance of doubt, Professional Services and Training are not included as part of the standard Product subscription and must be purchased separately pursuant to an Order and governed by a Statement of Work (SOW). The term "Product" explicitly excludes any third-party software, hardware, or services required by Customer to access or use the offering.
1.11. "Professional Services" means expert services provided by ThreatModeler to Customer, which are separate from the subscribed Product and are governed by a Statement of Work ("SOW"). Professional Services are purchased on a project or time-and-materials basis and may include, but are not limited to, implementation assistance, system configuration, dedicated training, and custom content or report creation. Unless otherwise expressly agreed in a SOW, all Professional Services are provided on a non-"work-for-hire" basis. All intellectual property rights in any deliverables, tools, or methodologies used or created by ThreatModeler in the course of providing Professional Services shall remain the exclusive property of ThreatModeler, subject to the limited license rights granted to Customer in the applicable SOW or Section 13.4 of this Agreement. The successful delivery of Professional Services is dependent on Customer's timely cooperation and fulfillment of its responsibilities as outlined in the applicable SOW.
1.12. "Scope of Use" means the specific usage limits, tiers, and metrics for the purchased Product subscription, as expressly set forth in the applicable Order. Common metrics include, but are not limited to, the number of Authorized Users and the number of Threat Models. Customer's use of the Product must not exceed the Scope of Use.
1.13. "Subscription Term" means the initial term for the subscription to the Services as specified in an Order, and any subsequent renewal terms.
1.14."Support Services" means the technical support, maintenance, and service level commitments provided by ThreatModeler for the subscribed Product. The specific scope, support channels, response times, and uptime commitments for the Support Services are detailed in the ThreatModeler Support Services Policy and Service Level Agreement ("SLA") available at threatmodeler.ai/legal/support-program.
2. LICENSE, SUPPORT, AND UPDATES
2.1. Subscription and Access Rights. Subject to Customer’s full and timely payment of all applicable fees and its continuous compliance with the terms of this Agreement, ThreatModeler grants Customer a subscription for its Authorized Users to access and use the subscribed Product during the applicable Subscription Term. This subscription includes a limited, non-exclusive, non-transferable, and non-sublicensable right to access and use the Product, solely for Customer's internal business purposes and strictly within the Scope of Use defined in the applicable Order. Customer agrees that no user license will be provided to any employee or contractor of an Affiliate that is a direct competitor of ThreatModeler, as determined in accordance with Section 1.1.
2.2. Support, Maintenance, and Updates. ThreatModeler will provide technical support and maintenance for the Product in accordance with the Support Services Policy and SLA referenced in Section 1.14. ThreatModeler reserves the right to update the Support Services Policy from time to time, provided that any such update will not result in a material and adverse decrease of the Support Services or SLA commitments during Customer's then-current Subscription Term.
2.3. Product Modifications. Customer acknowledges that the Product is an evolving, subscription-based offering. ThreatModeler reserves the right to enhance or modify the Product from time to time. However, ThreatModeler will not, during an active Subscription Term, make any changes that result in a material diminution of the overall functionality and value of the Product as it existed at the beginning of that Term.
3. ACCEPTABLE USE AND CUSTOMER OBLIGATIONS
3.1. General Responsibilities. Customer is and shall remain solely responsible and liable for:
(a) Authorized User Conduct: All activities conducted by its Authorized Users within the Product, and for ensuring their compliance with the terms of this Agreement. A breach by an Authorized User is deemed a breach by Customer.
(b) Customer Data: The accuracy, legality, quality, and integrity of all Customer Data, including obtaining all necessary rights, consents, and permissions to provide, use, and process the Customer Data as contemplated by this Agreement.
(c) Account Security: Maintaining the security and confidentiality of all Authorized User account credentials and for promptly notifying ThreatModeler of any unauthorized access or use.
(d) Compliance with Laws: Ensuring that its use of the Product complies with all applicable local, state, federal, and international laws and regulations.
3.2. Use Restrictions. Customer shall not, and shall not permit any Authorized User or any third party to, perform any of the following actions:
(a) Resale and Sublicensing: Sell, resell, lease, sublicense, or otherwise provide access to the Product to any third party, or use the Product to provide service bureau, timesharing, or other managed services for the benefit of any third party.
(b) Modification and Derivative Works: Modify, translate, adapt, or create derivative works based upon the Product or any part thereof.
(c) Reverse Engineering: Reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code, underlying ideas, or non-public APIs of the Product, except to the extent such a restriction is expressly prohibited by applicable law.
(d) Interference: Interfere with, disrupt, or create an undue burden on the integrity, performance, or security of the Product or the data contained therein.
(e) Security Testing: Conduct any security assessments, penetration tests, vulnerability scans, or load testing on the Product or its infrastructure without the prior express written consent and coordination of ThreatModeler.
(f) Malicious Use: Use the Product to store or transmit any viruses, worms, Trojan horses, or other malicious code, or to engage in any phishing, spamming, or denial-of-service attacks.
(g) Unlawful or Infringing Content: Use the Product to store or transmit any content that is infringing, libelous, or otherwise unlawful or tortious, or that violates the privacy or intellectual property rights of any third party.
(h) Public Benchmarking: Publicly disseminate any performance information, analysis, or competitive benchmarks of the Product without ThreatModeler's prior written consent.
(i) Circumvention: Attempt to circumvent any Scope of Use restrictions or other license control mechanisms within the Product.
(j) Multiplexing and Pooling: Use any technology, software, script, or automated agent to pool connections, redirect requests, or "multiplex" access to the Product in a manner that bypasses the Authorized User license limits, or allows unlicensed individuals to indirectly access, query, or utilize the Product's functionalities.
3.3. High-Risk Activities Prohibition. The Product is not designed, manufactured, or intended for use in hazardous environments requiring fail-safe performance, including but not limited to the operation of nuclear facilities, aircraft navigation or communication systems, air traffic control, direct life-support machines, or weapons systems ("High-Risk Activities"). Customer expressly agrees that it will not use, or permit the use of, the Product for any High-Risk Activities. ThreatModeler and its suppliers expressly disclaim any express or implied warranty of fitness for such purposes.
3.4. Prohibition on Sensitive Personal Information. Customer agrees that it shall not upload or process any "Sensitive Data" in the Product. Customer acknowledges that the Product is not designed for such data and ThreatModeler has no liability for any Sensitive Data processed in violation of this section.
"Sensitive Data" includes any data that requires heightened protection under applicable law, including, but not limited to, health information (HIPAA), financial information (GLBA, PCI DSS), government-issued IDs, and "special categories of personal data" under GDPR.
Customer shall indemnify, defend, and hold harmless ThreatModeler from any damages, losses, and costs arising from or related to Customer's breach of this Section 3.4.
4. FEES, PAYMENT, AND AUDITS
4.1. Fees. Customer shall pay all fees specified in all applicable Orders ("Fees"). Except as expressly provided in this Agreement, all payment obligations are non-cancellable and all Fees paid are non-refundable. The Fees are based on the Product subscription purchased and not on actual usage.
4.2. Invoicing and Payment. Unless otherwise specified in an Order Form, all Fees will be invoiced annually in advance. All invoices are due and payable net thirty (30) days from the invoice date, without offset or deduction. Late payments will accrue interest at the statutory late payment interest rate applicable under European commercial transaction regulations (specifically including Spanish Law 3/2004 on Morosidad), plus any legally permitted recovery costs.
4.3. Taxes.
a) Fees are stated exclusive of any taxes, levies, duties, or similar governmental assessments, including value-added, sales, use, or withholding taxes (collectively, "Taxes"). Customer is responsible for paying all Taxes associated with its purchases hereunder. If Customer is located within the EU and is required to account for VAT under the reverse charge mechanism, Customer shall provide ThreatModeler with a valid VAT identification number.
b) If ThreatModeler has the legal obligation to pay or collect Taxes for which Customer is responsible, the appropriate amount shall be invoiced to and paid by Customer, unless Customer provides ThreatModeler with a valid tax exemption certificate.
c) If Customer is required by law to withhold any Taxes from its payments to ThreatModeler, Customer must provide ThreatModeler with an official tax receipt or other appropriate documentation. Customer agrees to increase the payment to ThreatModeler by the amount necessary to ensure that ThreatModeler receives a net amount equal to the full amount of the Fees it would have received without the deduction.
4.4. Suspension of Service and Termination. If any invoiced amount is more than thirty (30) days overdue, ThreatModeler may, without limiting its other rights and remedies: (a) suspend Customer's access to the Product upon ten (10) days' written notice until such amounts are paid in full, and (b) if the failure to pay continues for sixty (60) days or more, terminate this Agreement for cause under Section 5.3.
4.5. Invoice Disputes. Customer must notify ThreatModeler in writing of any good-faith dispute with respect to an invoice within fifteen (15) days of the invoice date. If Customer fails to do so, Customer is deemed to have waived its right to dispute that invoice, and the invoice will be considered final and payable.
4.6. Usage Verification. Customer acknowledges and agrees that the Product includes a self-auditing function that electronically monitors and reports on Customer’s usage metrics (e.g., number of Authorized Users, number of Threat Models). ThreatModeler shall have the right to use this reporting data to verify Customer's compliance with the Scope of Use.
If Customer's use of the Product exceeds its purchased entitlement as set forth in the applicable Order, ThreatModeler will invoice Customer for such overage at ThreatModeler's then-current list prices for the entire period of non-compliance. Customer agrees to pay such invoice in accordance with Section 4.2 of this Agreement.
5. TERM AND TERMINATION
5.1. Agreement Term. The term of this Agreement commences on the Effective Date and continues as long as a Subscription Term for any Product is in effect, unless terminated earlier in accordance with its terms.
5.2. Subscription Term and Auto-Renewal. Each Subscription Term will automatically renew for additional periods equal to the expiring term (or one year, if the expiring term is longer than one year), unless either party gives the other written notice of non-renewal at least sixty (60) days before the end of the then-current Subscription Term. ThreatModeler reserves the right to increase the fees for any renewal term by providing notice thereof at least fifteen (15) days prior to the end of the current term.
5.3. Termination for Cause. A party may terminate this Agreement for cause: (i) upon thirty (30) days' written notice to the other party of a material breach if such breach remains uncured at the expiration of such period, or (ii) if the other party becomes the subject of a petition in bankruptcy or any other proceeding relating to insolvency, receivership, or assignment for the benefit of creditors.
5.4. Termination for Convenience by Customer. Customer may terminate this Agreement for its convenience at any time by providing ninety (90) days' prior written notice to ThreatModeler. Upon such termination, Customer shall not be entitled to any refund, credit, or pro-rata return of any Fees paid upfront (as all payment obligations are non-cancellable and all Fees paid are non-refundable under Section 4.1). Any unpaid Fees associated with the remaining duration of the committed Subscription Term shall become immediately due and payable.
5.5. Effect of Termination. Upon any termination or expiration of this Agreement: (a) all rights and subscriptions granted to Customer hereunder shall immediately terminate and Customer shall cease all use of the Product; (b) Customer shall immediately pay any unpaid fees accrued prior to the effective date of termination, as well as any future fees that become due under Section 5.4; and (c) each party will, upon request, promptly return or securely destroy all Confidential Information of the other party.
5.6. Data Portability and Deletion. Upon Customer's written request made within thirty (30) days after the effective date of termination, ThreatModeler will make Customer Data available for export. After this 30-day period, ThreatModeler will have no further obligation to maintain any Customer Data and will thereafter delete it in accordance with its standard policies.
5.7. Survival. The provisions of this Agreement which by their nature should survive termination or expiration shall remain in effect, including: Section 1 (Definitions), Section 4 (Fees, Payment, and Audits), Section 5.5 (Effect of Termination), Section 5.7 (Survival), Section 6 (Data Protection and Security), Section 7 (Confidentiality), Section 8 (Intellectual Property Rights), Section 10 (Indemnification), Section 11 (Limitation of Liability), and Section 14 (General Provisions).
5.8. Reinstatement of Lapsed Subscription. If any subscription for a Product expires or is terminated, and Customer seeks to reinstate such subscription at a later date, such reinstatement shall be subject to ThreatModeler's then-current policies. At a minimum, reinstatement will require Customer to pay: (a) a reinstatement fee; (b) all subscription fees that would have been payable during the period of the lapse; and (c) the subscription fees for the new Subscription Term.
6. DATA PROTECTION AND SECURITY
6.1. Security Program and Safeguards. ThreatModeler will implement and maintain a comprehensive written information security program, which includes administrative, physical, and technical safeguards aligned with accepted industry standards. This program is designed to protect the security, confidentiality, and integrity of Customer Data against accidental or unlawful destruction, loss, alteration, or unauthorized access, use, or disclosure. ThreatModeler will not materially decrease the overall security of the Product during a Subscription Term.
6.2. Data Processing, DPA, and Subprocessors.
(a) Data Processing Addendum. The parties acknowledge and agree that with respect to the processing of "Personal Data", ThreatModeler acts as a "Processor" or "Service Provider" and Customer is the "Controller" or "Business". All processing of Personal Data is subject to and governed by ThreatModeler's Data Processing Addendum ("DPA"), located at threatmodeler.ai/legal/dpa, which is hereby incorporated by reference.
(b) Subprocessors. Customer acknowledges that ThreatModeler uses third-party subprocessors to provide the Product. A current list of ThreatModeler's subprocessors is maintained at threatmodeler.ai/legal/subprocessors (the "Subprocessor List").
(c) New Subprocessors and Right to Object. ThreatModeler will provide Customer with at least thirty (30) days' prior written notice of any new subprocessor appointment by updating the Subprocessor List and notifying Customer of such update. Customer may, within fifteen (15) days of such notice, object in writing to the new subprocessor on reasonable, data protection-related grounds. If the parties cannot resolve the objection, Customer may, as its sole and exclusive remedy, terminate the applicable subscription for cause.
6.3. Security Incident Response.
(a) Notification. ThreatModeler will notify Customer without undue delay upon becoming aware of a "Security Incident," which is defined as the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Customer Data processed by ThreatModeler.
(b) Cooperation. ThreatModeler will provide reasonable cooperation to Customer in the investigation of the Security Incident, including providing any relevant information reasonably requested by Customer regarding the nature of the incident, the categories of data affected, and the corrective actions being taken.
6.4. Customer's Security Responsibilities. Customer acknowledges that its security responsibilities are a critical component of overall data protection. Customer is solely responsible for: (a) securely managing all Authorized User account credentials; (b) configuring and using the Product in a secure manner in accordance with the Documentation; (c) ensuring the security of its own systems and devices used to access the Product and (d) notifying ThreatModeler of any known or suspected security breach originating from its own systems or involving its Authorized User account credentials.
7. CONFIDENTIALITY
7.1. Obligation of Confidentiality. The Receiving Party shall:
(a) use the same degree of care that it uses to protect the confidentiality of its own confidential information of like kind (but in no event less than a reasonable degree of care);
(b) not use any Confidential Information of the Disclosing Party for any purpose outside the scope of this Agreement; and
(c) except as otherwise authorized by the Disclosing Party in writing, limit access to Confidential Information to those of its and its Affiliates’ employees, contractors, and agents who have a legitimate "need to know" for purposes consistent with this Agreement and who are bound by confidentiality obligations containing protections no less stringent than those herein. The Receiving Party shall be liable for any breach of this Section 7 by its representatives.
7.2. Compelled Disclosure. A Receiving Party may disclose Confidential Information of the Disclosing Party to the extent compelled by law or a valid court order to do so, provided the Receiving Party gives the Disclosing Party prior written notice of the compelled disclosure (to the extent legally permitted) and reasonable assistance, at the Disclosing Party's cost, if the Disclosing Party wishes to contest or seek a protective order for the disclosure.
7.3. Equitable Relief. The Disclosing Party may seek injunctive or other equitable relief in the event of a breach or threatened breach of this Section 7. The parties acknowledge that a breach may cause irreparable harm for which monetary damages alone may be inadequate.
8. INTELLECTUAL PROPERTY RIGHTS
8.1. ThreatModeler's Intellectual Property.
As between the Parties, ThreatModeler and its licensors exclusively own and retain all right, title, and interest in and to the Product, including the Platform, all generated threat models, reports, security requirements, and outputs (collectively, "Outputs"), and all underlying software, threat libraries, and technology.
Subject to Customer's payment of all Fees, ThreatModeler hereby grants Customer a non-exclusive, non-transferable, non-sublicensable license to use, copy, and distribute the Outputs solely for Customer's internal business and compliance purposes during the applicable Subscription Term, provided that Customer shall retain all rights in its proprietary Inputs contained within such Outputs.
8.2. Customer's Intellectual Property.
As between the parties, Customer exclusively owns and retains all right, title, and interest in and to the Customer Data, including all intellectual property rights therein.
8.3. License from Customer to Provide the Product.
Customer hereby grants ThreatModeler and its Affiliates a worldwide, limited-term, non-exclusive, royalty-free license to host, copy, transmit, process, and display Customer Data as reasonably necessary for ThreatModeler to provide, maintain, and support the Product for Customer in accordance with this Agreement. This license terminates upon the deletion of Customer Data as described in Section 5.6.
8.4. Ownership of Feedback.
Customer acknowledges and agrees that any suggestions, enhancement requests, recommendations, corrections, or other feedback provided by Customer or its Authorized Users relating to the operation of the Product ("Feedback") shall be owned by ThreatModeler. Customer hereby assigns to ThreatModeler all right, title, and interest in and to any Feedback, without any right to compensation. ThreatModeler is under no obligation to use or implement any Feedback.
8.5. ThreatModeler's Rights to Use Non-Identifiable Data.
(a) Data Collection and Ownership. Customer acknowledges and agrees that ThreatModeler has the right to collect, analyze, and use technical, operational, and telemetry data relating to the provision, use, and performance of the Product, including data derived from Customer Data (collectively, "Usage Data"). For the avoidance of doubt, ThreatModeler shall exclusively own all right, title, and interest in and to the Usage Data.
(b) Permitted Uses. Provided that such Usage Data is in an aggregated and de-identified format that does not, and cannot be used to, identify Customer, its Affiliates, or any individual ("Anonymized Data"), ThreatModeler shall have the perpetual, irrevocable, worldwide, royalty-free right to use, reproduce, modify, and create derivative works of such Anonymized Data for any lawful business purpose.
(c) Illustrative Examples of Permitted Uses. Without limiting the generality of the foregoing, these business purposes include, but are not limited to:
i. Product Improvement: Analyzing usage patterns to enhance and optimize the Product's performance, security, and usability.
ii. New Feature Development: Using insights from Anonymized Data to inform the development of new features, products, and services.
iii. Benchmarking and Industry Analysis: Creating and publishing aggregated statistical reports, industry trend analyses, and benchmarks (e.g., "average number of threats identified in the financial services sector").
(d) Clarification on Customer Data. For the absolute avoidance of doubt, ThreatModeler will not use Customer's un-anonymized, identifiable Customer Data for any purpose other than providing the Product to Customer as described in this Agreement.
8.6. API and Integration Intellectual Property.
To the extent that Customer develops any custom connectors, scripts, or software integrations designed to connect Customer’s internal tools or IDEs to the Product via ThreatModeler’s Application Programming Interfaces (APIs) or the Model Context Protocol (MCP) Server (collectively, "Integrations"), Customer shall retain ownership of its custom code for such Integrations.
However, Customer acknowledges and agrees that: (a) such Integrations shall not be construed as creating any joint intellectual property rights, (b) ThreatModeler retains exclusive ownership of the underlying APIs, the MCP Server technology, and the platform architecture, and (c) nothing in this Agreement shall restrict ThreatModeler from independently developing, licensing, or commercializing similar integrations, connectors, or features for its other customers.
9. WARRANTIES AND DISCLAIMERS
9.1. Mutual Warranties. Each party represents and warrants that it has the legal power and authority to enter into this Agreement and that it will comply with all applicable laws in its performance hereunder.
9.2. Limited Performance Warranty. ThreatModeler warrants that, during an applicable Subscription Term, the Product will perform materially in accordance with the applicable Documentation. For any breach of this warranty, Customer's sole and exclusive remedy shall be the Service Credits as specified in the Support Services Policy located at threatmodeler.ai/legal/support-program. However, if the Product's non-conformity results in a material and sustained failure to provide the core functionality, and ThreatModeler is unable to correct such non-conformity within a reasonable period, Customer shall have the right to terminate the subscription for the affected Product and receive a pro-rata refund of any prepaid fees for the remainder of the terminated Subscription Term.
9.3. WARRANTY DISCLAIMER. EXCEPT FOR THE EXPRESS WARRANTIES PROVIDED IN SECTION 9.2 AND SECTION 13 OF THIS AGREEMENT, AND TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE PRODUCT AND ANY SERVICES ARE PROVIDED "AS IS". WHILE THREATMODELER WARRANTS IT WILL USE COMMERCIALLY REASONABLE SKILL AND CARE IN PROVIDING THE PRODUCT, IT EXPRESSLY DISCLAIMS ALL OTHER WARRANTIES AND REPRESENTATIONS, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. CUSTOMER ACKNOWLEDGES THAT ANY OUTPUTS, SUGGESTIONS, OR CONTENT GENERATED BY THE CORE AI FUNCTIONALITY ARE PROVIDED FOR INFORMATIONAL PURPOSES ONLY, WITHOUT WARRANTY OF ANY KIND, AND CUSTOMER IS SOLELY RESPONSIBLE FOR REVIEWING, VALIDATING, AND TESTING THE ACCURACY AND APPROPRIATENESS OF ANY SUCH OUTPUTS. THREATMODELER DOES NOT WARRANT THAT THE USE OF THE PRODUCT WILL BE UNINTERRUPTED OR ERROR-FREE. CUSTOMER ACKNOWLEDGES AND AGREES THAT THREATMODELER SHALL NOT BE LIABLE FOR DELAYS, INTERRUPTIONS, SERVICE FAILURES, OR OTHER PROBLEMS INHERENT IN THE USE OF THE INTERNET AND ELECTRONIC COMMUNICATIONS OR OTHER SYSTEMS OUTSIDE THE REASONABLE CONTROL OF THREATMODELER.
10. INDEMNIFICATION
10.1. Indemnification by ThreatModeler. ThreatModeler will defend Customer against any third-party claim, demand, suit, or proceeding ("Claim") alleging that Customer's use of the Product, as delivered by ThreatModeler and used in accordance with this Agreement, directly infringes a valid EU patent, copyright, or registered trademark of such third party.. ThreatModeler will indemnify Customer for any damages, attorney fees, and costs finally awarded against Customer as a result of, or for amounts paid by Customer under a court-approved settlement of, such a Claim.
10.2. Mitigation and Remedy. If the Product becomes, or in ThreatModeler's opinion is likely to become, the subject of an infringement Claim, ThreatModeler may, at its option and expense:
(a) procure for Customer the right to continue using the Product;
(b) replace or modify the Product with a non-infringing but functionally equivalent alternative; or
(c) if options (a) and (b) are not commercially reasonable, terminate Customer's subscription for the infringing Product and provide a pro-rata refund of any prepaid fees for the remainder of the terminated Subscription Term.
10.3. Exclusions. ThreatModeler's obligations under Section 10.1 will not apply to any Claim to the extent it arises from: (a) use of the Product in combination with hardware, software, or data not provided by ThreatModeler; (b) Customer Data; (c) any modification to the Product not made by ThreatModeler; or (d) Customer's use of a version of the Product other than the then-current version, if the infringement would have been avoided by use of the current version made available to Customer.
10.4. Indemnification by Customer. Customer will defend ThreatModeler against any Claim made or brought against ThreatModeler by a third party arising from or related to: (i) the Customer Data, including any allegation that the Customer Data infringes or misappropriates the rights of a third party; or (ii) Customer’s use of the Product in breach of this Agreement or applicable law. Customer will indemnify ThreatModeler for any damages, attorney fees, and costs finally awarded against ThreatModeler as a result of, or for amounts paid by ThreatModeler under a court-approved settlement of, such a Claim.
10.5. Indemnification Procedure. The indemnifying party's obligations are contingent upon the indemnified party: (a) promptly giving written notice of the Claim; (b) giving the indemnifying party sole control of the defense and settlement of the Claim (provided that the indemnifying party may not settle any Claim unless it unconditionally releases the indemnified party of all liability); and (c) providing all reasonable assistance, at the indemnifying party's expense.
10.6. Exclusive Remedy. To the extent permitted by applicable law, this Section 10 states the indemnifying party's sole liability to, and the indemnified party's exclusive remedy against, the other party for any type of third-party infringement claim described in this section.
11. LIMITATION OF LIABILITY
11.1. DISCLAIMER OF INDIRECT AND CONSEQUENTIAL DAMAGES.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL EITHER PARTY OR ITS SUPPLIERS HAVE ANY LIABILITY TO THE OTHER PARTY FOR ANY LOST PROFITS, LOST DATA, LOSS OF USE, BUSINESS INTERRUPTION, COSTS OF PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES, OR FOR ANY INDIRECT, SPECIAL, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES, HOWEVER CAUSED AND, WHETHER IN CONTRACT, TORT OR UNDER ANY OTHER THEORY OF LIABILITY, AND WHETHER OR NOT THE PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
11.2. LIMITATION OF AGGREGATE LIABILITY.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL EITHER PARTY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT, WHETHER IN CONTRACT, TORT OR UNDER ANY OTHER THEORY OF LIABILITY, EXCEED THE TOTAL AMOUNT OF FEES ACTUALLY PAID BY CUSTOMER TO THREATMODELER HEREUNDER IN THE TWELVE (12) MONTHS PRECEDING THE DATE OF THE FIRST INCIDENT GIVING RISE TO THE LIABILITY.
11.3. EXCLUSIONS FROM LIMITATIONS ("UNLIMITED LIABILITY CARVE-OUTS").
THE LIMITATIONS SET FORTH IN SECTIONS 11.1 AND 11.2 SHALL NOT APPLY TO:
(a) A PARTY'S INDEMNIFICATION OBLIGATIONS UNDER SECTION 10;
(b) A VIOLATION OF THE OTHER PARTY'S INTELLECTUAL PROPERTY RIGHTS;
(c) CUSTOMER'S UNPAID PAYMENT OBLIGATIONS FOR FEES DUE UNDER ANY ORDER FORM; OR
(d) LIABILITY ARISING FROM A PARTY'S GROSS NEGLIGENCE OR WILLFUL MISCONDUCT.
11.4. Allocation of Risk. The parties acknowledge and agree that the essential purpose of this Section 11 is to allocate the risks under this Agreement between the parties and that the fees have been set and this Agreement entered into in reliance upon these limitations of liability.
12. CORE AI FUNCTIONALITY
12.1. General and Transparency Disclosure. The Product includes Core AI Functionality designed to assist and enhance the threat modeling process. Pursuant to Article 50 of the EU AI Act, Customer hereby acknowledges and agrees that certain features of the Product utilize artificial intelligence and machine learning technologies
12.1.1. Customer and its Authorized Users are hereby explicitly informed that they are interacting with an AI system when utilizing these features
12.1.2. Customer retains full control over the deployment of this functionality and is solely responsible for reviewing, validating, and accepting any outputs, security controls, or threat models generated by it. All AI-generated output is provided "AS IS" and its use is at Customer's sole risk.
12.2. Default AI Mode and Data Processing. Unless Customer configures the BYOAI Mode, the Product will operate in Default AI Mode, using ThreatModeler's designated AI subprocessors listed on its Subprocessor List. Under this mode, ThreatModeler will process Customer Data, including Inputs and Outputs, solely to provide and maintain the Core AI Functionality.
12.3. BYOAI Mode. If Customer subscribes to and configures the "Bring Your Own AI" (BYOAI) functionality, Customer may connect its own third-party AI provider account. In BYOAI Mode, Customer acknowledges that:
(a) All AI-related processing will occur directly between ThreatModeler and Customer's designated AI provider, under the terms of the agreement between Customer and that provider.
(b) Customer's AI provider is not a subprocessor of ThreatModeler. Customer is solely responsible for the security, privacy, and compliance of its relationship with its AI provider.
12.4. Optional AI Model Improvement Program.
(a) AI Model Improvement Program. To continuously improve, train, and optimize the accuracy, security context, and performance of ThreatModeler’s proprietary AI models, Customer agrees that ThreatModeler may include Customer in its AI model improvement program by default. Under this program, ThreatModeler may use Anonymized Data (as defined in Section 8.5(b)) derived from Customer’s use of the Product to train, validate, and improve its machine learning and artificial intelligence models.
(b) Right to Opt-Out. Customer’s participation in the AI model improvement program is entirely voluntary. Customer has the right to opt-out of the program at any time by submitting a formal written request via email to privacy@threatmodeler.com.
(c) Effect of Opt-Out. Upon receipt of Customer's written opt-out request, ThreatModeler shall ensure that the Customer’s tenant configuration is set to restrict any data extraction for AI training, and shall immediately cease utilizing any new Anonymized Data derived from Customer's account for AI model training purposes. For the avoidance of doubt, ThreatModeler will never use any un-anonymized, identifiable Customer Data (Inputs) to train, fine-tune, or develop any general or publicly available artificial intelligence models under any circumstances.
13. PROFESSIONAL SERVICES
13.1. Scope and Governance. ThreatModeler will provide Customer with the Professional Services, if any, as described in one or more mutually executed Statements of Work ("SOWs"). Each SOW will detail the specific scope, deliverables, timelines, fees, and any other terms applicable to a particular project. Each SOW is hereby incorporated by reference into this Agreement. In the event of a direct conflict between the terms of a SOW and this Agreement, the terms of this Agreement shall prevail, unless the SOW expressly identifies the conflicting provision of this Agreement and states its intent to override it for that specific project.
13.2. Performance Warranty. ThreatModeler warrants that all Professional Services will be performed in a professional and workmanlike manner, in all material respects in accordance with the specifications set forth in the applicable SOW. For any breach of this warranty, Customer's sole and exclusive remedy shall be for ThreatModeler, at its option, to either: (a) re-perform the non-conforming Professional Services at no additional charge; or (b) if re-performance is not commercially feasible, terminate the applicable SOW and provide a pro-rata refund of the fees paid for the non-conforming portion of the Professional Services. To receive this remedy, Customer must report the non-conformity in writing within thirty (30) days of the completion of the services.
13.3. Customer Cooperation. Customer acknowledges that the successful and timely delivery of Professional Services requires its good-faith cooperation. Customer agrees to provide ThreatModeler with timely access to its personnel, facilities, and any necessary information or materials. ThreatModeler shall not be liable for any delay or failure in performance to the extent caused by Customer's failure to meet its responsibilities. Any delays caused by Customer may result in additional fees and adjustments to the project timeline.
13.4. Intellectual Property.
(a) ThreatModeler's Pre-Existing IP. ThreatModeler shall retain all right, title, and interest in and to any of its pre-existing tools, methodologies, know-how, and other intellectual property used or provided in the course of performing the Professional Services ("ThreatModeler Background IP").
(b) Deliverables. Upon Customer's payment in full of all applicable fees, any custom reports, configurations, or other deliverables created specifically for Customer as described in a SOW ("Deliverables") are licensed to Customer for its internal use only during its active Subscription Term for the related Product. ThreatModeler retains ownership of all intellectual property rights in and to the Deliverables.
(c) No Work for Hire. For the avoidance of doubt, all Professional Services are provided on a non-"work-for-hire" basis.
13.5. Personnel and Expenses. ThreatModeler will determine the personnel assigned to perform the Professional Services. Unless otherwise specified in the applicable SOW, Customer will reimburse ThreatModeler for all reasonable, pre-approved travel and out-of-pocket expenses incurred in connection with the provision of Professional Services.
14. GENERAL PROVISIONS
14.1. Governing Law, Jurisdiction, and Venue. This Agreement and any disputes arising out of or in connection with it shall be governed by and construed in accordance with the laws of Spain. Both parties irrevocably agree to submit to the exclusive jurisdiction of the courts of the city of Madrid, Spain, for the resolution of any such dispute, expressly waiving any other jurisdiction to which they might be entitled. The United Nations Convention on Contracts for the International Sale of Goods does not apply to this Agreement.
14.2. Notices. All notices under this Agreement shall be sent exclusively by email to legal@threatmodeler.com (for ThreatModeler) and to the primary email address associated with Customer’s account or specified in the most recent Order Form (for Customer). Notices are deemed received upon successful transmission, provided no delivery failure is returned. Customer is solely responsible for keeping its email address current and operational.
14.3. Relationship of the Parties. The parties are independent contractors. This Agreement does not create a partnership, franchise, joint venture, agency, fiduciary, or employment relationship between the parties.
14.4. No Third-Party Beneficiaries. This Agreement is for the sole benefit of the parties hereto and their respective successors and permitted assigns and nothing herein, express or implied, is intended to or shall confer upon any other person or entity any legal or equitable right, benefit, or remedy of any nature whatsoever.
14.5. Subcontracting. ThreatModeler may use affiliates or other third-party contractors in the performance of its obligations hereunder, including for the provision of Support Services and Professional Services, provided that ThreatModeler shall remain fully responsible for the performance of any such subcontractor and for their compliance with all terms of this Agreement.
14.6. Assignment. Neither party may assign any of its rights or obligations hereunder, whether by operation of law or otherwise, without the other party's prior written consent (not to be unreasonably withheld). Notwithstanding the foregoing, either party may assign this Agreement in its entirety, without the other party's consent, to its Affiliate or in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of its assets.
14.7. Force Majeure. Neither party shall be liable for any failure or delay in performance (except for payment obligations) due to a "Force Majeure Event," meaning causes beyond its reasonable control, including but not limited to acts of God, war, terrorism, riots, strikes, or natural disasters.
14.8 Export Compliance. The Product and related technology may be subject to export control and economic sanctions laws of the United States, the European Union, and other applicable jurisdictions. Customer is solely responsible for complying with all such laws. Customer represents and warrants that it is not a sanctioned party or located in any comprehensively embargoed country, and Customer shall not permit access to or use of the Product in violation of any applicable export control laws.
14.9. Publicity. Neither party shall use the other party's name or logo in any press release, marketing materials, or other public announcement without the other party's prior written consent. However, ThreatModeler may identify Customer by name in its customer lists.
14.10. Severability. If any provision of this Agreement is held by a court of competent jurisdiction to be contrary to law, the provision will be deemed null and void, and the remaining provisions of this Agreement will remain in effect.
14.11. Waiver. No failure or delay by either party in exercising any right under this Agreement will constitute a waiver of that right or any other right.
14.12. Entire Agreement, Order of Precedence, and Supremacy.
(a) Entire Agreement. This Agreement, including all Order Forms, SOWs, and Exhibits, constitutes the entire agreement between the Parties and supersedes all prior understandings, oral or written. Any amendment must be in writing and signed by both Parties.
(b) Order of Precedence. In the event of a conflict, the documents shall control in the following order: (1) this Agreement, (2) the SOW, (3) the Order Form. Notwithstanding the foregoing, a specific provision in an Order Form or SOW may supersede a conflicting provision in this Agreement only if it explicitly identifies the section number it intends to override (e.g., "Notwithstanding Section 11.2 of the Agreement...") and is counter-signed by an authorized representative of ThreatModeler..
(c) Supremacy over Customer Forms. This Agreement and any ThreatModeler-issued Order Form shall prevail over any terms in a Customer-issued purchase order (PO), vendor portal, or other business form. All such Customer-provided terms are hereby rejected, null, and void. ThreatModeler’s delivery of the Product or acceptance of payment shall not be construed as acceptance of Customer's terms, regardless of whether such Customer forms are signed by ThreatModeler.
This On-Premise Software License Agreement (this “Agreement”) governs Customer’s license to, and use of, ThreatModeler's on-premise software platform and related services (the “Product”). This Agreement entered into by and between ThreatModeler Software, Inc., a Delaware corporation with its principal place of business at 101 Hudson Street, 21st Floor Jersey City, New Jersey 07302, USA (“ThreatModeler”); and the entity or individual identified as the customer in an applicable Order Form or that otherwise downloads, installs, or uses the Software (“Customer”). This Agreement takes effect on the date of the initial Order Form, or the date on which Customer first downloads or accesses the Software, whichever is earlier (the “Effective Date”).
BY EXECUTING AN ORDER FORM THAT REFERENCES THIS AGREEMENT, BY CLICKING “I AGREE,” OR BY ACCESSING OR USING THE PRODUCT, CUSTOMER AGREES TO BE BOUND BY THIS AGREEMENT. IF YOU ARE ENTERING INTO THIS AGREEMENT ON BEHALF OF A COMPANY OR OTHER LEGAL ENTITY, YOU REPRESENT THAT YOU HAVE THE AUTHORITY TO BIND SUCH ENTITY TO THIS AGREEMENT.
1. DEFINITIONS
1.1. "Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where "control" means direct or indirect ownership of more than fifty percent (50%) of the voting interests of the subject entity. Notwithstanding the foregoing, an "Affiliate" shall not include any entity that is a direct competitor of ThreatModeler. ThreatModeler reserves the right, in its reasonable business judgment, to determine whether an entity qualifies as a direct competitor.
1.2. "Authorized User" means a specific, uniquely identified individual (an employee or contractor of Customer or its Affiliates) who has been authorized by Customer to access and use the Software. Each Authorized User must be assigned unique user credentials (e.g., a unique user ID and password), and a user license may not be shared or used by more than one individual. However, user licenses may be permanently reassigned to a new individual replacing one who has terminated their employment or contract, or otherwise changed job status or function and no longer requires access to the Software. Customer is fully responsible for all acts and omissions of its Authorized Users.
1.3. "Confidential Information" means all information disclosed by a party ("Disclosing Party") to the other party ("Receiving Party"), whether orally or in writing, that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure. "Confidential Information" includes, without limitation: (a) For ThreatModeler: The Software in its entirety (exclusively in Object Code format, as no Source Code is licensed or disclosed under this Agreement), its underlying technology, algorithms, performance data, security reports, product roadmaps, and pricing; (b) For Customer: Any Customer Data or other technical or business information that Customer discloses to ThreatModeler in the course of receiving Support Services; (c) For Both Parties: The terms and conditions of this Agreement and all Order Forms. "Confidential Information" does not include any information that: (i) is or becomes generally known to the public without breach of any obligation owed to the Disclosing Party; (ii) was known to the Receiving Party prior to its disclosure by the Disclosing Party without breach of any obligation; (iii) is received from a third party without breach of any obligation; or (iv) was independently developed by the Receiving Party without use of or reference to the Disclosing Party's Confidential Information.
1.4. "Customer Data" means any proprietary information, data, content, code, models, diagrams, or materials uploaded, submitted, or inputted into the Software by Customer or its Authorized Users ("Inputs"). For the avoidance of doubt, Customer Data does not include any threat libraries, security controls, templates, rules, or threat modeling intelligence pre-existing within or generated by the Software ("ThreatModeler Content").
1.5. "Documentation" means ThreatModeler's official, generally available technical and functional documentation for the applicable Product, as made available on ThreatModeler's support portal or other designated website. For the avoidance of doubt, "Documentation" specifically excludes any and all marketing materials, websites, press releases, proposals, or non-technical blog posts, and shall not be construed as a warranty or commitment for the development or delivery of any future functionality or features.
1.6. "Feedback" means any suggestion, enhancement request, recommendation, correction, or other feedback provided by Customer or its Authorized Users relating to the operation or functionality of the Product.
1.7. "Intellectual Property Rights" means any and all registered and unregistered rights granted, applied for, or otherwise now or hereafter in existence under or related to any patent, copyright, trademark, trade secret, database protection, or other intellectual property law, and all similar or equivalent rights or forms of protection, in any part of the world. This includes, without limitation: (a) all rights in and to inventions (whether patentable or not), discoveries, and improvements; (b) all rights in and to works of authorship, including copyrights, mask work rights, and moral rights; (c) all rights in and to trade names, logos, trademarks, and service marks (together with all of the goodwill associated therewith); (d) all rights in and to confidential information, know-how, and trade secrets; and (e) all rights in and to domain names, website designs, and user interface designs.
1.8. "License Term" means the initial term for the Software license as specified in an Order, and any subsequent renewal terms.
1.9. "Order" means the binding transactional document for the purchase of Products. An Order is formed when: (a) Customer executes a "Quote" or "Order Form" issued by ThreatModeler; (b) Customer completes an online purchase or registration process through ThreatModeler's website; or (c) ThreatModeler accepts, in writing or by beginning performance, a "Purchase Order" or "PO" issued by Customer against a valid Quote. A PO issued by Customer becomes a binding Order only upon ThreatModeler's written acceptance. For the avoidance of doubt, any Purchase Order issued by Customer is accepted by ThreatModeler solely for the purpose of administrative convenience, invoicing, and billing; any pre-printed, standard, or conflicting terms and conditions contained in or attached to such Customer-issued PO are hereby expressly rejected by ThreatModeler and shall be null, void, and of no legal force or effect, as set forth in Section 14.12.
1.10. "Product(s)" means the Software and any related Support Services purchased by Customer as identified in an applicable Order.
1.11. "Professional Services" means expert services provided by ThreatModeler to Customer, which are separate from the licensed Software and are governed by a Statement of Work ("SOW"). Professional Services are purchased on a project or time-and-materials basis and may include, but are not limited to, implementation assistance, system configuration, dedicated training, and custom content or report creation. Unless otherwise expressly agreed in a SOW, all Professional Services are provided on a non-"work-for-hire" basis. All intellectual property rights in any deliverables, tools, or methodologies used or created by ThreatModeler in the course of providing Professional Services shall remain the exclusive property of ThreatModeler, subject to the limited license rights granted to Customer in the applicable SOW or Section 13.4 of this Agreement. The successful delivery of Professional Services is dependent on Customer's timely cooperation and fulfillment of its responsibilities as outlined in the applicable SOW.
1.12. "Scope of Use" means the specific usage limits, tiers, and metrics for the purchased Software license, as expressly set forth in the applicable Order. Common metrics include, but are not limited to, the number of Authorized Users and the number of Threat Models. Customer's use of the Software must not exceed the Scope of Use.
1.13. "Support Services" means the technical support and maintenance services, including access to Updates, provided by ThreatModeler for the Software. The specific scope, service levels, and commitments for the Support Services are detailed in the Support Services Policy, the current version of which is located at threatmodeler.ai/legal/support-program.
1.14. "Third-Party Code" means any code or libraries, including open source software, that are not proprietary to ThreatModeler and are included in or distributed with the Software.
1.15. "Updates" means any bug fixes, patches, maintenance releases, or new versions of the Software (including both minor and major releases) that ThreatModeler makes generally available, at no additional cost, to its customers with an active Support Services subscription.
2. LICENSE, DELIVERY AND SUPPORT
2.1. License Grant and Scope. Subject to Customer’s full and timely payment of all applicable fees and its continuous compliance with this Agreement, ThreatModeler grants Customer a non-exclusive, non-sublicensable, and non-transferable License, solely in Object Code format, to install, execute, and use the Software during the applicable License Term. The Software is licensed based on the metrics specified in the Order (e.g., number of Authorized Users). This License permits installation and use on servers owned or controlled by Customer, or by its authorized third-party service provider, solely for Customer's internal business purposes and strictly within the Scope of Use. Customer shall not use the Software beyond the specific capacity or licensing units defined in the applicable Order.
2.2. Delivery. ThreatModeler will make the Software available to Customer for electronic download from a designated repository. Delivery shall be deemed complete when ThreatModeler provides Customer with the necessary access credentials and any applicable license keys ("Delivery").
2.3. Acceptance. Customer shall have ten (10) business days from Delivery to test the Software and notify ThreatModeler in writing of any material non-conformity with the Documentation ("Acceptance Period"). The Software will be deemed accepted if Customer: (a) provides written notice of acceptance; (b) uses the Software in a production environment; or (c) fails to provide a written notice of non-conformity within the Acceptance Period. If Customer provides a timely notice of non-conformity, ThreatModeler shall use commercially reasonable efforts to correct it, as described in Section 9.2 of this Agreement.
2.4. Support and Maintenance. ThreatModeler will provide technical support and maintenance for the Software in accordance with the Support Services Policy, the current version of which is located at threatmodeler.ai/legal/support-program (or a successor URL). The Support Services Policy is hereby incorporated by reference into this Agreement. ThreatModeler reserves the right to update the Support Services Policy from time to time, provided that any such update will not result in a material diminution of the Support Services commitments during Customer's then-current License Term.
2.5. Customer Modifications. The Software may enable modification of its functionality through its rules engine or customized content (“Customer Modifications”). Customer may use such Modifications solely with its own instances of the Software. Notwithstanding anything to the contrary, ThreatModeler provides no support, warranty, indemnification, or other liability with respect to Customer Modifications. Customer agrees to indemnify, defend, and hold ThreatModeler harmless from any claim arising out of or related to Customer Modifications.
2.6. Third-Party Code. The Software includes Third-Party Code. The license terms applicable to such Third-Party Code may prevail over this Agreement with respect to that specific component. A list of material Third-Party Code and their applicable licenses is available in the Documentation.
2.7. Backup and Disaster Recovery Licenses. Customer may make one (1) archival copy of the Software solely for back-up or cold disaster recovery purposes, provided that Customer reproduces all copyright and other proprietary notices on such copy. Customer agrees that any such disaster recovery copy shall remain inactive (i.e., not executing or processing data) and may only be activated in the event of, and for the duration of, a primary server outage. Installation of the Software on any Staging, Development, or non-production environment other than a cold backup requires the purchase of additional licenses or a separate non-production order.
3. ACCEPTABLE USE AND CUSTOMER OBLIGATIONS
3.1. General Responsibilities. Customer is and shall remain solely responsible and liable for:
(a) Authorized User Conduct: All activities conducted by its Authorized Users within the Software, and for ensuring their compliance with the terms of this Agreement.
(b) Customer Data: The accuracy, legality, quality, and integrity of all Customer Data, including obtaining all necessary rights and consents for Customer to use and process the Customer Data with the Software.
(c) Environment and System Security: Maintaining the security and integrity of the Customer's own IT environment where the Software is installed, including securing all networks, servers, operating systems, and access credentials.
(d) Compliance with Laws: Ensuring that its use of the Software complies with all applicable local, state, federal, and international laws and regulations.
(e) Use of Current Version. Upon the release of an Update, Customer agrees to use commercially reasonable efforts to install and operate on the latest version of the Software made available to it. ThreatModeler's support obligations may be limited if Customer is operating on a version other than the two most current major releases, as further detailed in the Support Services Policy.
3.2. Use Restrictions. Customer shall not, and shall not permit any Authorized User or any third party to, perform any of the following actions:
(a) Sell, resell, lease, sublicense, or otherwise provide access to the Software to any third party.
(b) Modify, translate, adapt, or create derivative works based upon the Software, except as expressly permitted in this Agreement.
(c) Reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code or non-public APIs of the Software, except to the extent such a restriction is expressly prohibited by applicable law.
(d) Interfere with, disrupt, or create an undue burden on the integrity, performance, or security of the Software.
(e) Conduct any security assessments, penetration tests, or vulnerability scans on the Software itself in a manner that could constitute reverse engineering or an attempt to discover non-public vulnerabilities, without the prior express written consent of ThreatModeler. This restriction does not limit Customer's right to conduct security testing on its own underlying infrastructure.
(f) Use the Software to store or transmit any viruses, worms, or other malicious code.
(g) Use the Software to store or transmit any content that is infringing, libelous, or otherwise unlawful, or that violates the privacy or intellectual property rights of any third party.
(h) Publicly disseminate any performance information or competitive benchmarks of the Software without ThreatModeler's prior written consent.
(i) Attempt to circumvent any Scope of Use restrictions or other license control mechanisms within the Software.
(j) Multiplexing and Pooling: Use any technology, software, script, or automated agent to pool connections, redirect requests, or "multiplex" access to the Software in a manner that bypasses the Authorized User license limits, or allows unlicensed individuals to indirectly access, query, or utilize the Software's functionalities.
3.3. High-Risk Activities Prohibition. The Product is not designed, manufactured, or intended for use in hazardous environments requiring fail-safe performance, including but not limited to the operation of nuclear facilities, aircraft navigation or communication systems, air traffic control, direct life-support machines, or weapons systems ("High-Risk Activities"). Customer expressly agrees that it will not use, or permit the use of, the Product for any High-Risk Activities. ThreatModeler and its suppliers expressly disclaim any express or implied warranty of fitness for such purposes.
3.4. Prohibition on Transferring Sensitive Personal Information to ThreatModeler. Customer agrees that it shall not transfer, disclose, or otherwise make available to ThreatModeler (including in support tickets, logs, database dumps, or emails) any "Sensitive Data." Customer acknowledges that the Product and Support Services are not designed for such data, and ThreatModeler has no liability for any Sensitive Data received in violation of this section. "Sensitive Data" includes any data that requires heightened protection under applicable law, including, but not limited to, health information (HIPAA), financial information (GLBA, PCI DSS), government-issued IDs, and "special categories of personal data" under GDPR. Customer shall indemnify, defend, and hold harmless ThreatModeler from any damages, losses, and costs arising from or related to Customer's breach of this Section 3.4.
3.5. Infrastructure and Environment Disclaimer. Customer acknowledges and agrees that the Software is installed and operated within Customer’s own IT environment and infrastructure, which is entirely outside of ThreatModeler’s control. ThreatModeler shall have no liability, obligation, or responsibility whatsoever for: (a) any service interruptions, performance degradation, data loss, or failures of the Software caused by or resulting from Customer’s hardware, servers, local databases, operating systems, or internal network configurations; or (b) any security breaches, unauthorized access, or data exfiltration occurring within Customer’s local IT environment, unless such security incident is directly and solely caused by a documented, unpatched, and material vulnerability inherent in the Software as delivered by ThreatModeler.
4. FEES, PAYMENT, AND AUDITS
4.1. Fees. Customer shall pay all fees specified in all applicable Orders ("Fees"). Except as expressly provided in this Agreement, all payment obligations are non-cancellable and all Fees paid are non-refundable. The Fees are based on the Product license purchased and not on actual usage.
4.2. Invoicing and Payment. Unless otherwise specified in an Order Form, all Fees will be invoiced annually in advance. All invoices are due and payable net thirty (30) days from the invoice date, without offset or deduction. Late payments will accrue interest at a rate of 1.5% per month or the maximum rate permitted by law, whichever is lower.
4.3. Taxes.
a) Fees are stated exclusive of any taxes, levies, duties, or similar governmental assessments, including value-added, sales, use, or withholding taxes (collectively, "Taxes"). Customer is responsible for paying all Taxes associated with its purchases hereunder.
b) If ThreatModeler has the legal obligation to pay or collect Taxes for which Customer is responsible, the appropriate amount shall be invoiced to and paid by Customer, unless Customer provides ThreatModeler with a valid tax exemption certificate.
c) If Customer is required by law to withhold any Taxes from its payments to ThreatModeler, Customer must provide ThreatModeler with an official tax receipt or other appropriate documentation. Customer agrees to increase the payment to ThreatModeler by the amount necessary to ensure that ThreatModeler receives a net amount equal to the full amount of the Fees it would have received without the deduction.
4.4. Suspension of Support and Termination for Non-Payment. If any invoiced amount is more than thirty (30) days overdue, ThreatModeler may, without limiting its other rights and remedies: (a) suspend the provision of Support Services upon ten (10) days' written notice until such amounts are paid in full, and (b) if the failure to pay continues for sixty (60) days or more, terminate this Agreement for cause. Customer's License to use the Software is immediately revoked, and Customer must comply with the deinstallation requirements in Section 5.5.
4.5. Invoice Disputes. Customer must notify ThreatModeler in writing of any good-faith dispute with respect to an invoice within fifteen (15) days of the invoice date. If Customer fails to do so, Customer is deemed to have waived its right to dispute that invoice, and the invoice will be considered final and payable.
4.6. Usage Verification and Audit Rights.
(a) Usage Reports. Upon ThreatModeler’s reasonable written request (no more than twice per calendar year), Customer shall promptly (and in any event within ten (10) business days) extract and provide to ThreatModeler a system-generated usage report or screenshot from the Software's administrative console showing the active number of Authorized Users and Threat Models, to verify compliance with the Scope of Use.
(b) Audit. In the event Customer fails to provide such usage reports, or if ThreatModeler has a reasonable, documented suspicion of over-usage, ThreatModeler (or its designated independent third-party auditor subject to strict confidentiality) may, upon thirty (30) days' prior written notice, audit Customer's use of the Software. Such audit shall be conducted during normal business hours, at Customer's facilities, and shall not unreasonably interfere with Customer's business.
(c) Overages. If any verification or audit reveals that Customer has exceeded its Scope of Use, ThreatModeler will invoice Customer for such overage at ThreatModeler's then-current list prices for the entire period of non-compliance. If the underpayment exceeds five percent (5%) of the fees payable during the audited period, Customer shall also pay the reasonable costs of the audit.
5. TERM AND TERMINATION
5.1. Agreement Term. The term of this Agreement commences on the Effective Date and continues as long as a License Term for any Software is in effect, unless terminated earlier in accordance with its terms.
5.2. License Term and Auto-Renewal. Each License Term will automatically renew for additional periods equal to the expiring term (or one year, if the expiring term is longer than one year), unless either party gives the other written notice of non-renewal at least sixty (60) days before the end of the then-current License Term. ThreatModeler reserves the right to increase the fees for any renewal term by providing notice thereof at least seventy-five (75) days prior to the end of the current term.
5.3. Termination for Cause. A party may terminate this Agreement for cause: (i) upon thirty (30) days' written notice to the other party of a material breach if such breach remains uncured at the expiration of such period, or (ii) if the other party becomes the subject of a petition in bankruptcy or any other proceeding relating to insolvency. If Customer terminates for cause due to ThreatModeler's uncured material breach, ThreatModeler will provide a pro-rata refund of any prepaid fees for the remainder of the terminated License Term.
5.4. Termination for Convenience by Customer. Customer may terminate this Agreement for its convenience at any time by providing ninety (90) days' prior written notice to ThreatModeler. Upon such termination, Customer shall not be entitled to any refund, credit, or pro-rata return of any Fees paid upfront (as all payment obligations are non-cancellable under Section 4.1). All unpaid Fees associated with the remaining duration of the committed License Term shall become immediately due and payable upon the effective date of such termination.
5.5. Effect of Termination. Upon any termination or expiration of this Agreement: (a) all Licenses granted to Customer hereunder shall immediately terminate; (b) Customer shall immediately cease all use of the Software, uninstall it from all systems, and destroy all copies of the Software in its possession or control; (c) Customer shall immediately pay any unpaid fees accrued prior to the effective date of termination; and (d) each party will, upon request, promptly return or securely destroy all Confidential Information of the other party. Customer shall provide written certification of its compliance with subsection (b) within ten (10) business days of ThreatModeler's request.
5.6. 30-Day Return Policy. As part of our commitment to customer satisfaction, Customer may terminate the initial Order for the Software for any reason within thirty (30) days of the initial Delivery date. To exercise this right, Customer must provide written notice of termination and certify its compliance with the "Effect of Termination" clause (Section 5.5). Upon receipt, ThreatModeler will provide a full refund of the license fees paid for the returned Software. This return right applies only to the initial purchase and not to any renewals or subsequent purchases.
5.7. Survival. The provisions of this Agreement which by their nature should survive termination or expiration shall remain in effect, including: Section 1 (Definitions), Section 4 (Fees, Payment, and Audits), Section 5.5 (Effect of Termination), Section 5.7 (Survival), Section 6 (Data Protection and Security), Section 7 (Confidentiality), Section 8 (Intellectual Property Rights), Section 9.4 (Warranty Disclaimer), Section 10 (Indemnification), Section 11 (Limitation of Liability), and Section 14 (General Provisions).
5.8. Reinstatement of Lapsed Support. If Customer’s subscription for Support Services expires or is terminated, and Customer seeks to reinstate such services at a later date, such reinstatement shall be subject to ThreatModeler's then-current policies. At a minimum, reinstatement may require Customer to pay: (a) a reinstatement fee; (b) all Support Services fees that would have been payable during the period of the lapse; and (c) the Support Services fees for the new term.
6. DATA PROTECTION AND SECURITY
6.1. Customer as Sole Controller and Business. Customer acknowledges and agrees that because the Software is installed and operated entirely within Customer's own IT environment, Customer acts as the sole "Controller" and "Business" (as such terms are defined in applicable data protection laws) for any and all Customer Data processed by the Software. Customer is solely and exclusively responsible for the security of such data and for fulfilling all legal obligations related thereto.
6.2. ThreatModeler's Role Regarding the Licensed Software. ThreatModeler's primary role is strictly that of a software licensor. With respect to the standard operation of the licensed Software, ThreatModeler has no access to, and does not "Process" (as defined in applicable data protection laws), any Customer Data. Consequently:
(a) No Data Processing. ThreatModeler's Data Processing Addendum (DPA) does not apply to the licensing of the Software itself.
(b) Security of the Software. ThreatModeler warrants that the Software, as delivered, does not contain any known malicious code designed to exfiltrate or damage Customer Data without authorization.
6.3. Incidental Data Access by ThreatModeler. The parties acknowledge that in limited and specific circumstances as described below, ThreatModeler personnel may have incidental access to Customer Data. In such cases, and only in such cases, ThreatModeler shall act as a "Service Provider" or "Processor" to the Customer.
(a) Data Provided for Support Services. In the event Customer discloses any Customer Data to ThreatModeler in the course of receiving Support Services (for example, by transmitting log files, threat models, or database backups), ThreatModeler will:
(i) Process such data solely for the purpose of diagnosing and resolving the support incident;
(ii) Treat such data as Customer's Confidential Information at all times; and
(iii) Securely delete such data from ThreatModeler systems upon the resolution of the support incident.
(b) Data Accessed during Professional Services. In the event ThreatModeler personnel access Customer's systems (either remotely or on-site) to perform Professional Services, ThreatModeler will:
(i) Ensure its personnel access Customer Data only to the minimum extent necessary to perform the contracted services;
(ii) Ensure its personnel are bound by strict confidentiality obligations; and
(iii) Not copy, download, or exfiltrate any Customer Data from Customer's environment unless expressly authorized in writing by Customer for a specific, temporary purpose (e.g., to test a migration script).
6.4. Customer's Security Responsibilities. Customer is solely responsible for implementing and maintaining all administrative, physical, and technical safeguards for its own IT environment. ThreatModeler has no liability for any security incident, data breach, or compliance failure occurring within Customer's environment.
7. CONFIDENTIALITY
7.1. Obligation of Confidentiality. The Receiving Party shall:
(a) use the same degree of care that it uses to protect the confidentiality of its own confidential information of like kind (but in no event less than a reasonable degree of care);
(b) not use any Confidential Information of the Disclosing Party for any purpose outside the scope of this Agreement; and
(c) except as otherwise authorized by the Disclosing Party in writing, limit access to Confidential Information to those of its and its Affiliates’ employees, contractors, and agents who have a legitimate "need to know" for purposes consistent with this Agreement and who are bound by confidentiality obligations containing protections no less stringent than those herein. The Receiving Party shall be liable for any breach of this Section 7 by its representatives.
7.2. Compelled Disclosure. A Receiving Party may disclose Confidential Information of the Disclosing Party to the extent compelled by law or a valid court order to do so, provided the Receiving Party gives the Disclosing Party prior written notice of the compelled disclosure (to the extent legally permitted) and reasonable assistance, at the Disclosing Party's cost, if the Disclosing Party wishes to contest or seek a protective order for the disclosure.
7.3. Injunctive Relief. The parties agree that a breach of this Section 7 may cause irreparable harm for which monetary damages would not be an adequate remedy. Accordingly, the Disclosing Party shall be entitled to seek injunctive or other equitable relief to prevent or curtail any such breach, without the necessity of posting a bond.
7.4. Term of Confidentiality. The obligations of confidentiality, non-disclosure, and non-use set forth in this Section 7 shall survive the expiration or termination of this Agreement for a period of five (5) years. Notwithstanding the foregoing, with respect to any Confidential Information of either party that constitutes a "trade secret" or "secreto industrial" under applicable law (including ThreatModeler’s Software, Object Code, threat libraries, algorithms, schemas, and technology), such obligations of confidentiality and non-use shall survive the expiration or termination of this Agreement perpetually for as long as such information remains a trade secret.
8. INTELLECTUAL PROPERTY RIGHTS
8.1. ThreatModeler's Intellectual Property. As between the Parties, ThreatModeler and its licensors exclusively own and retain all right, title, and interest in and to the Product, including the Software (licensed solely in Object Code format), all pre-existing threat libraries, security controls, templates, rules, and all generated threat models, reports, security requirements, and outputs (collectively, "Outputs"), together with all Intellectual Property Rights therein.
Subject to Customer's full and timely payment of all Fees, ThreatModeler hereby grants Customer, during the applicable License Term, a non-exclusive, non-transferable, non-sublicensable, and limited license to use, copy, and distribute the Outputs solely for Customer's internal business and compliance purposes, provided that Customer shall retain all rights in its proprietary Inputs contained within such Outputs.
Customer explicitly acknowledges and agrees that: (a) this Agreement grants a limited License, not a sale; (b) no rights or licenses to the Source Code of the Software are granted hereunder; and (c) all rights not expressly granted to Customer are reserved exclusively by ThreatModeler.
8.2. Customer's Intellectual Property. As between the Parties, Customer exclusively owns and retains all right, title, and interest in and to the Customer Data (comprising proprietary Inputs uploaded into the Software) and all Intellectual Property Rights therein.
8.3. Ownership of Feedback. Customer agrees that any suggestions, enhancement requests, recommendations, or other feedback provided by Customer or its Authorized Users relating to the Software ("Feedback") shall be owned exclusively by ThreatModeler. Customer hereby irrevocably, perpetually, and unconditionally assigns and agrees to assign to ThreatModeler all worldwide right, title, and interest (including all patent, copyright, and trade secret rights) in and to such Feedback, without any right to royalty, compensation, or attribution.
8.4. License for Support. In the event Customer provides ThreatModeler with access to any Customer Data in the course of receiving Support Services (including via database backups, logs, or diagnostic files), Customer hereby grants ThreatModeler a temporary, non-exclusive, royalty-free, fully paid-up, worldwide license to use, copy, and process such data solely to diagnose and resolve the support incident. Customer represents and warrants that all such transferred materials have been sanitized and de-identified in accordance with Section 6.3(a)(iv). This license terminates automatically upon resolution of the support incident.
8.5. Protection of Proprietary Markings (DMCA Compliance). Customer shall not, and shall not permit any third party to, remove, alter, cover, or obscure any patent, copyright, trademark, trade secret, or other proprietary rights notices or Copyright Management Information (as defined in 17 U.S.C. § 1202) placed on or contained within the Software, the Documentation, or any generated Outputs (including generated PDF reports).
8.6. API and Integration Intellectual Property. To the extent Customer develops any custom connectors, scripts, or software integrations designed to connect Customer’s internal tools to the Software via ThreatModeler’s APIs or the Model Context Protocol (MCP) Server (collectively, "Integrations"), Customer shall retain ownership of its custom code. However, Customer agrees that: (a) Integrations shall not create any joint intellectual property rights; (b) ThreatModeler retains exclusive ownership of the underlying APIs, the MCP Server technology, and platform architecture; and (c) ThreatModeler is free to independently develop and commercialize similar integrations for other customers.
9. WARRANTIES AND DISCLAIMERS
9.1. Mutual Warranties. Each party represents and warrants that it has the legal power and authority to enter into this Agreement.
9.2. Limited Software Warranty. ThreatModeler warrants that, for a period of ninety (90) days from the date of Delivery, the Software will perform materially in accordance with the applicable Documentation ("Warranty Period"). For any breach of this warranty reported by Customer during the Warranty Period, Customer's sole and exclusive remedy, and ThreatModeler's entire liability, will be for ThreatModeler, at its option, to: (a) use commercially reasonable efforts to correct the non-conformity; or (b) provide a replacement of the non-conforming Software.
9.3. Professional Services Warranty. ThreatModeler warrants that any Professional Services will be performed in a professional and workmanlike manner. Customer's remedy for a breach of this warranty is to notify ThreatModeler in writing within thirty (30) days of the non-conforming service, in which case ThreatModeler will re-perform the deficient services at no additional cost.
9.4. WARRANTY DISCLAIMER. EXCEPT FOR THE EXPRESS WARRANTIES PROVIDED IN THIS SECTION 9, AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SOFTWARE AND ANY PROFESSIONAL SERVICES ARE PROVIDED "AS IS". THREATMODELER AND ITS SUPPLIERS EXPRESSLY DISCLAIM ALL OTHER WARRANTIES, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. CUSTOMER ACKNOWLEDGES AND AGREES THAT ANY AI-GENERATED OUTPUTS, SUGGESTIONS, OR RECOMMENDATIONS FROM OPTIONAL AI-ASSISTED FUNCTIONALITY ARE PROVIDED FOR INFORMATIONAL PURPOSES ONLY, AND ARE GOVERNED SOLELY BY SECTION 12.4 OF THIS AGREEMENT. THREATMODELER DOES NOT WARRANT THAT THE USE OF THE SOFTWARE WILL BE UNINTERRUPTED OR ERROR-FREE, OR THAT ALL DEFECTS CAN BE CORRECTED.
10. INDEMNIFICATION
10.1. Indemnification by ThreatModeler. ThreatModeler will defend Customer against any third-party claim, demand, suit, or proceeding ("Claim") alleging that Customer's use of the Software, as delivered by ThreatModeler and used in accordance with this Agreement, directly infringes a valid U.S. patent, copyright, or registered trademark of such third party. ThreatModeler will indemnify Customer for any damages, attorney fees, and costs finally awarded against Customer as a result of, or for amounts paid by Customer under a court-approved settlement of, such a Claim.
10.2. Mitigation and Remedy. If the Software becomes, or in ThreatModeler's opinion is likely to become, the subject of an infringement Claim, ThreatModeler may, at its option and expense:
(a) procure for Customer the right to continue using the Software;
(b) replace or modify the Software with a non-infringing but functionally equivalent alternative; or
(c) if options (a) and (b) are not commercially reasonable, terminate Customer's License for the infringing Software and provide a refund of the license fees paid for that Software, depreciated on a straight-line basis over a three (3) year useful life.
10.3. Exclusions. ThreatModeler's obligations under Section 10.1 will not apply to any Claim to the extent it arises from: (a) use of the Software in combination with hardware, software, or data not provided by ThreatModeler; (b) Customer Data; (c) any modification to the Software not made by ThreatModeler; or (d) Customer's use of a version of the Software other than the then-current version, if the infringement would have been avoided by use of the current version made available to Customer.
10.4. Indemnification by Customer. Customer will defend ThreatModeler against any Claim made or brought against ThreatModeler by a third party arising from or related to: (i) the Customer Data, including any allegation that the Customer Data infringes or misappropriates the rights of a third party; (ii) Customer’s use of the Software in breach of this Agreement or applicable law; or (iii) any Customer Modifications (as described in Section 2.5). Customer will indemnify ThreatModeler for any damages, attorney fees, and costs finally awarded against ThreatModeler as a result of, or for amounts paid by ThreatModeler under a court-approved settlement of, such a Claim.
10.5. Indemnification Procedure. The indemnifying party's obligations are contingent upon the indemnified party: (a) promptly giving written notice of the Claim; (b) giving the indemnifying party sole control of the defense and settlement of the Claim (provided that the indemnifying party may not settle any Claim unless the settlement unconditionally releases the indemnified party of all liability and does not include a statement as to, or an admission of, fault, culpability, or failure to act by or on behalf of the indemnified party); and (c) providing all reasonable assistance, at the indemnifying party's expense.
10.6. Exclusive Remedy. This Section 10 states the indemnifying party's sole liability to, and the indemnified party's exclusive remedy against, the other party for any type of third-party infringement claim described in this section.
11. LIMITATION OF LIABILITY
11.1. DISCLAIMER OF INDIRECT AND CONSEQUENTIAL DAMAGES.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL EITHER PARTY OR ITS SUPPLIERS HAVE ANY LIABILITY TO THE OTHER PARTY FOR ANY LOST PROFITS, LOST DATA, LOSS OF USE, BUSINESS INTERRUPTION, COSTS OF PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES, OR FOR ANY INDIRECT, SPECIAL, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES, HOWEVER CAUSED AND, WHETHER IN CONTRACT, TORT OR UNDER ANY OTHER THEORY OF LIABILITY, AND WHETHER OR NOT THE PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
11.2. LIMITATION OF AGGREGATE LIABILITY.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL EITHER PARTY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT, WHETHER IN CONTRACT, TORT OR UNDER ANY OTHER THEORY OF LIABILITY, EXCEED THE TOTAL AMOUNT OF FEES ACTUALLY PAID BY CUSTOMER TO THREATMODELER HEREUNDER IN THE TWELVE (12) MONTHS PRECEDING THE DATE OF THE FIRST INCIDENT GIVING RISE TO THE LIABILITY.
11.3. EXCLUSIONS FROM LIMITATIONS ("UNLIMITED LIABILITY CARVE-OUTS").
THE LIMITATIONS SET FORTH IN SECTIONS 11.1 AND 11.2 SHALL NOT APPLY TO:
(a) A PARTY'S INDEMNIFICATION OBLIGATIONS UNDER SECTION 10;
(b) A BREACH OF CONFIDENTIALITY OBLIGATIONS UNDER SECTION 7;
(c) A VIOLATION OF THE OTHER PARTY'S INTELLECTUAL PROPERTY RIGHTS;
(d) CUSTOMER'S UNPAID PAYMENT OBLIGATIONS FOR FEES DUE UNDER ANY ORDER FORM; OR
(e) LIABILITY ARISING FROM A PARTY'S GROSS NEGLIGENCE, WILLFUL MISCONDUCT, OR FRAUD.
11.4. Allocation of Risk. The parties acknowledge and agree that the essential purpose of this Section 11 is to allocate the risks under this Agreement between the parties and that the fees have been set and this Agreement entered into in reliance upon these limitations of liability.
12. OPTIONAL AI-ASSISTED FUNCTIONALITY
12.1. General. The Software may include optional features that can connect to third-party generative artificial intelligence services ("AI Features". The use of any AI Feature is at Customer's sole discretion and requires Customer to configure and enable such features within its on-premise installation of the Software.
12.2. Data Transmission and Processing. Customer acknowledges and agrees that when an AI Feature is enabled, the Software will transmit certain Customer Data (Inputs) directly from Customer's own IT environment to the API of the applicable third-party AI service provider. The resulting output ("Output") is then returned directly to the Software within Customer's environment. At no point during this process does ThreatModeler receive, process, store, or have access to the Customer Data (Inputs) or the Outputs generated by the AI Features.
12.3. Customer's Sole Responsibility. Customer is solely and exclusively responsible for its use of any AI Feature. This responsibility includes:
(a) Deciding which AI Features to enable and use.
(b) Its relationship with any third-party AI service provider, including compliance with that provider's terms of service and privacy policies. If an AI Feature connects to a provider designated by ThreatModeler (e.g., Azure OpenAI), Customer is responsible for reviewing and accepting that provider's terms before use.
(c) The content of any Customer Data (Inputs) provided to an AI Feature, including ensuring that no Sensitive Data (as defined in Section 3.4) is transmitted to any third-party AI service provider.
12.4. AI OUTPUT DISCLAIMER. ALL OUTPUTS GENERATED BY ANY AI FEATURE ARE PROVIDED "AS IS," WITHOUT WARRANTY OF ANY KIND]. OUTPUTS ARE GENERATED BY THIRD-PARTY SYSTEMS OUTSIDE OF THREATMODELER'S CONTROL. CUSTOMER IS SOLELY RESPONSIBLE FOR REVIEWING, VALIDATING, AND ENSURING THE ACCURACY, SECURITY, AND APPROPRIATENESS OF ANY AI-GENERATED OUTPUT BEFORE ANY USE OR RELIANCE THEREON. THREATMODELER SHALL HAVE NO LIABILITY WHATSOEVER ARISING FROM OR RELATED TO CUSTOMER'S USE OF AI FEATURES.
13. PROFESSIONAL SERVICES
13.1. Scope and Governance. ThreatModeler will provide Customer with the Professional Services, if any, as described in one or more mutually executed Statements of Work ("SOWs"). Each SOW is hereby incorporated by reference into this Agreement. In the event of a direct conflict between the terms of a SOW and this Agreement, the terms of this Agreement shall prevail, unless the SOW expressly identifies the conflicting provision of this Agreement and states its intent to override it for that specific project.
13.2. Performance Warranty. ThreatModeler warrants that all Professional Services will be performed in a professional and workmanlike manner, in all material respects in accordance with the specifications set forth in the applicable SOW. For any breach of this warranty, Customer's sole and exclusive remedy shall be for ThreatModeler, at its option, to either: (a) re-perform the non-conforming Professional Services at no additional charge; or (b) if re-performance is not commercially feasible, terminate the applicable SOW and provide a pro-rata refund of the fees paid for the non-conforming portion of the Professional Services. To receive this remedy, Customer must report the non-conformity in writing within thirty (30) days of the completion of the services.
13.3. Customer Cooperation. Customer acknowledges that the successful and timely delivery of Professional Services requires its good-faith cooperation. ThreatModeler shall not be liable for any delay or failure in performance to the extent caused by Customer's failure to meet its responsibilities.
13.4. Intellectual Property.
(a) ThreatModeler's Pre-Existing IP. ThreatModeler shall retain all right, title, and interest in and to any of its pre-existing tools, methodologies, know-how, and other intellectual property used or provided in the course of performing the Professional Services ("ThreatModeler Background IP").
(b) Deliverables. Upon Customer's payment in full of all applicable fees, any custom reports, configurations, or other deliverables created specifically for Customer as described in a SOW ("Deliverables") are licensed to Customer on a non-exclusive, non-transferable basis for its internal use only with the licensed Software during its active and fully-paid License Term for the underlying Software. ThreatModeler retains ownership of all intellectual property rights in and to the Deliverables.
(c) No Work for Hire. For the avoidance of doubt, all Professional Services are provided on a non-"work-for-hire" basis.
13.5. Personnel and Expenses. Unless otherwise specified in the applicable SOW, Customer will reimburse ThreatModeler for all reasonable, pre-approved travel and out-of-pocket expenses incurred in connection with the provision of Professional Services.
13.6. Customization Requests. Customer may request minor customizations to the Software that fall outside the scope of a formal Statement of Work. ThreatModeler may consider such requests in its sole discretion. Any such work will be treated as Professional Services, quoted separately, and will not be performed until agreed upon in writing by both parties.
14. GENERAL PROVISIONS
14.1. Governing Law, Jurisdiction, and Venue. This Agreement shall be governed by and construed in accordance with the laws of the State of Delaware, USA, without regard to its conflict of law principles. The parties irrevocably agree to the exclusive jurisdiction and venue of the state and federal courts located in the State of Delaware for the resolution of any dispute arising out of or relating to this Agreement.
14.2. Notices. All notices under this Agreement shall be sent exclusively by email to legal@threatmodeler.com (for ThreatModeler) and to the primary email address specified on the signature page or most recent Order Form (for Customer). Notices are deemed received upon successful transmission, provided no delivery failure is returned. Customer is solely responsible for keeping its email address current and operational.
14.3. Relationship of the Parties. The parties are independent contractors. This Agreement does not create a partnership, franchise, joint venture, agency, fiduciary, or employment relationship between the parties.
14.4. No Third-Party Beneficiaries. This Agreement is for the sole benefit of the parties hereto and their respective successors and permitted assigns and nothing herein, express or implied, is intended to or shall confer upon any other person or entity any legal or equitable right, benefit, or remedy of any nature whatsoever.
14.5. Subcontracting. ThreatModeler may use affiliates or other third-party contractors in the performance of its obligations hereunder, including for the provision of Support Services and Professional Services, provided that ThreatModeler shall remain fully responsible for the performance of any such subcontractor and for their compliance with all terms of this Agreement.
14.6. Assignment. Neither party may assign any of its rights or obligations hereunder, whether by operation of law or otherwise, without the other party's prior written consent (not to be unreasonably withheld). Notwithstanding the foregoing, either party may assign this Agreement in its entirety, without the other party's consent, to its Affiliate or in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of its assets
14.7. Force Majeure. Neither party shall be liable for any failure or delay in performance (except for payment obligations) due to a "Force Majeure Event," meaning causes beyond its reasonable control, including but not limited to acts of God, war, terrorism, riots, strikes, or natural disasters.
14.8. Export Compliance. The Product and related technology are subject to U.S. export control laws and regulations. Customer agrees to comply with all such laws and regulations and represents that it is not named on any U.S. government denied-party list. Customer shall not permit access to or use of the Product in any U.S. embargoed country or in violation of any U.S. export law or regulation.
14.9. U.S. Government End Users. If Customer is an agency or instrumentality of the United States Government ("USG"), the Product and Documentation qualify as "commercial items" as defined at Federal Acquisition Regulation (“FAR”) 48 C.F.R. 2.101. The use, duplication, and disclosure of the Product by the USG is subject to the restrictions set forth in this Agreement, consistent with FAR 12.212 and DFARS 227.7202. To the extent any provision of this Agreement conflicts with applicable federal law, such provision shall be deemed amended to be consistent with federal law.
14.10. Publicity. Neither party shall use the other party's name or logo in any press release, marketing materials, or other public announcement without the other party's prior written consent. However, ThreatModeler may identify Customer by name in its customer lists.
14.11. Severability. If any provision of this Agreement is held by a court of competent jurisdiction to be contrary to law, the provision will be deemed null and void, and the remaining provisions of this Agreement will remain in effect.
14.12. Waiver. No failure or delay by either party in exercising any right under this Agreement will constitute a waiver of that right or any other right.
14.13. Entire Agreement, Order of Precedence, and Supremacy.
(a) Entire Agreement. This Agreement, including all policies incorporated by reference, Order Forms, and SOWs, constitutes the entire agreement between the parties regarding its subject matter and supersedes all prior agreements. Amendments must be in a writing signed by both parties.
(b) Order of Precedence. In the event of a conflict, the documents shall control in the following order: (1) this Agreement, (2) the SOW, (3) the Order Form. Notwithstanding the foregoing, a specific provision in an Order Form or SOW may supersede a conflicting provision in this Agreement only if it explicitly identifies the section number it intends to override (e.g., "Notwithstanding Section 11.2 of the Agreement...") and is counter-signed by an authorized representative of ThreatModeler.
(c) Supremacy over Customer Forms. The terms of this Agreement and any ThreatModeler-issued Order Form shall supersede and prevail over any conflicting or additional terms in any Customer-issued purchase order (PO), vendor portal, or other business form. All such Customer terms are hereby rejected, null, and void. ThreatModeler’s delivery of the Product or acceptance of payment shall not be construed as acceptance of Customer's terms, regardless of whether such Customer forms are signed by ThreatModeler.
This On-Premise Software License Agreement (this “Agreement”) governs Customer’s license to, and use of, ThreatModeler's on-premise software platform and related services (the “Product”). This Agreement entered into by and between ThreatModeler Software, S.L., a Spanish limited liability company, and its principal place of business at Parque Tecnológico Walqa, Ctra. Zaragoza N-330A, Km. 566, 22197 Cuarte (Huesca, Aragon), Spain (“ThreatModeler”); and the entity or individual identified as the customer in an applicable Order Form or that otherwise downloads, installs, or uses the Software (“Customer”). This Agreement takes effect on the date of the initial Order Form, or the date on which Customer first downloads or accesses the Software, whichever is earlier (the “Effective Date”).
BY EXECUTING AN ORDER FORM THAT REFERENCES THIS AGREEMENT, BY CLICKING “I AGREE,” OR BY ACCESSING OR USING THE PRODUCT, CUSTOMER AGREES TO BE BOUND BY THIS AGREEMENT. IF YOU ARE ENTERING INTO THIS AGREEMENT ON BEHALF OF A COMPANY OR OTHER LEGAL ENTITY, YOU REPRESENT THAT YOU HAVE THE AUTHORITY TO BIND SUCH ENTITY TO THIS AGREEMENT.
1. DEFINITIONS
1.1. "Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where "control" means direct or indirect ownership of more than fifty percent (50%) of the voting interests of the subject entity. Notwithstanding the foregoing, an "Affiliate" shall not include any entity that is a direct competitor of ThreatModeler. ThreatModeler reserves the right, in its reasonable business judgment, to determine whether an entity qualifies as a direct competitor.
1.2. "Authorized User" means a specific, uniquely identified individual (an employee or contractor of Customer or its Affiliates) who has been authorized by Customer to access and use the Software. Each Authorized User must be assigned unique user credentials (e.g., a unique user ID and password), and a user license may not be shared or used by more than one individual. However, user licenses may be permanently reassigned to a new individual replacing one who has terminated their employment or contract, or otherwise changed job status or function and no longer requires access to the Software. Customer is fully responsible for all acts and omissions of its Authorized Users.
1.3. "Confidential Information" means all information disclosed by a party ("Disclosing Party") to the other party ("Receiving Party"), whether orally or in writing, that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure. "Confidential Information" includes, without limitation: (a) For ThreatModeler: The Software in its entirety (exclusively in Object Code format, as no Source Code is licensed or disclosed under this Agreement), its underlying technology, algorithms, performance data, security reports, product roadmaps, and pricing; (b) For Customer: Any Customer Data or other technical or business information that Customer discloses to ThreatModeler in the course of receiving Support Services; (c) For Both Parties: The terms and conditions of this Agreement and all Order Forms. "Confidential Information" does not include any information that: (i) is or becomes generally known to the public without breach of any obligation owed to the Disclosing Party; (ii) was known to the Receiving Party prior to its disclosure by the Disclosing Party without breach of any obligation; (iii) is received from a third party without breach of any obligation; or (iv) was independently developed by the Receiving Party without use of or reference to the Disclosing Party's Confidential Information.
1.4. "Customer Data" means any proprietary information, data, content, code, models, diagrams, or materials uploaded, submitted, or inputted into the Software by Customer or its Authorized Users ("Inputs"). For the avoidance of doubt, Customer Data does not include any threat libraries, security controls, templates, rules, or threat modeling intelligence pre-existing within or generated by the Software ("ThreatModeler Content").
1.5. "Documentation" means ThreatModeler's official, generally available technical and functional documentation for the applicable Product, as made available on ThreatModeler's support portal or other designated website. For the avoidance of doubt, "Documentation" specifically excludes any and all marketing materials, websites, press releases, proposals, or non-technical blog posts, and shall not be construed as a warranty or commitment for the development or delivery of any future functionality or features.
1.6. "Feedback" means any suggestion, enhancement request, recommendation, correction, or other feedback provided by Customer or its Authorized Users relating to the operation or functionality of the Product.
1.7. "Intellectual Property Rights" means any and all registered and unregistered rights granted, applied for, or otherwise now or hereafter in existence under or related to any patent, copyright, trademark, trade secret, database protection, or other intellectual property law, and all similar or equivalent rights or forms of protection, in any part of the world. This includes, without limitation: (a) all rights in and to inventions (whether patentable or not), discoveries, and improvements; (b) all rights in and to works of authorship, including copyrights, mask work rights, and moral rights; (c) all rights in and to trade names, logos, trademarks, and service marks (together with all of the goodwill associated therewith); (d) all rights in and to confidential information, know-how, and trade secrets; and (e) all rights in and to domain names, website designs, and user interface designs.
1.8. "License Term" means the initial term for the Software license as specified in an Order, and any subsequent renewal terms.
1.9. "Order" means the binding transactional document for the purchase of Products. An Order is formed when: (a) Customer executes a "Quote" or "Order Form" issued by ThreatModeler; (b) Customer completes an online purchase or registration process through ThreatModeler's website; or (c) ThreatModeler accepts, in writing or by beginning performance, a "Purchase Order" or "PO" issued by Customer against a valid Quote. A PO issued by Customer becomes a binding Order only upon ThreatModeler's written acceptance. For the avoidance of doubt, any Purchase Order issued by Customer is accepted by ThreatModeler solely for the purpose of administrative convenience, invoicing, and billing; any pre-printed, standard, or conflicting terms and conditions contained in or attached to such Customer-issued PO are hereby expressly rejected by ThreatModeler and shall be null, void, and of no legal force or effect, as set forth in Section 14.12.
1.10. "Product(s)" means the Software and any related Support Services purchased by Customer as identified in an applicable Order.
1.11. "Professional Services" means expert services provided by ThreatModeler to Customer, which are separate from the licensed Software and are governed by a Statement of Work ("SOW"). Professional Services are purchased on a project or time-and-materials basis and may include, but are not limited to, implementation assistance, system configuration, dedicated training, and custom content or report creation. Unless otherwise expressly agreed in a SOW, all Professional Services are provided on a non-"work-for-hire" basis. All intellectual property rights in any deliverables, tools, or methodologies used or created by ThreatModeler in the course of providing Professional Services shall remain the exclusive property of ThreatModeler, subject to the limited license rights granted to Customer in the applicable SOW or Section 13.4 of this Agreement. The successful delivery of Professional Services is dependent on Customer's timely cooperation and fulfillment of its responsibilities as outlined in the applicable SOW.
1.12. "Scope of Use" means the specific usage limits, tiers, and metrics for the purchased Software license, as expressly set forth in the applicable Order. Common metrics include, but are not limited to, the number of Authorized Users and the number of Threat Models. Customer's use of the Software must not exceed the Scope of Use.
1.13. "Support Services" means the technical support and maintenance services, including access to Updates, provided by ThreatModeler for the Software. The specific scope, service levels, and commitments for the Support Services are detailed in the Support Services Policy, the current version of which is located at threatmodeler.ai/legal/support-program.
1.14. "Third-Party Code" means any code or libraries, including open source software, that are not proprietary to ThreatModeler and are included in or distributed with the Software.
1.15. "Updates" means any bug fixes, patches, maintenance releases, or new versions of the Software (including both minor and major releases) that ThreatModeler makes generally available, at no additional cost, to its customers with an active Support Services subscription.
2. LICENSE, DELIVERY AND SUPPORT
2.1. License Grant and Scope. Subject to Customer’s full and timely payment of all applicable fees and its continuous compliance with this Agreement, ThreatModeler grants Customer a non-exclusive, non-sublicensable, and non-transferable License, solely in Object Code format, to install, execute, and use the Software during the applicable License Term. The Software is licensed based on the metrics specified in the Order (e.g., number of Authorized Users). This License permits installation and use on servers owned or controlled by Customer, or by its authorized third-party service provider, solely for Customer's internal business purposes and strictly within the Scope of Use. Customer shall not use the Software beyond the specific capacity or licensing units defined in the applicable Order.
2.2. Delivery. ThreatModeler will make the Software available to Customer for electronic download from a designated repository. Delivery shall be deemed complete when ThreatModeler provides Customer with the necessary access credentials and any applicable license keys ("Delivery").
2.3. Acceptance. Customer shall have ten (10) business days from Delivery to test the Software and notify ThreatModeler in writing of any material non-conformity with the Documentation ("Acceptance Period"). The Software will be deemed accepted if Customer: (a) provides written notice of acceptance; (b) uses the Software in a production environment; or (c) fails to provide a written notice of non-conformity within the Acceptance Period. If Customer provides a timely notice of non-conformity, ThreatModeler shall use commercially reasonable efforts to correct it, as described in Section 9.2 of this Agreement.
2.4. Support and Maintenance. ThreatModeler will provide technical support and maintenance for the Software in accordance with the Support Services Policy, the current version of which is located at threatmodeler.ai/legal/support-program (or a successor URL). The Support Services Policy is hereby incorporated by reference into this Agreement. ThreatModeler reserves the right to update the Support Services Policy from time to time, provided that any such update will not result in a material diminution of the Support Services commitments during Customer's then-current License Term.
2.5. Customer Modifications. The Software may enable modification of its functionality through its rules engine or customized content (“Customer Modifications”). Customer may use such Modifications solely with its own instances of the Software. Notwithstanding anything to the contrary, ThreatModeler provides no support, warranty, indemnification, or other liability with respect to Customer Modifications. Customer agrees to indemnify, defend, and hold ThreatModeler harmless from any claim arising out of or related to Customer Modifications.
2.6. Third-Party Code. The Software includes Third-Party Code. The license terms applicable to such Third-Party Code may prevail over this Agreement with respect to that specific component. A list of material Third-Party Code and their applicable licenses is available in the Documentation.
2.7. Backup and Disaster Recovery Licenses. Customer may make one (1) archival copy of the Software solely for back-up or cold disaster recovery purposes, provided that Customer reproduces all copyright and other proprietary notices on such copy. Customer agrees that any such disaster recovery copy shall remain inactive (i.e., not executing or processing data) and may only be activated in the event of, and for the duration of, a primary server outage. Installation of the Software on any Staging, Development, or non-production environment other than a cold backup requires the purchase of additional licenses or a separate non-production order.
3. ACCEPTABLE USE AND CUSTOMER OBLIGATIONS
3.1. General Responsibilities. Customer is and shall remain solely responsible and liable for:
(a) Authorized User Conduct: All activities conducted by its Authorized Users within the Software, and for ensuring their compliance with the terms of this Agreement.
(b) Customer Data: The accuracy, legality, quality, and integrity of all Customer Data, including obtaining all necessary rights and consents for Customer to use and process the Customer Data with the Software.
(c) Environment and System Security: Maintaining the security and integrity of the Customer's own IT environment where the Software is installed, including securing all networks, servers, operating systems, and access credentials.
(d) Compliance with Laws: Ensuring that its use of the Software complies with all applicable local, state, federal, and international laws and regulations.
(e) Use of Current Version. Upon the release of an Update, Customer agrees to use commercially reasonable efforts to install and operate on the latest version of the Software made available to it. ThreatModeler's support obligations may be limited if Customer is operating on a version other than the two most current major releases, as further detailed in the Support Services Policy.
3.2. Use Restrictions. Customer shall not, and shall not permit any Authorized User or any third party to, perform any of the following actions:
(a) Sell, resell, lease, sublicense, or otherwise provide access to the Software to any third party.
(b) Modify, translate, adapt, or create derivative works based upon the Software, except as expressly permitted in this Agreement.
(c) Reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code or non-public APIs of the Software, except to the extent such a restriction is expressly prohibited by applicable law.
(d) Interfere with, disrupt, or create an undue burden on the integrity, performance, or security of the Software.
(e) Conduct any security assessments, penetration tests, or vulnerability scans on the Software itself in a manner that could constitute reverse engineering or an attempt to discover non-public vulnerabilities, without the prior express written consent of ThreatModeler. This restriction does not limit Customer's right to conduct security testing on its own underlying infrastructure.
(f) Use the Software to store or transmit any viruses, worms, or other malicious code.
(g) Use the Software to store or transmit any content that is infringing, libelous, or otherwise unlawful, or that violates the privacy or intellectual property rights of any third party.
(h) Publicly disseminate any performance information or competitive benchmarks of the Software without ThreatModeler's prior written consent.
(i) Attempt to circumvent any Scope of Use restrictions or other license control mechanisms within the Software.
(j) Multiplexing and Pooling: Use any technology, software, script, or automated agent to pool connections, redirect requests, or "multiplex" access to the Software in a manner that bypasses the Authorized User license limits, or allows unlicensed individuals to indirectly access, query, or utilize the Software's functionalities.
3.3. High-Risk Activities Prohibition. The Product is not designed, manufactured, or intended for use in hazardous environments requiring fail-safe performance, including but not limited to the operation of nuclear facilities, aircraft navigation or communication systems, air traffic control, direct life-support machines, or weapons systems ("High-Risk Activities"). Customer expressly agrees that it will not use, or permit the use of, the Product for any High-Risk Activities. ThreatModeler and its suppliers expressly disclaim any express or implied warranty of fitness for such purposes.
3.4. Prohibition on Transferring Sensitive Personal Information to ThreatModeler. Customer agrees that it shall not transfer, disclose, or otherwise make available to ThreatModeler (including in support tickets, logs, database dumps, or emails) any "Sensitive Data." Customer acknowledges that the Product and Support Services are not designed for such data, and ThreatModeler has no liability for any Sensitive Data received in violation of this section. "Sensitive Data" includes any data that requires heightened protection under applicable law, including, but not limited to, health information (HIPAA), financial information (GLBA, PCI DSS), government-issued IDs, and "special categories of personal data" under GDPR. Customer shall indemnify, defend, and hold harmless ThreatModeler from any damages, losses, and costs arising from or related to Customer's breach of this Section 3.4.
3.5. Infrastructure and Environment Disclaimer. Customer acknowledges and agrees that the Software is installed and operated within Customer’s own IT environment and infrastructure, which is entirely outside of ThreatModeler’s control. ThreatModeler shall have no liability, obligation, or responsibility whatsoever for: (a) any service interruptions, performance degradation, data loss, or failures of the Software caused by or resulting from Customer’s hardware, servers, local databases, operating systems, or internal network configurations; or (b) any security breaches, unauthorized access, or data exfiltration occurring within Customer’s local IT environment, unless such security incident is directly and solely caused by a documented, unpatched, and material vulnerability inherent in the Software as delivered by ThreatModeler.
4. FEES, PAYMENT, AND AUDITS
4.1. Fees. Customer shall pay all fees specified in all applicable Orders ("Fees"). Except as expressly provided in this Agreement, all payment obligations are non-cancellable and all Fees paid are non-refundable. The Fees are based on the Product license purchased and not on actual usage.
4.2. Invoicing and Payment. Unless otherwise specified in an Order Form, all Fees will be invoiced annually in advance. All invoices are due and payable net thirty (30) days from the invoice date, without offset or deduction. Late payments will accrue interest at the statutory late payment interest rate applicable under European commercial transaction regulations (specifically including Spanish Law 3/2004 on Morosidad), plus any legally permitted recovery costs.
4.3. Taxes.
a) Fees are stated exclusive of any taxes, levies, duties, or similar governmental assessments, including value-added, sales, use, or withholding taxes (collectively, "Taxes"). Customer is responsible for paying all Taxes associated with its purchases hereunder.
b) If ThreatModeler has the legal obligation to pay or collect Taxes for which Customer is responsible, the appropriate amount shall be invoiced to and paid by Customer, unless Customer provides ThreatModeler with a valid tax exemption certificate.
c) If Customer is required by law to withhold any Taxes from its payments to ThreatModeler, Customer must provide ThreatModeler with an official tax receipt or other appropriate documentation. Customer agrees to increase the payment to ThreatModeler by the amount necessary to ensure that ThreatModeler receives a net amount equal to the full amount of the Fees it would have received without the deduction.
4.4. Suspension of Support and Termination for Non-Payment. If any invoiced amount is more than thirty (30) days overdue, ThreatModeler may, without limiting its other rights and remedies: (a) suspend the provision of Support Services upon ten (10) days' written notice until such amounts are paid in full, and (b) if the failure to pay continues for sixty (60) days or more, terminate this Agreement for cause. Customer's License to use the Software is immediately revoked, and Customer must comply with the deinstallation requirements in Section 5.5
4.5. Invoice Disputes. Customer must notify ThreatModeler in writing of any good-faith dispute with respect to an invoice within fifteen (15) days of the invoice date. If Customer fails to do so, Customer is deemed to have waived its right to dispute that invoice, and the invoice will be considered final and payable.
4.6. Usage Verification and Audit Rights.
(a) Usage Reports. Upon ThreatModeler’s reasonable written request (no more than twice per calendar year), Customer shall promptly (and in any event within ten (10) business days) extract and provide to ThreatModeler a system-generated usage report or screenshot from the Software's administrative console showing the active number of Authorized Users and Threat Models, to verify compliance with the Scope of Use.
(b) Audit. In the event Customer fails to provide such usage reports, or if ThreatModeler has a reasonable, documented suspicion of over-usage, ThreatModeler (or its designated independent third-party auditor subject to strict confidentiality) may, upon thirty (30) days' prior written notice, audit Customer's use of the Software. Such audit shall be conducted during normal business hours, at Customer's facilities, and shall not unreasonably interfere with Customer's business.
(c) Overages. If any verification or audit reveals that Customer has exceeded its Scope of Use, ThreatModeler will invoice Customer for such overage at ThreatModeler's then-current list prices for the entire period of non-compliance. If the underpayment exceeds five percent (5%) of the fees payable during the audited period, Customer shall also pay the reasonable costs of the audit.
5. TERM AND TERMINATION
5.1. Agreement Term. The term of this Agreement commences on the Effective Date and continues as long as a License Term for any Software is in effect, unless terminated earlier in accordance with its terms.
5.2. License Term and Auto-Renewal. Each License Term will automatically renew for additional periods equal to the expiring term (or one year, if the expiring term is longer than one year), unless either party gives the other written notice of non-renewal at least sixty (60) days before the end of the then-current License Term. ThreatModeler reserves the right to increase the fees for any renewal term by providing notice thereof at least seventy-five (75) days prior to the end of the current term.
5.3. Termination for Cause. A party may terminate this Agreement for cause: (i) upon thirty (30) days' written notice to the other party of a material breach if such breach remains uncured at the expiration of such period, or (ii) if the other party becomes the subject of a petition in bankruptcy or any other proceeding relating to insolvency. If Customer terminates for cause due to ThreatModeler's uncured material breach, ThreatModeler will provide a pro-rata refund of any prepaid fees for the remainder of the terminated License Term.
5.4. Termination for Convenience by Customer. Customer may terminate this Agreement for its convenience at any time by providing ninety (90) days' prior written notice to ThreatModeler. Upon such termination, Customer shall not be entitled to any refund, credit, or pro-rata return of any Fees paid upfront (as all payment obligations are non-cancellable under Section 4.1). All unpaid Fees associated with the remaining duration of the committed License Term shall become immediately due and payable upon the effective date of such termination.
5.5. Effect of Termination. Upon any termination or expiration of this Agreement: (a) all Licenses granted to Customer hereunder shall immediately terminate; (b) Customer shall immediately cease all use of the Software, uninstall it from all systems, and destroy all copies of the Software in its possession or control; (c) Customer shall immediately pay any unpaid fees accrued prior to the effective date of termination; and (d) each party will, upon request, promptly return or securely destroy all Confidential Information of the other party. Customer shall provide written certification of its compliance with subsection (b) within ten (10) business days of ThreatModeler's request.
5.6. 30-Day Return Policy. As part of our commitment to customer satisfaction, Customer may terminate the initial Order for the Software for any reason within thirty (30) days of the initial Delivery date. To exercise this right, Customer must provide written notice of termination and certify its compliance with the "Effect of Termination" clause (Section 5.5). Upon receipt, ThreatModeler will provide a full refund of the license fees paid for the returned Software. This return right applies only to the initial purchase and not to any renewals or subsequent purchases.
5.7. Survival. The provisions of this Agreement which by their nature should survive termination or expiration shall remain in effect, including: Section 1 (Definitions), Section 4 (Fees, Payment, and Audits), Section 5.5 (Effect of Termination), Section 5.7 (Survival), Section 6 (Data Protection and Security), Section 7 (Confidentiality), Section 8 (Intellectual Property Rights), Section 9.4 (Warranty Disclaimer), Section 10 (Indemnification), Section 11 (Limitation of Liability), and Section 14 (General Provisions).
5.8. Reinstatement of Lapsed Support. If Customer’s subscription for Support Services expires or is terminated, and Customer seeks to reinstate such services at a later date, such reinstatement shall be subject to ThreatModeler's then-current policies. At a minimum, reinstatement may require Customer to pay: (a) a reinstatement fee; (b) all Support Services fees that would have been payable during the period of the lapse; and (c) the Support Services fees for the new term.
6. DATA PROTECTION AND SECURITY
6.1. Roles of the Parties.
(a) Regarding the Licensed Software: Customer acknowledges and agrees that because the Software is installed and operated entirely within Customer's own IT environment, Customer is the sole Data Controller for all Personal Data processed by the Software. Customer is exclusively responsible for its compliance with applicable data protection laws, including the EU General Data Protection Regulation 2016/679 and the UK GDPR ("Data Protection Law").
(b) Regarding Incidental Processing: In the limited circumstances where ThreatModeler has access to Personal Data as described in Section 6.3, ThreatModeler shall act as a Data Processor on behalf of the Customer.
6.2. ThreatModeler's Limited Obligations as a Software Licensor. ThreatModeler's primary role is strictly that of a software licensor. With respect to the standard operation of the licensed Software, ThreatModeler has no access to, and does not Process, any Personal Data. ThreatModeler warrants that the Software, as delivered, contains no malicious code designed to exfiltrate Personal Data.
6.3. ThreatModeler's Obligations as an Incidental Data Processor. In the event Customer discloses Personal Data to ThreatModeler in the course of receiving Support Services or Professional Services, ThreatModeler, in its role as a Data Processor, commits to:
(a) Purpose Limitation: Process such Personal Data solely for the specific purpose of providing the requested services and in accordance with Customer's lawful instructions.
(b) Confidentiality: Ensure that its personnel authorized to access the Personal Data are bound by strict confidentiality obligations.
(c) Security Measures: Implement and maintain appropriate technical and organizational measures (TOMs) to protect the Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
(d) Sub-processing: Customer grants ThreatModeler a general written authorization to engage third-party subprocessors in connection with the provision of Support and Professional Services. ThreatModeler's current subprocessor list is maintained online. ThreatModeler shall ensure that any subprocessor is bound by data protection obligations at least as protective as those in this Section 6.
(e) Data Subject Rights: To the extent legally permitted, provide reasonable assistance to Customer to enable Customer to respond to requests from individuals exercising their rights under Data Protection Law (e.g., rights of access, rectification, or erasure).
(f) Sanitization and Deletion. Customer shall use commercially reasonable efforts to de-identify, obfuscate, or anonymize any Personal Data or confidential information contained within any log files, database dumps, or support tickets before transferring such materials to ThreatModeler. ThreatModeler will securely delete any such incidental Personal Data from its systems upon the completion of the specific support or professional service for which it was provided
6.4. International Data Transfers. The parties agree that any transfer of Personal Data from the European Economic Area (EEA), Switzerland, or the United Kingdom to ThreatModeler in a country outside of these regions for the purpose of receiving Support or Professional Services shall be governed by the Standard Contractual Clauses ("SCCs"), which shall be deemed incorporated by reference into this Agreement. For the purposes of the SCCs, Customer shall be the "data exporter" and ThreatModeler shall be the "data importer".
6.5. Customer's Security Responsibilities. Customer is solely responsible for the security of its own IT infrastructure and all Personal Data stored and processed within it. ThreatModeler has no liability for any data breach or compliance failure occurring within Customer's environment.
7. CONFIDENTIALITY
7.1. Obligation of Confidentiality. The Receiving Party shall:
(a) use the same degree of care that it uses to protect the confidentiality of its own confidential information of like kind (but in no event less than a reasonable degree of care);
(b) not use any Confidential Information of the Disclosing Party for any purpose outside the scope of this Agreement; and
(c) except as otherwise authorized by the Disclosing Party in writing, limit access to Confidential Information to those of its and its Affiliates’ employees, contractors, and agents who have a legitimate "need to know" for purposes consistent with this Agreement and who are bound by confidentiality obligations containing protections no less stringent than those herein. The Receiving Party shall be liable for any breach of this Section 7 by its representatives.
7.2. Compelled Disclosure. A Receiving Party may disclose Confidential Information of the Disclosing Party to the extent compelled by law or a valid court order to do so, provided the Receiving Party gives the Disclosing Party prior written notice of the compelled disclosure (to the extent legally permitted) and reasonable assistance, at the Disclosing Party's cost, if the Disclosing Party wishes to contest or seek a protective order for the disclosure.
7.3. Equitable Relief. The parties agree that a breach of this Section 7 may cause irreparable harm for which monetary damages would not be an adequate remedy. Accordingly, the Disclosing Party shall be entitled to seek injunctive or other equitable relief (such as medidas cautelares in a civil law jurisdiction) to prevent or curtail any such breach.
7.4. Term of Confidentiality. The obligations of confidentiality, non-disclosure, and non-use set forth in this Section 7 shall survive the expiration or termination of this Agreement for a period of five (5) years. Notwithstanding the foregoing, with respect to any Confidential Information of either party that constitutes a "trade secret" or "secreto industrial" under applicable law (including ThreatModeler’s Software, Object Code, threat libraries, algorithms, schemas, and technology), such obligations of confidentiality and non-use shall survive the expiration or termination of this Agreement perpetually for as long as such information remains a trade secret.
8. INTELLECTUAL PROPERTY RIGHTS
8.1. ThreatModeler's Intellectual Property. As between the Parties, ThreatModeler and its licensors exclusively own and retain all right, title, and interest in and to the Product, including the Software (exclusively in Object Code format), all threat libraries, security controls, templates, rules, threat modeling intelligence, the platform's user interfaces, and all generated threat models, reports, security requirements, and outputs (collectively, "Outputs"). ThreatModeler exclusively owns all Intellectual Property Rights in any of the foregoing.
Subject to Customer's full and timely payment of all Fees, ThreatModeler hereby grants Customer, during the applicable License Term, a non-exclusive, non-transferable, non-sublicensable, and limited license to use, copy, and distribute the Outputs solely for Customer's internal business and compliance purposes, provided that Customer shall retain all rights in its proprietary Inputs contained within such Outputs.
Customer explicitly acknowledges and agrees that: (a) this Agreement grants a limited License, not a sale; (b) no rights or licenses to the Source Code of the Software are granted hereunder; and (c) all rights not expressly granted to Customer are reserved exclusively by ThreatModeler.
8.2. Customer's Intellectual Property. As between the Parties, Customer exclusively owns and retains all right, title, and interest in and to the Customer Data (including all proprietary Inputs uploaded into the Software) and all Intellectual Property Rights therein.
8.3. Ownership and Assignment of Feedback. Customer agrees that any suggestions, enhancement requests, recommendations, corrections, or other feedback provided by Customer or its Authorized Users relating to the operation or functionality of the Software ("Feedback") shall be owned exclusively by ThreatModeler. Customer hereby irrevocably, perpetually, and without restriction assigns to ThreatModeler all worldwide right, title, and interest (including all Intellectual Property Rights and exploitation rights) in and to such Feedback, without any right to royalty, compensation, or moral rights claims. ThreatModeler is free to use and implement any Feedback without restriction or confidentiality obligation.
8.4. License for Support and Professional Services. In the event that Customer provides ThreatModeler with access to any Customer Data in the course of receiving Support Services or Professional Services (including via database backups, logs, or diagnostic materials), Customer grants ThreatModeler a temporary, non-exclusive, royalty-free, worldwide license to host, use, and process such data solely to diagnose and resolve the support incident or perform the services. Customer represents and warrants that all such transferred materials have been sanitized and de-identified in accordance with Section 6.3(f). This license terminates automatically upon the resolution of the incident or completion of the services.
8.5. Protection of Proprietary Markings. Customer shall not, and shall not permit any third party to, remove, alter, cover, or obscure any patent, copyright, trademark, trade secret, or other proprietary rights notices or legends placed on or contained within the Software, the Documentation, or any generated Outputs (including generated PDFs or threat model reports).
8.6. API and Integration Intellectual Property. To the extent that Customer develops any custom connectors, scripts, wrappers, or software integrations designed to connect Customer’s internal tools to the Software via ThreatModeler’s APIs or the Model Context Protocol (MCP) Server (collectively, "Integrations"), Customer shall retain ownership of its custom code for such Integrations. However, Customer acknowledges and agrees that: (a) such Integrations shall not create any joint intellectual property rights; (b) ThreatModeler retains exclusive ownership of the underlying APIs, the MCP Server technology, and platform architecture; and (c) nothing in this Agreement shall restrict ThreatModeler from independently developing, licensing, or commercializing similar integrations or features for its other customers.
9. WARRANTIES AND DISCLAIMERS
9.1. Mutual Warranties. Each party represents and warrants that it has the legal power and authority to enter into this Agreement.
9.2. Limited Software Warranty. ThreatModeler warrants that, for a period of ninety (90) days from the date of Delivery, the Software will perform materially in accordance with the applicable Documentation ("Warranty Period"). For any breach of this warranty reported by Customer during the Warranty Period, Customer's sole and exclusive remedy, and ThreatModeler's entire liability, will be for ThreatModeler, at its option, to: (a) use commercially reasonable efforts to correct the non-conformity; or (b) provide a replacement of the non-conforming Software.
9.3. Professional Services Warranty. ThreatModeler warrants that any Professional Services will be performed in a professional and workmanlike manner. Customer's remedy for a breach of this warranty is to notify ThreatModeler in writing within thirty (30) days of the non-conforming service, in which case ThreatModeler will re-perform the deficient services at no additional cost.
9.4. WARRANTY DISCLAIMER. EXCEPT FOR THE EXPRESS WARRANTIES PROVIDED IN THIS SECTION 9, AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SOFTWARE AND ANY PROFESSIONAL SERVICES ARE PROVIDED "AS IS". THREATMODELER AND ITS SUPPLIERS EXPRESSLY DISCLAIM ALL OTHER WARRANTIES, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. CUSTOMER ACKNOWLEDGES AND AGREES THAT ANY AI-GENERATED OUTPUTS, SUGGESTIONS, OR RECOMMENDATIONS FROM OPTIONAL AI-ASSISTED FUNCTIONALITY ARE PROVIDED FOR INFORMATIONAL PURPOSES ONLY, AND ARE GOVERNED SOLELY BY SECTION 12.4 OF THIS AGREEMENT. THREATMODELER DOES NOT WARRANT THAT THE USE OF THE SOFTWARE WILL BE UNINTERRUPTED OR ERROR-FREE, OR THAT ALL DEFECTS CAN BE CORRECTED.
10. INDEMNIFICATION
10.1. Indemnification by ThreatModeler. ThreatModeler will defend Customer against any third-party claim, demand, suit, or proceeding ("Claim") alleging that Customer's use of the Software, as delivered by ThreatModeler and used in accordance with this Agreement, , directly infringes a valid EU patent, copyright, or registered trademark of such third party. ThreatModeler will indemnify Customer for any damages, attorney fees, and costs finally awarded against Customer as a result of, or for amounts paid by Customer under a court-approved settlement of, such a Claim.
10.2. Mitigation and Remedy. If the Software becomes, or in ThreatModeler's opinion is likely to become, the subject of an infringement Claim, ThreatModeler may, at its option and expense:
(a) procure for Customer the right to continue using the Software;
(b) replace or modify the Software with a non-infringing but functionally equivalent alternative; or
(c) if options (a) and (b) are not commercially reasonable, terminate Customer's License for the infringing Software and provide a refund of the license fees paid for that Software, depreciated on a straight-line basis over a three (3) year useful life.
10.3. Exclusions. ThreatModeler's obligations under Section 10.1 will not apply to any Claim to the extent it arises from: (a) use of the Software in combination with hardware, software, or data not provided by ThreatModeler; (b) Customer Data; (c) any modification to the Software not made by ThreatModeler; or (d) Customer's use of a version of the Software other than the then-current version, if the infringement would have been avoided by use of the current version made available to Customer.
10.4. Indemnification by Customer. Customer will defend ThreatModeler against any Claim made or brought against ThreatModeler by a third party arising from or related to: (i) the Customer Data, including any allegation that the Customer Data infringes or misappropriates the rights of a third party; (ii) Customer’s use of the Software in breach of this Agreement or applicable law; or (iii) any Customer Modifications (as described in Section 2.5). Customer will indemnify ThreatModeler for any damages, attorney fees, and costs finally awarded against ThreatModeler as a result of, or for amounts paid by ThreatModeler under a court-approved settlement of, such a Claim.
10.5. Indemnification Procedure. The indemnifying party's obligations are contingent upon the indemnified party: (a) promptly giving written notice of the Claim; (b) giving the indemnifying party sole control of the defense and settlement of the Claim (provided that the indemnifying party may not settle any Claim unless it unconditionally releases the indemnified party of all liability); and (c) providing all reasonable assistance, at the indemnifying party's expense.
10.6. Exclusive Remedy. This Section 10 states the indemnifying party's sole liability to, and the indemnified party's exclusive remedy against, the other party for any type of third-party infringement claim described in this section.
11. LIMITATION OF LIABILITY
11.1. DISCLAIMER OF INDIRECT AND CONSEQUENTIAL DAMAGES.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL EITHER PARTY OR ITS SUPPLIERS HAVE ANY LIABILITY TO THE OTHER PARTY FOR ANY LOST PROFITS, LOST DATA, LOSS OF USE, BUSINESS INTERRUPTION, COSTS OF PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES, OR FOR ANY INDIRECT, SPECIAL, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES, HOWEVER CAUSED AND, WHETHER IN CONTRACT, TORT OR UNDER ANY OTHER THEORY OF LIABILITY, AND WHETHER OR NOT THE PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
11.2. LIMITATION OF AGGREGATE LIABILITY.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL EITHER PARTY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT, WHETHER IN CONTRACT, TORT OR UNDER ANY OTHER THEORY OF LIABILITY, EXCEED THE TOTAL AMOUNT OF FEES ACTUALLY PAID BY CUSTOMER TO THREATMODELER HEREUNDER IN THE TWELVE (12) MONTHS PRECEDING THE DATE OF THE FIRST INCIDENT GIVING RISE TO THE LIABILITY.
11.3. EXCLUSIONS FROM LIMITATIONS ("UNLIMITED LIABILITY CARVE-OUTS").
THE LIMITATIONS SET FORTH IN SECTIONS 11.1 AND 11.2 SHALL NOT APPLY TO:
(a) A PARTY'S INDEMNIFICATION OBLIGATIONS UNDER SECTION 10;
(b) A BREACH OF CONFIDENTIALITY OBLIGATIONS UNDER SECTION 7;
(c) A VIOLATION OF THE OTHER PARTY'S INTELLECTUAL PROPERTY RIGHTS;
(d) CUSTOMER'S UNPAID PAYMENT OBLIGATIONS FOR FEES DUE UNDER ANY ORDER FORM; OR
(e) LIABILITY ARISING FROM A PARTY'S GROSS NEGLIGENCE, WILLFUL MISCONDUCT, OR FRAUD.
11.4. Allocation of Risk. The parties acknowledge and agree that the essential purpose of this Section 11 is to allocate the risks under this Agreement between the parties and that the fees have been set and this Agreement entered into in reliance upon these limitations of liability.
12. OPTIONAL AI-ASSISTED FUNCTIONALITY
12.1. General. The Software may include optional features that can connect to third-party generative artificial intelligence services ("AI Features". The use of any AI Feature is at Customer's sole discretion and requires Customer to configure and enable such features within its on-premise installation of the Software.
12.2. Data Transmission and Processing. Customer acknowledges and agrees that when an AI Feature is enabled, the Software will transmit certain Customer Data (Inputs) directly from Customer's own IT environment to the API of the applicable third-party AI service provider. The resulting output ("Output") is then returned directly to the Software within Customer's environment. At no point during this process does ThreatModeler receive, process, store, or have access to the Customer Data (Inputs) or the Outputs generated by the AI Features.
12.3. Customer's Sole Responsibility. Customer is solely and exclusively responsible for its use of any AI Feature. This responsibility includes:
(a) Deciding which AI Features to enable and use.
(b) Its relationship with any third-party AI service provider, including compliance with that provider's terms of service and privacy policies. If an AI Feature connects to a provider designated by ThreatModeler (e.g., Azure OpenAI), Customer is responsible for reviewing and accepting that provider's terms before use.
(c) The content of any Customer Data (Inputs) provided to an AI Feature, including ensuring that no Sensitive Data (as defined in Section 3.4) is transmitted to any third-party AI service provider.
12.4. AI OUTPUT DISCLAIMER. ALL OUTPUTS GENERATED BY ANY AI FEATURE ARE PROVIDED "AS IS," WITHOUT WARRANTY OF ANY KIND]. OUTPUTS ARE GENERATED BY THIRD-PARTY SYSTEMS OUTSIDE OF THREATMODELER'S CONTROL. CUSTOMER IS SOLELY RESPONSIBLE FOR REVIEWING, VALIDATING, AND ENSURING THE ACCURACY, SECURITY, AND APPROPRIATENESS OF ANY AI-GENERATED OUTPUT BEFORE ANY USE OR RELIANCE THEREON. THREATMODELER SHALL HAVE NO LIABILITY WHATSOEVER ARISING FROM OR RELATED TO CUSTOMER'S USE OF AI FEATURES.
13. PROFESSIONAL SERVICES
13.1. Scope and Governance. ThreatModeler will provide Customer with the Professional Services, if any, as described in one or more mutually executed Statements of Work ("SOWs"). Each SOW is hereby incorporated by reference into this Agreement. In the event of a direct conflict between the terms of a SOW and this Agreement, the terms of this Agreement shall prevail, unless the SOW expressly identifies the conflicting provision of this Agreement and states its intent to override it for that specific project.
13.2. Performance Warranty. ThreatModeler warrants that all Professional Services will be performed in a professional and workmanlike manner, in all material respects in accordance with the specifications set forth in the applicable SOW. For any breach of this warranty, Customer's sole and exclusive remedy shall be for ThreatModeler, at its option, to either: (a) re-perform the non-conforming Professional Services at no additional charge; or (b) if re-performance is not commercially feasible, terminate the applicable SOW and provide a pro-rata refund of the fees paid for the non-conforming portion of the Professional Services. To receive this remedy, Customer must report the non-conformity in writing within thirty (30) days of the completion of the services.
13.3. Customer Cooperation. Customer acknowledges that the successful and timely delivery of Professional Services requires its good-faith cooperation. ThreatModeler shall not be liable for any delay or failure in performance to the extent caused by Customer's failure to meet its responsibilities.
13.4. Intellectual Property.
(a) ThreatModeler's Pre-Existing IP. ThreatModeler shall retain all right, title, and interest in and to any of its pre-existing tools, methodologies, know-how, and other intellectual property used or provided in the course of performing the Professional Services ("ThreatModeler Background IP").
(b) Deliverables. Upon Customer's payment in full of all applicable fees, any custom reports, configurations, or other deliverables created specifically for Customer as described in a SOW ("Deliverables") are licensed to Customer on a non-exclusive, non-transferable basis for its internal use only with the licensed Software during its active and fully-paid License Term for the underlying Software. ThreatModeler retains ownership of all intellectual property rights in and to the Deliverables.
(c) No Work for Hire. For the avoidance of doubt, all Professional Services are provided on a non-"work-for-hire" basis.
13.5. Personnel and Expenses. Unless otherwise specified in the applicable SOW, Customer will reimburse ThreatModeler for all reasonable, pre-approved travel and out-of-pocket expenses incurred in connection with the provision of Professional Services.
13.6. Customization Requests. Customer may request minor customizations to the Software that fall outside the scope of a formal Statement of Work. ThreatModeler may consider such requests in its sole discretion. Any such work will be treated as Professional Services, quoted separately, and will not be performed until agreed upon in writing by both parties.
14. GENERAL PROVISIONS
14.1. Governing Law, Jurisdiction, and Venue. This Agreement and any disputes arising out of or in connection with it shall be governed by and construed in accordance with the laws of Spain [14.1]. Both parties irrevocably agree to submit to the exclusive jurisdiction of the courts of the city of Madrid, Spain, for the resolution of any such dispute, expressly waiving any other jurisdiction to which they might be entitled. The United Nations Convention on Contracts for the International Sale of Goods does not apply to this Agreement .
14.2. Notices. All notices under this Agreement shall be sent exclusively by email to legal@threatmodeler.com (for ThreatModeler) and to the primary email address specified on the signature page or most recent Order Form (for Customer). Notices are deemed received upon successful transmission, provided no delivery failure is returned. Customer is solely responsible for keeping its email address current and operational.
14.3. Relationship of the Parties. The parties are independent contractors. This Agreement does not create a partnership, franchise, joint venture, agency, fiduciary, or employment relationship between the parties.
14.4. No Third-Party Beneficiaries. This Agreement is for the sole benefit of the parties hereto and their respective successors and permitted assigns and nothing herein, express or implied, is intended to or shall confer upon any other person or entity any legal or equitable right, benefit, or remedy of any nature whatsoever.
14.5. Subcontracting. ThreatModeler may use affiliates or other third-party contractors in the performance of its obligations hereunder, including for the provision of Support Services and Professional Services, provided that ThreatModeler shall remain fully responsible for the performance of any such subcontractor and for their compliance with all terms of this Agreement.
14.6. Assignment. Neither party may assign any of its rights or obligations hereunder, whether by operation of law or otherwise, without the other party's prior written consent (not to be unreasonably withheld). Notwithstanding the foregoing, either party may assign this Agreement in its entirety, without the other party's consent, to its Affiliate or in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of its assets
14.7. Force Majeure. Neither party shall be liable for any failure or delay in performance (except for payment obligations) due to a "Force Majeure Event," meaning causes beyond its reasonable control, including but not limited to acts of God, war, terrorism, riots, strikes, or natural disasters.
14.8. Export Compliance. The Product and related technology may be subject to export control and economic sanctions laws of the United States, the European Union, and other applicable jurisdictions. Customer is solely responsible for complying with all such laws. Customer represents and warrants that it is not a sanctioned party or located in any comprehensively embargoed country, and Customer shall not permit access to or use of the Product in violation of any applicable export control laws.
14.9. Publicity. Neither party shall use the other party's name or logo in any press release, marketing materials, or other public announcement without the other party's prior written consent. However, ThreatModeler may identify Customer by name in its customer lists.
14.10. Severability. If any provision of this Agreement is held by a court of competent jurisdiction to be contrary to law, the provision will be deemed null and void, and the remaining provisions of this Agreement will remain in effect.
14.11. Waiver and No Commercial Agency.
(a) Waiver. No failure or delay by either party in exercising any right under this Agreement will constitute a waiver of that right.
(b) No Commercial Agency. The relationship of the parties is strictly that of independent buyer and seller. This Agreement does not create any commercial agency, franchise, joint venture, or partnership under the laws of Spain or any other jurisdiction. Customer is not entitled to, and expressly waives, any right to claim compensation, damages, or indemnity for loss of goodwill, client portfolio, or prospective profits upon the expiration or termination of this Agreement.
14.12. Entire Agreement, Order of Precedence, and Supremacy.
(a) Entire Agreement. This Agreement, including all policies incorporated by reference, Order Forms, and SOWs, constitutes the entire agreement between the parties regarding its subject matter and supersedes all prior agreements. Amendments must be in a writing signed by both parties.
(b) Order of Precedence. In the event of a conflict, the documents shall control in the following order: (1) this Agreement, (2) the SOW, (3) the Order Form. Notwithstanding the foregoing, a specific provision in an Order Form or SOW may supersede a conflicting provision in this Agreement only if it explicitly identifies the section number it intends to override (e.g., "Notwithstanding Section 11.2 of the Agreement...") and is counter-signed by an authorized representative of ThreatModeler.
(c) Supremacy over Customer Forms. The terms of this Agreement and any ThreatModeler-issued Order Form shall supersede and prevail over any conflicting or additional terms in any Customer-issued purchase order (PO), vendor portal, or other business form. All such Customer terms are hereby rejected, null, and void. ThreatModeler’s delivery of the Product or acceptance of payment shall not be construed as acceptance of Customer's terms, regardless of whether such Customer forms are signed by ThreatModeler.