Partner Master Agreement
Our global channel framework, covering general partnership terms and modular sections for certified Resellers, Distributors, Referral Partners, MSPs, and OEM Partners.
Which region applies to you?
Select North America (NA) if your partner company is located in the United States or Canada. Select International (INT) if your partner company is located anywhere else in the world (such as Europe, UK, APAC, or LATAM).
This Partner Agreement (the “Agreement”) is made and entered into by and between ThreatModeler Software, Inc., a Delaware corporation with offices at 101 Hudson Street, 21st Floor Jersey City, New Jersey 07302, USA (“ThreatModeler”); and the entity identified as “Partner” in an applicable Order Form or that otherwise acts as a partner of ThreatModeler.
This Agreement takes effect on the date of the first-executed partner-specific Order Form, or the date on which Partner first performs any action consistent with a partner role (including, but not limited to, reselling a Product, submitting a referral lead, or distributing the Product), whichever is earlier (the “Effective Date”).
BY EXECUTING AN ORDER THAT REFERENCES THIS AGREEMENT, OR BY ACTING IN ANY PARTNER CAPACITY (E.G., BY RESELLING, DISTRIBUTING, OR REFERRING A LEAD), PARTNER AGREES TO BE LEGALLY BOUND BY THE TERMS AND CONDITIONS OF THIS AGREEMENT.
RECITALS
WHEREAS, ThreatModeler develops, markets, and licenses proprietary threat modeling software and related services; and
WHEREAS, Partner possesses expertise, resources, and relationships in the marketplace and desires to collaborate with ThreatModeler in one or more capacities as selected below.
THEREFORE, in consideration of the mutual covenants contained herein, the Parties agree to the terms and conditions set forth in this Agreement.
1. APPLICABLE PARTNER ROLE(S):
The specific partner role(s) authorized under this Agreement shall be as designated and selected in the applicable executed Order. Only the corresponding terms and conditions set forth in the Special Terms (Sections A through E below) that match the authorized partner role(s) selected in such Order shall apply to and govern the Parties.
| Reseller | Sells ThreatModeler licenses and subscriptions directly to End Users. This Partner owns the customer relationship and commercial transaction. The terms for this role are detailed in Special Terms, Section A. |
| Distributor | Manages a two-tier channel by selling ThreatModeler Products to a network of Resellers. This Partner is responsible for channel enablement, logistics, and management. The terms for this role are detailed in Special Terms, Section B. |
| Referral Partner | Identifies and qualifies potential customers, and introduces these sales leads to the ThreatModeler sales team in exchange for success-based referral fees. The terms for this role are detailed in Special Terms, Section C. |
| MSP / Hosting Partner | Delivers ThreatModeler's capabilities as a managed service. This Partner uses the Products to provide ongoing threat modeling, security, or hosting services to its own customers. The terms for this role are detailed in Special Terms, Section D. |
| Strategic / OEM Partner | Embeds or tightly integrates ThreatModeler's technology into their own proprietary product or service to create a single, unified "Combined Offering" sold under their own brand. The terms for this role are detailed in Special Terms, Section E. |
2. KEY COMMERCIAL TERMS
| Territory: | The authorized geographic country, countries, or region specified as the "Territory" in the applicable executed Order. All rights and licenses granted to Partner under this Agreement are strictly limited to such authorized Territory. |
| Default Currency: | U.S. Dollars (USD) (Unless otherwise specified in the applicable Order) |
| Email for Notices: | For ThreatModeler: legal@threatmodeler.com For Partner: As specified in the applicable Order. |
GENERAL TERMS AND CONDITIONS
1. DEFINITIONS
1.1. "Agreement" means this Partner Agreement, including its cover page, all sections of the General Terms and Conditions, the applicable Special Terms, and all Exhibits, Orders, and any ThreatModeler policies, addenda, or terms incorporated by reference herein (including the EULA and the DPA hosted on ThreatModeler’s website).
1.2 "Combined Offering" means (a) For MSP: The Product(s) managed and delivered by Partner as an integrated managed service in combination with Partner Separate Products or services to multiple End Users, as governed by Special Terms, Section D; and (b) For OEM: The Product(s) integrated, embedded, or bundled by Partner with the Partner Separate Product as a single, inseparable, unified commercial solution marketed and licensed to End Users under Partner’s brand, as governed by Special Terms, Section E.
1.3 "Documentation" means the official user manuals, technical specifications, and other explanatory materials provided by ThreatModeler for the Products, in any format, which are designed to instruct End Users and Partners in the installation, operation, and use of the Products.
1.4 “End User” means the final legal entity or individual that acquires, accesses, or otherwise uses the Products (including as part of a Combined Offering) for its own internal business purposes. An End User has no right to resell, sublicense, or further distribute the Products to any third party.
1.5 "End User License Agreement" or “EULA” means ThreatModeler's then-current standard end-user license agreement, the terms of which are located at threatmodeler.ai/legal/eula (or such other URL as ThreatModeler may provide from time to time). This includes, but is not limited to, specific versions for commercial entities, U.S. Federal Government entities (containing applicable FAR/DFARS clauses), and other governmental bodies.
1.6 “Fees” means the net amounts payable by Partner to ThreatModeler for the purchase of Products, or the commissions payable by ThreatModeler to Partner, as applicable to the Partner's role. The final, binding Fees for any given transaction are those specified in the corresponding Order. For clarity, Fees are calculated after the application of any discounts and do not include any taxes, duties, shipping costs, or other pass-through charges, which are the sole responsibility of the Partner.
1.7 “Government End User” means any central, regional or local government department, agency or entity performing governmental functions, and which is not headquartered in Australia, Austria, Belgium, Canada, Czech Republic, Denmark, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Japan, Luxembourg, the Netherlands, Norway, New Zealand, Poland, Portugal, Spain, Sweden, Switzerland, Turkey, the United Kingdom or the United States. This definition includes any international governmental organizations as well as any governmental research institutions, governmental corporations or their separate business units that are (a) not headquartered in the countries named above, and (b) engaged in the manufacture or distribution of items or services controlled on the Wassenaar Munitions List.
1.8. "Order(s)" means the final, binding transactional document for a specific purchase, which may take the form of: (a) a ThreatModeler-issued Quote that has been executed by the Partner and accepted by ThreatModeler; (b) a formal Order Form executed by both Parties; or (c) a Partner-issued Purchase Order (PO) that has been explicitly accepted by ThreatModeler in writing or fulfilled via Electronic Delivery.
1.9. "Order Form" means a ThreatModeler-provided document titled as such, used to document the terms of a specific Order.
1.10. “Partner Portal” means ThreatModeler’s dedicated online partner portal (currently located or to be hosted at https://www.threatmodeler.ai/ or another URL designated by ThreatModeler). Until such time as the online portal is fully operational and made available to Partner, any reference to the Partner Portal in this Agreement shall be deemed to refer to direct email communications with the ThreatModeler Partner Manager, secure shared folders, or other alternative communication methods designated by ThreatModeler in writing .
1.11 “Partner Separate Product” means the software, hardware, or services separately owned or licensed by Partner, which Partner combines or bundles with the Products to create the Combined Offering. The term "Partner Separate Product" explicitly excludes: (a) the Products, (b) any ThreatModeler Background IP, and (c) any connectors, integrations, or APIs developed to interface with the Software, all of which shall remain the exclusive property of ThreatModeler.
1.12 "Product(s)" means the commercially available, standard offerings of ThreatModeler as listed on its official Price List (which may include the Software, Support Services, standardized training, and Documentation). The term "Products" explicitly excludes custom professional services (which must be governed by an independent SOW), any "Resold Third-Party Product", any "Interfaced Third-Party Product", and any Source Code.
1.13. "Purchase Order" or "PO" means a commercially standard document issued by the Partner to ThreatModeler to place an order for Products. The terms of this Agreement and the applicable Order shall prevail over any terms contained in a PO.
1.14. "Quote" means a non-binding offer or price quotation issued by ThreatModeler to the Partner, which may become a binding Order upon execution and acceptance.
1.15 “Software” means the proprietary computer program(s) developed by ThreatModeler, including any Software Releases, whether delivered for on-premise installation or as the core of a cloud-based service.
1.16 “Software Release” means any new version, update, or upgrade of the Software that ThreatModeler makes generally available to its supported customers, excluding any new products, add-on modules, or features that ThreatModeler licenses separately for an additional fee.
1.17 “Support Services” means the technical support, maintenance, updates, and service level commitments provided by ThreatModeler for the Products. The operational responsibilities, support tiers, and escalation paths between ThreatModeler and the Partner, alongside the corresponding Response Time SLAs and Resolution Objectives (SLOs), are governed strictly by ThreatModeler’s Partner Support Program Policy, hosted and updated dynamically on ThreatModeler’s website (currently available at threatmodeler.ai/legal/support-program). Unless an alternative support package is explicitly purchased in an applicable Order Form, the Partner shall act as the sole and primary point of contact (providing Tier 1 and Tier 2 Support directly to its End Users), and ThreatModeler's obligations shall be limited strictly to providing Tier 3 Support to Partner’s designated contacts as set forth in the web-hosted Policy.
1.18 "Source Code" means the human-readable form of the Software's programming code, including all comments and procedural code, as well as any proprietary AI model weights, neural network architectures, training datasets, and algorithms, none of which shall be provided to Partner.
1.19 “Term” means collectively the Initial Term and the Renewal Term.
1.20 “Territory” means the geographic country or countries specified in the "Key Commercial Terms" section on the cover page of this Agreement.
2. TERM AND TERMINATION
2.1. Term. This Agreement will commence on the Effective Date, and will expire on the first anniversary of the Effective Date, unless earlier terminated by either party as provided in this Agreement (the “Initial Term”). Following the expiration of the Initial Term, this Agreement shall automatically renew for successive periods of one (1) year each subject to the notice and termination rights herein contained, unless either party provides the other party with thirty (30) days prior written notice of non-renewal (a “Renewal Term”).
2.2. Termination for Cause. Either party may terminate this Agreement for cause immediately upon written notice if: (a) the other party fails to cure any payment default within fifteen (15) days after receiving written notice of such non-payment; (b) the other party fails to perform any of its material obligations under this Agreement, and such failure continues uncured for thirty (30) days following written notice thereof; (c) the other party declares bankruptcy, is adjudicated bankrupt, or files a petition for reorganization under bankruptcy laws; or (d) a receiver or trustee is appointed for the other party or substantially all of its assets.
2.3. Effect of Termination. Upon termination or expiration of this Agreement:
a) All rights and licenses granted to Partner hereunder shall immediately terminate, and Partner shall cease all marketing, sale, and distribution of the Products.
b) All accrued and outstanding Fees shall become immediately due and payable by Partner to ThreatModeler.
c) Each party shall promptly return or, at the other party's request, destroy all Confidential Information of the other party in its possession and provide written certification of such destruction upon request.
2.4. Wind Down Period.
(a) Except in the case of termination by ThreatModeler for Partner's material breach, ThreatModeler shall, at Partner's election, cooperate in an orderly transition for any active End User contracts.
(b) ThreatModeler will continue to provide the Products and Services necessary to support such existing End User contracts for a transitional period of up to one (1) year ("Wind Down Period"), strictly conditioned upon Partner’s continued and timely payment of all applicable Fees and compliance with the terms of this Agreement.
(c) During the Wind Down Period, Partner's rights are limited to servicing existing End Users only; no new sales may be conducted. If the transition to a successor provider is not complete at the end of the Wind Down Period, Fees for any continued services shall be increased by one hundred percent (100%).
2.5. Survival. The termination or expiration of this Agreement shall not extinguish any rights or obligations that by their nature are intended to survive. The following sections shall survive any such termination or expiration: Section 1 (Definitions); Section 2.3 (Effect of Termination) and this Section 2.5 (Survival); Section 3 (Intellectual Property and License Rights); Section 5 (Ordering, Pricing and Payment), with respect to any accrued and unpaid Fees.; Section 6 (Records, Reporting, and Audit); Section 8 (Indemnification); Section 9.5 (Warranty Disclaimer); Section 10 (Confidentiality); Section 11 (Limitation of Liability); Section 12 (Data Protection) and Section 13 (General Provisions), particularly those related to Governing Law, Dispute Resolution, and Notices.
3. INTELLECTUAL PROPERTY AND LICENSE RIGHTS
3.1. ThreatModeler Ownership. ThreatModeler and its licensors retain all right, title, and interest in and to the Products, the ThreatModeler Marks, and all related Intellectual Property Rights. No rights are granted to Partner except as expressly set forth herein. For the avoidance of doubt, ThreatModeler shall solely own all intellectual property rights in any connectors, APIs, scripts, or interfaces developed by or on behalf of Partner that link to or interact with the Products. To the extent any such rights vest in Partner by law, Partner hereby irrevocably assigns all such right, title, and interest to ThreatModeler.
3.2. No Rights to Source Code. Partner acknowledges that it has no rights in or to the Source Code of any Product. Partner shall not, and shall not permit any third party to, create any derivative works, make translations of the Software, or disassemble, decompile, reverse assemble, reverse compile, recompile, or make extracts from the Software, or in any other way attempt to determine or derive the Source Code.
3.3. End User License Agreement (EULA) Mandate.
a) Obligation to Apply the Correct EULA. Partner acknowledges that different versions of the EULA apply to different End User types (e.g., commercial vs. governmental). Partner is responsible for identifying the End User type and ensuring that the correct and applicable version of the EULA is presented to and accepted by the End User.
b) Partner's Duty of Execution. For any transaction, Partner is required to either: (i) ensure the End User executes the applicable EULA prior to gaining access, or (ii) include the full terms of the applicable EULA within Partner's own binding agreement with the End User.
c) No Interference. Partner shall not interfere with any "click-through" or other mechanism designed to present and secure acceptance of the applicable EULA.
d) Material Breach. A failure to ensure an End User is legally bound by the terms of the applicable EULA constitutes a material breach of this Agreement.
3.4. Internal Use and Demonstration License (NFR).
ThreatModeler grants Partner a limited, non-exclusive, non-transferable, and non-sublicensable license to install and use the Products internally ("NFR License"). This NFR License is granted solely for the purposes of: (a) internal training of Partner's personnel; (b) demonstrating the Products to prospective End Users or Resellers; and (c) allowing evaluation of the Products by prospective End Users under Partner's supervision.
All use under this NFR License is strictly limited to non-production environments and shall not be used for any commercial purpose, including but not limited to, providing paid consulting, services, or risk assessments to any third party. All use remains subject to the terms of this Agreement, including the EULA compliance mandate set forth in Section 3.3.
4. TRADEMARKS AND MARKETING
4.1. Trademark License and Usage Guidelines.
a) Limited License. The trademarks, service marks, logos, and trade names under which ThreatModeler and its affiliates market the Products (collectively, the "ThreatModeler Marks", which explicitly include all trademarks and logos associated with both the ThreatModeler and IriusRisk brands) are the exclusive property of ThreatModeler or its licensors. This Agreement grants Partner a limited, non-exclusive, restricted, revocable, and non-sublicensable license to use the ThreatModeler Marks solely for the purpose of marketing and distributing the Products within the Territory as permitted herein.
b) Usage Requirements. Partner's usage of the ThreatModeler Marks must be in strict accordance with ThreatModeler’s then-current brand guidelines. Partner must submit each advertisement and promotional material to ThreatModeler for trademark review and written approval prior to its initial release. ThreatModeler may request, and Partner agrees to promptly provide, copies of any materials where the Marks have been used.
c) Goodwill. All goodwill associated with or created by Partner's use of the ThreatModeler Marks belongs exclusively to ThreatModeler, and Partner hereby assigns all such goodwill to ThreatModeler.
D) No Implied Rights. This Agreement gives Partner no rights in the ThreatModeler Marks, except for the limited license explicitly granted. All goodwill generated from Partner's use of the ThreatModeler Marks shall inure solely to the benefit of ThreatModeler.
4.2. Restrictions on Use of ThreatModeler Marks and Brand.
a) No Alteration or Misuse. Partner may not market the Products under any name other than those specified by ThreatModeler and shall not market its own Combined Offering under any name confusingly similar to a ThreatModeler Mark. Partner shall not exploit the ThreatModeler Marks for its own benefit or the benefit of any third party.
b) Domain Names. Partner agrees that its domain names will not contain the term "ThreatModeler". If Partner uses any ThreatModeler Mark in a domain name, upon ThreatModeler’s demand, Partner will immediately assign all rights in such domain name to ThreatModeler.
c) Website and Content Restrictions. Partner's website will not in any way copy content from, or resemble the look and feel of, the official ThreatModeler website. Partner shall not create the impression that its website is the ThreatModeler website or an official part of it. Specifically, Partner shall not:
i. Copy, co-brand, or frame the ThreatModeler website or have any portion of it visible within Partner's own website.
ii. Copy any content displayed on the ThreatModeler website without prior written permission.
d) Pricing Representation. Under no circumstances may any Partner website or other marketing collateral state or imply that ThreatModeler Products are available "on sale," at a "discount," or at a "% off" price different from ThreatModeler's official List Price. Partner determines its own final sale price to the End User, but shall not represent discounts as originating from ThreatModeler.
4.3. Public Announcements. Either party may make general statements confirming the existence of this partnership. However, any formal press releases or public relations announcements concerning this Agreement shall be mutually agreed upon by both parties in writing in advance.
5. ORDERING, PRICING AND PAYMENT
5.1. Ordering Process.
a) All purchases shall be governed by a final, binding transactional document ("Order"), as defined in Section 1. Partner typically initiates an Order by submitting a Purchase Order ("PO") based on a ThreatModeler-issued Quote.
b) A submitted PO shall only become binding upon ThreatModeler’s explicit written acceptance or upon Electronic Delivery of the ordered Products by ThreatModeler. Accepted POs become part of the final Order and are non-cancellable.
c) The terms of this Agreement and the applicable Order shall prevail over any conflicting or additional terms in Partner's PO or any other business form.
5.2. Pricing, Discounts, and Fees.
a) The final, binding prices, discounts, and fees ("Fees") for any transaction are those specified in the corresponding Order. These are generally based on ThreatModeler's then-current Price List.
b) ThreatModeler reserves the right to revise its List Price upon thirty (30) days' prior written notice. Any Order accepted by ThreatModeler prior to the effective date of a price increase will be honored at the old price.
5.3. Special Pricing.
ThreatModeler may, at its sole discretion, offer "Special Pricing" for specific opportunities. The terms of any such Special Pricing will be documented in the applicable Order and shall supplement, but not override, the other terms of this Agreement.
5.4. Invoicing and Payment.
a) ThreatModeler will invoice Partner upon availability of the ordered Products. All payments are due within thirty (30) days of the invoice date, free of any deductions or set-offs.
b) Payments shall be made in the currency specified in the Order (USD by default) via wire transfer to the bank account designated by ThreatModeler.
c) Late Payments: A service charge of 1.5% per month, or the maximum rate permitted by law, will accrue on any undisputed amounts past due.
d) Suspension for Non-Payment: In the event Partner's account is past due, ThreatModeler reserves the right, upon written notice, to place Partner on credit hold and suspend all Services, including access to Products and Support, until the account is settled.
5.5. Taxes.
a) All Fees are exclusive of any tax, levy, or similar governmental charge ("Taxes"). Partner is responsible for, and agrees to pay, all applicable Taxes, excluding only taxes based on ThreatModeler’s net income.
b) Partner agrees to indemnify ThreatModeler from any claim for Taxes demanded from ThreatModeler as a result of transactions under this Agreement. Partner shall provide valid tax exemption certificates upon request.
5.6. Delivery.
All Products will be made available to Partner electronically ("Electronic Delivery"). ThreatModeler will use commercially reasonable efforts to make Products available within five (5) business days of the effective date of the Order.
6. RECORDS, REPORTING, AND AUDIT
6.1. Record Keeping.
a) General Obligation: Partner agrees to maintain detailed and accurate books and records relating to the distribution, licensing, and support of the Products, including records of sales by End User, authorized user seats, tenant IDs, license activation keys, and/or Product deployment details.
b) Retention Period: Partner shall maintain these records during the Term of this Agreement and for a period of three (3) years following its termination or expiration.
6.2. Reporting.
a) General Reporting: Partner agrees to provide ThreatModeler with such sales and distribution information as ThreatModeler may reasonably request from time to time.
b) Notification of Claims: Partner will promptly notify ThreatModeler in writing (within five (5) business days) of any claim or proceeding initiated against Partner involving the Products, or of any claimed or suspected Product defects reported to Partner.
6.3. Audit Rights.
a) Right to Audit: ThreatModeler or its designated independent auditors may, upon thirty (30) days' prior written notice, inspect and audit all of Partner’s records specifically related to this Agreement to verify compliance with licensing metrics, user limits, and payment obligations.
b) Audit Procedure: Any such audit shall be permitted no more than once per calendar year, during normal business hours, and shall not unreasonably interfere with Partner's business activities.
c) Cost of Audit: The cost of the audit will be borne by ThreatModeler, unless the audit reveals a material discrepancy (defined as an underpayment of 5% or more of the amounts due to ThreatModeler), in which case the cost of the audit shall be borne by Partner.
d) Payment of Discrepancies: Any underpayment of Fees disclosed by an audit shall be paid by Partner to ThreatModeler immediately upon demand.
6.4. Excess Usage and True-Up.
a) Usage Monitoring: ThreatModeler shall have the right to electronically or physically monitor and audit the actual usage metrics of the Products (including but not limited to authorized user seats, active tenants, concurrent sessions, or deployment environments) by Partner and its End Users to ensure compliance with the purchased license limits specified in the applicable Order.
b) Excess Usage Billing ("True-Up"): If any monitoring, self-reporting, or audit reveals that Partner or any of its End Users has exceeded the purchased license limits, Partner shall immediately purchase additional licenses to cover such excess. ThreatModeler reserves the right to invoice Partner retroactively for all such excess usage at ThreatModeler’s then-current List Price (less any applicable partner discount) from the first date the excess usage commenced. Partner shall pay such invoice in accordance with Section 5 of this Agreement.
7. COMPLIANCE AND BUSINESS CONDUCT
7.1. Fair Business Practices and Pricing Freedom.
a) Partner agrees to conduct its business in a manner that reflects favorably upon the Products and the ThreatModeler brand, adhering to the highest ethical principles and complying with all applicable laws and regulations.
b) While ThreatModeler may provide a suggested retail price (List Price), Partner has sole and absolute discretion in determining its own resale prices to End Users or Resellers. No employee or representative of ThreatModeler has the authority to dictate Partner's pricing, and Partner agrees to promptly report any attempt to do so.
7.2. Anti-Corruption and Anti-Bribery.
a) Both parties agree to comply with all applicable anti-bribery and anti-corruption laws, including but not limited to the U.S. Foreign Corrupt Practices Act (FCPA) and the UK Bribery Act 2010.
b) Partner warrants that it will not, directly or indirectly, offer, pay, or promise anything of value to any government official (including any non-US or EU public official). For the purposes of this clause, "government official" includes officers of any government department or agency, persons officially acting on behalf of a government, employees of government-owned or controlled corporations, officials of political parties, and candidates for political office.
c) No payments or transfers of value shall be made which have the purpose or effect of public or commercial bribery, money laundering, extortion, or kickbacks to improperly influence a decision, obtain or retain business, or secure an improper advantage.
d) Partner represents and warrants that it has implemented and shall maintain robust internal policies, procedures, and controls to prevent and detect bribery, corruption, and money laundering.
e) A breach of this Section 7.2 is a material breach of this Agreement and gives ThreatModeler the right to terminate the Agreement immediately upon written notice.
7.3. Export Control and Distribution Compliance.
a) U.S. Export Regulations: Partner acknowledges that the Products are subject to U.S. Export Administration Regulations (EAR) and that diversion contrary to U.S. law is prohibited. Partner represents and warrants that it is not a denied or restricted party and will not transfer, resell, or divert the Products to any country embargoed by the U.S. government or to any entity whose export privileges have been suspended or denied.
b) Prohibited End Uses: Partner represents that it will not use or knowingly transfer the Products for any end use related to nuclear, chemical, or biological weapons, or missile technology, unless specifically authorized by the U.S. Government.
c) Restrictions on Encryption: Partner understands that certain Products may contain encryption features. Partner agrees not to transfer, resell, or use such Products to provide services to "Government End Users" (as defined in Section 1) unless explicitly authorized to do so by the U.S. Bureau of Industry and Security (BIS) under regulation or a specific license.
d) Partner's Ultimate Responsibility: Partner acknowledges it is ultimately responsible for its own compliance with all applicable import, export, and other laws.
8. INDEMNIFICATION
8.1. Indemnification by ThreatModeler.
a) Subject to the limitations set forth in Section 11 (Limitation of Liability) and this Section 8, ThreatModeler will defend, indemnify, and hold harmless Partner from and against any direct, third-party claim, suit, or action alleging that the Product, as delivered by ThreatModeler, infringes a valid patent registered in the United States, or any copyright or trademark of such third party.
b) Remediation Rights: If the Product becomes, or in ThreatModeler's opinion is likely to become, the subject of an infringement claim, ThreatModeler may, at its sole option and expense: (i) procure for Partner the right to continue using the Product; (ii) replace or modify the Product to make it non-infringing without materially reducing its functionality; or (iii) if options (i) and (ii) are not commercially reasonable, terminate Partner's rights to the infringing Product and provide a pro-rata refund of any prepaid, unused fees for that Product.
c) Exclusions: ThreatModeler shall have no liability under this section for any claim arising from: (i) the use of an older version of the Product if infringement would have been avoided by using a current version made available to Partner; (ii) the combination of the Product with non-ThreatModeler software, data, hardware, or artificial intelligence models not specified or approved by ThreatModeler in writing; (iii) any modification of the Product not performed by ThreatModeler; (iv) any training data, Inputs, prompt designs, or specifications provided by Partner or its End Users to the Products; or (v) any claims where Partner failed to take commercially reasonable steps to mitigate its damages.
d) Liability Cap for IP Claims: Notwithstanding anything to the contrary in this Agreement, ThreatModeler's total aggregate liability for indemnification claims under this Section 8.1 shall be strictly limited to the total net Fees actually paid by Partner to ThreatModeler during the twelve (12) months immediately preceding the event giving rise to the claim.
e) Entire Liability: This Section 8.1 states ThreatModeler's entire liability and Partner's sole and exclusive remedy for intellectual property infringement claims.
8.2. Indemnification by Partner.
Partner will defend, indemnify, and hold harmless ThreatModeler from and against any third-party claim, suit, or action arising from: a) A claim that Partner's own separate products or marketing collateral infringes the intellectual property rights of a third party; b) The modification of the Product by Partner, or the combination of the Product with non-ThreatModeler products, if the claim would have been avoided but for such modification or combination; c) Any representation, warranty, or contractual commitment made by Partner to an End User that is in excess of, or inconsistent with, the terms of the EULA and the official Documentation; d) Any breach by Partner of its obligations under Section 7 (Compliance and Business Conduct) of this Agreement; or e) Any security incident, data breach, or unauthorized access to personal data or End User systems, to the extent caused by: (i) Partner’s negligent hosting, management, or operation of the Products, or (ii) Partner’s failure to implement mandatory security updates or patches provided by ThreatModeler.
8.3. Indemnification Procedure.
The indemnifying party's obligations are conditioned upon the indemnified party: a) providing written notice of the claim within ten (10) business days of receiving formal service or notice of the claim (provided that any delay in notification shall only relieve the indemnifying party of its obligations hereunder to the extent such delay materially prejudices the defense or settlement of the claim); b) granting the indemnifying party sole control of the defense and all related settlement negotiations; and c) providing the indemnifying party with the reasonable assistance, information, and authority necessary to perform its obligations. The indemnified party may participate in the defense with its own counsel at its own expense. The indemnifying party will not agree to any settlement that admits fault or imposes a non-monetary or material financial obligation on the indemnified party without its prior written consent.
9. REPRESENTATIONS AND WARRANTIES
9.1. Mutual Representations. Each party represents and warrants to the other that it has the full power and authority to enter into and perform its obligations under this Agreement.
9.2. ThreatModeler's Limited Warranty.
a) Performance Warranty: ThreatModeler warrants only to Partner that, for a period of ninety (90) days from its initial delivery, the Software will substantially conform to its applicable Documentation.
b) Exclusive Remedy: If Partner provides a written report detailing a substantial non-conformity during the warranty period, ThreatModeler's sole obligation, and Partner's sole and exclusive remedy, will be for ThreatModeler to use commercially reasonable efforts to correct the non-conformity. ThreatModeler makes no warranty that all errors or failures will be corrected.
c) Warranty to Partner Only: The warranty provided herein is for the sole benefit of Partner. Partner has no authority to extend this warranty to any End User or any other third party. The End User's warranty is governed exclusively by the EULA.
9.3. Partner's Warranty. Partner represents and warrants that it will perform its obligations under this Agreement (including any support services provided by Partner) in a professional and workmanlike manner, consistent with industry standards, and that its own products and services do not infringe upon the intellectual property rights of any third party.
9.4. Restriction on Use with Open Source Software. Unless expressly permitted elsewhere, Partner shall not combine or distribute the Product with any "Open Source Software" (e.g., software licensed under the GPL or other "copy-left" licenses) in a manner that would subject the Product to the license obligations of such Open Source Software, such as requiring the disclosure of its source code.
9.5. WARRANTY DISCLAIMER.
EXCEPT FOR THE EXPRESS LIMITED WARRANTIES SET FORTH IN SECTION 9.2, THE PRODUCTS AND SERVICES ARE PROVIDED "AS IS." TO THE MAXIMUM EXTENT PERMITTED BY LAW, THREATMODELER AND ITS SUPPLIERS EXPRESSLY DISCLAIM ALL OTHER WARRANTIES AND REPRESENTATIONS OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. WITHOUT LIMITING THE FOREGOING, THREATMODELER MAKES NO REPRESENTATION OR WARRANTY REGARDING: (A) THE ACCURACY, COMPLETENESS, RELIABILITY, OR OUTCOMES OF ANY ANALYSES, RECOMMENDATIONS, OR OUTPUTS GENERATED BY THE ARTIFICIAL INTELLIGENCE OR MACHINE LEARNING ENGINE INTEGRATED WITHIN THE PRODUCTS (ALL OF WHICH ARE DESIGNED TO SUPPLEMENT, NOT REPLACE, PROFESSIONAL HUMAN SECURITY AUDITS); OR (B) THAT THE PRODUCTS WILL BE COMPLETELY SECURE OR FREE FROM COMPROMISE. THREATMODELER SHALL NOT BE LIABLE FOR DELAYS, INTERRUPTIONS, OR SERVICE FAILURES INHERENT IN THE USE OF THE INTERNET AND ELECTRONIC COMMUNICATIONS OR OTHER SYSTEMS OUTSIDE OF THREATMODELER'S REASONABLE CONTROL.
10. CONFIDENTIALITY
10.1. Definition of Confidential Information.
a) For the purposes of this Agreement, "Confidential Information" means any information disclosed by one party ("Disclosing Party") to the other party ("Receiving Party") that is either marked as "Confidential" or which, given its nature or the circumstances of its disclosure, should reasonably be considered confidential. This includes, but is not limited to: business plans, marketing and sales data, technical and developmental information, source code, and any non-public performance or pricing information related to the Products.
b) Automatic Confidentiality and Trade Secret Status: The technology, architecture, methodology, algorithms, AI models, performance telemetries, and API specifications of the ThreatModeler Products shall be deemed the Confidential Information and trade secrets of ThreatModeler without any marking or further designation, and shall receive the maximum protection under applicable Trade Secret laws (including the U.S. Defend Trade Secrets Act, as applicable).
10.2. Obligations of the Receiving Party.
a) Duty of Care: The Receiving Party agrees to hold the Disclosing Party's Confidential Information in strict confidence. The Receiving Party will use the same degree of care it uses to protect its own confidential information of a similar nature, but in no event less than a reasonable degree of care.
b) Use and Disclosure: The Receiving Party will not use the Confidential Information for any purpose outside the scope of this Agreement and will not disclose it to any third party, except to its employees, contractors, and legal/financial advisors who have a need to know and who are bound by confidentiality obligations at least as protective as those herein.
10.3. Exclusions. The obligations in Section 10.2 will not apply to any information that the Receiving Party can document: a) Was rightfully in its possession or known to it prior to receipt from the Disclosing Party; b) Is or has become public knowledge through no fault of the Receiving Party; c) Is rightfully obtained by the Receiving Party from a third party without a breach of any confidentiality obligation; or d) Was independently developed by employees of the Receiving Party who had no access to the Confidential Information.
10.4. Compelled Disclosure. If the Receiving Party is required to disclose Confidential Information by law, regulation, or court order, it will, to the extent legally permissible, provide the Disclosing Party with prompt prior written notice to allow the Disclosing Party an opportunity to seek a protective order. The disclosure shall be limited to the minimum extent required to comply.
10.5. Injunctive Relief. Each party acknowledges that any unauthorized disclosure of Confidential Information would cause substantial harm for which monetary damages alone would be an insufficient remedy. Therefore, upon any such breach, the Disclosing Party shall be entitled to seek immediate injunctive relief, in addition to any other remedies it may have at law, without the necessity of posting any bond or proving actual damages.
11. LIMITATION OF LIABILITY
11.1. Disclaimer of Consequential Damages. TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY (NOR ITS SUPPLIERS) SHALL BE LIABLE FOR ANY LOSS OF USE, LOST PROFITS, LOST DATA, BUSINESS INTERRUPTION, OR ANY INDIRECT, SPECIAL, INCIDENTAL, OR CONSEQUENTIAL DAMAGES OF ANY KIND, REGARDLESS OF THE FORM OF ACTION, WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), OR OTHERWISE, EVEN IF INFORMED OF THE POSSIBILITY OF SUCH DAMAGES IN ADVANCE.
11.2. Liability Cap. TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY'S TOTAL AGGREGATE LIABILITY TO THE OTHER UNDER THIS AGREEMENT SHALL NOT EXCEED THE TOTAL FEES ACTUALLY PAID BY PARTNER TO THREATMODELER DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE FIRST EVENT GIVING RISE TO THE CLAIM.
11.3. Exclusions from Limitations. THE LIMITATIONS AND EXCLUSIONS IN SECTIONS 11.1 AND 11.2 SHALL NOT APPLY TO: a) Partner’s indemnification obligations under Section 8.2 (Indemnification by Partner), or ThreatModeler’s indemnification obligations under Section 8.1 (which shall remain strictly capped under the specific liability limit set forth in Section 8.1(d)); b) Partner’s breach of Section 7 (Compliance and Business Conduct); c) Partner’s breach of Section 3 (Intellectual Property and License Rights), or either Party's misappropriation of the other Party’s trade secrets (as defined in Section 10.1(b)); d) Any Fees owed by Partner to ThreatModeler under this Agreement; or e) Liability arising from a party's fraud, gross negligence, or willful misconduct.
12. DATA PROTECTION
12.1. General Principles and Roles.
a) Each party agrees to comply with its respective obligations under all applicable data protection laws, including, where applicable, U.S. state privacy laws like the California Consumer Privacy Act (CCPA/CPRA).
b) This section governs the processing of "Personal Data" (or "Personal Information" as defined under applicable laws) and distinguishes between three primary processing relationships under this Agreement.
12.2. Relationship Data (Controller-to-Controller).
a) For the purpose of managing the business relationship created by this Agreement, each party may process business contact information of the other party's employees and representatives.
b) In this context, the parties act as independent Data Controllers for their own processing activities.
12.3. Lead Data for Referrals (Controller-to-Controller).
a) When a Partner, acting in the "Referral Partner" role, submits a sales lead to ThreatModeler, the parties acknowledge this constitutes a data sharing event.
b) For this specific activity, Partner (as the disclosing party) and ThreatModeler (as the receiving party) act as independent Data Controllers. Partner warrants that it has a lawful basis to share such Personal Data with ThreatModeler for ThreatModeler's own direct sales and marketing purposes.
12.4. End User and Service Data (Controller-to-Processor).
a) General Principle: For any Personal Data processed by ThreatModeler in the course of providing the Products and Support Services on behalf of a Partner or its End Users, the Partner (or its End User) acts as the Data Controller, and ThreatModeler acts as the Data Processor (or "Service Provider" under U.S. laws).
b) Data Processing Addendum (DPA): This Processor-Controller relationship is governed by ThreatModeler's then-current Data Processing Addendum ("DPA"), which is incorporated into this Agreement by reference. The DPA is available on ThreatModeler's legal website (currently at threatmodeler.ai/legal/dpa) and specifies ThreatModeler's obligations regarding data security, subprocessors, data subject rights, and international transfers.
c) Partner's Obligation: In any scenario where this relationship applies, Partner agrees to be bound by the terms of the applicable DPA.
12.5. DPA Updates.
ThreatModeler may update the DPA from time to time to reflect changes in law, regulations, or its data processing operations. ThreatModeler will provide Partner with notice of any material changes. Partner's continued relationship with ThreatModeler after such notice will constitute acceptance of the updated terms.
13. GENERAL PROVISIONS
13.1. Relationship of the Parties. The relationship of the parties is that of independent contractors. Nothing in this Agreement shall be construed as creating any agency, partnership, joint venture, or employer-employee relationship. Neither party has any authority to bind the other in any respect whatsoever.
13.2. Assignment. Neither party may assign or transfer this Agreement, in whole or in part, without the prior written consent of the other party. Notwithstanding the foregoing, either party may assign this Agreement without consent in connection with a merger, acquisition, or sale of all or substantially all of its assets, provided that the assigning party provides prompt written notice to the other party and the assignee agrees in writing to be bound by the terms of this Agreement.
13.3. Notices.
a) Method and Address. All notices and other communications required under this Agreement must be in writing and sent by email. Notices to ThreatModeler shall be sent to legal@threatmodeler.com. Notices to Partner shall be sent to the primary email address specified on the cover page of this Agreement.
b) Deemed Delivery. A notice sent by email will be deemed to have been duly given on the business day it is sent, provided that the sender does not receive a system-generated error message indicating that the email was not delivered.
c) Change of Address. Each party may change its designated email address for receiving notices by providing at least five (5) business days' prior written notice to the other party in accordance with this section. It is each party's responsibility to ensure its designated email address is current and operational.
13.4. Governing Law and Jurisdiction.
a)This Agreement shall be governed by the laws of the State of Delaware, without regard to its conflict of law principles. The parties agree to the exclusive jurisdiction of the state and federal courts located in Delaware.
b) The United Nations Convention on Contracts for the International Sale of Goods shall not apply to this Agreement.
13.5. Dispute Resolution. Prior to initiating any litigation, the parties agree to first attempt to resolve any dispute arising out of this Agreement informally. A party will initiate this process by providing written notice to the other. Each party will promptly designate a senior executive with authority to resolve the dispute. If the dispute is not resolved through negotiation within thirty (30) days, either party may then pursue legal remedies. This clause does not prevent either party from seeking immediate injunctive relief.
13.6. Force Majeure. Neither party shall be liable for any failure or delay in performing its obligations (except for payment obligations) due to causes beyond its reasonable control, including but not limited to acts of God, war, strikes, or natural disasters ("Force Majeure Event"). The affected party will provide prompt notice and use commercially reasonable efforts to resume performance.
13.7. Insurance.
a) Obligation to Maintain Coverage. During the Term of this Agreement and for one (1) year thereafter, each party shall, at its own expense, obtain and maintain the following insurance coverage from insurers with a Best's rating of A-, VII or better:
i. Commercial General Liability insurance, written on an occurrence form, including coverage for product and completed operations, personal and advertising injury, and contractual liability. Limits shall be no less than $1,000,000 USD per occurrence and $2,000,000 USD in the general aggregate. This policy shall include an endorsement naming the other party as an additional insured.
ii. Umbrella or Excess Liability insurance with a limit of no less than $3,000,000 USD per occurrence and in the aggregate.
iii. Workers' Compensation insurance with statutory limits as required by law, including a waiver of subrogation in favor of the other party.
iv. Professional Liability / Errors & Omissions insurance, covering liabilities arising from technology services and products, with a limit of no less than $1,000,000 USD per claim.
b) Policy Requirements. A party's required insurance shall be primary with respect to its obligations under this Agreement. The policy limits shall not be construed as a limitation of a party's liability under this Agreement. Neither party shall cancel, or allow to expire, or materially change its insurance policies without providing the other party with at least thirty (30) days' prior written notice.
c) Evidence of Insurance. Upon execution of this Agreement and at each subsequent renewal, each party shall, upon request, provide the other with a certificate of insurance evidencing the coverage required herein and confirming the additional insured status and waiver of subrogation.
13.8. Entire Agreement and Order of Precedence.
a) Entire Agreement: This Agreement, including all applicable Special Terms, all Exhibits, and all executed Orders, constitutes the complete and entire agreement between the parties regarding its subject matter. It supersedes all prior or contemporaneous understandings, oral or written. This Agreement may only be amended by a written document signed by authorized representatives of both parties.
b) Order of Precedence: In the event of any direct conflict between the terms of the documents comprising this Agreement, the following order of precedence will apply, with the document higher in the list controlling over the one lower in the list:
- The applicable Order
- The applicable Special Terms
- The Exhibits
- These General Terms and Conditions
c) Prevalence over Partner Forms: For clarity, the terms of this Agreement (including any Order) shall prevail over any pre-printed, conflicting, or additional terms contained in any Partner-issued Purchase Order or other business form, and any such terms are hereby rejected and shall be void.
13.9. Severability. If any provision of this Agreement is found to be unenforceable or invalid, that provision will be limited or eliminated to the minimum extent necessary so that this Agreement will otherwise remain in full force and effect and enforceable.
13.10. No Waiver. The failure of a party to exercise a right or to require performance of an obligation under this Agreement shall not be a waiver of that party's right to exercise that right or require such performance at any time thereafter.
SPECIAL TERMS
A. RESELLER TERMS
If the "Reseller" role is selected, the following terms apply:
1. Appointment and Status
1.1. Appointment. Subject to the terms of this Agreement, ThreatModeler grants Partner the non-exclusive, non-transferable right to market and resell the Products directly to End Users within the Territory. Partner shall resell the Products strictly on a transactional, back-to-back basis, and each order must be registered to a single, specific, and authorized End User at the time of purchase. Partner is strictly prohibited from reselling Products to any third-party reseller or purchasing Products for inventory, general stocking, or future redistribution without ThreatModeler's prior written consent.
1.2. Independent Reseller Status. Partner shall act as an independent reseller, at its own risk and expense. Partner is solely responsible for its business activities and unilaterally determines its own resale prices to End Users. Nothing in this Agreement prohibits ThreatModeler from making direct sales to any End User, with or without Partner involvement.
1.3. No Sub-Agents. Partner shall not appoint any sub-distributors, agents, or other third parties to exercise its resale rights without the prior written consent of ThreatModeler.
2. Partner's Obligations and Performance
2.1. Marketing and Ethical Conduct. Partner shall use commercially reasonable efforts to market and promote the Products. Partner must comply with the highest ethical principles in all its dealings.
2.2. No Unauthorized Warranties. Partner shall not make any representations or warranties on behalf of ThreatModeler with respect to the Products that are in excess of, or inconsistent with, the official Documentation and the EULA.
2.3. Accreditation and Training. Partner agrees to achieve and maintain the accreditation and training requirements for sales and technical personnel as set forth by ThreatModeler on its Partner Portal or other designated communication method from time to time.
2.4. EULA Compliance. Partner's obligation to ensure each End User executes the EULA is a material obligation of this role. Partner shall not modify, alter, or obscure any license agreements included with the Products.
2.5. Sales Reporting. Partner agrees to provide ThreatModeler with such sales and End User information as ThreatModeler may reasonably require from time to time for the purpose of order fulfillment and market analysis.
3. ThreatModeler's Obligations
3.1. Provision of Materials. ThreatModeler will make available to Partner, via the Partner Portal or other designated communication method, the necessary sales and marketing materials, Documentation, and standard installation kits to enable Partner to market and sell the Products.
3.2. Notice of Changes. ThreatModeler will use commercially reasonable efforts to provide Partner with at least thirty (30) days' notice of any material changes to the Products or to the List Price.
3.3. Product Training. ThreatModeler will provide access to training programs for Partner's personnel, which may be delivered by ThreatModeler or a designated third party.
4. Purchasing and Pricing
4.1. Purchasing Channels. Partner will purchase Products for resale either (i) directly from ThreatModeler, or (ii) from a ThreatModeler authorized distributor ("Distributor"). ThreatModeler reserves the right, upon notice, to transition Partner to a two-tier model where purchases must be made exclusively through an authorized Distributor.
4.2. Direct Purchase Process. For purchases made directly from ThreatModeler, Partner will submit a Purchase Order (PO) in response to a Quote, as detailed in Section 5 of the General Terms. For the avoidance of doubt, Partner's obligation to pay ThreatModeler under this Agreement is absolute, and is not conditioned upon, linked to, or delayed by Partner's actual collection of payments or fees from its End Users.
4.3. Incentive Programs. ThreatModeler may, at its discretion, offer marketing and incentive programs, such as Rebates. Partner's participation in any such program is subject to its compliance with the specific program requirements.
4.4. Pricing and Discounts. The pricing and discounts applicable to Partner for any given transaction shall be as specified in the corresponding Order.
5. Support Model
5.1. Support Framework. The specific support model for each transaction shall be specified in the applicable Order. The operational details, including service levels and escalation procedures, are governed by the Partner Support Program.
5.2. Partner-Led Support (Default Model). Unless otherwise specified, Partner is responsible for providing Tier 1 Support to its End Users. For the purposes of this Agreement, "Tier 1 Support" means acting as the initial point of contact for the End User, performing initial problem diagnosis, and resolving basic technical issues.
5.3. ThreatModeler-Led Support (Alternative Model). If explicitly specified in the Order, ThreatModeler will provide all tiers of support (Tier 1, 2, and 3) directly to the End User. In this scenario, Partner's discount on the transaction will be adjusted accordingly to reflect the reduced operational cost for the Partner.
B. DISTRIBUTOR TERMS
If the "Distributor" role is selected, the following terms apply:
1. Appointment and Status
1.1. Appointment. Subject to the terms of this Agreement, ThreatModeler grants Partner the non-exclusive, non-transferable right to market and distribute the Products solely to Resellers within the Territory who have been explicitly approved in writing by ThreatModeler (each, an "Authorized Reseller"). Partner shall not sell, license, or distribute the Products to any unapproved reseller, commercial intermediary, or end-user directly without ThreatModeler’s prior written consent.
1.2. No Direct Sales to End Users. Partner is not authorized to sell Products directly to End Users. All sales must be conducted through Partner's network of Resellers.
1.3. Independent Distributor Status. Partner acts as an independent distributor, at its own risk and expense, and unilaterally determines its own resale prices and commercial terms with its Resellers.
1.4. No Exclusivity. ThreatModeler reserves the right to make direct sales to any party and to appoint other distributors. Partner is permitted to distribute competing products.
2. Reseller Network Management
2.1. Authorization and Onboarding. Partner is responsible for recruiting, onboarding, and managing its network of Resellers. All Resellers must be approved by ThreatModeler and must agree to comply with ThreatModeler's channel policies, communicated via the Partner Portal, direct email, or other designated Communication Method.
2.2. Flow-Down of Obligations. Partner must have a binding written agreement with each of its Resellers that contractually obligates the Reseller to comply with all relevant terms of this Agreement, including but not limited to the EULA compliance mandate (Section 3.3), all Compliance and Business Conduct rules (Section 7), and all Intellectual Property and License Restrictions (Section 3).
2.3. Partner Liability. Partner remains fully liable to ThreatModeler for any breach of the terms of this Agreement caused by the acts or omissions of any Reseller within its network.
3. Marketing and Business Development
3.1. Marketing Efforts. Partner will use commercially reasonable efforts to market the Products to its Reseller network, which includes providing a sufficient number of trained sales representatives and appointing a marketing manager focused on the ThreatModeler product line.
3.2. Marketing Plan and Reviews. Partner shall submit an annual marketing plan to ThreatModeler for approval and will meet with ThreatModeler on a quarterly basis to review business performance.
3.3. Marketing Programs (MDF & Rebates). ThreatModeler may, at its discretion, establish Market Development Fund (MDF) or rebate programs, which will be governed by the then-current program guidelines.
4. Reporting, Records, and Audit
4.1. Point-of-Sale (POS) Reporting. Partner must provide ThreatModeler with standard monthly POS reports by the fifth (5th) business day of each month, detailing the Products sold, the purchasing Reseller, and the final End User information.
4.2. Record Keeping. Partner will keep full and accurate books of account and records related to this Agreement (including POs, Invoices, Debit/Credit Memos, and POS reports) for three (3) years after the end of each calendar quarter.
4.3. Mutual Audit Rights. Each party may, once per calendar year upon thirty (30) days' notice, audit the records of the other party specifically related to this Agreement to ensure compliance. The cost of the audit will be borne by the requesting party.
5. Purchasing, Payment and Credit Management
5.1. Purchasing Process. The general process for ordering, pricing, invoicing, payment, and delivery of Products is governed by Section 5 of the General Terms. Distributor's obligation to pay ThreatModeler under this Agreement is absolute, and is not conditioned upon, linked to, or delayed by Distributor's actual collection of payments or fees from its Resellers.
5.2. Credit and Debit Management.
a) Partner may issue a debit memo for undisputed credits owed by ThreatModeler (e.g., for approved rebates). Partner must provide reasonable documentation ("Required Debit Documentation") to support the claim.
b) A debit memo shall be deemed accepted by ThreatModeler unless ThreatModeler disputes it in writing within thirty (30) days of receiving the Required Debit Documentation.
c) Any claim for a credit or billing adjustment by either party shall be forfeited if not submitted within one (1) year of the event that led to the claim.
6. Support Model
6.1. Support Framework. Partner is responsible for providing Tier 1 support to its Resellers. The Resellers are then responsible for providing Tier 1 support to their End Users.
6.2. Escalation. Partner acts as the single point of contact for escalating support issues from its Reseller network to ThreatModeler, as governed by the Partner Support Program.
C. REFERRAL PARTNER TERMS
If the "Referral Partner" role is selected, the following terms apply:
1. Definitions for this Section
1.1. "Account" means the specific customer entity identified in an accepted Lead Registration Form who procures Products directly from ThreatModeler as a result of Partner's referral activities.
1.2. "Opportunity" means the specific, initial sales opportunity for the procurement of Products by an Account, as proposed by Partner and accepted by ThreatModeler. Unless otherwise stated in the Lead Registration Form, this does not include any follow-on, renewal, or additional sales to the Account.
1.3. "Lead Registration Form" means the official document or electronic form provided by ThreatModeler, which must be completed by Partner for each Opportunity to qualify for a Referral Fee.
1.4. "Referral Fee" means the commission payable to Partner for a successful Opportunity, calculated in accordance with these terms.
2. Program Description and Lead Process
2.1. Independent Contractor Status (No Agency). Partner acts solely as an independent contractor. Nothing in this Agreement creates a partnership, joint venture, or agency relationship. Partner has no authority to bind ThreatModeler in any way. The parties expressly agree to exclude this Agreement from the scope of any applicable agency laws.
2.2. Program Participation. Partner shall be subject to any program and accreditation requirements as set forth on the Partner Portal (when available). Partner shall bear all its own costs for fulfilling its responsibilities hereunder.
2.3. Lead Submission and Privacy Warranty: Upon identifying a prospective Opportunity, Partner must submit a Lead Registration Form to ThreatModeler via the Partner Portal, or via email to ThreatModeler's partner management team if the online Portal is not yet available. Prior to submitting any Lead Registration Form, Partner represents and warrants that it has: (a) complied with all Applicable Data Protection Laws, (b) provided all necessary privacy notices to the contact person, and (c) obtained all required consents to share such contact details with ThreatModeler for direct marketing purposes.
2.4. Lead Acceptance and Duplication Rule: ThreatModeler may, in its sole discretion, accept or reject any submitted Lead Registration Form and will notify Partner of its decision. ThreatModeler has no obligation to Partner for a rejected Lead. If multiple partners register the same prospective Account or Opportunity, ThreatModeler shall only recognize the lead of the partner whose Lead Registration Form was first accepted in writing by ThreatModeler ("first-come, first-served" rule).
2.5. Exclusions. No Referral Fee shall be payable for any transaction with any public sector, governmental, or state-owned entities, or where paying such a fee would violate applicable law, procurement regulations, anti-bribery laws, or Section 7.2 of this Agreement.
3. Referral Fee Calculation and Payment
3.1. Calculation of Fee. The Referral Fee is calculated as a percentage of the net new license or subscription fees actually collected by ThreatModeler from the Account for the initial Opportunity only... The specific percentage is defined in the Referral Fee Schedule provided by ThreatModeler to Partner in writing (via email or as an exhibit to the applicable Order Form) or hosted on the Partner Portal (when available).
3.2. Eligibility and Timeframe. A Referral Fee is earned only if a definitive sales contract is signed between ThreatModeler and the Account within six (6) months of ThreatModeler's acceptance of the Lead Registration Form.
3.3. Payment Terms. ThreatModeler shall pay the earned Referral Fee to Partner within thirty (30) days after receiving payment in full from the Account for the applicable Products. The Referral Fee represents the full and only compensation due to Partner for the Opportunity.
3.4. Fee Adjustments. Prior to consummating a sale, ThreatModeler may request in writing a reduction in the Referral Fee to facilitate the deal. If Partner rejects such a request, ThreatModeler, in its sole discretion, may decide not to proceed with the sale, in which case no Referral Fee will be payable.
3.5. Refunds ("Clawback"). If ThreatModeler issues a refund to an Account for any reason, Partner shall refund to ThreatModeler the applicable portion of the Referral Fee within thirty (30) days of ThreatModeler's request. ThreatModeler may also offset this amount against any future fees owed to Partner.
3.6. Termination of a Specific Opportunity. ThreatModeler may terminate its pursuit of an accepted Opportunity if it determines, in its sole discretion, that the Account has inadequate credit, has committed to another vendor, or if other material conditions have changed. In such a case, no Referral Fee will be payable.
D. MSP / HOSTING PARTNER TERMS
If the "MSP / Hosting Partner" role is selected, the following terms apply:
1. Appointment and Service Model
1.1. Appointment. Subject to the terms of this Agreement, ThreatModeler grants Partner the non-exclusive, non-transferable right to provide managed and/or hosting services that include the Products ("Managed Service") to End Users within the Territory.
1.2. Service Model: The specific service model for each End User engagement shall be designated in the applicable Order:
a) "Partner-Hosted" Model: Partner is granted a limited, non-transferable license to install and operate the Products strictly on its own or secure third-party controlled infrastructure to deliver the Managed Service to End Users.
b) "ThreatModeler-Hosted" Model: Partner is appointed to market and manage the provision of ThreatModeler's standard SaaS Products to End Users. In any scenario where ThreatModeler processes Personal Data on behalf of the Partner or its End Users, the relationship shall be governed by ThreatModeler's then-current Data Processing Addendum ("DPA"), as further detailed in the General Terms.
2. Partner's Service Delivery and Commercial Obligations
2.1. Primary Point of Contact. Partner agrees that for any End User receiving a Managed Service, the Partner is the sole and primary point of contact. All End Users are Partner's customers. Partner is solely responsible for all commercial interactions (contracting, invoicing, fee collection) and all technical interactions (onboarding, configuration, and Tier 1 & 2 support).
2.2. Support Obligations. Partner is responsible for providing Tier 1 and Tier 2 support to its End Users. Escalation of support issues to ThreatModeler is governed by the Partner Support Program.
2.3. Marketing and Promotion. Partner shall use commercially reasonable efforts to market the Managed Service and is responsible for all its own costs.
3. License, EULA, and Service Restrictions
3.1. License Ownership and Usage Limitations: For both service models, Partner must hold the Product licenses solely in its own name. Licenses procured for a Managed Service cannot be transferred or assigned to an End User. Partner shall only deploy and use the Products for the purpose of active, value-add Managed Services. Partner is strictly prohibited from reselling or distributing the Products on a stand-alone, license-only basis to any End User under the guise of an MSP model.
3.2. EULA Compliance. Partner must ensure that each End User is legally bound by the terms of ThreatModeler's then-current EULA, prior to being granted access to the Managed Service. This can be achieved by having the End User execute the EULA directly or by incorporating its full terms into Partner's own binding agreement with the End User. A failure to comply with this clause is a material breach of this Agreement.
3.3. General Restrictions. Partner shall not, and shall not permit its End Users or any third party to:
a) Copy or reproduce the Products, except as strictly necessary to provide the Managed Service.
b) Modify, create derivative works from, or in any way alter the Products or their source code.
c) Disassemble, decompile, or reverse engineer the Software or otherwise attempt to gain access to the source code.
3.4. No Stand-alone Distribution. The Products may only be delivered as an integrated part of the Managed Service.
3.5. End User Breach. If an End User materially breaches its agreement with Partner or the EULA, Partner shall promptly notify ThreatModeler. If such breach is not cured, ThreatModeler reserves the right to suspend or terminate the provision of the underlying Products for that specific End User, with no liability to Partner or the End User.
4. Terms Specific to the "Partner-Hosted" Model
4.1. Hosting and Service Level Obligations. Partner agrees that its hosting environment must, at a minimum, meet or exceed the standards and service levels detailed in ThreatModeler's public-facing terms for its own SaaS offering, located at threatmodeler.ai/legal/eula.
4.2. Third-Party Software Indemnity.
a) Acknowledgement of Risk: Partner understands and acknowledges that the Products may include embedded software from Third-Party Vendors. The use of such software in a multi-tenant commercial hosting environment may be prohibited or require additional licenses and fees.
b) Partner's Responsibility to Secure Rights: Partner’s purchase of the Product does not grant it any rights to use such embedded third-party software for a multi-tenant Managed Service. Partner is solely responsible for obtaining any and all necessary approvals and licenses from the respective Third-Party Vendors. ThreatModeler will provide commercially reasonable assistance to Partner in this effort.
c) Indemnification by Partner: Partner shall defend, indemnify, and hold harmless ThreatModeler from any and all liability, damages, costs, and legal fees arising from a claim related to Partner's use of such embedded software. This includes claims from: (i) Partner’s failure to obtain necessary approvals; (ii) Partner’s failure to comply with third-party agreements; or (iii) any use of the third-party software by or on behalf of Partner's End Users.
d) Indemnification Procedure: ThreatModeler will promptly notify Partner of any such claim. Partner shall have sole control of the defense and all related settlement negotiations, provided that Partner shall not agree to any settlement that admits fault or imposes obligations on ThreatModeler without ThreatModeler’s prior written consent.
E. STRATEGIC / OEM PARTNER TERMS
If the "Strategic / OEM Partner" role is selected, the following terms apply:
1. Appointment and Grant of Rights
1.1. Appointment. Subject to the terms of this Agreement, ThreatModeler grants Partner the non-exclusive, non-transferable right to integrate the Products with Partner's own distinct products or services ("Partner Separate Product") to create a single, unified solution ("Combined Offering") for sale to End Users within the Territory.
1.2. License Grant for Integration. For the sole purpose of creating and supporting the Combined Offering, Partner is granted a limited, non-transferable license to use, copy, and reproduce the Products as technically necessary to bundle and integrate them as an inseparable component of the Combined Offering.
1.3. Independent OEM Status. Partner acts as an independent original equipment manufacturer (OEM). Partner is solely responsible for all aspects of its Combined Offering, including its final pricing, marketing, and sales strategy.
2. Intellectual Property, Brand, and License Restrictions
2.1. IP Ownership Clarification. The creation of a Combined Offering is for marketing and sale purposes only and does not create any new or joint intellectual property rights.
a) ThreatModeler IP: ThreatModeler (or its affiliates, as applicable) retains all right, title, and interest in and to the ThreatModeler Products, including all Software, APIs, connectors, and any updates or derivative works thereof. All software code, scripts, and connectors developed by Partner to interface with the Products shall belong exclusively to ThreatModeler.
b) Partner IP: Partner retains all right, title, and interest in and to the Partner Separate Product.
2.2. No Stand-alone Distribution. Partner must not market, license, or sell the ThreatModeler Products as a stand-alone offering. The Products must always be delivered as a fully integrated and inseparable part of the Combined Offering.
2.3. Brand, Naming, and Attribution: Partner shall market the Combined Offering under its own brand name. The name of the Combined Offering must not be confusingly similar to any ThreatModeler Mark. However, Partner agrees to display a visible and prominent notice within the user interface of the Combined Offering (e.g., on the 'About' or 'Login' screens) and in all corresponding user documentation stating: 'Powered by ThreatModeler™' or 'Contains ThreatModeler™ Technology', in accordance with ThreatModeler's brand guidelines.
2.4. Prohibition of Reverse Engineering. Partner has no rights to the Source Code of any Product and shall not (and shall not permit others to) disassemble, decompile, or reverse engineer the Software.
3. Partner's Obligations and Responsibilities
3.1. Sole Responsibility for the Combined Offering. Partner is the "manufacturer of record" for the Combined Offering. As such, Partner is solely responsible for all aspects of its lifecycle, including its development, quality assurance, testing, marketing, sales, and overall performance.
3.2. EULA Flow-Down. Partner must ensure that its own binding end-user agreement for the Combined Offering includes, at a minimum, all the disclaimers of warranty, limitations of liability, and license restrictions contained in ThreatModeler's then-current EULA. A failure to flow down these protections is a material breach of this Agreement.
3.3. Secure Distribution. Partner may not distribute the Combined Offering via electronic means unless it is through a secure, access-controlled distribution model that protects ThreatModeler's intellectual property.
3.4. Development Work for ThreatModeler. If Partner performs custom development work on the core ThreatModeler Product itself, such work is outside the scope of this OEM relationship and must be governed by a separate Master Subcontractor Agreement that ensures ThreatModeler owns the resulting IP.
3.5. Data Processing. To the extent that the functioning of the Combined Offering requires ThreatModeler to process Personal Data for which the Partner or its End User is the Data Controller, the relationship shall be governed by ThreatModeler's then-current Data Processing Addendum ("DPA"), as further detailed in the General Terms.
4. Reporting and Commercial Model
4.1. Royalty-Based Fees. Unless otherwise agreed in an Order, the fees payable by Partner ("Royalties") will be calculated based on the number of units of the Combined Offering sold or distributed by Partner during a specific period.
4.2. Usage Reporting and Electronic Verification: Partner must provide ThreatModeler with accurate quarterly usage reports within thirty (30) days of the end of each calendar quarter. These reports will detail the number of units of the Combined Offering sold or distributed and will be used by ThreatModeler to calculate and invoice the applicable Royalties. ThreatModeler reserves the right to electronically verify Partner's active customer nodes or active user seats through Product telemetry data to validate the accuracy of the usage reports.
5. Support Model
5.1. Partner as Sole Support Provider. Partner is responsible for providing all tiers of support (Tier 1, 2, and 3) for the Combined Offering directly to its End Users. The End User must have no direct support contact with ThreatModeler.
5.2. OEM Escalation Channel. Partner must purchase "OEM Support" from ThreatModeler. This provides a dedicated escalation channel for specific, named technical contacts within Partner's organization to report reproducible bugs in the core ThreatModeler Product to ThreatModeler's engineering teams, as defined in the Partner Support Program.
This Partner Agreement (the “Agreement”) is made and entered into by and between ThreatModeler Software, S.L., a Spanish limited liability company and its principal place of business at Parque Tecnológico Walqa, Ctra. Zaragoza N-330A, Km. 566, 22197 Cuarte (Huesca, Aragon), Spain (“ThreatModeler”); and the entity identified as “Partner” in an applicable Order Form or that otherwise acts as a partner of ThreatModeler.
This Agreement takes effect on the date of the first-executed partner-specific Order Form, or the date on which Partner first performs any action consistent with a partner role (including, but not limited to, reselling a Product, submitting a referral lead, or distributing the Product), whichever is earlier (the “Effective Date”).
BY EXECUTING AN ORDER THAT REFERENCES THIS AGREEMENT, OR BY ACTING IN ANY PARTNER CAPACITY (E.G., BY RESELLING, DISTRIBUTING, OR REFERRING A LEAD), PARTNER AGREES TO BE LEGALLY BOUND BY THE TERMS AND CONDITIONS OF THIS AGREEMENT.
RECITALS
WHEREAS, ThreatModeler develops, markets, and licenses proprietary threat modeling software and related services; and
WHEREAS, Partner possesses expertise, resources, and relationships in the marketplace and desires to collaborate with ThreatModeler in one or more capacities as selected below.
THEREFORE, in consideration of the mutual covenants contained herein, the Parties agree to the terms and conditions set forth in this Agreement.
1. APPLICABLE PARTNER ROLE(S):
The specific partner role(s) authorized under this Agreement shall be as designated and selected in the applicable executed Order. Only the corresponding terms and conditions set forth in the Special Terms (Sections A through E below) that match the authorized partner role(s) selected in such Order shall apply to and govern the Parties.
| Reseller | Sells ThreatModeler licenses and subscriptions directly to End Users. This Partner owns the customer relationship and commercial transaction. The terms for this role are detailed in Special Terms, Section A. |
| Distributor | Manages a two-tier channel by selling ThreatModeler Products to a network of Resellers. This Partner is responsible for channel enablement, logistics, and management. The terms for this role are detailed in Special Terms, Section B. |
| Referral Partner | Identifies and qualifies potential customers, and introduces these sales leads to the ThreatModeler sales team in exchange for success-based referral fees. The terms for this role are detailed in Special Terms, Section C. |
| MSP / Hosting Partner | Delivers ThreatModeler's capabilities as a managed service. This Partner uses the Products to provide ongoing threat modeling, security, or hosting services to its own customers. The terms for this role are detailed in Special Terms, Section D. |
| Strategic / OEM Partner | Embeds or tightly integrates ThreatModeler's technology into their own proprietary product or service to create a single, unified "Combined Offering" sold under their own brand. The terms for this role are detailed in Special Terms, Section E. |
2. KEY COMMERCIAL TERMS
| Territory: | The authorized geographic country, countries, or region specified as the "Territory" in the applicable executed Order. All rights and licenses granted to Partner under this Agreement are strictly limited to such authorized Territory. |
| Default Currency: | Euros (EUR) (Unless otherwise specified in the applicable Order) |
| Email for Notices: | For ThreatModeler: legal@threatmodeler.com For Partner: As specified in the applicable Order. |
GENERAL TERMS AND CONDITIONS
1. DEFINITIONS
1.1. "Agreement" means this Partner Agreement, including its cover page, all sections of the General Terms and Conditions, the applicable Special Terms, and all Exhibits, Orders, and any ThreatModeler policies, addenda, or terms incorporated by reference herein (including the EULA and the DPA hosted on ThreatModeler’s website).
1.2 "Combined Offering" means (a) For MSP: The Product(s) managed and delivered by Partner as an integrated managed service in combination with Partner Separate Products or services to multiple End Users, as governed by Special Terms, Section D; and (b) For OEM: The Product(s) integrated, embedded, or bundled by Partner with the Partner Separate Product as a single, inseparable, unified commercial solution marketed and licensed to End Users under Partner’s brand, as governed by Special Terms, Section E.
1.3 "Data Processing Addendum" or "DPA" means ThreatModeler's then-current data processing addendum compliant with Applicable Data Protection Laws (including the GDPR) the terms of which are located on ThreatModeler's legal website (currently at threatmodeler.ai/legal/dpa)
1.4 "Documentation" means the official user manuals, technical specifications, and other explanatory materials provided by ThreatModeler for the Products, in any format, which are designed to instruct End Users and Partners in the installation, operation, and use of the Products.
1.5 “End User” means the final legal entity or individual that acquires, accesses, or otherwise uses the Products (including as part of a Combined Offering) for its own internal business purposes. An End User has no right to resell, sublicense, or further distribute the Products to any third party.
1.6 "End User License Agreement" or “EULA” means ThreatModeler's then-current standard end-user license agreement, the terms of which are located at threatmodeler.ai/legal/eula (or such other URL as ThreatModeler may provide from time to time). This includes, but is not limited to, specific versions for commercial entities, U.S. Federal Government entities (containing applicable FAR/DFARS clauses), and other governmental bodies.
1.7 “Fees” means the net amounts payable by Partner to ThreatModeler for the purchase of Products, or the commissions payable by ThreatModeler to Partner, as applicable to the Partner's role. The final, binding Fees for any given transaction are those specified in the corresponding Order. For clarity, Fees are calculated after the application of any discounts and do not include any taxes, duties, shipping costs, or other pass-through charges, which are the sole responsibility of the Partner.
1.8 “Government End User” means any central, regional or local government department, agency or entity performing governmental functions, and which is not headquartered in Australia, Austria, Belgium, Canada, Czech Republic, Denmark, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Japan, Luxembourg, the Netherlands, Norway, New Zealand, Poland, Portugal, Spain, Sweden, Switzerland, Turkey, the United Kingdom or the United States. This definition includes any international governmental organizations as well as any governmental research institutions, governmental corporations or their separate business units that are (a) not headquartered in the countries named above, and (b) engaged in the manufacture or distribution of items or services controlled on the Wassenaar Munitions List.
1.9. "Order(s)" means the final, binding transactional document for a specific purchase, which may take the form of: (a) a ThreatModeler-issued Quote that has been executed by the Partner and accepted by ThreatModeler; (b) a formal Order Form executed by both Parties; or (c) a Partner-issued Purchase Order (PO) that has been explicitly accepted by ThreatModeler in writing or fulfilled via Electronic Delivery.
1.10. "Order Form" means a ThreatModeler-provided document titled as such, used to document the terms of a specific Order.
1.11. “Partner Portal” means ThreatModeler’s dedicated online partner portal (currently located or to be hosted at https://www.threatmodeler.ai/ or another URL designated by ThreatModeler). Until such time as the online portal is fully operational and made available to Partner, any reference to the Partner Portal in this Agreement shall be deemed to refer to direct email communications with the ThreatModeler Partner Manager, secure shared folders, or other alternative communication methods designated by ThreatModeler in writing .
1.12 “Partner Separate Product” means the software, hardware, or services separately owned or licensed by Partner, which Partner combines or bundles with the Products to create the Combined Offering. The term "Partner Separate Product" explicitly excludes: (a) the Products, (b) any ThreatModeler Background IP, and (c) any connectors, integrations, or APIs developed to interface with the Software, all of which shall remain the exclusive property of ThreatModeler.
1.13 "Product(s)" means the commercially available, standard offerings of ThreatModeler as listed on its official Price List (which may include the Software, Support Services, standardized training, and Documentation). The term "Products" explicitly excludes custom professional services (which must be governed by an independent SOW), any "Resold Third-Party Product", any "Interfaced Third-Party Product", and any Source Code.
1.14. "Purchase Order" or "PO" means a commercially standard document issued by the Partner to ThreatModeler to place an order for Products. The terms of this Agreement and the applicable Order shall prevail over any terms contained in a PO.
1.15. "Quote" means a non-binding offer or price quotation issued by ThreatModeler to the Partner, which may become a binding Order upon execution and acceptance.
1.16 “Software” means the proprietary computer program(s) developed by ThreatModeler, including any Software Releases, whether delivered for on-premise installation or as the core of a cloud-based service.
1.17 “Software Release” means any new version, update, or upgrade of the Software that ThreatModeler makes generally available to its supported customers, excluding any new products, add-on modules, or features that ThreatModeler licenses separately for an additional fee.
1.18 “Support Services” means the technical support, maintenance, updates, and service level commitments provided by ThreatModeler for the Products. The operational responsibilities, support tiers, and escalation paths between ThreatModeler and the Partner, alongside the corresponding Response Time SLAs and Resolution Objectives (SLOs), are governed strictly by ThreatModeler’s Partner Support Program Policy, hosted and updated dynamically on ThreatModeler’s website (currently available at threatmodeler.ai/legal/support-program). Unless an alternative support package is explicitly purchased in an applicable Order Form, the Partner shall act as the sole and primary point of contact (providing Tier 1 and Tier 2 Support directly to its End Users), and ThreatModeler's obligations shall be limited strictly to providing Tier 3 Support to Partner’s designated contacts as set forth in the web-hosted Policy.
1.19 "Source Code" means the human-readable form of the Software's programming code, including all comments and procedural code, as well as any proprietary AI model weights, neural network architectures, training datasets, and algorithms, none of which shall be provided to Partner.
1.20 “Term” means collectively the Initial Term and the Renewal Term.
1.21 “Territory” means the geographic country or countries specified in the "Key Commercial Terms" section on the cover page of this Agreement.
2. TERM AND TERMINATION
2.1. Term. This Agreement will commence on the Effective Date, and will expire on the first anniversary of the Effective Date, unless earlier terminated by either party as provided in this Agreement (the “Initial Term”). Following the expiration of the Initial Term, this Agreement shall automatically renew for successive periods of one (1) year each subject to the notice and termination rights herein contained, unless either party provides the other party with thirty (30) days prior written notice of non-renewal (a “Renewal Term”).
2.2. Termination for Cause. Either party may terminate this Agreement for cause immediately upon written notice if: (a) the other party fails to cure any payment default within fifteen (15) days after receiving written notice of such non-payment; (b) the other party fails to perform any of its material obligations under this Agreement, and such failure continues uncured for thirty (30) days following written notice thereof; (c) the other party declares bankruptcy, is adjudicated bankrupt, or files a petition for reorganization under bankruptcy laws; or (d) a receiver or trustee is appointed for the other party or substantially all of its assets.
2.3. Effect of Termination. Upon termination or expiration of this Agreement:
a) All rights and licenses granted to Partner hereunder shall immediately terminate, and Partner shall cease all marketing, sale, and distribution of the Products.
b) All accrued and outstanding Fees shall become immediately due and payable by Partner to ThreatModeler.
c) Each party shall promptly return or, at the other party's request, destroy all Confidential Information of the other party in its possession and provide written certification of such destruction upon request.
2.4. Wind Down Period.
(a) Except in the case of termination by ThreatModeler for Partner's material breach, ThreatModeler shall, at Partner's election, cooperate in an orderly transition for any active End User contracts.
(b) ThreatModeler will continue to provide the Products and Services necessary to support such existing End User contracts for a transitional period of up to one (1) year ("Wind Down Period"), strictly conditioned upon Partner’s continued and timely payment of all applicable Fees and compliance with the terms of this Agreement.
(c) During the Wind Down Period, Partner's rights are limited to servicing existing End Users only; no new sales may be conducted. If the transition to a successor provider is not complete at the end of the Wind Down Period, Fees for any continued services shall be increased by one hundred percent (100%).
2.5. Survival. The termination or expiration of this Agreement shall not extinguish any rights or obligations that by their nature are intended to survive. The following sections shall survive any such termination or expiration: Section 1 (Definitions); Section 2.3 (Effect of Termination) and this Section 2.5 (Survival); Section 3 (Intellectual Property and License Rights); Section 5 (Ordering, Pricing and Payment), with respect to any accrued and unpaid Fees.; Section 6 (Records, Reporting, and Audit); Section 8 (Indemnification); Section 9.5 (Warranty Disclaimer); Section 10 (Confidentiality); Section 11 (Limitation of Liability); Section 12 (Data Protection) and Section 13 (General Provisions), particularly those related to Governing Law, Dispute Resolution, and Notices.
3. INTELLECTUAL PROPERTY AND LICENSE RIGHTS
3.1. ThreatModeler Ownership. ThreatModeler and its licensors retain all right, title, and interest in and to the Products, the ThreatModeler Marks, and all related Intellectual Property Rights. No rights are granted to Partner except as expressly set forth herein. For the avoidance of doubt, ThreatModeler shall solely own all intellectual property rights in any connectors, APIs, scripts, or interfaces developed by or on behalf of Partner that link to or interact with the Products. To the extent any such rights vest in Partner by law, Partner hereby irrevocably assigns all such right, title, and interest to ThreatModeler.
3.2. No Rights to Source Code. Partner acknowledges that it has no rights in or to the Source Code of any Product. Partner shall not, and shall not permit any third party to, create any derivative works, make translations of the Software, or disassemble, decompile, reverse assemble, reverse compile, recompile, or make extracts from the Software, or in any other way attempt to determine or derive the Source Code.
3.3. End User License Agreement (EULA) Mandate.
a) Obligation to Apply the Correct EULA. Partner acknowledges that different versions of the EULA apply to different End User types (e.g., commercial vs. governmental). Partner is responsible for identifying the End User type and ensuring that the correct and applicable version of the EULA is presented to and accepted by the End User.
b) Partner's Duty of Execution. For any transaction, Partner is required to either: (i) ensure the End User executes the applicable EULA prior to gaining access, or (ii) include the full terms of the applicable EULA within Partner's own binding agreement with the End User.
c) No Interference. Partner shall not interfere with any "click-through" or other mechanism designed to present and secure acceptance of the applicable EULA.
d) Material Breach. A failure to ensure an End User is legally bound by the terms of the applicable EULA constitutes a material breach of this Agreement.
3.4. Internal Use and Demonstration License (NFR).
ThreatModeler grants Partner a limited, non-exclusive, non-transferable, and non-sublicensable license to install and use the Products internally ("NFR License"). This NFR License is granted solely for the purposes of: (a) internal training of Partner's personnel; (b) demonstrating the Products to prospective End Users or Resellers; and (c) allowing evaluation of the Products by prospective End Users under Partner's supervision.
All use under this NFR License is strictly limited to non-production environments and shall not be used for any commercial purpose, including but not limited to, providing paid consulting, services, or risk assessments to any third party. All use remains subject to the terms of this Agreement, including the EULA compliance mandate set forth in Section 3.3.
4. TRADEMARKS AND MARKETING
4.1. Trademark License and Usage Guidelines.
a) Limited License. The trademarks, service marks, logos, and trade names under which ThreatModeler and its affiliates market the Products (collectively, the "ThreatModeler Marks", which explicitly include all trademarks and logos associated with both the ThreatModeler and IriusRisk brands) are the exclusive property of ThreatModeler or its licensors. This Agreement grants Partner a limited, non-exclusive, restricted, revocable, and non-sublicensable license to use the ThreatModeler Marks solely for the purpose of marketing and distributing the Products within the Territory as permitted herein.
b) Usage Requirements. Partner's usage of the ThreatModeler Marks must be in strict accordance with ThreatModeler’s then-current brand guidelines. Partner must submit each advertisement and promotional material to ThreatModeler for trademark review and written approval prior to its initial release. ThreatModeler may request, and Partner agrees to promptly provide, copies of any materials where the Marks have been used.
c) Goodwill. All goodwill associated with or created by Partner's use of the ThreatModeler Marks belongs exclusively to ThreatModeler, and Partner hereby assigns all such goodwill to ThreatModeler.
D) No Implied Rights. This Agreement gives Partner no rights in the ThreatModeler Marks, except for the limited license explicitly granted. All goodwill generated from Partner's use of the ThreatModeler Marks shall inure solely to the benefit of ThreatModeler.
4.2. Restrictions on Use of ThreatModeler Marks and Brand.
a) No Alteration or Misuse. Partner may not market the Products under any name other than those specified by ThreatModeler and shall not market its own Combined Offering under any name confusingly similar to a ThreatModeler Mark. Partner shall not exploit the ThreatModeler Marks for its own benefit or the benefit of any third party.
b) Domain Names. Partner agrees that its domain names will not contain the term "ThreatModeler". If Partner uses any ThreatModeler Mark in a domain name, upon ThreatModeler’s demand, Partner will immediately assign all rights in such domain name to ThreatModeler.
c) Website and Content Restrictions. Partner's website will not in any way copy content from, or resemble the look and feel of, the official ThreatModeler website. Partner shall not create the impression that its website is the ThreatModeler website or an official part of it. Specifically, Partner shall not:
i. Copy, co-brand, or frame the ThreatModeler website or have any portion of it visible within Partner's own website.
ii. Copy any content displayed on the ThreatModeler website without prior written permission.
d) Pricing Representation. Under no circumstances may any Partner website or other marketing collateral state or imply that ThreatModeler Products are available "on sale," at a "discount," or at a "% off" price different from ThreatModeler's official List Price. Partner determines its own final sale price to the End User, but shall not represent discounts as originating from ThreatModeler.
4.3. Public Announcements. Either party may make general statements confirming the existence of this partnership. However, any formal press releases or public relations announcements concerning this Agreement shall be mutually agreed upon by both parties in writing in advance.
5. ORDERING, PRICING AND PAYMENT
5.1. Ordering Process.
a) All purchases shall be governed by a final, binding transactional document ("Order"), as defined in Section 1. Partner typically initiates an Order by submitting a Purchase Order ("PO") based on a ThreatModeler-issued Quote.
b) A submitted PO shall only become binding upon ThreatModeler’s explicit written acceptance or upon Electronic Delivery of the ordered Products by ThreatModeler. Accepted POs become part of the final Order and are non-cancellable.
c) The terms of this Agreement and the applicable Order shall prevail over any conflicting or additional terms in Partner's PO or any other business form.
5.2. Pricing, Discounts, and Fees.
a) The final, binding prices, discounts, and fees ("Fees") for any transaction are those specified in the corresponding Order. These are generally based on ThreatModeler's then-current Price List.
b) ThreatModeler reserves the right to revise its List Price upon thirty (30) days' prior written notice. Any Order accepted by ThreatModeler prior to the effective date of a price increase will be honored at the old price.
5.3. Special Pricing.
ThreatModeler may, at its sole discretion, offer "Special Pricing" for specific opportunities. The terms of any such Special Pricing will be documented in the applicable Order and shall supplement, but not override, the other terms of this Agreement.
5.4. Invoicing and Payment.
a) ThreatModeler will invoice Partner upon availability of the ordered Products. All payments are due within thirty (30) days of the invoice date, free of any deductions or set-offs.
b) Payments shall be made in the currency specified in the Order (EUR by default) via wire transfer to the bank account designated by ThreatModeler.
c) Late Payments: Any undisputed past-due amounts shall accrue interest at the statutory late payment interest rate applicable under European commercial transaction regulations (Directive 2011/7/EU or applicable local laws, such as Spanish Law 3/2004 on Morosidad), plus any legally permitted flat-fee recovery costs.
d) Suspension for Non-Payment: In the event Partner's account is past due, ThreatModeler reserves the right, upon written notice, to place Partner on credit hold and suspend all Services, including access to Products and Support, until the account is settled.
5.5. Taxes.
a) All Fees are exclusive of any tax, levy, or similar governmental charge ("Taxes"). Partner is responsible for, and agrees to pay, all applicable Taxes, excluding only taxes based on ThreatModeler’s net income.
b) Partner agrees to indemnify ThreatModeler from any claim for Taxes demanded from ThreatModeler as a result of transactions under this Agreement. Partner shall provide valid tax exemption certificates upon request.
5.6. Delivery.
All Products will be made available to Partner electronically ("Electronic Delivery"). ThreatModeler will use commercially reasonable efforts to make Products available within five (5) business days of the effective date of the Order.
6. RECORDS, REPORTING, AND AUDIT
6.1. Record Keeping.
a) General Obligation: Partner agrees to maintain detailed and accurate books and records relating to the distribution, licensing, and support of the Products, including records of sales by End User, authorized user seats, tenant IDs, license activation keys, and/or Product deployment details.
b) Retention Period: Partner shall maintain these records during the Term of this Agreement and for a period of three (3) years following its termination or expiration.
6.2. Reporting.
a) General Reporting: Partner agrees to provide ThreatModeler with such sales and distribution information as ThreatModeler may reasonably request from time to time.
b) Notification of Claims: Partner will promptly notify ThreatModeler in writing (within five (5) business days) of any claim or proceeding initiated against Partner involving the Products, or of any claimed or suspected Product defects reported to Partner.
6.3. Audit Rights.
a) Right to Audit: ThreatModeler or its designated independent auditors may, upon thirty (30) days' prior written notice, inspect and audit all of Partner’s records specifically related to this Agreement to verify compliance with licensing metrics, user limits, and payment obligations.
b) Audit Procedure: Any such audit shall be permitted no more than once per calendar year, during normal business hours, and shall not unreasonably interfere with Partner's business activities.
c) Cost of Audit: The cost of the audit will be borne by ThreatModeler, unless the audit reveals a material discrepancy (defined as an underpayment of 5% or more of the amounts due to ThreatModeler), in which case the cost of the audit shall be borne by Partner.
d) Payment of Discrepancies: Any underpayment of Fees disclosed by an audit shall be paid by Partner to ThreatModeler immediately upon demand.
6.4. Excess Usage and True-Up.
a) Usage Monitoring: ThreatModeler shall have the right to electronically or physically monitor and audit the actual usage metrics of the Products (including but not limited to authorized user seats, active tenants, concurrent sessions, or deployment environments) by Partner and its End Users to ensure compliance with the purchased license limits specified in the applicable Order.
b) Excess Usage Billing ("True-Up"): If any monitoring, self-reporting, or audit reveals that Partner or any of its End Users has exceeded the purchased license limits, Partner shall immediately purchase additional licenses to cover such excess. ThreatModeler reserves the right to invoice Partner retroactively for all such excess usage at ThreatModeler’s then-current List Price (less any applicable partner discount) from the first date the excess usage commenced. Partner shall pay such invoice in accordance with Section 5 of this Agreement.
7. COMPLIANCE AND BUSINESS CONDUCT
7.1. Fair Business Practices and Pricing Freedom.
a) Partner agrees to conduct its business in a manner that reflects favorably upon the Products and the ThreatModeler brand, adhering to the highest ethical principles and complying with all applicable laws and regulations.
b) While ThreatModeler may provide a suggested retail price (List Price), Partner has sole and absolute discretion in determining its own resale prices to End Users or Resellers. No employee or representative of ThreatModeler has the authority to dictate Partner's pricing, and Partner agrees to promptly report any attempt to do so.
7.2. Anti-Corruption and Anti-Bribery.
a) Both parties agree to comply with all applicable anti-bribery and anti-corruption laws, including but not limited to the U.S. Foreign Corrupt Practices Act (FCPA), the UK Bribery Act 2010, the applicable anti-corruption Directives of the European Union (including Directive (EU) 2026/1021), and any similar national or local laws or regulations in the Territory.
b) Partner warrants that it will not, directly or indirectly, offer, pay, or promise anything of value to any government official (including any non-US or EU public official). For the purposes of this clause, "government official" includes officers of any government department or agency, persons officially acting on behalf of a government, employees of government-owned or controlled corporations, officials of political parties, and candidates for political office.
c) No payments or transfers of value shall be made which have the purpose or effect of public or commercial bribery, money laundering, extortion, or kickbacks to improperly influence a decision, obtain or retain business, or secure an improper advantage.
d) Partner represents and warrants that it has implemented and shall maintain robust internal policies, procedures, and controls to prevent and detect bribery, corruption, and money laundering.
e) A breach of this Section 7.2 is a material breach of this Agreement and gives ThreatModeler the right to terminate the Agreement immediately upon written notice.
7.3. Export Control and Distribution Compliance.
a) Export and Sanctions Regulations: Partner acknowledges that the Products are subject to the U.S. Export Administration Regulations (EAR) and the export control, dual-use, and trade sanctions regulations of the European Union (including Regulation (EU) 2021/821), Spain, and other applicable jurisdictions. Partner represents and warrants that it is not a restricted, sanctioned, or denied party under any U.S., EU, or United Nations trade blacklist, and that it will not transfer, resell, or divert the Products contrary to applicable export laws.
b) Prohibited End Uses: Partner represents that it will not use or knowingly transfer the Products for any end use related to nuclear, chemical, or biological weapons, or missile technology, unless specifically authorized by the U.S. Government.
c) Restrictions on Encryption: Partner understands that certain Products may contain encryption features. Partner agrees not to transfer, resell, or use such Products to provide services to "Government End Users" (as defined in Section 1) unless explicitly authorized to do so by the U.S. Bureau of Industry and Security (BIS) under regulation or a specific license.
d) Partner's Ultimate Responsibility: Partner acknowledges it is ultimately responsible for its own compliance with all applicable import, export, and other laws.
8. INDEMNIFICATION
8.1. Indemnification by ThreatModeler.
a) Subject to the limitations set forth in Section 11 (Limitation of Liability) and this Section 8, ThreatModeler will defend, indemnify, and hold harmless Partner from and against any direct, third-party claim, suit, or action alleging that the Product, as delivered by ThreatModeler, infringes a valid patent registered in the European Union, or any copyright or trademark of such third party.
b) Remediation Rights: If the Product becomes, or in ThreatModeler's opinion is likely to become, the subject of an infringement claim, ThreatModeler may, at its sole option and expense: (i) procure for Partner the right to continue using the Product; (ii) replace or modify the Product to make it non-infringing without materially reducing its functionality; or (iii) if options (i) and (ii) are not commercially reasonable, terminate Partner's rights to the infringing Product and provide a pro-rata refund of any prepaid, unused fees for that Product.
c) Exclusions: ThreatModeler shall have no liability under this section for any claim arising from: (i) the use of an older version of the Product if infringement would have been avoided by using a current version made available to Partner; (ii) the combination of the Product with non-ThreatModeler software, data, hardware, or artificial intelligence models not specified or approved by ThreatModeler in writing; (iii) any modification of the Product not performed by ThreatModeler; (iv) any training data, Inputs, prompt designs, or specifications provided by Partner or its End Users to the Products; or (v) any claims where Partner failed to take commercially reasonable steps to mitigate its damages.
d) Liability Cap for IP Claims: Notwithstanding anything to the contrary in this Agreement, ThreatModeler's total aggregate liability for indemnification claims under this Section 8.1 shall be strictly limited to the total net Fees actually paid by Partner to ThreatModeler during the twelve (12) months immediately preceding the event giving rise to the claim.
e) Entire Liability: This Section 8.1 states ThreatModeler's entire liability and Partner's sole and exclusive remedy for intellectual property infringement claims.
8.2. Indemnification by Partner.
Partner will defend, indemnify, and hold harmless ThreatModeler from and against any third-party claim, suit, or action arising from: a) A claim that Partner's own separate products or marketing collateral infringes the intellectual property rights of a third party; b) The modification of the Product by Partner, or the combination of the Product with non-ThreatModeler products, if the claim would have been avoided but for such modification or combination; c) Any representation, warranty, or contractual commitment made by Partner to an End User that is in excess of, or inconsistent with, the terms of the EULA and the official Documentation; d) Any breach by Partner of its obligations under Section 7 (Compliance and Business Conduct) of this Agreement; or e) Any security incident, data breach, or unauthorized access to personal data or End User systems, to the extent caused by: (i) Partner’s negligent hosting, management, or operation of the Products, or (ii) Partner’s failure to implement mandatory security updates or patches provided by ThreatModeler.
8.3. Indemnification Procedure.
The indemnifying party's obligations are conditioned upon the indemnified party: a) providing written notice of the claim within ten (10) business days of receiving formal service or notice of the claim (provided that any delay in notification shall only relieve the indemnifying party of its obligations hereunder to the extent such delay materially prejudices the defense or settlement of the claim); b) granting the indemnifying party sole control of the defense and all related settlement negotiations; and c) providing the indemnifying party with the reasonable assistance, information, and authority necessary to perform its obligations. The indemnified party may participate in the defense with its own counsel at its own expense. The indemnifying party will not agree to any settlement that admits fault or imposes a non-monetary or material financial obligation on the indemnified party without its prior written consent.
9. REPRESENTATIONS AND WARRANTIES
9.1. Mutual Representations. Each party represents and warrants to the other that it has the full power and authority to enter into and perform its obligations under this Agreement.
9.2. ThreatModeler's Limited Warranty.
a) Performance Warranty: ThreatModeler warrants only to Partner that, for a period of ninety (90) days from its initial delivery, the Software will substantially conform to its applicable Documentation.
b) Exclusive Remedy: If Partner provides a written report detailing a substantial non-conformity during the warranty period, ThreatModeler's sole obligation, and Partner's sole and exclusive remedy, will be for ThreatModeler to use commercially reasonable efforts to correct the non-conformity. ThreatModeler makes no warranty that all errors or failures will be corrected.
c) Warranty to Partner Only: The warranty provided herein is for the sole benefit of Partner. Partner has no authority to extend this warranty to any End User or any other third party. The End User's warranty is governed exclusively by the EULA.
9.3. Partner's Warranty. Partner represents and warrants that it will perform its obligations under this Agreement (including any support services provided by Partner) in a professional and workmanlike manner, consistent with industry standards, and that its own products and services do not infringe upon the intellectual property rights of any third party.
9.4. Restriction on Use with Open Source Software. Unless expressly permitted elsewhere, Partner shall not combine or distribute the Product with any "Open Source Software" (e.g., software licensed under the GPL or other "copy-left" licenses) in a manner that would subject the Product to the license obligations of such Open Source Software, such as requiring the disclosure of its source code.
9.5. WARRANTY DISCLAIMER.
EXCEPT FOR THE EXPRESS LIMITED WARRANTIES SET FORTH IN SECTION 9.2, THE PRODUCTS AND SERVICES ARE PROVIDED "AS IS." TO THE MAXIMUM EXTENT PERMITTED BY LAW, THREATMODELER AND ITS SUPPLIERS EXPRESSLY DISCLAIM ALL OTHER WARRANTIES AND REPRESENTATIONS OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. WITHOUT LIMITING THE FOREGOING, THREATMODELER MAKES NO REPRESENTATION OR WARRANTY REGARDING: (A) THE ACCURACY, COMPLETENESS, RELIABILITY, OR OUTCOMES OF ANY ANALYSES, RECOMMENDATIONS, OR OUTPUTS GENERATED BY THE ARTIFICIAL INTELLIGENCE OR MACHINE LEARNING ENGINE INTEGRATED WITHIN THE PRODUCTS (ALL OF WHICH ARE DESIGNED TO SUPPLEMENT, NOT REPLACE, PROFESSIONAL HUMAN SECURITY AUDITS); OR (B) THAT THE PRODUCTS WILL BE COMPLETELY SECURE OR FREE FROM COMPROMISE. THREATMODELER SHALL NOT BE LIABLE FOR DELAYS, INTERRUPTIONS, OR SERVICE FAILURES INHERENT IN THE USE OF THE INTERNET AND ELECTRONIC COMMUNICATIONS OR OTHER SYSTEMS OUTSIDE OF THREATMODELER'S REASONABLE CONTROL.
10. CONFIDENTIALITY
10.1. Definition of Confidential Information.
a) For the purposes of this Agreement, "Confidential Information" means any information disclosed by one party ("Disclosing Party") to the other party ("Receiving Party") that is either marked as "Confidential" or which, given its nature or the circumstances of its disclosure, should reasonably be considered confidential. This includes, but is not limited to: business plans, marketing and sales data, technical and developmental information, source code, and any non-public performance or pricing information related to the Products.
b) Automatic Confidentiality and Trade Secret Status: The technology, architecture, methodology, algorithms, AI models, performance telemetries, and API specifications of the ThreatModeler Products shall be deemed the Confidential Information and trade secrets of ThreatModeler without any marking or further designation, and shall receive the maximum protection under applicable Trade Secret laws (including the Spanish Law on Trade Secrets, as applicable).
10.2. Obligations of the Receiving Party.
a) Duty of Care: The Receiving Party agrees to hold the Disclosing Party's Confidential Information in strict confidence. The Receiving Party will use the same degree of care it uses to protect its own confidential information of a similar nature, but in no event less than a reasonable degree of care.
b) Use and Disclosure: The Receiving Party will not use the Confidential Information for any purpose outside the scope of this Agreement and will not disclose it to any third party, except to its employees, contractors, and legal/financial advisors who have a need to know and who are bound by confidentiality obligations at least as protective as those herein.
10.3. Exclusions. The obligations in Section 10.2 will not apply to any information that the Receiving Party can document: a) Was rightfully in its possession or known to it prior to receipt from the Disclosing Party; b) Is or has become public knowledge through no fault of the Receiving Party; c) Is rightfully obtained by the Receiving Party from a third party without a breach of any confidentiality obligation; or d) Was independently developed by employees of the Receiving Party who had no access to the Confidential Information.
10.4. Compelled Disclosure. If the Receiving Party is required to disclose Confidential Information by law, regulation, or court order, it will, to the extent legally permissible, provide the Disclosing Party with prompt prior written notice to allow the Disclosing Party an opportunity to seek a protective order. The disclosure shall be limited to the minimum extent required to comply.
10.5. Injunctive Relief. Each party acknowledges that any unauthorized disclosure of Confidential Information would cause substantial harm for which monetary damages alone would be an insufficient remedy. Therefore, upon any such breach, the Disclosing Party shall be entitled to seek immediate injunctive relief, in addition to any other remedies it may have at law, without the necessity of posting any bond or proving actual damages.
11. LIMITATION OF LIABILITY
11.1. Disclaimer of Consequential Damages. TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY (NOR ITS SUPPLIERS) SHALL BE LIABLE FOR ANY LOSS OF USE, LOST PROFITS, LOST DATA, BUSINESS INTERRUPTION, OR ANY INDIRECT, SPECIAL, INCIDENTAL, OR CONSEQUENTIAL DAMAGES OF ANY KIND, REGARDLESS OF THE FORM OF ACTION, WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), OR OTHERWISE, EVEN IF INFORMED OF THE POSSIBILITY OF SUCH DAMAGES IN ADVANCE.
11.2. Liability Cap. TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY'S TOTAL AGGREGATE LIABILITY TO THE OTHER UNDER THIS AGREEMENT SHALL NOT EXCEED THE TOTAL FEES ACTUALLY PAID BY PARTNER TO THREATMODELER DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE FIRST EVENT GIVING RISE TO THE CLAIM.
11.3. Exclusions from Limitations. THE LIMITATIONS AND EXCLUSIONS IN SECTIONS 11.1 AND 11.2 SHALL NOT APPLY TO: a) Partner’s indemnification obligations under Section 8.2 (Indemnification by Partner), or ThreatModeler’s indemnification obligations under Section 8.1 (which shall remain strictly capped under the specific liability limit set forth in Section 8.1(d)); b) Partner’s breach of Section 7 (Compliance and Business Conduct); c) Partner’s breach of Section 3 (Intellectual Property and License Rights), or either Party's misappropriation of the other Party’s trade secrets (as defined in Section 10.1(b)); d) Any Fees owed by Partner to ThreatModeler under this Agreement; e) Liability arising from a party's fraud, gross negligence, or willful misconduct; or (f) Liability for death or personal injury caused by a party's negligence, or any other liability that cannot be excluded or limited under applicable mandatory laws.
12. DATA PROTECTION
12.1. General Principles and Roles.
a) Each party agrees to comply with its respective obligations under all applicable data protection laws, with particular emphasis on the EU's General Data Protection Regulation (GDPR) for all activities within the European Economic Area.
b) This section governs the processing of "Personal Data" (or "Personal Information" as defined under applicable laws) and distinguishes between three primary processing relationships under this Agreement.
12.2. Relationship Data (Controller-to-Controller).
a) For the purpose of managing the business relationship created by this Agreement, each party may process business contact information of the other party's employees and representatives.
b) In this context, the parties act as independent Data Controllers for their own processing activities.
12.3. Lead Data for Referrals (Controller-to-Controller).
a) When a Partner, acting in the "Referral Partner" role, submits a sales lead to ThreatModeler, the parties acknowledge this constitutes a data sharing event.
b) For this specific activity, Partner (as the disclosing party) and ThreatModeler (as the receiving party) act as independent Data Controllers. Partner warrants that it has a lawful basis to share such Personal Data with ThreatModeler for ThreatModeler's own direct sales and marketing purposes.
12.4. End User and Service Data (Controller-to-Processor).
a) General Principle: For any Personal Data processed by ThreatModeler in the course of providing the Products and Support Services on behalf of a Partner or its End Users, the Partner (or its End User) acts as the Data Controller, and ThreatModeler acts as the Data Processor (or "Service Provider" under U.S. laws).
b) Data Processing Addendum (DPA): This Processor-Controller relationship is governed by ThreatModeler's then-current Data Processing Addendum ("DPA"), which is incorporated into this Agreement by reference. The DPA is available on ThreatModeler's legal website (currently at threatmodeler.ai/legal/dpa) and specifies ThreatModeler's obligations regarding data security, subprocessors, data subject rights, and international transfers.
c) Partner's Obligation: In any scenario where this relationship applies, Partner agrees to be bound by the terms of the applicable DPA.
12.5. DPA Updates.
ThreatModeler may update the DPA from time to time to reflect changes in law, regulations, or its data processing operations. ThreatModeler will provide Partner with notice of any material changes. Partner's continued relationship with ThreatModeler after such notice will constitute acceptance of the updated terms.
13. GENERAL PROVISIONS
13.1. Relationship of the Parties. The relationship of the parties is that of independent contractors. Nothing in this Agreement shall be construed as creating any agency, partnership, joint venture, or employer-employee relationship. Neither party has any authority to bind the other in any respect whatsoever.
13.2. Assignment. Neither party may assign or transfer this Agreement, in whole or in part, without the prior written consent of the other party. Notwithstanding the foregoing, either party may assign this Agreement without consent in connection with a merger, acquisition, or sale of all or substantially all of its assets, provided that the assigning party provides prompt written notice to the other party and the assignee agrees in writing to be bound by the terms of this Agreement.
13.3. Notices.
a) Method and Address. All notices and other communications required under this Agreement must be in writing and sent by email. Notices to ThreatModeler shall be sent to legal@threatmodeler.com. Notices to Partner shall be sent to the primary email address specified on the cover page of this Agreement.
b) Deemed Delivery. A notice sent by email will be deemed to have been duly given on the business day it is sent, provided that the sender does not receive a system-generated error message indicating that the email was not delivered.
c) Change of Address. Each party may change its designated email address for receiving notices by providing at least five (5) business days' prior written notice to the other party in accordance with this section. It is each party's responsibility to ensure its designated email address is current and operational.
13.4. Governing Law and Jurisdiction.
This Agreement and any dispute, controversy, or claim arising out of or in connection with it, its subject matter, or its formation shall be governed by and construed in accordance with the laws of Spain. The Parties hereby irrevocably submit to the exclusive jurisdiction of the courts of the city of Madrid, Spain, for the resolution of any dispute arising under or in connection with this Agreement
13.5. Dispute Resolution. Prior to initiating any litigation, the parties agree to first attempt to resolve any dispute arising out of this Agreement informally. A party will initiate this process by providing written notice to the other. Each party will promptly designate a senior executive with authority to resolve the dispute. If the dispute is not resolved through negotiation within thirty (30) days, either party may then pursue legal remedies. This clause does not prevent either party from seeking immediate injunctive relief.
13.6. Force Majeure. Neither party shall be liable for any failure or delay in performing its obligations (except for payment obligations) due to causes beyond its reasonable control, including but not limited to acts of God, war, strikes, or natural disasters ("Force Majeure Event"). The affected party will provide prompt notice and use commercially reasonable efforts to resume performance.
13.7. Insurance.
a) Obligation to Maintain Coverage. During the Term of this Agreement and for one (1) year thereafter, each party shall, at its own expense, obtain and maintain the following insurance coverage from insurers with a Best's rating of A-, VII or better:
i. Commercial General Liability insurance, written on an occurrence form, including coverage for product and completed operations, personal and advertising injury, and contractual liability. Limits shall be no less than €1,000,000 EUR per occurrence and €2,000,000 EUR in the general aggregate. This policy shall include an endorsement naming the other party as an additional insured.
ii. Umbrella or Excess Liability insurance with a limit of no less than €3,000,000 EUR per occurrence and in the aggregate.
iii. Workers' Compensation insurance with statutory limits as required by law, including a waiver of subrogation in favor of the other party.
iv. Professional Liability / Errors & Omissions insurance, covering liabilities arising from technology services and products, with a limit of no less than €1,000,000 EUR per claim.
b) Policy Requirements. A party's required insurance shall be primary with respect to its obligations under this Agreement. The policy limits shall not be construed as a limitation of a party's liability under this Agreement. Neither party shall cancel, or allow to expire, or materially change its insurance policies without providing the other party with at least thirty (30) days' prior written notice.
c) Evidence of Insurance. Upon execution of this Agreement and at each subsequent renewal, each party shall, upon request, provide the other with a certificate of insurance evidencing the coverage required herein and confirming the additional insured status and waiver of subrogation.
13.8. Entire Agreement and Order of Precedence.
a) Entire Agreement: This Agreement, including all applicable Special Terms, all Exhibits, and all executed Orders, constitutes the complete and entire agreement between the parties regarding its subject matter. It supersedes all prior or contemporaneous understandings, oral or written. This Agreement may only be amended by a written document signed by authorized representatives of both parties.
b) Order of Precedence: In the event of any direct conflict between the terms of the documents comprising this Agreement, the following order of precedence will apply, with the document higher in the list controlling over the one lower in the list:
- The applicable Order
- The applicable Special Terms
- The Exhibits
- These General Terms and Conditions
c) Prevalence over Partner Forms: For clarity, the terms of this Agreement (including any Order) shall prevail over any pre-printed, conflicting, or additional terms contained in any Partner-issued Purchase Order or other business form, and any such terms are hereby rejected and shall be void.
13.9. Severability. If any provision of this Agreement is found to be unenforceable or invalid, that provision will be limited or eliminated to the minimum extent necessary so that this Agreement will otherwise remain in full force and effect and enforceable.
13.10. No Waiver. The failure of a party to exercise a right or to require performance of an obligation under this Agreement shall not be a waiver of that party's right to exercise that right or require such performance at any time thereafter.
13.11. European Agency Law Disclaimer. The parties expressly agree that their relationship is that of independent seller and buyer. This Agreement shall not be construed as creating an agency relationship under the laws of any European jurisdiction, including but not limited to the Spanish Law 12/1992 on Agency Contracts or similar national implementations of the EU Directive 86/653/EEC. Partner acknowledges that it is not entitled to, and expressly waives to the maximum extent permitted by law, any right to claim compensation or indemnity for goodwill or client portfolio upon the termination or expiration of this Agreement.
SPECIAL TERMS
A. RESELLER TERMS
If the "Reseller" role is selected, the following terms apply:
1. Appointment and Status
1.1. Appointment. Subject to the terms of this Agreement, ThreatModeler grants Partner the non-exclusive, non-transferable right to market and resell the Products directly to End Users within the Territory. Partner shall resell the Products strictly on a transactional, back-to-back basis, and each order must be registered to a single, specific, and authorized End User at the time of purchase. Partner is strictly prohibited from reselling Products to any third-party reseller or purchasing Products for inventory, general stocking, or future redistribution without ThreatModeler's prior written consent.
1.2. Independent Reseller Status. Partner shall act as an independent reseller, at its own risk and expense. Partner is solely responsible for its business activities and unilaterally determines its own resale prices to End Users. Nothing in this Agreement prohibits ThreatModeler from making direct sales to any End User, with or without Partner involvement.
1.3. No Sub-Agents. Partner shall not appoint any sub-distributors, agents, or other third parties to exercise its resale rights without the prior written consent of ThreatModeler.
2. Partner's Obligations and Performance
2.1. Marketing and Ethical Conduct. Partner shall use commercially reasonable efforts to market and promote the Products. Partner must comply with the highest ethical principles in all its dealings.
2.2. No Unauthorized Warranties. Partner shall not make any representations or warranties on behalf of ThreatModeler with respect to the Products that are in excess of, or inconsistent with, the official Documentation and the EULA.
2.3. Accreditation and Training. Partner agrees to achieve and maintain the accreditation and training requirements for sales and technical personnel as set forth by ThreatModeler on its Partner Portal or other designated communication method from time to time.
2.4. EULA Compliance. Partner's obligation to ensure each End User executes the EULA is a material obligation of this role. Partner shall not modify, alter, or obscure any license agreements included with the Products.
2.5. Sales Reporting. Partner agrees to provide ThreatModeler with such sales and End User information as ThreatModeler may reasonably require from time to time for the purpose of order fulfillment and market analysis.
3. ThreatModeler's Obligations
3.1. Provision of Materials. ThreatModeler will make available to Partner, via the Partner Portal or other designated communication method, the necessary sales and marketing materials, Documentation, and standard installation kits to enable Partner to market and sell the Products.
3.2. Notice of Changes. ThreatModeler will use commercially reasonable efforts to provide Partner with at least thirty (30) days' notice of any material changes to the Products or to the List Price.
3.3. Product Training. ThreatModeler will provide access to training programs for Partner's personnel, which may be delivered by ThreatModeler or a designated third party.
4. Purchasing and Pricing
4.1. Purchasing Channels. Partner will purchase Products for resale either (i) directly from ThreatModeler, or (ii) from a ThreatModeler authorized distributor ("Distributor"). ThreatModeler reserves the right, upon notice, to transition Partner to a two-tier model where purchases must be made exclusively through an authorized Distributor.
4.2. Direct Purchase Process. For purchases made directly from ThreatModeler, Partner will submit a Purchase Order (PO) in response to a Quote, as detailed in Section 5 of the General Terms. For the avoidance of doubt, Partner's obligation to pay ThreatModeler under this Agreement is absolute, and is not conditioned upon, linked to, or delayed by Partner's actual collection of payments or fees from its End Users.
4.3. Incentive Programs. ThreatModeler may, at its discretion, offer marketing and incentive programs, such as Rebates. Partner's participation in any such program is subject to its compliance with the specific program requirements.
4.4. Pricing and Discounts. The pricing and discounts applicable to Partner for any given transaction shall be as specified in the corresponding Order.
5. Support Model
5.1. Support Framework. The specific support model for each transaction shall be specified in the applicable Order. The operational details, including service levels and escalation procedures, are governed by the Partner Support Program..
5.2. Partner-Led Support (Default Model). Unless otherwise specified, Partner is responsible for providing Tier 1 Support to its End Users. For the purposes of this Agreement, "Tier 1 Support" means acting as the initial point of contact for the End User, performing initial problem diagnosis, and resolving basic technical issues.
5.3. ThreatModeler-Led Support (Alternative Model). If explicitly specified in the Order, ThreatModeler will provide all tiers of support (Tier 1, 2, and 3) directly to the End User. In this scenario, Partner's discount on the transaction will be adjusted accordingly to reflect the reduced operational cost for the Partner.
B. DISTRIBUTOR TERMS
If the "Distributor" role is selected, the following terms apply:
1. Appointment and Status
1.1. Appointment. Subject to the terms of this Agreement, ThreatModeler grants Partner the non-exclusive, non-transferable right to market and distribute the Products solely to Resellers within the Territory who have been explicitly approved in writing by ThreatModeler (each, an "Authorized Reseller"). Partner shall not sell, license, or distribute the Products to any unapproved reseller, commercial intermediary, or end-user directly without ThreatModeler’s prior written consent.
1.2. No Direct Sales to End Users. Partner is not authorized to sell Products directly to End Users. All sales must be conducted through Partner's network of Resellers.
1.3. Independent Distributor Status. Partner acts as an independent distributor, at its own risk and expense, and unilaterally determines its own resale prices and commercial terms with its Resellers.
1.4. No Exclusivity. ThreatModeler reserves the right to make direct sales to any party and to appoint other distributors. Partner is permitted to distribute competing products.
2. Reseller Network Management
2.1. Authorization and Onboarding. Partner is responsible for recruiting, onboarding, and managing its network of Resellers. All Resellers must be approved by ThreatModeler and must agree to comply with ThreatModeler's channel policies, communicated via the Partner Portal, direct email, or other designated Communication Method.
2.2. Flow-Down of Obligations. Partner must have a binding written agreement with each of its Resellers that contractually obligates the Reseller to comply with all relevant terms of this Agreement, including but not limited to the EULA compliance mandate (Section 3.3), all Compliance and Business Conduct rules (Section 7), and all Intellectual Property and License Restrictions (Section 3).
2.3. Partner Liability. Partner remains fully liable to ThreatModeler for any breach of the terms of this Agreement caused by the acts or omissions of any Reseller within its network.
3. Marketing and Business Development
3.1. Marketing Efforts. Partner will use commercially reasonable efforts to market the Products to its Reseller network, which includes providing a sufficient number of trained sales representatives and appointing a marketing manager focused on the ThreatModeler product line.
3.2. Marketing Plan and Reviews. Partner shall submit an annual marketing plan to ThreatModeler for approval and will meet with ThreatModeler on a quarterly basis to review business performance.
3.3. Marketing Programs (MDF & Rebates). ThreatModeler may, at its discretion, establish Market Development Fund (MDF) or rebate programs, which will be governed by the then-current program guidelines.
4. Reporting, Records, and Audit
4.1. Point-of-Sale (POS) Reporting. Partner must provide ThreatModeler with standard monthly POS reports by the fifth (5th) business day of each month, detailing the Products sold, the purchasing Reseller, and the final End User information.
4.2. Record Keeping. Partner will keep full and accurate books of account and records related to this Agreement (including POs, Invoices, Debit/Credit Memos, and POS reports) for three (3) years after the end of each calendar quarter.
4.3. Mutual Audit Rights. Each party may, once per calendar year upon thirty (30) days' notice, audit the records of the other party specifically related to this Agreement to ensure compliance. The cost of the audit will be borne by the requesting party.
5. Purchasing, Payment and Credit Management
5.1. Purchasing Process. The general process for ordering, pricing, invoicing, payment, and delivery of Products is governed by Section 5 of the General Terms. Distributor's obligation to pay ThreatModeler under this Agreement is absolute, and is not conditioned upon, linked to, or delayed by Distributor's actual collection of payments or fees from its Resellers.
5.2. Credit and Debit Management.
a) Partner may issue a debit memo for undisputed credits owed by ThreatModeler (e.g., for approved rebates). Partner must provide reasonable documentation ("Required Debit Documentation") to support the claim.
b) A debit memo shall be deemed accepted by ThreatModeler unless ThreatModeler disputes it in writing within thirty (30) days of receiving the Required Debit Documentation.
c) Any claim for a credit or billing adjustment by either party shall be forfeited if not submitted within one (1) year of the event that led to the claim.
6. Support Model
6.1. Support Framework. Partner is responsible for providing Tier 1 support to its Resellers. The Resellers are then responsible for providing Tier 1 support to their End Users.
6.2. Escalation. Partner acts as the single point of contact for escalating support issues from its Reseller network to ThreatModeler, as governed by the Partner Support Program.
C. REFERRAL PARTNER TERMS
If the "Referral Partner" role is selected, the following terms apply:
1. Definitions for this Section
1.1. "Account" means the specific customer entity identified in an accepted Lead Registration Form who procures Products directly from ThreatModeler as a result of Partner's referral activities.
1.2. "Opportunity" means the specific, initial sales opportunity for the procurement of Products by an Account, as proposed by Partner and accepted by ThreatModeler. Unless otherwise stated in the Lead Registration Form, this does not include any follow-on, renewal, or additional sales to the Account.
1.3. "Lead Registration Form" means the official document or electronic form provided by ThreatModeler, which must be completed by Partner for each Opportunity to qualify for a Referral Fee.
1.4. "Referral Fee" means the commission payable to Partner for a successful Opportunity, calculated in accordance with these terms.
2. Program Description and Lead Process
2.1. Independent Contractor Status (No Agency). Partner acts solely as an independent contractor. Nothing in this Agreement creates a partnership, joint venture, or agency relationship. Partner has no authority to bind ThreatModeler in any way. The parties expressly agree to exclude this Agreement from the scope of any applicable agency laws.
2.2. Program Participation. Partner shall be subject to any program and accreditation requirements as set forth on the Partner Portal (when available). Partner shall bear all its own costs for fulfilling its responsibilities hereunder.
2.3. Lead Submission and Privacy Warranty: Upon identifying a prospective Opportunity, Partner must submit a Lead Registration Form to ThreatModeler via the Partner Portal, or via email to ThreatModeler's partner management team if the online Portal is not yet available. Prior to submitting any Lead Registration Form, Partner represents and warrants that it has: (a) complied with all Applicable Data Protection Laws, (b) provided all necessary privacy notices to the contact person, and (c) obtained all required consents to share such contact details with ThreatModeler for direct marketing purposes.
2.4. Lead Acceptance and Duplication Rule: ThreatModeler may, in its sole discretion, accept or reject any submitted Lead Registration Form and will notify Partner of its decision. ThreatModeler has no obligation to Partner for a rejected Lead. If multiple partners register the same prospective Account or Opportunity, ThreatModeler shall only recognize the lead of the partner whose Lead Registration Form was first accepted in writing by ThreatModeler ("first-come, first-served" rule).
2.5. Exclusions. No Referral Fee shall be payable for any transaction with any public sector, governmental, or state-owned entities, or where paying such a fee would violate applicable law, procurement regulations, anti-bribery laws, or Section 7.2 of this Agreement.
3. Referral Fee Calculation and Payment
3.1. Calculation of Fee. The Referral Fee is calculated as a percentage of the net new license or subscription fees actually collected by ThreatModeler from the Account for the initial Opportunity only... The specific percentage is defined in the Referral Fee Schedule provided by ThreatModeler to Partner in writing (via email or as an exhibit to the applicable Order Form) or hosted on the Partner Portal (when available).
3.2. Eligibility and Timeframe. A Referral Fee is earned only if a definitive sales contract is signed between ThreatModeler and the Account within six (6) months of ThreatModeler's acceptance of the Lead Registration Form.
3.3. Payment Terms. ThreatModeler shall pay the earned Referral Fee to Partner within thirty (30) days after receiving payment in full from the Account for the applicable Products. The Referral Fee represents the full and only compensation due to Partner for the Opportunity.
3.4. Fee Adjustments. Prior to consummating a sale, ThreatModeler may request in writing a reduction in the Referral Fee to facilitate the deal. If Partner rejects such a request, ThreatModeler, in its sole discretion, may decide not to proceed with the sale, in which case no Referral Fee will be payable.
3.5. Refunds ("Clawback"). If ThreatModeler issues a refund to an Account for any reason, Partner shall refund to ThreatModeler the applicable portion of the Referral Fee within thirty (30) days of ThreatModeler's request. ThreatModeler may also offset this amount against any future fees owed to Partner.
3.6. Termination of a Specific Opportunity. ThreatModeler may terminate its pursuit of an accepted Opportunity if it determines, in its sole discretion, that the Account has inadequate credit, has committed to another vendor, or if other material conditions have changed. In such a case, no Referral Fee will be payable.
D. MSP / HOSTING PARTNER TERMS
If the "MSP / Hosting Partner" role is selected, the following terms apply:
1. Appointment and Service Model
1.1. Appointment. Subject to the terms of this Agreement, ThreatModeler grants Partner the non-exclusive, non-transferable right to provide managed and/or hosting services that include the Products ("Managed Service") to End Users within the Territory.
1.2. Service Model: The specific service model for each End User engagement shall be designated in the applicable Order:
a) "Partner-Hosted" Model: Partner is granted a limited, non-transferable license to install and operate the Products strictly on its own or secure third-party controlled infrastructure to deliver the Managed Service to End Users.
b) "ThreatModeler-Hosted" Model: Partner is appointed to market and manage the provision of ThreatModeler's standard SaaS Products to End Users. In any scenario where ThreatModeler processes Personal Data on behalf of the Partner or its End Users, the relationship shall be governed by ThreatModeler's then-current Data Processing Addendum ("DPA"), as further detailed in the General Terms.
2. Partner's Service Delivery and Commercial Obligations
2.1. Primary Point of Contact. Partner agrees that for any End User receiving a Managed Service, the Partner is the sole and primary point of contact. All End Users are Partner's customers. Partner is solely responsible for all commercial interactions (contracting, invoicing, fee collection) and all technical interactions (onboarding, configuration, and Tier 1 & 2 support).
2.2. Support Obligations. Partner is responsible for providing Tier 1 and Tier 2 support to its End Users. Escalation of support issues to ThreatModeler is governed by the Partner Support Program.
2.3. Marketing and Promotion. Partner shall use commercially reasonable efforts to market the Managed Service and is responsible for all its own costs.
3. License, EULA, and Service Restrictions
3.1. License Ownership and Usage Limitations: For both service models, Partner must hold the Product licenses solely in its own name. Licenses procured for a Managed Service cannot be transferred or assigned to an End User. Partner shall only deploy and use the Products for the purpose of active, value-add Managed Services. Partner is strictly prohibited from reselling or distributing the Products on a stand-alone, license-only basis to any End User under the guise of an MSP model.
3.2. EULA Compliance. Partner must ensure that each End User is legally bound by the terms of ThreatModeler's then-current EULA, prior to being granted access to the Managed Service. This can be achieved by having the End User execute the EULA directly or by incorporating its full terms into Partner's own binding agreement with the End User. A failure to comply with this clause is a material breach of this Agreement.
3.3. General Restrictions. Partner shall not, and shall not permit its End Users or any third party to:
a) Copy or reproduce the Products, except as strictly necessary to provide the Managed Service.
b) Modify, create derivative works from, or in any way alter the Products or their source code.
c) Disassemble, decompile, or reverse engineer the Software or otherwise attempt to gain access to the source code.
3.4. No Stand-alone Distribution. The Products may only be delivered as an integrated part of the Managed Service.
3.5. End User Breach. If an End User materially breaches its agreement with Partner or the EULA, Partner shall promptly notify ThreatModeler. If such breach is not cured, ThreatModeler reserves the right to suspend or terminate the provision of the underlying Products for that specific End User, with no liability to Partner or the End User.
4. Terms Specific to the "Partner-Hosted" Model
4.1. Hosting and Service Level Obligations. Partner agrees that its hosting environment must, at a minimum, meet or exceed the standards and service levels detailed in ThreatModeler's public-facing terms for its own SaaS offering, located at threatmodeler.ai/legal/eula.
4.2. Third-Party Software Indemnity.
a) Acknowledgement of Risk: Partner understands and acknowledges that the Products may include embedded software from Third-Party Vendors. The use of such software in a multi-tenant commercial hosting environment may be prohibited or require additional licenses and fees.
b) Partner's Responsibility to Secure Rights: Partner’s purchase of the Product does not grant it any rights to use such embedded third-party software for a multi-tenant Managed Service. Partner is solely responsible for obtaining any and all necessary approvals and licenses from the respective Third-Party Vendors. ThreatModeler will provide commercially reasonable assistance to Partner in this effort.
c) Indemnification by Partner: Partner shall defend, indemnify, and hold harmless ThreatModeler from any and all liability, damages, costs, and legal fees arising from a claim related to Partner's use of such embedded software. This includes claims from: (i) Partner’s failure to obtain necessary approvals; (ii) Partner’s failure to comply with third-party agreements; or (iii) any use of the third-party software by or on behalf of Partner's End Users.
d) Indemnification Procedure: ThreatModeler will promptly notify Partner of any such claim. Partner shall have sole control of the defense and all related settlement negotiations, provided that Partner shall not agree to any settlement that admits fault or imposes obligations on ThreatModeler without ThreatModeler’s prior written consent.
E. STRATEGIC / OEM PARTNER TERMS
If the "Strategic / OEM Partner" role is selected, the following terms apply:
1. Appointment and Grant of Rights
1.1. Appointment. Subject to the terms of this Agreement, ThreatModeler grants Partner the non-exclusive, non-transferable right to integrate the Products with Partner's own distinct products or services ("Partner Separate Product") to create a single, unified solution ("Combined Offering") for sale to End Users within the Territory.
1.2. License Grant for Integration. For the sole purpose of creating and supporting the Combined Offering, Partner is granted a limited, non-transferable license to use, copy, and reproduce the Products as technically necessary to bundle and integrate them as an inseparable component of the Combined Offering.
1.3. Independent OEM Status. Partner acts as an independent original equipment manufacturer (OEM). Partner is solely responsible for all aspects of its Combined Offering, including its final pricing, marketing, and sales strategy.
2. Intellectual Property, Brand, and License Restrictions
2.1. IP Ownership Clarification. The creation of a Combined Offering is for marketing and sale purposes only and does not create any new or joint intellectual property rights.
a) ThreatModeler IP: ThreatModeler (or its affiliates, as applicable) retains all right, title, and interest in and to the ThreatModeler Products, including all Software, APIs, connectors, and any updates or derivative works thereof. All software code, scripts, and connectors developed by Partner to interface with the Products shall belong exclusively to ThreatModeler.
b) Partner IP: Partner retains all right, title, and interest in and to the Partner Separate Product.
2.2. No Stand-alone Distribution. Partner must not market, license, or sell the ThreatModeler Products as a stand-alone offering. The Products must always be delivered as a fully integrated and inseparable part of the Combined Offering.
2.3. Brand, Naming, and Attribution: Partner shall market the Combined Offering under its own brand name. The name of the Combined Offering must not be confusingly similar to any ThreatModeler Mark. However, Partner agrees to display a visible and prominent notice within the user interface of the Combined Offering (e.g., on the 'About' or 'Login' screens) and in all corresponding user documentation stating: 'Powered by ThreatModeler™' or 'Contains ThreatModeler™ Technology', in accordance with ThreatModeler's brand guidelines.
2.4. Prohibition of Reverse Engineering. Partner has no rights to the Source Code of any Product and shall not (and shall not permit others to) disassemble, decompile, or reverse engineer the Software.
3. Partner's Obligations and Responsibilities
3.1. Sole Responsibility for the Combined Offering. Partner is the "manufacturer of record" for the Combined Offering. As such, Partner is solely responsible for all aspects of its lifecycle, including its development, quality assurance, testing, marketing, sales, and overall performance.
3.2. EULA Flow-Down. Partner must ensure that its own binding end-user agreement for the Combined Offering includes, at a minimum, all the disclaimers of warranty, limitations of liability, and license restrictions contained in ThreatModeler's then-current EULA. A failure to flow down these protections is a material breach of this Agreement.
3.3. Secure Distribution. Partner may not distribute the Combined Offering via electronic means unless it is through a secure, access-controlled distribution model that protects ThreatModeler's intellectual property.
3.4. Development Work for ThreatModeler. If Partner performs custom development work on the core ThreatModeler Product itself, such work is outside the scope of this OEM relationship and must be governed by a separate Master Subcontractor Agreement that ensures ThreatModeler owns the resulting IP.
3.5. Data Processing. To the extent that the functioning of the Combined Offering requires ThreatModeler to process Personal Data for which the Partner or its End User is the Data Controller, the relationship shall be governed by ThreatModeler's then-current Data Processing Addendum ("DPA"), as further detailed in the General Terms.
4. Reporting and Commercial Model
4.1. Royalty-Based Fees. Unless otherwise agreed in an Order, the fees payable by Partner ("Royalties") will be calculated based on the number of units of the Combined Offering sold or distributed by Partner during a specific period.
4.2. Usage Reporting and Electronic Verification: Partner must provide ThreatModeler with accurate quarterly usage reports within thirty (30) days of the end of each calendar quarter. These reports will detail the number of units of the Combined Offering sold or distributed and will be used by ThreatModeler to calculate and invoice the applicable Royalties. ThreatModeler reserves the right to electronically verify Partner's active customer nodes or active user seats through Product telemetry data to validate the accuracy of the usage reports.
5. Support Model
5.1. Partner as Sole Support Provider. Partner is responsible for providing all tiers of support (Tier 1, 2, and 3) for the Combined Offering directly to its End Users. The End User must have no direct support contact with ThreatModeler.
5.2. OEM Escalation Channel. Partner must purchase "OEM Support" from ThreatModeler. This provides a dedicated escalation channel for specific, named technical contacts within Partner's organization to report reproducible bugs in the core ThreatModeler Product to ThreatModeler's engineering teams, as defined in the Partner Support Program.