This Enterprise License Agreement (the Agreement) is between Trustity and Customer and governs Customer’s access to and use of the Products. By signing or accepting an Order Form that references this Agreement, or by accessing the Products on Customer’s behalf, Customer agrees to this Agreement.
1. Definitions
- “Affiliate”
- means an entity that directly or indirectly controls, is controlled by, or is under common control with a party.
- “Authorized User”
- means an employee, contractor, or other individual whom Customer authorizes to use the Products for Customer’s internal business purposes.
- “Customer”
- means the legal entity identified in an Order Form, or the business entity accepting this Agreement.
- “Customer Data”
- means data, content, configurations, credentials, logs, or other information submitted to or processed through the Products by or for Customer.
- “Documentation”
- means Trustity’s then-current user, technical, and operational documentation made available for the Products.
- “Order Form”
- means an ordering document accepted by Trustity and Customer that identifies Products, quantities, subscription or license terms, and fees.
- “Products”
- means the Trustity products, software, agents, modules, cloud services, and related services identified in an Order Form, including any applicable product-specific components or addenda. The public portfolio currently includes the Cloud Portal, TAO, VisionX, GenGuard, Vault/PAM, HostGuard IPS, Trustity Axiom, Trustity SecSend, and Trustity Authenticator.
- “Trustity”
- means Trustity, the technology company offering the Products.
2. Orders and precedence
Each Order Form is governed by this Agreement. An Order Form becomes binding when signed or otherwise accepted by both parties. Affiliates may purchase Products under separate Order Forms and, for those orders, are treated as Customer under this Agreement.
If documents conflict, the following order of precedence applies: (a) a signed commercial document, but only where it expressly states that it overrides the conflicting provision; (b) the applicable Order Form; (c) a data processing addendum or other product-specific addendum signed by both parties, for its subject matter; and (d) this Agreement. Purchase order terms or similar unilateral terms do not modify this Agreement, even if accepted for administrative convenience.
3. License grant and service access
Subject to Customer’s payment of applicable fees and compliance with this Agreement, Trustity grants Customer, during the applicable Order Form term, a limited, non-exclusive, non-transferable, non-sublicensable right for Authorized Users to access and use the Products and Documentation identified in that Order Form, solely for Customer’s internal business and security operations and within the quantities, environments, devices, territories, and other scope stated in the Order Form.
Customer may make a reasonable number of backup copies of downloadable software solely for disaster recovery. Trustity and its licensors reserve all rights not expressly granted. No rights are granted by implication, estoppel, or otherwise.
4. License and use restrictions
Customer will not, and will not permit any third party to:
- sell, resell, sublicense, rent, lease, distribute, or provide the Products as a service bureau, except under a separate Partner, MSSP, or reseller addendum signed by Trustity;
- copy or modify the Products except as expressly permitted by this Agreement;
- reverse engineer, decompile, disassemble, or seek to derive source code, underlying ideas, algorithms, or non-public APIs, except to the limited extent applicable law prohibits this restriction;
- circumvent license keys, usage limits, access controls, or technical protection measures;
- use the Products to develop, train, or benchmark a competing product, or publish benchmark results without Trustity’s prior written consent;
- remove proprietary notices or misrepresent the source or ownership of a Product;
- introduce malicious code, disrupt Product integrity or availability, or conduct unauthorized penetration or vulnerability testing; or
- use the Products unlawfully, to infringe rights, or beyond the scope of an Order Form.
5. Customer responsibilities
Customer is responsible for its deployment, configuration, policies, endpoint compatibility, network access, Authorized Users, and all activity under its accounts. Customer will maintain appropriate backups and business continuity measures and will use security features consistent with the sensitivity of Customer Data.
Customer represents that it has all rights, permissions, and lawful bases needed for Trustity to process Customer Data and provide the Products. Customer is solely responsible for determining whether and how to deploy monitoring, DLP, endpoint, credential-management, and security controls.
Where the Products monitor employees, contractors, communications, devices, images, activity, credentials, or other individuals, Customer must provide all notices, obtain all consents, consult employee representatives, and satisfy labor, privacy, communications, surveillance, and data protection requirements applicable to its use. Trustity does not determine whether Customer’s monitoring practices are lawful or appropriate.
6. Accounts and access credentials
Customer will ensure that account information is accurate and current, that each account is assigned to an identified Authorized User, and that credentials are kept confidential and not shared except through approved service-account functionality. Customer will apply least privilege, promptly revoke unnecessary access, and notify Trustity without undue delay at security@trustity.co of suspected unauthorized account use or credential compromise.
7. Updates, changes, and support
Trustity may provide patches, updates, upgrades, and modifications to maintain security, performance, legal compliance, or functionality. Updates may be automatically delivered where the Product or Customer’s configuration permits. Customer will install security-critical updates within a reasonable period and maintain supported versions.
Trustity may change the Products during a subscription, provided it does not materially reduce the overall core functionality of an ordered Product. Support scope, channels, response targets, maintenance windows, and any service commitments apply only if stated in the applicable Order Form or another signed commercial document.
8. Fees, invoicing, and taxes
Fees, currency, billing schedule, payment terms, and permitted usage are set out in the Order Form. Except as expressly stated there, fees are non-cancellable and non-refundable. Customer will pay undisputed invoices when due and notify Trustity promptly of a good-faith dispute, identifying the disputed amount and basis.
Fees exclude taxes, duties, levies, and similar governmental assessments. Customer is responsible for them, other than taxes based on Trustity’s net income. If withholding is required by law, Customer will provide valid documentation and, unless prohibited by law or the Order Form, pay amounts necessary for Trustity to receive the invoiced net amount.
9. Intellectual property and feedback
Trustity and its licensors own all right, title, and interest in the Products, Documentation, technology, designs, improvements, and related intellectual property. Customer owns Customer Data. Customer grants Trustity a limited, worldwide right to host, copy, transmit, process, and display Customer Data solely to provide, maintain, secure, troubleshoot, and support the Products and to comply with applicable law. Trustity will not use Customer Data to train generalized artificial intelligence or machine-learning models, for advertising, or to develop profiles unrelated to Customer’s use of the Products. Trustity may use aggregated or de-identified information that cannot reasonably identify Customer or any individual to improve the Products.
If Customer provides suggestions or feedback, Customer grants Trustity a perpetual, irrevocable, worldwide, royalty-free right to use it without restriction or attribution, provided Trustity does not publicly identify Customer as its source without permission.
10. Confidentiality
“Confidential Information” means non-public information disclosed by one party to the other that is marked confidential or reasonably should be understood as confidential, including Customer Data, Product source code, non-public security information, pricing, and business plans. It excludes information the recipient can document: (a) is public without breach; (b) was lawfully known without restriction; (c) is received lawfully from a third party without confidentiality duty; or (d) was independently developed without use of the discloser’s Confidential Information.
The recipient will use Confidential Information only to perform or exercise rights under the parties’ relationship, protect it using at least reasonable care, and disclose it only to personnel, Affiliates, advisers, and subcontractors who need to know it and are bound by confidentiality duties. A legally compelled disclosure is permitted if the recipient gives advance notice where lawful and reasonable assistance at the discloser’s expense. Unauthorized disclosure may cause irreparable harm for which equitable relief may be appropriate.
11. Data protection
Each party will comply with data protection laws applicable to its role. As between the parties, Customer determines the purposes and means of processing Customer Data, and Trustity processes Customer Data to provide the Products, follow Customer’s documented instructions, and satisfy legal obligations.
If the parties sign a data processing addendum, that addendum governs processing of personal data within its scope. A standard DPA is available on request for applicable deployments. Nothing in this Agreement represents that a DPA has already been signed. Customer will not submit special-category, regulated, or highly sensitive data unless the applicable Product, Order Form, and signed data terms expressly support it. Trustity’s current privacy information is available in its Privacy Policy.
After confirming a security incident affecting Customer Personal Data, Trustity will notify Customer without undue delay and provide the information reasonably available to support Customer’s legal and regulatory obligations.
12. Security and subprocessors
Trustity will maintain reasonable administrative, technical, and organizational safeguards designed to protect Customer Data against unauthorized access, use, alteration, and disclosure, taking into account the nature of the Products and Customer Data. Security information is available through the Trust Center.
Trustity may use Affiliates and third-party subprocessors to provide the Products and remains responsible for their performance to the extent required by this Agreement and applicable law. Trustity will impose appropriate contractual data-protection and confidentiality obligations on subprocessors that process Customer Data. Any additional notice or objection procedure applies only where required by law or stated in a signed data processing addendum.
No system is completely secure, and Customer acknowledges that security outcomes also depend on Customer’s environment, configuration, access controls, updates, and response practices.
13. Warranties and disclaimers
Trustity warrants that, during an applicable paid term, the Products will perform in all material respects in accordance with the Documentation when used as authorized. Customer’s exclusive remedy for breach is for Trustity to use commercially reasonable efforts to correct the nonconformity; if Trustity cannot do so within a reasonable time, either party may terminate the affected Order Form and Trustity will refund prepaid fees for the terminated portion of the remaining term. Customer must report a warranty claim with reasonable detail promptly after discovery.
The warranty does not apply to issues caused by unauthorized use or modification, unsupported systems or versions, Customer or third-party systems, failure to follow Documentation, or events outside Trustity’s reasonable control.
Except for the express warranty above and to the maximum extent permitted by law, the Products, Documentation, support, and related services are provided “as is” and “as available.” Trustity disclaims all implied, statutory, and other warranties, including merchantability, fitness for a particular purpose, title, non-infringement, and warranties arising from course of dealing or usage of trade. Trustity does not warrant uninterrupted or error-free operation, detection or prevention of every threat, or that use of the Products alone will satisfy Customer’s legal or compliance duties.
14. Indemnification
Trustity IP indemnity. Trustity will defend Customer against a third-party claim alleging that Customer’s authorized use of a paid Product infringes a patent, copyright, or trademark, and will pay damages and reasonable costs finally awarded or agreed in a Trustity-approved settlement. Trustity has no obligation for a claim arising from Customer Data, Customer specifications, unauthorized modification or use, combination with items not supplied by Trustity where the claim would otherwise not arise, continued use after notice, or failure to use an available non-infringing update.
If a Product is, or in Trustity’s reasonable opinion is likely to be, subject to an infringement claim, Trustity may: (a) procure continued use; (b) modify or replace it with materially equivalent functionality; or (c) terminate the affected Order Form and refund prepaid fees allocable to the unused remaining term. This Section states Customer’s exclusive remedy for third-party intellectual property claims.
Customer indemnity. Customer will defend Trustity and its Affiliates against third-party claims arising from Customer Data, Customer’s unlawful monitoring or deployment, or Customer’s or an Authorized User’s material breach of Sections 4 or 5, and will pay damages and reasonable costs finally awarded or agreed in a Customer-approved settlement.
The indemnified party must promptly notify the indemnifying party, provide reasonable cooperation at the indemnifying party’s expense, and give it sole control of defense and settlement. Delay relieves obligations only to the extent materially prejudicial. No settlement may admit fault by, impose non-monetary obligations on, or fail to fully release the indemnified party without its prior written consent.
15. Limitation of liability
To the maximum extent permitted by law, neither party will be liable under or relating to this Agreement for lost profits, revenues, goodwill, or data, business interruption, or indirect, incidental, special, consequential, exemplary, or punitive damages, even if advised of their possibility.
General cap. Except for the enhanced cap and uncapped items below, each party’s aggregate liability arising from or relating to this Agreement will not exceed the fees paid or payable by Customer to Trustity under the affected Order Form during the 12 months immediately preceding the event giving rise to liability. If the event occurs before 12 months of fees have accrued, the general cap is the fees paid or payable for the first 12 months of that Order Form.
Enhanced cap. Aggregate liability for (i) a party’s breach of confidentiality, (ii) a security incident affecting Customer Data caused by Trustity’s failure to maintain the safeguards required by this Agreement, and (iii) Trustity’s intellectual property indemnity under Section 14, will not exceed two times (2x) the general cap.
The exclusions and caps do not apply to: (a) Customer’s payment obligations; (b) a party’s fraud, fraudulent misrepresentation, or willful misconduct; (c) Customer’s breach of the license and use restrictions; or (d) liability that applicable law does not permit the parties to exclude or limit. The limitations apply regardless of the theory of liability and form an essential basis of the bargain.
16. Term, suspension, termination, and data handling
This Agreement begins when Customer first accepts it and continues while an Order Form remains in effect. Each Order Form has the term and renewal mechanics stated in that Order Form.
Either party may terminate an affected Order Form or this Agreement for material breach if the breach is not cured within 30 days after written notice, or within 10 days for non-payment. Either party may terminate immediately if the other party enters insolvency, liquidation, or similar proceedings that are not dismissed within 60 days, to the extent permitted by law.
Trustity may suspend access to the extent reasonably necessary to address a security threat, unlawful use, material violation of Sections 4 or 5, or overdue undisputed fees after notice and a reasonable opportunity to cure. Where practicable, Trustity will limit the suspension, provide notice, and work with Customer to restore access promptly.
On expiration or termination, Customer will stop using affected Products and delete or return software and Documentation as requested. Unless an Order Form, signed DPA, or legal hold says otherwise: Customer may export available Customer Data for 30 days after termination; Trustity will delete Customer Data from active systems within 90 days after that export period; and remaining backups are overwritten in the ordinary backup lifecycle. Customer should export needed data before the end of the term. Retained copies remain subject to confidentiality and security obligations.
Sections that by their nature should survive do survive, including accrued payment obligations and Sections 4, 8 through 20.
17. Export controls and sanctions
Each party will comply with applicable export-control, import, and economic sanctions laws. Customer will not access, export, re-export, transfer, or use the Products in or for prohibited countries, territories, persons, or end uses, including prohibited weapons or military end uses. Customer represents that it and its Authorized Users are not subject to applicable sanctions or denied-party restrictions. Trustity may refuse or suspend performance where reasonably necessary to comply with these laws.
18. Governing law and courts
This Agreement and any dispute or claim arising from it are governed by the laws of the State of Israel, without regard to conflict-of-laws principles. The United Nations Convention on Contracts for the International Sale of Goods does not apply. The courts located in Tel Aviv-Yafo, Israel have exclusive jurisdiction, and each party irrevocably submits to their jurisdiction and venue. Either party may seek urgent injunctive or equitable relief in any court of competent jurisdiction to protect intellectual property, Confidential Information, or system security.
19. Notices
Legal notices must be in writing and delivered by personal delivery, nationally recognized courier, or email with confirmation of receipt. A notice to Customer may be sent to the legal or administrative contact in the applicable Order Form or Customer account. Notices to Trustity must be sent to legal@trustity.co and to: Trustity, 30 Emek Hefer Boulevard, Ashkelon, Israel. Notices are effective on confirmed receipt. Routine operational communications may be sent through the Product or by email and are not legal notices.
20. General
Neither party may assign this Agreement without the other party’s prior written consent, except to an Affiliate or in connection with a merger, reorganization, or sale of substantially all assets relevant to this Agreement, provided the assignee is not a direct competitor of the non-assigning party and assumes all obligations in writing. Any other attempted assignment is void.
Neither party is liable for delay or failure caused by events beyond its reasonable control, except Customer’s payment obligations. The parties are independent contractors; this Agreement creates no partnership, franchise, fiduciary, agency, or employment relationship. There are no third-party beneficiaries.
This Agreement and applicable signed commercial documents are the entire agreement concerning their subject matter and supersede prior or contemporaneous proposals and communications on that subject. Amendments must be in writing and signed by authorized representatives, except that Trustity may update these online terms prospectively by giving reasonable notice; material changes will take effect at the next renewal unless required sooner by law or to address material security risk. Continued use after the applicable effective date constitutes acceptance.
A waiver must be in writing and applies only to the specific instance. If a provision is unenforceable, it will be modified to the minimum extent necessary and the remainder stays effective. Headings are for convenience only. “Including” means “including without limitation.” Electronic signatures and counterparts are valid and together form one instrument.
