1. SaaS Agreement & Definitions
This Software as a Service License Agreement (“SaaS Agreement”) is entered into by and between the client entity (“Company” or “Customer”) and OnDuty Security, Inc., a Delaware corporation (“Vendor”, “we”, or “OnDuty Security”). This Agreement sets forth the definitive terms, conditions, rights, and restrictions governing the license and usage of our proprietary enterprise security platform, cloud sensors, and associated services (collectively, “Services”).
Key Operational Definitions:
- •Acceptable Use Policy (AUP): The rules governing appropriate, secure utilization of our network infrastructure and sensor deployments.
- •Documentation: All official installation guides, API reference documentation, operating manuals, and release notes.
- •Subscription Term: The contractual period commencing on the Go-Live Date during which Customer is authorized to access the SaaS.
- •User: Any individual employee, contractor, or agent authorized by Customer to access the enterprise workspace.
- •Free Plan: A no-cost, self-service tier of the SaaS made available without an executed Quote or Order Form. No fees are paid under the Free Plan, and no Subscription Term, service level commitment, or paid-tier commitment applies unless Customer separately upgrades to a paid plan. References to "Customer" in this Agreement include individuals who register for a Free Plan account.
Eligibility
You must be at least eighteen (18) years old, and have the legal capacity to enter into a binding agreement, to register for or use the Service. If you are registering on behalf of a company or other legal entity, you represent that you have the authority to bind that entity to this Agreement. By checking the acceptance box at signup or otherwise accessing the Service, you represent and warrant that the foregoing is true.
2. License Grant & Restrictions
Subject to timely payment of all applicable subscription fees detailed in an executed Quote or Order Form, OnDuty Security grants Customer a limited, non-exclusive, non-transferable, revocable license to utilize the SaaS and deployed eBPF sensors strictly for internal business operations during the Subscription Term.
Evaluation Licenses
For evaluation or proof-of-concept deployments, rights are limited strictly to internal testing for thirty (30) calendar days unless extended in writing. Evaluation software is provided "AS IS" without express warranties or indemnification.
SDK & API Access
We grant Customer a revocable, limited license to utilize our Software Development Kit (SDK) and exposed REST APIs solely to configure customized interoperability and internal automated security workflows within Customer's cloud environments.
Free Plan
We grant Customer a limited, non-exclusive, non-transferable, revocable, terminable at will license to use the Free Plan for Customer's own internal, non-commercial or internal-evaluation purposes, subject to any usage limits we publish or apply. The Free Plan is provided on an "AS IS" and "AS AVAILABLE" basis as described in Section 6, is supported on a best-efforts basis only as described in Section 7, and may be modified, limited, suspended, or discontinued at any time in our sole discretion without liability to Customer.
Strict License Restrictions
Customer specifically agrees not to:
- 1. Reverse engineer, decompile, disassemble, or attempt to derive the underlying source code of our platform, eBPF sensors, or AI detection engines.
- 2. Modify, translate, or create derivative works of any OnDuty Security software or third-party embedded materials.
- 3. Exceed the total count of licensed Users, monitored cloud workloads, or active container nodes stipulated in the governing Quote.
- 4. Publish or disclose benchmarking results, performance evaluations, or security audits to any third party without prior written consent.
- 5. Sell, lease, sublicense, or operate the SaaS as part of a commercial service bureau or managed security service provider (MSSP) offering without an executed partner agreement.
License Audit Rights: OnDuty Security reserves the right, upon fifteen (15) days written notice, to verify compliance via remote system inspection or certified deployment reports. Discrepancies resulting in over-deployment will be invoiced at current standard list rates plus applicable late interest.
3. Intellectual Property Ownership
All Rights Retained: OnDuty Security and its licensors retain all exclusive rights, title, and interest in and to the platform, software, sensor binaries, SDKs, documentation, AI models, and all derivative works, modifications, and enhancements thereto. Customer receives no ownership interest or title under this Agreement.
Feedback Assignment
Any comments, bug reports, feature suggestions, or workflow recommendations ("Feedback") provided by Customer become the absolute, unrestricted property of OnDuty Security. Customer irrevocably assigns all intellectual property rights in such Feedback without compensation or moral right retention.
Analytics & Aggregated Data
We retain sole proprietary ownership over all anonymized, de-identified metadata and aggregated operational telemetry ("Analytics Information") generated across our cloud clusters. This data is utilized freely to enhance machine learning classifiers, threat detection signatures, and general platform reliability.
4. Customer Data & Scanning Authorization
Ownership: As between the parties, Customer retains all right, title, and interest in and to all data, source code, repository contents, cloud configuration, scan targets, and resulting scan findings that Customer submits to or connects with the Service (“Customer Data”). Customer grants OnDuty Security a limited, non-exclusive, worldwide license to host, copy, process, transmit, and analyze Customer Data solely as necessary to provide, secure, and improve the Services during the period Customer uses them.
Authorization to Scan: Customer represents and warrants that it owns, or has all rights, consents, and authorizations necessary to connect, each repository, cloud account, domain, or other asset it submits to the Service, and to authorize OnDuty Security to access and scan that asset on Customer's behalf. Customer shall not connect or direct scans at any asset it is not authorized to test.
Sensitive Material in Findings: Customer acknowledges that scans may surface credentials, secrets, or other sensitive material present in Customer's own code or environments; such material is treated as Customer Data and Customer is responsible for remediating it. Breach of this Section is subject to the indemnification obligations in Section 10 (Limitation of Liability & Indemnification).
5. Acceptable Use Policy & Operations
Customer is fully responsible for all activity conducted within its authenticated enterprise workspace and must adhere to our Acceptable Use Policy (AUP). Customer shall not submit any illegal, misleading, defamatory, or threatening material ("Objectionable Matter") or utilize the platform to execute unauthorized vulnerability scans against third-party external networks.
Cryptographic Certificate Security: Customer is strictly responsible for securing API access keys, OAuth tokens, and TLS client certificates. Customer must notify us immediately upon suspecting any unauthorized token extraction or credentials compromise.
Suspension Rights: OnDuty Security reserves the absolute right to suspend workspace access immediately without advance notice if Customer's deployment threatens cloud network integrity, triggers denial-of-service protections, violates export control embargoes, or defaults on undisputed invoice obligations.
6. Warranties & Disclaimers
Software Conformance: OnDuty Security warrants that during the Subscription Term of an active paid subscription, the core SaaS platform will perform materially in accordance with published official Documentation under normal operational conditions.
Professional Services: Any customized onboarding, deployment engineering, or training services are warranted to be executed in a professional, workmanlike manner consistent with rigorous industry standards. Claims under this warranty must be submitted within thirty (30) calendar days of deliverable completion.
Free Plan — Provided "AS IS"
THE FOREGOING WARRANTIES APPLY ONLY TO ACTIVE PAID SUBSCRIPTIONS. THE FREE PLAN IS PROVIDED STRICTLY "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, AND WITHOUT ANY UPTIME, AVAILABILITY, ACCURACY, OR SUPPORT-RESPONSE COMMITMENT. THE SERVICE — INCLUDING UNDER ANY PAID PLAN — IS NOT A SUBSTITUTE FOR AN INDEPENDENT PROFESSIONAL SECURITY ASSESSMENT, AND CUSTOMER REMAINS SOLELY RESPONSIBLE FOR ITS OWN SECURITY PROGRAM, CONTROLS, AND DECISIONS, INCLUDING ANY DECISION MADE OR NOT MADE IN RELIANCE ON OUTPUT FROM THE SERVICE. AI-GENERATED FINDINGS, SUMMARIES, SCORES, AND RECOMMENDATIONS MAY BE INACCURATE, INCOMPLETE, OR OUT OF DATE, AND CUSTOMER MUST INDEPENDENTLY VERIFY THEM BEFORE ACTING ON THEM.
Disclaimer of Implied Warranties
EXCEPT FOR THE EXPRESS WARRANTIES OUTLINED ABOVE, ONDUTY SECURITY SPECIFICALLY DISCLAIMS ALL STATUTORY OR IMPLIED WARRANTIES, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. WE DO NOT GUARANTEE THAT THE PLATFORM WILL DETECT EVERY ADVANCED ZERO-DAY THREAT OR OPERATE WITHOUT OCCASIONAL LATENCY OR INTERRUPTION.
7. Customer Support
Best-Efforts Support — No SLA
All support for the Service — on both free and paid plans — is currently provided on a best-efforts basis via email, with no guaranteed response time, no uptime or availability commitment, and no service credits or other remedies of any kind. We may prioritize paid subscriptions over Free Plan accounts at our discretion.
Formal service level agreements, response-time commitments, and uptime commitments are available only through a separately executed enterprise agreement signed by both parties. Nothing in this Section or elsewhere in this Agreement constitutes such a commitment.
Customer Responsibilities: To facilitate resolution of support requests, Customer agrees to designate a technical contact, submit reproduction steps where applicable, and cooperate in isolating network configurations or cloud IAM permission boundaries.
8. Data Processing Agreement (DPA) Summary
To the extent Customer processes personal information or sensitive workload parameters within the platform, our Data Processing Agreement (DPA) is incorporated by reference and governs all processing activities under GDPR Article 28 and the California Consumer Privacy Act (CCPA).
- Data Processor Status: OnDuty Security acts strictly as a Data Processor. We never sell, share, or monetize Customer personal records or sensor telemetry for commercial third-party marketing.
- Sub-processor Authorization: Customer grants general authorization for enterprise sub-processors (AWS, GCP, Azure). We provide advance notification for new sub-processor appointments, granting Customer three (3) business days to lodge legitimate data protection objections.
- Security Controls & Incident Management: We maintain commercially reasonable administrative, technical, and organizational controls appropriate to our size and stage; a SOC 2 attestation is on our roadmap (see our Trust Center). In the event of a verified data breach affecting Customer Data, we will notify Customer without undue delay as required by applicable law and provide reasonable diagnostic assistance.
- International Cross-Border Transfers: Where required by applicable law, transfers of European Economic Area (EEA) data outside the EEA rely on European Commission-approved Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms.
9. Billing, Payments & Taxes
Payment Terms: All subscription invoices are due net thirty (30) calendar days from the invoice issuance date in US Dollars. Prepaid SaaS subscription fees are non-refundable except where Customer terminates for our uncured material breach.
Late Payments & Taxes: Overdue accounts are subject to late interest charges equal to the lesser of 1.5% per month or the maximum rate permitted by law. Customer is solely responsible for all federal, state, local sales, use, value-added, or withholding taxes levied on the subscription (excluding taxes based on our net income).
10. Limitation of Liability & Indemnification
Limitation of Aggregate Liability
NOTWITHSTANDING ANYTHING TO THE CONTRARY, IN NO EVENT SHALL ONDUTY SECURITY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR IN CONNECTION WITH THIS AGREEMENT (WHETHER IN CONTRACT, TORT, STRICT LIABILITY, OR OTHERWISE) EXCEED THE TOTAL FEES ACTUALLY PAID BY CUSTOMER IN THE TWELVE (12) MONTHS PRECEDING THE INCIDENT GIVING RISE TO THE CLAIM. FOR FREE PLAN ACCOUNTS, WHERE NO FEES HAVE BEEN PAID, ONDUTY SECURITY SHALL HAVE NO FINANCIAL LIABILITY WHATSOEVER TO CUSTOMER, AND ONDUTY SECURITY’S TOTAL AGGREGATE LIABILITY SHALL BE ZERO U.S. DOLLARS ($0). IF, NOTWITHSTANDING THE FOREGOING, A COURT OR ARBITRATOR OF COMPETENT JURISDICTION HOLDS A ZERO-DOLLAR LIMITATION UNENFORCEABLE AS APPLIED TO A PARTICULAR CLAIM, ONDUTY SECURITY’S LIABILITY FOR THAT CLAIM SHALL NOT EXCEED ONE U.S. DOLLAR ($1), WHICH THE PARTIES AGREE IS A REASONABLE MINIMUM FLOOR GIVEN THAT THE FREE PLAN IS PROVIDED ENTIRELY WITHOUT CHARGE.
Exclusion of Consequential Damages
IN NO EVENT SHALL EITHER PARTY BE LIABLE TO THE OTHER FOR ANY INDIRECT, SPECIAL, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES WHATSOEVER, INCLUDING LOSS OF REVENUE, LOST PROFITS, BUSINESS INTERRUPTION, DATA CORRUPTION, OR REPUTATIONAL HARM, REGARDLESS OF WHETHER SUCH PARTY WAS ADVISED OF THE POSSIBILITY OF SUCH LOSSES.
Free Plan — No Liability Beyond Cap
THE FREE PLAN IS OFFERED AT NO CHARGE. TO THE MAXIMUM EXTENT PERMITTED BY LAW, ONDUTY SECURITY SHALL HAVE NO LIABILITY WHATSOEVER FOR ANY DAMAGES ARISING FROM OR RELATED TO CUSTOMER’S USE OF THE FREE PLAN, INCLUDING WITHOUT LIMITATION ANY SECURITY INCIDENT, DATA LOSS, OR BUSINESS INTERRUPTION CUSTOMER ALLEGES RESULTED FROM RELIANCE ON THE FREE PLAN, BEYOND THE CAP SET FORTH ABOVE.
Customer Indemnification: Customer agrees to defend, indemnify, and hold harmless OnDuty Security and its officers against any third-party claims resulting from Customer's violation of export control restrictions, unlawful data submissions, or unauthorized execution of vulnerability testing against restricted third-party networks.
11. Governing Law & General Provisions
Governing Law & Arbitration: This Agreement shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to conflict of laws principles. Any formal dispute or claim arising out of this Agreement shall be settled by binding arbitration administered by the American Arbitration Association (AAA) before a single arbitrator in New York City, New York, conducted in the English language.
Class Action & Jury Trial Waiver
TO THE MAXIMUM EXTENT PERMITTED BY LAW, ALL CLAIMS MUST BE BROUGHT IN A PARTY’S INDIVIDUAL CAPACITY, AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, COLLECTIVE, CONSOLIDATED, OR REPRESENTATIVE PROCEEDING. THE ARBITRATOR MAY NOT CONSOLIDATE MORE THAN ONE PERSON’S CLAIMS AND MAY NOT OTHERWISE PRESIDE OVER ANY FORM OF A CLASS OR REPRESENTATIVE PROCEEDING. EACH PARTY WAIVES ANY RIGHT TO A JURY TRIAL TO THE EXTENT A CLAIM PROCEEDS IN COURT RATHER THAN ARBITRATION.
US Government End-Users: The platform and cloud sensors are classified as "Commercial Items" under 48 C.F.R. § 2.101, consisting of commercial computer software. Licensed to US Government end-users solely with standard commercial rights.
Entire Agreement: This SaaS Agreement, together with executed Quotes, Order Forms, and the incorporated AUP and DPA, constitutes the entire understanding between the parties, superseding all prior oral or written representations.
Modifications to These Terms: We may modify this Agreement from time to time by posting an updated version and providing notice via email or in-platform notification. Changes take effect on the stated effective date, and Customer's continued use of the Service after that date constitutes acceptance of the updated Agreement. If Customer does not agree to a change, Customer's sole remedy is to stop using the Service and close its account. For negotiated enterprise agreements executed by both parties, modifications are valid only if made in a writing signed by authorized representatives of both parties.
Questions regarding our SaaS Agreement or these Terms?
If you require customized enterprise order forms, sub-processor notifications, or official compliance documentation, our legal and customer success teams are ready to assist.