Legal
Terms of service
Revised September 14, 2026.
These Terms of Service (Terms) govern the Rapticore products, software, AI capabilities, and related services identified in an Order. They cover hosted subscriptions, customer-hosted deployments, and self-service purchases. Product availability, licensed capacity, deployment arrangements, and pricing are established by the applicable Order.
1 Agreement and acceptance
1.1 Parties and acceptance. These Terms form an agreement between Rapticore Inc., a Delaware corporation (Rapticore, we, or us), and the person or legal entity accepting them (Customer or you). You accept by signing an Order that incorporates these Terms, or by affirmatively accepting them through a registration, checkout, installation, or activation process that presents these Terms. Mere browsing of our public website does not by itself constitute acceptance of a paid subscription or this arbitration agreement. The Agreement begins on the date of valid acceptance unless an Order specifies a later service commencement date.
1.2 Business use and authority. The Services are offered for business, professional, educational, and organizational use. You must be at least 18 and legally able to contract. A person accepting for an organization represents that they have authority to bind it. A user without purchasing authority may use only access already authorized under that organization's Agreement. Self-service availability does not itself make a purchase a consumer transaction. Nonwaivable consumer rights apply wherever the law requires them.
1.3 Contract documents. The Agreement consists of these Terms, accepted Orders, and any applicable signed master services agreement, data processing agreement (DPA), business associate agreement (BAA), service level agreement (SLA), product schedule, statement of work (SOW), or other addendum expressly incorporated into an Order. A self-service checkout and the associated confirmation constitute an Order for the products, quantities, price, term, and other purchase conditions affirmatively accepted there. Advertising, roadmaps, and general website descriptions do not create additional entitlements.
1.4 Priority and existing agreements. Mandatory law controls. A BAA controls a conflict concerning protected health information; a DPA controls a conflict concerning personal-data processing. An applicable signed master services agreement controls over these Terms. Otherwise, a signed addendum or Order expressly accepted by Rapticore and expressly identifying a provision it modifies controls that provision, followed by the applicable product schedule, these Terms, and Documentation. An online checkout establishes the selections and terms expressly presented and accepted there. Model Training authorization under this Agreement must satisfy Section 8.4. Additional or inconsistent terms in a purchase order or vendor portal are rejected unless Rapticore expressly accepts them in writing.
These Terms supplement an existing signed agreement only to the extent validly incorporated under that agreement. Publication alone does not amend it. An amendment or new Order may expressly adopt specified AI, data-use, security, authorization, and liability provisions for identified Services and periods. Existing signed agreements and legally effective privacy commitments remain applicable until validly amended.
1.5 Privacy notice. Our Privacy Policy describes personal-data processing. It is a notice and is not incorporated as an additional contractual warranty or obligation unless a signed agreement expressly incorporates it. This does not limit rights or duties imposed by applicable privacy, consumer-protection, or other law. The Policy does not expand Rapticore's contractual rights to Customer Data or replace a required DPA or BAA. Acceptance of these Terms is not individual consent where separate consent is legally required.
1.6 Authorized reseller purchases. Customer may obtain Services directly from Rapticore or through an authorized distributor or reseller identified in the applicable Order. The Order or checkout identifies the billing and collection party. Rapticore remains the provider and contracting party for the Rapticore Services under the Agreement. An authorized reseller may establish commercial terms within its agreed authority and handle invoicing, collection, renewals, and commercial support. Separately supplied reseller professional or managed services are governed by Customer's agreement with that provider and do not become Rapticore Services merely because they are purchased together. A reseller has no authority to amend these Terms or expand Rapticore's product, security, privacy, warranty, indemnity, or service-level obligations unless Rapticore expressly accepts the change in writing or applicable law otherwise requires. A reseller's invoice, proposal, or separate agreement does not by itself create additional Rapticore obligations. These Terms do not confer or modify any reseller's territory, exclusivity, customer-attribution, or commission rights.
2 Definitions
AI Features means capabilities using artificial intelligence, machine learning, large language models, other models, or agent orchestration, including analysis, classification, recommendations, code generation, and authorized actions. They may use Rapticore, third-party, or Customer-selected models running locally or remotely.
Anonymized Service Data means data derived from Customer Data or operational telemetry that has been processed so it cannot reasonably identify or be linked to an individual or household, or be used to infer information about a particular individual, and meets applicable anonymization or deidentification requirements. Customer identifiers and customer-specific confidential content must also be removed, generalized, or aggregated so the retained information does not reasonably identify Customer or expose its confidential code, credentials, nonpublic vulnerabilities, or identifiable system details. General technical patterns and aggregate service statistics may qualify. Pseudonymization, hashing, tokenization, or partial redaction alone is not sufficient.
Authorized Users means Customer's employees, contractors, affiliates, or other individuals Customer permits to use the Services for Customer's authorized purposes, subject to the Order. Customer remains responsible for their compliance. Providing services to clients or operating as a managed service provider requires the rights described in Section 3.3.
Customer Data means information supplied, accessed, collected, or generated on Customer's behalf through the Services, including source code, repositories, prompts, files, logs, cloud configurations, asset inventories, credentials, security evidence, personal data, support submissions, and customer-specific findings and Outputs. Data obtained through Customer-authorized integrations is Customer Data. Customer Data excludes Rapticore Technology, independently sourced public or licensed threat intelligence, Anonymized Service Data satisfying Section 7.3, and account or business-contact records processed independently under Section 7.6. Those exclusions do not turn customer-specific findings or embedded confidential information into Rapticore property.
Customer Environment means systems, networks, cloud accounts, applications, domains, endpoints, repositories, infrastructure, and other resources owned or controlled by Customer, or that Customer is legally authorized to assess, monitor, or manage.
Customer-Hosted Software means software licensed for deployment on Customer-controlled infrastructure, including on-premises equipment, private clouds, virtual private clouds, and local workstations. A hybrid deployment combines Customer-Hosted Software with hosted Services or remote processing.
Documentation means Rapticore's applicable user, technical, security, and deployment documentation made available for the purchased version or Service. Order means a mutually accepted ordering document or self-service purchase record described in Section 1.3. Subscription Term means the initial service period and any validly renewed period specified in an Order.
Model Training means using data to train, pretrain, fine-tune, retrain, distill, or otherwise update the learned parameters, weights, or adapters of an AI or machine-learning model, including through reinforcement learning. Using a trained model for inference, or maintaining a Customer-specific retrieval index without changing model parameters, is not Model Training, but remains subject to all Customer Data restrictions.
Outputs means customer-specific reports, findings, recommendations, generated code, proposed changes, and other results produced for Customer through the Services. Rapticore Technology means the Services and underlying software, orchestration, models owned by Rapticore, interfaces, reusable tools, templates, methods, Documentation, and other technology, excluding Customer Data and Customer-owned Outputs.
Services means products and related functionality provided under an Order, including hosted software, Customer-Hosted Software, APIs, agents, command-line and developer tools, integrations, AI Features, updates, and purchased support or professional services. Third-Party Services means independently supplied services, infrastructure, software, models, or integrations used with the Services.
3 Products and licensed use
3.1 Covered Services. These Terms govern the Services identified in the applicable Order or accepted self-service offer, whether purchased separately or in a bundle. Covered capabilities may include application and code security; adversarial intelligence, attack surface monitoring, and authorized red teaming; agentic penetration testing and dynamic application security testing; and cloud posture, guardrails, remediation, security operations, and incident-response assistance. The Order controls the purchased product, edition, deployment, and entitlements. Product names may change without requiring a new agreement or expanding licensed rights. A renamed or successor offering is covered to the extent supplied in fulfillment of the Order. Availability of a capability in one product does not make it included in another.
3.2 Rights during the term. Subject to payment and compliance, Rapticore grants Customer a limited, nonexclusive right during the Subscription Term to access hosted Services and to install and use licensed Customer-Hosted Software within the scope of the Order. Customer may permit Authorized Users to use the Services and make reasonable backup copies of licensed software. The license is nontransferable except under Section 20.3. No perpetual license is granted unless an Order expressly says so. Rights granted by an applicable open-source license are addressed separately in Section 10.3.
3.3 Scope and capacity. Each Order specifies relevant entitlements, which may include products, users, active hosts, applications, repositories, resources, accounts, environments, assessment frequency, concurrency, storage, API use, or AI consumption. The applicable counting rules and overage treatment must be disclosed at purchase. Unused capacity is not interchangeable between products unless the Order permits it. Resale, sublicensing, service-bureau use, client assessments, and managed services require an Order expressly authorizing those activities and the necessary authorization from each affected client.
3.4 Trial and free access. Trials, free plans, demonstrations, and evaluations have only the duration, capacity, support, and permitted use stated in their offer. There is no universal free-trial entitlement or cloud-account allowance. A trial converts to paid service only if Customer expressly accepted the conversion date, price or pricing method, billing frequency, and cancellation method before conversion. Otherwise it ends or reverts to an available free plan. Customer must export needed data before a trial or free plan ends, subject to Section 16.5.
4 Deployment and support
4.1 Hosted Services. Rapticore operates the hosted components it supplies. Customer manages its connected environments, users, access permissions, and configuration. Availability commitments, recovery objectives, support hours, and service credits apply only if expressly provided in an Order or SLA. No general promise of uninterrupted service, geographic residency, or a particular certification is created by these Terms.
4.2 Customer-hosted deployments. Unless an Order assigns a responsibility to Rapticore, Customer supplies and operates the underlying infrastructure, operating systems, network controls, storage, encryption and key management, local model infrastructure, backups, restoration, and supported dependencies. Customer installs security updates and follows documented compatibility requirements. Support and any express software warranty remain subject to the supported environment, cooperation requirements, and exclusions in this Agreement.
4.3 Connectivity and access. Customer-hosted does not necessarily mean offline, air-gapped, or without outbound data transfer. Remote AI inference, hosted management, license validation, updates, telemetry, integrations, and support can require connectivity. Required connections and data categories must be disclosed in the applicable Order, Documentation, or configuration flow. Rapticore will maintain controls designed to enforce agreed egress, model-route, offline, and residency restrictions for components under its control, as described in Section 8.2. Remote support access requires Customer's authorization and must be limited to its authorized purpose.
4.4 Local data and telemetry. The permissions in Section 7 do not create a right to extract data from a disconnected deployment. Rapticore may receive only data transmitted through disclosed, authorized functionality or separately provided by Customer. Mandatory licensing or operational telemetry and any optional improvement telemetry must be distinguished in deployment information. Logs, crash reports, and support bundles containing customer information remain Customer Data until properly anonymized.
4.5 Support and updates. Support, implementation, migration, custom integrations, and professional services are provided only as included in an Order or SOW. Rapticore may request reasonable diagnostic information and may offer a supported update to address an issue. Customer may redact unrelated information before submitting support materials. Unsupported versions or modifications may limit support to the extent they cause the issue. Material lifecycle changes to paid software are subject to Section 17.
4.6 License verification and enforcement. Rapticore may validate entitlements through disclosed licensing and usage mechanisms. Customer must maintain accurate entitlement and usage records during the Subscription Term and for 12 months afterward. No more than once in any 12-month period, and on at least 10 business days' written notice, Rapticore or a qualified independent auditor subject to confidentiality may request and review records reasonably necessary to verify compliance. Verification will be remote where practicable, during normal business hours, and designed to minimize disruption; it does not require Customer source code, production credentials, or unrelated personal data. Customer will reasonably cooperate. Rapticore pays the review cost unless verified under-licensing exceeds five percent of the fees properly due for the reviewed period, in which case Customer pays reasonable verification costs. Customer must pay any verified shortfall at the applicable contracted rates, or the rates disclosed for excess use where applicable. Additional access requires a mutually agreed process.
Licensed functionality may stop when a subscription expires or is validly suspended. Customer is responsible for continuity and timely export. License enforcement does not authorize intentional deletion of Customer-controlled data or changes to unrelated systems.
5 Accounts and Customer responsibilities
5.1 Account administration. Customer must provide accurate registration and billing details, maintain a current administrative and security contact, protect credentials and API keys, and use available access controls appropriate to its risk. Credentials must not be shared in a manner that defeats user or access restrictions. Customer must promptly notify Rapticore of suspected compromise affecting the Services. Customer is responsible for all activity occurring under its accounts, credentials, and API keys, except to the extent caused by Rapticore's breach of this Agreement.
5.2 Rights and lawful instructions. Customer must hold the rights and permissions necessary to supply Customer Data, connect accounts, direct processing, and authorize assessments or changes. Customer is responsible for required notices to and lawful permissions from personnel, clients, system owners, and other affected persons. Connecting an account or accepting these Terms does not grant rights against an unrelated third party. Neither party is required to follow an unlawful instruction.
5.3 Operational judgment. Customer selects the deployment, scope, access level, retention settings, and AI configuration appropriate for its obligations. Customer must maintain suitable backups and business continuity arrangements for its environments, evaluate recommendations, and validate material changes before production use or authorize a defined automated policy under Section 6.4. Customer remains responsible for its own security program and regulatory decisions.
6 Security assessments and automated actions
6.1 Authorized scope and Customer representations. Customer represents and warrants, each time it initiates or authorizes an assessment or action, that it holds legally sufficient authority for the specific targets, access, processing, and actions requested, and that this authority remains in effect for the activity's duration. This includes instructions initiated by its Authorized Users, agents, integrations, and automated policies. Customer must establish accurate targets, exclusions, permitted actions, relevant time windows, and an emergency contact, and retain evidence of required authorizations. Public availability, discovery, common ownership assumptions, or a link from an authorized asset does not by itself authorize active testing of another system. Required cloud-provider, hosting-provider, client, and third-party approvals remain Customer's responsibility. Rapticore may rely on Customer's representations and submitted authorization records without independently verifying ownership or authority for every target; its ability to request evidence does not transfer that responsibility.
6.2 Rules of engagement. An accepted assessment configuration, authorization record, or signed rules-of-engagement document must define the scope of active testing. More intrusive activity, including destructive testing, denial-of-service simulation, social engineering, or testing of safety-critical or operational-technology systems, requires separate express written authorization accepted by Rapticore and a supported assessment offering. General acceptance of these Terms does not authorize those activities. Rapticore may request evidence of authorization and suspend an assessment when scope or authorization is uncertain.
6.3 Assessment effects and allocation of operational risk. Security assessments and automated actions can generate traffic, alerts, test records, resource charges, service degradation, data alteration or loss, and other effects, including in authorized environments. Customer must select appropriate targets and operating windows, notify affected stakeholders where necessary, maintain restorable backups, and confirm that permitted actions are suitable for its environment. Customer assumes the operational risks inherent in activities it authorizes. Rapticore will use commercially reasonable controls designed to keep activity within the accepted scope and limits. Customer is responsible for third-party infrastructure and consumption charges attributable to its authorized activity, except to the extent caused by Rapticore's breach. Liability for any breach remains governed by Section 18.
6.4 Automated action authority. Customer may expressly authorize actions through an approved policy, workflow, integration permission, or individual approval. That authorization applies only within its configured scope, permissions, and limits and continues until revoked or expired. It may permit actions without a separate human approval for every step. Access to an AI Feature or a generated suggestion alone is not blanket authorization to change systems. Customer is responsible for reviewing its selected policy and the authority it grants. Rapticore will maintain controls designed to apply accepted scope, permission, and approval settings in components under its control.
6.5 Stopping and evidence. Customer must promptly stop or revoke activities that exceed its authority or create unacceptable impact, using available controls and its own credentials or network access where needed. Revocation may not undo completed actions or immediately stop an already dispatched third-party operation. Rapticore will take reasonable steps to stop affected activities under its control when notified. Customer-specific evidence and findings are confidential Customer Data. Rapticore may not publish identifiable findings about Customer without separate permission, except as legally required.
7 Customer Data and service improvement
7.1 Ownership and limited permission. Customer retains its rights in Customer Data. Customer grants Rapticore permission to access, collect, transmit, host, reproduce, analyze, and otherwise process Customer Data only to provide, secure, maintain, troubleshoot, and support the Services for Customer, follow Customer's lawful instructions, meet legal obligations, and create Anonymized Service Data as permitted below. Access is limited to personnel and permitted service providers that need it and are subject to appropriate confidentiality and data-protection duties. This is not a license to sell, publish, or generally commercialize Customer Data.
7.2 Confidential treatment. Customer Data remains protected by Section 11, the DPA, and any BAA. Prompts, retrieved context, Outputs, assessment evidence, embeddings, caches, logs, and feedback containing Customer Data receive the same protection regardless of format or storage location. Rapticore will not use Customer Data for advertising, sell it, or disclose it for cross-context behavioral advertising. Rapticore will implement and maintain logical separation and access controls designed to prevent disclosure of one customer's Customer Data through another customer's prompts, retrieval indexes, agent memory, or Outputs.
7.3 Anonymized service improvement. Subject to applicable law and any DPA or BAA, Customer authorizes Rapticore to create and use Anonymized Service Data to operate, analyze, evaluate, maintain, and improve the Services. Permitted purposes include reliability and performance analysis, capacity planning, quality testing, non-training evaluation of AI Features, user-experience improvements, and improving detection rules and workflows without Model Training. Rapticore may retain such data after termination and combine it with other qualifying anonymized information for those purposes. Model Training remains prohibited under Section 8.4 even after anonymization.
Rapticore will apply reasonable technical and organizational measures designed to prevent identification or reconstruction, assess reasonably available means of linkage, maintain and use this data in anonymized form, and not attempt reidentification except for controlled testing solely to validate deidentification where applicable law permits. Recipients must be contractually bound to equivalent restrictions. Rapticore will use aggregation, suppression of small groups, generalization, or other measures appropriate to the data and linkage risk; no single numerical threshold alone establishes anonymization. Rapticore may publish aggregate service statistics only if they do not identify Customer or disclose its confidential information. Rapticore owns Anonymized Service Data and improvements developed through its permitted use, subject to these restrictions. Rapticore may commercialize resulting product improvements and generalized detection rules that do not disclose Customer Data; this does not authorize the sale of derived datasets or Model Training. If data cannot meet the definition of Anonymized Service Data, it remains Customer Data and cannot be reused for general service improvement under this clause. Creating anonymized data from personal or regulated data is itself processing subject to the applicable legal and contractual restrictions.
7.4 Content and feedback boundaries. Confidential uploads, prompts, findings, support material, and integration data remain Customer Data. Public community contributions are governed by the publication terms expressly presented for that forum. Voluntary product suggestions are subject to Section 10.4. Neither mechanism permits Rapticore to treat confidential service content as public or to obtain Model Training rights without Section 8.4 authorization.
7.5 Restricted data. Customer must not submit protected health information to a Rapticore-managed component unless Rapticore has expressly agreed to that use and any required BAA is in place. Payment-card data outside an authorized payment-provider flow, government-classified information, export-controlled technical data, or other specially regulated data may be processed only where the offering and necessary written agreements expressly support it. Sensitive payment authentication data must not be submitted to prompts, support, or assessment repositories. Ordinary source code, security logs, credentials, and personal data reasonably necessary for an authorized security function are not categorically prohibited, but Customer must use appropriate controls and agreements.
Customer must promptly notify Rapticore of a prohibited submission and cooperate with lawful containment, return, or deletion. Rapticore may isolate the affected content, restrict the relevant functionality, or decline unsupported processing. Customer will reimburse reasonable, documented incremental costs directly caused by its breach of this Section, except to the extent attributable to Rapticore's breach or other conduct excluded under Section 18.2. This reimbursement and the indemnity in Section 18.2 allocate contractual costs; they do not transfer or waive statutory duties, prevent a legally applicable business-associate relationship, or authorize processing without required agreements. Customer-hosted processing, remote support, telemetry, and AI routes must all be considered when determining the applicable duties.
7.6 Data-protection roles. For personal data in Customer Data, Rapticore acts as processor or service provider on Customer's behalf, or as subprocessor where Customer is a processor, to the extent those roles apply. Customer determines the lawful purpose and instructions. Rapticore may act as an independent controller or business for account administration, billing, website operations, fraud prevention, and business contacts, as described in its Privacy Policy; this does not expand its rights over service content.
Where Customer purchases through an authorized reseller identified in the Order, Rapticore may exchange necessary account, Order, metered-usage totals, and payment records to administer the identified purchase, provide authorized support, and meet related legal, tax, accounting, security, or dispute needs. Rapticore will not disclose that information for unrelated prospecting, advertising profiles, onward sale, or Model Training. These restrictions govern Rapticore's disclosure decisions; they are not a guarantee of an independent reseller's conduct or a representation that every reseller activity is processing on Rapticore's behalf. A reseller's independent collection and lawful handling of its own transaction records are governed by its applicable notice, agreement, and law. Rapticore remains responsible for its own obligations under the Agreement and applicable law.
Before disclosure, Rapticore will establish the required lawful basis and any binding recipient restrictions required by applicable law or the Agreement, and will restrict or suspend disclosures where those requirements cannot be met. Required permissions and agreements depend on the actual processing role; Customer's acceptance does not substitute for an individual's permission where law requires it. Detailed security content requires a separately authorized support or service workflow and any required processing agreement. The parties will put any legally required DPA, processing details, and transfer safeguards in place before the relevant processing begins. These Terms do not themselves amend a reseller's separate agreement.
8 AI models and AI data handling
8.1 Local and remote processing. AI Features may use local models, remotely hosted models, Rapticore-managed model services, or Customer-connected models and provider accounts. Some workflows may use multiple models. Subject to the agreed deployment and data restrictions, Customer authorizes inference using Customer Data reasonably necessary for enabled functionality. Local inference does not guarantee that every other component is local. Remote inference may transmit prompts, selected code, evidence, logs, context, and other relevant Customer Data to a model service; data is not necessarily anonymized before such processing.
8.2 Disclosure and routing controls. Before routing Customer Data through a Rapticore-managed AI arrangement, Rapticore will make available through the Order, Documentation, provider information, or configuration flow the relevant provider or processing arrangement, data categories, material retention or human-review conditions, and available regional restrictions. Rapticore will implement and maintain routing and access controls designed to enforce Customer's supported configuration and express contractual restrictions for components under Rapticore's control. Customer is responsible for settings and connectivity in components it controls.
Rapticore may select, replace, or use fallback providers within the authorized arrangement, subject to agreed protections and applicable subprocessor notice and objection rights. This does not authorize a remote fallback for an agreed local-only route. If no permitted route is available, Rapticore may pause or disable the affected feature. A change outside an agreed local-only, provider, or regional restriction requires Customer's authorization through the applicable Order or configuration process and any required contractual amendment.
8.3 Rapticore-managed providers. Where Rapticore engages an AI provider to process Customer Data on its behalf, that provider is subject to the applicable subprocessor arrangements. Rapticore will select and configure providers under binding written terms that restrict use of Customer Data, prompts, and Outputs for Model Training, consistent with Section 8.4. These terms may be an applicable accepted provider agreement and need not be individually negotiated. Rapticore will not enable a managed route for which those restrictions cannot be established, absent the separate authorization required by Section 8.4. Rapticore remains responsible for its providers' performance of the obligations it delegates under this Agreement. No universal zero-retention, no-human-access, or named-provider guarantee is made unless expressly agreed. Permitted security or abuse-monitoring retention must be disclosed, limited to its stated purpose, and consistent with the DPA and other commitments; it does not authorize Model Training.
8.4 No Model Training without a separate agreement. Rapticore will not use Customer Data, prompts, Outputs, customer-related account, usage, or support data, or data derived from any of them, including Anonymized Service Data, to train, fine-tune, retrain, distill, or otherwise update Rapticore's or a third party's AI or machine-learning models unless a separate written agreement expressly authorizes that use. That agreement must be signed or separately affirmatively accepted by an authorized Customer representative and specifically identify the data, permitted training purposes, relevant model or provider scope, applicable retention, and any withdrawal terms or limits. It may be a dedicated addendum or an express provision in a negotiated Order or other agreement that specifically overrides this Section. General service-improvement language, a privacy-policy update, submission of feedback, use of an AI Feature, and default or preselected settings are insufficient. Any additional legally required permissions must also be obtained.
This restriction does not prevent Model Training on independently developed Rapticore laboratory data, independently obtained public or licensed information for which training rights and a lawful basis exist, or synthetic data created without using the prohibited data as a source. Customer-related operational telemetry, redacted support content, free or trial usage, and synthetic derivatives of Customer Data remain within the restriction. Rapticore may offer a separate, voluntary training program under the specific agreement described above; participation is not a default condition of using the Services.
8.5 Inference and retrieval. Inference, temporary context handling, Customer-specific embeddings and retrieval, and evaluation without updates to model parameters may be used to deliver the enabled Services. Their stores, logs, caches, and Outputs remain Customer Data where applicable and are subject to the same retention, isolation, security, and deletion requirements. They may not be repurposed as a shared customer-content knowledge base. Calling an activity evaluation, feedback, synthetic-data generation, or service improvement does not exempt Model Training from Section 8.4.
8.6 Customer-connected models. Where Customer independently contracts with a provider or supplies its own model, endpoint, or API key, Customer controls its provider agreement, account configuration, permissions, geographic settings, and direct provider charges. That provider may have different retention, training, or review terms, which Customer must assess before connecting it. Rapticore does not amend or guarantee Customer's separate provider contract. Rapticore's own handling and routing of data still must comply with this Agreement, and Rapticore will not opt Customer into provider training or use the connection as an indirect way to train models on Customer Data without Section 8.4 authorization. Customer's independent instructions outside the Services do not expand Rapticore's rights. Customer's use of its own credentials does not by itself determine the parties' legal data-protection roles.
8.7 Limits of AI results. Outputs may be inaccurate, incomplete, nonunique, or unsuitable for a particular environment. AI Features can miss vulnerabilities or produce false positives and cannot guarantee a secure system or compliance outcome. Customer must apply review and validation appropriate to the consequence of a decision or action, including the controls in Section 6. AI-generated code may be subject to third-party rights or licenses. AI Features are provided subject to the warranties, exclusions, and liability limits in Sections 15 and 18.
9 Third-party integrations
Customer may enable integrations with repositories, cloud platforms, ticketing systems, identity providers, communications tools, and other Third-Party Services. Customer authorizes the access and transmission reasonably necessary for its selected functionality within the permissions granted. Customer must obtain required rights and may revoke the integration, although doing so may disable dependent functionality and does not reverse completed actions.
Customer's independently procured Third-Party Services are governed by its agreements with those providers. Rapticore is not responsible for their independent performance or terms, but remains responsible for its own integration software, data handling, and breaches of this Agreement. Third parties engaged by Rapticore to provide the Services are not excluded from Rapticore's responsibilities merely because they are third parties. Section 8 applies specifically to AI providers. External links do not imply endorsement.
10 Intellectual property and Outputs
10.1 Rapticore Technology. Rapticore and its licensors retain ownership of Rapticore Technology, general methods, rules, templates, reusable tools, and improvements, including those developed through permitted use of Anonymized Service Data or Feedback. Customer retains its rights in Customer Data and customer-specific Outputs. A customer-specific report or result does not transfer the underlying detection method, orchestration, or other reusable technology. No implied license or transfer of source code, model weights, or underlying product technology is granted. Rights in customer-funded development are governed by an applicable SOW.
10.2 Customer-specific Outputs. As between the parties and to the extent permitted by law, Customer owns customer-specific Outputs, excluding embedded Rapticore Technology and third-party materials. Rapticore assigns to Customer any rights it holds in those customer-specific Outputs. For Rapticore Technology embedded in an Output, Rapticore grants a perpetual, worldwide, nonexclusive, royalty-free license to use, copy, modify, and share that technology only as part of using or sharing the Output for Customer's business purposes, including remediation and disclosure to its personnel, advisors, auditors, insurers, clients where authorized, and service providers. This does not license the standalone Rapticore platform or models. Third-party materials remain subject to their licenses. No guarantee is made that AI-generated material qualifies for copyright protection or is exclusive to Customer.
10.3 Open-source and third-party software. Identified open-source components and separately licensed third-party software or model weights are governed by their applicable licenses. Nothing in these Terms restricts rights those licenses expressly grant. Supplying or integrating an open-source component does not make all Rapticore software open source or grant rights in unrelated proprietary components.
10.4 Feedback. For product suggestions, enhancement requests, and other voluntary feedback intended for Rapticore's product development (Feedback), Customer grants Rapticore a perpetual, irrevocable, worldwide, nonexclusive, transferable, sublicensable, royalty-free right to use, reproduce, modify, incorporate, and commercialize the Feedback for any lawful purpose without payment or attribution. This license does not transfer Customer Data, authorize disclosure of Confidential Information, cover a consumer review protected from such a license by law, or override Section 8.4. Support attachments and embedded customer content remain subject to Sections 7 and 11.
11 Confidentiality and security
11.1 Confidential information. Confidential Information means information disclosed or accessed in connection with the Agreement that is marked confidential or should reasonably be understood to be confidential, including Customer Data, nonpublic security findings, credentials, business information, and nonpublic Rapticore Technology, nonpublic benchmark results, negotiated pricing, and security documentation. It excludes information the recipient can demonstrate was lawfully known without restriction, independently developed without the discloser's information, lawfully received without confidentiality duties, or publicly available without a breach.
11.2 Protection and disclosure. Each recipient will use Confidential Information only for the Agreement's permitted purposes, protect it with at least reasonable care, and disclose it only to personnel, advisors, and authorized providers with a need to know and appropriate confidentiality duties. Each party is responsible for recipients to whom it delegates obligations. Legally compelled disclosure is permitted only to the required extent, with advance notice where lawful and reasonable assistance with protective measures. No residual-knowledge exception permits reuse of confidential data or circumvention of Section 8.4.
11.3 Security safeguards. Rapticore will maintain reasonable administrative, technical, and physical safeguards appropriate to the nature of Customer Data it processes and its Services, including controls for access, confidential handling, and service security. Specific security measures, residency, audit rights, and compliance commitments are governed by the applicable security schedule, DPA, BAA, or Order. Customer will maintain appropriate safeguards for components under its control under Sections 4 and 5.
11.4 Security incidents. Rapticore will notify Customer without undue delay after becoming aware of a breach of security resulting in unauthorized access to, acquisition, disclosure, destruction, loss, or alteration of Customer Data in systems controlled by Rapticore or its subprocessors. Rapticore will promptly assess credible indications of a potential breach. Notification will not await completion of the investigation, identification of every affected record, final forensic confirmation, or completion of an assessment of the risk of harm. Earlier notification, broader definitions, or other requirements imposed by applicable law, a DPA, or a BAA control. Rapticore will provide information reasonably available for Customer's response, supplement material facts as they become available, and take reasonable containment and remediation measures within its control. Routine errors and unsuccessful attempts that do not compromise Customer Data are excluded unless applicable law or agreement requires otherwise. Notification is not an admission of fault or liability. Each party retains its own legal notification duties; Customer is responsible for notices concerning its affected personnel, users, or other persons except as law or an express agreement assigns otherwise.
11.5 Duration. General confidentiality duties continue for five years after termination. Protection of trade secrets continues while they remain trade secrets. Customer Data, personal data, credentials, and nonpublic vulnerability details remain protected for as long as retained or as otherwise required by law. Return and deletion are governed by Section 16 and the applicable DPA or BAA.
12 Acceptable use
Customer must not use the Services unlawfully; assess or alter systems without required authorization; steal credentials or data; distribute harmful content outside an authorized supported security workflow; harass others; impersonate another customer; access another customer's data; interfere with Rapticore's service infrastructure; bypass license, scope, approval, or access controls; or enable others to do so.
Customer must not copy, resell, sublicense, or modify Rapticore Technology beyond its license, remove proprietary notices, reverse engineer proprietary software or models except where applicable law permits notwithstanding this restriction, or use unauthorized access to obtain confidential technology. Customer must not use access to the Services, nonpublic Documentation, or proprietary components to copy material product functionality or develop, train, or improve a competing commercial offering. This restriction does not prohibit independent development without such use, lawful interoperability, rights expressly granted by an open-source license, or activity that applicable law does not permit Rapticore to restrict. Customer may use documented APIs, supported automation, developer integrations, and coding agents within the purchased scope, including for its own remediation and security work. Internal evaluation is permitted. For business use, Customer must not publish or disclose nonpublic performance benchmarks or comparative test results without Rapticore's prior written consent, except to its personnel and professional advisors under confidentiality for internal evaluation. This restriction does not apply to consumer reviews or assessments protected by the Consumer Review Fairness Act or other applicable law, legally protected disclosures, or communications with regulators. Customer must not knowingly misrepresent results or disclose protected Rapticore Confidential Information.
Scanning, crawling, analyzing suspicious code, and testing security controls are not prohibited merely because they are security activities when performed through supported functionality within authorized scope and applicable law. These permissions do not authorize testing Rapticore's infrastructure or another customer's environment. A suspected vulnerability in Rapticore's own Services should be reported to support@rapticore.com; that reporting channel is not a grant of testing authorization.
13 Fees and usage charges
13.1 Pricing and payment. Fees, currency, billing frequency, committed quantities, applicable taxes, included consumption, and any overage rates are stated in the Order. Self-service charges are due at purchase and on the accepted renewal or usage schedule. Invoiced Orders are due within 30 days after invoice unless the Order says otherwise. Customer authorizes charges to its selected payment method for amounts accepted in the Order and valid renewals, including disclosed metered charges. Payment processing may be performed by a payment provider.
13.2 AI and infrastructure charges. AI usage, premium models, assessment execution, cloud infrastructure, and other variable consumption may be included, metered, prepaid, or charged separately under the Order. Rapticore will make the applicable units, rates or pricing method, and overage treatment available before paid consumption is enabled. Customer is responsible for consumption initiated through its accounts, integrations, agents, configurations, or automated policies under Section 5.1, including disclosed in-flight and delayed-reported usage. Unless an enforced limit is expressly included, lack of an alert or failure to pause usage does not waive charges under the accepted pricing terms. Rapticore may limit or suspend excess consumption and may require prepayment or additional capacity before further use. Customer-connected provider charges are payable directly by Customer unless otherwise agreed. This Section does not authorize an undisclosed rate or override a binding spending limit.
13.3 Usage controls. Rapticore's usage records govern billing subject to reasonable review of documented errors. Budgets, estimates, and alerts are informational unless expressly identified as enforced limits. An enforced limit may still allow charges for disclosed in-flight or delayed-reported usage; the relevant limitation must be disclosed. Customer may dispute a charge in good faith within 30 days after the invoice or statement, without limiting mandatory rights, and must timely pay undisputed amounts while the parties investigate. Billing disputes may be submitted to support@rapticore.com.
13.4 Taxes and refunds. Fees exclude applicable transaction taxes, which Customer pays except taxes on Rapticore's net income. Fees are nonrefundable except where the Agreement or mandatory law expressly provides a refund. Annual or other fixed commitments remain payable even if billed in installments; canceling renewal does not cancel the current commitment. Prepaid credits expire or roll over only as expressly disclosed when purchased and as permitted by law.
13.5 Late payment. Overdue undisputed amounts may accrue interest at the lesser of 1.5 percent per month and the lawful maximum. Customer will pay reasonable costs of collecting overdue undisputed amounts, including reasonable legal fees where permitted by law. Rapticore may suspend affected Services after at least 10 days' notice of an overdue undisputed amount and an opportunity to resolve it, subject to Section 16. A payment dispute pursued in good faith is not itself grounds to suspend the disputed portion if Customer pays undisputed amounts and reasonably cooperates.
13.6 Reseller billing. Where an Order identifies an authorized reseller as the billing and collection party, Customer will pay that reseller using the agreed billing terms. Timely payment to that designated reseller satisfies Customer's corresponding payment obligation for the identified Rapticore Services; Customer will not be required to pay Rapticore again for the same charges solely because the reseller delays or fails to remit them. On a reasonable request, Customer will provide appropriate payment evidence without unnecessary sensitive payment information. Rapticore will not treat Customer as in payment default or suspend paid Services solely for the reseller's remittance delay. This does not extend the purchased term or scope or prevent suspension on another ground permitted by the Agreement. Billing corrections, refunds, renewal changes, and cancellations may be handled through the reseller channel identified in the Order; Customer may also contact Rapticore at support@rapticore.com for coordination. A timely cancellation through the designated channel is measured when received, without limiting mandatory cancellation rights. Customer remains responsible for amounts properly due under its accepted commitments. An Order for Rapticore Services purchased through a reseller must be accepted by Rapticore, including through an authorized electronic ordering process, and must separately identify the Rapticore Services, quantities or usage units, term, and charges, and the provider and charges for independent reseller services. Any bundle discount and its allocation must be shown. Rapticore may require missing information or clarification before accepting a new Order. An omission in an accepted Order does not make independent reseller services Rapticore Services or expand Rapticore's obligations; Section 18.5 supplies the liability-fee allocation fallback. This Section governs Customer's purchase and does not itself impose an order-format obligation on a reseller that is not a party to the Agreement.
14 Renewal and cancellation
14.1 Self-service renewal. A self-service subscription renews automatically only if the renewal arrangement was clearly disclosed and affirmatively accepted at checkout. Unless the accepted Order states otherwise, renewal is for the same billing period and purchased scope at the previously accepted rate, subject to a properly notified price change. Checkout and confirmation must identify recurring charges, the renewal period, any trial conversion, and how to cancel. Rapticore will provide required reminders and keep required consent records.
14.2 Self-service cancellation. Customer may turn off automatic renewal at any time before the next renewal through an accessible online cancellation method identified in its account or confirmation. Cancellation does not require a sales call. If that method is unavailable, Customer may email support@rapticore.com from an authorized account contact; Rapticore will use the request's receipt time for the renewal deadline and confirm cancellation. Cancellation stops subsequent renewals immediately and access ordinarily continues through the paid term. No 30-day advance cancellation requirement applies to self-service subscriptions. Uninstalling software or disconnecting an integration does not by itself cancel billing.
14.3 Negotiated Orders. Renewal of a negotiated business Order follows its stated provisions. If it expressly provides for automatic renewal but is silent on the nonrenewal deadline, either party may give notice at least 30 days before its end. A negotiated Order that does not provide for automatic renewal expires at the end of its term unless renewed by agreement. Mandatory law overrides any incompatible notice or cancellation condition.
14.4 Price changes. Rapticore will not increase committed subscription prices during the current term unless an accepted Order expressly provides an adjustment mechanism. For future self-service renewals, Rapticore will provide at least 30 days' advance notice of an increase; if the notice is too late, the increase moves to a later renewal. Any additional statutory notice window or reminder also applies. For negotiated automatic renewals, notice must arrive early enough to give Customer at least 30 days to exercise nonrenewal before the applicable deadline. Customer may reject a future increase by canceling renewal. Material changes requiring renewed affirmative consent will not take effect without that consent.
14.5 Mandatory protections. Nothing limits legally required withdrawal, cancellation, refund, billing-dispute, or renewal rights. Where consumer subscription rules apply, Rapticore will supply the required disclosures, affirmative consent, acknowledgment, reminders, and cancellation method.
15 Warranties and disclaimers
15.1 Mutual authority. Each party represents that it has authority to enter into and perform the Agreement. Each party will comply with laws applicable to its performance. Customer's specific permissions and authorization obligations are described in Sections 5 and 6.
15.2 Limited paid-service warranty and remedy. During the paid Subscription Term, Rapticore warrants that the Services will materially conform to the applicable Documentation when used as authorized in a supported environment, and purchased professional services will be performed with reasonable skill and care. Customer must give written notice within 30 days after discovering a material nonconformity and provide reasonable diagnostic information and cooperation. Rapticore may, at its option, correct the nonconformity, supply a materially equivalent workaround, or reperform deficient professional services. If Rapticore cannot provide an applicable remedy within 45 days after receiving adequate notice and cooperation, either party may terminate the materially affected Service, and Rapticore will refund prepaid unused subscription fees for that Service or fees for the deficient professional services that cannot reasonably be reperformed. These are Customer's sole and exclusive contractual remedies, and Rapticore's entire obligation, for breach of this limited warranty. Other claims, if any, remain subject to Section 18 and mandatory law.
15.3 Exclusions. The limited warranty does not cover problems to the extent caused by unauthorized modifications, unsupported environments, Customer or independently procured third-party systems, or use contrary to the Agreement or Documentation. Trial, free, evaluation, and expressly designated beta features are provided as is, to the extent permitted by law, without the conformity warranty or an SLA unless expressly agreed. Sections 7, 8, and 11 continue to govern their data handling.
15.4 Disclaimers. EXCEPT FOR EXPRESS WARRANTIES IN THE AGREEMENT AND NONWAIVABLE LEGAL RIGHTS, RAPTICORE DISCLAIMS IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. THE SERVICES DO NOT GUARANTEE DETECTION OF EVERY VULNERABILITY, PREVENTION OF EVERY INCIDENT, ERROR-FREE AI OUTPUTS, SUCCESSFUL REMEDIATION, OR REGULATORY CERTIFICATION. REPORTS AND COMPLIANCE MAPPINGS ARE INFORMATIONAL AND DO NOT REPLACE CUSTOMER'S PROFESSIONAL JUDGMENT OR AN INDEPENDENT AUDIT.
16 Suspension termination and data return
16.1 Suspension. Rapticore may suspend access, an assessment, or other functionality to address an actual or reasonably suspected security threat, unauthorized use, unlawful instruction, material breach, unsupported regulated-data submission, or overdue undisputed payment under Section 13.5, or to comply with law or a provider restriction necessary to supply the Services lawfully. Rapticore will use reasonable efforts to limit the suspension to the affected activity where practicable and provide notice and an opportunity to remedy unless immediate action is reasonably necessary or notice is prohibited. Access may resume once Customer has remedied the grounds and provided reasonable assurance against recurrence. A suspension caused by Customer's breach does not reduce committed fees. Other service interruptions are governed by any applicable SLA and this Agreement.
16.2 Termination for cause. Either party may terminate the affected Order or, if appropriate to the breach, the Agreement if a material breach remains uncured 30 days after written notice. A breach incapable of cure may justify immediate termination where lawful. Either party may terminate to the extent permitted by insolvency law if the other ceases business or enters an applicable insolvency proceeding. Terminating one Order does not automatically terminate unrelated Orders.
16.3 Financial consequences. If Customer terminates for Rapticore's uncured material breach, Rapticore will refund prepaid fees for the unused portion of the terminated Services. If Rapticore terminates for Customer's uncured material breach, unpaid committed fees for the remaining term become due only to the extent enforceable under applicable law, and prepaid fees are not refundable except as required by law. Other express refund rights remain applicable.
16.4 Ending licensed use. On expiry or termination, Customer must stop using affected licensed Services, revoke integrations as appropriate, and uninstall subscription-licensed Customer-Hosted Software, except for an expressly granted perpetual license or agreed transition use. Customer may retain its Customer Data, lawfully obtained Outputs, and archival records. Expiry does not authorize Rapticore to erase data on Customer-controlled infrastructure. Obligations intended to survive include accrued payment, ownership, Output licenses, confidentiality, data-use restrictions, deletion duties, indemnities, liability limits, and dispute resolution.
16.5 Export and deletion. Unless a DPA, BAA, mandatory law, or an agreed Order requires different handling, Customer may request an export of Customer Data held in paid hosted Services within 30 days after expiry or termination. Rapticore may provide an available standard export or limited retrieval access, subject to necessary security and legal restrictions and payment of undisputed past-due amounts. That payment condition does not delay deletion, mandatory privacy rights, or return required by law, a DPA, or a BAA. Custom formats, transition consulting, and restoration of archived material may require a separate fee. Customer should export needed data during the Subscription Term. A shorter window for free, trial, or beta access applies only if disclosed before use; otherwise the 30-day window applies.
After the export window, Rapticore will delete Customer Data from active service systems within 30 days, unless earlier deletion is lawfully required or agreed. Residual backups will be deleted or irreversibly overwritten within 90 additional days, or a shorter required period. Pending deletion, backups remain protected, are excluded from ordinary use, and may be accessed only for necessary recovery, security, or legal purposes; deletion instructions will be reapplied to any restored copy. Limited records may be retained to the extent and for the period necessary to meet legal obligations, preserve evidence for actual or reasonably anticipated disputes, or maintain security and compliance records, where permitted by the governing DPA, BAA, and law. Such retained data is restricted to those purposes and excluded from Model Training and general product improvement.
Deletion covers associated customer-specific retrieval indexes, embeddings, AI logs, and caches under Rapticore's control. Rapticore will require its managed subprocessors to comply with the applicable deletion requirements. Customer manages deletion in its own infrastructure and independently procured provider accounts. Anonymized Service Data satisfying Section 7.3 may be retained under that Section. Export availability does not require retention beyond an earlier legally required deletion deadline.
17 Changes to Services and Terms
17.1 Service evolution. Rapticore may update and improve the Services. It will not materially reduce the core paid functionality committed in an Order during its current term without providing a materially equivalent alternative or a right to terminate the affected Service and receive a prorated refund of prepaid unused fees. Necessary emergency security or legal changes may take effect promptly, with notice as practicable. For material deprecation of an API, supported deployment, or paid product, Rapticore will use commercially reasonable efforts to provide at least 60 days' notice and reasonable migration information where practicable, subject to urgent legal, security, or third-party dependency changes. This does not promise new features or indefinite support for every version.
17.2 Changes to Terms. Rapticore will identify the version and effective date of updates. Material changes for existing paid Customers ordinarily take effect at the next renewal after at least 30 days' advance notice, with additional time where needed to exercise nonrenewal. During a committed term, changes require agreement unless narrowly necessary to comply with law or address a material security risk; if such a mandatory change materially adversely affects Customer, Customer may terminate the affected Service and receive a prorated refund of prepaid unused fees. Nonmaterial clarifications may take effect on notice. New Customers accept the version presented to them. Where affirmative acceptance is required, Rapticore will obtain it. No unilateral update authorizes Model Training, applies new arbitration terms retroactively to an existing dispute, or overrides a signed agreement.
18 Indemnification and liability
18.1 Rapticore intellectual-property indemnity. For paid generally available Services, Rapticore will defend Customer against a third-party claim alleging that authorized use of Rapticore-supplied proprietary Services infringes that party's United States patent, copyright, trademark, or trade secret, and pay damages and reasonable costs finally awarded or agreed in a settlement approved by Rapticore. This excludes claims to the extent arising from Customer Data; modifications not made or authorized by Rapticore; combinations with items not supplied or specified by Rapticore where the claim would not otherwise arise; independently procured third-party services; use outside the Agreement; continued challenged use after Rapticore provides a reasonably suitable noninfringing alternative or directs suspension; or use of a superseded version after a supported noninfringing update is made available without an additional license charge. Free, trial, beta, evaluation, and separately licensed third-party components are not covered. AI-generated Outputs are not separately covered unless a signed Order expressly provides otherwise; covered claims concerning the underlying proprietary Services remain subject to this Section.
If a covered claim is made or reasonably likely, Rapticore may obtain continued-use rights, modify or replace the affected Service, or, if those options are not commercially reasonable, terminate it and refund prepaid unused fees. This is Customer's sole and exclusive contractual remedy and Rapticore's entire obligation for third-party intellectual-property infringement claims, subject to Sections 18.3 through 18.6 and mandatory law.
18.2 Customer indemnity. Customer will defend, indemnify, and hold harmless Rapticore, its affiliates, and their officers, directors, employees, and service providers against third-party claims, demands, and proceedings, including governmental proceedings to the extent legally indemnifiable, arising from: (a) Customer Data or Customer's instructions infringing, misappropriating, or violating a third party's rights or applicable law; (b) Customer's lack of the authority required by Section 6 for an assessment, access, processing, or modification, including activity initiated by its Authorized Users or automated policies; (c) Customer's submission of protected health information, payment-card data, export-controlled technical data, or other restricted data to a Rapticore-managed component in breach of Section 7.5; or (d) Customer's or its Authorized Users' unlawful use of the Services, or breach of Section 12 concerning unauthorized access, credential or data theft, interference with systems, infringement or misappropriation of rights, or circumvention of license, scope, approval, or access controls. Publication of a benchmark or comparative assessment does not, by itself, trigger this indemnity, and nothing in this Section restricts a review or disclosure protected by applicable law. Covered amounts include reasonable defense costs and legal fees, damages finally awarded, settlements approved under Section 18.3, and fines or penalties only to the extent indemnification is permitted by applicable law.
This indemnity does not apply to the extent a claim is caused by Rapticore's breach, unauthorized processing, negligence, fraud, or willful misconduct. It does not create authority to test a third party's systems or relieve Rapticore of its own statutory duties. Customer's obligations under this Section are not subject to Sections 18.4 or 18.5.
18.3 Indemnity procedure. The protected party must give prompt notice, with delay relieving obligations only to the extent materially prejudicial, permit the indemnifying party to control the defense through reasonably qualified counsel, and provide reasonable cooperation at that party's expense. The protected party may participate through its own counsel at its expense, except that reasonable separate-counsel costs are covered where a material conflict of interest requires separate representation. If the indemnifying party fails to assume or diligently conduct a covered defense after notice and a reasonable opportunity to do so, the protected party may defend and recover reasonable covered costs, subject to the applicable limitations. No settlement may admit fault, impose a nonmonetary obligation on a protected party, or fail to release it from the covered claim without its prior written consent, not unreasonably withheld. An indemnity does not bind a regulator or restrict cooperation required by law.
18.4 Excluded damages. TO THE MAXIMUM EXTENT PERMITTED BY LAW AND SUBJECT TO SECTION 18.6, NEITHER PARTY IS LIABLE FOR INDIRECT, SPECIAL, INCIDENTAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES; LOST PROFITS, REVENUE, GOODWILL, BUSINESS OPPORTUNITIES, OR ANTICIPATED SAVINGS; BUSINESS INTERRUPTION; OR LOSS OF USE OR LOSS OR CORRUPTION OF DATA, ARISING OUT OF OR RELATING TO THE AGREEMENT, WHETHER ASSERTED AS DIRECT OR INDIRECT DAMAGES. RAPTICORE IS NOT LIABLE FOR CUSTOMER'S COSTS OF SUBSTITUTE SERVICES, NOTIFICATION, CALL-CENTER SERVICES, OR CREDIT OR IDENTITY MONITORING, OR FINES OR PENALTIES IMPOSED ON CUSTOMER, EXCEPT TO THE EXTENT AN EXPRESS SIGNED AGREEMENT OR NONWAIVABLE LAW PROVIDES OTHERWISE. Covered third-party awards, settlements, and defense costs payable under Section 18.1 are not excluded solely because of their characterization as consequential damages, but remain subject to Section 18.5. Customer's obligations under Section 18.2 are governed by Section 18.6.
18.5 Aggregate liability cap. SUBJECT TO SECTION 18.6, EACH PARTY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE AGREEMENT WILL NOT EXCEED THE FEES ACTUALLY PAID FOR THE AFFECTED RAPTICORE SERVICES DURING THE 12 MONTHS IMMEDIATELY BEFORE THE FIRST EVENT GIVING RISE TO LIABILITY, PLUS UNPAID FEES CONTRACTUALLY ACCRUED FOR THOSE SERVICES ACTUALLY PROVIDED DURING THAT PERIOD, WITHOUT DOUBLE COUNTING. Accrued fees are included whether or not an invoice has been issued or payment is yet due. Unpaid commitments for future service periods, taxes, refunds, credits, and charges paid directly to independent third-party providers are excluded. For prepaid multiyear fees, the paid-fee base instead includes only the portion allocable to the affected Services during that 12-month period, regardless of when the prepayment was actually made. No amount is counted both as paid and accrued.
For direct purchases, the fee base uses Customer's charges for the affected Rapticore Services under the applicable Order. For purchases through an authorized reseller, it uses the charges for those Rapticore Services separately identified in Customer's applicable Order, including amounts paid to the designated reseller, regardless of when the reseller remits them to Rapticore. Separately identified reseller professional services, managed services, and other independent offerings are excluded. If an Order omits the allocation for a combined charge, only the portion reasonably attributable to the affected Rapticore Services is included. That portion is determined from the documented quantities, scope, and term using the relative standalone selling prices of the bundled components in effect when the Order was accepted, with bundle discounts allocated proportionately. Where a standalone price is unavailable, a reasonable estimate supported by contemporaneous quotes and comparable transactions is used. The allocation cannot exceed the actual combined charge otherwise included under this Section, treat a paid component as free solely because it was not itemized, or use later price changes to increase the cap. Rapticore will provide a reasonable explanation and supporting calculation on request, with appropriate redaction of unrelated confidential information that does not prevent understanding the allocation; disputes follow Section 19. An applicable signed Order expressly accepted by Rapticore may expressly establish a different fee allocation or cap. Where all affected Services were expressly supplied without any fee, including free, trial, beta, or evaluation access supplied on that basis, the aggregate cap is USD 100. A paid subscription awaiting invoicing or payment is not no-charge access merely because no payment has yet been received.
This is a single aggregate cap, not a separate amount for each claim, claimant, Order, incident, or legal theory. Related claims arise from their first related event. Defense costs and amounts paid to resolve claims count toward the applicable cap. No claim obtains a higher or additional cap merely because it concerns confidentiality, security, personal-data processing, AI, Section 8.4, or Rapticore's indemnity. A different cap applies only if an applicable signed agreement expressly provides it, and does not stack with this cap unless that agreement expressly says otherwise.
18.6 Exceptions and risk allocation. Sections 18.4 and 18.5 do not limit: (a) Customer's payment obligations for agreed fees, taxes, and properly due collection costs; (b) Customer's defense, indemnity, and related obligations under Section 18.2; (c) Customer's liability arising from its lack of the authority required by Section 6, or its prohibited submission of restricted data under Section 7.5, including the reimbursement obligation there; or (d) either party's fraud, willful misconduct or willful injury, or any other liability that applicable law does not permit to be excluded or limited, including personal injury, gross negligence, or statutory liability to that extent. The Customer-specific exceptions do not make Customer responsible for loss to the extent caused by Rapticore conduct excluded under Section 18.2.
No automatic enhanced cap or IP indemnity applies to free, trial, beta, or evaluation access. Sections 18.4 and 18.5 apply regardless of legal theory, foreseeability, or failure of a limited remedy's essential purpose, to the extent permitted by law. They allocate commercial risk between the parties and do not limit a regulator's powers or bind persons who are not parties to the Agreement.
If an exclusion or limitation in this Section is unenforceable as applied to a claim, that exclusion or limitation will be severed only to the extent required by applicable law. Other exclusions and limitations remain effective to the extent permitted by law. Nothing in this paragraph limits a liability or remedy that applicable law prohibits the parties from limiting, or requires a court to reform an unlawful provision.
Neither party nor any person indemnified under this Agreement may recover the same loss more than once, whether through reimbursement, indemnification, damages, or another contractual remedy. Amounts already recovered for a loss will be credited against any other recovery for that same loss. This does not prevent recovery of separate losses or costs otherwise recoverable under this Agreement.
19 Dispute resolution
19.1 Informal resolution. A party should first send written notice describing the dispute and requested relief to the other party's notice contact. The parties will attempt good-faith resolution for 30 days. Either party may seek urgent interim relief, make a regulatory complaint, or file a claim necessary to preserve a limitation period without waiting. Failure to complete informal discussions does not waive nonwaivable remedies or automatically forfeit attorney-fee rights.
19.2 Individual arbitration. EXCEPT AS PROVIDED BELOW, THE PARTIES AGREE TO RESOLVE DISPUTES ARISING FROM THE AGREEMENT BY BINDING INDIVIDUAL ARBITRATION, AND WAIVE A JURY TRIAL FOR THOSE ARBITRABLE DISPUTES. The Federal Arbitration Act governs this provision. The American Arbitration Association (AAA) will administer under its applicable Commercial Arbitration Rules, or its Consumer Arbitration Rules where AAA or applicable law requires those rules. Applicable rules, filing information, and fee schedules are available at adr.org. The arbitrator will be selected under those rules.
19.3 Procedure and exceptions. For business disputes, the seat is San Francisco, California, with remote hearings permitted under the rules or by agreement. Consumer location, fees, and procedural protections apply where required. Each party pays fees as the applicable rules and law require; Rapticore will pay amounts necessary for enforceability where required by consumer law or AAA rules. The arbitrator may award remedies available under applicable law subject to enforceable contractual limits and must issue a reasoned award. Either party may bring an eligible individual claim in small-claims court or seek temporary relief from a court to protect confidential information, intellectual property, or system security pending resolution. Nonarbitrable claims and nonwaivable public injunctive relief may proceed in court as required by law.
19.4 Class waiver and severance. TO THE EXTENT PERMITTED BY LAW, CLAIMS IN ARBITRATION MUST BE BROUGHT INDIVIDUALLY, NOT AS CLASS OR REPRESENTATIVE CLAIMS. A court decides disputes about the formation or enforceability of this arbitration agreement or waiver. If a particular claim or remedy cannot lawfully be arbitrated individually, that claim or remedy may proceed in court and the remaining arbitrable matters proceed individually, unless law requires a different result. No provision eliminates a nonwaivable right to public injunctive relief. Courts and arbitrators may coordinate proceedings as permitted by law.
19.5 Consumer arbitration opt-out. If Customer purchases as an individual primarily for personal, family, or household purposes, Customer may opt out of this arbitration provision by emailing support@rapticore.com with the subject Arbitration Opt Out within 30 days after first accepting it, identifying Customer's legal name and account email and clearly stating the opt-out. Rapticore will not penalize a timely consumer opt-out. Business and organizational purchases do not have this opt-out unless an applicable signed agreement or mandatory law provides one. A prior valid opt-out remains effective unless Customer later expressly agrees otherwise. A timely applicable opt-out makes Section 20.1's court provisions apply and does not alter a separate signed dispute-resolution agreement.
19.6 Time to bring business claims. To the extent permitted by applicable law, a party must commence an action or arbitration concerning a business or organizational purchase within 12 months after the claim accrues under applicable law. This period does not apply to claims for payment, Customer's obligations or liabilities excluded from the cap under Sections 18.6(b) and 18.6(c), infringement or misappropriation of intellectual property, claims involving fraud or willful injury, or claims or limitation periods that law does not permit the parties to shorten. It does not apply to consumer purchases. Applicable discovery and mandatory tolling rules remain in effect, and the period is suspended during the 30-day informal-resolution process under Section 19.1. If this contractual period is unenforceable for a claim, the applicable statutory period governs.
20 General provisions and notices
20.1 Governing law and courts. California law governs without its conflict-of-laws rules, subject to the Federal Arbitration Act and mandatory protections of other applicable law. The United Nations Convention on Contracts for the International Sale of Goods does not apply. For disputes properly heard in court, the parties consent to state courts in San Francisco County, California, or federal courts in the Northern District of California, except where small-claims rules or mandatory law require otherwise. No standalone waiver of a jury trial in court is created by this clause.
20.2 Notices. Rapticore may send contractual notices to Customer's designated administrative or legal email. Material renewal, fee, termination, and Terms-change notices will be sent by email or another agreed durable method and may also appear in the product. Customer must keep its contacts current and maintain the ability to receive notices. Customer may send legal and arbitration notices to support@rapticore.com with the subject Legal Notice or Arbitration Opt Out, as appropriate; privacy requests go to privacy@rapticore.com. Support, billing, and cancellation requests go to support@rapticore.com. Postal notices may be sent to Rapticore Inc., 2227 Derby Street, Berkeley, CA 94705, unless an Order or a subsequent valid notice provides another address.
Email notices are effective when transmitted to the designated address unless the sender receives an automated delivery-failure response, subject to any stronger legal requirement. Mailed notices are effective on confirmed receipt. Subscription cancellation under Section 14.2 is measured when the request is received, whether or not confirmation has been sent. This Section does not replace formal service of process or requirements for commencing arbitration.
20.3 Assignment. Neither party may assign the Agreement without the other's consent, not unreasonably withheld, except to an affiliate or a successor in a merger, reorganization, or sale of substantially all relevant business or assets, provided the assignee assumes the Agreement and the assignment does not relieve accrued obligations. Any transfer of Customer Data must remain within the Agreement and applicable law. An impermissible assignment is ineffective to the extent permitted by law.
20.4 Limited customer identification. Unless a signed agreement, an accepted Order, or Customer's prior written notice provides otherwise, an organizational Customer grants Rapticore permission to identify it by its business name and logo in customer lists on Rapticore's website and sales materials, and in confidential financing and diligence materials. Use must follow reasonable trademark guidelines supplied by Customer and must not imply an endorsement, certification, or security outcome. Customer may withdraw public-use permission on written notice; Rapticore will stop new public uses and remove the name and logo from materials under its control within 30 days. Materials already distributed need not be recalled. Necessary confidential business and transaction records may be retained subject to confidentiality and applicable law. This permission does not authorize publication of an individual's identity or image, confidential contract terms, or identifiable security findings. Press releases, testimonials, case studies, and reference participation require separate written permission.
20.5 Force majeure. A party is excused from delay or failure to perform to the extent caused by events beyond its reasonable control, including natural disasters, war, civil unrest, labor disruption, governmental action, telecommunications or utility failure, independent third-party infrastructure outages, and denial-of-service or other cyberattacks. The affected party must use reasonable mitigation efforts, give notice as practicable, and resume performance when reasonably possible. An event is not excused to the extent caused by that party's failure to maintain the safeguards or continuity measures it expressly agreed to provide. This Section does not excuse accrued payment obligations or nonwaivable legal duties, and confidentiality and data-protection obligations continue to the extent performance remains reasonably possible. If a material interruption continues for more than 60 days, either party may terminate the affected Services on notice, and Rapticore will refund prepaid fees for the unused period after termination.
20.6 Export and sanctions. Each party will comply with export-control, sanctions, and trade laws applicable to its activities. Customer must not use or provide the Services in a prohibited jurisdiction, for a prohibited end use, or for a prohibited person. Neither an Order nor these Terms grants a governmental export authorization.
20.7 Entire agreement and interpretation. The Agreement is the complete agreement concerning its subject matter and supersedes prior agreements only for the Services and period it validly governs, subject to Section 1.4 and existing signed agreements. Failure to enforce a term is not a waiver. If a provision is unenforceable, it is limited or severed only as permitted by law, and the rest remains effective, subject to Section 19. The parties are independent contractors. There are no third-party beneficiaries except persons expressly protected by an applicable indemnity. Electronic signatures and counterparts are effective where permitted by law.