Legal

Master Service Agreement

This Master Service Agreement ("Agreement" or "MSA") is entered into between Darkdome Corporation ("Darkdome," "we," "us"), and the entity identified as "Customer". This Agreement governs Customer's access to and use of the Darkdome platform for security alert ingestion, AI-assisted classification, threat intelligence enrichment, and incident response management (the "Services"). By executing an Order Form, or by accessing or using the Services, Customer agrees to be bound by this Agreement.

1. Definitions

AI Features
the artificial intelligence and machine learning functionality embedded in the Services, including alert classification, severity/malicious scoring, remediation suggestions, and auto-template generation, as further described in the Darkdome AI Terms.
Customer
the legal entity that accepts the terms and accesses or uses the Services, and on whose behalf Users are authorized to access the Services. Where an Order Form is executed by an affiliate or business unit of a larger corporate group, "Customer" refers solely to the executing entity unless otherwise expressly stated in the Order Form.
Customer Data
any data, alerts, logs, incident records, comments, tags, evidence, or other information that Customer or its Users submit to, or that is ingested by, the Services, including data received via email, webhook, or any other supported vendor integrations.
Documentation
Darkdome's then-current user guides, integration guides, and API reference materials made available to Customer.
Order Form
an ordering document executed by the parties that references this Agreement and specifies the subscription plan, alert volume tier, add-ons, fees, and term.
Subprocessor
any third party engaged by Darkdome to process Customer Data in connection with delivering the Services, including cloud infrastructure providers and threat intelligence data sources.
Threat Intelligence Sources
third-party or open-source threat intelligence feeds integrated into the Services (including, as of the Effective Date, VirusTotal, AlienVault OTX, AbuseIPDB, MISP, Shodan, URLScan.io, ThreatFox (abuse.ch), Hybrid Analysis, MalwareBazaar, among others), as may be updated from time to time.
User
an individual authorized by Customer to access the Services under Customer's account, such as a security analyst, administrator, or manager.

2. The Services

2.1 Description

The Services provide (a) ingestion of security alerts via email, webhook-based triggers and pre-built vendor API-based integrations; (b) normalization of alerts using standard or customer-defined templates; (c) AI- and threat-intelligence-assisted classification and triage recommendations; (d) case and incident management tooling, including tagging, evidence attachment, and analyst collaboration; (e) reporting dashboards; (f) knowledge base; (g) user-defined and personalized workflows; (h) messaging integration with third party tools; (i) SLA & metrics module; (j) granular role based access control; (k) pre-defined dashboards; and (l) organization/features personalization. Specific features available to Customer are set out in the applicable Order Form and Documentation.

2.2 Human-in-the-Loop Design

The Services are designed to assist, and not replace, the judgment of Customer's trained security personnel. All AI-generated classifications, severity scores, and remediation suggestions are advisory. Customer is solely responsible for reviewing, validating, and acting upon (or declining to act upon) any such output before it is treated as final, consistent with Section 7 (AI Features) and the Darkdome AI Terms.

2.3 Changes to the Services

Darkdome may modify, update, or discontinue features of the Services from time to time, provided that Darkdome will not materially reduce the core functionality of the Services during a paid subscription term without providing reasonable advance notice.

2.4 Beta and Preview Features

Darkdome may make beta, pilot, or preview features available on an "as-is" basis. Such features are excluded from the Service Level commitments and may be modified or discontinued at any time in Darkdome's discretion.

3. Access and Use Rights

3.1 Subscription License

Subject to this Agreement and the applicable Order Form, Darkdome grants Customer a non-exclusive, non-transferable, non-sublicensable right to access and use the Services and Documentation during the subscription term, solely for Customer's internal security operations and incident response purposes.

3.2 Accounts and Role-Based Access

Customer is responsible for configuring role-based access control (RBAC) in accordance with the principle of least privilege, for promptly deactivating Users who no longer require access, and for maintaining the confidentiality of authentication credentials. Darkdome recommends multi-factor authentication (MFA) for all accounts, consistent with CIS Critical Security Control 6 (Access Control Management) and NIST SP 800-63B.

3.3 Restrictions

Customer will not, and will not permit any User or third party to: (a) reverse engineer, decompile, or attempt to derive the source code, models, or underlying algorithms of the Services; (b) use the Services to build a competing product; (c) resell, sublicense, or provide the Services to any third party outside of Customer's organization without Darkdome's prior written consent; (d) circumvent usage limits or authentication controls; or (e) use the Services in violation of the Darkdome Acceptable Use Policy, which is incorporated by reference into this Agreement.

4. Customer Data

4.1 Ownership

As between the parties, Customer owns all right, title, and interest in and to Customer Data. Darkdome obtains no ownership rights in Customer Data.

4.2 License to Darkdome

Customer grants Darkdome a limited, non-exclusive license to access, host, process, transmit, and display Customer Data solely to: (a) provide, maintain, and support the Services; (b) generate alert classifications, threat intelligence enrichment, and incident management functionality; (c) monitor performance and security of the Services; and (d) subject to Section 7 and the AI Terms, improve and train the Services' AI Features.

4.3 Data Protection Addendum

To the extent Customer Data includes personal data subject to the Lei Geral de Proteção de Dados (LGPD), the General Data Protection Regulation (GDPR), or other applicable data protection laws, the parties will execute Darkdome's Data Processing Addendum ("DPA"), which is incorporated herein by reference and controls with respect to the processing of personal data.

4.4 Data Return and Deletion

Upon termination or expiration of the applicable Order Form, and upon Customer's written request made within thirty (30) days thereafter, Darkdome will make available an export of Customer Data in a structured, commonly used format, and will thereafter delete Customer Data from production systems in accordance with Darkdome's data retention schedule and the DPA, except as required to be retained by applicable law.

5. Security Program

5.1 Security Measures

Darkdome maintains an information security program aligned with recognized industry frameworks, including the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover functions) and the CIS Critical Security Controls. Measures include, without limitation, encryption of Customer Data at rest and in transit, role-based access controls, audit logging, web application firewall (WAF) and anti-DDoS protections, secure software development lifecycle practices, and periodic third-party penetration testing.

5.2 Certifications Roadmap

As of the Effective Date, Darkdome has not obtained SOC 2, ISO/IEC 27001, or PCI-DSS certification. Darkdome will disclose its current certification status and roadmap to Customer upon request and will notify Customer of material changes to its security posture.

5.3 Security Incident Notification

Darkdome will notify Customer without undue delay, and in any event within the timeframe required by applicable law, upon becoming aware of a confirmed security incident resulting in unauthorized access to, or disclosure of, Customer Data hosted on the Services, and will provide reasonably requested information to assist Customer in meeting its own regulatory notification obligations.

5.4 Customer Security Responsibilities

Customer is responsible for the security of its own environment, including credentials, endpoints, email systems, and any Logic App, webhook, or integration configuration used to transmit alerts to the Services, and for promptly reporting suspected compromise of its Darkdome account.

6. Confidentiality

6.1 Definition

"Confidential Information" means non-public information disclosed by either party that is designated as confidential or that a reasonable person would understand to be confidential given the nature of the information and circumstances of disclosure, including Customer Data, security findings, pricing, and non-public product roadmaps.

6.2 Obligations

Each party will use the other party's Confidential Information solely to perform its obligations or exercise its rights under this Agreement, and will protect it using at least the same degree of care it uses for its own confidential information of similar nature, and no less than a reasonable degree of care.

6.3 Exceptions

Confidentiality obligations do not apply to information that is or becomes publicly available without breach of this Agreement, was rightfully known prior to disclosure, is independently developed without use of the disclosing party's Confidential Information, or is required to be disclosed by law, provided reasonable notice is given where legally permitted.

7. AI Features

7.1 Incorporation of AI Terms

Customer's use of AI Features is additionally governed by the Darkdome AI Terms, incorporated herein by reference. In the event of a conflict between this Agreement and the AI Terms with respect to AI Features specifically, the AI Terms control.

7.2 No Guarantee of Outcome

Darkdome does not guarantee that AI Features will detect, correctly classify, or prevent any particular security event, and Customer acknowledges that false positives and false negatives are an inherent characteristic of automated security classification systems.

8. Fees and Payment

8.1 Fees

Customer will pay the fees set out in the applicable Order Form, based on the selected subscription plan and alert-volume tier, plus any applicable overage fees for alert volume exceeding the contracted tier, calculated and invoiced in accordance with the Order Form.

8.2 Payment Terms

Fees are payable via credit card or invoice/boleto as specified in the Order Form, in advance of each billing period unless otherwise agreed, and are due within the period stated on the invoice. Late payments may accrue interest at the maximum rate permitted by applicable law and may result in suspension of the Services following notice.

8.3 Taxes

Fees are exclusive of applicable taxes, which Customer is responsible for, other than taxes on Darkdome's net income.

9. Term, Renewal, and Termination

9.1 Term

This Agreement commences on the Effective Date and continues until all Order Forms have expired or been terminated. Each Order Form has an initial term of one (1) or three (3) years, as specified therein, and will automatically renew for successive periods of equal length unless either party provides written notice of non-renewal at least thirty (30) days before the end of the then-current term.

9.2 Termination for Cause

Either party may terminate this Agreement or an Order Form if the other party materially breaches this Agreement and fails to cure such breach within thirty (30) days after written notice.

9.3 Effect of Termination

Upon termination, Customer's access to the Services will cease, and each party will return or destroy the other party's Confidential Information, subject to Section 4.4 (Data Return and Deletion) and any surviving obligations.

10. Warranties and Disclaimers

10.1 Mutual Warranties

Each party represents that it has the legal power to enter into this Agreement and will comply with applicable laws in its performance hereunder.

10.2 Disclaimer

EXCEPT AS EXPRESSLY STATED IN THIS AGREEMENT, THE SERVICES AND AI FEATURES ARE PROVIDED "AS IS," AND DARKDOME DISCLAIMS ALL OTHER WARRANTIES, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. DARKDOME DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, OR THAT ALL SECURITY THREATS WILL BE DETECTED OR CORRECTLY CLASSIFIED.

11. Limitation of Liability

11.1 Exclusion of Damages

TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR LOSS OF PROFITS, REVENUE, DATA, OR GOODWILL, ARISING OUT OF OR RELATED TO THIS AGREEMENT, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

11.2 Liability Cap

EXCEPT FOR EXCLUDED CLAIMS DEFINED BELOW, EACH PARTY'S TOTAL LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER TO DARKDOME UNDER THE APPLICABLE ORDER FORM IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO LIABILITY.

11.3 Excluded Claims

The limitations in this Section 11 do not apply to: (a) a party's indemnification obligations under Section 12; (b) breach of confidentiality obligations; (c) a party's gross negligence or willful misconduct; or (d) Customer's payment obligations.

12. Indemnification

12.1 By Darkdome

Darkdome will defend Customer against third-party claims alleging that the Services, as provided by Darkdome and used in accordance with this Agreement, infringe such third party's intellectual property rights, and will indemnify Customer for damages finally awarded, subject to Customer promptly notifying Darkdome and cooperating in the defense.

12.2 By Customer

Customer will defend and indemnify Darkdome against third-party claims arising from Customer Data, Customer's breach of this Agreement, or Customer's violation of the Acceptable Use Policy.

13. Intellectual Property

13.1 Darkdome IP

Darkdome retains all right, title, and interest in and to the Services, Documentation, underlying software, AI models, and all improvements, including any feedback or suggestions provided by Customer, which Darkdome may use without restriction or compensation.

13.2 Aggregated and De-Identified Data

Darkdome may generate and use aggregated or de-identified data derived from Customer Data (which does not identify Customer or any individual) to improve the Services, develop threat intelligence insights, and for benchmarking, as further described in the AI Terms.

14. Subprocessors and Third-Party Sources

14.1 Subprocessor List

Darkdome uses Subprocessors to provide the Services, including cloud infrastructure providers and the Threat Intelligence Sources identified in Section 1. Darkdome will maintain an up-to-date list of Subprocessors and will provide notice of new Subprocessors as required under the DPA.

14.2 Third-Party Integrations

The Services support ingestion integrations with third-party security products (including, among others, Trend Micro, CrowdStrike, Palo Alto Networks, Elastic, Splunk, Microsoft Entra ID, Check Point, Duo Security, Microsoft Azure, Microsoft 365, and Microsoft Active Directory) and collaboration platforms (including Microsoft Teams, Slack, and Google Workspace). Customer's use of such third-party products remains subject to Customer's agreements with those providers, and Darkdome is not responsible for their availability or performance.

15. Service Level and Support

15.1 SLA

Darkdome's then-current Service Level Agreement ("SLA"), specifying uptime commitments, support response times, and service credits, is incorporated herein by reference and made available at [SLA URL].

15.2 Support

Darkdome will provide support in accordance with the support tier purchased under the applicable Order Form.

16. Export Control and Sanctions

16.1 Compliance

Given the cybersecurity nature of the Services and Darkdome's planned expansion into the United States, Customer represents that it is not located in, and will not access or use the Services from, any country or on behalf of any person subject to comprehensive trade sanctions administered by the United Nations, the United States (OFAC), the European Union, or Brazil, and will comply with all applicable export control and anti-boycott laws, including, where applicable, the U.S. Export Administration Regulations (EAR).

17. Governing Law and Dispute Resolution

17.1 Governing Law

This Agreement is governed by the laws of [Brazil / State of Delaware, USA — to be finalized per Customer's contracting entity], without regard to conflict-of-laws principles.

17.2 Venue

The parties submit to the exclusive jurisdiction of the courts of [comarca / venue TBD] to resolve any dispute not otherwise resolved through good-faith negotiation, except that either party may seek injunctive relief in any court of competent jurisdiction to protect its intellectual property or Confidential Information.

18. General Provisions

18.1 Force Majeure

Neither party is liable for delay or failure to perform resulting from causes beyond its reasonable control, including natural disasters, war, labor disputes, internet or utility failures, or governmental action.

18.2 Assignment

Neither party may assign this Agreement without the other party's prior written consent, except in connection with a merger, acquisition, or sale of substantially all assets, provided that Darkdome may assign this Agreement in connection with a change of control affecting its corporate structure (including the contemplated addition of new equity holders).

18.3 Notices

Notices must be in writing and sent to the addresses specified in the applicable Order Form or to the legal notice email address published on Darkdome's website.

18.4 Entire Agreement

This Agreement, together with all Order Forms, the DPA, the AI Terms, the Acceptable Use Policy, and the SLA, constitutes the entire agreement between the parties regarding its subject matter and supersedes all prior agreements on that subject.

18.5 Severability; Waiver

If any provision of this Agreement is held unenforceable, the remaining provisions will remain in full force and effect. No waiver of any provision will be effective unless in writing.

18.6 Survival

Sections regarding fees owed, confidentiality, data return, warranties/disclaimers, limitation of liability, indemnification, intellectual property, and general provisions survive termination or expiration of this Agreement.