FutureSafe — home Talk to a Security Expert

Legal Terms & Conditions

Terms & Conditions

Last updated May 3, 2026 7,710 words

Last Modified: May 3, 2026

Scope

a) Services. This Agreement governs the business relationship between FutureSafe and you, including all services that we perform for you, as well as any services, licenses, software, subscriptions, advisory offerings, assessments, deliverables, or products that we sell or re-sell to you (collectively, the "Services").

b) Sales Order. The Services will be described in one or more orders, proposals, or statements of work that we provide to you (each, a "SO"). Once you agree to a Sales Order (either by signing it or by electronic acceptance), the Sales Order will be governed by this Agreement.

c) Conflict. If there is a conflict between the language in a SO and this Agreement, then the language of this Agreement will control. The Parties may specify in the applicable SO that a particular provision of the SO is to supersede a provision of this Agreement, in which case the superseding SO provisions shall be applicable only to such SO and shall be effective for such SO only if such provision expressly references the applicable Section of this Agreement that is to be modified and clearly states that such provision supersedes the conflicting or inconsistent provision in this Agreement.

General

a) Assessments. Security or vulnerability assessments undertaken by FutureSafe or its designated third-party technicians ("Assessments") endeavor to identify, evaluate, and/or categorize actual or potential vulnerabilities, hazards, or deficiencies in an information technology environment ("Environment") using structured, systematic procedures and proprietary methodologies. Assessments will be handled in the manner and priority as determined by us or our designated third-party technician(s) (collectively, "Technicians").

b) Advisory Services. Certain Services may be consultative, strategic, governance-related, or recommendations-based in nature, including without limitation virtual chief information security officer services, security leadership support, policy drafting, board reporting support, regulatory-readiness support, AI governance, AI compliance advisory, model risk advisory, privacy advisory, control framework mapping, risk assessments, tabletop facilitation, remediation planning, and audit or examination support (collectively, "Advisory Services"). Advisory Services are professional advisory services only and do not transfer to FutureSafe responsibility for Client's management, operational, legal, compliance, privacy, disclosure, reporting, product, engineering, or governance decisions unless expressly stated otherwise in a SO.

c) Software Agents. The Services may require Technicians to install software code (often referred to as "Software Agents") into the Environment that could be used on a 24×7 basis to monitor, track, and record all activity occurring on the device(s) in which the code is installed. You hereby consent to such installation and use of Software Agents as we or any Technician deem reasonably necessary to provide the Services to you.

d) Access. Assessments and other Services may require Technicians to physically or virtually access the Environment at various times, scheduled and unscheduled. You hereby grant to us and any Technicians the right to monitor, diagnose, manipulate, communicate with, retrieve information from, and otherwise access the Environment on a 24×7 basis solely for the purpose of enabling us or our designated vendors, as applicable, to provide the Services. It is your responsibility to secure, at your own cost and prior to the commencement of any Services, any necessary rights of entry, licenses (including software licenses), permits, approvals, notices, or other permissions necessary for the Technicians to provide the Services both physically and virtually, as applicable. Proper and safe environmental conditions must be provided and assured by you at all times. Technicians will not be required to engage in any activity or provide any Services under conditions that pose or may pose a safety or health concern, or that would require extraordinary or non-industry-standard efforts to achieve.

e) Alarms; Security Systems. Client understands and agrees that security devices, alarms, automated controls, blocking actions, or other security measures, both physical and virtual, may be tripped or activated despite efforts to avoid such occurrences. Client shall be responsible for notifying any monitoring company and all law enforcement authorities of the potential for false alarms due to the provision of the Services and shall take all steps necessary to ensure that false alarms are not reported or treated as real alarms or credible threats against any person, place, or property. Some alarms and advanced security measures, when activated, may cause the partial or complete shutdown of the Environment, causing substantial downtime and/or delay to Client's business activities. We shall not be responsible for, and shall be held harmless and indemnified by Client against, any claims, costs, fees, or expenses incurred by Client that arise or result from (i) any response to the Services by any monitoring company or law enforcement authorities, or (ii) the partial or complete shutdown of the Environment by any alarm, automated response, or security monitoring device.

f) Advice; Instructions. From time to time, we may provide you with specific advice and directions related to the Services ("Advice"). For example, Advice may include replacing obsolete equipment, implementing specific controls, adopting governance measures, limiting or suspending use of certain AI features or use cases, notifying users, increasing human review, retraining staff, or refraining from engaging in acts that disrupt the Environment or make the Environment less secure or less compliant. You are strongly advised to promptly follow our Advice which, depending on the situation, may require you to make additional purchases or investments in the Environment at your sole cost. We are not responsible for any problems or issues, including downtime, security-related issues, privacy-related issues, compliance-related issues, or AI-related issues, caused by your failure to promptly follow our Advice. If, in our discretion, your failure to follow our Advice renders part or all of the Services economically or technically unreasonable to provide, then we may terminate the applicable SO for cause by providing notice of termination to you. Unless specifically and expressly stated in a SO, any services required to remediate issues caused by your failure to follow our Advice are out-of-scope and not covered under any SO.

g) EULAs. Portions of the Services may require the acceptance of the terms of one or more third-party end user license agreements, terms of service, terms of use, acceptable use policies, AI provider terms, or similar terms (together, "EULAs"). If acceptance of a EULA is required in order to provide the Services to you, then you hereby grant us permission to accept the EULA on your behalf. EULAs may contain service levels, warranties, restrictions, usage limitations, retention terms, AI training or processing terms, and/or liability limitations that are different than those contained in this Agreement. You agree to adhere to and be bound by the terms of such EULAs. If you are required to enforce the provisions of a EULA, you will look only to the applicable third-party provider for such enforcement. If, while providing the Services, we are required to comply with a third-party EULA and the third-party EULA is modified or amended, we reserve the right to modify or amend any applicable SO with you to ensure our continued compliance with the terms of the third-party EULA.

h) Third Party Services. Portions of the Services may be acquired from, or rely upon the services of, third-party manufacturers or providers ("Third Party Services"). Not all Third Party Services may be expressly identified as such in a SO, and at all times we reserve the right to utilize the services of any third-party provider or to change third-party providers in our sole discretion as long as the change does not materially diminish the Services provided to you under a SO. We will not be responsible, and will be held harmless by you, for the failure of any third-party provider or manufacturer to provide Third Party Services to us or to you, including failures relating to model performance, service availability, retention, interoperability, data handling, security, or changes in product functionality.

i) Authorized Contact(s). We will be entitled to rely on any directions or consent provided by your personnel or representatives who are authorized in a SO to provide such directions or consent ("Authorized Contacts"). If no Authorized Contact is identified in an applicable SO or if a previously identified Authorized Contact is no longer available to us, then your Authorized Contact will be the person (i) who signed this Agreement, (ii) who signed the applicable SO, and/or (iii) who is generally designated by you during the course of our relationship to provide us with direction or guidance. We will rely upon directions and guidance from your Authorized Contact until we are affirmatively made aware of a change of status of the Authorized Contact. We reserve the right to delay the Services until we can confirm the Authorized Contact's authority within your organization.

j) Executive Owner; Risk Acceptance. For any Advisory Services, Client shall designate an executive owner or equivalent authorized decision-maker with authority to review and approve recommendations, remediation priorities, risk acceptance decisions, policy positions, control exceptions, AI use cases, and any production deployment decisions. FutureSafe may rely conclusively on such person's approvals, instructions, and decisions, and Client retains sole responsibility for all decisions to accept, reject, defer, or modify any recommendation or risk treatment option.

Fees; Payment

a) Fees. You agree to pay the fees, costs, and expenses described in each SO. All payments due will be automatically drafted via ACH or a credit card within five (5) days of the invoice due date. If drafted via a credit card, a 3.5% administrative fee may apply. In the event of insufficient funds, or a declination of the credit card after three (3) attempts, your account may be suspended pursuant to this Agreement. In order to lift the suspension, a reconnect fee equal to the then-current monthly payment may be required. Pre-payment options may be available. You are responsible for sales tax and any other taxes or governmental fees associated with the Services. If you qualify for a tax exemption, you must provide us with a valid certificate of exemption or other appropriate proof of exemption. You are also responsible for all freight, insurance, and taxes, including import or export duties, sales, use, value add, and excise taxes.

b) Schedule. Unless otherwise stated in a SO, invoices for monthly recurring payments will be sent on or about the day after the SO was digitally signed by you.

c) Nonpayment. Fees that remain unpaid after the date on the invoice will be subject to interest on the unpaid amount(s) until and including the date payment is received, at the lower of either 1.5% per month or the maximum allowable rate of interest permitted by applicable law. We reserve the right, but not the obligation, to suspend part or all of the Services without prior notice to you in the event that any portion of undisputed fees are not timely received by us, and monthly or recurring charges shall continue to accrue during any period of suspension. Notice of disputes related to fees must be received by us within sixty (60) days after the applicable Service is rendered or the date on which you pay an invoice, whichever is later; otherwise, you waive your right to dispute the fee thereafter. A reconnect fee of up to five percent (5%) may be charged to you if we suspend the Services due to your nonpayment. Time is of the essence in the performance of all payment obligations by you. Should collection action become necessary, you agree to pay for all of our costs of collection, including reasonable attorneys' fees and costs.

d) ACH. Generally, all prices quoted in a SO anticipate automatic monthly recurring payment by you. Payments by any other methods may result in increased fees or costs.

e) Reimbursable Expenses. Except as may otherwise be stated in the applicable SO, you agree to reimburse us for all reasonable and customary out-of-pocket expenses, including, but not limited to, airfare, rental car, mileage, tolls, and lodging expenses, incurred by us in connection with the performance of Services. Meal expenses shall be billed at our then-current per-diem amount. Travel time will be billed at one-half the on-site billable rate each way. Reimbursable expenses shall be invoiced monthly.

Warranties; Limitation of Liability

a) Provision of Services. Client understands and agrees that the security-related information technology service industry is constantly evolving, and that one or more of the procedures implemented by Technicians may be novel, proprietary, and/or custom-tailored to meet the specific needs of a specific Environment. We warrant that any Services that we deliver will be provided in a manner generally consistent with the practices of the industry; however, to the extent that novel or custom-tailored procedures are implemented in our discretion, it is agreed that such procedures may fall outside of recognized or traditional practices and shall not be a basis for any claim that FutureSafe or any of the Technicians breached any standard of care to Client. For Services containing a deliverable, such Services will be deemed accepted by you if not rejected in a reasonably detailed writing within five (5) days of submission to you. In the event the Services provided by us are not in conformance with this warranty, you must provide written notice to us within five (5) days after the performance of the Services and such notice will specify in reasonable detail the nature of the breach. Upon confirmation of the breach, we will use commercially reasonable efforts to take the steps necessary to correct the deficiency at no charge to you. This is your sole and exclusive remedy for breach of this warranty.

b) Results. We do not warrant or represent that the Services will produce any particular result or outcome, that every potential hazard, vulnerability, deficiency, compliance gap, or governance issue in the Environment will be detected, or that any recommendation will be accepted, adopted, or implemented by Client or any third party. Further, we do not warrant or represent that the Services or the results of the Services will meet any particular Client requirement unless such requirement is expressly and specifically stated in a SO.

c) Best-Efforts Advisory Services; vCISO and AI Compliance Advisory. To the extent the Services include Advisory Services, Client understands and agrees that such Advisory Services are provided on a best-efforts, commercially reasonable, advisory-only basis and are dependent upon the accuracy, completeness, timeliness, and continued availability of information, systems, personnel, vendors, records, and decisions provided by Client and third parties. FutureSafe does not warrant or represent that any Advisory Services will cause Client to satisfy, achieve, maintain, or demonstrate compliance with any law, regulation, framework, standard, certification requirement, examination expectation, enforcement position, consent order, contractual obligation, insurer requirement, or industry guidance, including those applicable to regulated industries. Unless expressly stated in an applicable SO, FutureSafe does not provide legal advice, accounting advice, audit opinions, attest services, certification services, or regulatory filing services, and does not guarantee that Client will pass any audit, examination, assessment, certification, underwriting review, or regulatory inquiry.

d) Client Decision-Making. Client acknowledges that Advisory Services are recommendations only and that all decisions regarding governance, risk acceptance, control implementation, remediation, disclosures, notifications, system configurations, model selection, model deployment, use restrictions, human review, incident response, regulatory interpretations, compliance strategy, and operational execution remain solely with Client. Client further acknowledges that regulated-industry obligations may require licensed counsel, specialized compliance professionals, independent assessors, auditors, or other third parties, and Client is solely responsible for engaging such parties where required.

e) AI-Specific Disclaimer. With respect to AI-related Services, FutureSafe does not warrant or represent that any artificial intelligence, machine learning, large language model, automated decision system, third-party model, dataset, output, recommendation, or related tool is lawful, accurate, complete, unbiased, non-infringing, explainable, secure, fit for any particular purpose, or compliant with any present or future legal or regulatory requirement. AI-related laws, regulations, agency guidance, and industry standards are evolving rapidly, and any advice, deliverable, or recommendation regarding AI governance or compliance reflects conditions and interpretations reasonably available at the time the Services are performed and may become incomplete, outdated, or inapplicable due to subsequent legal, technical, operational, or regulatory developments.

f) Service Levels. The Services will meet the technical standards of performance or service levels, if any, set forth in the applicable SO. Client's sole and exclusive remedy for any failure to meet the applicable technical standards of performance or service levels shall be as specified in the applicable SO.

g) Third Parties. You shall not make any representations or warranties on behalf of us to any third party. You shall be solely responsible and liable for any representations or warranties that you make to any third party regarding us, the Services, or any other aspect of this Agreement. We make no representations or warranties with regard to any third-party services and pass through to you the terms and conditions for the services delivered by a third party.

h) Disclaimer of Warranty. EXCEPT AS EXPRESSLY PROVIDED IN THIS SECTION, NEITHER PARTY MAKES ANY OTHER REPRESENTATION OR WARRANTY OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, AND ANY WARRANTIES ARISING FROM USAGE OF TRADE OR COURSE OF PERFORMANCE. NO EMPLOYEE, AGENT, OR REPRESENTATIVE OF OURS IS AUTHORIZED TO MAKE ANY ADDITIONAL OR OTHER REPRESENTATIONS OR WARRANTIES ON OUR BEHALF. YOU ARE NOT RELYING ON ANY OTHER REPRESENTATIONS OR WARRANTIES. IN ADDITION, YOU UNDERSTAND AND ACKNOWLEDGE THAT THE INTERNET AND MODERN COMPUTING ENVIRONMENTS ARE NOT SECURE MEDIA, MAY BE INHERENTLY UNRELIABLE, MAY BE SUBJECT TO INTERRUPTION OR DISRUPTION, AND MAY BE SUBJECT TO INADVERTENT OR DELIBERATE BREACHES OF SECURITY, PRIVACY FAILURES, MODEL FAILURES, OR DATA PROCESSING ERRORS, FOR WHICH WE CANNOT BE HELD LIABLE EXCEPT AS EXPRESSLY PROVIDED HEREIN.

i) Limit on Types of Damages Recoverable. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, NEITHER PARTY WILL, AND OUR SUPPLIERS AND LICENSORS WILL NOT, BE LIABLE TO THE OTHER PARTY OR ANY OTHER THIRD PARTY CLAIMING THROUGH A PARTY FOR ANY INCIDENTAL, CONSEQUENTIAL, SPECIAL, INDIRECT, EXEMPLARY, OR PUNITIVE DAMAGES, INCLUDING WITHOUT LIMITATION LOST PROFITS, LOST REVENUES, LOSS OF GOODWILL, LOST OR DAMAGED DATA, INVESTMENTS MADE, LOSS OF BUSINESS OPPORTUNITY, BUSINESS INTERRUPTION, REGULATORY FINES, REGULATORY PENALTIES, RESTITUTION, DISGORGEMENT, CUSTOMER REDRESS, RECALL COSTS, NOTICE COSTS, CREDIT MONITORING COSTS, INCREASED INSURANCE PREMIUMS, DENIAL OF INSURANCE COVERAGE, OR COSTS OF RESPONDING TO GOVERNMENTAL, ACCREDITING, OR SUPERVISORY INQUIRIES, ARISING IN CONNECTION WITH THIS AGREEMENT, ANY SO, OR THE SERVICES, HOWEVER CAUSED AND UNDER WHATEVER THEORY OF LIABILITY, INCLUDING BREACH OF CONTRACT, TORT, STRICT LIABILITY, AND NEGLIGENCE, EVEN IF SUCH PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES, DIRECT DAMAGES DO NOT SATISFY A REMEDY, OR A LIMITED REMEDY FAILS OF ITS ESSENTIAL PURPOSE.

j) Limit on the Amount of Damages Recoverable. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, OUR TOTAL CUMULATIVE LIABILITY UNDER OR RELATING TO THIS AGREEMENT AND THE SERVICES, REGARDLESS OF THE NATURE OF THE OBLIGATION, FORM OF ACTION, OR THEORY OF LIABILITY, INCLUDING CONTRACT, TORT, STRICT LIABILITY, AND NEGLIGENCE, SHALL BE LIMITED IN ALL CASES TO AN AMOUNT THAT SHALL NOT EXCEED, IN THE AGGREGATE, FEES PAID BY YOU TO US DURING THE SIX (6) MONTH PERIOD IMMEDIATELY PRECEDING THE FIRST EVENT GIVING RISE TO LIABILITY FOR THE SERVICES THAT ARE THE BASIS OF THE PARTICULAR CLAIM AND UNDER THE APPLICABLE SO. FOR THE AVOIDANCE OF DOUBT, THE LIMITATIONS OF LIABILITY AND EXCLUSIONS OF DAMAGES IN THIS AGREEMENT APPLY FULLY TO ALL ADVISORY SERVICES, INCLUDING VCISO, SECURITY GOVERNANCE, PRIVACY, REGULATORY COMPLIANCE, AI GOVERNANCE, AI COMPLIANCE, MODEL RISK, AND RELATED STRATEGIC OR CONSULTATIVE SERVICES, REGARDLESS OF WHETHER A CLAIM IS BASED ON ALLEGED RELIANCE ON RECOMMENDATIONS, ASSESSMENTS, REPORTS, ROADMAPS, POLICIES, OR OTHER DELIVERABLES.

k) No Responsibility for Client's Compliance Status or AI Outcomes. Without limiting any other limitation, exclusion, or disclaimer in this Agreement, FutureSafe shall not be liable for Client's failure to comply with applicable law, regulatory guidance, contractual obligations, or insurer requirements, or for fines, penalties, sanctions, assessments, chargebacks, remediation costs, notice costs, monitoring costs, customer redress, lost certification status, increased insurance premiums, denial of coverage, or costs of responding to any governmental, accrediting, or supervisory inquiry, except to the extent finally determined by a court of competent jurisdiction to have directly resulted from FutureSafe's gross negligence or willful misconduct. FutureSafe shall further not be liable for any claim arising from or relating to (i) Client's interpretation or implementation of advisory recommendations, (ii) Client's decision not to implement recommendations, (iii) inaccurate, incomplete, stale, or misleading information supplied by Client or third parties, (iv) changes in law, regulation, guidance, threat conditions, technology, vendors, or Client's environment after the Services are rendered, (v) any AI output, hallucination, bias, drift, toxicity, explainability failure, training data issue, infringement allegation, automated decision, or model performance issue, or (vi) actions or omissions of Client's counsel, auditors, assessors, regulators, cloud providers, software vendors, model providers, or other third parties.

l) Non-Managed Systems. We shall not be liable for any damages caused by services, systems, software, models, data sources, or other components that neither we nor our employees, agents, or subcontractors furnish or manage pursuant to this Agreement. We shall not be liable for the actions or inactions of your employees, agents, contractors, legal counsel, auditors, compliance personnel, model developers, or other third parties.

m) Applicability. The terms in this Section shall apply to the maximum extent permitted by applicable law. If applicable law precludes a party from excluding liability for certain types of damages for certain acts or omissions or capping its liability for certain acts or omissions, then the terms in this Section shall apply to not limit liability for such acts and omissions but will apply for all other acts and omissions.

n) Allocation of Risk. EACH PARTY ACKNOWLEDGES THAT THE FOREGOING DAMAGES EXCLUSIONS AND LIMITATIONS OF LIABILITY SET FORTH IN THIS SECTION REFLECT THE ALLOCATION OF RISK SET FORTH IN THIS AGREEMENT AND ACKNOWLEDGES THAT THE OTHER PARTY WOULD NOT HAVE ENTERED INTO THIS AGREEMENT ABSENT SUCH EXCLUSIONS AND LIMITATIONS OF LIABILITY OR THAT THE PRICES PAID BY YOU FOR THE SERVICES WOULD HAVE BEEN HIGHER.

Indemnification

Each party (an "Indemnifying Party") agrees to indemnify, defend and hold the other party (an "Indemnified Party") harmless from and against any and all third-party losses, damages, costs, expenses, or liabilities, including reasonable attorneys' fees and court costs (collectively, "Damages"), that arise from, or are related to, (a) real property damage or personal injury, including death, (b) any breach by a Party of its confidentiality obligations hereunder, and (c) a Party's gross negligence or willful misconduct. In addition, Client shall indemnify, defend, and hold harmless FutureSafe and its officers, directors, employees, agents, subcontractors, successors, and assigns from and against any third-party claim arising from or relating to Client's regulated operations, Client's compliance representations, Client's notices or disclosures, Client's AI or automated decision-making deployments, Client's use of any recommendation after receipt, Client's failure to obtain required consents, approvals, or legal review, or Client's violation of applicable law, except to the extent finally determined by a court of competent jurisdiction to have directly resulted from FutureSafe's gross negligence or willful misconduct.

The Indemnified Party will have the right, but not the obligation, to control the intake, defense, and disposition of any claim or cause of action for which indemnity may be sought under this section. The Indemnifying Party shall be permitted to have counsel of its choosing participate in the defense of the applicable claim(s); however, (i) such counsel shall be retained at the Indemnifying Party's sole cost, and (ii) the Indemnified Party's counsel shall be the ultimate determiner of the strategy and defense of the claim(s) for which indemnity is provided. No claim for which indemnity is sought by an Indemnified Party will be settled without the Indemnifying Party's prior written consent, which shall not be unreasonably delayed or withheld.

Term; Termination

a) Term. This Agreement begins on the earliest date on which you accept a SO and continues until terminated as described in this Agreement. Each SO will have its own term and will be terminated only as provided herein, unless otherwise expressly stated in the applicable SO. The termination of one SO shall not, by itself, cause the termination of or otherwise impact this Agreement or the status or progress of any other SO between the parties.

b) Termination Without Cause. Neither Party will terminate this Agreement without cause if, on the date of termination, a SO is in progress. In addition, neither Party will terminate a SO without cause prior to the SO's natural expiration date. If you terminate a SO without cause and without our consent, then you will be responsible for paying the termination fee described in the Termination For Cause section below. If no SO is in progress, then either Party may terminate this Agreement without cause by providing the other party with ninety (90) days prior written notice.

c) Termination For Cause. In the event that one Party commits a material breach under a SO or under this Agreement, the non-defaulting Party will have the right, but not the obligation, to terminate immediately this Agreement or the relevant SO, provided that (i) the non-defaulting Party has notified the defaulting Party of the specific details of the breach in writing, and (ii) the defaulting Party has not cured the default within thirty (30) days, or ten (10) days for non-payment by Client, following receipt of written notice of breach. If we terminate this Agreement or any SO for cause, or if you terminate any SO without cause prior to the SO's expiration date, then we will be entitled to receive, and you hereby agree to pay to us, all amounts that would have been paid to us had this Agreement or SO remained in effect, at the rates that were in effect at the time of termination. If you terminate this Agreement or a SO for cause, then you will be responsible for paying only for those Services that were delivered up to the effective date of termination.

d) Termination for Financial Insecurity. Either Party may terminate this Agreement and all Sales Orders upon written notice if the other Party ceases conducting business in the normal course, admits its insolvency, makes an assignment for the benefit of creditors, or becomes the subject of any judicial or administrative proceeding in bankruptcy, receivership, or reorganization. Termination shall be effective upon receipt of the written notice.

e) Client Activity As A Basis for Termination. In the event that you or any of your staff, personnel, contractors, or representatives engages in any unacceptable act or behavior that renders it impracticable, imprudent, or unreasonable to provide the Services to you, or if your refusal to implement minimum safeguards, governance controls, required notices, or legally required constraints materially increases risk to us or third parties, then in addition to our other rights under this Agreement, we will have the right upon providing you with ten (10) days prior written notice, to terminate this Agreement or the applicable SO for cause.

f) Transition; Deletion of Data. In the event that you request our assistance to transition away from the Services, we will provide such assistance if (i) all fees due and owing to us are paid to us in full prior to us providing our assistance to you, and (ii) you agree to pay our then-current hourly rate for such assistance, with up-front amounts to be paid to us as we may require. For the purposes of clarity, it is understood and agreed that the retrieval and provision of passwords, log files, data, administrative server information, reports, evidence files, model governance artifacts, and/or the conversion of data are transition services, each of which is subject to the preceding requirements. Unless otherwise expressly stated in a SO, we will have no obligation to store or maintain any Client data in our possession or control beyond fifteen (15) calendar days following the termination of this Agreement. We will be held harmless for, and indemnified by you against, any and all claims, costs, fees, or expenses incurred by either Party that arise from, or are related to, our deletion of your data beyond the time frames described in this section.

Confidentiality

a) Confidential Information. For the purposes of this Agreement, Confidential Information means any and all non-public information provided to one party ("Discloser") by the other party ("Recipient"), including but not limited to customer data, customer lists, internal documents, Environment configurations, the results of any Assessments, AI use case information, model evaluation results, data flow diagrams, governance records, and related information. Confidential Information also includes the precise products and specific solutions implemented into and/or comprising the Services, and the rates charged for such Services, all of which will not be shared or disclosed by you to any third party without our prior written consent. Confidential Information will not include information that (i) has become part of the public domain through no act or omission by the Recipient, (ii) was developed independently by the Recipient, or (iii) is or was lawfully and independently provided to the Recipient prior to disclosure by the Discloser, from a third party who is not and was not subject to an obligation of confidentiality or otherwise prohibited from transmitting such information.

b) Use and Disclosure. A Recipient will keep the Confidential Information it receives confidential and will not use or disclose such information to any third party for any purpose except as expressly authorized by the Discloser in writing or as needed to provide the Services or to fulfill its obligations under this Agreement. Notwithstanding the foregoing, a Recipient may collect, completely de-identify and anonymize, and use any information it obtains under this Agreement for educational or informational purposes, such as the creation of white papers, case studies, benchmark materials, or similar activities, or for its internal business purposes, such as improving its services or augmenting existing services, provided such use does not identify Client or disclose Client Confidential Information.

c) Due Care. A Recipient will exercise the same degree of care with respect to the Confidential Information it receives from a Discloser as it normally takes to safeguard and preserve its own confidential and proprietary information, which in all cases will be at least a commercially reasonable level of care. If the Parties enter into any other agreement related to Confidential Information, such as a business associate agreement, a data processing addendum, or a similar agreement, on or after the Effective Date, the contractual terms that require the higher levels of confidentiality will apply to each Party's use of Confidential Information to the extent applicable.

d) Compelled Disclosure. If a Recipient is legally compelled to disclose any of the Confidential Information, the Recipient will promptly notify the Discloser in writing of such requirement so that the Discloser may seek a protective order or other appropriate remedy and/or waive compliance with the provisions of this section. The Recipient will use commercially reasonable efforts, at the Discloser's expense, to obtain or assist the Discloser in obtaining any such protective order. Failing the entry of a protective order or the receipt of a waiver hereunder, the Recipient may disclose, without liability hereunder, that portion and only that portion of the Confidential Information that it has been advised by written opinion from its counsel that it is legally compelled to disclose.

e) Encryption. You shall encrypt at the application level all Confidential Information and all data that is considered sensitive data or that must be treated as confidential under state or federal law or under your contractual obligations to others. This includes, but is not limited to, Social Security Numbers, financial account numbers, driver's license numbers, state identification numbers, protected health information, nonpublic personal information, biometric data, and any other regulated personal information or sensitive business information made available to us in connection with the Services.

Additional Terms

a) Legal Compliance. Both Parties will comply with all laws, rules, and regulations applicable to them. Notwithstanding any provision to the contrary, we will be permitted to modify the Services in any SO as reasonably necessary to ensure that we remain in legal compliance with any applicable federal, state, or local rule, law, regulation, court order, regulatory guidance, or third-party provider requirement. Modifications made to the scope of Services pursuant to this paragraph will not require your consent unless (i) the modification will increase the cost of the applicable Service by more than five percent (5%) of the fee quoted to you, or (ii) the modification will substantially undermine the intent, purpose, or goals of the Service, in which case your consent will be obtained before such modifications are implemented.

b) Regulatory Compliance. Unless otherwise expressly stated in a SO, the Services are not intended, and will not be used, to bring Client into full regulatory compliance with any rule, regulation, or requirement that may be applicable to Client's business or operations. Depending on the Services provided, the Services may aid Client's efforts to fulfill regulatory compliance; however, the Services are not, and should not be used as, a compliance solution or legal determination.

c) Regulated Industry Services. If Client operates in a regulated industry, Client shall remain solely responsible for identifying all laws, regulations, agency guidance, supervisory expectations, contractual obligations, reporting obligations, retention obligations, and industry standards applicable to Client's business, systems, data, and use cases, including obligations applicable to artificial intelligence, automated decision-making, cybersecurity, privacy, consumer protection, discrimination, safety, recordkeeping, and vendor oversight. FutureSafe's Services may support Client's compliance efforts, but do not replace Client's internal compliance function, legal function, privacy function, model risk management function, information security function, or governing body oversight.

d) Client Responsibilities in Regulated and AI Contexts. Client is solely responsible for (i) adopting and approving policies and procedures, (ii) implementing and maintaining administrative, technical, and physical safeguards, (iii) making required filings, notices, disclosures, submissions, and certifications, (iv) validating that controls operate effectively in Client's actual environment, (v) reviewing and approving any AI use case before production use, (vi) providing meaningful human oversight where required or prudent, (vii) conducting legal, compliance, and business review of AI and automated decision-making use cases, (viii) ensuring rights to use data, prompts, inputs, outputs, and training materials, and (ix) determining whether any recommendation, model, workflow, or control is appropriate for Client's regulated activities.

e) Counsel; Audit; Certification Disclaimer. Unless otherwise expressly stated in a SO, the Services do not constitute legal advice, do not create an attorney-client relationship, do not constitute an external audit, do not provide an attestation, and do not certify compliance with any law, regulation, framework, or standard. Client is solely responsible for obtaining legal advice and any required independent audit, attestation, certification, or assessment from qualified providers.

f) Breach/Cyber Security Incident Recovery. Unless otherwise expressly stated in a SO, we will not be responsible for providing the remediation of any hazards, vulnerabilities, deficiencies, compliance failures, or AI-related issues that we discover in the Environment. Such services, if requested by you, may be provided under a separate SO to which you and we must both agree.

g) Environment Modifications. Any changes to the Environment, data sources, models, workflows, vendors, or governance processes that occur after the provision of the Services may create exploits, vulnerabilities, control failures, or compliance gaps that could render the results or conclusions of the Services obsolete or invalid. We do not warrant or guarantee the Results if the Environment is modified in any manner, and you are strongly encouraged to re-engage with us if, after the Services are rendered, you make any such modifications.

h) Cooperation. You understand and agree that the timing and efficacy of the Services may depend upon numerous factors, including but not limited to your timely provision of accurate information to us and your ongoing cooperation and participation in the consulting process. You agree to cooperate timely and reasonably with any Service-related requests we may make, such as requests for additional information about the Environment or requests to make your designated security, privacy, legal, compliance, or AI governance personnel available to us.

i) Required Consents. You shall obtain and keep in effect all consents, licenses, approvals, notices, permissions, and authorizations required to give us, or any person or entity acting for us under this Agreement, the right or license to access, use, modify, review, test, store, process, or analyze in electronic form and other forms any systems, data, models, outputs, or derivative works necessary for us to perform our obligations under this Agreement without infringing privacy rights, contract rights, or intellectual property rights of others. Upon request, you will provide us evidence of any such Required Consents. We will be relieved of our obligations to the extent affected by Client's failure to promptly obtain and provide any Required Consents.

j) Evidence Retention and Deliverables. Unless expressly stated in a SO, FutureSafe is not responsible for long-term evidence preservation, litigation hold support, regulatory submission management, formal record retention schedules, legal hold implementation, or maintenance of audit-ready documentary packages beyond the delivery period stated in the SO or, if no period is stated, fifteen (15) calendar days following delivery or termination, whichever first occurs.

k) Regulatory Change; Scope Changes. Because cybersecurity, privacy, and AI-related legal and regulatory requirements may change rapidly, FutureSafe may recommend changes to scope, controls, documentation, reporting, or Service assumptions in response to changes in law, regulator guidance, supervisory expectations, threat conditions, or third-party provider requirements. Material additional work required as a result of such changes shall be out of scope unless otherwise expressly included in the applicable SO and may require a change order or new SO.

Ownership

Each Party is, and will remain, the owner and/or licensor of all works of authorship, patents, trademarks, copyrights, trade secrets, and other intellectual property owned by such Party. Nothing in this Agreement or any SO shall be deemed to convey or grant any ownership rights or goodwill in one Party's intellectual property to the other Party. For the purposes of clarity, you understand and agree that we own any software, code, templates, methodologies, frameworks, scoring models, algorithms, prompts, processes, reports, and other works of authorship that we use or create while providing the Services to you, excluding Client's pre-existing materials and Client Confidential Information. If we or any designated third-party vendors provide licenses to you for software under a SO, then you understand and agree that such software is licensed, and not sold, to you.

Arbitration

Except for undisputed collection actions to recover fees due to us, any dispute, claim, or controversy arising from or related to this Agreement, including the determination of the scope or applicability of this agreement to arbitrate, shall be settled by arbitration before one arbitrator who is mutually agreed upon by the parties. The arbitration shall be administered and conducted by the American Arbitration Association or, if there is no such arbitrator available within a twenty (20) mile radius of our office, by any arbitration forum as determined by us, pursuant to that forum's arbitration rules for commercial disputes. In the event of any inconsistency between such rules and the procedures set forth in this paragraph, the procedures set forth in this paragraph will control. The arbitrator will be experienced in contract and information technology transactions. If the parties cannot agree on an arbitrator within fifteen (15) days after a demand for arbitration is filed, the arbitration venue shall select the arbitrator. The arbitration will take place in our office unless we agree to a different venue. The arbitrator will determine the scope of discovery in the matter; however, it is the intent of the parties that any discovery proceedings be limited to the specific issues in the applicable matter, and that discovery be tailored to fulfill that intent. Initially, the cost of the arbitration proceedings shall be split evenly between the parties and each Party will pay its own attorneys' fees and costs; however, the Party prevailing in the arbitration shall be entitled to an award of its reasonable attorneys' fees and costs.

Insurance

Each Party will obtain and maintain in effect during the term of this Agreement policies of comprehensive general liability, workers' compensation, professional liability, cyber liability insurance, and such other types of insurance each deems necessary to protect its interests from claims, liabilities, or damages that may arise out of the performance of its obligations under this Agreement. Client acknowledges that cyber liability, professional liability, technology errors and omissions, privacy liability, and any specialty coverage for AI-related or regulatory claims should be evaluated by Client with its insurance advisors based on Client's own operations and risk profile.

Right to Resell

a) License Grant. FutureSafe grants Client the right to resell the Services under Client's name and trademarks in the United States only. Client shall not use FutureSafe's name, trademarks, or logos in any manner without FutureSafe's prior written consent.

b) End User Defined. End User means the customers to whom Client resells the Services.

c) Relationship to End Users. FutureSafe's relationship with Client under the Agreement is solely with Client; End Users are not third-party beneficiaries of the Agreement. Client is the initial point of contact for all End Users. Client shall be solely responsible for End User pricing, billing, collections, customer service, legal compliance, and technical support. Client shall require each End User to sign a written contract with terms substantially similar to the terms contained in this Agreement and the applicable SO and include an express acknowledgement that End User has no rights against Client's supplier in connection with the Services.

d) Support. Client will be the first line of support for its End Users and will provide live support to its End Users including basic troubleshooting for the Services. FutureSafe will provide support to Client in connection with its End User accounts. If an End User needs advanced support, FutureSafe may, in its discretion, participate in three-way conversations or other three-party communications to assist Client in providing advanced support. FutureSafe does not expect to communicate directly with End Users regarding support questions, and Client agrees that it will not refer End Users to FutureSafe for direct support without FutureSafe's prior written consent.

e) Liability for Fees; End User Compliance. Client acknowledges that it is liable under the Agreement for the fees due for Services regardless of whether End Users pay amounts due in connection with their account with Client. Client acknowledges that it is responsible for use of the Services by each End User and compliance by each End User with the applicable terms of the Agreement.

f) Indemnification by Client. Client will indemnify and hold harmless FutureSafe and its officers, directors, shareholders, employees, agents, successors, and assigns from any and all liabilities, damages, costs, and expenses, including reasonable attorneys' fees and expenses, arising out of any claim, suit, or proceeding made or brought by any End User against FutureSafe relating to or arising out of the Services, including claims arising from Client's resale representations, Client's compliance commitments to End Users, or Client's deployment of regulated or AI-enabled workflows.

Miscellaneous

a) Client Regulatory Status. You warrant and represent that you know of no law or regulation governing your business that would impede or restrict our provision of the Services, or that would require us to register with, report to, or obtain approval from any government or regulatory authority as a result of our provision of the Services, except to the extent specifically disclosed by you in writing prior to commencement of the applicable Services. You agree to promptly notify us if you become subject to any of the foregoing which, in our discretion, may require a modification to the scope or pricing of the Services. Similarly, if you are subject to responsibilities under any applicable privacy, security, lending, insurance, healthcare, education, employment, consumer protection, or AI-related law, regulation, or guidance, then you agree to identify to us any data, systems, use cases, or information subject to such requirements before providing such information to us or, as applicable, before giving us access to such information.

b) Security. We do not warrant or guarantee that the Services will detect or resolve all malware or malicious activity in the Environment. You are strongly advised to educate your personnel to properly identify and react to phishing and related social engineering activity and to obtain and maintain insurance against cyberattacks, data loss, malware-related matters, privacy-related breaches, and technology-related claims, as such incidents can occur even under a best-practice scenario.

c) AI Use Restrictions and Validation. Client is solely responsible for validating the appropriateness, accuracy, legality, fairness, and business suitability of any AI-assisted or automated output before such output is used in production, communicated externally, used to make decisions affecting individuals, or relied upon for legal, compliance, operational, employment, lending, insurance, healthcare, education, safety, or other regulated purposes. Client shall not rely on any AI output without human review where such review is required by law, regulation, contract, internal policy, or prudent risk management.

d) Publicity. Each Party may use the other Party's name and trademarks in its marketing and promotional materials solely for the purpose of identifying the business relationship between the Parties, unless otherwise agreed in writing.

e) Assignment. Neither this Agreement nor any SO may be assigned or transferred by a Party without the prior written consent of the other Party, and this Agreement will be binding upon any parties to whom this Agreement is permitted to be assigned or transferred. Notwithstanding the foregoing, either Party may assign its rights and obligations hereunder to a successor in ownership in connection with any merger, consolidation, or sale of substantially all of the assets of that Party's business, or any other transaction in which ownership of more than fifty percent (50%) of that Party's voting securities are transferred, provided that the assignee must be reasonably capable of fulfilling the assignor's duties and obligations, including financial obligations, under this Agreement, and must so state in writing. This Agreement shall inure to the benefit of and be binding upon the successors and permitted assignees of the respective Parties.

f) Amendment. This Agreement may be amended or modified only by a written amendment executed by both parties, except that FutureSafe may update non-material administrative, operational, or contact details on its website or forms without a signed amendment so long as such updates do not materially alter pricing, scope, liability allocation, dispute resolution, confidentiality, or other substantive rights or obligations under this Agreement. Any material amendment to this Agreement or to a SO must be in writing and expressly accepted by both parties.