Terms and Conditions for Invoke Security Advisor A Managed Security Engineering (MSE) service on Microsoft's AppSource marketplace Introduction This document outlines the terms and conditions that apply to your purchase and use of the Invoke Security Advisor service (the "Service"), a Managed Security Engineering (MSE) service offered by Invoke, LLC ("INVOKE") through its AppSource marketplace. By purchasing and using the Service, you agree to be bound by these terms and conditions. If you do not agree to these terms and conditions, you may not purchase or use the Service. Service Description The Service is a Managed Security Engineering (MSE) service that provides you with security assessments, recommendations, and remediation actions for your environment, based on Microsoft, INVOKE, and other potential industry standard recommended practices, including but not limited to Zero Trust (ZT). The Service is delivered by INVOKE, a Microsoft partner, using the Invoke Security Advisor platform, a cloud-based solution. The Service includes the following components: • A periodic security solution area evaluation of your environment, covering aspects such as architecture, security frameworks, and posture management across identity and access management, data security, threat protection, hybrid and cloud infrastructure, applications, endpoint management, and security operations. • A security report that summarizes the findings and recommendations of the assessment, based on but not limited to INVOKE proprietary, Microsoft, and industry standard methodologies. • A roadmap dashboard that provides you with a visual representation of your security posture, as well as actionable insights and remediation steps. • Security architect(s) and/or engineer(s) who will work with you to review the report, answer your questions, and help you implement the roadmap and recommendations. • A security review meeting that will take place periodically, where the security engineer will provide you with an update on your security progress, as well as any new or emerging threats or vulnerabilities. Service Fees and Payment The Service requires that you have an Invoke Services Agreement (ISA) already fully executed with INVOKE. The Service is offered as a subscription-based service, with a minimum term of 12 months. The Service fees are quoted on a case-by-case basis. Some service fees are billed up front and billed monthly in advance of services being performed, and are subject to change at any time, with prior notice to you. You are responsible for paying the Service fees, as well as any applicable taxes, in accordance with the payment method and terms that you select when you purchase the Service. If you fail to pay the Service fees on time, INVOKE may suspend or terminate your access to the Service, without prejudice to any other rights or remedies that INVOKE may have. Service Availability and Support The Service is provided on an "as is" and "as available" basis, without any warranties or guarantees of any kind, express or implied. INVOKE does not warrant that the Service will be uninterrupted, error-free, secure, or accurate, or that it will meet your expectations or requirements. You acknowledge that the Service may be subject to limitations, delays, and other problems inherent in the use of the internet and cloud computing, and that INVOKE is not responsible for any damages or losses resulting from such problems. You are solely responsible for ensuring that you have the necessary equipment, software, and internet connection to access and use the Service. INVOKE will provide you with technical support for the Service, in accordance with the support level that you choose when you purchase the Service. You can contact the support team by email, during the business hours specified in the Service description. The support team will make reasonable efforts to respond to your requests and resolve any issues that you may encounter with the Service. However, INVOKE does not guarantee that they will be able to resolve all issues, or that they will be able to do so within a certain time frame. You agree to cooperate with the support team and provide them with the necessary information and access to your environment, as requested by them, to facilitate the delivery of the Service and the resolution of any issues. Service Changes and Termination INVOKE reserves the right to modify, suspend, or discontinue the Service, or any part thereof, at any time, with or without notice to you. You agree that INVOKE will not be liable to you or any third party for any modification, suspension, or discontinuation of the Service, or any loss or damage that may result therefrom. You may terminate your subscription to the Service at any time, by notifying INVOKE in writing, at least 90 days before the end of your current subscription term. If you terminate your subscription before the end of your current subscription term, you will not receive any refund or credit for any unused portion of the Service fees that you have already paid. INVOKE may terminate your subscription to the Service at any time, with or without cause, by notifying you in writing, at least 30 days before the effective date of termination. If INVOKE terminates your subscription without cause, you will receive a pro-rated credit for any unused portion of the Service credits that you have already paid, pursuant to your Invoke Services Agreement. Upon termination of your subscription, your access to the Service will cease, and you will no longer receive any security reports, dashboard updates, or engineer support or services. You will also be responsible for deleting any data or information that you have stored or processed using the Service, and INVOKE will have no obligation to retain or return any such data or information to you. Service Data and Privacy In order to provide you with the Service, INVOKE may collect, store, process, and use certain data and information from your environment, such as your user accounts, security settings, configurations, audit logs, alerts, risks, issues, and incidents. You grant INVOKE the right to access, use, and disclose such data and information, solely for the purpose of delivering the Service to you, and in accordance with the Invoke Privacy Policy, which are incorporated by reference. You represent and warrant that you have the necessary rights and permissions to grant such right to INVOKE, and that you have obtained the consent of any individuals whose personal data may be included in such data and information, as required by applicable laws and regulations. You acknowledge that INVOKE may use aggregated and anonymized data and information derived from the Service, for their own business purposes, such as improving the Service, developing new products and services, and conducting research and analysis. Such aggregated and anonymized data and information will not identify you or any individuals and will not be subject to the Invoke Security Privacy Policy. Service Security and Compliance INVOKE is committed to protecting the security and confidentiality of your data and information, and will implement and maintain appropriate technical and organizational measures to mitigate the risk of unauthorized or unlawful access, use, disclosure, alteration, or destruction of your data and information. However, you acknowledge that no method of transmission or storage of data over the internet or the cloud is completely secure, and that INVOKE cannot guarantee the absolute security of your data and information. You are responsible for maintaining the security of your environment, and for complying with any laws and regulations that apply to your use of the Service, such as data protection, privacy, and security laws and regulations. You agree to notify INVOKE promptly of any breach or suspected breach of security or compliance that may affect the Service or your data and information. Service Limitations and Disclaimers The Service is intended to provide you with security assessments, recommendations, services, and remediation actions for your environment, based on the Invoke, Microsoft, and/or industry standard methodologies. However, the Service does not guarantee that your environment will be secure, compliant, or free from any threats or vulnerabilities, or that it will achieve a certain level of security maturity. You are solely responsible for implementing and verifying the security recommendations and remediation actions provided by the Service, and for ensuring that they are suitable and appropriate for your specific needs and circumstances. You acknowledge that the Service is not a substitute for your own independent judgment, analysis, and evaluation of your security posture, and that you should not rely solely on the Service for your security decisions or actions. You also acknowledge that the Service is not a substitute for professional security advice, guidance, or services, and that you should consult with qualified security experts if you have any questions or concerns about your security posture or the Service. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, INVOKE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, WITH RESPECT TO THE SERVICE, INCLUDING BUT NOT LIMITED TO, WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ACCURACY. YOU EXPRESSLY AGREE THAT YOUR USE OF THE SERVICE IS AT YOUR OWN RISK, AND THAT YOU ASSUME FULL RESPONSIBILITY AND LIABILITY FOR ANY LOSS OR DAMAGE THAT MAY RESULT FROM YOUR USE OF THE SERVICE. Service Liability and Indemnification TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, INVOKE WILL NOT BE LIABLE TO YOU OR ANY THIRD PARTY FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR EXEMPLARY DAMAGES, INCLUDING BUT NOT LIMITED TO, DAMAGES FOR LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR OTHER INTANGIBLE LOSSES, ARISING OUT OF OR IN CONNECTION WITH YOUR USE OF OR INABILITY TO USE THE SERVICE, EVEN IF MICROSOFT OR INVOKE SECURITY HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. IN ANY EVENT, THE TOTAL LIABILITY OF MICROSOFT AND INVOKE SECURITY TO YOU OR ANY THIRD PARTY FOR ANY CLAIMS OR DAMAGES RELATING TO THE SERVICE WILL NOT EXCEED THE AMOUNT OF THE SERVICE FEES THAT YOU HAVE PAID TO MICROSOFT IN THE 12 MONTHS PRIOR TO THE DATE OF THE CLAIM. You agree to indemnify, defend, and hold harmless INVOKE, and their respective officers, directors, employees, agents, and affiliates, from and against any and all claims, liabilities, damages, losses, costs, and expenses, including reasonable attorney fees, arising out of or in connection with your use of the Service, your breach of these terms and conditions, or your violation of any applicable laws or regulations, or the rights of any third party. Service Governing Law and Dispute Resolution These terms and conditions, and your use of the Service, are governed by the laws of the State of Texas, USA, without regard to its conflict of laws principles. Any dispute, controversy, or claim arising out of or in connection with these terms and conditions, or your use of the Service, will be subject to the exclusive jurisdiction and venue of the courts located in Montgomery County, Texas, USA. You waive any objection to such jurisdiction and venue, and agree not to commence or participate in any class action or consolidated action against INVOKE, relating to these terms and conditions, or your use of the Service. Service Miscellaneous These terms and conditions constitute the entire agreement between you and Microsoft, and supersede any prior or contemporaneous agreements, communications, or representations, with respect to the Service. You may not assign or transfer these terms and conditions, or your rights or obligations under these terms and conditions, without the prior written consent of Microsoft. Microsoft may assign or transfer these terms and conditions, or its rights or obligations under these terms and conditions, to any third party, without your consent. Any failure or delay by Microsoft or Invoke Security to exercise or enforce any right or provision of these terms and conditions, will not constitute a waiver of such right or provision. If any provision of these terms and conditions is found to be invalid or unenforceable by a court of competent jurisdiction, the remaining provisions of these terms and conditions will remain in full force and effect. These terms and conditions do not create any partnership, joint venture, employment, or agency relationship between you and INVOKE, or any rights or benefits for any third party, except as expressly stated herein.