ARMOR ONE
MASTER SERVICES AGREEMENT
Version 1.0
Purpose of this Agreement
This Master Services Agreement (“Agreement”) establishes the general legal, operational, and commercial terms governing the relationship between ARMOR ONE (“Provider”) and the Client.
Rather than repeating standard contractual provisions in every proposal, quote, or project, this Agreement serves as the foundation for all services provided by Provider. Individual Quotes, Statements of Work (“SOWs”), Service Schedules, Change Orders, and other written documents describe the specific services, pricing, deliverables, and responsibilities applicable to a particular engagement. Those documents are incorporated into this Agreement by reference and together form the complete agreement between the parties.
The purpose of this Agreement is to establish a long-term technology partnership focused on maintaining reliable, secure, and efficient technology environments while clearly defining the responsibilities and expectations of both Provider and Client.
ARTICLE 1
Agreement Structure
1.1 Master Agreement
This Agreement establishes the general terms and conditions governing all services provided by Provider unless otherwise agreed in writing.
1.2 Service Documents
Services may be described in one or more of the following documents:
- Quotes
- Statements of Work (SOWs)
- Service Schedules
- Change Orders
- Project Proposals
- Renewal Agreements
- Other written documents executed by the parties
Each such document becomes part of this Agreement upon acceptance by both parties or upon the Client’s acceptance through electronic signature, written approval, payment, or authorization for Provider to begin work.
1.3 Order of Precedence
If a conflict exists between documents, the following order of precedence shall apply:
- Executed Amendment
- Statement of Work
- Service Schedule
- Quote or Proposal
- This Master Services Agreement
Unless expressly stated otherwise, the more specific document governs only the services described within that document.
1.4 Entire Agreement
This Agreement, together with all incorporated service documents, constitutes the entire agreement between the parties concerning the services provided by Provider and supersedes all prior proposals, negotiations, discussions, representations, or agreements relating to those services.
ARTICLE 2
Definitions
For purposes of this Agreement, the following definitions apply.
Agreement means this Master Services Agreement together with all incorporated Quotes, Statements of Work, Service Schedules, Change Orders, and amendments.
Business Day means Monday through Friday, excluding federal holidays observed by Provider.
Client means the individual, business, or organization purchasing services from Provider.
Change Order means a written modification to an existing project or scope of work.
Confidential Information means non-public business, financial, technical, operational, or proprietary information disclosed by either party.
Managed Services means recurring technology services provided under an ongoing service agreement.
Professional Services means consulting, engineering, implementation, migration, project, or other non-recurring services.
Provider means ARMOR ONE.
Service Schedule means a document describing recurring services, service-specific responsibilities, exclusions, service levels, and pricing.
Statement of Work (SOW) means a document describing project-specific deliverables, scope, assumptions, milestones, timelines, and pricing.
Supported Environment means technology that meets Provider’s published minimum standards and remains supported by its manufacturer or software publisher.
ARTICLE 3
Relationship of the Parties
3.1 Independent Contractor
Provider performs all services as an independent contractor. Nothing contained in this Agreement creates or shall be interpreted as creating a partnership, joint venture, agency, fiduciary relationship, employer-employee relationship, or other legal relationship beyond that of independent contracting parties.
3.2 No Exclusive Relationship
Unless expressly agreed in writing, this Agreement does not create an exclusive relationship. Client remains free to obtain services from other providers, and Provider remains free to provide services to other clients.
3.3 Authority
Each party represents that the individual executing this Agreement or authorizing services possesses the legal authority to bind that party.
3.4 Good Faith Cooperation
Both parties agree to work cooperatively and communicate in good faith throughout the relationship. Timely communication, reasonable access to necessary information, and mutual cooperation are essential to the successful delivery of technology services.
ARTICLE 4
Services
4.1 Scope of Services
Provider shall perform the technology services identified in the applicable Quote, Statement of Work (“SOW”), Service Schedule, Change Order, or other written agreement executed by the parties.
Services may include, but are not limited to:
- Managed IT Services
- Co-Managed IT Services
- Help Desk and End User Support
- Cybersecurity Services
- Microsoft 365 Services
- Cloud Services
- Backup and Disaster Recovery
- Business Continuity Services
- Network Administration
- Infrastructure Management
- Server Administration
- Virtualization Services
- Wireless Network Management
- VoIP and Unified Communications
- Procurement and Licensing
- Professional Services
- Technology Consulting
- Projects and Implementations
- Other technology-related services mutually agreed upon in writing.
No services shall be considered included unless specifically identified within an executed service document.
4.2 Technology Partnership
The parties acknowledge that the objective of this Agreement extends beyond simply resolving technical issues as they occur.
Provider will make commercially reasonable efforts to serve as the Client’s trusted technology partner by helping the Client improve reliability, security, operational efficiency, and long-term technology planning.
This may include recommendations regarding:
- cybersecurity best practices;
- software and hardware lifecycle planning;
- regulatory or industry technology considerations;
- infrastructure modernization;
- business continuity;
- disaster recovery;
- technology budgeting;
- cloud adoption;
- operational efficiencies.
Unless specifically stated otherwise, recommendations provided by Provider are advisory in nature. Final business decisions remain solely the responsibility of the Client.
4.3 Service Availability
Provider will deliver services during its normal business hours unless otherwise specified in the applicable Service Schedule or Quote.
Support availability, response objectives, emergency services, after-hours support, and service level commitments shall be governed by the applicable Service Schedule.
Unless expressly agreed otherwise in writing, Provider does not guarantee twenty-four (24) hour availability or immediate response.
4.4 Remote Services
The Client acknowledges that many services may be delivered remotely through secure remote access technologies.
Provider may utilize:
- remote monitoring and management software (RMM);
- secure remote desktop tools;
- automation platforms;
- scripting technologies;
- cloud administration portals;
- secure management interfaces;
- vendor management portals.
The Client authorizes Provider to utilize such technologies as reasonably necessary to perform contracted services.
4.5 Onsite Services
When onsite services are required, Provider will coordinate scheduling with the Client.
Unless otherwise stated within an executed Quote or Service Schedule:
- onsite work shall be performed during normal business hours;
- travel charges, if applicable, shall be identified in the applicable service document;
- emergency onsite requests may be subject to additional charges.
4.6 Third-Party Vendors
Provider may coordinate with Internet Service Providers, software vendors, cloud providers, telecommunications carriers, hardware manufacturers, or other third parties on the Client’s behalf.
While Provider will make commercially reasonable efforts to assist with vendor coordination, Provider is not responsible for:
- delays caused by third parties;
- third-party service interruptions;
- vendor support responsiveness;
- manufacturer warranty performance;
- licensing decisions made by third parties.
The Client remains responsible for maintaining active relationships and agreements with its third-party vendors unless Provider expressly assumes those responsibilities under a separate written agreement.
4.7 Recommendations
Provider may periodically recommend changes intended to improve the Client’s technology environment.
Recommendations may include, without limitation:
- replacing unsupported hardware;
- software upgrades;
- security improvements;
- backup enhancements;
- firewall modernization;
- wireless improvements;
- Microsoft licensing changes;
- endpoint protection improvements;
- infrastructure redesign.
The Client acknowledges that declining such recommendations may increase operational, security, or support risks.
Provider shall not be liable for issues directly resulting from the Client’s decision to decline reasonable recommendations.
4.8 Excluded Services
Unless specifically included within an executed Quote, Service Schedule, or Statement of Work, the following are excluded from recurring managed services:
- custom software development;
- website development;
- data entry;
- line-of-business software training;
- manufacturer warranty repairs;
- electrical work;
- structured cabling;
- physical security installation;
- building maintenance;
- office relocations;
- major technology projects;
- technology acquisitions;
- consulting outside the contracted scope.
Excluded services may be provided under a separate Quote or Statement of Work.
ARTICLE 5
Client Responsibilities
5.1 Cooperation
The Client agrees to cooperate with Provider and provide timely access to personnel, information, equipment, systems, facilities, and documentation reasonably necessary for Provider to perform the contracted services.
Failure to provide reasonable cooperation may delay service delivery or increase project timelines.
5.2 Authorized Contacts
The Client shall designate one or more authorized representatives who may:
- approve work;
- authorize projects;
- request changes;
- receive important communications;
- make technology decisions on behalf of the Client.
Provider may reasonably rely upon instructions received from an authorized contact unless notified otherwise in writing.
5.3 Administrative Access
The Client shall provide Provider with the administrative credentials, permissions, licenses, and access reasonably required to perform contracted services.
If administrative access cannot be obtained or is intentionally restricted, Provider shall not be responsible for delays, incomplete work, or limitations resulting from such restrictions.
5.4 Supported Technology
The Client agrees to maintain technology that reasonably meets Provider’s published technology standards.
Provider may recommend replacement or upgrade of technology that is:
- unsupported;
- obsolete;
- end-of-life;
- insecure;
- incompatible with current industry standards.
Support for unsupported technology may be limited or unavailable.
5.5 Security Cooperation
The Client agrees to cooperate with Provider regarding cybersecurity recommendations, including:
- password policies;
- multi-factor authentication;
- endpoint protection;
- operating system updates;
- software patching;
- user awareness training;
- backup verification;
- access control recommendations.
The Client understands that cybersecurity requires shared responsibility.
5.6 Accurate Information
The Client agrees to provide accurate and complete information reasonably necessary for Provider to perform services.
Provider shall not be responsible for delays, incorrect recommendations, or incomplete work resulting from inaccurate or incomplete information supplied by the Client.
5.7 Software Licensing
Unless otherwise agreed in writing, the Client remains responsible for maintaining legally compliant software licensing for all software not specifically supplied by Provider.
Provider may recommend licensing changes but assumes no responsibility for licensing deficiencies outside its contracted scope.
5.8 Safe Working Environment
When onsite services are provided, the Client agrees to provide a reasonably safe working environment.
Provider reserves the right to suspend onsite work where unsafe conditions exist until such conditions have been corrected.
ARTICLE 6
Technology Standards
6.1 Supported Environment
Provider delivers services most effectively when the Client’s technology environment is maintained in accordance with current industry standards and manufacturer recommendations.
Unless otherwise agreed in writing, Provider’s services are intended to support technology that:
- is currently supported by its manufacturer or software publisher;
- receives active security updates;
- is properly licensed;
- is compatible with Provider’s management and security tools;
- meets Provider’s minimum hardware and software standards.
Provider may periodically publish or update its minimum technology standards as industry requirements evolve.
6.2 End-of-Life and Unsupported Technology
Provider may recommend replacement or upgrade of hardware, software, operating systems, cloud services, or network equipment that has reached:
- End of Support (EOS);
- End of Life (EOL);
- End of Security Updates;
- Manufacturer Obsolescence; or
- another condition that materially increases operational or cybersecurity risk.
Provider may limit support for unsupported technology where continued support is impractical, technically infeasible, or presents unreasonable risk.
6.3 Deferred Technology Recommendations
The Client understands that delaying or declining Provider’s recommendations may increase the likelihood of:
- system failures;
- security vulnerabilities;
- compatibility issues;
- reduced application performance;
- hardware failures;
- data loss;
- increased support time;
- increased support costs.
Provider shall not be responsible for service interruptions, security incidents, or performance issues directly attributable to the Client’s decision to continue using technology that Provider previously identified as obsolete, unsupported, or materially deficient.
6.4 Third-Party Software
Provider supports many third-party software applications as part of the Client’s technology environment.
However, Provider does not warrant:
- compatibility between third-party products;
- vendor update schedules;
- software defects;
- licensing models;
- application availability; or
- vendor business decisions.
Where software issues originate with a third-party vendor, Provider may assist with troubleshooting and vendor coordination, but final resolution may depend upon the software publisher.
6.5 Standardization
To improve reliability, cybersecurity, documentation, and support efficiency, Provider may recommend reasonable technology standardization across the Client’s environment.
Examples include:
- workstation manufacturers;
- firewall platforms;
- wireless infrastructure;
- endpoint security software;
- backup platforms;
- productivity software;
- operating system versions;
- remote management tools.
Unless specifically included within an executed service document, the Client is not required to adopt Provider’s recommendations. However, non-standard technology may require additional support time and may be subject to additional charges.
6.6 Replacement Planning
Provider may periodically recommend replacement of technology approaching the end of its useful life.
These recommendations are intended to assist the Client with budgeting, operational planning, cybersecurity, and business continuity.
Technology replacement recommendations are advisory only unless specifically incorporated into an executed Quote, Statement of Work, or Service Schedule.
ARTICLE 7
Service Changes
7.1 Scope Changes
Either party may request changes to services during the term of this Agreement.
Requested changes may include:
- additional services;
- reduced services;
- project modifications;
- licensing changes;
- infrastructure changes;
- user count adjustments;
- location changes; or
- other modifications to the service relationship.
No requested change shall become effective until approved by both parties unless otherwise authorized under an existing Service Schedule.
7.2 Change Orders
Where a requested modification materially changes the scope of work, Provider may require execution of a Change Order before performing the requested work.
A Change Order may address:
- revised scope;
- pricing;
- timelines;
- assumptions;
- deliverables;
- project milestones;
- dependencies.
Once approved, the Change Order becomes part of this Agreement.
7.3 Additional Services
Services requested by the Client that fall outside the scope of an existing managed service, Statement of Work, or Service Schedule may be billed separately at Provider’s then-current rates unless otherwise agreed in writing.
Provider will make commercially reasonable efforts to notify the Client before performing billable work that falls outside the contracted scope whenever practical.
7.4 Emergency Work
From time to time, emergency situations may require Provider to perform immediate work in order to:
- restore operations;
- protect data;
- contain cybersecurity threats;
- minimize business interruption; or
- prevent additional damage.
When reasonably possible, Provider will obtain authorization before performing emergency work.
If immediate action is necessary to protect the Client’s environment and prior authorization cannot reasonably be obtained, Provider may perform commercially reasonable emergency services and invoice such work in accordance with the applicable Service Schedule or Provider’s then-current rates.
7.5 Client Requested Delays
If the Client requests suspension, postponement, or delay of scheduled work, Provider will make commercially reasonable efforts to accommodate the request.
Delays requested by the Client may require revised project schedules, additional coordination, or additional charges where significant rescheduling becomes necessary.
7.6 Service Evolution
Technology requirements evolve over time.
Accordingly, the parties acknowledge that services may reasonably evolve throughout the relationship to address:
- cybersecurity threats;
- regulatory changes;
- cloud platform changes;
- manufacturer requirements;
- software lifecycle changes;
- operational improvements; and
- emerging technology best practices.
Provider will communicate material service changes to the Client in advance whenever reasonably practical.
ARTICLE 8
Professional Services
8.1 General
Professional Services are non-recurring services performed outside the scope of the Client’s recurring Managed Services.
Professional Services may include, but are not limited to:
- technology consulting;
- infrastructure design;
- cloud migrations;
- Microsoft 365 implementations;
- server deployments;
- network installations;
- cybersecurity assessments;
- remediation projects;
- office relocations;
- technology upgrades;
- project management; and
- other consulting or implementation services.
Unless otherwise stated in writing, Professional Services are governed by this Agreement.
8.2 Statements of Work
Professional Services may be documented in a Statement of Work (“SOW”), Project Proposal, Quote, or other written agreement.
Each SOW should, where applicable, identify:
- project scope;
- assumptions;
- deliverables;
- estimated timelines;
- Client responsibilities;
- pricing;
- project milestones; and
- acceptance criteria.
If a conflict exists between this Agreement and an executed Statement of Work, the Statement of Work shall govern only with respect to that project.
8.3 Estimates
Unless expressly identified as a fixed-price project, all estimates of hours, costs, completion dates, and implementation schedules are provided in good faith based upon information reasonably available at the time of preparation.
Actual time and cost may vary based upon:
- changes in scope;
- unforeseen technical conditions;
- third-party delays;
- Client-requested modifications;
- inaccurate or incomplete information; or
- other circumstances beyond Provider’s reasonable control.
8.4 Client Responsibilities
Successful completion of Professional Services requires timely cooperation from the Client.
The Client agrees to:
- provide access to systems and facilities;
- identify project decision makers;
- review requested information promptly;
- participate in scheduled meetings when necessary;
- provide timely approvals; and
- complete assigned responsibilities within reasonable timeframes.
Project schedules may be extended where delays are caused by the Client or third parties.
8.5 Acceptance of Work
Unless otherwise specified in the applicable Statement of Work, project deliverables shall be deemed accepted upon the earliest of:
- the Client’s written acceptance;
- the Client’s productive use of the deliverable; or
- ten (10) business days following delivery, provided the Client has not identified a material deficiency in writing.
Provider will make commercially reasonable efforts to correct verified deficiencies that are inconsistent with the agreed project scope.
8.6 Project Suspension
If a project is delayed for more than thirty (30) consecutive days due to the Client’s actions or inaction, Provider may:
- reschedule project resources;
- revise implementation timelines;
- require execution of a revised project schedule; or
- invoice work completed to date.
ARTICLE 9
Fees, Billing, and Payment
9.1 Fees
The Client agrees to pay all fees identified in the applicable Quote, Statement of Work, Service Schedule, renewal agreement, or other executed service document.
Unless expressly stated otherwise, all prices are quoted in United States Dollars.
9.2 Recurring Services
Recurring Managed Service fees are billed in advance on a monthly basis unless otherwise specified in writing.
Recurring charges begin on the service commencement date identified in the applicable service document.
Partial months may be prorated at Provider’s discretion.
9.3 Professional Services
Professional Services may be billed:
- upon project completion;
- according to project milestones;
- monthly based upon work performed; or
- in advance,
as specified in the applicable Statement of Work or Quote.
9.4 Hardware, Software, and Licensing
Hardware, software, cloud subscriptions, software licensing, and third-party services may require payment prior to procurement unless otherwise agreed in writing.
Provider is not obligated to purchase products or activate services until required payments have been received.
9.5 Taxes
Unless expressly stated otherwise, fees do not include applicable federal, state, or local taxes.
The Client remains responsible for all applicable taxes except taxes imposed upon Provider’s net income.
9.6 Payment Terms
Invoices are due upon receipt.
Any invoice remaining unpaid thirty (30) days after the invoice date shall be considered past due.
Past-due balances may be subject to:
- suspension of services;
- finance charges permitted by applicable law;
- collection costs;
- reasonable attorney fees; and
- other remedies available under this Agreement or applicable law.
9.7 Billing Disputes
The Client shall notify Provider in writing of any billing dispute within fifteen (15) days after receipt of the applicable invoice.
Undisputed portions of an invoice remain payable in accordance with this Agreement.
The parties agree to work in good faith to resolve billing disputes promptly.
ARTICLE 10
Automatic Payment Authorization
10.1 AutoPay Requirement
To maintain efficient billing operations, Provider requires enrollment in automatic electronic payment (“AutoPay”) for all recurring service agreements unless Provider expressly agrees otherwise in writing.
Accepted payment methods may include:
- ACH;
- electronic funds transfer;
- approved business payment methods; or
- other payment methods designated by Provider.
10.2 Authorization
By entering into this Agreement, the Client authorizes Provider to automatically process recurring payments for all amounts properly due under this Agreement using the payment method maintained on file.
The Client agrees to maintain accurate and current payment information throughout the term of this Agreement.
10.3 Failed Payments
If an automatic payment is declined, rejected, returned, or otherwise fails, the Client agrees to promptly provide an alternative payment method.
Repeated payment failures may result in:
- suspension of services;
- delayed project work;
- removal of recurring discounts;
- collection activity; or
- termination of services as permitted under this Agreement.
10.4 Payment Information
The Client remains solely responsible for maintaining valid payment information.
Provider shall not be responsible for service interruptions resulting from expired, cancelled, or otherwise invalid payment methods.
10.5 Changes to Payment Method
The Client may update its payment information at any time by providing Provider with revised payment details in a manner approved by Provider.
Changes shall become effective as soon as reasonably practical following verification by Provider.
ARTICLE 11
Price Adjustments
11.1 Annual Price Review
Provider may review recurring service pricing annually to account for increases in operating costs, labor, software licensing, cybersecurity requirements, inflation, and other business expenses.
Any recurring price adjustment shall become effective no more than once during any twelve (12) month period unless otherwise agreed in writing.
11.2 Standard Annual Adjustment
Unless otherwise stated in the applicable Quote or Service Schedule, recurring service fees may be increased annually by the greater of:
- One and One-Half Percent (1.5%); or
- The annual percentage increase in the Consumer Price Index for All Urban Consumers (CPI-U), U.S. City Average, as published by the U.S. Bureau of Labor Statistics (or any successor index).
11.3 Notice
Provider will provide the Client with at least thirty (30) days’ prior written notice before any recurring price adjustment becomes effective.
Notice may be delivered by email to the Client’s designated administrative contact.
11.4 Scope Changes
This Article applies only to annual pricing adjustments.
Changes resulting from:
- additional users;
- additional devices;
- expanded services;
- reduced services;
- licensing changes;
- vendor price increases;
- project work; or
- Client-requested modifications,
may be billed separately in accordance with the applicable Quote, Statement of Work, or Service Schedule and are not considered annual price adjustments.
11.5 Third-Party Services
If a third-party vendor materially increases the cost of software licensing, cloud services, telecommunications, security services, hardware support, or other recurring products supplied to the Client, Provider may adjust the affected charges upon thirty (30) days’ written notice.
Provider will make commercially reasonable efforts to minimize the impact of such increases whenever practical.
ARTICLE 12
Term and Renewal
12.1 Initial Term
The initial term of this Agreement shall be identified in the applicable Quote, Service Schedule, or Statement of Work.
Unless otherwise specified in writing, the initial term may be:
- Month-to-Month;
- Twelve (12) Months;
- Thirty-Six (36) Months; or
- Sixty (60) Months.
12.2 Commencement
The Agreement becomes effective on the earlier of:
- the Effective Date identified in the applicable service document;
- the date the Client electronically or physically accepts a Quote, Statement of Work, or Service Schedule;
- the date Provider begins delivering services at the Client’s request; or
- the date the Client first makes payment for services under this Agreement.
12.3 Automatic Renewal
Unless either party provides notice of non-renewal prior to expiration of the Initial Term, this Agreement shall automatically continue on a month-to-month basis under the terms of this Agreement.
12.4 Month-to-Month Renewal Pricing
Upon expiration of the Initial Term, recurring services shall automatically convert to Provider’s then-current standard month-to-month pricing unless the parties execute a new fixed-term agreement.
Pricing discounts associated with an initial fixed-term commitment are not guaranteed beyond the Initial Term.
12.5 Termination Following Renewal
After the Agreement has converted to month-to-month status, either party may terminate recurring services by providing at least thirty (30) days’ prior written notice.
The Client remains responsible for all amounts accrued through the effective termination date.
12.6 New Service Agreements
Nothing in this Agreement prevents the parties from entering into a new fixed-term agreement at any time.
A new agreement may include revised pricing, services, or commercial terms mutually acceptable to both parties.
ARTICLE 13
Suspension and Termination
13.1 Suspension of Services
Provider may suspend some or all services, upon reasonable notice when practical, if:
- invoices become materially past due;
- required payment methods are removed or repeatedly fail;
- the Client materially breaches this Agreement;
- continued service would violate applicable law;
- the Client’s environment presents a significant cybersecurity risk to Provider or other clients; or
- suspension is reasonably necessary to protect Provider’s systems, personnel, or other clients.
Provider will make commercially reasonable efforts to minimize service disruption whenever circumstances permit.
13.2 Termination for Cause
Either party may terminate this Agreement upon written notice if the other party materially breaches this Agreement and fails to cure such breach within thirty (30) days after receiving written notice describing the breach.
If the breach cannot reasonably be cured within thirty (30) days, the breaching party shall not be considered in default provided it promptly begins corrective action and diligently pursues completion.
13.3 Immediate Termination
Either party may immediately terminate this Agreement if:
- the other party permanently ceases business operations;
- the other party becomes subject to liquidation or dissolution;
- continued performance becomes unlawful; or
- a court of competent jurisdiction orders termination.
13.4 Client Termination During Initial Term
If the Client elects to terminate a fixed-term recurring service agreement before expiration of the Initial Term for reasons other than Provider’s uncured material breach, the Client shall remain responsible for the early termination obligations expressly identified in the applicable Quote, Service Schedule, or other executed agreement.
If no early termination provision exists in the applicable service document, termination shall not relieve the Client of payment obligations that accrued prior to the effective termination date.
Drafting Note: I intentionally wrote this to reference the Service Schedule or Quote rather than hard-coding an early termination formula into the MSA. This gives ARMOR ONE flexibility to use different commercial models (for example, 100% of remaining MRR, 50% of remaining MRR, hardware payoff, or no ETF at all) depending on the client and offering.
13.5 Effect of Termination
Termination of this Agreement does not relieve either party of obligations that, by their nature, survive termination, including obligations relating to:
- payment of outstanding invoices;
- confidentiality;
- intellectual property;
- limitation of liability;
- indemnification;
- dispute resolution; and
- any other provisions intended to survive termination.
13.6 Transition Assistance
Upon termination, Provider will cooperate in good faith to facilitate an orderly transition of services.
Transition assistance beyond the scope of the Client’s recurring services may be billed at Provider’s then-current professional services rates unless otherwise agreed in writing.
Provider is not obligated to release administrative credentials, documentation, backups, or other deliverables until all undisputed outstanding amounts due under this Agreement have been paid in full, except where prohibited by applicable law.
ARTICLE 14
Confidentiality
14.1 Confidential Information
During the course of the business relationship, either party may disclose confidential or proprietary information to the other.
“Confidential Information” includes non-public information relating to a party’s:
- business operations;
- financial information;
- customers;
- vendors;
- technology;
- systems;
- network architecture;
- security practices;
- pricing;
- trade secrets; and
- other information reasonably understood to be confidential.
Confidential Information does not include information that:
- is or becomes publicly available through no wrongful act of the receiving party;
- was lawfully known by the receiving party before disclosure;
- is lawfully obtained from a third party without restriction; or
- is independently developed without use of the disclosing party’s Confidential Information.
14.2 Obligations of the Parties
Each party agrees to:
- protect the other party’s Confidential Information using at least the same degree of care it uses to protect its own confidential information, but no less than a commercially reasonable degree of care;
- use Confidential Information solely for purposes of performing under this Agreement;
- limit disclosure to employees, contractors, or advisors with a legitimate need to know; and
- require such individuals to maintain the confidentiality of the information.
14.3 Required Disclosure
Nothing in this Agreement prohibits either party from disclosing Confidential Information when required by law, court order, subpoena, or governmental authority.
Where legally permitted, the receiving party shall provide reasonable notice to the disclosing party before making such disclosure.
14.4 Return or Destruction
Upon written request following termination of the Agreement, each party shall return or securely destroy the other party’s Confidential Information that remains in its possession, except where retention is:
- required by law;
- necessary for insurance or audit purposes;
- maintained in routine backup systems; or
- reasonably required to enforce legal rights under this Agreement.
Information retained under these exceptions shall remain subject to the confidentiality obligations of this Agreement.
14.5 Survival
The confidentiality obligations contained in this Article survive termination of this Agreement.
ARTICLE 15
Intellectual Property
15.1 Pre-Existing Intellectual Property
Each party retains all ownership rights in its respective intellectual property existing prior to the Effective Date of this Agreement.
Nothing in this Agreement transfers ownership of pre-existing intellectual property.
15.2 Provider Materials
Provider retains ownership of all methodologies, documentation templates, scripts, automation routines, monitoring configurations, internal processes, standard operating procedures, software tools, reports, and other materials developed or used in the ordinary course of providing services.
Nothing in this Agreement grants the Client ownership of Provider’s internal tools, proprietary processes, or operational methodologies.
15.3 Client Data
The Client retains all ownership rights to its:
- business records;
- electronic data;
- databases;
- documents;
- email;
- cloud data;
- intellectual property;
- proprietary information; and
- other business information.
Except as necessary to perform services under this Agreement, Provider acquires no ownership interest in Client data.
15.4 Work Product
Unless otherwise agreed in writing, project deliverables specifically created for the Client under an executed Statement of Work become the property of the Client upon payment in full of all amounts due for those deliverables.
Provider retains ownership of any pre-existing intellectual property incorporated into such deliverables.
15.5 Third-Party Software
Software, cloud platforms, licensing, and third-party products supplied under this Agreement remain subject to the applicable vendor licensing agreements.
Nothing in this Agreement transfers ownership of third-party software or licenses to either party beyond the rights granted by the applicable vendor.
ARTICLE 16
Cybersecurity
16.1 Shared Responsibility
The parties acknowledge that cybersecurity is a shared responsibility.
Provider will implement the cybersecurity services specifically identified in the applicable Service Schedule or Statement of Work.
The Client remains responsible for its own business decisions, employee conduct, internal policies, regulatory compliance, and timely cooperation with Provider’s reasonable security recommendations.
16.2 No Guarantee Against Cyber Incidents
While Provider employs commercially reasonable security practices and technologies, no technology environment can be guaranteed to be completely secure.
Accordingly, Provider does not warrant or guarantee that the Client will never experience:
- cybersecurity incidents;
- ransomware attacks;
- phishing attacks;
- business email compromise;
- unauthorized access;
- malware infections;
- denial-of-service attacks;
- data loss; or
- other security events.
Provider’s obligation is to exercise commercially reasonable care in delivering the contracted cybersecurity services—not to guarantee a particular security outcome.
16.3 Client Cooperation
The Client agrees to reasonably cooperate with Provider regarding cybersecurity measures, including, where applicable:
- timely installation of security updates;
- use of multi-factor authentication;
- endpoint protection deployment;
- password policy implementation;
- user awareness training;
- access management;
- backup testing; and
- incident response activities.
The Client acknowledges that declining reasonable security recommendations may increase the likelihood or severity of future security incidents.
16.4 Security Incidents
If Provider becomes aware of a suspected cybersecurity incident affecting the Client’s managed environment, Provider will make commercially reasonable efforts to:
- investigate the reported condition;
- notify the Client’s designated contact;
- recommend appropriate containment measures;
- perform contracted incident response services, if applicable; and
- coordinate with third-party vendors where appropriate.
Additional incident response services outside the Client’s contracted service scope may be billed separately unless otherwise stated in the applicable Service Schedule.
16.5 Regulatory Compliance
Unless expressly agreed in writing, Provider does not provide legal, regulatory, or compliance consulting services.
Recommendations concerning HIPAA, GLBA, PCI DSS, FTC Safeguards Rule, CMMC, NIST, or other regulatory frameworks are provided for informational purposes only.
The Client remains solely responsible for determining and maintaining its own legal and regulatory compliance obligations.
16.6 Cyber Insurance
Provider strongly recommends that the Client maintain appropriate cyber liability insurance and business interruption insurance consistent with the size and nature of its business.
Provider’s services are not intended to replace or serve as a substitute for insurance coverage.
ARTICLE 17
Automation, Artificial Intelligence, and Remote Management
17.1 Use of Technology
To improve service quality, efficiency, consistency, and cybersecurity, Provider may utilize commercially reasonable technologies in the delivery of services, including:
- Remote Monitoring and Management (RMM) platforms;
- scripting and automation tools;
- software deployment systems;
- endpoint management platforms;
- patch management systems;
- security monitoring tools;
- cloud management platforms;
- documentation systems;
- reporting platforms; and
- artificial intelligence (“AI”) technologies.
The Client authorizes Provider to use such technologies as reasonably necessary to perform the contracted services.
17.2 Automation
Provider may automate routine administrative tasks, including but not limited to:
- software deployment;
- operating system updates;
- security patching;
- configuration management;
- monitoring;
- alerting;
- reporting;
- remediation of common technical issues; and
- routine maintenance activities.
Provider will exercise commercially reasonable care when implementing automated processes but cannot guarantee that automation will be error-free in every circumstance.
17.3 Artificial Intelligence
Provider may use commercially available artificial intelligence technologies to assist with:
- documentation;
- technical analysis;
- log review;
- cybersecurity investigations;
- reporting;
- scripting assistance;
- knowledge management;
- workflow automation; and
- administrative efficiency.
Provider will use commercially reasonable efforts to avoid intentionally submitting Client Confidential Information into publicly available AI systems in a manner that would compromise the Client’s confidentiality.
Provider remains responsible for reviewing AI-assisted work products before relying upon them in the delivery of services.
17.4 Remote Access
The Client authorizes Provider to remotely access systems, devices, and cloud services under Provider’s management when reasonably necessary to:
- provide support;
- investigate issues;
- perform maintenance;
- implement updates;
- deploy software;
- maintain security;
- monitor system health; or
- fulfill Provider’s obligations under this Agreement.
Provider will use commercially reasonable security practices when accessing Client systems remotely.
17.5 Third-Party Platforms
The Client acknowledges that Provider utilizes various third-party software platforms in delivering services.
These platforms may process or store limited information necessary to perform contracted services.
Provider will exercise commercially reasonable diligence when selecting third-party service providers but cannot guarantee the future performance, availability, or security practices of independent third-party vendors.
ARTICLE 18
Warranties and Disclaimers
18.1 Standard of Performance
Provider warrants that services will be performed in a professional and workmanlike manner consistent with generally accepted industry practices.
If the Client believes Provider has failed to meet this standard, the Client shall promptly notify Provider and provide a reasonable opportunity to investigate and correct the issue.
18.2 Hardware and Software
Provider does not manufacture hardware, software, or cloud services supplied under this Agreement.
Manufacturer warranties, software publisher warranties, and third-party vendor warranties remain solely those of the applicable manufacturer or vendor.
Provider assigns to the Client any transferable manufacturer warranties received by Provider to the extent permitted by the applicable vendor.
18.3 Disclaimer of Other Warranties
EXCEPT AS EXPRESSLY PROVIDED IN THIS AGREEMENT, PROVIDER DISCLAIMS ALL OTHER WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING ANY IMPLIED WARRANTIES OF:
- MERCHANTABILITY;
- FITNESS FOR A PARTICULAR PURPOSE;
- TITLE; AND
- NON-INFRINGEMENT.
18.4 No Guarantee of Continuous Operation
The Client acknowledges that information technology systems are inherently subject to interruption, failure, maintenance, cybersecurity events, utility outages, Internet disruptions, manufacturer defects, and circumstances beyond Provider’s reasonable control.
Accordingly, Provider does not warrant uninterrupted or error-free operation of any system, network, software, cloud service, or technology environment.
18.5 Recommendations
Technology recommendations made by Provider are based upon information reasonably available at the time they are provided.
Because technology continually evolves, Provider does not guarantee that any recommendation will remain the optimal solution indefinitely.
ARTICLE 19
Limitation of Liability
19.1 General Limitation
To the maximum extent permitted by applicable law, Provider’s total aggregate liability arising out of or relating to this Agreement shall not exceed the total fees actually paid by the Client to Provider during the twelve (12) months immediately preceding the event giving rise to the claim.
19.2 Excluded Damages
To the maximum extent permitted by applicable law, neither party shall be liable to the other for any:
- indirect damages;
- incidental damages;
- consequential damages;
- exemplary damages;
- punitive damages;
- special damages;
- lost profits;
- lost revenue;
- lost business opportunities;
- loss of goodwill; or
- business interruption,
regardless of the legal theory asserted, even if advised of the possibility of such damages.
19.3 Exceptions
The limitations contained in this Article shall not apply to:
- either party’s fraud or willful misconduct;
- either party’s obligations under Article 14 (Confidentiality);
- either party’s indemnification obligations under Article 20; or
- liability that cannot legally be limited under applicable law.
19.4 Allocation of Risk
The parties acknowledge that the pricing established under this Agreement reflects the allocation of risk contained herein.
The limitations of liability contained in this Agreement are a material basis upon which Provider has agreed to provide services at the agreed pricing.
ARTICLE 20
Indemnification
20.1 Client Indemnification
The Client agrees to defend, indemnify, and hold harmless Provider and its owners, officers, employees, contractors, and agents from and against third-party claims, damages, liabilities, judgments, and reasonable expenses, including reasonable attorneys’ fees, arising from:
- the Client’s breach of this Agreement;
- the Client’s negligent or wrongful acts or omissions;
- the Client’s misuse of technology or services;
- the Client’s violation of applicable law; or
- content, data, or materials supplied by the Client that infringe upon the rights of a third party.
20.2 Provider Indemnification
Provider agrees to defend, indemnify, and hold harmless the Client from third-party claims arising directly from Provider’s gross negligence, willful misconduct, or material breach of this Agreement, subject to the limitations contained in this Agreement.
20.3 Indemnification Procedure
A party seeking indemnification shall:
- promptly notify the other party in writing of the claim;
- permit the indemnifying party to control the defense and settlement of the claim, provided that no settlement imposing liability on the indemnified party shall be entered without that party’s consent, which shall not be unreasonably withheld; and
- reasonably cooperate with the defense of the claim at the indemnifying party’s expense.
ARTICLE 21
Insurance
21.1 Provider Insurance
Provider will maintain commercially reasonable insurance coverage appropriate for the nature and size of its business operations, which may include one or more of the following:
- Commercial General Liability Insurance;
- Professional Liability (Errors & Omissions) Insurance;
- Cyber Liability Insurance; and
- Workers’ Compensation Insurance, where required by law.
Evidence of insurance may be provided upon reasonable written request, subject to Provider’s confidentiality obligations and insurer restrictions.
21.2 Client Insurance
Provider recommends that the Client maintain insurance appropriate to its business operations, including, where applicable:
- property insurance;
- business interruption insurance;
- cyber liability insurance;
- crime or employee dishonesty coverage; and
- any industry-specific insurance required by law or contract.
The Client acknowledges that Provider’s services are intended to reduce technology risk but are not a substitute for appropriate insurance coverage.
21.3 No Assumption of Insurable Risk
Nothing in this Agreement shall be interpreted as Provider assuming responsibility for risks that are customarily covered by the Client’s insurance policies.
ARTICLE 22
Force Majeure
22.1 Excusable Delay
Neither party shall be liable for any failure or delay in performing its obligations under this Agreement to the extent such failure or delay results from circumstances beyond that party’s reasonable control.
Examples include, but are not limited to:
- natural disasters;
- severe weather;
- fire;
- flood;
- acts of God;
- war;
- terrorism;
- civil unrest;
- labor disputes;
- governmental actions;
- utility failures;
- Internet outages;
- cloud service disruptions;
- widespread cybersecurity incidents;
- pandemics; and
- failures of third-party infrastructure.
22.2 Notice
The affected party shall provide reasonable notice to the other party when practical and shall use commercially reasonable efforts to resume performance as soon as reasonably possible.
22.3 Payment Obligations
Force Majeure does not relieve either party of payment obligations that accrued before the Force Majeure event occurred.
ARTICLE 23
Dispute Resolution
23.1 Good Faith Resolution
Before initiating formal legal proceedings, the parties agree to make a good faith effort to resolve disputes through direct discussions between authorized representatives.
23.2 Governing Law
This Agreement shall be governed by and interpreted in accordance with the laws of the State of Michigan, without regard to its conflict of law principles.
23.3 Venue
Any legal action arising out of or relating to this Agreement shall be brought exclusively in the state or federal courts having jurisdiction in Monroe County, Michigan, or another mutually agreed venue.
Each party consents to the personal jurisdiction of such courts.
Attorney Review Note: Because federal courts are organized by judicial district rather than county, your attorney may wish to refine this venue provision to specify the appropriate federal district court serving Monroe County, Michigan.
23.4 Attorney’s Fees
In any legal action arising under this Agreement, the prevailing party may recover its reasonable attorneys’ fees, court costs, and litigation expenses to the extent permitted by applicable law.
ARTICLE 24
Notices
24.1 Written Notices
Formal notices required under this Agreement shall be provided in writing.
Notices may be delivered by:
- nationally recognized overnight courier;
- certified United States Mail, return receipt requested;
- personal delivery; or
- electronic mail to the designated business contact, provided no delivery failure notice is received.
24.2 Effective Date of Notice
Unless otherwise required by applicable law:
- notices delivered personally are effective upon delivery;
- notices sent by overnight courier are effective on the documented delivery date;
- notices sent by certified mail are effective upon delivery or refusal of delivery; and
- notices sent by email are effective on the date transmitted, provided no undeliverable or bounce notification is received.
24.3 Change of Contact Information
Each party agrees to promptly notify the other of any material changes to its legal name, mailing address, billing address, or primary business contact information.
ARTICLE 25
General Provisions
25.1 Assignment
Neither party may assign this Agreement without the prior written consent of the other party, except that Provider may assign this Agreement in connection with a merger, acquisition, sale of substantially all assets, or corporate reorganization.
25.2 Subcontractors
Provider may utilize qualified subcontractors, consultants, or third-party service providers in performing services under this Agreement.
Provider remains responsible for the performance of services provided on its behalf.
25.3 Severability
If any provision of this Agreement is determined by a court of competent jurisdiction to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.
25.4 Waiver
The failure of either party to enforce any provision of this Agreement shall not constitute a waiver of that provision or any other provision.
25.5 Electronic Signatures
The parties agree that electronic signatures, electronic records, and electronically accepted Quotes, Statements of Work, and Service Schedules shall have the same legal force and effect as original handwritten signatures to the fullest extent permitted by applicable law.
25.6 Counterparts
This Agreement may be executed in one or more counterparts, each of which shall be deemed an original, and all of which together constitute one agreement.
25.7 Survival
Any provisions that by their nature should survive termination—including, but not limited to, provisions relating to payment obligations, confidentiality, intellectual property, limitation of liability, indemnification, dispute resolution, and governing law—shall survive termination or expiration of this Agreement.
ARTICLE 26
Acceptance and Execution
26.1 Acceptance
This Agreement becomes binding upon the earliest of:
- execution of this Agreement by both parties;
- the Client’s execution of a Quote, Statement of Work, or Service Schedule incorporating this Agreement by reference;
- the Client’s electronic acceptance of services; or
- Provider’s commencement of services at the Client’s request.
26.2 Authority
Each party represents that the individual executing this Agreement or authorizing services has full authority to bind that party.
26.3 Incorporation by Reference
All Quotes, Statements of Work, Service Schedules, Change Orders, renewals, and written amendments executed by the parties are incorporated into this Agreement by reference and become part of the contractual relationship between the parties.
26.4 Entire Agreement
This Agreement, together with all documents incorporated by reference, constitutes the complete understanding between the parties concerning the services provided by Provider and supersedes all prior negotiations, discussions, understandings, and agreements relating to those services.
No amendment or modification shall be effective unless made in writing and signed or electronically accepted by both parties.