Cyber Defense Suite Terms
Version 1.0 · Effective September 18, 2026
These terms cover Shadowbear’s Cyber Defense Suite. Part A (Service Terms) applies to every Cyber Defense Suite client. Part B (General Terms) applies only to clients who have not signed a Shadowbear Master Services Agreement. If you have signed one, your Master Services Agreement takes the place of Part B.
1. About these Terms
1.1 Who we are. In these Terms, "Shadowbear," "we," and "us" mean Shadowbear LLC, a Virginia limited liability company with its principal place of business in Ashburn, Virginia. "Client" and "you" mean the business that orders the Cyber Defense Suite.
1.2 How these Terms apply. These Cyber Defense Suite Terms (the "Terms") apply to every Service Order for the Shadowbear Cyber Defense Suite that references them. You accept these Terms by signing a Service Order that references them.
1.3 Order of precedence. If you have not signed a Master Services Agreement, the documents apply in this order: (a) the Service Order, for the description, quantities, Fees, term and any Approved Deviations it lists; (b) these Terms; and (c) nothing else. Terms in your purchase orders, vendor forms or supplier portals have no effect, even if we accept or act on them.
1.4 If you have signed our Master Services Agreement. Part B does not apply to you. Part A applies as Service-specific terms of each Cyber Defense Suite Service Order under your Master Services Agreement (the "MSA"), and the MSA governs if the two conflict. Section 7.4 (Performance exit) applies under your MSA as well: it is a remedy for missed response targets that the Service Order expressly provides, as MSA Section 3.2 allows, and for the situation it covers it sets a different early termination fee (none), as MSA Section 6.3 allows.
1.5 Changes to these Terms. We may update these Terms by posting a new version at shadowbear.com/cyber-defense-suite-terms with a new effective date. The version in effect when you signed your Service Order applies until the end of its current term, and the new version applies from your next renewal unless you agree in writing to adopt it sooner. Changes that SPECTRA requires for its warranty program, or that the law requires, may take effect thirty (30) days after we notify you in writing.
1.6 Defined terms. In these Terms:
- "Service Order" means a Shadowbear proposal, statement of work, quote or order form that describes the Services, quantities, Fees and term, and that both parties sign or otherwise accept.
- "Services" means the Cyber Defense Suite plan and any add-ons listed in a Service Order. Each line item in a Service Order is a separate Service.
- "Fees" means the amounts payable for the Services, as stated in the Service Order.
- "Service Start Date" means the date the Service Order names as the start of the Services, or, if none is named, the date both parties have signed it.
- "Client Environment" means the networks, systems, devices, cloud tenants, accounts, applications and data that you own, license or control. The "In-Scope Environment" is the part of the Client Environment the Service Order covers.
- "Protected User" means an individual (an employee or contractor) who has a user account in the In-Scope Environment.
- "Named Contacts" means the people you designate in the Service Order to approve changes and emergency actions and to receive escalations.
- "SPECTRA" means Spectra Cyber Group Ltd. (doing business as SPECTRA), the independent cyber risk management firm that certifies the Cyber Defense Suite, and "SpectraCare" means its limited service performance warranty.
- "Third-Party Services" means the software, platforms and services from other providers that we use to deliver the Services.
PART A: SERVICE TERMS
2. The Cyber Defense Suite
2.1 Plans. The Cyber Defense Suite comes in three plans. Each plan includes everything in the plan before it.
| Plan | What it includes | SpectraCare warranty | Minimum |
|---|---|---|---|
| Core |
| $10,000 | 3 Protected Users |
| Advanced | Everything in Core, plus:
| $10,000 | 3 Protected Users |
| Command | Everything in Advanced, plus:
| $30,000 | 10 Protected Users |
2.2 Managed detection and response. Our SOC monitors the In-Scope Environment 24 hours a day, 7 days a week, 365 days a year. It collects and correlates endpoint, identity, cloud tenant and network edge telemetry; triages every alert; opens a case for each confirmed threat and investigates it to closure; and can take automated response actions (isolating a device, stopping a process, disabling an account or blocking network traffic) under Section 5.5.
2.3 Vulnerability management and patching. We scan covered endpoints and servers on a recurring schedule, deploy operating system and supported application patches within agreed maintenance windows, and give you prioritized recommendations for higher-risk findings.
2.4 Identity and cloud monitoring. We monitor your Microsoft 365 or Google Workspace tenant for suspicious and risky activity, including administrative and privileged activity, and help you put multi-factor authentication, conditional access and baseline hardening in place.
2.5 Log retention and reporting. SIEM logs, alerts and case records are kept for twelve (12) months from collection. You receive a monthly executive summary of alerts, cases, training results and trends, and we provide case records on request for audits, insurance applications and your customers’ due diligence.
2.6 Training, phishing simulations and dark web monitoring (Advanced and Command). Protected Users receive monthly security awareness training and quarterly phishing simulations, with user-level results. We monitor your domains for exposed credentials and alert you, with guidance on password resets, when they appear in known breach data.
2.7 SaaS Backup (Advanced and Command; add-on for Core). We back up Microsoft 365 or Google Workspace mail, files, calendars and contacts, monitor the backups and help you restore data. SaaS Backup is not intended for controlled unclassified information (CUI) or other specially regulated data unless the Service Order says it is.
2.8 vCISO sessions (Command). Quarterly strategy sessions with Shadowbear, up to eight (8) hours per 12-month term in total. Unused hours do not carry over.
2.9 Penetration test (Command). One external penetration test per 12-month term, covering up to ten (10) external IP addresses, performed by a qualified tester under written rules of engagement you approve and scheduled by mutual agreement. Web application, internal and cloud testing and retesting are not included and can be quoted separately. The engagement ends with delivery of the report.
2.10 Add-ons. The Service Order may add: additional endpoints, servers, SaaS-only users and firewall or network device log integrations; SaaS Backup on Core; additional SpectraCare coverage; a password manager; penetration testing on Core and Advanced; and incident response or advisory hours. Partner services, such as managed IT support from Vanilla Cyber, business phones from Vantage Unified and Vanta compliance automation, are not part of the Cyber Defense Suite and are provided under their own Service Orders and partner terms.
2.11 What is not included. Unless a Service Order adds it:
- End-user help desk and general IT support.
- Hardware, your software licensing and your network connectivity.
- Backup of endpoints and servers, and SaaS backup on Core.
- Incident response beyond SOC investigation and containment, such as recovery and rebuild of affected systems, forensic investigation, evidence preservation for litigation, breach coaching, dealing with threat actors and breach notification services.
- Running your compliance program, and audits, assessments or certifications.
- On-site work and travel.
We bill out-of-scope work at the hourly rate in the Service Order (or our standard rate if none is stated), and only with the prior approval of a Named Contact.
2.12 Our security stack. We deliver the Suite on a standard set of Third-Party Services that we select, configure and manage. We may change them as long as the Services stay materially the same. Where a platform requires end user terms, you agree to them.
3. Protected Users, devices and minimums
3.1 How the Suite is billed. Fees are charged per Protected User per month. Each Protected User includes one endpoint. Additional endpoints, servers and network device integrations are add-ons.
3.2 Monthly true-up. We count Protected Users and devices through our platforms each month and adjust the Fees going forward. Tell us within five (5) business days when you add or remove users or devices, including departing staff.
3.3 Plan minimums. The minimums are 3 Protected Users on Core, 3 on Advanced and 10 on Command. Meeting the minimum is what earns the plan’s included SpectraCare warranty. If you have fewer Protected Users than the minimum, you can still buy the plan: you pay only for the Protected Users you have, and you must carry a $10,000 SpectraCare warranty at the charge stated in the Service Order.
4. SpectraCare cyber warranty
4.1 SPECTRA certification and warranty. In this Section 4, "Customer" means Client.
The Shadowbear Cyber Defense Suite (Core, Advanced and Command plans) has been certified by SPECTRA, an independent cyber risk management firm, to be resilient to certain cyber events such as ransomware, business email compromise, and other disaster scenarios that may apply, subject to the terms and conditions of the Spectra Certification Services and Limited Service Performance Warranty Agreement located at https://spectracyber.com/spectracare-terms-conditions with a warranty value in accordance with the following table:
| Warranty | Value of Warranty |
|---|---|
| Managed Detection and Response (Core plan) | $10,000 |
| Managed Detection and Response (Advanced plan) | $10,000 |
| Managed Detection and Response (Command plan) | $30,000 |
| Managed Detection and Response (any plan, below the plan minimum) | $10,000 |
| Additional coverage | As stated in the Service Order, in $10,000 increments |
Customer agrees that this agreement incorporates all of the terms and conditions listed above, and that the warranty will only become effective upon issuance of a Certification of Resilience by SPECTRA.
The SpectraCare warranty for the Cyber Defense Suite applies only to managed detection and response, the certified service shown in the table above. Business email compromise is not a covered event under these Terms.
4.2 Who provides the warranty. SPECTRA issues SpectraCare directly to you and decides and pays any warranty claims under its terms. Shadowbear provides SpectraCare as part of the Suite but does not issue, guarantee or pay warranty claims. What the warranty covers is set by SPECTRA’s terms for the certified service shown in the table above. For managed detection and response, those terms cover a successful ransomware attack on the systems the Services cover, not third-party cloud services such as Microsoft 365 or Google Workspace. SpectraCare is a limited service performance warranty, not insurance, and it does not replace your cyber insurance.
4.3 When coverage starts and ends. Coverage begins when SPECTRA issues your Certificate of Resilience, after we register you and confirm that the certified service is live. It renews each year with your Service Order term and ends when your Cyber Defense Suite Services end. Under its terms, SPECTRA may suspend or end the warranty if Fees go unpaid or if you do not allow important or critical parts of the Services, such as patches and upgrades, to be implemented.
4.4 What you need to do. To keep the warranty available, you will:
- keep the Cyber Defense Suite active and paid;
- allow us to implement critical patches, upgrades and configurations;
- confirm your registration and accept SPECTRA’s terms when SPECTRA asks you to; and
- report a suspected covered event to us in writing within ten (10) business days, and provide, or allow us to provide, the logs and other evidence SPECTRA requires within thirty (30) days of the event.
We will help you prepare and submit the claim, and we will provide the case records and logs we hold.
4.5 Information we share with SPECTRA. You authorize us to register you with SPECTRA and to share the information SPECTRA needs to certify your environment and administer the warranty: your business contact details, a description of the covered environment, your Service Order and its warranty value, and records of service performance, incidents and claims. SPECTRA’s terms limit personal data to basic business contact information.
4.6 Warranty charges. The warranty included with a plan at or above its minimum has no separate charge. The required warranty for a client below the plan minimum, and any additional coverage, are charged as stated in the Service Order. They are billed annually in advance at the start of each contract year and are non-refundable once SPECTRA activates the warranty.
4.7 Cyber insurance. SPECTRA certification may help you obtain cyber insurance quotes through SPECTRA’s carrier partners. Insurers set their own terms and pricing, and we do not promise any premium, discount or coverage.
5. Onboarding, service levels and support
5.1 Onboarding. Onboarding usually finishes within five (5) business days after the Service Start Date: kickoff and scoping, agent deployment and integrations, baseline configuration and tuning, and go-live. Go-live is when every in-scope endpoint and server reports to our platforms and your cloud tenant integration is healthy. We send an onboarding completion report. Delays in the access, approvals or information we need extend these timelines.
5.2 Coverage hours. Monitoring, detection and response run 24 hours a day, 7 days a week, 365 days a year. Non-emergency requests, scheduled changes and reporting questions are handled from 9:00 a.m. to 5:00 p.m. Eastern Time, Monday through Friday, except U.S. federal holidays.
5.3 Acknowledgement targets. The SOC assigns each alert a severity. "Acknowledgement" means an analyst has started triage, measured from when the alert is created.
| Severity | Acknowledgement target | Examples |
|---|---|---|
| Critical | 15 minutes | Active ransomware behavior, a confirmed compromise of a privileged account, lateral movement |
| High | 60 minutes | Malware blocked but the device is still at risk, a suspicious privileged role change, an impossible-travel sign-in |
| Medium | 8 hours | A first sign-in from a new region or hosting provider, an unusual mailbox rule, a policy violation |
| Low | 24 hours | Informational detections, low-confidence indicators, hygiene findings |
5.4 How we notify you. For Critical and High cases, we phone and email your Named Contacts when the threat is confirmed and again when it is contained. For Medium and Low cases, we notify you by email or through the case record within one business day. Every case appears in the monthly executive report.
5.5 Containment authorization. You authorize us to isolate devices, stop processes, disable accounts and block network traffic without asking first when the SOC confirms an active threat. Systems you want exempt from automated isolation must be listed in the Service Order. We notify your Named Contacts of any containment action as soon as practicable.
5.6 Targets, not guarantees. The targets in this Section 5 are service targets, not guarantees, and missing them does not give you service credits. Your remedy for a material miss is the performance exit in Section 7.4.
5.7 Contacting us. Use the contacts in your Service Order. For an urgent security matter, call 571-680-6880.
6. Your responsibilities
You will:
- name at least two Named Contacts who can approve changes and emergency actions, and keep their details current;
- give us, and keep in place, administrative access to the in-scope cloud tenants, devices and network edge devices;
- run supported, licensed operating systems and applications, and keep devices online for patching within the agreed maintenance windows;
- put our minimum security baselines in place, or let us do it, including multi-factor authentication on all cloud accounts and our agent on every in-scope endpoint and server, and not remove or disable our agents;
- tell your staff about training enrollment and the endpoint agent, and have Protected Users complete assigned training;
- tell us before the Service Start Date about any regulated data in the In-Scope Environment, such as CUI, protected health information or payment card data, so that we can agree on any additional terms it needs;
- keep your own backups unless you buy SaaS Backup, keep your own cyber insurance, and decide and make any notifications the law or your contracts require after an incident;
- report suspected incidents to us promptly; and
- make sure your other IT providers work with us, and take responsibility for their actions in the Client Environment.
7. Term, renewal and ending the Services
7.1 Initial term. Twelve (12) months from the Service Start Date, unless the Service Order says otherwise.
7.2 Renewal. After the initial term, the Services continue month to month unless the Service Order states a renewal term. Either party may end month-to-month Services with thirty (30) days’ written notice.
7.3 Month to month from the start. If you do not want an initial term, the Services are available month to month from the Service Start Date at the higher month-to-month rate stated in the Service Order.
7.4 Performance exit. If, during the first ninety (90) days after the Service Start Date, we materially miss the acknowledgement targets in Section 5.3, and we do not correct the problem within fifteen (15) days after you tell us in writing what was missed, you may end the Service Order without an early termination fee. You must give written notice within thirty (30) days after the correction period ends.
7.5 Early termination. If you end a Service Order during its initial term for any reason other than Section 7.4 or our uncured material breach, you will pay the recurring Fees for the rest of the initial term as an early termination fee. This fee is not a penalty.
7.6 When we may end the Services. We may end a Service Order: (a) if undisputed Fees remain unpaid fifteen (15) days after a written past-due notice; (b) if you materially breach these Terms and do not cure the breach within thirty (30) days after written notice; (c) if your use of the Services creates a material security or legal risk to us or our other clients; or (d) on sixty (60) days’ written notice if a Third-Party Service we need is discontinued, materially changed or repriced and we cannot agree on a substitute or a price adjustment. In case (d), we refund any prepaid Fees for the period after termination, and no early termination fee applies.
7.7 When the Services end. You will pay the Fees owed up to the end date. We stop the Services and may remove our agents and software. On written request made within thirty (30) days after the end date, we will export the data reasonably available from the Services at our hourly rate. From the end date, you are responsible for securing the Client Environment, and your SpectraCare warranty ends.
8. Billing
8.1 Recurring Fees. Recurring Fees are invoiced monthly in advance and are due on or before the first day of each service period. Fees are in U.S. dollars and do not include taxes.
8.2 Price protection. Your per-user rate is fixed for the initial term. We may pass through a Third-Party Service provider’s cost increase on thirty (30) days’ written notice, and we may change rates for a renewal term on thirty (30) days’ written notice before it starts.
8.3 Other charges. Warranty charges are billed as described in Section 4.6. Add-ons and out-of-scope work are billed as stated in the Service Order.
PART B: GENERAL TERMS
Part B applies only if you have not signed a Shadowbear Master Services Agreement. If you have, your Master Services Agreement applies instead.
9. Access, third parties and recommendations
9.1 Authorization. You authorize us, our subcontractors and our Third-Party Service providers to access the In-Scope Environment, install and run agents and software, collect logs and telemetry, scan for vulnerabilities, make configuration changes and take the other actions reasonably needed to provide the Services. Penetration testing, phishing simulations and other intentional testing happen only under a written scope you approve, and you confirm you have the authority to approve testing of every system and person in scope.
9.2 Third-Party Services and subcontractors. Third-Party Services are subject to their providers’ terms. We are not responsible for their acts, omissions, availability or security beyond taking reasonable care in selecting and configuring them. We may use subcontractors, and we remain responsible for their work and for their compliance with Sections 10 and 11.
9.3 Recommendations. We may make written recommendations about security controls, configurations and practices. You decide whether to adopt them. If you decline, delay or do not fund a recommendation, we are not liable for losses it was meant to prevent or reduce, and any extra work that results may be billed as out-of-scope work.
9.4 Emergency actions. If we reasonably believe immediate action is needed to contain an active threat to the Client Environment or to our other clients, we may take reasonable containment actions before getting your approval, and we will tell you as soon as practicable.
10. Data protection and security
10.1 Your data. "Client Data" means the data you or your users give us, or that we collect from the Client Environment, in connection with the Services, including logs, telemetry, configurations and backups. You own Client Data. You grant us a non-exclusive license to access, collect, store, process and transmit Client Data, and to let our subcontractors and Third-Party Service providers do so, solely to provide the Services, to comply with law and as these Terms allow.
10.2 Our safeguards. We maintain administrative, technical and physical safeguards appropriate to Client Data and the Services, including access controls, multi-factor authentication for our administrative access, encryption of Client Data in transit and at rest where the platforms support it, and logging of administrative activity.
10.3 Security incidents. A "Security Incident" is a confirmed unauthorized access to, or acquisition, disclosure, alteration or destruction of, Client Data in our possession or control, including through a compromise of our own systems. We will notify you without undue delay, and in any event within seventy-two (72) hours, after we confirm a Security Incident, and share what we reasonably know about it and the steps taken. Threats we detect in the Client Environment are handled under Section 5 and are not Security Incidents unless Client Data in our possession is affected. You decide whether any notice to regulators, individuals, insurers or others is required and give it.
10.4 Regulated data. You will not give us, or store in systems we administer, protected health information, payment card data, CUI, classified information or other specially regulated data unless the Service Order identifies it, so that we can agree on any additional terms it requires.
10.5 Retention and return. We keep logs, telemetry and backups for the periods in Section 2.5 or the Service Order. After the Services end, we may delete Client Data once the export period in Section 7.7 has passed, except for copies kept in routine backups or as the law requires, which stay protected under Section 11.
10.6 Aggregated data. We may use data from the Services that has been aggregated and de-identified, so that it does not identify you or any individual, to improve our services and for threat intelligence and benchmarking.
11. Confidentiality
11.1 What is confidential. "Confidential Information" means non-public information one party shares with the other in connection with the Services that is marked confidential or that a reasonable person would understand to be confidential, including Client Data, security findings, incident and vulnerability information, network architecture, credentials, pricing and our tools and methods. It does not include information that is or becomes public through no fault of the recipient, that the recipient already knew without restriction, that the recipient develops independently, or that the recipient receives from a third party without restriction.
11.2 Obligations. Each party will use the other’s Confidential Information only for the Services, protect it with at least reasonable care, and share it only with people who need to know it and are bound by similar confidentiality obligations. A party may disclose it when the law requires, after giving prompt notice where allowed. You will share security assessment results and incident details only with people who need to know them, and with your insurers, auditors, assessors, regulators and advisors.
11.3 Duration. These obligations last during the Services and for three (3) years after they end, and for as long as information remains a trade secret. Obligations for Client Data continue as described in Section 10.
12. Intellectual property
12.1 Our materials. We and our licensors own our tools, scripts, playbooks, templates, methods and documentation, including improvements made while providing the Services. Nothing in these Terms transfers them to you.
12.2 Deliverables. Once the related Fees are paid, you may use, copy and modify the reports and other deliverables we give you for your internal business purposes, including sharing them with your insurers, auditors, assessors, regulators and advisors. You may not sell or license them.
13. Payment terms
13.1 Due dates and late payment. Invoices other than recurring Fees are due within fifteen (15) days of the invoice date. Late amounts accrue a charge of one and one-half percent (1.5%) per month, or the maximum lawful rate if lower. After written notice, we may suspend the Services for balances more than fifteen (15) days past due, and SPECTRA may suspend the warranty under its terms. You will reimburse our reasonable costs of collection, including attorneys’ fees.
13.2 Disputed invoices. Tell us in writing about a good-faith invoice dispute within fifteen (15) days of the invoice date, explain why, and pay the undisputed amount on time.
13.3 Taxes. You are responsible for sales, use, excise and similar taxes on the Services, other than taxes on our income.
14. Warranties and disclaimers
14.1 Our service warranty. We will perform the Services in a professional and workmanlike manner, with qualified personnel and commercially reasonable tools and methods consistent with generally accepted industry practice for managed security providers. If we do not, tell us in writing within thirty (30) days. We will re-perform or otherwise fix the problem, and if we cannot within a reasonable time, we will refund the Fees for the nonconforming part and either party may end the affected Service. This is your only remedy for breach of this warranty.
14.2 The nature of security services. No security product or service can guarantee that the Client Environment will not be compromised. The Services reduce, detect and respond to cyber risk; they do not guarantee that security incidents, malware, data loss or business interruption will not happen. We are not an insurer of your systems, data or operations. SpectraCare is SPECTRA’s warranty, governed by Section 4 and SPECTRA’s terms.
14.3 Compliance. The Services can help you meet the requirements of frameworks such as CMMC, NIST SP 800-171, SOC 2 and ISO 27001, but compliance, certification and assessment outcomes are decided by you and your assessors, auditors and regulators. We do not guarantee any outcome and do not give legal advice.
14.4 Disclaimer. EXCEPT AS EXPRESSLY STATED IN THESE TERMS, THE SERVICES, DELIVERABLES AND THIRD-PARTY SERVICES ARE PROVIDED "AS IS," AND WE DISCLAIM ALL OTHER WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICES WILL DETECT OR PREVENT EVERY THREAT OR SECURITY INCIDENT, OR THAT THE SERVICES OR THIRD-PARTY SERVICES WILL BE UNINTERRUPTED OR ERROR FREE.
15. Limitation of liability
15.1 Excluded damages. TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY IS LIABLE TO THE OTHER FOR INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, EXEMPLARY OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, BUSINESS, GOODWILL OR ANTICIPATED SAVINGS, LOSS OR CORRUPTION OF DATA, BUSINESS INTERRUPTION, THE COST OF SUBSTITUTE SERVICES, RANSOM OR EXTORTION PAYMENTS, OR REGULATORY FINES OR PENALTIES, ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICES, WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY OR OTHERWISE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
15.2 Liability cap. TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY’S TOTAL CUMULATIVE LIABILITY ARISING OUT OF OR RELATING TO A SERVICE, THE SERVICE ORDER UNDER WHICH IT IS PROVIDED, OR THESE TERMS AS THEY APPLY TO THAT SERVICE, WILL NOT EXCEED THE TOTAL FEES ACTUALLY PAID BY CLIENT FOR THE SPECIFIC SERVICE THAT GAVE RISE TO THE CLAIM DURING THE TWELVE (12) MONTHS IMMEDIATELY BEFORE THE EVENT GIVING RISE TO THE CLAIM (THE "CAP").
15.3 How the Cap is calculated. Each Service line item is a separate Service, and only the Fees paid for the Service that gave rise to the claim count. Fees for other Services, including those sold alongside it, do not count. For a one-time Service, the Cap is the Fees paid for it. If a Service has run for less than twelve (12) months, the Cap is the Fees paid for it to date. Claims arising from the same event or related events are treated as one claim, and the Cap is an aggregate limit for all claims relating to a Service.
15.4 Exceptions. Sections 15.1 and 15.2 do not limit your obligation to pay Fees, either party’s liability for fraud, gross negligence or willful misconduct, your obligations under Section 16, or liability that cannot be limited by law.
15.5 SpectraCare. Warranty payments are made by SPECTRA under its terms. They are not a liability of Shadowbear, are not limited or increased by this Section, and do not count toward the Cap.
15.6 Basis of the bargain. These limits are an essential part of the bargain between the parties, the Fees reflect them, and they apply even if a limited remedy fails of its essential purpose. Except for claims to collect unpaid Fees, a claim must be brought within one (1) year after it accrues.
16. Indemnification
16.1 By you. You will defend us, and our members, managers, employees, contractors and subcontractors, against third-party claims arising from: (a) Client Data or materials you provide; (b) use of the Services by you or your users that violates these Terms, the law or a third party’s rights; (c) testing or monitoring you authorized for systems, accounts or people you were not entitled to include in scope; (d) your failure to meet Section 6 or Section 10.4, or your decision to decline or delay a recommendation under Section 9.3; or (e) claims by your customers, users or others relating to the Client Environment or your business, except to the extent caused by our breach of these Terms. You will pay the damages, costs and reasonable attorneys’ fees finally awarded or agreed in a settlement you approve.
16.2 By us. We will defend you against third-party claims that our deliverables or materials, as we delivered them and as used under these Terms, infringe a U.S. patent, copyright or trademark or misappropriate a trade secret, and pay the amounts finally awarded or agreed in a settlement we approve. This does not cover Third-Party Services, your data or materials, changes we did not make, or combinations with items we did not supply. Our liability under this Section 16.2 is subject to Section 15.
16.3 Process. The party seeking defense will promptly notify the other in writing, give it control of the defense and settlement (no settlement may impose obligations on or admit fault by the defended party without its consent, which will not be unreasonably withheld) and cooperate at the defending party’s expense.
17. Non-solicitation
While the Services run and for twelve (12) months after they end, neither party will solicit for employment or engagement any employee or individual contractor of the other who worked on the Services, without the other’s written consent. General job postings do not count. A party that breaches this Section will pay the other, as liquidated damages and not as a penalty, fifty percent (50%) of the individual’s annualized compensation.
18. Disputes and governing law
18.1 Escalation. Before going to court (other than for injunctive relief or to collect undisputed Fees), a party will give the other written notice of the dispute, and senior representatives will meet within fifteen (15) business days to try to resolve it in good faith. If it is not resolved within thirty (30) days after the notice, either party may pursue its remedies.
18.2 Governing law and venue. These Terms are governed by the laws of the Commonwealth of Virginia, without regard to its conflict of laws rules. The state courts in Loudoun County, Virginia, and the United States District Court for the Eastern District of Virginia have exclusive jurisdiction, and the parties waive any objection to venue there. SpectraCare is governed by SPECTRA’s terms and the law they specify.
18.3 Jury waiver and fees. TO THE EXTENT PERMITTED BY LAW, EACH PARTY WAIVES ITS RIGHT TO A JURY TRIAL. The prevailing party in an action to enforce these Terms may recover its reasonable attorneys’ fees and costs.
19. General
19.1 Relationship. We are an independent contractor. These Terms do not create a partnership, joint venture, agency or employment relationship.
19.2 Force majeure. Neither party is liable for delays or failures (other than payment) caused by events beyond its reasonable control, including natural disasters, epidemics, government action, war, terrorism, civil unrest, labor disputes, internet or utility failures, Third-Party Service outages, and cyber attacks that could not have been prevented with reasonable care.
19.3 Assignment. Neither party may assign these Terms without the other’s consent, which will not be unreasonably withheld, except to a successor in a merger, acquisition or sale of substantially all of its assets or of the relevant business, on written notice.
19.4 Notices. Legal notices must be in writing and delivered by email with confirmation of receipt, by nationally recognized courier or by certified mail, to the addresses in the Service Order. Our notice address is Shadowbear LLC, 44679 Endicott Dr, Suite 300 #3131, Ashburn, VA 20147, ian@shadowbear.com. Routine communications may be made by email or through our ticketing system.
19.5 Entire agreement and deviations. These Terms and your Service Orders are the entire agreement about the Services and replace earlier proposals and understandings. A change to these Terms for a particular client is effective only if it is listed under an "Approved Deviations" heading in a Service Order signed by Shadowbear’s Chief Executive Officer or another officer designated in writing.
19.6 Waiver and severability. Not enforcing a provision is not a waiver. If a provision is unenforceable, it will be enforced to the maximum extent allowed and the rest of these Terms stay in effect.
19.7 Publicity. We may name you as a client, with your logo, in our marketing and client lists unless you object in writing, and we will stop within ten (10) business days of an objection. Neither party will issue a press release about the Services without the other’s consent.
19.8 Other terms. Each party will comply with applicable export control and sanctions laws. Service Orders and amendments may be signed electronically and in counterparts. Headings are for convenience, "including" means "including without limitation," and no rule of construction against the drafter applies. Sections that by their nature should survive the end of the Services survive, including Sections 4.5, 7.7, 8 and 10 through 19.
Shadowbear LLC · 44679 Endicott Dr, Suite 300 #3131, Ashburn, VA 20147 · 571-680-6880 · hello@shadowbear.com · shadowbear.com