Software as a Service (SaaS) Exhibit
Last Updated: August 24th 2026
This SaaS Exhibit (“SaaS Exhibit”) forms part of the Master Service Agreement (“MSA”) between Centripetal Networks, LLC and Customer identified in the applicable Order Form. This SaaS Exhibit governs Customer’s access to and use of the SaaS Products (as defined in the MSA), which are identified in the applicable Order Form. Capitalized terms used but not defined in this SaaS Exhibit have the meanings set forth in the MSA.
1. ACCESS AND USE
Subject to Customer’s timely payment of all undisputed Fees and its continued compliance with the applicable Agreements, Centripetal grants Customer a limited, non-exclusive, non-transferable, non-assignable, and non-sublicensable (except as expressly permitted herein) right, during the applicable Term, to access and use, and where applicable to install and operate the client or endpoint software components of, the SaaS Products specified in the applicable Order Form solely for Customer’s internal lawful business purposes. Customer shall use and access the SaaS Products in accordance with the Agreements and the Documentation. Customer acknowledges that the SaaS Products (including any associated software components) are licensed, not sold. As between the Parties, Centripetal and its licensors own all right, title, and interest in and to the intellectual property rights in the SaaS Products and any associated software components, including any improvements, modifications, or enhancements thereto, as further set forth in Section 5 (Centripetal Ownership) of the MSA. All rights not expressly granted to Customer are reserved by Centripetal and its licensors. Centripetal will provide Customer with the necessary credentials, passwords, and connectivity details to enable access to the SaaS Products.
2. USE RESTRICTIONS
Customer shall not use the SaaS Products in any manner not expressly permitted by the applicable Agreements or the Documentation. Without limiting the foregoing, Customer shall not, and shall not permit any third party to, directly or indirectly: (i) use the SaaS Products in any manner that violates Data Protection Laws or any other applicable law; (ii) use the SaaS Products in any manner that violates the applicable Agreements; (iii) use the SaaS Products in any manner that infringes, misappropriates, or otherwise violates any third-party’s rights; (iv) copy, modify, or create derivative works of the SaaS Products or create models that may compete with the SaaS Products, in whole or part; (v) rent, lease, lend, sell, sublicense, assign, transfer, or make available the SaaS Products to any third-party; (vi) reverse engineer, disassemble, decompile, decode, adapt, or attempt to derive or gain access to any software code or component of the SaaS Products; (vii) use the SaaS Products or any related outputs, including Threat Intelligence Data or Deliverables, to provide services to third parties (for example, as part of a managed service, outsourcing arrangement, or redistribution of threat intelligence feeds), except as expressly permitted in writing by Centripetal; (viii) use the SaaS Products for purposes of benchmarking, competitive analysis, or publication of performance tests without Centripetal’s prior written consent; (ix) interfere with or disrupt the integrity, performance, or security of the SaaS Products, including attempting to bypass or disable any security or access controls; (x) input, store, or transmit malicious code, unlawful content, or any material that violates third-party privacy or IP rights through the SaaS Products; (xi) remove any proprietary notices from the SaaS Products; or (xii) use, export, re-export, or provide access to the SaaS Products in violation of applicable export control or economic sanctions laws.
3. SUSPENSION OR TERMINATION OF SAAS PRODUCTS
Centripetal may suspend, temporarily or permanently terminate, deny, discontinue, or restrict Customer’s and any Authorized User’s access to and use of all or any of the SaaS Products, without any Liability to Customer, if: (i) Centripetal determines that Customer’s or any Authorized User’s use of the SaaS Products (1) violates Section 2 (Use Restrictions) of the SaaS Exhibit, Data Protection Laws, other applicable law, or the applicable Agreements, (2) creates or causes any security or privacy threat or risk, or disrupts any other person’s use of the SaaS Products, or (3) is illegal, unlawful, fraudulent, deceptive, defamatory, obscene, offensive, abusive, unethical, immoral, or dishonest; (ii) there is a threat or attack to the SaaS Products, Hardware, or Centripetal’s systems or infrastructure; (iii) Customer’s or Centripetal’s connection to computer systems, Internet, or hosting providers is impaired; (iv) Centripetal must do so under any Data Protection Laws or other applicable law, or pursuant to an order or instruction of any law enforcement, governmental, or regulatory authority; (v) Centripetal has ceased to continue its business in the ordinary course, made an assignment for the benefit of creditors or similar disposition, or becomes the subject of any bankruptcy, reorganization, liquidation, dissolution, or similar proceeding; (vi) there is suspension or termination of Centripetal’s use of any third-party technology or service required to support the SaaS Products; or (vii) Customer fails to pay undisputed Fees when due. Unless prohibited from doing so or otherwise commercially impracticable, Centripetal shall use commercially reasonable efforts to provide notice of any suspension or termination of the SaaS Products or Services to Customer under this section, and update Customer about the resumption of the SaaS Products following any such suspension or termination. Centripetal has no Liability to Customer arising out of or related to any suspension or termination of the SaaS Product under this section. The foregoing does not affect any refund of prepaid Fees to which Customer is entitled under Section 13 (Termination) of the MSA. Nothing in this section limits Centripetal’s obligations under the DPA. The rights in this Section are in addition to, and do not limit, Centripetal’s suspension and termination rights under Section 15 (Fees) of the MSA or any other right or remedy.
4. CUSTOMER RESPONSIBILITIES
Customer is liable to Centripetal for all Liability arising out of or related to Customer’s and Authorized Users’ access to and use of the SaaS Products. Without limiting the foregoing, Customer shall (i) ensure that it has all rights and authorizations necessary to provide Customer Data to Centripetal, including logs and telemetry from Customer’s third-party systems, for the purposes described in the MSA and this SaaS Exhibit; (ii) ensure that Customer’s systems, networks, and devices meet the minimum technical requirements specified by Centripetal for the SaaS Products and are properly configured and maintained; (iii) implement and maintain commercially reasonable measures designed to ensure the confidentiality and security of all passwords, biometrics, tokens, or other credentials used by Customer and Authorized Users to access the SaaS Products, and ensure that access credentials are not shared with or disclosed to any third-party; (iv) be responsible for the acts and omissions of its Authorized Users, including ensuring that Authorized Users comply with this SaaS Exhibit; (v) provide all notices and obtain all consents from individuals whose Personal Information may be processed in connection with Customer’s use of the SaaS Products, if such notice and consent is required by applicable Data Protection Laws; (vi) promptly notify Centripetal of any unauthorized access to, or use of, the SaaS Products of which Customer becomes aware; and (vii) for any SaaS Product that includes one or more installed or mobile client application(s), including CleanINTERNET-Remote, deployed on Authorized Users’ or other individuals’ devices (including personally owned devices), obtain and maintain all rights, authorizations, and consents necessary for the installation and operation of the client and for Centripetal’s access to, monitoring of, and processing of DNS queries, web communications, other traffic, and related data from those devices, including when the devices are used outside Customer’s network.
5. USAGE AND THREAT INTELLIGENCE DATA
Customer understands that in order for Centripetal to provide the SaaS Products, Centripetal needs to monitor, access, and process network traffic, queries, logs, and other data transmitted through or generated by the SaaS Products. Such monitoring and processing may include analyzing and correlating that data to detect threats, enhance performance, and improve the SaaS Products. Rights, ownership, and permitted uses of any resulting Usage Data and Threat Intelligence Data are governed by Section 5 (Centripetal Ownership) and Section 6 (Customer Ownership) of the MSA. Customer is responsible for providing all notices and obtaining all consents required under applicable law to enable such monitoring, access, and processing.
6. THIRD-PARTY PRODUCTS
Certain Products may include embedded software or software components delivered with SaaS Products, and may incorporate or be delivered through Third-Party Technology. Customer acknowledges and agrees that (i) Centripetal does not control and is not responsible for the operation, features, accuracy, or reliability of any Third-Party Technology; (ii) to the extent Centripetal makes any third-party license terms available to Customer, Customer’s use of the applicable Third-Party Technology is subject to those terms; and (iii) Centripetal provides Third-Party Technology “as is” without warranties of any kind and expressly disclaims all Liability with respect to such Third-Party Technology, except to the extent otherwise expressly set forth in the MSA. For clarity, certain SaaS Products may incorporate identified Third-Party Technology as specified in the applicable Order Form or related schedule.
7. LIABILITY
The Liability obligations of the Parties are set forth in Section 19 (Limitation of Liability) of the MSA, which apply in full to the SaaS Products. For clarity, Centripetal has no indemnification obligation with respect to any Third-Party Technology incorporated in or used with the SaaS Products.
8. RETURN OF INFORMATION
On the expiration or termination of the MSA, Centripetal shall return to Customer or destroy all Customer Data within ninety 90 days after the expiration or termination of the MSA; provided that Centripetal may retain such Customer Data on backup media as long as such media is periodically erased or overwritten, and such retained Customer Data shall remain subject to the Agreements for as long as Centripetal retains it.
9. MANAGED DETECTION AND RESPONSE (CI-MDR)
CI-MDR may be provided using Third-Party Technology, comprising endpoint security software and a managed detection and response service supplied by Centripetal’s third-party provider. Although CI-MDR is offered as a SaaS Product, Section 2 (Use Restrictions), Section 6 (Third-Party Products), and Section 7 (Liability) apply to it in full. In particular: (a) CI-MDR, including the endpoint agent and any service outputs, is provided “as is,” and Centripetal makes no warranty, representation, or guarantee regarding CI-MDR beyond any expressly stated in the MSA; (b) Centripetal has no indemnification obligation to Customer with respect to CI-MDR or the underlying Third-Party Technology; (c) detection, isolation, containment, and other response actions affecting an endpoint form part of the managed CI-MDR service and are undertaken at Customer’s risk, and Centripetal does not guarantee that any threat will be detected, prevented, or remediated; and (d) Customer’s access to CI-MDR depends on Centripetal’s continued access to that Third-Party Technology, and Centripetal may suspend or discontinue CI-MDR under Section 3 (Suspension or Termination of SaaS Products) if that access ends.