This Evaluation Agreement (the "Agreement") is between Surface Security, Inc., a Delaware corporation ("Surface Security," "we," or "us"), and the organization identified in the Signature Record ("Customer" or "you"). It takes effect when Customer signs it and confirms that signature through Surface Security's online signing process (the "Effective Date"). Surface Security accepts this Agreement by offering it for signature, and it countersigns to complete the Signature Record. The Data Processing Addendum (the "DPA") whose version is stated in the Signature Record is part of this Agreement.
1. Definitions
- "Affiliate" means an entity that controls, is controlled by, or is under common control with a party.
- "Authorized Users" means employees and contractors of Customer and its Affiliates who use the Enterprise Platform for their benefit.
- "Customer Data" means data that Customer, its Affiliates, or Authorized Users provide to, or that is processed by, the Enterprise Platform during the evaluation, including browsing activity, page content, screenshots, detections, and user information.
- "Customer-Hosted Evaluation" means an evaluation in which Customer runs the Enterprise Platform in its own environment, on-premises or in its own cloud tenant.
- "Documentation" means the user and technical documentation Surface Security provides for the Enterprise Platform.
- "Enterprise Platform" means Surface Security's enterprise browser security software and services, including the browser extension, control plane, updates, and Documentation.
- "Evaluation Period" means 30 days from the date Customer first receives access to the Enterprise Platform: for a Hosted Trial, when its first Authorized User signs in; otherwise, when Surface Security provides installation packages, as confirmed by email. It also includes any extension the parties agree by email between the contacts described in Section 12.
- "Hosted Trial" means an evaluation environment that Surface Security operates for Customer.
- "Service Data" means version, license, error, and network address information about the Enterprise Platform's operation. It contains no browsing activity, page content, or other Customer personal data. Surface Security may use it to provide, secure, and support the Enterprise Platform.
- "Signature Record" means the electronic record generated by Surface Security's online signing process. It states:
- Customer's legal name and address;
- the name, title, and email address of the individual who signed for Customer, and their typed signature;
- the versions and SHA-256 hashes of this Agreement and the DPA, computed over the published source text of each; and
- the time and IP address of Customer's signature and email confirmation, and, once added, the name, title, and time of Surface Security's countersignature.
- "Threat Indicators" has the meaning in Section 4.4.
2. Evaluation
2.1 License. During the Evaluation Period, Surface Security grants Customer a non-exclusive, non-transferable, non-sublicensable license to install the browser extension on devices Customer and its Affiliates manage and, for a Customer-Hosted Evaluation, the other components in Customer's environment. The license also covers using the Enterprise Platform, including to protect Authorized Users, solely for Customer's internal evaluation. Customer may let its Affiliates and Authorized Users use the Enterprise Platform under this Agreement and is responsible for their compliance with it. Surface Security keeps all rights not expressly granted. Open-source components are licensed under their own licenses.
2.2 Real data. Customer may connect real users and data to the evaluation. Customer decides which users, devices, and data to include, subject to Section 4.6.
2.3 No fees. The evaluation is free unless the parties agree otherwise in writing. Customer has no obligation to buy anything.
2.4 Support. Surface Security will provide reasonable onboarding and support during the Evaluation Period, by email or in sessions Customer schedules.
2.5 Access. Surface Security will not provide access to the Enterprise Platform, or receive Customer Data, before the Effective Date. Access to a Hosted Trial is limited to Authorized Users whose work email addresses are at the same domain as the individual who signed for Customer. Surface Security may decline an evaluation by notifying Customer within 10 business days after the Effective Date. This Agreement then ends, and Section 4.7 applies to any Customer Data already provided.
3. Restrictions and Permitted Testing
3.1 Restrictions. Customer will not, and will not allow others to:
- sell, sublicense, or provide the Enterprise Platform to third parties, or use it to provide services to third parties;
- reverse engineer, decompile, or disassemble the Enterprise Platform, except as Section 3.2 allows or as applicable law permits despite this restriction;
- use the Enterprise Platform or Documentation to build a product or service offered to third parties that competes with the Enterprise Platform, or resell its detections as a commercial threat intelligence feed. This does not restrict Customer's internal use of Customer Data, including detections;
- publish the results of benchmark or comparative tests of the Enterprise Platform without Surface Security's prior written consent. Customer may run such tests and share the results in confidence with its Affiliates, advisors, auditors, and regulators; or
- use the Enterprise Platform in violation of applicable law.
3.2 Permitted testing and security operations. Nothing in this Agreement restricts Customer from:
- inspecting, scanning, testing, or assessing the security, privacy, efficacy, and network behavior of Enterprise Platform components on systems Customer controls. This includes static and dynamic analysis, decompilation, and deobfuscation of the browser extension and other client components; interception of their network traffic; package and container scanning; simulated phishing and adversary-emulation exercises; and attempts to evade, tamper with, or disable the Enterprise Platform. Customer may do this itself or through third-party testers acting for it under confidentiality obligations;
- testing the web console and APIs of Customer's own Hosted Trial after five business days' email notice to Surface Security, excluding denial-of-service testing and any attempt to access other customers' data;
- using detections, verdicts, and alerts in its own security operations, including SIEM, SOAR, and internal threat intelligence systems; or
- sharing indicators of compromise with information sharing organizations, CERTs, law enforcement, or regulators.
Customer will not otherwise test the security of the infrastructure that runs a Hosted Trial without Surface Security's prior written consent. If Customer finds a vulnerability in the Enterprise Platform, it will report it to Surface Security. It will not publish the vulnerability until the fix is released or 90 days after the report, whichever comes first. Customer may share it in confidence with its regulators, auditors, and information sharing organizations at any time.
4. Customer Data
4.1 Ownership and use. As between the parties, Customer owns Customer Data. Surface Security will use Customer Data only to provide the evaluation and support to Customer, as described in the DPA, and for no other purpose, except as Section 4.4 permits.
4.2 Hosted Trial. For a Hosted Trial, Surface Security processes Customer Data as Customer's processor under the DPA. It stores Customer Data only in the United States, unless the parties agree otherwise in writing.
4.3 Customer-Hosted Evaluation. In a Customer-Hosted Evaluation, the Enterprise Platform stores Customer Data in Customer's environment and sends it elsewhere only as described in Section 6. Surface Security accesses that environment only in sessions that Customer initiates and supervises, or as Customer otherwise authorizes in writing. It receives Customer Data only in those sessions or in files Customer chooses to send, such as support logs. The DPA applies to that access and those files.
4.4 Threat Indicators. Customer instructs Surface Security to extract indicators of confirmed malicious activity from Customer Data, limited to:
- malicious domains;
- malicious web addresses, with query strings, fragments, and user-specific path elements removed;
- attacker IP addresses; and
- hashes of confirmed-malicious files.
These are "Threat Indicators." Surface Security may use Threat Indicators to improve threat detection for its customers. Threat Indicators will not include information that identifies Customer, its Affiliates, Authorized Users, or any other individual, including Customer's own domains, brands, or lookalikes of them. Surface Security will not try to re-identify them, and will not disclose them to third parties in a form linked to Customer. In a Customer-Hosted Evaluation, the software sends Threat Indicators to Surface Security only if Customer turns that feature on. Customer may opt out of this Section 4.4 at any time by email to legal@surface-security.com, effective for data processed afterward. Extracted Threat Indicators are not Customer Data.
4.5 No model training. Surface Security will not use Customer Data, including page content and screenshots, to train, fine-tune, or evaluate any machine-learning or AI model, except models used only for Customer's own deployment, and will not let any subprocessor do so. Surface Security will not send Customer Data to a third-party AI service unless that service is listed as a subprocessor in the DPA and is contractually prohibited from retaining Customer Data or using it for training.
4.6 Regulated data. For a Hosted Trial, Customer will configure the evaluation, and choose which users and devices to connect, so that it does not collect data from systems that process:
- protected health information under HIPAA, or health data subject to health-data hosting laws;
- payment card data; or
- confidential supervisory information,
unless the parties first sign an agreement that covers that data, such as a business associate agreement. If Surface Security becomes aware that a Hosted Trial contains such data, it will notify Customer and delete the data at Customer's direction. Customer's failure to exclude such data does not reduce Surface Security's obligations under Section 7 or the DPA.
4.7 Deletion. Within 30 days after this Agreement ends, or earlier on Customer's written request, Surface Security will delete all Customer Data, including copies in support tickets, email, and exports. It will certify the deletion in writing on request. Until deletion, Surface Security will return Customer Data on request in a commonly used, machine-readable format. Copies in backups are deleted when those backups are overwritten in the normal course, and they remain protected under the DPA until then. This Section does not apply to:
- Threat Indicators under Section 4.4;
- data the law requires Surface Security to keep, which it will protect and use only for that purpose; or
- a Hosted Trial the parties agree in a signed agreement to continue. That agreement then governs retention.
5. Customer Responsibilities
5.1 Notices and consents. Customer is responsible for giving any notices to, and obtaining any consents from, its Authorized Users and others whose browser activity the Enterprise Platform processes, as applicable law and Customer's own policies require. This includes laws on employee monitoring and interception of electronic communications, and consultation with works councils where applicable. Surface Security will provide reasonable information about the data the Enterprise Platform processes, and its privacy settings, to help Customer meet these obligations, including for data protection impact assessments and works council consultations.
5.2 Decisions. The Enterprise Platform's detections are automated and may be incomplete or wrong. It is designed to protect against security threats. It is not designed to evaluate individuals' performance or behavior, or to make employment decisions. Customer will not use its output as the sole basis for decisions that have legal or similarly significant effects on individuals.
5.3 Environment and accounts. In a Customer-Hosted Evaluation, Customer is responsible for securing, operating, and backing up its environment. Customer will keep its credentials for the Enterprise Platform secure.
6. Software Integrity
For software that Surface Security provides for installation on systems Customer controls, including the browser extension in a Hosted Trial:
- Surface Security will scan it with current malware-detection tools before release. It will not contain malware, or code designed to disable it other than the expiry behavior described below;
- it will contain no mechanism that lets Surface Security or anyone else access Customer's environment or Customer Data, other than the connections listed in the Documentation as of the Effective Date or added with at least 30 days' email notice;
- it will not send Customer Data outside Customer's environment except through those connections (and, in a Hosted Trial, to Customer's Hosted Trial). The Documentation identifies which connections Customer can disable or route through its own infrastructure, and the effect of doing so;
- software packages and updates will be cryptographically signed, and Surface Security will provide a software bill of materials on request;
- Surface Security will notify Customer without undue delay of any actively exploited or critical vulnerability in the software, and of its fix; and
- Surface Security will give Customer at least 7 days' email notice before the Evaluation Period ends. After it ends, the software may stop providing protection, but it will not block Authorized Users' browsing, and it will not delete, encrypt, or lock Customer Data.
7. Confidentiality
7.1 Definition. "Confidential Information" means non-public information that one party (the "Discloser") gives the other (the "Recipient") in connection with the evaluation, whether before or after the Effective Date, that is marked confidential or would reasonably be understood to be confidential. Surface Security's Confidential Information includes the Enterprise Platform, Documentation, pricing, and roadmaps. Customer's Confidential Information includes Customer Data, and Customer's systems, architecture, configurations, and security posture.
7.2 Obligations. The Recipient will protect the Discloser's Confidential Information with at least reasonable care and use it only for this Agreement. The Recipient may disclose it only:
- to its Affiliates, employees, contractors, auditors, and professional advisors who need to know it and are bound by confidentiality obligations at least as protective as these;
- in Customer's case, to its regulators and examiners, without notice; or
- as required by law, after giving the Discloser prompt notice where lawful, and cooperating, at the Discloser's expense, to limit the disclosure.
Surface Security may disclose Customer Data only as Section 4 and the DPA permit.
7.3 Exclusions. Confidential Information does not include information that:
- is or becomes public through no fault of the Recipient;
- the Recipient already knew without restriction;
- the Recipient develops independently; or
- the Recipient receives rightfully from a third party without restriction.
These exclusions do not apply to personal data in Customer Data.
7.4 Duration. These obligations last for three years after this Agreement ends. For trade secrets, Customer Data, and information about Customer's systems, architecture, and security posture, they last for as long as the information remains confidential.
7.5 Return. When this Agreement ends, the Recipient will return or destroy the Discloser's Confidential Information on request. This does not apply to copies in routine backups or copies the law requires the Recipient to keep, which remain subject to this Section 7.
8. Feedback and Publicity
8.1 Feedback. If Customer gives Surface Security feedback about the Enterprise Platform, Surface Security may use it without restriction or payment. Customer grants a non-exclusive, worldwide, perpetual, irrevocable, royalty-free license for this use. Feedback does not include Customer's Confidential Information or Customer Data, and this license grants no rights under Customer's patents. Surface Security will not identify Customer as the source of feedback without Customer's consent.
8.2 Publicity. Neither party will use the other's name or logo, or identify Customer as a customer, evaluator, or prospect, without the other's prior written consent.
9. Authority, Warranties, and Disclaimers
9.1 Authority. Each party represents that it has the authority to enter into this Agreement. The individual who completes the Signature Record for Customer confirms that Customer has authorized them to do so. If Customer makes the Enterprise Platform available to Authorized Users or provides Customer Data to it, Customer is bound by this Agreement from that time. Surface Security's obligations under Sections 4, 6, and 7 and the DPA apply to that Customer Data in any case.
9.2 Disclaimer. EXCEPT AS SET OUT IN SECTIONS 6 AND 9.1, THE ENTERPRISE PLATFORM IS PROVIDED FOR EVALUATION "AS IS," WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY. THIS INCLUDES ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. SURFACE SECURITY DOES NOT WARRANT THAT THE ENTERPRISE PLATFORM WILL DETECT OR PREVENT ALL THREATS, WILL BE FREE OF FALSE POSITIVES OR FALSE NEGATIVES, OR WILL OPERATE WITHOUT INTERRUPTION OR ERROR. Nothing in this Section limits Surface Security's obligations under Sections 4 and 7 or the DPA.
10. Limitation of Liability
10.1 Exclusion. TO THE FULLEST EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, OR GOODWILL, ARISING OUT OF OR RELATED TO THIS AGREEMENT.
10.2 Cap. TO THE FULLEST EXTENT PERMITTED BY LAW, EACH PARTY'S TOTAL LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT IS LIMITED TO US$10,000. FOR BREACHES OF SECTIONS 4, 6, OR 7 OR OF THE DPA, THE LIMIT IS US$100,000. THESE LIMITS ARE NOT CUMULATIVE; THE HIGHER LIMIT IS THE MAXIMUM TOTAL LIABILITY.
10.3 Data breach costs. For breaches of Sections 4, 6, or 7 or the DPA, the following are direct damages:
- reasonable costs of forensic investigation;
- the costs of notifying affected individuals and regulators, credit or identity monitoring, and call centers; and
- fines, penalties, and third-party claims payable because of the breach.
10.4 Exceptions. Sections 10.1 and 10.2 do not limit:
- liability for fraud, gross negligence, or willful misconduct;
- a party's liability for infringing or misappropriating the other party's intellectual property; or
- liability that cannot be limited by law, including liability to data subjects under the standard contractual clauses incorporated in the DPA.
11. Term and Termination
11.1 Term. This Agreement runs from the Effective Date until the Evaluation Period ends.
11.2 Termination. Either party may end this Agreement:
- for any reason, on five business days' written notice (email is enough); or
- immediately, if the other party materially breaches it.
Customer may also end this Agreement immediately on notice after a Security Incident, as defined in the DPA.
11.3 Effect. When this Agreement ends, Customer will stop using the Enterprise Platform, unless the parties have signed an agreement to continue. Customer will remove the browser extension and, for a Customer-Hosted Evaluation, uninstall and delete the other software. Surface Security will provide removal instructions. Surface Security will delete Customer Data as described in Section 4.7.
11.4 Survival. Sections 1, 2.3, 3.1, 3.2, 4, 5.2, 6 (for software that remains installed), 7, 8, 9.2, 10, 11.3, 11.4, and 12 survive the end of this Agreement.
12. General
-
Governing law and courts. This Agreement is governed by the laws of the State of Delaware, without regard to its conflict-of-laws rules, except as the DPA provides. The state and federal courts located in Delaware have exclusive jurisdiction, except that either party may seek injunctive relief in any court of competent jurisdiction to protect its intellectual property or Confidential Information.
-
Jury waiver. EACH PARTY WAIVES ITS RIGHT TO A JURY TRIAL in any dispute arising out of or related to this Agreement. If this waiver is unenforceable in the forum hearing a claim, and that forum is in California, the parties agree to judicial reference under California Code of Civil Procedure section 638.
-
Regulated customers. To the extent permitted by law, Surface Security acknowledges that Customer's regulators may examine the services it provides to Customer, including under 12 U.S.C. § 1867(c), and it will cooperate with their reasonable requests. Where Customer is a U.S. banking organization, Surface Security will notify Customer as soon as possible after determining that it has experienced a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, the Hosted Trial for four or more hours.
-
Export, sanctions, and anti-corruption. Each party will comply with applicable export control, sanctions, and anti-corruption laws. Each party represents that it is not located in, organized under the laws of, or ordinarily resident in a country or region subject to comprehensive U.S., EU, or UK sanctions. It also represents that it is not on a U.S., EU, or UK restricted-party list, and is not 50% or more owned, individually or in total, by persons who are.
-
U.S. government. The Enterprise Platform is "commercial computer software" and "commercial computer software documentation," provided to U.S. government users only with the rights set out in this Agreement.
-
Assignment. Neither party may assign this Agreement without the other's written consent, except to a successor in a merger, acquisition, or sale of substantially all of its assets, with notice to the other party.
-
Notices. Notices must be in writing and sent by email:
- to Customer, to the signer's email address in the Signature Record, and to any legal, security-incident, or privacy contacts Customer designates by notice; and
- to Surface Security, to legal@surface-security.com.
Either party may change its addresses by notice.
-
Force majeure. Neither party is responsible for delays or failures caused by events beyond its reasonable control. This does not excuse obligations under Section 7 or the DPA, including maintaining security measures and notifying Security Incidents. A cyberattack is not a force majeure event to the extent Surface Security's failure to maintain those measures contributed to it.
-
Entire agreement. This Agreement and the DPA are the entire agreement between the parties about the evaluation, and they replace any earlier agreement about it. However, any non-disclosure agreement between the parties continues to apply to information disclosed under it, and where both apply, the more protective terms control. Terms in any purchase order, click-through, installer, console, or portal have no effect, even if accepted, whether they are presented before or after the Effective Date. This includes Surface Security's website Terms of Service.
-
Precedence. If this Agreement conflicts with the DPA regarding personal data, the provision that better protects that data controls. The standard contractual clauses incorporated in the DPA control over both.
-
Changes. Changes must be in writing and signed by both parties, including electronically, except as Section 1 (Evaluation Period extensions) and DPA Sections 3.2 and 5.2 provide.
-
Execution record. The parties may sign this Agreement electronically, and electronic signatures and records have the same effect as handwritten ones. The Signature Record, and the copies of this Agreement and the DPA attached to it, are the parties' agreed record of execution. Later versions posted on Surface Security's website do not apply unless both parties sign them.
-
Other terms. If any part of this Agreement is found unenforceable, the rest remains in effect. A party's failure to enforce a provision is not a waiver. The parties are independent contractors. This Agreement gives no rights to third parties, except data subjects' rights under the standard contractual clauses incorporated in the DPA.