Customer contract (Master Services Agreement)

Living document · v1.1.0 · 2026-07-12. This is the working template; the signed PDF exchanged at onboarding is derived from this page and stays in sync with it.

1. Parties

This Master Services Agreement (“Agreement”) is between Norbeck Security Operations (NSO) and the customer entity identified on the signed cover page (“Customer”). Each engagement is governed by this Agreement plus a Scope of Work.

2. Services

  • Continuous or scheduled network security scanning of Customer-owned assets.
  • Findings triage, severity scoring, and remediation guidance.
  • Access to the NSO web application, API, and worker SDK.
  • All work is bounded by the Rules of Engagement.

3. Customer responsibilities

  • Provide accurate contact and billing information; maintain a designated security contact.
  • Prove ownership of each asset via DNS handshake before scanning.
  • Grant, in writing, any third-party authorization needed for hosted assets.
  • Enable MFA on all user accounts and rotate recovery codes yearly.
  • Respond to Critical findings within the SLA on the Scope of Work.

4. Fees & billing

  • Subscription fees, per-scan overage, and per-asset verification-retry fees are set on the Scope of Work.
  • Verification-retry charges are itemized on /settings/verification-audit.
  • Fees are billed monthly in arrears; invoices are due net-30.

5. Data protection & confidentiality

  • NSO processes Customer data solely to deliver the services.
  • Data at rest is encrypted (AES-256); data in transit uses TLS 1.2+.
  • Scan credentials are encrypted with AES-256-GCM in an isolated column.
  • NSO staff access is logged; privileged actions are audited.
  • Customer may export or delete their tenant at any time; deletion is irreversible after 30 days.

6. Warranties & disclaimers

NSO warrants that services will be performed with commercially reasonable skill and care. Security scanning is inherently probabilistic: NSO does not warrant discovery of every vulnerability or the absence of false positives. Beyond the express warranties, services are provided “as is”.

7. Liability

Each party’s aggregate liability under this Agreement is capped at the fees paid by Customer in the twelve months preceding the claim. Neither party is liable for indirect, incidental, or consequential damages, except for breaches of confidentiality, data protection, or the Rules of Engagement.

8. Term & termination

  • Initial term: 12 months, auto-renewing in 12-month periods unless either party gives 30 days written notice.
  • Either party may terminate for uncured material breach after 15 days notice.
  • On termination NSO ceases scanning immediately; Customer data is exported on request and deleted within 30 days.

9. Change control (living document)

Amendments to this Agreement are versioned in the changelog. Material changes require the Customer’s written acknowledgement (email from the designated contact is sufficient) before the next billing cycle.

10. Governing law

This Agreement is governed by the laws of the State of Maryland, USA, without regard to conflict-of-laws rules. Disputes are resolved in the state or federal courts sitting in Montgomery County, Maryland.