CYBERCOMPLY ON-PREMISES / SELF-HOSTED SOFTWARE LICENSE AGREEMENT
This Software License Agreement (“Agreement”) is entered into by and between Armada Cyber Defense LLC, doing business as CyberComply (“Provider”), and [Customer Legal Name], a [State and Entity Type], with its principal address at [Customer Address] (“Customer”).
This Agreement becomes effective on the date it is fully executed by both parties (“Effective Date”).
1. Software and Purpose
CyberComply is a governance, risk, and compliance software platform designed to help organizations manage requirements, controls, assessments, evidence, policies, risks, remediation, documentation, and reporting (“Software”).
This Agreement governs Customer’s installation and use of the Software in Customer-managed cloud infrastructure or an on-premises environment.
2. License Grant
Subject to payment of the applicable fees and compliance with this Agreement, Provider grants Customer a nonexclusive, nontransferable license to install and use the Software for its internal business purposes during the License Term.
The license includes:
- Unlimited supported frameworks.
- Unlimited projects.
- Unlimited authorized users.
“Supported frameworks” means frameworks available in the licensed self-hosted edition of CyberComply. It does not mean every existing framework or an obligation to develop additional frameworks upon request.
“Unlimited” means there is no contractual numerical limit on supported frameworks, projects, or authorized users within the approved deployment. Performance, storage, and availability depend on Customer’s infrastructure and the Software’s technical requirements.
This license does not authorize unlimited installations, resale, sublicensing, or use to provide services to unrelated customer organizations. Such rights require a separate written agreement.
Employees, contractors, and auditors may access the Software to support Customer’s internal activities, subject to appropriate permissions and confidentiality obligations. Customer is responsible for their compliance with this Agreement.
3. License Term
The license is valid for three years, beginning on the License Start Date specified below.
License Start Date: [Date]
License Expiration Date: [Date]
The Effective Date establishes when this Agreement becomes binding. The License Start Date establishes when the three-year license period begins.
This is a fixed-term license and does not provide perpetual or lifetime rights.
4. License Fee and Payment
The license fee is [US$ ] for the three-year License Term.
Payment arrangement: [Payment amount, schedule, and due dates]
Installation, onboarding, migration, custom integrations, additional support, and other professional services are included only when expressly identified in this Agreement or a signed statement of work.
Customer is responsible for applicable taxes and third-party infrastructure, hosting, connectivity, and service charges unless otherwise agreed in writing.
License fees are nonrefundable except as expressly provided in this Agreement or required by law.
Customer must notify Provider of any good-faith invoice dispute within thirty days of receipt and pay undisputed amounts when due. Provider may suspend license rights for undisputed overdue amounts after written notice and fifteen days to cure.
Provider will not erase Customer data or access Customer infrastructure without authorization to enforce payment obligations.
5. Deployment and Installation
Customer may deploy the Software in its own cloud environment or on-premises infrastructure, subject to the agreed technical requirements.
Deployment type: [Customer-managed cloud / On premises]
Approved environment and location: [Details]
Authorized production installations: [Number]
Authorized test, staging, and disaster-recovery installations: [Details]
Covered legal entities: [Customer only / Specifically named affiliates]
Provider will supply the agreed deployment package, activation materials, and available installation documentation.
Delivery date or period: [Details]
Installation and onboarding responsibilities: [Details]
Deployment options do not constitute a guarantee of compatibility with every cloud platform, operating system, or hardware configuration. The parties will confirm compatibility and prerequisites before installation.
Customer is responsible for maintaining its infrastructure, operating systems, databases, network connectivity, certificates, access controls, backups, and disaster-recovery arrangements unless a signed service schedule assigns specific responsibilities to Provider.
6. Custom Integrations
Custom integrations are available at an additional charge based on scope.
Before integration work begins, the parties must approve a written statement of work specifying:
- Integration requirements and deliverables.
- Technical dependencies and Customer responsibilities.
- Fees and payment milestones.
- Delivery schedule and acceptance criteria.
- Maintenance responsibilities.
- Ownership or licensing of integration deliverables.
Changes to the approved scope require written agreement.
Third-party subscriptions, API fees, access permissions, and related charges are Customer’s responsibility unless otherwise specified. Changes to third-party services may require additional integration work and separately agreed fees.
7. Updates, Maintenance, and Support
The parties will complete the following before signing:
Included updates: [Specify security patches, bug fixes, software releases, and framework updates]
Support coverage period: [Specify]
Support channels and hours: [Specify]
Response targets, if applicable: [Specify]
Responsibility for installing updates: [Customer / Provider / Separately scoped]
Supported versions and technical prerequisites: [Specify]
Additional maintenance or support fees: [Specify or “None for the listed coverage”]
Only the services expressly identified above or in a signed service schedule are included.
Infrastructure administration, backup restoration, migration, custom development, training, compliance consulting, and third-party troubleshooting require a separate agreement unless expressly included.
Provider does not control Customer-managed infrastructure and makes no hosting uptime commitment for that infrastructure unless expressly agreed in writing.
8. Customer Data, Privacy, and Storage
Customer retains ownership of all data and content it enters into the Software.
For on-premises or self-hosted deployments, customer data may be stored in infrastructure controlled by Customer. Provider’s collection or processing of information through support, licensing, diagnostics, integrations, or other services is governed by Provider’s Privacy Policy and this Agreement. Storage locations, access permissions, and responsibility for retention, export, and deletion are specified in this Agreement and its applicable schedules.
Customer is responsible for lawful collection and use of information, user permissions, retention, backups, and deletion within its controlled environment, except where responsibilities are expressly assigned to Provider.
Provider’s Privacy Policy applies to information Provider actually collects or processes, including information supplied through sales, billing, onboarding, support, and related services. Statements in that policy concerning Provider-hosted Console storage do not mean that Provider hosts or administers Customer’s self-hosted environment.
Customer grants Provider a limited right to process Customer data only as necessary to perform the contracted services or as otherwise expressly authorized by Customer. This Agreement does not grant Provider unrestricted access to Customer infrastructure or permission to use Customer content for unrelated purposes or AI model training.
Before deployment, the parties will document any external connections, licensing checks, diagnostics, telemetry, AI services, or integrations that transmit information outside Customer’s environment. That documentation will identify the information transmitted, its purpose, destination, and applicable controls.
Where required, the parties will execute a separate data-processing agreement.
Requests concerning personal information held by Provider may be directed to contact@armadacyberdefense.us. Requests concerning information held solely within Customer-controlled infrastructure are Customer’s responsibility.
9. Security and Authorized Access
Each party is responsible for implementing reasonable safeguards for information and systems within its possession or control.
Provider may access Customer’s environment only with Customer’s authorization or as expressly permitted in a signed service schedule. Access must be limited to the agreed purpose and duration.
Customer should provide sanitized support information where practical and avoid submitting unnecessary sensitive information.
Self-hosting does not establish that the Software or infrastructure is approved to store classified information, Controlled Unclassified Information, Federal Contract Information, or other restricted data. Any proposed use involving such information requires written agreement addressing authorization, technical suitability, security requirements, and responsibilities before that information is introduced.
Each party will notify the other without undue delay after discovering a security incident affecting the other party’s information in its possession or control, subject to applicable law and agreed incident-response requirements.
10. Confidentiality
Each party will protect nonpublic business, technical, financial, security, and customer information received from the other party using reasonable care.
Confidential information may be used only to perform obligations or exercise rights under this Agreement. It may be disclosed to personnel, contractors, and professional advisers who need access and are subject to appropriate confidentiality obligations.
Confidential information does not include information that:
- Becomes publicly available without a breach.
- Was already lawfully known without restriction.
- Is independently developed without using the other party’s confidential information.
- Is lawfully received from another source without a confidentiality obligation.
Disclosure required by law is permitted, with advance notice where legally allowed.
Confidentiality obligations continue for three years after expiration or termination. Trade secrets remain protected for as long as they qualify for protection under applicable law.
11. Intellectual Property and Restrictions
Provider and its licensors retain all rights, title, and interest in the Software, documentation, underlying technology, trademarks, and associated intellectual property.
The Software is licensed, not sold. No source-code ownership or redistribution rights are transferred.
Customer may not:
- Resell, sublicense, rent, or commercially distribute the Software without written authorization.
- Remove proprietary notices.
- Bypass license controls.
- Reverse engineer or decompile the Software except to the extent expressly permitted by applicable law.
- Use the Software for unlawful, fraudulent, or harmful activity.
- Introduce malware or attempt unauthorized access to systems or information.
Authorized installation and backup copies are permitted within the deployment rights specified in this Agreement. Third-party and open-source components remain subject to their applicable licenses.
12. Third-Party Services
Customer’s use of third-party cloud providers, integrations, software, or services is governed by the applicable third-party agreements.
Provider is not responsible for third-party availability, practices, or changes, except for obligations expressly assumed in a signed statement of work.
13. No Guarantee of Compliance Outcome
CyberComply supports governance, risk, compliance, documentation, and readiness activities.
Use of the Software does not guarantee regulatory compliance, certification, authorization, a successful assessment, a government contract award, or prevention of security incidents.
Customer remains responsible for implementing its controls, maintaining accurate evidence, meeting applicable requirements, and obtaining any necessary independent assessments or certifications.
14. Warranties and Disclaimers
Except for express commitments in this Agreement or a signed service schedule, the Software is provided “AS IS” and “AS AVAILABLE.”
To the maximum extent permitted by law, Provider disclaims implied warranties, including merchantability, fitness for a particular purpose, and noninfringement.
Provider does not warrant uninterrupted or error-free operation. General software content and documentation do not constitute legal, regulatory, or formal assessment advice.
15. Limitation of Liability
To the maximum extent permitted by law, neither party will be liable for indirect, incidental, special, consequential, or punitive damages, or lost profits, revenue, or business opportunities arising from this Agreement.
Each party’s aggregate liability arising from this Agreement will not exceed the total fees paid or payable under this Agreement.
This limitation does not excuse Customer’s payment obligations or limit liability for fraud, willful misconduct, or matters that applicable law prohibits limiting.
Any separately agreed exceptions or additional liability limits must be identified in a signed schedule.
16. Indemnification
Customer will defend and indemnify Provider against third-party claims arising from Customer’s unlawful use of the Software, infringement by Customer-supplied materials, or unauthorized resale or distribution.
Provider will defend and indemnify Customer against third-party claims that the unmodified Software, used as authorized, infringes a United States copyright or patent.
Provider’s obligation excludes claims arising from unauthorized modifications, combinations not supplied or approved by Provider, or use contrary to this Agreement.
The party seeking indemnification must promptly notify the other party, provide reasonable cooperation, and permit control of the defense. No settlement may impose an admission or nonmonetary obligation on the protected party without its consent.
If a covered infringement claim prevents authorized use, Provider may obtain continued usage rights, modify or replace the affected Software with materially equivalent functionality, or terminate the affected license and refund the prepaid license fee attributable to the unused term.
17. Suspension and Termination
Either party may terminate this Agreement for a material breach that remains uncured thirty days after written notice.
Where unlawful activity or an active security threat requires earlier restriction, Provider may restrict affected services or license functionality to the extent reasonably necessary and will provide notice as soon as practicable.
If Customer terminates for Provider’s uncured material breach, Provider will refund the prepaid license fee attributable to the unused License Term.
Upon expiration or termination, Customer must discontinue production use and remove active Software installations, subject to any agreed export period.
Customer retains ownership of its data. Provider has no right to erase data held solely in Customer-controlled infrastructure.
Agreed export period and method: [Specify available formats, duration, and any export-only access]
Customer is responsible for maintaining independent exports and backups. Any retained archival Software copies may not be used to resume production operation.
Provisions concerning accrued payment obligations, intellectual property, confidentiality, liability, and dispute resolution survive as appropriate.
18. Renewal
The license does not automatically renew.
Any renewal requires a written agreement identifying the renewal term, price, and included services.
19. Website Terms and Privacy Policy
Provider’s Privacy Policy and Terms of Use apply where relevant:
Privacy Policy: https://cybercomply.us/legal/privacy
Terms of Use: https://cybercomply.us/legal/terms
Dated copies or identified versions of these policies should be attached to this Agreement.
If a provision of the website terms conflicts with this Agreement concerning the self-hosted license, this Agreement controls.
Website provisions concerning subscription billing, hosted data deletion, termination, or policy changes do not alter the fixed-term rights and obligations expressly established here.
Changes to the website terms do not amend this Agreement without written agreement signed by both parties. Nothing in this section limits obligations imposed by applicable privacy law.
A signed data-processing agreement controls any conflict concerning personal-data processing.
20. Governing Law and Dispute Resolution
This Agreement is governed by the laws of the State of Florida, without regard to conflict-of-laws principles.
Any dispute arising out of or relating to this Agreement will be resolved exclusively in the state or federal courts located in Miami-Dade County, Florida.
21. General Provisions
Each party will comply with laws applicable to its performance, including applicable export restrictions.
Neither party may assign this Agreement without the other party’s prior written consent.
Amendments must be in writing and signed by both parties. A statement of work overrides a provision of this Agreement only when it expressly identifies the provision and the agreed change.
If any provision is unenforceable, the remaining provisions remain effective. Failure to enforce a provision does not constitute a waiver.
This Agreement and its signed schedules constitute the entire agreement concerning the licensed deployment and supersede prior discussions or proposals concerning that subject.
Electronic signatures and counterparts may be used.
22. Notices and Contact Information
Provider
Armada Cyber Defense LLC
Doing business as CyberComply
Miami-Dade County, Florida
Email: contact@armadacyberdefense.us
Phone: (305) 306-1800
Customer
Legal name: [Customer Legal Name]
Address: [Customer Address]
Notice email: [Email]
Contact person: [Name and Title]
Formal notices must be sent to the designated notice addresses with delivery confirmation or another method agreed in writing.
