Master Service Agreement · version 1

Master Service Agreement

Version 1 · Effective 2 August 2026

This Master Service Agreement (“Agreement”) governs your purchase and use of SentinelMDM's services. By checking the acceptance box, signing an Order Form, or using the Services, you agree to this Agreement. If you are accepting on behalf of a company or other organization, you represent that you have authority to bind it, and “you” and “Customer” mean that organization.

Please read Sections 5, 6, 7, 12 and 13 carefully. They describe controls we apply to your systems, obligations that are yours and not ours, the fact that we cannot recover your encrypted data under any circumstances, and the limits of our liability.

1 · Definitions

  • “Services” — the software, hardware, monitoring and managed IT services we provide, as described in an Order Form or Statement of Work.
  • “Order Form” — an ordering document, online checkout or quote that references this Agreement and specifies the Services, fees and term.
  • “SOW” — a Statement of Work describing project-based services.
  • “Managed Systems” — the computers, mobile devices, servers and network equipment you place under our management.
  • “Agent” — software we install on a Managed System to deliver the Services.
  • “Customer Data” — data you or your users submit to, or that the Services collect from, Managed Systems.
  • “Encrypted Customer Data” — Customer Data protected by the zero-knowledge encryption described in Section 7.2.

2 · Structure of this Agreement

2.1 This Agreement sets the general terms. Each Order Form or SOW describes specific Services and incorporates this Agreement by reference.

2.2 Order of precedence. If terms conflict, a signed SOW controls over an Order Form, which controls over this Agreement — but only for the Services covered by that document and only where the conflict is explicit. Sections 7, 12 and 13 control over all other documents unless a signed amendment expressly overrides them by number.

2.3 Your purchase order terms, click-through terms on your own systems, and vendor portal terms do not apply to us and are rejected, even if we acknowledge or sign them.

3 · The Services

3.1 We will provide the Services described in each Order Form or SOW with reasonable skill and care, consistent with generally accepted industry practices.

3.2 Changes. We may modify the Services provided the modification does not materially reduce their core functionality during a paid term. We will give at least 30 days' notice of any material change.

3.3 Third-party components. The Services incorporate third-party software, hardware and cloud infrastructure. We are responsible for our own performance, not for defects, outages or discontinuation of third-party components, though we will make commercially reasonable efforts to work around them.

3.4 Beta features. Features identified as beta, preview or experimental are provided as-is, without warranty or support, and may be changed or withdrawn at any time.

4 · Enrollment, access & administrative rights

4.1 Grant of access. You grant us and our authorized personnel the right to access, monitor, configure and administer the Managed Systems as needed to deliver the Services. This includes remote administrative access with the ability to execute commands, install and remove software, modify system and security configuration, access files, restart systems and view system state.

4.2 Your authority to grant it. You represent that you own the Managed Systems or have the legal right to place them under management, and that you have obtained every consent, notice, authorization and employee or household-member disclosure required by applicable law before enrollment. This is your responsibility, not ours. We rely entirely on your representation and do not independently verify it.

4.3 Monitoring features. Certain Services can capture screen content, keystrokes, location, network activity, application usage and similar information. Laws governing these capabilities vary significantly by jurisdiction and by relationship (employer/employee, parent/minor, household). You are solely responsible for determining whether your use is lawful and for obtaining required consents. We may refuse or discontinue any deployment we believe is unlawful.

4.4 Support access. Where you enable a support access or delegated administration feature, you authorize our personnel to act within your account under that delegation. Delegated access is recorded and can be revoked by you at any time.

4.5 Credentials. You are responsible for safeguarding account credentials and for all activity under your account. Notify us immediately of suspected compromise.

5 · Security controls & endpoint management

This section describes controls that intentionally restrict how Managed Systems can be used. By enabling them you accept the operational consequences described here.

  • 5.1 Application control. We may deploy allow-listing that blocks execution of software not on an approved list. Unapproved software — including software you already use — will not run until approved.
  • 5.2 Removable media control. We may block USB storage and other removable devices not on an approved list.
  • 5.3 Update management. We may suspend, defer, schedule or force operating system and application updates, including update cycles that restart Managed Systems. Restarts are preceded by an on-screen warning where technically possible, but work in progress may be lost. You are responsible for saving work and for scheduling maintenance windows that suit your operations.
  • 5.4 Disk encryption. We may enable full-disk encryption and escrow recovery keys on your behalf. Recovery keys are retained for as long as the volume remains encrypted. Encryption carries an inherent risk of data inaccessibility if hardware fails or a recovery key is lost.
  • 5.5 Detection. We may deploy detection, deception and network-discovery capabilities that generate alerts. Alerts are indicators, not conclusions. Detection technology produces both false positives and false negatives. We do not warrant that any threat will be detected, and detection is not a guarantee against compromise.
  • 5.6 Automated response. Where you enable automated response, the Services may terminate processes, isolate a Managed System from the network or block software without human review. Automated response can interrupt legitimate work. You accept this trade-off when enabling the feature.
  • 5.7 Compatibility. Security controls can conflict with line-of-business software, drivers and peripherals. We will work with you in good faith to resolve conflicts but do not warrant compatibility with any specific third-party product.

6 · Customer responsibilities

6.1 Backups are your responsibility. Unless a signed Order Form expressly includes a backup and recovery service with a stated recovery point and recovery time objective, you are solely responsible for backing up your data and verifying that your backups are complete and restorable. Any backup, sync or file-copy feature we provide is a convenience, not a backup service, and must not be relied on as your only copy.

6.2 Testing. You are responsible for testing configuration and policy changes against your own workflows before broad deployment, and for telling us which systems and applications are business-critical.

6.3 Environment. You will maintain functional power, internet connectivity, physical security, and licensed operating systems and applications on Managed Systems.

6.4 Cooperation. You will provide timely access, information, decisions and a responsive point of contact. Our obligations and timelines are excused to the extent delayed by your failure to cooperate.

6.5 Legal compliance. You are responsible for compliance with laws applicable to your business and data, including employment, privacy, wiretap, children's privacy and sector-specific regulations. We do not provide legal or compliance advice, and the Services do not by themselves make you compliant with any law, standard or framework.

6.6 Prohibited use. You will not use the Services to monitor anyone without required consent, access systems you are not authorized to access, violate any law, or interfere with the Services or other customers.

7 · Customer data, privacy & retention

7.1 Ownership. You own your Customer Data. We claim no ownership. We process it only to deliver, secure, support and improve the Services, and as described in our Privacy Policy.

7.2 Zero-knowledge encryption — read this carefully. Certain Customer Data is encrypted on your device before transmission using keys derived from your password and held only by you. We cannot decrypt this data. We have no master key, no backdoor and no recovery mechanism. The consequences are absolute and irreversible:

  • We cannot reset your password. Password recovery by email link or support request is not possible for zero-knowledge accounts.
  • If you lose your password, Encrypted Customer Data is permanently unrecoverable — by you, by us, and by anyone else. Recovery requires generating a new key pair and abandoning all previously encrypted data.
  • We cannot produce Encrypted Customer Data in response to your request, a subpoena, a court order or a regulatory demand, because we do not possess the means to read it.

You accept this design and its consequences. You are responsible for safeguarding your password and any recovery material. Nothing in this Agreement obligates us to recover data we are technically incapable of reading.

7.3 Retention & automatic deletion. Certain categories of Customer Data are automatically and permanently purged on a rolling 30-day schedule. This deletion is by design and is not reversible. If you require longer retention you must export data before the retention period ends. We are not liable for data lost to scheduled deletion.

7.4 Security. We maintain commercially reasonable administrative, technical and physical safeguards. No system is perfectly secure, and we do not warrant that the Services or your data will be free from unauthorized access.

7.5 Incident notice. We will notify you without undue delay after confirming a security incident affecting your Customer Data, and will cooperate reasonably in your investigation and any notification obligations you have.

7.6 Deletion on termination. After termination we will delete Customer Data in the ordinary course. Export your data before termination — see Section 9.5.

8 · Fees, billing & taxes

  • 8.1 You will pay the fees stated in each Order Form, in USD. Fees are non-refundable except as expressly stated.
  • 8.2 Renewal. Subscriptions renew automatically for successive terms equal to the initial term unless either party gives notice of non-renewal at least 30 days before the end of the then-current term.
  • 8.3 Price changes. We may change subscription pricing effective at the start of a renewal term on at least 30 days' notice. If you do not accept the change you may decline renewal.
  • 8.4 Payment terms. Invoiced amounts are due within 15 days. Overdue amounts accrue interest at the lesser of 1.5% per month or the maximum permitted by law. You will reimburse reasonable costs of collection.
  • 8.5 Disputes. Dispute an invoice in good faith within 15 days and we will work with you in good faith; undisputed amounts remain due.
  • 8.6 Chargebacks. Initiating a chargeback for services delivered, without first raising a good-faith dispute under Section 8.5, is a material breach and permits immediate suspension under Section 9.4.
  • 8.7 Hardware. Title and risk of loss pass on delivery. Hardware returns are governed by the return policy stated at purchase. Physical damage voids return eligibility.
  • 8.8 Taxes. Fees exclude taxes. You are responsible for all taxes other than taxes on our net income.

9 · Term, termination & suspension

9.1 Term. This Agreement begins on the Effective Date and continues until all Order Forms have expired or been terminated.

9.2 Termination for convenience. Either party may terminate a subscription effective at the end of the then-current term by giving notice under Section 8.2. Terminating mid-term does not entitle you to a refund except as stated in Section 9.3.

9.3 Termination for cause. Either party may terminate immediately if the other materially breaches and fails to cure within 30 days of written notice, or immediately on the other's insolvency. If you terminate for our uncured material breach we will refund prepaid fees for the unused remainder of the term.

9.4 Suspension. We may suspend the Services immediately, with notice where practicable, if fees are more than 15 days overdue; your use threatens the security or integrity of the Services or another customer; we reasonably believe your use is unlawful; or you initiate a chargeback in breach of Section 8.6. Suspension does not relieve you of payment obligations.

9.5 Effect of termination. On termination we will cease providing the Services and remove Agents from Managed Systems on reasonable request. You must export your Customer Data before termination. We will make it available for 30 days after termination where technically feasible, after which it is deleted. Encrypted Customer Data can only be exported by you, using your key — see Section 7.2.

9.6 Survival. Sections 1, 6.1, 7.2, 7.3, 8, 9.5, 9.6, 10, 11, 12, 13, 14, 18 and 19 survive termination.

10 · Confidentiality

10.1 Each party may receive the other's non-public information (“Confidential Information”). The receiving party will use it only to perform under this Agreement, protect it with at least reasonable care, and not disclose it except to personnel and contractors bound by comparable obligations.

10.2 Exclusions. Confidential Information does not include information that is public through no fault of the receiving party, was known without obligation before disclosure, is independently developed, or is rightfully received from a third party.

10.3 Compelled disclosure. A party may disclose if legally compelled, after giving prompt notice where lawfully permitted.

10.4 Security details. Our security architecture, detection logic, deception techniques and infrastructure details are our Confidential Information. Disclosing them degrades their effectiveness for every customer.

11 · Intellectual property

11.1 Ownership. We retain all rights in the Services, Agents, software, documentation and any improvements. No rights are granted except as expressly stated.

11.2 License. Subject to payment and compliance, we grant you a non-exclusive, non-transferable, non-sublicensable license to use the Services and install Agents on Managed Systems during the term.

11.3 Restrictions. You will not reverse engineer or attempt to derive source code (except where that restriction is unenforceable under applicable law); resell, sublicense or provide the Services as a service bureau; remove proprietary notices; or use the Services to build a competing product.

11.4 Open source. Certain components are provided under open source licenses, which govern those components and take precedence over Section 11.3 for those components only.

11.5 Feedback. If you give us suggestions or feedback we may use them without restriction or obligation.

12 · Warranties & disclaimers

12.1 Limited warranty. We warrant that we will perform the Services with reasonable skill and care. Your exclusive remedy for breach is re-performance of the deficient Services or, if we cannot reasonably re-perform, a refund of fees paid for those deficient Services.

12.2 Mutual. Each party warrants it has authority to enter into this Agreement.

12.3 DISCLAIMER. EXCEPT AS EXPRESSLY STATED IN SECTION 12.1, THE SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE.” WE DISCLAIM ALL OTHER WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT.

12.4 Specifically, we do not warrant that: the Services will be uninterrupted, timely or error-free; any threat, intrusion, malware or data loss will be detected or prevented; security controls will be compatible with any particular software or hardware; data will be recoverable, or that we will be able to assist in recovering it (see Section 7.2); automated responses will not interrupt legitimate activity; or that use of the Services will make you compliant with any law, standard or framework.

12.5 Security services reduce risk. They do not eliminate it. A determined attacker may succeed despite properly functioning Services.

13 · Limitation of liability

13.1 EXCLUSION OF INDIRECT DAMAGES. NEITHER PARTY IS LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR EXEMPLARY DAMAGES, OR FOR LOST PROFITS, LOST REVENUE, LOST BUSINESS, LOST GOODWILL OR BUSINESS INTERRUPTION, EVEN IF ADVISED OF THE POSSIBILITY AND EVEN IF A REMEDY FAILS OF ITS ESSENTIAL PURPOSE.

13.2 DATA LOSS. WE ARE NOT LIABLE FOR LOSS, CORRUPTION OR INABILITY TO RECOVER DATA, INCLUDING DATA LOST THROUGH A FORGOTTEN PASSWORD (SECTION 7.2), SCHEDULED DELETION (SECTION 7.3), OR YOUR FAILURE TO MAINTAIN BACKUPS (SECTION 6.1). THE COST OF RECONSTRUCTING LOST DATA IS YOURS.

13.3 CAP. EACH PARTY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF THIS AGREEMENT WILL NOT EXCEED THE FEES YOU PAID OR OWED US FOR THE SERVICES GIVING RISE TO THE CLAIM IN THE 12 MONTHS IMMEDIATELY PRECEDING THE EVENT.

13.4 Exceptions. Sections 13.1–13.3 do not apply to your payment obligations; either party's indemnification obligations under Section 14; your breach of Sections 11.3 or 6.6; or a party's gross negligence, willful misconduct or fraud.

13.5 Allocation of risk. You acknowledge these limits reflect an agreed allocation of risk, that our fees are set in reliance on them, and that we would not provide the Services on these commercial terms without them.

13.6 Some jurisdictions do not allow certain exclusions or limitations. In those jurisdictions our liability is limited to the greatest extent permitted by law.

14 · Indemnification

14.1 By us. We will defend you against third-party claims that the Services, as provided by us and used as permitted, infringe a U.S. patent, copyright, trademark or trade secret, and pay damages finally awarded or amounts we agree in settlement. If the Services become subject to such a claim we may procure the right to continue use, modify the Services to be non-infringing, or terminate the affected Services and refund prepaid unused fees. This is our entire liability for infringement.

14.2 By you. You will defend and indemnify us against third-party claims arising from your breach of Sections 4.2, 4.3, 6.5 or 6.6; any claim that monitoring or management of a Managed System was unauthorized or violated privacy, wiretap, employment or children's privacy law; your Customer Data; or your use of the Services in violation of law.

14.3 Procedure. The indemnified party will promptly notify the indemnifying party, give it sole control of the defense, and provide reasonable cooperation at the indemnifying party's expense. No settlement imposing a non-monetary obligation on the indemnified party may be made without its consent, not unreasonably withheld.

15 · Force majeure

Neither party is liable for delay or failure to perform (other than payment obligations) caused by events beyond its reasonable control, including natural disasters, war, terrorism, civil unrest, labor disputes, epidemics, government action, power or telecommunications failure, internet or cloud provider outage, or large-scale cyberattack against infrastructure the party does not control.

16 · Personnel & subcontractors

16.1 We may use subcontractors to deliver the Services and remain responsible for their performance under this Agreement.

16.2 Non-solicitation. During the term and for 12 months after, neither party will knowingly solicit for employment any employee of the other who was directly involved in the Services. General advertising not targeted at those individuals is not a breach.

17 · Publicity

We may identify you as a customer by name and logo in customer lists, unless you notify us otherwise in writing. Any other public statement, case study or quote requires your prior written approval.

18 · Governing law & disputes

18.1 Governing law. This Agreement is governed by the laws of the State of Kansas, USA, excluding its conflict-of-laws rules and the U.N. Convention on Contracts for the International Sale of Goods.

18.2 Escalation. Before filing any action the parties will attempt in good faith to resolve the dispute through discussion between senior representatives for at least 30 days after written notice of the dispute.

18.3 Venue. The parties consent to exclusive jurisdiction and venue in the state and federal courts located in Kansas, and waive objection to that venue.

18.4 Injunctive relief. Either party may seek injunctive relief in any court of competent jurisdiction to protect its Confidential Information or intellectual property without first following Section 18.2.

18.5 Limitations period. Any claim must be brought within one year after it accrues, except claims for non-payment.

19 · General

  • 19.1 Entire agreement. This Agreement, together with Order Forms, SOWs and policies referenced by URL, is the entire agreement and supersedes all prior proposals and understandings.
  • 19.2 Amendment. We may update this Agreement for future terms. Changes take effect for you only when you accept the updated version. The version you accepted continues to govern your account until you accept a newer one. We will notify you of material changes and ask you to review and accept them.
  • 19.3 Electronic acceptance. You agree that checking an acceptance box, clicking “I Agree,” or electronically signing an Order Form has the same legal effect as a handwritten signature under the federal ESIGN Act and applicable state UETA. We maintain records of acceptance including the version accepted, date and time, and originating IP address, and you agree those records are admissible evidence of acceptance.
  • 19.4 Notices. Notices to you may be sent to the email address on your account and are effective when sent. Notices to us must be sent to admin@sentinelmdm.com.
  • 19.5 Assignment. Neither party may assign this Agreement without the other's consent, except to a successor in a merger, acquisition or sale of substantially all assets, on notice.
  • 19.6 Waiver & severability. Failure to enforce a provision is not a waiver. If a provision is held unenforceable it will be modified to the minimum extent necessary to make it enforceable, and the rest remains in effect.
  • 19.7 Independent contractors. The parties are independent contractors. This Agreement creates no partnership, joint venture, agency or employment relationship.
  • 19.8 No third-party beneficiaries. This Agreement is for the benefit of the parties only.
  • 19.9 Export & sanctions. You will comply with applicable export control and sanctions laws.

20 · Acceptance

By checking the acceptance box, signing an Order Form, or using the Services, you acknowledge that you have read and understood this Agreement — including Section 7.2 (we cannot recover your encrypted data or reset your password), Section 6.1 (backups are your responsibility) and Section 13 (limits of liability) — and agree to be bound by it.

Master Service Agreement version 1 · effective 2 August 2026. Your acceptance is recorded with a timestamp, originating IP address, and a cryptographic hash of the exact version accepted. Questions? Email admin@sentinelmdm.com.