Skip to content
Sidero Labs
Talos LinuxTalos OmniCustomersPricingBlogDocs
Start trialGet demo →

Talos Enterprise Linux Master Services Agreement

This Talos Enterprise Linux Master Services Agreement (“Agreement” or “MSA”) is entered into between Sidero Labs, Inc., a Delaware corporation (“Company”), and the entity or individual that has accepted this Agreement (“Customer”) (individually a “party” and together the “parties”), effective as of the date Customer accepts this Agreement as described below.

This Agreement governs Customer’s purchase and use of Talos Enterprise Linux (“TEL”). Customer’s specific Services, Fees, Service Capacity, and Initial Service Term are set forth in the applicable Order Form, Subscription Confirmation (Section 4.4), or Reseller documentation (Section 4.5), as applicable to Customer’s purchase. There shall be no force or effect to any different terms of any related purchase order or similar form, even if presented to Company after the date hereof.

SERVICES AND SUPPORT

1.1 Services. Subject to the terms of this Agreement, Company will provide Customer the Services specified in the applicable Order Form through which the Services are ordered (each an "Order Form") (the "Services" or "SaaS Services"). SaaS Services are provided in accordance with the Service Level Terms in Exhibit A, while Self-Hosted Services are provided as software for use on Customer-managed infrastructure and are expressly excluded from the uptime guarantees in Exhibit A.

1.2 Talos Enterprise Linux. The Services, the Support Services, and the license granted under Section 2.6 (Enterprise Image Factory Access) are offered together as Company’s "Talos Enterprise Linux" or "TEL" commercial offering, as further described in the Order Form. Support Services, Enterprise Image Factory access, and the CVE remediation targets in Exhibit D are provided as standard, included components of an active TEL subscription and are not offered on a standalone basis.

1.3 SaaS Services.

1.3(a) SaaS Services: The "SaaS Services" (or "Hosted Services") consist of the proprietary Omni management platform hosted and maintained by Company, through which Customer may manage Kubernetes clusters and Talos Linux distributions.

1.3(b) Self-Hosted Services: The "Self-Hosted Services" consist of Company-provided code and management tools (the "Self-Hosted Software") that Customer installs and operates on Customer’s own private infrastructure, or infrastructure that Customer controls. The Self-Hosted Software includes Company’s Discovery Service component, which Customer may deploy and operate on its own infrastructure for use in connection with its Self-Hosted deployment. For the avoidance of doubt, the Discovery Service is not a "Supported Product" under Exhibit D and is not made available through the Enterprise Image Factory under Section 2.6; Customer's right to run it is limited to the license granted in Section 1.3(d).

1.3(c) Definition of Platform and Software: The "Platform" means and includes (i) the proprietary and third-party software applications provided or otherwise made available by Company (the "Software"), including updates, enhancements, patches, fixes or modifications; and (ii) all technology, technical information, discoveries, ideas, theories, improvements, tools, designs, original works of authorship, processes, algorithms, software, inventions, know-how, techniques, data, documentation and other information, including all intermediate and partial versions thereof, underlying the Platform.

1.3(d) Access and License Grant: Subject to Customer’s compliance with the terms and conditions of this Agreement, Customer is granted a limited, non-exclusive, non-transferable (except as permitted in Section 9), non-sublicensable, terminable, royalty-free (apart from the Services fees due to Company) license:

(i) for SaaS Services: to access and use the Services; and

(ii) for Self-Hosted Services: to use those portions of the Platform applicable to the relevant Order Form and Customer’s subscription, including any Software that Company makes available to Customer;

Usage Limitations: Customer shall exercise the rights granted in subsections (i) and (ii) only in order to make use of the Services and solely for Customer’s internal business operations during the Term. For clarity, Customer’s license to the Services for its business operations may include Customer’s management of Services at Customer’s clients’ worksites. No other rights or licenses are granted except as expressly set forth herein.

1.3(e) Exclusions of Open Source: For the avoidance of doubt, "Platform" and "Software" do not include open-source software (e.g., Talos Linux), which is governed by its own license.

1.4 Support Services. Company will provide Customer with Enterprise Support Services in accordance with the terms in Exhibit B, as a standard component of Customer’s TEL subscription.

1.5 Other Services. To the extent specified in an applicable Order Form accepted by the parties, the Company will perform (a) services to assist Customer in implementing the SaaS Services ("Implementation Services" or "Professional Services"). Such work will be performed for the prices in the applicable Order Form and SOWs, pursuant to the terms set forth herein and in SOWs signed by the parties.

1.6 Free Trial. If Customer registers for a free trial, Sidero Labs will make the applicable Services available on a trial basis, free of charge, until the earlier of: (a) the end of the trial period stated in the confirmation email sent to Customer upon registering for the trial; (b) the date Customer adds a payment method and converts to a paid subscription, or the date Sidero Labs provides written confirmation (including by email) of Customer's request for invoiced billing; or (c) termination by Sidero Labs at its discretion. Trial use is subject to all terms of this Agreement except payment obligations. NOTWITHSTANDING SECTION 6, DURING THE TRIAL PERIOD THE SERVICES ARE PROVIDED "AS IS" WITH NO WARRANTY OF ANY KIND AND SECTION 8 LIABILITY LIMITATIONS APPLY IN FULL. If Customer does not add a payment method or receive a billing confirmation from Sidero Labs before the trial period ends, Customer's access to the Services will be suspended and Customer Data may be deleted after thirty (30) days, with no liability to Sidero Labs. For clarity, the Enterprise Image Factory access described in Section 2.6 and the CVE remediation targets in Exhibit D are entitlements of an active, paid TEL subscription and are not available during a free trial.

RESTRICTIONS AND RESPONSIBILITIES

2.1 Restrictions

2.1.1 Open Source Compliance: Customer acknowledges that the Services manage or utilize software distributions, such as Talos Linux, provided under open-source licenses like the Mozilla Public License (MPL). Nothing in this Agreement shall restrict Customer’s rights to use, modify, or distribute such open-source software in accordance with its respective license.

2.1.2 Supportability of Modifications: While Customer may modify open-source software under its own license, any such modifications or Derivative Works are expressly excluded from the scope of Company’s Support Services. Company shall have no obligation to provide support for any version of the software that has been modified by Customer or a third party.

2.1.3 Proprietary Materials: Customer will not modify, translate, or create any Derivative Works based on the Services, Software or Platform (except to the extent expressly permitted by Company or authorized within the Services); use the Services, Platform or any Software for timesharing or service bureau purposes or otherwise for the benefit of a third party; or remove any proprietary notices or labels. "Derivative Work" for this Agreement means any modification of or extension to any software, process, algorithm, trade secret, work of authorship, invention, or to any other intellectual property right therein or thereto.

2.1.4 Security Vulnerability Disclosure. If Customer discovers a potential security vulnerability in Talos Linux, the Platform, or other Company Technology, Customer agrees to report the finding directly to Company via the channels specified in the Company’s published Security Policy. Customer shall use commercially reasonable efforts to follow "Coordinated Vulnerability Disclosure" practices, providing Company with a period of at least ninety (90) days to address and patch the vulnerability before making any public disclosure.

2.2 Export Control. Technical data, Software, and the Platform provided by Company are subject to U.S. export control laws, including the U.S. Export Administration Regulations and all applicable U.S. sanctions. Customer agrees (i) not to export or re-export any technical data, software, or access to the Platform provided by Company in violation of such laws; and (ii) not to export or re-export the foregoing to any country, region, or individual restricted by U.S. law.

2.3 Customer Compliance and Indemnification. Customer represents, covenants, and warrants that Customer will use the Services only in compliance with Company’s standard published policies then in effect (the "Policy") and all applicable laws and regulations. Customer hereby agrees to indemnify and hold harmless the Company against any damages, losses, liabilities, settlements and expenses (including without limitation costs and reasonable attorneys’ fees) in connection with any third party claim or action that arises from an alleged violation of the foregoing or otherwise from Customer’s use of the Services in violation of the terms of this Agreement or from its willful misconduct. Although Company has no obligation to monitor Customer’s use of the Services, Company may do so and may prohibit any use of the Services it believes may be (or alleged to be) in violation of the foregoing.

2.4 Customer Equipment. Customer shall be responsible for obtaining and maintaining any equipment and ancillary services needed to connect to, access or otherwise use the Services, including, without limitation, modems, hardware, servers, software, operating systems, networking, web servers and the like (collectively, "Equipment"). Customer shall also be responsible for maintaining the security of the Equipment, Customer account, passwords (including but not limited to administrative and user passwords) and files, and for all uses of Customer account or the Equipment with or without Customer’s knowledge or consent.

2.5 Self-Hosted Infrastructure Responsibility. For Self-Hosted Services, Customer is solely responsible for:

  • Infrastructure provisioning and configuration;
  • Cloud provider selection and costs;
  • Network configuration and security controls;
  • Identity and access management;
  • Backup, redundancy, and disaster recovery;
  • Compliance with applicable laws and regulations.

Company shall not be liable for:

  • Downtime, outages, or degradation caused by Customer infrastructure;
  • Third-party services or integrations;
  • Cloud cost overruns;
  • Security vulnerabilities introduced by Customer configuration or third-party components.

Support for Self-Hosted Services is limited to the unmodified Software and does not extend to Customer’s underlying infrastructure, workloads, or third-party components.

2.6 Enterprise Image Factory Access.

2.6.1 Grant of Access. Subject to Customer’s active TEL subscription, Company grants Customer a limited, non-exclusive, non-transferable, non-sublicensable license during the Term to access Company’s Enterprise Image Factory, consisting of (a) Company’s compiled, signed installation and update images and other build artifacts for Supported Products ("Build Artifacts"), and (b) Company’s repository of machine-readable Software Bills of Materials ("SBOM") and Vulnerability Exploitability eXchange ("VEX") statements, in each case specific to each released image of the Supported Products (collectively, the "Enterprise Image Factory"). "Supported Products" has the meaning given in the Security Patch Availability Policy attached as Exhibit D and excludes components or features designated "Alpha," "Beta," "Experimental," or "Tech Preview." Company makes no commitment as to which specific releases, images, or Supported Products are covered, or as to publication cadence, except as set forth in Exhibit D.

For the avoidance of doubt, nothing in this Section restricts Customer’s rights under the Mozilla Public License 2.0 to build, use, modify, or distribute Talos Linux from its published open-source code independently of the Enterprise Image Factory; the license granted in this Section applies solely to Company’s pre-built, commercially distributed Build Artifacts, SBOMs, and VEX statements, which are made available only under this Agreement and not under the MPL. The Build Artifacts, SBOMs, and VEX statements made available through the Enterprise Image Factory constitute Proprietary Information of Company under Section 3.1.

2.6.2 Permitted Use. Customer may use the Enterprise Image Factory solely for the following internal purposes in connection with its Supported Product deployments: (a) deployment and operation of Supported Products using Company’s pre-built images in lieu of Customer-built images; (b) security analysis; (c) compliance and audit evidence; (d) configuration of vulnerability scanning tools; and (e) evidencing remediation status under Exhibit D, and as expressly permitted in Section 2.6.3.

2.6.3 Restrictions and Permitted Disclosures. Customer shall not: (a) redistribute, publish, sell, license, or sublicense the Build Artifacts, SBOMs, or VEX statements, in bulk or in machine-readable form, to any third party, except as expressly permitted below; (b) repackage, resell, or commercialize the Enterprise Image Factory or its contents as a standalone product or service distinct from Customer’s own use of Supported Products; (c) circumvent or attempt to circumvent any authentication, access control, or rate-limiting mechanism applied to the Enterprise Image Factory; or (d) use the Enterprise Image Factory to generate, distribute, or otherwise provide to any third party any SBOM, VEX statement, vulnerability assessment, build artifact, or similar artifact concerning any deployment of Talos Linux, Omni, or other Company-developed software that is not a Supported Product under Customer’s active TEL subscription.

Notwithstanding clause (a), Customer may: (i) disclose Enterprise Image Factory contents to Customer’s auditors, assessors, or regulators under reasonable confidentiality obligations and solely to the extent necessary to evidence Customer’s compliance or security posture; (ii) disclose such contents as required by applicable law, regulation, or court order; (iii) provide Customer’s own customers, in summary or aggregated (non-machine-readable) form, with information regarding the vulnerability status and provenance of Supported Products that Customer operates for them under and within the scope of Customer’s active TEL subscription; and (iv) deploy the Build Artifacts, in their compiled and unmodified form, within Customer’s own production environment and to Customer’s Affiliates for Customer’s internal business operations, consistent with the license granted in Section 1.3(d).

2.6.4 Operational Continuity and Discontinuation. Company reserves the right to modify the data schema, transmission protocols, or access mechanisms of the Enterprise Image Factory, provided such modifications do not materially degrade Customer’s ability to consume the data using industry-standard tools. Upon the expiration or termination of this Agreement, or upon the expiration or termination of Customer’s TEL subscription (whichever occurs first): (a) Customer’s right to access the Enterprise Image Factory shall cease; and (b) Company may deactivate the corresponding authentication credentials. Notwithstanding the foregoing, Customer may retain copies of Enterprise Image Factory contents obtained during the Term solely for legal, regulatory, or audit purposes, subject to Customer’s continued confidentiality obligations under Section 3.

CONFIDENTIALITY; PROPRIETARY RIGHTS

3.1 Confidential Information. Each party (the "Receiving Party") understands that the other party (the "Disclosing Party") has disclosed or may disclose business, technical, or financial information relating to the Disclosing Party's business (hereinafter referred to as "Confidential Information").

(a) Definitions. Confidential Information of Company includes non-public information regarding features, functionality, and performance of the Service, as well as pricing and roadmap data. Confidential Information of Customer includes Customer Data, as well as any diagnostic logs, system configurations, or support materials provided by Customer to Company.

(b) Obligations. The Receiving Party agrees: (i) to take reasonable precautions to protect such Confidential Information; and (ii) not to use (except in performance of the Services or as otherwise expressly permitted in this Agreement) or divulge to any third person any such Confidential Information.

(c) Compelled Disclosure. If the Receiving Party is required by law or court order to disclose Confidential Information, it shall (to the extent legally permitted) provide the Disclosing Party with prompt written notice so that the Disclosing Party may seek a protective order or other appropriate remedy.

(d) Exclusions. The foregoing shall not apply to information that the Receiving Party can document: (i) is or becomes generally available to the public through no breach hereof by the Receiving Party; (ii) was lawfully in its possession or known by it prior to receipt from the Disclosing Party; (iii) was lawfully disclosed to the Receiving Party without restriction by a third party; or (iv) was independently developed without use of any Confidential Information of the Disclosing Party.

(e) Return of Materials. Upon termination of this Agreement, or upon the Disclosing Party's written request, the Receiving Party shall promptly return or destroy all Confidential Information in its possession (excluding Customer Data, which is governed by Section 3.4.2 and the DPA) and certify such destruction in writing if requested; provided that the Receiving Party may retain Confidential Information to the extent required by applicable law or regulation, or as part of automated backup systems that are overwritten in the ordinary course of business, subject to the ongoing confidentiality obligations of this Section.

(f) Survival. These obligations survive expiration or termination of this Agreement for five (5) years; provided that obligations with respect to trade secrets (including software algorithms and Company Technology) shall survive for as long as such information remains a trade secret under applicable law, without regard to any breach by the Receiving Party.

3.2 Company Intellectual Property. (a) Ownership. Company owns and shall retain all right, title, and interest (including all intellectual property rights) in and to: (i) the Services, Platform, and Software; (ii) any documentation, training materials, consulting methods, and "Company Tools"; (iii) any and all improvements, enhancements, or modifications to the foregoing; and (iv) any software, applications, inventions, or other technology developed by Company in connection with support or implementation services (collectively, the "Company Technology").

(b) Company Tools. "Company Tools" means any proprietary frameworks, code, or methodologies which Company uses to provide the Services or create Deliverables, including all Derivative Works thereof, regardless of whether such tools were developed using Customer funding or in the course of performing this Agreement.

(c) Deliverables. Unless otherwise agreed in a signed Statement of Work, all Deliverables provided to Customer are owned by Company. Company grants Customer a non-exclusive, non-transferable, and non-sublicensable license to use such Deliverables solely in connection with its authorized use of the Services during the Term.

(d) Feedback. Customer may, from time to time, provide suggestions, enhancement requests, or other feedback to Company regarding the Company Technology ("Feedback"). Customer hereby grants to Company a royalty-free, worldwide, transferable, sublicensable, irrevocable, and perpetual license to use or incorporate any Feedback into the Company Technology or Services without restriction or obligation to Customer.

(e) Open Source Exclusion. For the avoidance of doubt, "Company Technology" does not include the open-source software distributions (such as Talos Linux or Kubernetes) supported under this Agreement, which are governed exclusively by their respective open-source licenses.

3.3 Customer Data Ownership. Customer shall own all right, title and interest in and to the Customer Data and any Intellectual Property Customer created prior to or separate from this Agreement.

3.4 Data Processing and Compliance.

3.4.1 Roles. The parties acknowledge that with regard to the processing of Personal Data, Customer is the Data Controller and Company is the Data Processor acting on Customer’s instructions. Both parties shall comply with all applicable privacy and data protection laws (e.g., GDPR, CCPA).

3.4.2 Data Processing Addendum. To the extent Company processes Personal Data on Customer’s behalf, the parties agree to comply with the Sidero Labs Data Processing Addendum (DPA), which is hereby incorporated by reference and found at https://www.siderolabs.com/data-processing-addendum/. The DPA shall include appropriate safeguards for cross-border transfers, such as Standard Contractual Clauses (SCCs).

3.4.3 Usage Data. Notwithstanding the foregoing and except with respect to Self-Hosted Services, Company shall have the right to collect and analyze data relating to the performance of the Services. Company may (i) use such information to improve the Services; and (ii) disclose such data solely in anonymized, aggregated form that is not traceable to any party and contains no Personal Data.

3.4.4 Privacy Policy. Customer acknowledges that Company's collection, use, and disclosure of personal information related to Customer's use of the Services — such as administrative account information and usage telemetry — is governed by the Company's Privacy Policy, available at https://www.siderolabs.com/privacy-policy/, as updated from time to time.

3.5 Marketing. Subject to Customer’s prior written consent, Company may identify Customer as a recipient of services and use its name and logo in sales presentations, marketing materials, and press releases.

PAYMENT OF FEES

4.1 Fees. Customer will pay Company the then-applicable fees described in each applicable Order Form for the Services and any Support agreement or Professional Services (the "Fees"). If Customer's use of the Services exceeds the Service Capacity set forth on the applicable Order Form or otherwise requires the payment of additional fees per the terms of this Agreement, Customer shall be billed for such usage and agrees to pay the additional fees in the manner provided herein. Company reserves the right to change the Fees or applicable charges and to institute new charges and Fees at the end of the Initial Service Term or then-current renewal term, upon sixty (60) days' prior written notice to Customer (which may be sent by email), consistent with the non-renewal notice period in Section 5.1, so that Customer has a full opportunity to elect non-renewal before any Fee increase takes effect for a renewal term. Company reserves the right to suspend Customer's access to the Services and the provision of Support Services if any undisputed Fees are more than thirty (30) days past due. Such suspension shall not constitute a termination of this Agreement nor relieve Customer of its obligation to pay all Fees due hereunder.

4.2 Payment Terms. Full payment for invoices must be received by Company thirty (30) days after the mailing date of the invoice. Unpaid amounts may be subject to a finance charge of 1% per month on any outstanding balance, plus all reasonable expenses of collection. Customer shall be responsible for all taxes associated with Services other than U.S. taxes based on Company's net income.

Billing Disputes. If Customer believes in good faith that Company has billed Customer incorrectly, Customer must contact Company no later than 60 days after the closing date on the first billing statement in which the error or problem appeared, in order to receive an adjustment, refund, or credit. Inquiries should be directed to Company's customer support department.

Good Faith Exceptions. Customer shall pay all undisputed amounts by the original due date. No finance charges shall accrue on amounts subject to a good-faith dispute while the parties work to resolve the inquiry.

4.3 Self-Service Customers. Notwithstanding Sections 4.1 and 4.2, for Customers who subscribe through Sidero Labs' online self-service portal ("Self-Service Customers"), the following terms apply:

(a) Fees are charged automatically to Customer's payment method on file at the start of each billing period (monthly or annual, as selected at signup); payment is due immediately upon charge and the 30-day invoice terms in Section 4.2 do not apply.

(b) Upon Customer's addition of a payment method, Customer authorizes Sidero Labs to charge that payment method on a recurring basis for all applicable Fees until Customer cancels.

(c) Sidero Labs will provide at least thirty (30) days' prior written notice by email to Customer's account address before any Fee increase takes effect.

(d) If any charge is declined, disputed, or reversed and remains unresolved for 10 business days following the initial failed charge, Sidero Labs may suspend or terminate Customer's access to the Services.

(e) Customer may cancel at any time through Customer's account settings or by emailing support@siderolabs.com; cancellation takes effect at the end of the then-current Term and no refund is issued for the unused remainder of that Term.

(f) Consistent with California Business and Professions Code §17600 et seq., the automatic renewal terms described in this Section are disclosed to Customer at the time of signup, and Customer's acceptance at signup constitutes affirmative consent to recurring charges on the terms described herein.

(g) For Self-Service Customers who subsequently request invoiced billing, Sidero Labs' written confirmation of such request — including by email or by issuance of an invoice — together with the plan and pricing reflected in Customer's account at the time of the request, shall constitute the applicable Order Form for purposes of this Agreement.

4.4 Subscription Confirmation as Order Form. Upon Customer's addition of a payment method to its account profile, Sidero Labs or its payment processor will provide Customer with a subscription confirmation specifying the selected Service plan, applicable Fees, and billing cycle (the "Subscription Confirmation"). For Self-Service Customers, the Subscription Confirmation constitutes the applicable Order Form for purposes of this Agreement, including for purposes of Section 9.11 (Order of Precedence). Customer is responsible for maintaining a valid email address on Customer's account to receive Subscription Confirmations and fee-change notices.

4.5 Reseller Purchases. If Customer has purchased Talos Enterprise Linux (including its bundled SaaS, Self-Hosted, Support, Enterprise Image Factory, and CVE remediation components) through an authorized third-party reseller ("Reseller") rather than directly from Company, the following terms shall apply:

(a) Order Form Definition: For the purposes of this Agreement, the "Order Form" shall be defined as the purchase order, statement of work, or other ordering document entered into between Customer and the Reseller. The scope of Services, Service Capacity (such as node counts), and the Initial Service Term shall be as set forth in such Reseller documentation.

(b) Payment to Reseller: Notwithstanding Sections 4.1 and 4.2, Customer shall pay all applicable Fees directly to the Reseller in accordance with the terms agreed upon between Customer and Reseller. Company shall have no obligations or liability regarding billing errors, payment disputes, or refund requests arising from the relationship between Customer and Reseller. Any Service Credits due to Customer under Exhibit A for Reseller Purchases shall be issued to the Reseller for the benefit of the Customer, and the Reseller shall be solely responsible for applying such credits to Customer's account.

(c) Suspension for Non-Payment: Company reserves the right to suspend Customer's access to the Services or Support Services if Company does not receive the applicable payments for Customer's account from the Reseller. Company will use commercially reasonable efforts to provide Customer with at least ten (10) business days' prior written notice of such impending suspension. Such suspension shall not constitute a breach of this Agreement by Company.

(d) Direct Agreement: Customer's acceptance of this Agreement via the click-to-accept process required at first login to the Services — regardless of whether Customer purchased through a Reseller — constitutes Customer's direct agreement to be bound by this Agreement, entered into by the individual accepting on Customer's behalf, who represents that they have authority to bind Customer. This Agreement governs Customer's use of the Services and, consistent with Section 13.3 of the Omni End User License Agreement (siderolabs.com/eula), controls over that End User License Agreement to the extent of any conflict. No terms in the agreement between Customer and Reseller shall modify or supersede the protections, limitations of liability, or acceptable use policies set forth herein.

TERM AND TERMINATION

5.1 Term and Renewal. Subject to earlier termination as provided below, this Agreement is for the Initial Service Term, commencing on and continuing for the duration specified in the applicable Order Form. Thereafter, this Agreement shall automatically renew for successive renewal periods of the same duration as the Initial Service Term (unless a different renewal period is specified in the Order Form) (the Initial Service Term together with all renewal periods, the "Term"), unless either party gives the other written notice of non-renewal at least sixty (60) days prior to the end of the then-current Term.

5.2 Termination. In addition to any other remedies it may have, either party may also terminate this Agreement: (i) upon written notice to the breaching party specifying the nature of such breach in reasonable detail, if such material breach (A) is capable of cure and remains uncured for thirty (30) days after the breaching party's receipt of such written notice, or (B) is not capable of cure; (ii) if the other party becomes insolvent or admits in writing its inability to pay its debts as they mature or makes an assignment for the benefit of creditors; or (iii) if a petition under the United States Bankruptcy Act, as it now exists or as it may be amended, or any similar law of any other jurisdiction, is filed concerning the other party.

5.3 Payment on Termination. Customer will pay in full for the Services up to and including the last day on which the Services are provided. If Company terminates the Agreement without cause, Customer will be refunded for any pre-paid services which are not provided.

5.4 Survival. All sections of this Agreement which by their nature should survive termination will survive termination, including, without limitation, responsibilities and restrictions, accrued rights to payment, confidentiality obligations, intellectual property rights, warranty disclaimers, and limitations of liability. For clarity, the license granted under Section 2.6 (Enterprise Image Factory Access) terminates as provided in Section 2.6.4 and does not survive termination or expiration of Customer's TEL subscription.

WARRANTY AND DISCLAIMER

6.1 Performance Standard. Company shall use reasonable efforts consistent with prevailing industry standards to maintain the Services in a manner which minimizes errors and interruptions in the Services and shall perform the SaaS Services, Support Services and Professional Services in a professional and workmanlike manner. Services may be temporarily unavailable for scheduled maintenance or for unscheduled emergency maintenance, either by Company or by third-party providers, or because of other causes beyond Company's reasonable control, but Company shall use reasonable efforts to provide advance notice in writing or by e-mail of any scheduled service disruption.

6.2 Open Source & Upstream Security. Open-source software distributions (including Talos Linux and Kubernetes) are provided "AS IS" pursuant to their respective open-source licenses. While Company will use commercially reasonable efforts to provide security updates and backports as defined in Exhibit B, Customer acknowledges that such fixes are subject to upstream project support (e.g., Linux kernel, runc, and Kubernetes); Company does not warrant that the software will be uninterrupted or error-free, or that all vulnerabilities can or will be patched, particularly where a fix is unavailable from the relevant upstream project. The patching timeframes set forth in Exhibit D (Security Patch Availability Policy) are operational targets and are not warranties or service level commitments; Section 6.3's disclaimers and Section 8's limitations of liability apply in full to any claim relating to the timing or availability of a security patch.

6.3 Disclaimers. HOWEVER, COMPANY DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED OR ERROR FREE; NOR DOES IT MAKE ANY WARRANTY AS TO THE RESULTS THAT MAY BE OBTAINED FROM USE OF THE SERVICES OR REGARDING THE SECURITY, ACCURACY, RELIABILITY, TIMELINESS OR PERFORMANCE OF THE SERVICES OR THAT SERVICES WILL MEET CUSTOMER'S REQUIREMENTS. EXCEPT AS EXPRESSLY SET FORTH IN SECTION 6.1, THE SERVICES AND PROFESSIONAL SERVICES ARE PROVIDED "AS IS" AND COMPANY DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN THE CASE OF A BREACH OF WARRANTY BY COMPANY, CUSTOMER'S SOLE AND EXCLUSIVE REMEDY SHALL BE FOR COMPANY AT ITS OPTION TO REPERFORM THE SERVICES OR ISSUE A PRO-RATA REFUND FOR THE NON-CONFIRMING SERVICE.

6.4 Security Program and Limitations. Company maintains a security program that includes administrative, technical, and organizational safeguards designed to protect the security, confidentiality, and integrity of the Services and Customer Data, assessed pursuant to a SOC 2 Type II audit. Company shall use commercially reasonable efforts to detect, respond to, and mitigate any confirmed Security Incident in accordance with its documented incident response procedures.

6.5 Security Limitations. Notwithstanding the foregoing, Customer acknowledges that no system can be guaranteed to be completely secure, and COMPANY DOES NOT WARRANT THAT THE SERVICES OR ANY DATA TRANSMITTED OR STORED IN CONNECTION THEREWITH WILL BE IMMUNE FROM UNAUTHORIZED ACCESS, SECURITY BREACHES, OR OTHER SECURITY INCIDENTS. COMPANY HEREBY DISCLAIMS ANY WARRANTY OF ABSOLUTE SECURITY OR UNINTERRUPTED PROTECTION AGAINST CYBER THREATS. Except for Company's gross negligence or willful misconduct, any liability arising from a Security Incident shall be subject to the limitations set forth in Section 8.

(a) Breach Notification. In the event of a confirmed Security Incident involving unauthorized access to or unauthorized disclosure of Customer Data, Company shall notify Customer without undue delay, and in any event within seventy-two (72) hours of Company's confirmation of such incident. Company shall provide reasonable cooperation to Customer in its investigation and remediation of any such incident. For purposes of this Section, "confirmation" means the point at which Company has sufficient information to reasonably conclude that a Security Incident affecting Customer Data has occurred.

(b) Audit Transparency. Upon Customer's written request (not more than once per calendar year) and subject to the confidentiality obligations set forth in Section 3 of this Agreement, Company shall provide Customer with a summary of its most recent SOC 2 Type II report or equivalent security assessment. Company makes no representation that such report demonstrates compliance with any specific regulatory regime applicable to Customer.

(c) Limitations and Exclusions. Company shall not be responsible for Security Incidents arising from: (i) Customer's infrastructure, Self-Hosted deployment, or configuration of the Services; (ii) compromised or misappropriated Customer credentials; (iii) third-party integrations or services not provided by Company; or (iv) vulnerabilities in open-source components where no fix has been made available to Company by the relevant upstream project. The foregoing exclusions shall apply regardless of whether Company had notice of the relevant condition.

6.6 Regulatory Compliance Disclaimer. Except as expressly stated in this Agreement, Company does not represent or warrant that the Services comply with, or will enable Customer to comply with, any specific law, regulation, or industry standard, including but not limited to HIPAA, FedRAMP, ITAR, PCI-DSS, SOC reporting requirements, or similar regulatory regimes. Customer is solely responsible for ensuring its use of the Services meets its specific legal and regulatory obligations. Any reference to compliance, certifications, or security standards in marketing materials, security documentation, or discussions shall not be deemed a warranty or guarantee of regulatory compliance.

INDEMNITY

7.1 Company Indemnity. Company shall indemnify, defend and hold Customer harmless from liability to third parties based upon claims by such parties ("Claims") resulting from infringement by the Service — including Talos Linux and the Build Artifacts, SBOMs, and VEX statements made available through the Enterprise Image Factory under Section 2.6 — of any copyright or misappropriation of any trade secret owned by such third party, provided Company is promptly notified of any and all threats, claims and proceedings related thereto and given reasonable assistance and the opportunity to assume sole control over defense and settlement. Company will not be responsible for any settlement it does not approve in writing.

7.2 Exclusions from Indemnity. The foregoing obligations do not apply with respect to portions or components of the Service:

(i) not supplied by Company;

(ii) made in whole or in part in accordance with Customer specifications where the alleged infringement is caused by adherence to such specifications;

(iii) that are modified after delivery by Company and the alleged infringement is caused by the Customer modification;

(iv) combined with other products, processes or materials where the alleged infringement relates to such combination;

(v) where Customer continues allegedly infringing activity after being notified in writing thereof or after being informed of modifications that would have avoided the alleged infringement;

(vi) that are underlying third-party open-source software incorporated into the Service and not developed by Company (e.g., Kubernetes and other upstream dependencies); for the avoidance of doubt, this exclusion does not apply to Talos Linux, which Company develops and maintains and for which Company's indemnity obligation under Section 7.1 applies on the same basis as the Service;

(vii) where Customer's use of the Service is not strictly in accordance with this Agreement and such use causes the alleged infringement; or

(viii) resulting from the interaction of the Service with Customer's Self-Hosted infrastructure, network configuration, or third-party cloud provider environments.

7.3 Remedy for Infringement. If, due to a claim of infringement, the Services are held by a court of competent jurisdiction to be or are believed by Company to be infringing, Company may, at its option and expense: (a) replace or modify the Service to be non-infringing provided that such modification or replacement contains substantially similar features and functionality; (b) obtain for Customer a license to continue using the Service; or (c) if neither of the foregoing is commercially practicable, terminate this Agreement and Customer's rights hereunder and provide Customer a refund of any prepaid, unused fees for the Service.

7.4 Sole Remedy. THE FOREGOING CONSTITUTES COMPANY'S ENTIRE LIABILITY, AND CUSTOMER'S SOLE AND EXCLUSIVE REMEDY WITH RESPECT TO THIRD PARTY CLAIMS OF INFRINGEMENT OF ANY KIND OR NATURE.

LIMITATION OF LIABILITY

8.1 Liability Cap. NOTWITHSTANDING ANYTHING TO THE CONTRARY, EXCEPT FOR BODILY INJURY OF A PERSON, IN NO EVENT WILL EITHER PARTY OR ITS SUPPLIERS' (INCLUDING BUT NOT LIMITED TO ALL EQUIPMENT AND TECHNOLOGY SUPPLIERS), OFFICERS', AFFILIATES', REPRESENTATIVES', CONTRACTORS' AND EMPLOYEES' AGGREGATE, CUMULATIVE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS AND ALL SOWS AND ORDER FORMS EXCEED THE AMOUNTS RECEIVED BY COMPANY FROM CUSTOMER DURING TWELVE (12) MONTHS PRECEDING THE FIRST EVENT GIVING RISE TO LIABILITY.

8.2 Confidentiality Super Cap. NOTWITHSTANDING THE FOREGOING, EACH PARTY'S AGGREGATE LIABILITY FOR BREACH OF ITS CONFIDENTIALITY OBLIGATIONS UNDER SECTION 3.1 SHALL NOT EXCEED THREE (3) TIMES THE TOTAL FEES PAID OR PAYABLE BY CUSTOMER DURING THE TWELVE (12) MONTHS PRECEDING THE FIRST EVENT GIVING RISE TO SUCH CLAIM. THIS LIMITATION IS CUMULATIVE FOR ALL CLAIMS ARISING UNDER ALL SOWS AND ORDERING DOCUMENTS, AND SHALL APPLY EVEN IF THE REMEDIES PROVIDED IN THIS AGREEMENT SHALL FAIL OF THEIR ESSENTIAL PURPOSE.

8.3 Exclusion of Damages. NEITHER PARTY SHALL BE RESPONSIBLE OR LIABLE WITH RESPECT TO ANY SUBJECT MATTER OF THIS AGREEMENT OR TERMS AND CONDITIONS RELATED THERETO UNDER ANY CONTRACT, NEGLIGENCE, STRICT LIABILITY OR OTHER THEORY: (A) INTERRUPTION OF USE OR FOR LOSS OR CORRUPTION OF DATA INCLUDING NONPAYMENT ONLY FOR THE AFFECTED TIME PERIOD AS A RESULT OF THE FOREGOING, OR COST OF PROCUREMENT OF SUBSTITUTE GOODS, SERVICES OR TECHNOLOGY OR LOSS OF BUSINESS; (B) FOR ANY INDIRECT, EXEMPLARY, INCIDENTAL, SPECIAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF OR IN ANY WAY RELATING TO THESE TERMS, THE SERVICES PROVIDED, OR THE USE OF OR INABILITY TO USE THE SERVICES; OR (C) FOR ANY MATTER BEYOND THE AFFECTED PARTY'S REASONABLE CONTROL; WHETHER OR NOT THE OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

8.4 Open Source and Self-Hosted Software. Customer acknowledges that the Services utilize open-source projects (e.g., Talos Linux) and that Self-Hosted Services involve deploying Company code on Customer's own infrastructure. While Company will use commercially reasonable efforts to address bugs or vulnerabilities in the software, Company shall not be liable for any damages, system failures, or security breaches resulting from the use of Talos Linux or the Self-Hosted Services, except to the extent such damages are a direct result of Company's gross negligence or willful misconduct in the performance of its obligations. For the avoidance of doubt, the limitations in Section 8.1 apply to all claims related to the software, the Self-Hosted Services, the Enterprise Image Factory, and the Support Services.

9. MISCELLANEOUS

9.1 Severability and Waiver: If any provision of this Agreement is found to be unenforceable or invalid, that provision will be limited or eliminated to the minimum extent necessary so that this Agreement will otherwise remain in full force and effect and enforceable. The failure of either party to enforce any right or provision of this Agreement shall not be deemed a waiver of such right or provision.

9.2 Assignment: Except in connection with a merger or sale of substantially all of its assets (a "Change in Control") or Company's assignment to an affiliate, this Agreement is not assignable or transferable by either Party except with the other Party's prior written consent; provided that the assigning party shall provide the other party with written notice within thirty (30) days of any such assignment, and provided further that assignment to a direct competitor of the other party shall require prior written consent notwithstanding the foregoing exception.

9.3 Entire Agreement and Modification: This Agreement, together with the applicable Order Forms and any Exhibits and SOWs entered by the parties, constitutes the complete and exclusive statement of the mutual understanding of the parties. It supersedes and cancels all previous written and oral agreements, communications, and other understandings relating to the subject matter of this Agreement. All waivers and modifications must be in a writing signed by both parties.

9.4 Relationship of the Parties: No agency, partnership, joint venture, or employment is created as a result of this Agreement. Customer does not have any authority of any kind to bind Company in any respect whatsoever.

9.5 Notices: All notices under this Agreement will be in writing and will be deemed to have been duly given when received, if personally delivered; the day after it is sent, if sent by e-mail to the addresses provided in the Order Form; the day after it is sent, if sent for next-day delivery by a recognized overnight delivery service; or upon receipt, if sent by certified or registered mail.

9.6 Force Majeure: Neither party shall be liable by reason of failure or delay in the performance of its obligations hereunder on account of strikes, shortages, riots, insurrection, war, acts of terrorism, public health emergencies, pandemic, epidemic, fires, flood, storm, explosions, earthquakes, outages or failures of third-party cloud service providers, Internet delays or outages, acts of God, governmental action, labor conditions, or any other cause which is beyond the reasonable control of the party.

9.7 Governing Law and Jurisdiction: This Agreement shall be governed by the laws of the State of California without regard to its conflict of laws provisions. Except for actions seeking injunctive relief, the parties agree to the exclusive jurisdiction of the federal and state courts in Santa Barbara County, California. In any action or proceeding to collect fees or other amounts due and payable under this Agreement, the prevailing party shall be entitled to recover its reasonable costs and attorneys' fees.

9.8 Dispute Resolution: Excluding actions seeking injunctive relief, if any disputes arise between the parties, before taking formal action, the parties will use reasonable efforts to resolve the dispute through their good-faith discussions within thirty (30) days from the date that one party notifies the other of such dispute in reasonable detail.

9.9 Capacity Audit: Not more than once per twelve (12) month period, Company may verify Customer's node count to ensure compliance with the Support and Platform Capacity defined in the Order Form. Customer agrees to provide a certified report or allow the execution of a discovery script solely for the purpose of verifying the number of active nodes receiving Services.

9.10 Non-Solicitation: During the Term of this Agreement and for a period of twelve (12) months thereafter, neither party shall, directly or indirectly, solicit for employment or hire any employee or contractor of the other party who was involved in the performance or receipt of the Services, without the prior written consent of the other party. This provision shall not restrict either party from hiring individuals who respond to general, public advertisements for employment.

9.11 Order of Precedence: In the event of any conflict or inconsistency between the documents comprising this Agreement, the following order of precedence shall apply: (i) the Order Form (but only as to the specific Services, Fees, Term, Renewal, and Capacity being purchased); (ii) the Acceptable Use Policy (Exhibit C) (as to all matters regarding prohibited use and platform security); (iii) the Security Patch Availability Policy (Exhibit D) (as to matters of security patch availability and CVE remediation targets specifically); (iv) the Terms and Conditions of this MSA; and (v) any other Exhibits or SOWs. No terms in a Customer purchase order or similar document shall have any force or effect.

If Customer's organization has accepted Sidero Labs' Terms of Service or Omni MSA at account creation, or has a separately negotiated Master Services Agreement executed with Sidero Labs (including one executed through a Sidero Labs-authorized reseller acting on Sidero Labs' behalf) (any of the foregoing, an "Existing Agreement"), such Existing Agreement supplements this Agreement and, to the extent of any conflict, controls as to the Omni SaaS or Self-Hosted Services it addresses. Because Support Services, the Enterprise Image Factory license described in Section 2.6, and the CVE remediation targets in Exhibit D are components of Talos Enterprise Linux not addressed by any Existing Agreement, this Agreement exclusively governs those components regardless of the terms of any Existing Agreement. Acceptance of this Agreement does not modify, supersede, or replace any Existing Agreement except as expressly provided in this Section 9.11.

9.12 Insurance. During the Term, Company shall maintain at its own expense: (i) Commercial General Liability insurance with limits of not less than $1,000,000 per occurrence and $2,000,000 in the aggregate; and (ii) Technology Errors & Omissions/Cyber Liability insurance with limits of not less than $2,000,000 in the aggregate. Upon Customer's written request, Company shall provide a certificate of insurance evidencing the foregoing coverage.

EXHIBIT A

Service Level Terms

The Company will use commercially reasonable efforts to ensure that the Services shall be available 99% of the time, measured monthly, excluding scheduled maintenance ("Services Availability"). Any uptime or downtime calculation will exclude periods affected by such maintenance. Further, any downtime resulting from outages of third-party connections or utilities or other reasons beyond Company's control will also be excluded from any such calculation. Excluding scheduled maintenance periods, the Service will be deemed "available" so long as Customer's authorized users are able to login to their assigned Customer portal interface. "Services Availability" as used herein relates to the core Service's availability as served from Company-hosted environments for Customer portal access. This SLA does not apply to Self-Hosted Service(s). For Self-Hosted Services, Company's sole obligation is to provide Support Services for the code in accordance with Exhibit B, but no uptime availability credit shall apply.

Customer's sole and exclusive remedy, and Company's entire liability, in connection with Service availability shall be that for each period of downtime lasting longer than four (4) hours during one (1) calendar month, Company will credit Customer 2% of Service fees for that month; provided that no more than one such credit will accrue per day. Downtime shall begin to accrue as soon as Customer (with notice to Company) recognizes that downtime is taking place, and continues until the availability of the Services is restored. In order to receive downtime credit, Customer must notify Company in writing within five (5) business days from the time of downtime, and failure to provide such notice will forfeit the right to receive downtime credit. Such credits may not be redeemed for cash and shall not be cumulative beyond a total of credits for one (1) week of Service Fees in any one (1) calendar month in any event. Company will only apply a credit to the month in which the incident occurred. Company's blocking of data communications or other Service in accordance with its security processes and published policies shall not be deemed to be a failure of Company to provide adequate service levels under this Agreement.

EXHIBIT B

Support Services Terms

1. Support Subscription. Enterprise Support Services are included as a standard component of Customer's active Talos Enterprise Linux ("TEL") subscription, as described in the Order Form. Company will provide such support in accordance with these terms. All capitalized terms not defined herein have the meaning in the Master Services Agreement ("MSA").

2. Scope of Coverage

Support coverage includes Customer issues related to the following components:

  • Sidero Omni SaaS: Support for the Omni SaaS service or Self-Hosted Omni.
  • Talos Linux: Troubleshooting, configuration guidance, and bug fixes for the Talos Linux Operating System.
  • Management Tools: Assistance with Sidero CLI and automation tools.
  • Kubernetes Control Plane: Support for the Kubernetes lifecycle and control plane.

Support for Self-Hosted Services is limited to the Software itself and does not include troubleshooting of Customer's underlying infrastructure, network latency, or hardware failures.

3. Support Lifecycle and Upstream Dependency

  • Kubernetes: Support is provided for the most current 5 stable releases of Kubernetes.
  • Talos Linux: Full support and security updates are provided for the two latest minor releases.
  • Security & CVE Policy: Sidero Labs's security patch and CVE response obligations, including coverage of current and prior (N-1) releases of Supported Products, are set forth in the Security Patch Availability Policy (Exhibit D).
  • Upstream Disclaimer: Customer acknowledges that fixes are subject to upstream project availability; Company does not warrant that all vulnerabilities can be patched if a fix is unavailable from the relevant upstream project.

4. Professional Services and Support Exclusions. Sidero offers Professional Services ("PS") for projects falling outside the scope of standard Support. Unless explicitly included in an Order Form or a separate Statement of Work (SOW), Support Services do not include:

  • Feature Development: Implementation of new features or hardware device support.
  • Design & Third-Party Tools: Troubleshooting third-party components, architectural design/discussion, or implementation of management components.
  • Workload Debugging: Workload-specific debugging (e.g., writing Kubernetes Jobs or Deployments).
  • Modified Software: Support for any software that has been modified or altered by the Customer or a third party.
  • Other Professional Services.

5. Support Turn-Around. Company will provide services and response to issues and requests within the scope of Support Services for Talos Enterprise Linux and Talos Linux according to the response-time matrix below, using all commercially reasonable efforts to respond within the applicable timeframes according to the various priority levels as defined. Support is available 24 x 7 x 365.

6. Sidero Labs reserves the right to re-classify the Priority Level of any support request at its reasonable discretion based on the technical impact described by the Customer and the definitions provided in the Priority Definitions table below.

PriorityInitial Response TimeOngoing Update Response Time (not counting issues pending a response from Customer)
Priority 0 — Urgent1 hour2 hours
Priority 1 — High2 hours4 hours
Priority 2 — Medium4 business hours8 business hours
Priority 3 — Low1 business day2 business days

Business hours: Monday to Friday, 8:00am to 5:00pm Eastern US time, excluding US Federal Holidays. Support is available 24 x 7 x 365 for Priority 0 and Priority 1 issues.

PriorityPriority Definitions
Priority 0 — UrgentA problem that severely impacts your use of the software (such as loss of data or in which your systems are not functioning). The situation halts your business operations and no procedural workaround exists.
Priority 1 — HighA problem where the software is functioning but your use is severely reduced. The situation is causing a high impact to portions of your business operations and no procedural workaround exists.
Priority 2 — MediumA problem that involves partial, non-critical loss of use of the software. There is a medium-to-low impact on your business, but your business continues to function, including by using a procedural workaround.
Priority 3 — LowA general usage question, reporting of a documentation error, or recommendation for a future product enhancement or modification. There is low-to-no impact on your business or the performance or functionality of your system.

7. Customer Collaboration. Sidero Labs's ability to deliver high-quality Support Services is conditioned upon the Customer:

  • maintaining a current TEL subscription;
  • providing Sidero Labs with all reasonable assistance, diagnostic data, and information necessary to resolve the issue;
  • providing appropriate contact information for the technical personnel requiring support; and
  • utilizing Sidero Labs's published Support guidance and FAQs prior to escalating common configuration issues.

EXHIBIT C

Acceptable Use Policy

This Acceptable Use Policy (this "Policy") describes and provides guidance on prohibited uses of the Services and Platform of Sidero Labs, Inc., a Delaware corporation ("Sidero Labs" or the "Company"). The "Services" mean the products and services that are ordered by you (hereinafter "Customer," "you," or "your") under an Order Form and pursuant to a Master Services Agreement with the Company (the "MSA"). In the event of any conflict or inconsistency between this Policy, the Order Form, and the MSA, the order of precedence set forth in Section 9.11 of the MSA shall control. Capitalized terms in this Policy that are not otherwise defined herein have the meanings ascribed to them in the MSA or Order Form.

If you violate this Policy or authorize or help others to do so, Sidero Labs may suspend or terminate your use of and access to the Services and the Platform, or any part thereof.

The examples listed in this Policy are not exhaustive. Prohibited uses and activities include, without limitation, any use of the Services or Platform by Customer or any of its users (each an "End User") in a manner that, in Sidero Labs's reasonable judgment, involves, facilitates, or attempts to engage in:

1. Modifying, reverse-engineering, hacking or attempting to hack or otherwise discover any underlying ideas, algorithms or source code of a proprietary nature or vulnerabilities of the Services or Platform;

2. Using the Services or Platform in a manner that is, facilitates, or otherwise encourages (a) any illegal, fraudulent, or abusive activities, or (b) materially interfering with or harming the business or activities of Sidero Labs or any of its customers;

3. Attempting to bypass or break any security mechanism of the Services or Platform, or using the Services or Platform in any other manner that poses a material security or service risk to Sidero Labs or any of its other users;

4. Permitting direct or indirect access to or use of the Services or Platform for (i) any form of excessive automated bulk activity such as spamming; (ii) inauthentic interactions, such as the creation or use of fake accounts and automated inauthentic activity; or (iii) using the resources of the Platform (but excluding resources simply managed by the Platform) for mining or demonstrating proof-of-work or other proof by use of resources for any cryptocurrency or blockchain;

5. Selling, reselling, licensing, sublicensing, providing, leasing, lending, using for time-sharing or service bureau purposes, or otherwise using or allowing others to use the Services for the benefit of any third party, except as expressly permitted by the MSA, Order Form or Statement of Work;

6. Transmitting, storing, using, displaying, distributing or otherwise making available any content, data or technology that may damage, interfere with, surreptitiously intercept, or expropriate any system, program or data, including without limitation viruses, Trojan horses, bots, worms, scripting exploits, time bombs or other malicious code;

7. Using the Services or Platform to interfere with or disrupt the integrity or performance of the Services or Platform (or their components), or to attempt to gain unauthorized access to the Services or Platform, or any related systems or networks;

8. Launching or facilitating a denial of service attack (including any actions, which effectively cause a similar result) on any of the Services or Platform, or any other conduct that, at Sidero Labs's sole discretion, materially and adversely impacts the availability, reliability, or stability of the Services or Platform;

9. Using the Services or Platform for any illegal purpose or to violate, or to encourage or facilitate the violation of, any laws (including, without limitation, data protection, privacy, consumer protection, and export control laws);

10. Copying the Services or Platform, or any part, feature, function or user interface thereof, or accessing the Services or Platform in order to build a competitive product or service;

11. Modifying, altering, tampering with or creating a derivative work of any software included in the Services or Platform;

12. Using the Services or Platform in any manner that would result in an infringement, dilution, misappropriation or other violation of any intellectual property or proprietary rights of others, including but not limited to copyrights and rights arising from patents, trademarks and trade secrets;

13. Using the Services or Platform to create or transmit any material or content that is, facilitates, or encourages libelous, defamatory, discriminatory, or otherwise malicious or harmful speech or acts to any person or entity, including but not limited to hate speech and any other material or content that Sidero Labs reasonably believes degrades, intimidates, incites violence against, or encourages prejudicial action against anyone based on age, disability, ethnicity, gender, geographic location, national origin, race, religion, sexual orientation or any other protected category;

14. Using the Services or Platform to transmit, store, display, distribute or otherwise make available content that is defamatory, libelous, threatening, harassing, abusive, hateful, deceptive, fraudulent, obscene, indecent, harmful to minors, or otherwise objectionable; or

15. Collecting or using the Personal Information (as defined in the California Consumer Privacy Act of 2018 – see https://oag.ca.gov/privacy/ccpa) of any individual without their permission.

Responsibility for End Users

This Policy applies with respect to the use or access by anyone using or accessing the Services or the Platform on Customer's behalf, and Customer is responsible for violations of this Policy by the End Users.

Monitoring and Enforcement

Sidero Labs reserves the right, but does not assume the obligation, to investigate any violation of this Policy or misuse of the Services or Platform. Sidero Labs may report any activity that it suspects violates any law or regulation to appropriate law enforcement officials, regulators, or other appropriate third parties. Such reporting may include disclosing applicable Customer Data. Sidero Labs also may cooperate with appropriate law enforcement agencies, regulators, or other appropriate third parties to help with the investigation and prosecution of illegal conduct by providing network and systems information related to alleged violations of this Policy.

Reporting Violations

If you become aware of any violation of this Policy by you or any End User, you must immediately notify Sidero Labs and provide assistance as reasonably requested to stop or remedy the violation.

EXHIBIT D

Security Patch Availability Policy

1. Purpose and Scope

This Exhibit sets forth Company's policy and commitments regarding the availability of security patches for the Platform and Software provided under the Agreement, as a standard component of Customer's active Talos Enterprise Linux ("TEL") subscription. This Exhibit applies to the commercially supported components of the Talos Linux distribution and the Omni management platform as delivered by Company to Customer under an active subscription (collectively, "Supported Products").

This Exhibit does not apply to: (a) open-source components used by Customer independently of the Services and not obtained through Company's supported release channels; (b) Customer's own software, configurations, or workloads running on the Platform; (c) third-party software or dependencies not maintained by Company ("Third-Party Software"), except to the extent incorporated into Supported Products; or (d) versions of Supported Products that have reached end of support under Company's published lifecycle policy.

2. Definitions

"Confirmation Date" means the date on which Company confirms that a CVE affects a Supported Product and determines that a Qualifying Patch is warranted.

"CVE" means a common vulnerability or exposure identified in the MITRE CVE database or the NIST National Vulnerability Database.

"Qualifying Patch" means a CVE for which all of the following conditions are met: (i) the CVE affects a Supported Product; (ii) the CVE is independently rectifiable within the affected component (i.e., it is not dependent on the resolution of other unrelated defects); and (iii) either (a) the maintainer of the affected component has released a stable, production-ready, or generally available (GA) version that remediates the CVE, as evidenced by release notes, commit messages, or a published security advisory; or (b) the affected component can be rebuilt with updated compilers, libraries, or dependencies to remediate the CVE without introducing known regressions. For components maintained by Company (including Talos Linux and Omni), the Qualifying Patch determination is made by Company. For Third-Party Software incorporated into Supported Products, a Qualifying Patch requires that the upstream maintainer has made a stable fix publicly available. For the avoidance of doubt, upstream pre-release, release-candidate, or known-regressive patches do not constitute a Qualifying Patch.

"Patching Timeframe" means the target period within which Company will use commercially reasonable efforts to make a patch available, measured from the later of: (x) the Confirmation Date, and (y) for Third-Party Software components, the date a Qualifying Patch becomes publicly available from the upstream maintainer.

3. Vulnerability Severity Classification

Company classifies security vulnerabilities using the Common Vulnerability Scoring System (CVSS) v3.1 or its successor, supplemented by Company's own assessment of exploitability, affected components, and real-world risk. The following severity levels are used for purposes of this Exhibit:

Severity LevelCVSS Score RangeDescription
Critical9.0 – 10.0Remote exploitation without authentication or user interaction; potential for system compromise or worm-class propagation.
High7.0 – 8.9Exploitation could result in significant compromise of confidentiality, integrity, or availability; may require authentication or user interaction.
Medium4.0 – 6.9Exploitation is more difficult or yields limited impact; may require local access or unusual configuration.
Low0.1 – 3.9Exploitation requires unlikely circumstances or produces minimal consequences.

Where Company's assessment of real-world risk differs materially from the CVSS Base Score, Company may reclassify a vulnerability and will document the rationale in the corresponding security advisory or within its published VEX documentation.

Vulnerabilities actively listed on the CISA Known Exploited Vulnerabilities (KEV) catalog will automatically be prioritized as Critical, subject to the conditions of Section 4.

4. Patch Availability Targets

Company will use commercially reasonable efforts to make security patches for Qualifying Patches available to Customer within the Patching Timeframes set forth below:

Severity LevelPatching TimeframePatch Channel
Critical14 calendar daysSupported release channel; security advisory published
High30 calendar daysSupported release channel; security advisory published
MediumNext scheduled releaseIncluded in next minor or patch release
LowNext scheduled releaseIncluded in next minor or patch release

The Patching Timeframes in this Section 4 represent Company's good-faith operational targets and are not service level commitments subject to service credits or contractual penalties. Company's obligation is to use commercially reasonable efforts to meet these targets. Factors that may affect actual availability include the complexity of the vulnerability, the availability of upstream fixes for Third-Party Software incorporated into Supported Products, the need for regression testing, and coordination with responsible disclosure timelines.

Where a CVE affects a Third-Party Software component incorporated into a Supported Product, the Patching Timeframe begins when the upstream maintainer makes a Qualifying Patch publicly available, not from the date of public disclosure of the CVE.

5. Remediation Criteria

A CVE will be considered remediated for purposes of this Exhibit when any of the following has occurred:

(a) A patched version of the affected Supported Product has been published to Company's supported release channel and is available for Customer deployment. For the avoidance of doubt, Company's delivery target is met upon publication to the release channel, regardless of when or whether Customer applies the update to their active environments;

(b) The CVE is no longer reported when the affected Supported Product is scanned using industry-standard vulnerability scanners (e.g., Grype, Trivy, or equivalent) configured to ingest Company's published Vulnerability Exploitability eXchange (VEX) documentation, subject to Customer holding an active TEL subscription; or

(c) The CVE has been addressed in a published Company security advisory, release notes, or VEX documentation with either a fix, a verified workaround, or a determination (with documented rationale) that the CVE does not materially affect the Supported Product as delivered.

6. Security Advisories

For each Critical or High severity vulnerability affecting components maintained by Company (including Talos Linux and Omni) for which Company issues a patch, Company will publish a security advisory that includes: (a) a description of the vulnerability and affected components; (b) the CVE identifier(s), where assigned; (c) the CVSS Base Score and Company's severity classification; (d) the affected versions of the Supported Product; (e) the patched version(s); and (f) any available workarounds or mitigations. For Critical or High severity vulnerabilities affecting Third-Party Software incorporated into Supported Products, Company will address such vulnerabilities through patched releases and document the fixes in the corresponding release notes. Company is not obligated to issue individual security advisories for third-party CVEs.

Security advisories are published through Company's standard advisory channels (website, release notes, and/or email notification to designated Customer contacts).

7. Customer Responsibilities

Company's obligation under this Exhibit is to make security patches available through supported release channels. Customer is solely responsible for:

(a) Deploying security patches to Customer's environment in a timely manner consistent with Customer's own security policies, regulatory requirements, and change management processes;

(b) Maintaining supported versions of the Supported Products as set forth in Company's published lifecycle policy;

(c) Monitoring Company's security advisory channels for notifications of available patches;

(d) Notifying Company promptly if Customer becomes aware of a security vulnerability in a Supported Product that has not been addressed by a published advisory.

For the avoidance of doubt, Company does not guarantee that Customer's environment will be free of vulnerabilities, and Company is not responsible for any security incident arising from Customer's failure to apply available patches or maintain supported versions.

8. Exclusions

Company is not obligated to provide patches under this Exhibit for vulnerabilities that:

(a) Affect only versions of Supported Products that have reached end of support under Company's published lifecycle policy;

(b) Do not have a CVE identifier assigned by MITRE or listed in the NIST National Vulnerability Database;

(c) Do not have a Qualifying Patch available (i.e., no upstream fix exists and the vulnerability cannot be remediated by rebuilding the affected component);

(d) Are caused by Customer's modifications to the Supported Products not authorized by Company;

(e) Are caused by Customer's use of the Supported Products in combination with third-party software, hardware, or configurations not supported by Company;

(f) Arise from Customer's failure to implement a previously available patch or workaround that addresses the vulnerability;

(g) Affect components or features explicitly designated as "Alpha," "Beta," "Experimental," or "Tech Preview" within the Documentation or release channels. Such components are provided on an as-is basis and are not subject to the Patching Timeframes in Section 4.

9. Open-Source Components

The Platform incorporates open-source components, including Talos Linux, which is licensed under the Mozilla Public License 2.0. Security patches for open-source components are made available to all users of the open-source project through the project's public release channels.

The Patching Timeframes, security advisory obligations, and remediation criteria in this Exhibit apply to patches delivered through Company's commercially supported release channels to Customers with active TEL subscriptions. They do not create any obligation with respect to the open-source project's community releases, which are provided on an as-available basis under their respective open-source licenses.

10. Emergency Measures

In the event of an actively exploited vulnerability (zero-day) affecting a Supported Product, Company will use best efforts to provide a workaround, mitigation guidance, or patch on an expedited basis, and will communicate the status of remediation efforts to Customer's designated security contact. Company may, in its discretion, issue an out-of-cycle release to address such vulnerabilities.

11. Critical Vulnerability Response Commitment

For vulnerabilities classified as Critical under Section 3, or for actively exploited vulnerabilities (zero-day) addressed under Section 10, Company will provide the following response commitments:

(a) Acknowledgment. Company will acknowledge a confirmed Critical or zero-day vulnerability to Customer's designated security contact within twenty-four (24) hours of the Confirmation Date.

(b) Status Updates. For Critical severity vulnerabilities, Company will provide written status updates to Customer's designated security contact every forty-eight (48) hours until remediation is published to a supported release channel or interim mitigation guidance is provided.

(c) Escalation. Customer may escalate directly to Company's engineering leadership if a Critical vulnerability remains unresolved beyond the applicable Patching Timeframe set forth in Section 4.

(d) Transparency. If the applicable Patching Timeframe target cannot be met, Company will notify Customer in writing with the reason (e.g., awaiting stable upstream fix, regression discovered in testing) and a revised estimated timeline.

The response commitments in this Section 11 are communication obligations and do not modify the Patching Timeframes in Section 4 or the limitation of liability, warranty disclaimers, or other risk allocation provisions set forth in the Agreement.

12. Relationship to Agreement

This Exhibit is incorporated into and forms part of the Agreement. Capitalized terms not defined in this Exhibit have the meanings given to them in the Agreement. In the event of a conflict between this Exhibit and the body of the Agreement, the body of the Agreement shall prevail except with respect to the specific subject matter of this Exhibit (security patch availability), which shall be governed by this Exhibit.

Nothing in this Exhibit modifies Company's limitation of liability, warranty disclaimers, or other risk allocation provisions set forth in the Agreement.

Sidero Labs

490 South Fairview
Goleta, CA 93117
e: info@SideroLabs.com
t: (888) 488-2567

Product

  • Talos Linux
  • Talos Omni
  • Pricing
  • Support

Company

  • Customers
  • About us
  • Careers
  • Become a partner

Resources

  • Blog
  • Docs
  • The smallest Kubernetes →
  • Copy Fail barely scratches Talos Linux →
  • Why patching won't save you →
StatusGet support
Join our newsletters.
© 2026 Sidero Labs, Inc. All Rights Reserved
Privacy PolicyTerms & Conditions