Breach Point, Inc. (“Breach Point”) provides access to its Insight Recon Active Directory security assessment software subject to the terms and conditions set forth in this End User License Agreement (the “EULA”). Please read this EULA carefully.
As used in this EULA, “You” or “Your” refers to the person or entity using the Insight Recon Software. Breach Point and You are referred to collectively as the “Parties” and individually as a “Party.”
If You accept this EULA on behalf of a company or other legal entity, You represent that You have authority to bind that entity, and “You” and “Your” refer to that entity.
By clicking “Agree,” or by downloading, installing, accessing, or using the Insight Recon Software, You agree to be bound by this EULA. If You do not agree, do not download, install, access, or use the Insight Recon Software.
Definitions
1.1 “Authorized User” means an employee, contractor, or other individual authorized by You to access and use the Insight Recon Software on Your behalf, subject to the applicable Subscription Terms.
1.2 “Documentation” means user documentation for the Insight Recon Software made generally available by Breach Point.
1.3 “Insight Recon Software” means the Insight Recon Active Directory security assessment software made available by Breach Point under this EULA in object-code form, together with the hosted Insight Recon customer platform and portal through which Scan Data is processed and reports are made available, including updates, upgrades, and new versions provided to You, and the Documentation.
1.4 “Open Source Component” means a third-party software component included in or distributed with the Insight Recon Software that is licensed under an Open Source License.
1.5 “Open Source License” means a license approved by the Open Source Initiative or otherwise commonly recognized as an open-source or free-software license, including the GNU Lesser General Public License.
1.6 “Plan Entitlement Schedule” means the versioned schedule available at insightrecon.com/plan-entitlements that identifies usage entitlements, limitations, and permitted use rights associated with Insight Recon subscription plans. The version applicable to Your subscription is the version identified in Your applicable Subscription Terms at activation or renewal.
1.7 “Scan Data” means data, results, findings, configuration information, and other output collected from or generated about a Target Environment by the Insight Recon Software at Your direction.
1.8 “Security Incident” means unauthorized access to or acquisition of Your Scan Data in Breach Point’s possession or control that materially compromises the confidentiality or security of such Scan Data. Unsuccessful attempts, blocked attacks, probes, scans, or other events that do not result in unauthorized access to or acquisition of Your Scan Data are not Security Incidents.
1.9 “Subscription Terms” means the plan, subscription term, fees, usage entitlements, limitations, and permitted use rights applicable to Your subscription as identified in:
- an applicable order form or other written agreement between the Parties; or
- for a self-service subscription, the applicable Plan Entitlement Schedule together with a checkout confirmation, order confirmation, invoice, account entitlement record, renewal record, or other electronic subscription record issued or maintained by Breach Point or by an authorized reseller or merchant of record on Breach Point’s behalf.
1.10 “Target Environment” means any network, domain, directory service, system, host, account, application, or other environment against which You direct the Insight Recon Software to run.
License Grant
2.1 Grant
Subject to Your compliance with this EULA and applicable Subscription Terms, Breach Point grants You a limited, non-exclusive, non-transferable except as permitted under Section 18, non-sublicensable license during the applicable term to download, install, access, and use the Insight Recon Software for Your internal business purposes and for any additional commercial, consulting, MSSP, auditing, or third-party assessment purposes expressly permitted by Your Subscription Terms (the “License”).
2.2 Authorized Users
You may permit Authorized Users to access and use the Insight Recon Software on Your behalf, subject to applicable Subscription Terms and this EULA. You are responsible for the acts and omissions of Your Authorized Users and for their compliance with this EULA.
2.3 Updates
Breach Point may release updates, upgrades, or new versions of the Insight Recon Software. Unless accompanied by separate license terms, such releases are subject to this EULA. Breach Point is not obligated to provide any particular update or maintain or support a prior version except as expressly agreed in writing.
2.4 Reservation of Rights
All rights not expressly granted are reserved by Breach Point and its licensors.
Restrictions on Use
Except as expressly authorized by this EULA, applicable Subscription Terms, Section 4, an applicable third-party or Open Source License, or applicable law notwithstanding a contractual prohibition, You agree not to, and not to permit any third party to:
- copy, distribute, reproduce, rent, lease, lend, loan, sell, resell, or sublicense any portion of the Insight Recon Software, or make the Insight Recon Software itself available to a third party on a service-bureau, timesharing, hosting, or managed-service basis, except as expressly permitted by Your Subscription Terms;
- translate, adapt, modify, alter, or combine the Insight Recon Software with other software, or prepare derivative works based in whole or in part on the Insight Recon Software;
- reverse engineer, decompile, disassemble, or otherwise attempt to derive source code or another human-perceivable form of the Insight Recon Software;
- use proprietary features or functionality of the Insight Recon Software as a basis to develop, copy, or reproduce substantially similar functionality or features;
- circumvent, disable, defeat, or interfere with any license key, entitlement enforcement, usage limit, or technical protection measure;
- remove, obscure, or alter any copyright, trademark, or other proprietary rights notice, mark, or legend appearing as part of the Insight Recon Software; or
- publish or disclose to a third party any non-public benchmark, performance test, or comparative evaluation of the Insight Recon Software without Breach Point’s prior written consent, except where such consent may not lawfully be required.
Nothing in this Section 3 prohibits You from using, exporting, analyzing, sharing, or acting upon Your Scan Data as permitted by this EULA.
Open Source and Third-Party Components
4.1 Third-Party Components
Certain versions of the Insight Recon Software may include third-party software components, including Open Source Components, subject to separate license terms. Applicable components, copyright notices, and license information are identified in third-party notices accompanying the applicable distribution.
Your rights in each such component are governed by its applicable third-party or Open Source License. To the extent any provision of this EULA conflicts with rights granted under such a license, the applicable license controls to the extent of the conflict.
4.2 Preservation of Open Source Rights
Nothing in this EULA is intended or shall be construed to limit, restrict, or condition rights granted under an applicable Open Source License. Any provision conflicting with an applicable Open Source License is of no force or effect solely to the extent of that conflict.
4.3 Permitted Open Source Activities
Notwithstanding Section 3, to the extent permitted or required by an applicable Open Source License, You may copy or distribute the applicable Open Source Component, modify or replace the applicable Open Source Component, recombine or relink the Insight Recon Software with a modified version of that Open Source Component, and reverse engineer the Insight Recon Software solely to the extent necessary to debug modifications to that Open Source Component.
4.4 Modified or Relinked Versions
Breach Point has no obligation to support, maintain, update, warrant, or indemnify any version of the Insight Recon Software modified, recombined, or relinked by You or a third party, except to the extent otherwise required by applicable law or the applicable Open Source License.
4.5 Third-Party Disclaimer
Third-party and Open Source Components are licensed by their respective licensors. Breach Point makes no warranty concerning such components except to the extent required by applicable law or license.
Authorization; Acceptable Use
5.1 Authorization
You represent, warrant, and covenant that You possess all rights, permissions, consents, and authorizations necessary to use the Insight Recon Software against each Target Environment and to collect, process, use, and authorize Breach Point to process resulting Scan Data as contemplated by this EULA.
If a Target Environment is owned or operated by a person or entity other than You, You must obtain written authorization from its owner or operator sufficient to authorize the assessment activities You direct the Insight Recon Software to perform and the collection and processing of resulting Scan Data.
Upon Breach Point’s reasonable request in connection with suspected unauthorized or unlawful use, You will provide evidence reasonably sufficient to demonstrate authorization. You may redact unrelated confidential, financial, or commercial terms.
5.2 Prohibited Uses
You shall not use the Insight Recon Software to:
- access, scan, assess, enumerate, or otherwise interact with a Target Environment for which You lack required authorization;
- violate applicable law or regulation or infringe or misappropriate third-party rights;
- conduct, facilitate, or prepare for an unauthorized intrusion, data exfiltration, denial of service, or other unauthorized attack; or
- evade, defeat, or test the resilience of a third party’s security controls without authorization.
Nothing in this Section prohibits assessments of third-party Target Environments where authorized under Section 5.1 and permitted by Your Subscription Terms.
5.3 Credentials and Privileges
You are responsible for accounts, credentials, tokens, and privilege levels supplied or configured for use with Insight Recon, for safeguarding them, and for activity conducted through them. Breach Point does not select or approve the privilege level appropriate for a particular Target Environment.
5.4 Operational Risk Acknowledgment
You acknowledge that security assessment activities may generate network, directory-service, authentication, endpoint, logging, monitoring, and other system activity and may, depending on the Target Environment and its configuration, credentials, policies, security controls, or third-party software, trigger account lockout policies, alerts, monitoring, detection or response controls, or otherwise affect the availability, performance, or behavior of a Target Environment.
You are responsible for appropriately scoping and scheduling assessments, selecting and safeguarding credentials and permissions, maintaining appropriate backups and change controls, and coordinating assessment activity with appropriate personnel.
To the maximum extent permitted by applicable law and subject to Section 12.4, Breach Point shall not be liable for any such effect.
5.5 Suspension
Breach Point may suspend or disable access if it reasonably believes Your use violates this Section 5, creates a material risk of harm, or must be suspended to comply with applicable law or legal process. Where reasonably practicable, Breach Point will provide notice and an opportunity to cure.
Ownership
Except for third-party and Open Source Components identified in applicable notices, the Insight Recon Software contains proprietary and copyright-protected material, trade secrets, and other intellectual property owned by Breach Point and its licensors.
As between You and Breach Point, Breach Point retains all right, title, and interest in the proprietary portions of the Insight Recon Software.
Except for rights expressly granted under this EULA or an applicable third-party or Open Source License, this EULA grants no right to any patent, copyright, trade secret, trade name, trademark, or other intellectual property right.
Scan Data; Confidentiality
7.1 Your Scan Data
As between the Parties, You retain all right, title, and interest in Your Scan Data.
You grant Breach Point a limited, non-exclusive, worldwide license to host, store, process, transmit, reproduce, and display Scan Data solely as necessary to provide, maintain, secure, operate, and support Insight Recon and as otherwise expressly permitted by this EULA.
For Scan Data derived from a Target Environment owned or operated by a third party, You represent and warrant that You have obtained the rights and authorizations necessary to grant Breach Point the rights in this Section 7, including Sections 7.1 and 7.3.
7.2 Breach Point Confidentiality
Breach Point will treat Scan Data as confidential and will not disclose it except:
- to personnel, contractors, and subprocessors with a need to know in connection with the Insight Recon Software and subject to appropriate confidentiality obligations;
- with Your authorization; or
- as required by applicable law or legal process, with prior notice to You where legally permitted and reasonably practicable.
Breach Point will maintain commercially reasonable administrative, technical, and physical safeguards designed to protect Scan Data against unauthorized access, use, or disclosure.
7.3 Aggregated and De-Identified Data
Breach Point may generate and use aggregated or de-identified information derived from operation of Insight Recon, including telemetry, usage statistics, and security findings data, to operate, secure, analyze, and improve its products and services and produce industry research, aggregate statistics, and trend reports, provided such information does not identify You, an Authorized User, or a Target Environment and cannot reasonably be used to do so.
As between the Parties, Breach Point owns such aggregated and de-identified information.
7.4 Personal Data
Nothing in Sections 7.1 or 7.3 authorizes either Party to process personal data in violation of applicable data-protection law.
Where required, the Parties will enter into an appropriate Data Processing Addendum.
Breach Point’s privacy practices are described in the Privacy Policy.
7.5 Your Confidentiality Obligation
Proprietary portions of Insight Recon, Documentation, and non-public information concerning architecture, design, detection logic, implementation, or operation constitute Breach Point confidential information.
This obligation does not apply to information You demonstrate:
- is publicly available through no breach of this EULA;
- was lawfully known without restriction before disclosure;
- was lawfully received from a third party without confidentiality obligations; or
- was independently developed without use of Breach Point confidential information.
7.6 Security Incident Notification
Breach Point will notify You without undue delay after becoming aware of a confirmed Security Incident affecting Your Scan Data and will provide information reasonably available regarding the nature of the incident and remediation undertaken, subject to applicable law, legal-process restrictions, and legitimate security or law-enforcement considerations.
Where an applicable Data Processing Addendum imposes different notification obligations concerning personal data, that Data Processing Addendum controls.
Feedback
If You voluntarily provide suggestions, comments, ideas, bug reports, feature requests, or other feedback concerning Insight Recon (“Feedback”), You grant Breach Point a perpetual, irrevocable, worldwide, royalty-free, fully paid-up, transferable, and sublicensable license to use and exploit Feedback for any lawful purpose without attribution or compensation.
Fees and Payment
Fees, billing terms, subscription terms, usage entitlements, and permitted use rights are set forth in applicable Subscription Terms.
Except as otherwise provided in an applicable order form or written agreement, by an authorized reseller or merchant of record, under an applicable refund policy governing the transaction, under Section 10.3, or as required by law, fees are non-refundable.
For transactions processed through Paddle or another authorized merchant of record, applicable payment, cancellation, refund, and mandatory consumer-right provisions of the merchant of record also apply to the transaction.
Breach Point may suspend paid features or access for non-payment after reasonable notice.
Term and Termination
10.1 Term
This EULA takes effect upon acceptance or first download, installation, access, or use and continues until terminated.
10.2 Termination by You
You may terminate by ceasing use and deleting proprietary copies in Your possession or control. Termination does not entitle You to a refund except as expressly provided.
10.3 Termination by Breach Point
Breach Point may terminate or suspend:
- immediately upon a material breach incapable of cure;
- following failure to cure a curable material breach within a reasonable period after notice;
- upon expiration or non-renewal or failure to pay;
- immediately when reasonably necessary to comply with law, legal process, or address a material security risk; or
- for convenience upon thirty (30) days’ written notice.
If Breach Point terminates a paid subscription solely under clause (v), Breach Point will provide a prorated refund of prepaid fees attributable to the unused subscription period, directly or through the applicable merchant of record as appropriate.
10.4 Effect
Upon termination, the proprietary License terminates. Rights independently granted under an Open Source License are unaffected.
10.5 Scan Data Following Termination
Following expiration or termination, Breach Point will remove Scan Data from active systems within thirty (30) days, except to the extent longer retention is required by applicable law or reasonably necessary to establish, exercise, or defend legal claims.
Residual copies of Scan Data contained in routine backup or archival systems may be retained until overwritten or deleted in accordance with Breach Point’s standard backup-retention practices, provided that such copies remain access-restricted and are not restored or otherwise processed except as reasonably necessary for disaster recovery, security, legal compliance, or the establishment, exercise, or defense of legal claims.
Any retained Scan Data remains subject to applicable confidentiality and security obligations.
Disclaimer of Warranty
Limitation of Liability
- THE AMOUNTS ACTUALLY PAID BY YOU FOR INSIGHT RECON DURING THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM; OR
- ONE HUNDRED DOLLARS ($100).
Nothing in this Section limits Your payment obligations or obligations under Section 13.
12.5 Allocation of Risk
The Parties acknowledge these limitations reflect an agreed allocation of risk and are an essential basis of the bargain.
Indemnification by You
You will defend, indemnify, and hold harmless Breach Point and its directors, officers, employees, agents, successors, assigns, and affiliates against third-party claims and resulting damages, liabilities, settlements, fines, penalties, reasonable attorneys’ fees, and costs arising from:
- Your material breach of Sections 3, 5, 7.5, or 14;
- Your use of Insight Recon against a Target Environment without authorization required by Section 5.1;
- Your Scan Data to the extent a third party alleges Your collection, provision, authorization, or use violates its rights; or
- Your fraud, negligence, or willful misconduct.
Breach Point will provide reasonably prompt notice and reasonable cooperation. You may control the defense, but may not settle in a way imposing liability, payment, admission, or continuing obligation on Breach Point without prior written consent, not to be unreasonably withheld.
Export Control and Sanctions
Insight Recon may be subject to United States export-control and economic-sanctions laws.
You represent and warrant that:
- You are not located in, organized under the laws of, or ordinarily resident in a jurisdiction where access to or use of Insight Recon is prohibited by applicable U.S. law;
- You are not identified on, and are not owned or controlled by a person identified on, an applicable U.S. restricted or denied-party list; and
- You will not export, re-export, transfer, provide, make available, or use Insight Recon in violation of applicable export-control or sanctions laws.
U.S. Government End Users
To the extent applicable, Insight Recon is “commercial computer software” and its Documentation is “commercial computer software documentation” under applicable U.S. federal acquisition regulations, including FAR 12.212 and DFARS 227.7202.
Use by or on behalf of the U.S. Government is subject to applicable commercial-software rights and restrictions and this EULA to the extent permitted by law.
Amendments; Subscription Changes
16.1 EULA Amendments
Breach Point may amend this EULA. Material amendments will generally become effective thirty (30) days after notice by email, through the customer portal or Insight Recon Software, or by another reasonable electronic means.
Changes required by applicable law or reasonably necessary to address an urgent security or legal risk may take effect sooner upon notice.
16.2 Current Subscription Terms
An EULA amendment does not retroactively modify fees already paid, the duration of a then-current prepaid term, or material Subscription Terms expressly applicable to that term unless agreed by the Parties or required by law.
16.3 Plan Entitlement Schedule
The Plan Entitlement Schedule version applicable at activation or renewal remains applicable through the then-current subscription term.
A renewed subscription may become subject to the then-current Schedule. Breach Point will provide at least thirty (30) days’ advance notice before renewal of a material reduction in Domain entitlements, Authorized User entitlements, or permitted use rights that will apply at renewal, unless required by law or reasonably necessary to address an urgent security or legal risk.
Governing Law; Venue; Jury and Class Action Waivers
17.1 Governing Law
This EULA is governed by the laws of the Commonwealth of Virginia without regard to conflict-of-laws principles. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
17.2 Venue
Any action, claim, or proceeding arising from or relating to this EULA or Insight Recon shall be brought exclusively in the state courts located in the City of Richmond, Virginia or the United States District Court having jurisdiction in Richmond, Virginia.
Each Party submits to the personal jurisdiction of such courts and waives objections based on improper venue or forum non conveniens.
17.5 Equitable Relief
Nothing prevents either Party from seeking appropriate injunctive or equitable relief to protect intellectual property rights or confidential information.
Assignment
You may not assign this EULA without Breach Point’s prior written consent, except in its entirety in connection with a merger, reorganization, or sale of substantially all relevant assets, provided the assignee agrees to be bound and is not a direct competitor of Breach Point.
Breach Point may assign this EULA to an affiliate or in connection with merger, reorganization, financing, acquisition, restructuring, or sale of all or substantially all relevant business or assets.
Notices
Legal notices to Breach Point:
Legal notices to You may be sent to the contact information associated with Your account.
Routine service, billing, amendment, and renewal notices may be delivered electronically through email, account interfaces, or the customer portal.
Survival
Provisions that by their nature should survive termination will survive, including Sections 3, 4, 5.1, 5.2, 5.4, 6, 7, 8, 9, 10.4, 10.5, 11, 12, 13, 14, 17, 19, 20, 21, 22, 23, and 24.
Waiver
A waiver is effective only if in writing and signed by the Party against whom it is enforced. Delay or partial exercise of a right does not waive that or another right.
Severability
If a provision is invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable while preserving intent or, if that is not possible, omitted only to the necessary extent. The remainder remains effective.
Entire Agreement; Order of Precedence
This EULA, applicable Subscription Terms, Plan Entitlement Schedule, and any applicable order form, Data Processing Addendum, or signed written agreement constitute the agreement concerning Insight Recon software and subscriptions.
In the event of conflict, unless a signed agreement expressly provides otherwise:
- A signed written agreement expressly governing Insight Recon controls.
- An applicable Data Processing Addendum controls solely with respect to personal-data processing.
- An applicable order form or individualized subscription record controls with respect to the specific price, term, entitlement, or other matter expressly stated in that document.
- This EULA controls.
- The applicable Plan Entitlement Schedule controls.
- Other applicable Subscription Terms control.
The Insight Recon Terms of Use govern use of Breach Point’s public websites and are not incorporated into this EULA except to the extent expressly stated herein. This EULA governs the download, installation, licensing, access, operation, and use of the Insight Recon Software and customer subscriptions.
This does not apply to a Plan Entitlement Schedule, Data Processing Addendum, order form, or other document expressly identified as a binding contractual document.
The Privacy Policy describes Breach Point’s privacy practices and applies as provided by applicable law and the relevant agreements.
Third-Party Beneficiaries
Except as expressly stated, this EULA does not create third-party beneficiary rights.
Breach Point’s directors, officers, employees, agents, successors, assigns, and affiliates are intended beneficiaries of Sections 12 and 13 to the extent those Sections apply to them.
No licensor of an Open Source Component becomes a contractual third-party beneficiary solely because its component is included in Insight Recon.