Service and Data Partner Agreement

LAST UPDATED: 28/07/2026

This Service and Data Partner Agreement, including any of its exhibits, annexes, appendixes, or other document which are incorporated by reference (collectively, “Agreement”) is entered into by and between Nord Security Inc., registered at Americas Towers, 1177 6th Avenue, 5th FLR, New York, NY 10036, USA (“NordStellar”) and the entity purchasing NordStellar Services (“Partner”), whose legal name, registration details and contact information are specified in the applicable Quote and Insertion Order for Nord Security Services (“Insertion Order”) signed by both Parties and shall govern Partner’s purchase and/or use of the respective NordStellar Services. This Agreement forms an integral part of each Insertion Order and shall govern Partner’s purchase, access to, and/or use of the NordStellar Services. For the purposes of this Agreement, NordStellar and Partner may be individually referred to as a “Party” and jointly as the “Parties”.

This Agreement shall come into force as of the date indicated in the respective Insertion Order and/or first usage of the Services, whichever is earlier (“Effective Date”). By undertaking an Evaluation Use of NordStellar Services, Partner agrees to be bound by the terms of this Agreement.

Capitalized terms not otherwise defined in the text of this Agreement will have the meanings assigned to them in Exhibit A (Definitions).

WHEREAS:

I. Service Provider specializes in the provision of cyber threat intelligence services.

II. Partner operates in the industry and business sector specified in the applicable Insertion Order and desires to utilize Service Provider’s Services and/or API for its business purposes or on behalf of its Customers.

III. The Parties wish to cooperate in the delivery, access, or integration of dark web monitoring and cyber threat intelligence services as set forth herein and in the applicable Insertion Order.

IV. This Agreement shall govern Service Provider’s provision and Partner’s use of API to fetch the Breached Assets associated with or owned by Partner’s Customers as well as Partner’s access to and use of the Breached Assets. Insertion Order and any Addendum may contain additional terms specific to the Services and Breached Assets provided thereunder. The provisions of any such Insertion Order or Addendum shall govern and take precedence over any conflicting or inconsistent provisions of this Agreement.

NOW THEREFORE, the Parties hereby agree as follows:

1. LICENCE AND RESTRICTIONS

1.1. Grant of Rights. Subject to and conditioned on the terms and conditions of this Agreement, Service Provider hereby grants Partner a worldwide, limited, non-exclusive, non-transferable, non-assignable (except in connection with a permitted assignment of this Agreement), non-sublicensable license during the Term to: (i) use the Service for Partner’s internal business purposes solely to access the Breached Assets; (ii) display and allow access to such Breached Assets to Customers through the Product(s); (iii) permit use of such Breached Assets by Customers solely for the Approved Use Case; (iv) modify the Breached Assets to display it on the Product(s); and (iv) copy a reasonable amount of the Breached Assets to the Product only as necessary to exercise the rights granted in this Section. Partner may only exercise such rights granted herein through its employees and contractors who are performing data security monitoring services solely on Partner’s behalf.

1.2. Restrictions. Except as expressly permitted under this Agreement, Partner shall not itself nor shall it permit any third party to: (i) provide any third party, including Customers and Data Subjects, access to the Service, except that Partner may provide access to its subsidiaries or other group companies; (ii) reverse engineer, decode, decompile, disassemble or otherwise attempt to access or derive the source code or architectural framework of the Service, or any portion thereof; (iii) allow Customers to access the Breached Assets outside of the Product(s); (iv) rent, lease, lend, sell or sublicense the Breached Assets or otherwise provide access to the Breached Assets to any third party other than the Customer, unless otherwise provided in the applicable Insertion Order or Addendum; (v) provide use of the Service on a service bureau, rental or managed services basis, provide or permit other individuals or entities to create Internet "links" to the Services or "frame" or "mirror" the Service on any other server, or wireless or Internet-based device; (vi) interfere with, modify, disrupt or disable features or functionality of the Service, including without limitation any such mechanism used to restrict or control the functionality, or defeat, avoid, bypass, remove, deactivate or otherwise circumvent any software protection or monitoring mechanisms of the Service; or (vii) use the Service in any way that does not comply with all applicable laws and regulations.

2. PARTNER RESPONSIBILITIES

2.1. Partner Obligations. In providing access to the Breached Assets to Customers, Partner shall (i) restrict access to the Breached Assets and the Product(s) only to Customers and only for the Approved Use Case; and (ii) bind all Customers to license terms that are at least as protective of the Breached Assets as those in this Agreement, including terms that prohibit Customers from making the Breached Assets available to Data Subjects outside of the Partner Platform, and terms that prohibit Customers from renting, leasing, lending, selling or sublicensing the Breached Assets or otherwise providing access to the Breached Assets to any third party other than the Data Subject to which such Breached Assets belong. For the avoidance of doubt, point (ii) does not apply in cases where protection of Breached Assets is ensured by technical implementation of the Partner Platform (e.g. cases where Customer can only check Breached Assets concerning himself).

2.2. Restrictions on Product. During the term of the applicable Insertion Order, Partner may only display copies of the Breached Assets solely as part of the Product(s) to Customers. Unless otherwise expressly approved by Service Provider in the applicable Insertion Order, the Product(s) will not display Breached Assets to the general public (i.e., non-Customers). If Partner collects personal data from the Customers via the Product(s), Partner will provide a privacy policy that clearly discloses the personal data that Partner collects, as well as Partner’s other relevant information practices, and that will be consistent with all applicable laws. Partner shall obtain authorisation from the applicable Data Subject prior to disclosing of their personal data to Service Provider, including through the Service.

2.3. Technical Requirements. Partner shall be solely responsible for obtaining, configuring and maintaining any hardware, network connectivity and third-party software required to access the Service or Breached Assets, including computers, operating systems, web browsers and storage devices.

2.4. Protection. Partner shall be solely responsible for protecting the confidentiality of Credentials and will be liable for any unauthorized use thereof. In the event that Partner becomes aware of any unauthorized use of the Service (including the Breached Assets) through use of Partner Facilities, Partner shall promptly give written notice to Service Provider of such unauthorized use and make reasonable efforts to eliminate such unauthorized use. Partner shall at all times implement appropriate security policies and procedures and access control methodologies to safeguard access to the Service and Breached Assets through Partner Facilities. All such measures shall comply with prevailing industry standards but in no case consist of less than reasonable care.

3. FEES AND TAXES

3.1. Fees. Partner shall pay Service Provider the applicable fees set forth in the Insertion Order pursuant to the payment terms therein, including the Revenue Share (“Fees”). Revenue Share fees will be calculated based on the Fees listed in the attached Insertion Order. Any reporting necessary to compute the Fee’s will be delivered on the 5th business day following the end of the month.

3.2. Taxes. Any and all amounts payable hereunder by Partner are exclusive of any value added, sales, use, excise or other similar taxes (collectively, “Taxes”). Partner shall be solely responsible for paying all applicable Taxes. If Service Provider has the legal obligation to collect any Taxes, Partner shall reimburse Service Provider upon invoice by Service Provider. If Partner is required by law to withhold any taxes from its payments to Service Provider, Partner shall provide Service Provider with an official tax receipt or other appropriate documentation to support such payments and take reasonable steps to minimize such payment.

3.3. Late Payments. If Partner fails to pay any past due invoice within (ten) 10 business days after Partner’s receipt of a past due notice from Service Provider, Service Provider may revoke or suspend the Service and the provision of all Breached Assets until such time as Partner brings its account completely current. Service Provider may charge interest on all past due invoices at a rate of 1.5% per month, or the highest rate allowed by applicable law, whichever is lower. If Partner is delinquent in its payments for two (2) consecutive months, Service Provider may, upon written notice to Partner, modify the payment terms to require full pre-payment of any or all Insertion Orders, or require other assurances to secure Partner’s payment obligations hereunder.

3.4. Right to Audit. Service Provider or a mutually agreed upon third party agent subject to obligations of confidentiality will be entitled to inspect and audit any records in Partner’s control or possession related to the performance of this Agreement, upon reasonable notice to Partner, and at a reasonable time during normal business hours, for the purpose of verifying compliance with this Agreement and the Fees payable to Service Provider for the two (2) year period preceding the audit (the “Audit Period”). Service Provider may exercise its audit right no more than once every twelve (12) months, unless it has reasonable cause for noncompliance, and such audit shall not unreasonably interfere with Partner’s business activities. Partner will provide its full cooperation and assistance with such audit and provide access to all Breached Assets and the applicable agreements, records, and systems in Partner’s possession or control. Without limiting the generality of the foregoing, as part of the audit, Service Provider may request, and Partner agrees to provide, a written report, signed by an authorized representative, listing Partner’s then-current deployment of the Breached Assets, Products and its use cases. Partner will pay to Service Provider within thirty (30) business days after the completion of the audit the amount of any underpayment revealed by any such audit plus an additional fee of 25% of the applicable unpaid fee disclosed by the audit. In addition, if any such audit reveals an underpayment by Partner of five percent (5%) or more, then Partner will also reimburse Service Provider for the reasonable costs and expenses of such audit. The requirements of this Section shall survive for one (1) year following the termination of the last Insertion Order governed by this Agreement.

4. INTELLECTUAL PROPERTY

4.1. Service Provider’s Ownership. The Services and Breached Assets are licensed, not sold, and all rights not granted herein are reserved by Service Provider. Partner acknowledges and agrees that, as between Service Provider and Partner, Service Provider owns all right, title and interest in and to Service and the Breached Assets, including all related Intellectual Property.

4.2. Partner Ownership. Service Provider acknowledges and agrees that, as between Partner and Service Provider, Partner owns all right, title and interest in and to any data provided by Partner to Service Provider hereunder (“Partner Data”) and the Products (excluding the Breached Assets contained therein). Partner hereby grants Service Provider and its service providers a worldwide, royalty-free, non-exclusive license to use, process, transmit and reproduce Partner Data only as necessary for Service Provider to provide the Services to Partner.

4.3. Usage Data. Service Provider may publish, share or otherwise distribute, to any party, analytics, statistics or other data related to Partner’s use of the Services or Breached Assets (“Usage Data”), provided that such Usage Data are de-identified or aggregated with the data from other Service Provider’s customers, partners, or users in a manner that does not allow usage data about Partner to be separated from the aggregate data and be identified as originating from Partner.

4.4. Suggestions. If Partner elect to provide or make available to Service Provider any suggestions, comments, ideas, improvements or other feedback relating to the Services or Breached Assets (“Suggestions”), Service Provider shall own and be free to use, disclose, reproduce, have made, modify, license, transfer and otherwise utilize and distribute such Suggestions in any manner, without credit or compensation to Partner.

4.5. Trademark Notices. Partner shall not remove, obscure or modify in any way any copyright or trademark notices or other notices or disclaimers that appear within the Services or Breached Assets. Service Provider’s marks may not be included in or as part of Partner’s registered corporate name, any Partner logo, the Product, or any of Partner’s other service or product names. Moreover, Partner may not create any derivative works of the Service Provider’s marks or use the Service Provider’s marks in a manner that creates or reasonably implies an inaccurate sense of endorsement, sponsorship, or association with Service Provider. Partner will not otherwise use business names and/or logos in a manner that can mislead, confuse, or deceive Customers. All use of the Service Provider’s marks and all goodwill arising out of such use, will inure to Service Provider’s benefit.

4.6. Reservation of Rights. Each of the Parties reserves all rights not expressly granted under this Agreement.

5. TERM, SUSPENSION AND TERMINATION

5.1. Term. Except as provided in Section 5.3, the term for this Agreement shall commence on the Effective Date and continue for one (1) year (the “Initial Term”). Thereafter, this Agreement shall auto-renew for successive one (1) year periods (each, a “Renewal Term”), subject to payment of all applicable fees by Partner, unless either party provides 90 days’ written notice to the other party before the expiration of the then-current term. The Initial Term and all Renewal Terms shall collectively be referred to as the “Term.”  The term of each Insertion Order shall be as set forth in the Insertion Order itself (the “Insertion Order Term”). Any Insertion Order that expires or terminates after this Agreement expires or terminates shall continue to be subject to and governed by all the terms and conditions of this Agreement for the duration of the Insertion Order Term.

5.2. Suspension. Service Provider reserves the right to immediately suspend Partner’s access to the Service in the event of an Emergency Security Issue, or if Partner engages in activities that Service Provider reasonably determines is harmful to the Customer, Service Provider, or Service, until Partner remedies such Emergency Security Issue and activities. Service Provider will make commercially reasonable efforts to limit suspension to the minimum extent and duration necessary.

5.3. Termination. Notwithstanding anything to the contrary, this Agreement may be terminated as follows: (i) by the non-breaching party upon a material breach of this Agreement by the other party, which breach is not cured within thirty (30) days after receipt of written notice from the non-breaching party; (ii) by either party in the event the other party becomes insolvent or bankrupt; becomes the subject of any proceedings under bankruptcy, insolvency or debtor’s relief law; has a receiver or manager appointed to dissolve its business; makes an assignment for the benefit of creditors; or takes the benefit of any applicable law or statute in force for the winding up or liquidation of such party’s business; or (iii) by either party, within sixty (60) days following the acquisition of more than 50% of the other party’s voting stock by an entity that reasonably competes with the non-acquired party; (iv) by mutual agreement of the Parties in writing.

5.4. Events Upon Termination. Upon termination of this Agreement for any reason: (i) all licenses granted hereunder shall terminate, (ii) Service Provider shall cease providing the Services and the Breached Assets to Partner; (iii) Partner will permanently delete all Breached Assets in its possession, if any and if applicable Insertion Orders do not provide otherwise; (iv) all payment obligations of Partner will immediately become due; and (v) each Party shall immediately cease all use of the other Party’s Confidential Information (as defined in Section 9 and return or destroy all copies of such Confidential Information that are within its custody or control within thirty (30) calendar days after such termination and, if requested by the other Party, provide a written certification of such destruction.

5.5. Any provision that, by its terms, is intended to survive the expiration or termination of this Agreement shall survive such expiration or termination, including Section 1 “Licence and Restrictions”, Section 3 “Fees and Taxes”, Section 4 “Intellectual Property”, Clause 5.4 (events upon termination), Clause 5.5 (survival), Section 6 “Representations and Warranties”, Section 7 “Limitation of Liability”, Section 8 “Indemnification”, Section 9 “Confidentiality”, Section 10 “Personal Data”, Section 12 “Governing Law and Dispute Resolution”, and Section 13 “Other Provisions.”

6. REPRESENTATIONS AND WARRANTIES

6.1. Mutual. Service Provider and Partner each represents and warrants to the other that: (a) it has the necessary power and authority to enter into this Agreement and to perform its obligations and duties under this Agreement; (b) the execution and performance of this Agreement have been authorized by all necessary corporate or institutional action; and (c) entry into and performance of this Agreement will not breach of any other agreement of such party or any judgment, order, or decree by which such party is bound. Each party’s sole liability and obligation, and other party’s exclusive remedy, for any and all breaches of this Section 6.1 are the indemnity obligations set forth in Section 8.

6.2. By Service Provider. Service Provider warrants that the Service will be provided in accordance with: (i) the applicable documentation provided by Service Provider; and (ii) the service levels set forth in Exhibit B. Service Provider’s sole liability and obligation for any and all breaches of this Section 6.2 is to correct any such deficiency, and solely to the extent Service Provider cannot correct such deficiencies within a reasonable period of time, Partner’s exclusive remedy is to terminate this Agreement as set forth in Section 5.3.

6.3. By Partner. Partner represents and warrants that (i) it will use the information obtained from  Service Provider solely for the legitimate purpose of providing cybersecurity and fraud prevention services to its customers, (ii) it will not use such information for any illegal purpose, and (iii) any such information which constitutes confidential information of one of its customers will be subject to the confidentiality obligations and use restrictions set forth in the contract between Partner and such customer.

6.4. EXCEPT AS OTHERWISE PROVIDED IN THIS SECTION 6, ALL PRODUCTS, SERVICES AND DATA PROVIDED UNDER THIS AGREEMENT, INCLUDING THE SERVICE AND BREACHED ASSETS, ARE PROVIDED “AS IS,” “AS AVAILABLE” AND WITH ALL FAULTS. EACH PARTY, TO THE MAXIMUM EXTENT PERMITTED BY LAW, EXPRESSLY DISCLAIMS ALL OTHER WARRANTIES AND REPRESENTATIONS, EXPRESS OR IMPLIED, INCLUDING: (A) THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE NON-INFRINGEMENT, TITLE, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING, USAGE, OR TRADE PRACTICE, IN CONNECTION WITH THIS AGREEMENT; AND (B) ANY WARRANTY WITH RESPECT TO THE QUALITY, ACCURACY, CURRENCY OR COMPLETENESS OF THE PRODUCTS AND SERVICES PROVIDED UNDER THIS AGREEMENT, INCLUDING THE SERVICE AND BREACHED ASSETS, OR THAT SUCH PRODUCTS AND SERVICES WILL BE ERROR-FREE, UNINTERRUPTED, FREE FROM OTHER FAILURES OR WILL MEET PARTNER’S REQUIREMENTS.

7. LIMITATION OF LIABILITY

7.1. EXCEPT AS SET FORTH IN SECTION 7.2: (i) IN NO EVENT SHALL EITHER PARTY BE LIABLE TO THE OTHER PARTY FOR ANY INCIDENTAL, INDIRECT, SPECIAL, PUNITIVE OR CONSEQUENTIAL DAMAGES, OR LOST PROFITS, GOODWILL, OR DATA, OR FOR COST OF COVER DAMAGES, INCLUDING DAMAGES ARISING FROM ANY TYPE OR MANNER OF COMMERCIAL, BUSINESS OR FINANCIAL LOSS OCCASIONED BY OR RESULTING FROM ANY USE OF OR INABILITY TO USE THE PRODUCTS AND SERVICES PROVIDED UNDER THIS AGREEMENT, SUCH AS ANY MALFUNCTION, DEFECT OR FAILURE OF THE SERVICE OR ITS DELIVERY VIA THE INTERNET, EVEN IF SUCH PARTY HAD ACTUAL OR CONSTRUCTIVE KNOWLEDGE OF THE POSSIBILITY OF SUCH DAMAGES AND REGARDLESS OF WHETHER SUCH DAMAGES WERE FORESEEABLE; AND (B) IN NO EVENT SHALL EITHER PARTY’S AGGREGATE LIABILITY UNDER THIS AGREEMENT EXCEED THE AMOUNT OF FEES RECEIVED BY SERVICE PROVIDER FROM PARTNER UNDER THIS AGREEMENT IN THE TWELVE (12)-MONTH PERIOD IMMEDIATELY PRECEDING THE DATE ON WHICH THE EVENTS GIVING RISE TO LIABILITY AROSE (OR UP TO USD$50 IF THE SERVICES ARE FREE).

7.2. SECTION 7.1 WILL NOT APPLY TO BREACHES OF THE CONFIDENTIALITY OBLIGATIONS IN SECTION 9, INFRINGEMENT OR MISAPPROPRIATION OF THE OTHER PARTY’S INTELLECTUAL PROPERTY RIGHTS, INCLUDING WITHOUT LIMITATION, BREACHES BY PARTNER OF SECTION 1.2, OR EITHER PARTY’S GROSS NEGLIGENCE OR WILLFUL MISCONDUCT.

7.3. Service Provider will have no liability whatsoever with regard to the contents of the Breached Assets.

7.4. THE FOREGOING LIMITATIONS, EXCLUSIONS AND DISCLAIMERS SHALL APPLY REGARDLESS OF WHETHER SUCH LIABILITY ARISES FROM ANY CLAIM BASED UPON CONTRACT, WARRANTY, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY OR OTHERWISE, AND WHETHER OR NOT THE PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH LOSS OR DAMAGE. INSOFAR AS APPLICABLE LAW PROHIBITS ANY LIMITATION ON LIABILITY HEREIN, THE PARTIES AGREE THAT SUCH LIMITATION WILL BE AUTOMATICALLY MODIFIED, BUT ONLY TO THE EXTENT SO AS TO MAKE THE LIMITATION COMPLIANT WITH APPLICABLE LAW. THE PARTIES AGREE THAT THE LIMITATIONS ON LIABILITIES SET FORTH HEREIN ARE AGREED ALLOCATIONS OF RISK AND SUCH LIMITATIONS WILL APPLY NOTWITHSTANDING THE FAILURE OF ESSENTIAL PURPOSE OF ANY LIMITED REMEDY.

8. INDEMNIFICATION

8.1. Service Provider Indemnification. Service Provider shall defend, at its own expense, all suits, actions, and claims brought against Partner by a third party to the extent arising from (i) Service Provider’s violation of any state or Federal law, rule or regulation; (ii) Service Provider’s breach of Sections 6 or 9; or (iii) that the Service, when used as expressly permitted herein, infringes the Intellectual Property of such third party (collectively, “Partner Claims”). Further, Service Provider will indemnify and hold Partner harmless from and against all losses, damages, costs, liabilities and expenses (including reasonable attorneys’ fees) (collectively, “Losses”), finally awarded by a court of competent jurisdiction or paid in settlement and incurred by Partner, to the extent arising from such Partner Claims; provided, however, that Service Provider shall have no obligation to indemnify Partner from any Losses to the extent they arise from: (i) use of the Service or the Breached Assets in any manner that does not comply in all material respects with the terms and conditions of this Agreement or the applicable Insertion Order, laws or regulations; (ii) use of the Service in combination with any hardware or software not provided or approved by Service Provider; (iii) modifications to the Service not made or authorized by Service Provider; or (iv) the Product or any Partner Data (Sections 8.1(1) through 8.1(iv), collectively, “Partner Acts”). In the event that any part of the Service becomes the subject of a Partner Claim or Service Provider reasonably determines that any part of the Service is likely to become the subject of a Partner Claim, Service Provider may, at its sole discretion: (1) procure for Partner a license as necessary for Partner to exercise the rights granted by Service Provider under this Agreement; (2) modify or replace the Service to avoid infringement, provided, however, that the Service as modified or replaced retains materially similar in features and functionality; or (3) terminate this Agreement and provide a pro rata refund of the fees paid by Partner to Service Provider for the unused portion of the Term. This Section 8.1 states Service Provider’s entire liability and Partner’s sole and exclusive remedy for all third-party claims.

8.2. Partner Indemnification. Partner shall defend, at its own expense, all claims, suits and actions against Service Provider brought by a third party to the extent arising from: (i) Partner Acts or Partner’s breach of Sections 1.2, 2 or 9; (ii) any dispute between Partner and Customers; and (iii) any violation of applicable laws or regulations by Partner (collectively, “Service Provider Claims”). Partner will indemnify and hold Service Provider harmless from and against all Losses finally awarded by a court of competent jurisdiction or paid in settlement and incurred by Service Provider, to the extent arising from such Service Provider Claims.

8.3. Procedure. The indemnified Party shall: (i) give the indemnifying Party prompt written notice of any such claim; provided, however, that failure of the indemnified Party to give such prompt written notice shall not relieve the indemnifying Party of any obligation to indemnify pursuant to this Section 8, except to the extent the indemnifying Party has been prejudiced thereby; (ii) cooperate fully with the indemnifying Party, at the indemnifying Party’s expense, in the defense or settlement of any such claim; and (iii) give the indemnifying Party sole and complete control over the defense or settlement of any claim; provided, however, that any settlement must include a complete release of the indemnified Party without requiring the indemnified Party to make any payment or bear any obligation.

9. CONFIDENTIALITY

9.1. For purposes of this Agreement, “Confidential Information” shall mean all information, whether written, oral or in any other medium disclosed by or on behalf of the Disclosing Party to the Receiving Party (as hereinafter defined) including, without limitation, data, technology, know-how, inventions, discoveries, designs, processes, formulations, models, equipment, algorithms, software programs, interfaces, documents, specifications, information concerning research and development work, and/or trade and business secrets. Confidential Information will also include information disclosed by the Disclosing Party which relates to current, planned or proposed products, marketing and business plans, pricing, forecasts, projections and analyses, financial information, and customer and business partners information. For the avoidance of doubt, Confidential Information shall include any such information disclosed by or on behalf of one Party to the other prior to the Effective Date of this Agreement. For the avoidance of doubt, Confidential Information excludes Partner Data and any unauthorized access, acquisition, use, or disclosure thereof.

9.2. Each Party hereto receiving or otherwise obtaining Confidential Information (the “Receiving Party”) from the other Party (the “Disclosing Party”) shall have a duty to protect that Confidential Information.

9.3. The Receiving Party agrees that it will not copy or use the Confidential Information except for purposes related to the provision of the Services under this Agreement. The Receiving Party shall not acquire any rights in the Confidential Information by virtue of this Agreement.

9.4. The Receiving Party agrees that it shall hold all Confidential Information in confidence and shall take all reasonable steps to safeguard the Confidential Information including, without limitation, those steps that it takes to protect its own Confidential Information of a similar nature. The Receiving Party shall not disclose or otherwise provide any Confidential Information to any third party without the prior written consent of the Disclosing Party. The Receiving Party shall immediately notify the Disclosing Party in writing if it becomes aware that the Confidential Information has been disclosed to an unauthorized third party or breach of any other undertaking indicated herein above and take all reasonable measures to prevent or reduce damage to the Disclosing Party.

9.5. Each Party shall ensure that its employees, contractors, agents, and other representatives who receive or have access to sign and beConfidential Information are bound by written confidentiality terms substantially similar to the ones under obligations no less protective than those set forth in this Section 9.

9.6. The confidentiality provisions under this Section 9 are to remain in full force and effect notwithstanding the termination of this Agreement for at least 36 (thirty-six) months following the termination of this Agreement.

9.7. If the Receiving Party is not sure whether certain information is Confidential Information, the Receiving Party shall consult with the Disclosing Party.

9.8. Information or data shall not be deemed Confidential Information if or when, and to the extent that the Receiving Party can prove that such Confidential Information is or becomes generally available to the public or enters the public domain other than due to a breach of this Agreement.

9.9. Confidential Information shall remain the property of the Disclosing Party. Disclosure under this Agreement shall not be construed as granting the Receiving Party any right or license to any Confidential Information. The Receiving Party does not acquire any intellectual property rights under this Agreement except the limited rights necessary to use the Confidential Information for the execution of this Agreement.

9.10. The Disclosing Party makes no representation or warranty as to the accuracy, completeness or otherwise of the Confidential Information supplied, and the Receiving Party agrees that it is responsible for making its own evaluation of Confidential Information.

9.11. On the Disclosing Party’s written request, the Receiving Party shall promptly: i) return to the Disclosing Party all Confidential Information (and any documents, tangible materials and copies of it) in the Receiving Party’s control or possession; ii) delete and destroy all Confidential Information from any computer or data storage system into which it was entered; and iii) if required by the Disclosing Party at any time, certify in writing that the provisions of paragraphs i) and ii) above have been complied with.

9.12. The Receiving Party accepts full liability for the actions or inactions of its representatives, i.e., its advisors and members of governing bodies, directors, officers, members, employees, agents, managers, affiliates, consultants, and individuals seconded to work who will receive the Confidential Information to perform acts required under this Agreement.

9.13. Each Party acknowledges that all of the Disclosing Party's Confidential Information is owned solely by the Disclosing Party (or its licensors) and that the unauthorized disclosure or use of such Confidential Information may cause irreparable harm and significant injury, the degree of which may be difficult to ascertain. Accordingly, each Party agrees that the Disclosing Party will have the right to obtain an immediate injunction enjoining any breach of this Agreement, without the requirement of a bond of any kind or nature, as well as the right to pursue any and all other rights and remedies available at law or in equity for such a breach.

9.14. Neither Party will make any announcements or statements to the public concerning the relationship between them or the transactions described herein without the prior written consent of the other Party. Unless otherwise provided herein, neither Party will have the right to use the other Party’s name, marks, or logos without the prior written consent of the other Party.

10. PERSONAL DATA

10.1. To the extent the Parties process any information that constitutes “personal data” under applicable data protection laws, the Parties agree that the NordStellar Data Processing Agreement (available at: https://platform.nordstellar.com/misc/legal/agreement/dpa_250127.pdf) (the “DPA”) is incorporated by reference into this Agreement. The DPA, together with any data processing provisions set out in the applicable Insertion Order, governs the Parties’ respective obligations regarding the protection and processing of personal data in connection with this Agreement. If there is any conflict or inconsistency between the DPA and an Insertion Order, the Insertion Order will prevail to the extent of the conflict.

10.2. For the purposes of applying the DPA to this Agreement, any references in the DPA to the “Master Services Agreement” will be deemed to refer to this Agreement and/or the applicable Insertion Order, and any references to the “Customer” will be deemed to refer to the Partner.

11. ASSIGNMENT

Partner may not assign this Agreement or any of the interests, rights or obligations granted hereunder, in whole or in part, whether voluntarily or by operation of law, contract, merger (whether Partner is the surviving or disappearing entity), stock or asset sale, consolidation, dissolution, through government action or otherwise. Any such attempted assignment, except with the express written consent of Service Provider, is null and void, and Service Provider may immediately terminate this Agreement. This Agreement shall be binding upon and inure to the benefit of the Parties hereto and their respective successors and permitted assigns.

12. GOVERNING LAW AND DISPUTE RESOLUTION

12.1. This Agreement shall be governed by and construed and enforced in accordance with the laws of the United States of America and the State of Delaware without regard to conflict of laws principles. The United Nations Convention on Contracts for the International Sale of Goods and the Uniform Computer Information Transaction Act (UCITA) are specifically excluded from application to this Agreement. EACH PARTY AGREES THAT ALL CLAIMS SHALL BE RESOLVED ONLY ON AN INDIVIDUAL BASIS AND NOT IN A CLASS, CONSOLIDATED OR REPRESENTATIVE ACTION OR OTHER SIMILAR PROCESS (INCLUDING ARBITRATION), HEREBY WAIVES ALL RIGHTS TO JURY TRIAL IN CONNECTION WITH ANY ACTION, CLAIM OR SUIT IN ANY WAY ARISING OUT OF OR RELATED TO THIS AGREEMENT.

12.2. All claims, disputes, or other differences between or relating to the Parties - including but not limited to all claims, defenses, counterclaims, disputes or other differences arising from or relating in any way to the Agreement (whether contractual, tortious, or otherwise in nature) - shall be exclusively resolved by binding arbitration (all aspects of which shall be kept strictly confidential) pursuant to the United States of America Federal Arbitration Act and the Commercial Arbitration Rules of the American Arbitration Association, with arbitration to occur in Lewes, Delaware before a sole arbitrator, and the American Arbitration Association to administer the arbitration. The arbitrator, who shall have the exclusive power to rule on his or her own jurisdiction, including but not limited to any objections with respect to the existence, scope or validity of this arbitration provision, shall award the prevailing party attorney’s fees, costs and expenses in connection with the arbitration (including, if applicable, its expert witness expenses and attorney’s fees associated with its internal attorney hours), including but not limited to any appeal or enforcement proceedings. Prior to or in the absence of any such award, the costs and expenses charged by the arbitrator and the American Arbitration Association shall be split equally amongst the Parties. The award of the arbitrator shall be accompanied by a detailed statement of the reasons upon which the award is based. Any award or judgment will be enforceable in any court of competent jurisdiction. The arbitrator shall issue a final award within one hundred and twenty days of the filing of the arbitration demand. Notwithstanding the foregoing, nothing in this Section will restrict any party at any time from seeking injunctive relief as set forth in Section 13.5.

13. OTHER PROVISIONS

13.1. Independent Contractors. The relationship between Service Provider and Partner established by this Agreement is solely that of independent contractors. Neither Party is in any way the partner or agent of the other, nor is either Party authorized or empowered to create or assume any obligation of any kind, implied or expressed, on behalf of the other Party, without the express prior written consent of such other Party.

13.2. Notice. All notices, demands and other communications (“Notices”) to be given or delivered under or by reason of the provisions of this Agreement shall be in writing and sent to the Parties according to the contact information provided below, or such other contact information as either Party shall notify the other in accordance with this Section 13.2:

To Service Provider

Nord Security Inc.

Americas Towers,

1177 6th Avenue, 5th FLR,

New York, NY 10036, USA

[email protected]

To Partner: As indicated in the Insertion Order.

13.3. Evaluation Use. In some cases, we or others on our behalf may offer a free trial for our paid Services prior to charging your payment method for internal testing and evaluation purposes (“Evaluation Use”). We determine your Evaluation Use eligibility at our sole discretion, and to the extent permitted under applicable law, we may limit or withdraw the Evaluation Use option at any time without notice. Evaluation Use is granted for a limited period as specified in Insertion Order. Evaluation Use is provided "as is" and is not covered under NordStellar’s warranties or indemnities.

13.4. Interpretation. For the purposes of this Agreement: (i) the words “such as,” “include,” “includes” and “including” shall be deemed to be followed by the words “without limitation;” (ii) the word “or” is not exclusive; and (iii) the words “herein,” “hereof,” “hereby,” “hereto” and “hereunder” refer to this Agreement as a whole. This Agreement shall be construed without regard to any presumption or rule requiring construction or interpretation against the Party drafting an instrument or causing any instrument to be drafted.

13.5. Entire Agreement. This Agreement together with each applicable Insertion Order and any addendum or exhibits expressly incorporated therein or herein contains the sole and entire agreement of the Parties with respect to the subject matter hereof and supersedes all previous and contemporaneous oral and written negotiations, understandings, and agreements with respect to such subject matter.

13.6. Right to Preliminary and Injunctive Relief. Each Party agrees that money damages would be an inadequate remedy in the event of a breach or threatened breach of the provisions in this Agreement protecting such Party’s Intellectual Property or Confidential Information, and that in the event of such a breach or threat, such Party, in addition to any other remedies to which it is entitled, is entitled to such preliminary or injunctive relief, or other equitable remedies (including an order prohibiting the other Party from taking actions in breach of such provisions), without the need for posting bond, to preserve all of such Party’s rights.

13.7. No Waiver. The failure of either Party to require strict performance by the other Party of any provision hereof shall not affect the full right to require such performance at any time thereafter, nor shall the waiver by either Party of a breach of any provision hereof be taken or held to be a waiver of the provision itself. Any waiver of the provisions of this Agreement, or of any breach or default hereunder, must be set forth in a written instrument signed by the Party against which such waiver is to be enforced.

13.8. Amendment. No amendment of this Agreement will be valid unless executed in writing and signed by both Parties.

13.9. Force Majeure. Neither party shall be liable for any failure to perform under this Agreement to the extent due to any act of God, fire, casualty, flood, war, strike, lock out, failure of Internet or public utilities, injunction or any act, exercise, assertion or requirement of any governmental authority, epidemic, destruction of production facilities, insurrection or any other cause beyond the reasonable control of the party invoking this provision.

13.10. Severability. If any provision of this Agreement is held illegal, invalid or unenforceable by any court or arbitral tribunal of competent jurisdiction, the other provisions of this Agreement will remain in full force and effect. Any provision of this Agreement held illegal, invalid or unenforceable only in part or to a certain degree will remain in full force and effect to the extent not held invalid or unenforceable. The Parties will amend this Agreement by replacing such illegal, invalid or unenforceable provisions with legal, valid and enforceable provisions which would produce as nearly as possible the result intended by the Parties. The Parties will make all their best efforts to ensure the implementation of all the provisions hereof.

13.11. Contract for services. This Agreement is a contract for the provision of services and not a contract for the sale of goods. The provisions of the Uniform Commercial Code (UCC), the Uniform Computer Information Transaction Act (UCITA), or any substantially similar legislation as may be enacted, shall not apply to this Agreement. If Partner is located outside of the territory of the United States, the Parties agree that the United Nations Convention on Contracts for the International Sale of Goods shall not govern this Agreement or the rights and obligations of the Parties under this Agreement.

13.12. Sanctions Compliance. Partner represents and warrants that, throughout the Term of this Agreement, neither it nor any of its direct or indirect shareholders, beneficiaries, principals, executives, employees, agents are (i) subject, directly or indirectly, to any sanctions or restrictive measures administered or enforced by the United Nations, the United States of America, the European Union and/or its Member States, the United Kingdom, or any other applicable governmental authority (collectively, “Sanctions”), nor (ii) located, organized, or resident in any country or region that is subject to comprehensive Sanctions or embargoes, including but not limited to Belarus, Cuba, Iran, North Korea, Russia, Syria, or the restricted regions of Ukraine. Partner further acknowledges that the export, re-export, transfer, or use of the Service (“Controlled Items”) may be subject to export control and sanctions laws of the United States, the European Union, its Member States, and any other applicable jurisdiction. Partner agrees to comply fully with all such laws and regulations, including not exporting, re-exporting, or otherwise transferring any Controlled Items (a) to any prohibited country, entity, or individual without obtaining any required government authorizations or (b) in violation of applicable sanctions or export control laws. Partner also agrees to inform Service Provider immediately in writing if it or any party listed in this Clause 13.11 becomes subject to Sanctions or if any of the representations or warranties made in this Clause 13.11 are no longer accurate. In the event of any breach of this Clause 13.13, Service Provider reserves the right to terminate this Agreement immediately and without prior notice, and Partner agrees to immediately discontinue usage of Service and immediately delete Breached Assets. Any such breach will be considered a material breach of this Agreement.

13.14. Expenses. Each Party will bear all costs and expenses incurred or to be incurred by it in connection with the negotiations, execution and performance of this Agreement.

Exhibit A****DEFINITIONS

Approved Use Case” shall mean the Use Case set forth in the applicable Insertion Order.

Breached Assets” shall mean all Historical Breached Assets and all New Breached Assets made available to Partner through the Service.

Historical Breached Assets” shall mean Service Provider’s historical database of breached data that has been exposed on deep & dark web, which Service Provider has detected up to the Effective Date.

New Breached Assets” shall mean all breached data that has been exposed on deep & dark web, which Service Provider detects on or after the Effective Date, and makes available to Partner on a daily or other recurrent basis to refresh the Historical Breached Assets.

Credentials” means any user accounts, passwords and other authentication credentials associated with use of the Service by Partner.

Customer” means the end-user customer of the Partner who licenses use of the Product and Breached Assets, under terms no less protective of the Breached Assets as those set forth in this Agreement.

Partner Platform” means Partner’s online application, service or platform, as described in the applicable Insertion Order, through which Partner allows Customers to access their Breached Assets.

Data Subject” means an end user of the Partner Platform who has been verified by a Partner through a valid email address, and who: (i) signs up for a user account on the Customer Platform; or (ii) provides personal information to Customer in connection with use of the Customer Platform.

Emergency Security Issue” means any: (i) use of the Service by Partner in violation of the terms and conditions of this Agreement that disrupts or is reasonably likely to disrupt the availability of the Service to other users; or (ii) access to the Service by any unauthorized third party through use of any Partner Facilities.

Intellectual Property” means all patents and inventions; copyrights, mask works and other works of authorship (including moral rights); trademarks, service marks, trade dress, trade names, logos and other source identifiers; trade secrets; software, databases and data; and all other intellectual property and industrial designs, including all rights associated therewith.

Insertion Order” means each mutually agreed Quote and Insertion Order for Nord Security Services that specifies the Service and Breached Assets to be provided by Service Provider, and the fees to be paid by Partner for such items.

Partner Facilities” means Credentials, Product and any account, hardware, system or other facility within Partner’s custody or control.

Product” means Partner’s online application, service, or platform in which the Breached Assets are integrated, as described in the applicable Insertion Order, including without limitation any websites and any mobile websites or applications, accessible to and directly used by Customers.

Service” means Service Provider’s proprietary online data delivery service, including all firehoses that provide access to cloud computing platforms, Application Programming Interfaces (“APIs”), Software Development Kits (“SDKs”), software plugins, code, libraries, protocols, formats, documentation, and other related materials (as may be updated from time to time) for detecting, collecting, and presenting data and credential exposure through human intelligence and/or automated scanning.