Security & Privacy
Legal Documents
In Picus, your privacy is protected in an open and transparent manner. Also, the use of our website and services are subject to terms and conditions, which are bounded by legal agreements. Below, you can find all related legal documents.
PICUS SECURITY PRIVACY POLICY
Last Updated: 26.03.2026
1. INTRODUCTION
This Privacy Policy describes how Picus Security, Inc. and its Affiliates listed in Section 11 (collectively, "Picus", "we", "us", or "our") process personal data in connection with our websites, products, services, and related interactions.
Picus is committed to protecting personal data and maintaining transparency regarding its processing activities. This Privacy Policy applies to personal data processed through our websites (including www.picussecurity.com and app.picussecurity.com), our Services (as described below), and any other electronic communications networks by Picus.
This document is an informational disclosure of our privacy practices. While the use of our Services is subject to the Picus Subscription Agreement (PSA), this Policy serves to inform you about how and why we collect, process, and protect your personal data.
2. COLLECTION OF YOUR PERSONAL INFORMATION
Personal Data is any information that directly or indirectly identifies a natural person. We will ask for your consent when we need information that personally identifies you (personal information) or allows us to contact you to provide a service or carry out a transaction that you have requested, such as receiving information about Picus Security products and services, ordering email newsletters, joining a limited-access site or service, or purchasing, downloading and/or registering Picus Security products.
The channels and types of personal information we may collect, including but not limited to, are listed below:
2.1. Information you directly provide to us
We collect information when you request a service, register for an event, or communicate with us.
- Free-trial & Demo requests: Under your free-trial or demo requests, we may collect your first name, last name, company name, company email address, country, and phone number (optional).
- Platform account: We may collect your company email addresses for authentication and logging into our online platform.
- General Inquiries (Contact Us): When you make inquiries, such as scheduling a demo, learning about pricing, or upgrading a product, we may collect your first name, last name, company email, company name, job title, country, phone number (optional) information and any descriptive message submitted to facilitate the inquiry.
- Job application: We receive your job applications through a third-party platform. If you apply for a job at Picus, we may collect your full name, email, resume/CV, phone (optional), current company (optional), LinkedIn Profile (optional), and any other optional information submitted within your application.
- Partner account & User application: Under our partner program, we may collect your corporate email address.
- Picus Technology Alliances Partner Program application: Under our Technology Alliances Partner Program (TAP), we may collect your first name, last name, work email address, and role information.
- Picus Technology Alliances Team meeting request: For meeting requests with the Picus Technology Alliances Team, we may collect your first name, last name, and email address.
- Blog: If you subscribe to our blog, we may collect your company email address.
- Purple Academy by Picus: If you wish to obtain a service from Purple Academy, we may collect your full name, company email address, company, country, and job title information.
- Content Requests (Webinars, Case Studies, Reports): For webinars, case studies, and reports requests, we may collect your full name, company email address, company, country, and job title information.
- Exclusive Reports: Under exclusive report requests, we may collect your full name, company email address, company name, title, and country information.
We may also collect your personal data such as your first name, last name, and email address when you follow us on social media, attend our events, or correspond with us by phone, email, social media, or otherwise.
2.2. Information from your visits to our website
Our website enables us to communicate with you about us, our products, and our services. Even if you do not login with an account, we may automatically collect certain information each time you visit our website. This may include the name of the Internet Service Provider, Internet Protocol (IP) address, date and time of access browser type and version, time zone setting, operating system and platform, pages accessed, and the Internet address of the website from which you linked directly to our website. This information is mainly used to provide access to our website, improve the webpage view, and adapt to device settings and language. We also use this information to analyze trends and to improve our website and online services.
For more details on automatically collected information about your visit to our website, please see our Cookie Policy.
2.3. Information from other resources
We may also collect your personal information indirectly from third party sources such as business partners, advertising networks, payment and delivery services as well as public records, such as social media platforms and industry associations.
Please note that, in such cases, we strive to ensure that these parties adhere to privacy standards consistent with ours. However, we do not have any liability or responsibility over their use, storage, and disclosure of your personal information, as governed by their own privacy policies and such third parties are responsible for their own processing activities in accordance with their respective privacy policies.
3. USE AND CONTROL OF YOUR PERSONAL INFORMATION
We process personal data depending on the nature of our relationship with you (e.g., customer, prospective customer, user, partner, or job applicant) and the context in which the data is collected.
Consistent with applicable data protection laws and choices that may be available to you, we may use your personal information for the following purposes, including but not limited to:
Service Delivery and Contractual Obligations: To provide, operate, and maintain our products and services, including responding to requests, fulfilling contractual obligations, and delivering requested information.
Communication and Customer Engagement: To communicate with you regarding our products, services, updates, support requests, and relevant business communications.
Marketing and Events: To send marketing communications, event invitations, and promotional materials, in accordance with your preferences and, where required, your consent.
Platform Improvement and Analytics: To analyze usage, improve functionality, optimize performance, and enhance user experience across our websites and services.
Security and Fraud Prevention: To maintain the security of our systems, detect, investigate, and prevent unauthorized access, fraud, abuse, or other illegal activities.
Legal and Regulatory Compliance: To comply with applicable laws, regulations, legal processes, and enforceable governmental requests.
Legal Basis for Processing (GDPR): Where applicable, we rely on the following legal bases under GDPR:
- Performance of a contract (Article 6(1)(b))
- Compliance with legal obligations (Article 6(1)(c))
- Legitimate interests (Article 6(1)(f)), such as improving services and ensuring security
- Consent (Article 6(1)(a)), where required (e.g., marketing communications)
Marketing Preferences: You may opt out of marketing communications at any time by following the unsubscribe instructions in our emails or contacting us directly. You may also withdraw your consent at any time where processing is based on consent.
We will collect and use your personal data (as described in section 3) in accordance with applicable data protection laws. Our grounds for processing your personal data are as follows:
- Explicit Consent: Where necessary we will only collect and process your personal data if you have given your clear and affirmative consent for us to do so.
- Legitimate Interests: We may use and process some of your personal data where we have sensible and legitimate business grounds for doing so. Our legitimate interests for processing your personal data are for us to enable you access and use of our Services, to create and update our active cybersecurity initiatives or activities having been flagged with previous intent to conduct fraudulent or criminal activity, to effectively implement our features, to understand and to administer our technical and customer support for the delivery of our Services.
- Legal obligations: We may need to process your personal data when we are required to comply with a legal obligation.
- Performance of a contract: Provided that it is directly related to the establishment or performance of the contract, it is necessary to process the personal data of the parties to the contract. We may need to process your personal data when we provide Services to you or when we communicate with you about the Service.
4. HOW WE SHARE YOUR PERSONAL DATA
We do not sell your personal information. We only share your personal data in the following circumstances:
- Service Providers (Data Processors): We share data with trusted third-party vendors who provide services on our behalf, such as cloud hosting, CRM, analytics, and email delivery. These providers are strictly bound by data processing agreements.
- Affiliates: We may share data within the Picus affiliates to support global service delivery and operations.
- Legal & Regulatory Authorities: We may disclose your information if required by law, court order, or governmental request, or to protect the rights, property, and safety of Picus, our users, or the public.
- Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, personal data may be transferred to the acquiring entity.
5. COOKIES
Cookies are small files or identifiers placed on your device when you visit our websites. They enable us to recognize your device, facilitate navigation between pages, enhance user experience, and maintain the security and functionality of our platforms
We use cookies on our Websites (www.picussecurity.com and app.picussecurity.com) to track user preferences, improve user experience, and conduct behavioral advertising.
For detailed information, including how to manage your preferences, please visit our Cookie Policy.
6. INTERNATIONAL DATA TRANSFERS
As a globally operating company hosted on cloud-based infrastructure, personal data may be transferred to and processed in countries outside of your jurisdiction (such as the United States).
We ensure that such transfers comply with applicable data protection laws. Regardless of the destination, we utilize legally recognized transfer mechanisms, including the European Commission’s Standard Contractual Clauses (SCCs), where applicable, to guarantee an adequate level of data protection.
7. DATA SECURITY AND RETENTION
We implement robust technical and organizational measures to protect your personal data and prevent unauthorized access, disclosure, use, or modification. At Picus, we utilize industry-standard technologies, operational security methods, and cyber security solutions, including access controls, encryption, and monitoring mechanisms, for the protection of personal data.
In this context, we regularly review and validate the adequacy and effectiveness of our security controls, tools, and procedures to maintain a secure environment. Please note that no security measures are completely secure. For more information, please see our Corporate Practices.
Picus retains personal information only for the period necessary to fulfill the purposes for which it was collected. Thereafter, personal data may be retained for a reasonable period to comply with audit, contractual, or legal obligations, or where we have a legitimate interest in retaining it.
Retention periods are determined based on the type of personal data and the nature of the processing. When personal data is no longer required for these purposes, it is securely deleted, destroyed, or anonymized in accordance with applicable laws and our internal policies.
Adequate technical and administrative measures have been implemented within our Information Security Management System to ensure secure storage and destruction of personal information.
8. YOUR RIGHTS
We respect your privacy and your rights under applicable data protection laws, including the GDPR, CCPA, and KVKK. Depending on your jurisdiction and the nature of our processing, your rights may include:
Right to Access: Request a copy of the personal data we hold about you.
Right to Rectification: Request the correction of inaccurate or incomplete personal data.
Right to Erasure (“Right to be Forgotten”): Request the deletion of your personal data under certain conditions.
Right to Restriction of Processing: Request that we limit how we use your data.
Right to Data Portability: Request the transfer of your data to another organization or directly to you.
Right to Object: Object to the processing of your data based on legitimate interests or for direct marketing purposes.
Withdrawal of Consent: Where processing is based on your consent, you have the right to withdraw it at any time.
To exercise any of these rights, please fill out the initial request form here so that we can provide you the appropriate data subject request form depending on the legal source of your request.
9. CHILDREN AND SENSITIVE DATA
- Children: Our Website, application, and services are intended for business use and we do not expect them to be of any interest to minors. We do not knowingly or intentionally collect personal data from anyone under 16 years of age.
- Sensitive data: We do not collect or receive any sensitive categories of personal data. We explicitly request that you do not send or disclose any sensitive personal information to us, whether directly or through our products, AI features, or support channels.
10. CONTACT US
If you have any questions or concerns regarding this Policy or our data protection practices, please contact us at privacy@picussecurity.com.
11. AFFILIATES
Picus Affiliates covered by this Policy include Picus Security, Inc., Picus Bilişim Güvenlik Ticaret A.Ş., and Picus Security US, LLC.
12. CHANGES TO THIS PRIVACY POLICY
We review this Privacy Policy regularly and may change it to reflect our product and service updates, corporate practices, regulatory requirements, or other purposes.
We encourage you to frequently check this page as the "Last Updated" date at the top of this Policy indicates the most recent modifications. For significant changes, we will provide a more prominent notice, such as via email or a notification within our platform, as required by applicable law.
Last Updated: 24.03.2026
INTRODUCTION
Picus Security Inc., along with its affiliates, Picus Bilişim Güvenlik Tic. A.Ş. and Picus Security US, LLC (“Picus Security” or “Company”), may collect and process personal data for various purposes through cookies on our websites www.picussecurity.com and app.picussecurity.com (“Websites”).
This Cookie Policy explains what cookies are, how we use them, the legal basis for processing your data, and how you can manage your preferences in compliance with applicable data protection laws. When you visit our Websites, a cookie consent banner allows you to manage these preferences directly. For more information on how we collect, store, and use your personal data, please refer to our Privacy Policy.
Please note that this policy may be updated from time to time to reflect changes in technology, legal requirements, or our Company's data practices.
WHAT ARE COOKIES?
Cookies are small text files placed on your device when you visit a website. They act as a digital memory for your browser, allowing our Websites to recognize your device on subsequent visits and remember your preferences.
These files may store or retrieve information on your browser to ensure our Websites function properly, enable security features, and provide analytics or advertising insights. In addition to cookies, we may use similar technologies such as pixels, tags, or scripts for these purposes.
Cookies typically contain data such as a unique identifier, session information, or user preferences.
Cookies do not typically directly identify you, such as by name or contact details. However, they may contain unique identifiers or other data that, when combined with other information we collect, could be used to recognize or remember you across different sessions or websites. In such cases, this information may be considered personal data under applicable data protection laws and will be processed in accordance with our Privacy Policy.
By making websites work more efficiently, cookies enhance your user experience and provide essential information to website owners.
WHY WE USE COOKIES
At Picus Security, we use cookies and similar technologies to operate our Websites, maintain security, understand how our Websites are used, remember user preferences, and, where applicable, support advertising and marketing activities.
Depending on their purpose, cookies may be used to:
- Ensure the security and proper functioning of our Websites
- Enable core features and improve usability
- Analyze usage and performance of our Websites
- Personalize content and support marketing activities
Legal Basis: “Necessary” cookies are used based on our legitimate interest in operating and securing our Websites.
Where required by applicable law, analytics, functionality, and advertising cookies are used only with your consent.
COOKIE CATEGORIES
We categorize cookies based on their purpose to provide transparency on how your data is processed:
Necessary Cookies: These cookies are essential for the operation, security, and accessibility of our Websites. They enable core functionalities such as page navigation, authentication, and secure access. As these cookies are required for the Websites to function, they do not require user consent and cannot be switched off in our systems.
Analytics Cookies: These cookies collect aggregated and statistical information about how visitors interact with the Websites. They help us understand usage patterns, identify usability issues, and improve performance.
Advertising Cookies: These cookies are used to deliver relevant advertisements and measure the effectiveness of our marketing campaigns. They may track your browsing activity across different websites and services.
Functional Cookies: These cookies are optional for the website to function. These cookies allow the Websites to remember user preferences and settings (such as language or region) to personalize your experience.
COOKIE SOURCES
Cookies may also be categorized depending on who implements them:
First-Party Cookies: These cookies are issued directly by our Websites and are used to support core functionality, performance, and user experience within our domain.
Third-Party Cookies: These cookies are set by third-party service providers that support analytics, advertising, and certain functionalities of the Websites.
Third-party providers may collect information about your browsing behavior across multiple websites and use such data to:
- Analyze usage and performance,
- Deliver targeted advertisements, and
- Measure the effectiveness of marketing campaigns.
The processing of data by such third parties is governed by their respective privacy policies.
We use both third-party cookies and our cookies to show you personalized ads on various websites. This practice, known as "retargeting", is based on your clicks, the pages you browse on our Websites, the products you view, and the advertisements that are shown to you. We also use cookies as part of our online marketing campaigns to understand how users interact with our Websites after seeing online ads, including those displayed on third-party websites.
You can manage your preferences or withdraw your consent for non-essential cookies at any time through the cookie settings available on our Websites. Additionally, most web browsers allow you to control or delete cookies through their settings.
For more information on third-party providers and their data practices, please refer to the privacy policies listed in Table 1 below.
COOKIE INVENTORY
When you visit our Websites or log in to our Platform (app.picussecurity.com), we use the following services:
Table 1: Advertisement, Analytics/Targeting Cookies Used on our Websites
|
Service Provider |
Applied on (Context) |
Purpose |
Type |
Related Privacy Policies |
|
Google Analytics, Google Tag Manager |
Website & App |
Analytics/Targeting |
First-party |
|
|
Hotjar |
Website & App |
Analytics/Targeting |
First-party |
|
|
Hubspot |
Website |
Analytics/Targeting |
First-party |
Hubspot Privacy Policy, Cookies set in a visitor's browser by HubSpot |
|
Swan |
Website |
Advertisement |
Third-party |
|
|
|
Website |
Advertisement, Analytics/Targeting |
Third-party |
|
|
Poptin |
Website |
Analytics/Targeting |
First-party |
|
|
Youtube |
Website |
Advertisement |
Third-party |
|
|
|
Website |
Advertisement |
Third-party |
|
|
Heap |
App |
Analytics/Targeting |
First-party |
|
|
New Relic |
App |
Analytics/Targeting |
Third-party |
|
|
Userguiding |
App |
Analytics/Targeting |
First-party |
These cookies are not integral to the functioning of our site, and your use and experience of our site will not be impaired by blocking or deleting them. However, certain features of our site may not function fully or as intended.
Our Websites use Google Analytics, an analysis service of Google LLC ("Google") with IP anonymization features. On the other hand, Google Analytics uses cookies to enable the analysis of website usage. The information generated by cookies about the use of the website is transmitted to and stored on a Google server in the USA. Upon the instruction of the operator of this website, Google uses this information to prepare reports to evaluate your use and provide related services. The IP address transmitted from your browser within the framework of Google Analytics is not combined with other data from Google. If you do not want these cookies to be stored, you can adjust your settings accordingly in your browser.
In addition, our website (www.picussecurity.com) may also use Google AdWords and double-click cookies for statistical purposes.
If you think we have missed a cookie, please let us know by sending an email to security@picussecurity.com.
HOW TO CONTROL COOKIES
You have the right to decide whether to accept or reject cookies. You can exercise your preferences through the following methods:
- Cookie Consent Banner: When you first visit our Websites, a cookie consent banner will appear, allowing you to accept all cookies or customize your preferences by opting in or out of specific categories. You can update these settings at any time through our Websites.
- Browser Controls Most web browsers allow you to manage cookies through their settings. You can set your browser to refuse all cookies or to indicate when a cookie is being sent. However, please note that if you disable cookies, certain features of our Websites may not function as intended, and your user experience may be impacted.
- Google Analytics Opt-Out To specifically prevent your data from being used by Google Analytics across all websites, you can install the Google Analytics Opt-out Browser Add-on.
Your choices are browser- and device-specific, so you may need to update your preferences separately on each device and browser you use.
FURTHER INFORMATION ON COOKIES
To learn more about cookies, including how to see which cookies have been set and how to manage and delete them, you can visit the following websites: All About Cookies, About Cookies, Your Choices Online, and Cookie Database.
CONTACT
If you have any questions about our use of cookies, please contact us at security@picussecurity.com.
PICUS SUBSCRIPTION AGREEMENT
IMPORTANT – CAREFULLY READ ALL THE TERMS AND CONDITIONS OF THIS PICUS SUBSCRIPTION AGREEMENT (THE “AGREEMENT”). BY SIGNING AN ORDER FORM INCORPORATING THIS AGREEMENT, CLICKING “I ACCEPT”, CLICKING “CREATE”, PROCEEDING WITH THE INSTALLATION AND/OR ACCESS AND USE OF THE PICUS SOLUTIONS, OR USING THE PICUS SOLUTIONS AS AN AUTHORIZED REPRESENTATIVE OF YOUR COMPANY NAMED ON THE APPLICABLE ORDER FORM ON WHOSE BEHALF YOU INSTALL AND/OR USE THE PICUS SOLUTIONS, YOU ARE INDICATING THAT YOU HAVE READ, UNDERSTOOD, AND ACCEPT THIS AGREEMENT WITH PICUS (AS DEFINED BELOW). IF YOU DO NOT AGREE WITH ALL OF THE TERMS OF THIS AGREEMENT, DO NOT INSTALL, COPY, OR OTHERWISE USE THE PICUS SOLUTIONS. THE EFFECTIVE DATE OF THIS AGREEMENT SHALL BE THE DATE THAT YOU SIGN AN ORDER FORM WITH PICUS OR OTHERWISE ACCEPT THIS AGREEMENT.
Last Updated: April 17, 2026
1. DEFINITIONS. Capitalized terms used in this AGREEMENT shall have the meaning given to them in Schedule 1: Definitions, attached hereto.
2. ORDERS.
2.1. Formation. This AGREEMENT governs the overall relationship of the parties in relation to Customer’s use of the Picus Solutions. Customer is not permitted to use the Picus Solutions until it has recorded its consent to this AGREEMENT via a signed Order Form referencing this Agreement or an electronic acceptance of this Agreement. Each executed Order Form creates a separate Agreement between Picus and Customer. Upon Picus’ written acceptance of the Order Form, Picus or its Partner (as defined below) shall provide Customer with a license certificate evidencing the purchase of the Picus Solutions.
2.2. Informal. Provision of the Picus Solutions, Support, or any other products or services provided by Picus or its Affiliates to Customer or its Affiliates is governed by this AGREEMENT unless otherwise agreed in writing by the parties.
2.3. Affiliate Orders. If an Order Form incorporating this AGREEMENT is executed by an Affiliate of either party, the terms “Customer” and “Picus”, as used in this AGREEMENT, shall be read to mean the applicable Customer Affiliate and/or Picus Affiliate that executed the applicable Order Form.
2.4. Orders through Partners. If Customer purchases the Picus Solutions from or through an authorized distributor, reseller, or managed services provider (each a “Partner”), Customer’s and its Users’ access to and use of the Picus Solutions will be governed by this AGREEMENT. Instead of Customer paying Fees to Picus, Customer will pay applicable amounts to the Partner as agreed upon between Customer and Partner, and Partner will pay Picus the Fees set forth in the applicable Partner Order (defined below). Customer’s order details (e.g., scope of use including Permitted Capacity, Subscription Term, and Fees) will be as stated in the order form placed by Partner with Picus on Customer’s behalf (“Partner Order”). Partner is responsible for the accuracy of such Partner Order. Picus may suspend or terminate Customer’s rights to access and use the Picus Solutions if it does not receive the corresponding payment from Partner. This AGREEMENT is directly between Picus and Customer and governs all use of the Picus Solutions by Customer and its Users. Partners are not authorized to modify this AGREEMENT or make any promises, representations, warranties, or commitments on Picus’s behalf, and Picus is not bound by any obligations to Customer other than as set forth in this AGREEMENT. Picus is not a party to (or responsible under) any separate agreement between Customer and Partner and is not responsible for any Partner’s acts, omissions, products, or services. The amount paid or payable by Partner to Picus for Customer’s use of the Picus Solution under this Agreement will be deemed the amount paid by and due from Customer to Picus under this AGREEMENT.
3. PICUS SOLUTIONS.
3.1. License Grant. Subject to Customer’s compliance with the terms and conditions of the Agreement, including payment of all applicable fees, Picus hereby grants to Customer for its internal business purposes a limited, non-sublicensable, non-exclusive, non-customized, non-transferable, worldwide license, solely during the Subscription Term or Trial Period, as applicable and as set forth in the Order Form, to:
(a) either:
(i) install, execute, and use, or permit Users to install, execute, and use, in object code form only, the Software on Customer-provided infrastructure; or
(ii) access and use the Cloud Service; and
(b) reproduce and use a reasonable number of copies of the Documentation for use with the Picus Solutions.
(c) shall ensure that use of the Picus Platform is subject to the restrictions and limitations contained in this Agreement, including the export control law requirements.
Picus shall own and retain all right, title, and interest in the Picus Solutions and all intellectual property rights inherent therein, including – without limitation – all changes or improvements requested or suggested by Customer, notwithstanding any use of terms such as "purchase", "sale", or the like within this Agreement. Customer agrees that its use of the Picus Solutions will be solely to facilitate satisfaction of its obligations under this Agreement. Should Customer use the Picus Solutions for any other purpose (including Customer's internal or production use), Customer agrees to report such use to Picus, to pay the applicable fee (on a pro-rata basis) for any past use, and to enter into an agreement to purchase a license for the Picus Solutions. Any unauthorized use of the Picus Solutions will be deemed to be a material breach of this Agreement.
3.2. Control Systems.
(a) Upon execution of this Agreement and subject to the terms outlined in this Agreement, Customer may use the Picus Solutions to test the defensive capabilities of the Control Systems that the Picus Solutions are designed to test. The Picus Solutions may not cover all of Customer’s identified Control Systems, and Picus may unilaterally add or remove different Control Systems categories provided by the Picus Solutions.
(b) Customer authorizes Picus to perform Security Validation tests on Control Systems specified by Customer. Picus will provide Customer with the results of any Security Validation tests automatically via the Picus Solutions user interface. The Picus Solutions aim at revealing which threats identified by Customer are blocked and not blocked by the Control Systems used in Customer’s different digital environments, and Customer acknowledges that Security Validation test results may differ for the same security control technology in use in different environments. Picus shall not be held liable if the Picus Solutions fail to discover certain security or configuration shortcomings on the target Control Systems and shall not become subject to any claim and request (including but not limited to compensation, damage, loss, or reimbursement) related to any such failure.
3.3. Trial Versions and Beta Features.
3.3.1. Beta Features. Beta Features may be subject to additional beta terms as provided by Picus from time to time. Picus may, in its sole discretion: (i) cease providing Beta Features at any time; or (ii) cease providing Beta Features free of charge and require Customer to purchase such features for continued use as part of the Picus Solutions. Customer will not attempt to circumvent, dismantle, or otherwise interfere with any time-control disabling functionality in any Beta Feature that causes the Beta Feature to cease functioning.
3.3.2. Trial Versions. Picus may provide the Trial Version free of charge for a time period of two weeks days or such longer period as may be granted by Picus (“Trial Period”). Picus may extend the Trial Period in its sole and exclusive discretion. Picus may immediately terminate Customer’s access to and use of the Trial Version at any time. Picus will have no liability under the Agreement arising out of or related to any use of a Trial Version by Customer or any End User or the deletion of any data generated during the Trial Period. Any use of a Trial Version is solely at Customer’s own risk and may be subject to additional requirements as specified by Picus. Picus is not obligated to provide Support for any Trial Version, and all Trial Versions are provided as-is without warranty. Customer agrees to use the Trial Version in a non-production environment.
3.4. Support. Picus will provide Customer with Support for the Picus Solutions. Customer may obtain Support from Picus by logging a support request in the Picus support portal (currently available at the following URL: https://support.picussecurity.com/) or by sending a support request to the TAC (Technical Assistance Center) team.
3.5. Compliance with Law. In performing its duties hereunder and in any of its dealings with respect to the Picus Solutions, Customer will comply with all applicable international, national, state, regional, and local laws and regulations, including data protection, data privacy, export control, and anti-corruption laws. Picus shall not be responsible for Customer’s compliance with applicable laws. With respect to any Customer Information, the parties acknowledge that, under the EU General Data Protection Regulation (“GDPR”) and applicable personal data protection law, Picus acts as a data processor on behalf of Customer under the GDPR and applicable personal data protection law, and will process such Personal Data solely in accordance with Customer's instructions and the terms of the Data Processing Agreement referenced in Section 10.2(b). Without limiting anything else in this Section 3, Customer represents and warrants that it (i) has all necessary rights and authorizations to disclose, transfer, provide, or cause to be disclosed, transferred, or provided such customer information; and (ii) will provide any required notice to and obtain any required consent from data subjects and other third parties to the transfer to and Processing by Picus of such customer information. Picus will process such customer information as part of its provision of the Picus Solution and any related Support and maintenance activities and services, and as otherwise stated in Picus Privacy Policy as may be updated from time to time by Picus. A current version of which is located here: https://www.picussecurity.com/trust-center/privacy-security
4. ADDITIONAL CUSTOMER RESPONSIBILITIES.
Customer: (i) must keep its passwords secure and confidential and use industry-standard password management practices; (ii) is solely responsible for the Content and all activity conducted through its account within the Picus Solutions; (iii) must use commercially reasonable efforts to prevent unauthorized access to its account and notify Picus promptly of any such unauthorized access; (iv) may use the Picus Solution only in accordance with the Documentation and applicable law; (v) is responsible for its Users’ compliance with the terms of the Agreement; and (vi) must not exceed the Permitted Capacity (defined below).
5. FEES AND PAYMENT.
5.1. Subscription Fees. Fees are due and payable as set forth on the Order Form. Unless otherwise stated on an Order Form, Customer shall timely pay all fees within thirty (30) days of the date of invoice. Payment obligations are non-cancelable, and fees paid are non-refundable. All payments shall be made in the currency stated on the Order Form. Picus may charge interest on overdue amounts at the lesser of 1.5% per month or the maximum legal rate and may charge Customer for any cost or expense arising out of collection efforts. Except as provided below in Subsection 5.2 (Permitted Capacity), there will be no fee increases during Customer’s Subscription Term; however, Customer’s fees are subject to increase upon renewal (including any auto-renewal) following expiration of the then-current Subscription Term that any such increase shall not exceed the greater of (i) five percent (5%) of the fees in effect during the immediately preceding Subscription Term, or (ii) the percentage change in the U.S. Consumer Price Index (All Urban Consumers, CPI-U) for the twelve (12) months preceding the renewal date.
5.2. Permitted Capacity. Customer understands that its right to use the Picus Solutions is limited by the Permitted Capacity purchased. Customer and its Affiliate's combined use may in no event exceed the Permitted Capacity authorized under the applicable Order. The Permitted Capacity may be defined during the registration process or on an Order Form. Customer may submit a request to increase Permitted Capacity at any time, and, upon execution of an Order Form, Customer will pay fees due for such increase at a prorated amount for the remainder of Customer’s then-current Subscription Term. Any Order Form for such an increase will renew concurrently with Customer’s then-current Subscription Term for a period equal to Customer’s initial Subscription Term.
5.3. Taxes. All fees are exclusive of Taxes (as defined below), and Customer shall pay or reimburse Picus for all Taxes arising out of transactions contemplated by this Agreement. If Customer is required to withhold any Tax for payments due, Customer shall gross up its payments to Picus so that Picus receives sums due in full, free of any deductions. As reasonably requested, Customer will provide documentation to Picus showing that Taxes have been paid to the relevant taxing authority. “Tax(es)” means any sales, VAT, GST, use, withholding, or other taxes (other than taxes on Picus’s income), export and import fees, customs duties and similar charges imposed by any government or other authority. Customer hereby confirms that Picus can rely on the name and address that Customer provides to Picus when Customer agrees to the fees or in connection with Customer’s payment method as being the place of supply for sales tax and income tax purposes or as being the place of supply for VAT or GST purposes where Customer has established its business.
6. CONFIDENTIAL INFORMATION.
As used in this Agreement, “Confidential Information” means any nonpublic information or materials disclosed under this Agreement by either party to the other party, either directly or indirectly, in writing, orally, or by inspection of tangible objects, which the disclosing party clearly identifies as confidential or proprietary. Picus’s Confidential Information includes the Picus Solutions and any information or materials relating to the Picus Solutions (including pricing), or otherwise. Confidential Information may also include confidential or proprietary information disclosed to a disclosing party by a third party.
The receiving party will: (i) hold the disclosing party’s Confidential Information in confidence and use reasonable care to protect the same; (ii) restrict disclosure of such Confidential Information to those employees or agents with a need to know such information and who are under a duty of confidentiality respecting the protection of Confidential Information substantially similar to those of this Agreement; and (iii) use Confidential Information only for the purposes for which it was disclosed, unless otherwise set forth in this Agreement. The restrictions will not apply to Confidential Information, excluding Personal Data, to the extent it: (i) is (or through no fault of the recipient, has become) generally available to the public; (ii) was lawfully received by the receiving party from a third party without such restrictions; (iii) was known to the receiving party without such restrictions prior to receipt from the disclosing party; or (iv) was independently developed by the receiving party without breach of this Agreement or access to or use of the disclosing party’s Confidential Information.
The receiving party may disclose Confidential Information to the extent the disclosure is required by law, regulation, or judicial order, provided that the receiving party will provide to the disclosing party prompt notice, where permitted, of such order and will take reasonable steps to contest or limit the steps of any required disclosure. The parties agree that, in addition to any other relief to which the non-breaching party may be entitled, any material breach of this Section 6 will cause irreparable injury and the non-breaching party may seek injunctive relief in a court of competent jurisdiction without the need of posting bond.
7. RESTRICTIONS. Except as expressly set forth in the Agreement, and to the maximum extent permitted by applicable law, Customer will not (and will not allow any third party to): (i) decompile, disassemble, reverse engineer, or otherwise attempt to derive the structure of the Picus Solutions or the source code from the Picus Solutions; (ii) download or export the threat or attack libraries/codes from Picus Solutions; (iii) distribute, license, sublicense, assign, transfer, provide, lease, lend, rent, disclose, use for timesharing or service bureau purposes, or otherwise use for the benefit of any third party the Picus Solutions (iv) use or access the Picus Solutions in order to build a similar or competitive product or service or to disclose to any third party any benchmarking or comparative study involving the Picus Solutions; (v) modify, adapt, translate, or create derivative works of the Picus Solutions or Documentation; (vi) remove, alter, or obscure in any way any proprietary rights notices (including copyright notices) of Picus or its suppliers on or within the Picus Solutions or Documentation; or (vi) use the Picus Solutions on any hardware or other system not owned by Customer.
8. TERM AND TERMINATION.
8.1. Subscription Term. Subject to the termination rights set forth herein, the term of this AGREEMENT will commence on the Effective Date and will continue as long as the Picus Solutions is being provided to Customer under an Order Form. Unless otherwise agreed in the Order Form, the Subscription Term stated on an Order Form will automatically renew for successive terms of 12 months each unless either party gives the other party written notices of non-renewal not less than 45 calendar days before the expiration of the then-current Subscription Term.
8.2. Termination for Material Breach. Customer may terminate this Agreement immediately without further notice if Picus materially breaches its obligations under the Agreement and does not remedy such breach within 30 calendar days of receiving written notice of such breach from Customer. Picus may terminate an affected Order Form, all Order Forms, or the Agreement in place between Picus and Customer immediately without further notice if Customer materially breaches its obligations under the Agreement and does not remedy such breach within 30 calendar days of receiving written notice of such breach from Picus.
8.3. Termination for Dissolution, Bankruptcy. Subject to applicable law, either party may immediately terminate the AGREEMENT and/or any Order Form on written notice if the other party enters compulsory or voluntary liquidation or reorganization, enters into an assignment for the benefit of the creditors, ceases to carry on business, or takes or suffers any similar action which the other party reasonably believes means that it may be unable to pay its debts.
8.4. Parties’ Rights After Expiration or Termination. Expiration or termination of all or part of the Agreement shall not affect any accrued rights, remedies, obligations, or liabilities of the parties. Nothing in this Agreement shall constitute a waiver or limitation of any rights that Picus may have under applicable law. Customer may only use the Picus Solutions during the period for which Customer has paid the subscription fee.
8.5. Upon the Termination of an Applicable Order Form. Upon termination of an applicable Order Form: (i) the licenses granted under the Order Form for the Picus Solutions will immediately terminate, and Customer and its Users will immediately cease use of the Picus Solutions; (ii) Picus’s obligations to provide Support will immediately terminate; (iii) in the event of a termination for Customer’s breach of the Agreement, Customer will pay to Picus the full amount of any outstanding fees due hereunder; (iv) in the event of a termination for Picus’s breach of the Agreement, Picus will refund to customer the pro-rata amount of any prepaid but unused fees; (v) for Cloud Service Customers, Customer may request that Picus delete the Content belonging to Customer; and (vi) on Customer’s request, Picus will destroy, anonymize, inaccessible, or return all Customer Confidential Information in its possession or control and will not make or retain any copies of such information in any form, except that Picus may retain one archival copy of such information solely to ensure compliance with the Agreement; in the context of statistical/benchmark result analyzes that cannot be directly linked to the Customer or as required by applicable law or regulation.
8.6. Customer Acknowledgment. CUSTOMER ACKNOWLEDGES AND AGREES THAT THE PICUS SOLUTIONS MAY CONTAIN DISABLING CODE THAT (EITHER AUTOMATICALLY OR AT PICUS’S CONTROL) WILL RENDER THE PICUS SOLUTIONS (AND RELATED DATA) UNUSABLE UPON TERMINATION OR CUSTOMER’S BREACH OF THE AGREEMENT AND FAILURE TO CURE WITHIN 30 DAYS OF RECEIVING NOTICE OF SUCH BREACH FROM PICUS.
8.7. Survival. Sections 3 (Picus Solutions), 4 (Additional Customer Responsibilities), 5 (Fees a Payment), 6 (Confidential Information), 7 (Restrictions), 8 (Term and Termination), 9 (Proprietary Rights), 12 (Indemnification), 13 (Limitation on Liability), and 19 (Miscellaneous) shall survive any termination or expiration of this Agreement, along with any other provisions which by their express terms do survive or by their nature should survive.
9. PROPRIETARY RIGHTS. The Picus Solutions, Picus Content, and Picus Marks are licensed, not sold, under the terms of this Agreement. Use of “purchase” in conjunction with licenses under this Agreement does not imply a transfer of ownership. Except for the limited rights expressly granted by Picus to Customer under this Agreement, Customer acknowledges and agrees that all right, title, and interest in and to all copyrights, trademarks, patents, trade secrets, intellectual property (including without limitation algorithms, business processes, improvements, enhancements, modifications, derivative works, and information collected and analyzed in connection with the Picus Solutions), and other proprietary rights arising out of or relating to the Picus Solutions, Picus Content, and Picus Marks, and the provision of each, belong exclusively to Picus or its suppliers or licensors. All right, title, and interest in and to content which may be accessed through the Picus Solutions is the property of the respective owner and may be protected by applicable intellectual property laws and treaties. The Picus Solutions may include software products licensed from third parties ("Third Party Components”). Licensors of any Third Party Components shall have no obligations or liability to Customer under this Agreement but are third-party beneficiaries of this Agreement. All rights not expressly granted to Customer under this Agreement are reserved by Picus, and this Agreement does not grant any implied rights to the Picus Solutions, Picus Content, Picus Marks, or Third Party Components.
10. DATA SECURITY AND PRIVACY.
10.1. Content. Customer-owned Content remains the property of Customer. Customer represents and warrants to Picus that Customer has provided all required notices and has obtained all required licenses, permissions, and consents regarding Content for use within the Picus Solution. Customer grants Picus a perpetual, transferrable, worldwide, fully paid, royalty-free right and license to use the Content in accordance with this Agreement.
For the purposes of this Agreement, Customer Content includes data generated, provided, or collected during customer interactions with the Picus Platform, including but not limited to simulation and analytics results, as well as data gathered from customer actions through Picus products and services. Picus retains simulation run data, as part of Content data, for a limited duration in accordance with its data retention policies. Data exceeding this period will be deleted as part of routine data management. The security requirements stated in Section 10 constitute the sole contractual obligations of Picus regarding the handling, use, and security of Customer Content.
10.2. Data Security Measures and Data Processing Addendum.
(a) Security Measures. Picus (i) implements and maintains reasonable security measures appropriate to the nature of the Content including, without limitation, technical, physical, administrative, and organizational controls designed to maintain the confidentiality, security, availability, and integrity of Content; (ii) implements and maintains industry standard systems and procedures for detecting, preventing, responding to attacks, intrusions, or other systems failures and regularly tests or otherwise monitors the effectiveness of the safeguards’ key controls, systems, and procedures; (iii) designates an employee or employees to coordinate implementation and maintenance of its security measures (as defined below); and (iv) identifies reasonably foreseeable internal and external risks to the security, confidentiality, availability, and integrity of Content that could result in the unauthorized disclosure, access, misuse, alteration, destruction, or other compromise of such information.
(b) Data Processing Agreement. When legally required, the parties agree to comply with the terms of Picus’s Data Processing Agreement (the “DPA”); and also Policies that are presently found at the following URL: https://www.picussecurity.com/trust-center/ as may be periodically updated by Picus.
(c) Customer User Information. With respect to any User Information, the parties acknowledge that, under the terms of the DPA, Picus is a data processor for End User Information and will maintain and otherwise Process such Personal Information according to its own policies, procedures, and DPA requirements. Without limiting anything else in this Section, Customer represents and warrants that it (i) has all necessary rights and authorizations to disclose, transfer, provide, or cause to be disclosed, transferred, or provided, such User Information; (ii) will provide any required notice to and obtain any required consent from Users and other third parties to the transfer to and Processing by Picus of such User Information. Picus will Process such User Information as part of its provision of the Picus Solutions and any related Support services and as otherwise stated in Picus Privacy Policy, as may be updated regularly by Picus (the current version of which is located here: https://www.Picussecurity.com/trust-center/).
10.3. Statistical Data. Picus may utilize Content and other data, results, and analytics (“Statistical Data”) to improve the Picus Solutions for marketing and product improvement purposes and to manage its license models. To the extent used for external marketing purposes, Statistical Data will be aggregated and anonymized and will not identify Customer, its Users, or any natural person.
10.4. Cookies. Whenever Customer or Users interact with the Picus Solutions or Picus websites, Picus automatically receives and records some technical and usage information on its server logs from the browser or device, which may include user activities, IP address, and the type of browser and/or device being used to access the Picus Solutions or Picus websites, as further described in the Cookies Policy (the current version of which is located here: https://www.picussecurity.com/trust-center/).
10.5. ARTIFICIAL INTELLIGENCE AND AUTOMATED FEATURES
10.5.1. AI Features Scope. If applicable, Picus Platform may include features powered by artificial intelligence, machine learning, and automated orchestration (e.g., generative AI capabilities, threat simulation builders, and automated remediation guidance) (collectively, “AI Features”). These AI Features are integrated components of the Picus Platform and are subject to the terms of this Agreement, including the security and privacy obligations set forth in Section 10. Notwithstanding any warranties in Section 11.1 or Schedule 2, all AI Features are provided strictly on an "AS IS" and "AS AVAILABLE" basis.
10.5.2. Usage Limits and Modifications. Customer acknowledges that AI Features may be subject to capacity constraints and usage limits, including but not limited to prompt, query, or token limits, which may be dynamically adjusted by Picus. Picus reserves the right, in its sole discretion, to impose, modify, or enforce such limits, or to alter, suspend, or deprecate specific AI Features or their functionalities at any time, to ensure the optimal performance, stability, and security of the Picus Solutions.
10.5.3. Data Protection and Model Training. To provide the AI Features, Picus adheres to the following enterprise-grade commitments regarding Customer Content and Confidential Information:
(a) No Foundational Training: Picus shall not use Customer’s Content, Confidential Information, or specific prompts to train, retrain, or fine-tune foundational AI models for the benefit of other customers or third parties.
(b) Enterprise Third-Party Providers: Where Picus utilizes third-party AI service providers (e.g., enterprise API services), such processing shall be conducted within secure environments. Picus ensures that such third-party providers are contractually prohibited from using Customer’s Content or Confidential Information to train their own artificial intelligence models.
(c) Transient Processing: Customer acknowledges that the processing of prompts and contextual data by AI Features may require transient data handling, which shall be strictly governed by Picus’s data security measures outlined in Section 10.2.
10.5.4. Feedback and Improvements. Notwithstanding Section 10.5.3, Customer may provide feedback, ratings, or suggestions regarding the AI Features ("Feedback"). Customer agrees that Picus may use such Feedback to improve the performance, accuracy, and security of its AI Features, provided that such use does not disclose Customer Content or Confidential Information to any third party.
10.5.5 . Outputs and Customer Responsibility. AI Features may generate recommendations, attack simulations, scripts, or remediation guidance (collectively, “Outputs”). Customer acknowledges that AI Technology is probabilistic by nature; therefore, Outputs are provided "AS-IS" for informational and operational assistance purposes only. Picus does not warrant that Outputs will be entirely error-free, accurate, or unique to Customer. Customer is solely responsible for independently reviewing, testing, and validating all Outputs prior to implementing them within its Control Systems or production environments. Picus assumes no liability for any action or inaction taken by Customer based solely on such Outputs.
10.5.6 . Ethical AI and Compliance. Picus will use commercially reasonable efforts to maintain internal policies and procedures for the ethical, transparent, and responsible development of its AI Features, designed to align with generally accepted industry security standards (such as SOC 2 Type II or equivalent). Customer shall not use the AI Features to: (i) develop foundation models or other large scale models that compete with Picus; (ii) reverse assemble, reverse compile, or otherwise attempt to discover the source code or underlying components of the AI Features; or (iii) use the Outputs to train competing automated security simulation tools.
11. WARRANTY AND DISCLAIMERS.
11.1. Picus Warranty.
(a) Picus warrants that for the duration of the Term: (i) it will not materially decrease the overall security of the Picus Solutions; (ii) it will not materially decrease the overall functionality of the Picus Solutions; (iii) the Picus Solutions will perform substantially in conformance with the Documentation; (iv) Picus will maintain all necessary licenses, consents, and permissions for performance of its obligations under the Agreement; and (v) it uses commercially reasonable efforts consistent with industry standards to regularly scan for and remove any Malware from the Picus Solutions. Customer acknowledges that the foregoing is null and void to the extent the Picus Solutions: (i) fail to conform with this warranty because of Customer’s use with any third-party hardware or software other than as authorized by Picus in the Documentation; (ii) are used other than in accordance with its published Documentation; or (iii) are used in breach of the Agreement. If the Picus Solutions do not conform with the warranties stated in this Subsection 11.1(a), then Customer’s sole remedy, and Picus entire liability, is to correct the non-conformance promptly.
(b) Availability SLA. Picus warrants that it will maintain the availability of the Cloud Service as provided in the Availability SLA attached hereto as Schedule 2.
11.2. Customer Warranty. Customer warrants that it has the full right, power, and authority to consent to the use the Picus Solutions to perform the Security Validation tests of the Control Systems set as target systems by Customer or its representatives.
11.3. Picus Warranty Disclaimer. EXCEPT AS EXPRESSLY PROVIDED IN THIS AGREEMENT, THE PICUS SOLUTIONS, PICUS CONTENT, PICUS MARKS, SUPPORT, AND ALL OTHER PRODUCTS AND SERVICES PROVIDED HEREUNDER OR MADE AVAILABLE UNDER THIS AGREEMENT, INCLUDING THIRD PARTY HOSTED SERVICES OR SOFTWARE (COLLECTIVELY, FOR THE PURPOSES OF THIS PARAGRAPH, “PRODUCTS”), ARE PROVIDED ON AN “AS IS” AND “AS AVAILABLE” BASIS. TO THE MAXIMUM EXTENT PERMITTED UNDER APPLICABLE LAW, PICUS DISCLAIMS AND EXCLUDES ALL REPRESENTATIONS AND WARRANTIES OF ANY KIND, EXPRESS, IMPLIED, OR STATUTORY, INCLUDING ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, RELIABILITY, SECURITY, LOSS OR CORRUPTION OF DATA, CONTINUITY, OR ABSENCE OF DEFECT RELATING TO THE PRODUCTS OR THE RESULTS OF THE SAME. PICUS DOES NOT WARRANT THAT THE PRODUCTS, INCLUDING ANY SPECIFICATIONS OR FUNCTIONS CONTAINED IN THEM, WILL MEET END USERS’ REQUIREMENTS, THAT THE PRODUCTS WILL BE ERROR-FREE, OR THAT DEFECTS IN THE PRODUCTS WILL BE CORRECTED.
12. INDEMNIFICATION
12.1. By Picus. Subject to Subsection 12.3 (Process), Picus will, at its cost and expense, indemnify and hold Customer harmless from any third party claim brought against Customer alleging that Customer’s authorized use of the Picus Solutions provided by Picus to Customer pursuant to this Agreement infringes or misappropriates any U.S. patent, copyright, trademark, trade secret, or other intellectual property rights of a third party, provided: (i) Customer’s use of the Picus Solutions complies with this Agreement; (ii) the infringement or misappropriation is not caused by modification or alteration of the Picus Solutions or Documentation; (iii) the infringement or misappropriation was not caused by a combination or use of the Picus Solutions with products or software not supplied by Picus; and/or (iv) the infringement or misappropriation is not caused by Customer’s negligence or willful misconduct. This Section states Picus’s entire liability (and shall be Customer’s sole and exclusive remedy) with respect to indemnification by Picus to Customer. If a claim under this Section occurs, or in Picus’s opinion appears reasonably likely to occur, then Picus may at its expense and in its sole discretion: (i) modify the Picus Solutions to become non-infringing; (ii) procure the necessary rights to allow Customer to continue using the Picus Solutions; (iii) replace the Picus Solutions with a functional equivalent; or (iv) if neither (i) through (iii) are commercially practicable, terminate the Picus Solutions and refund any prepaid and unused fees.
12.2. By Customer. Subject to Subsection 12.3, Customer will, at its cost and expense, indemnify, defend, and hold Picus and its directors and employees harmless from and against any and all losses arising from or in connection with (a) the performance of its obligations under this Agreement or a breach of this Agreement; (b) any allegation that Customer infringed upon or misappropriated any patent, copyright, trademark, or other intellectual property right of a third party; (c) any allegation that Customer infringed upon or misappropriated any Picus intellectual property; or (d) the gross negligence or willful misconduct of Customer.
12.3. Process. If the indemnified party receives notice of a claim that is covered by this Section 12, the indemnified party shall give the indemnifying party prompt written notice such claim, provided that failure to give prompt notice shall not relieve a party of its obligations under this Section unless such failure materially prejudices the claim. The indemnifying party shall be allowed to solely conduct the defense of the matter, including choosing legal counsel to defend the claim, provided that the choice is reasonable and is communicated to the indemnified party in advance. The indemnified party shall comply with the indemnifying party’s reasonable requests for assistance and cooperation in the defense of the claim. The indemnifying party may not settle the claim without the indemnified party’s consent, which may not be unreasonably withheld, delayed, or conditioned.
13. LIMITATION OF LIABILITY.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT WILL PICUS, ITS AFFILIATES, OR ITS OR THEIR DIRECTORS, EMPLOYEES, AGENTS, OR LICENSORS HAVE ANY LIABILITY, CONTINGENT OR OTHERWISE, FOR ANY INDIRECT, SPECIAL, INCIDENTAL, CONSEQUENTIAL, PUNITIVE, STATUTORY, OR EXEMPLARY DAMAGES, INCLUDING, BUT NOT LIMITED TO, LOST PROFITS, LOST OR CORRUPTED DATA, LOSS OF GOODWILL, WORK STOPPAGE, EQUIPMENT FAILURE OR MALFUNCTION, PROPERTY DAMAGE, OR ANY OTHER ECONOMIC DAMAGES OR LOSSES ARISING OUT OF OR RELATING TO THIS AGREEMENT, THE PICUS SOLUTIONS, PICUS CONTENT, PICUS MARKS, OR ANY OTHER PRODUCTS OR SERVICES PROVIDED HEREUNDER, EVEN IF THEY HAVE BEEN ADVISED OF THE POSSIBILITY THEREOF, AND REGARDLESS OF THE LEGAL OR EQUITABLE THEORY (CONTRACT, TORT (INCLUDING NEGLIGENCE), STATUTE, INDEMNITY, OR OTHERWISE) UPON WHICH ANY SUCH LIABILITY IS BASED.
THE AGGREGATE LIABILITY OF PICUS, ITS AFFILIATES, AND ITS DIRECTORS, EMPLOYEES, LICENSORS, SUPPLIERS, AND AGENTS SHALL BE LIMITED TO DAMAGES NOT TO EXCEED THE TOTAL AMOUNT PAYABLE OR PAID TO PICUS UNDER THIS AGREEMENT DURING THE TWELVE (12) MONTHS PRIOR TO THE EVENT GIVING RISE TO THE CLAIM.
14. FUTURE FUNCTIONALITY. Customer agrees that it has not relied on the availability of any future functionality of the Picus Solutions or any other future product or service in executing the Agreement. Customer acknowledges that information provided by Picus regarding future functionality should not be relied upon to make a purchase decision.
15. GOVERNMENT LICENSES. For purposes of sales to government entities in the United States, the Picus Solutions and the accompanying Documentation are deemed to be “commercial computer software” and “commercial computer software documentation”, respectively, pursuant to DFARS Section 227.7202 and FAR Section 12.212(b), as applicable. Any use, modification, reproduction, release, performing, displaying, or disclosure of the Picus Solutions or the accompanying Documentation by or for the U.S. Government will be governed solely by the terms and conditions of the Agreement, in conjunction with statutes, regulations, and the terms of the GSA Schedule, if applicable.
16. EXPORT COMPLIANCE AND ANTI-CORRUPTION.
16.1. Picus’s products and services are subject to U.S. export control, sanctions, import compliance, and anticorruption laws and regulations (“Trade Controls”). Customer agrees that it shall not sell, provide access to, license, or transfer any of the Picus’s products or services to any Persons that are: (i) subject to the restriction of a sanctions or export denial list, including, but not limited to, the U.S. Department of the Treasury’s Specially Designated Nationals and Blocked Persons (“SDN”) List maintained by OFAC and the U.S. Department of Commerce’s Bureau of Industry and Security’s (“BIS”) Entity List; (ii) located in, ordinarily resident in, organized under the laws of, or owned or controlled by a region subject to a comprehensive U.S. or other applicable embargo and/or sanctions (presently including Cuba, Iran, Syria, North Korea and the Crimea, Donetsk People’s Republic, Luhansk People’s Republic regions of Ukraine, Afghanistan, Belarus, Myanmar/Burma, Russia, and Venezuela; (iii) engaged in or facilitating end uses prohibited by Trade Controls, including, but not limited to, nuclear, chemical, or biological weapons proliferation, restricted military or military-intelligence users or use, restricted supercomputers or semiconductor development or production in China, missile systems or technology, restricted unmanned aerial vehicle end uses, or any other activities that are prohibited to a U.S. person; (iv) or otherwise acting on behalf or for the benefit of the foregoing. Customer represents and warrants that it is not directly or indirectly owned by, controlled by, a Person in (i)-(iv).
Customer represents and warrants that neither Customer, its Representatives, nor, to Customer’s knowledge, its Affiliate’s Representatives are currently the subject of any investigation by the Office of Foreign Assets Control (OFAC) of the U.S. Department of the Treasury, the Bureau of Industry (BIS) of the U.S. Department of Commerce, or any other governmental authority pursuant to any laws that other governmental authorities administer.
Customer shall promptly notify Picus if it or any of its representatives or its affiliates’ representatives become the subject of any such investigation at trade.compliance@picussecurity.com..
Customer represents and warrants that its use of Picus’s Services will in all respects comply with current U.S. export controls regulations and requirements, including, without limitation, those promulgated by U.S. Departments of State, Commerce, Homeland Security, Treasury, and Defense. Any breach of this Section 16.1 is a material breach of the Agreement for which no cure period shall apply.
16.2. Customer warrants and agrees that it has not received or been offered any illegal or improper bribe, kickback, payment, gift, or thing of value from any Picus employee or agent in connection with the Agreement. Reasonable gifts and entertainment provided in the ordinary course of business do not violate the above restriction.
16.3. If Customer learns of any violation of the above restriction, Customer will promptly notify the Picus legal department at legal@picussecurity.com.
16.4. Customer’s failure to comply with any term of this Section 16 will constitute a material breach of the Agreement and will entitle Picus to immediately terminate the Agreement without notice in addition to any other remedy available at law or equity.
16.5. Customer represents and warrants that it is in compliance with all applicable anti-corruption laws, and that it has not and will not violate any anti-corruption law, including but not limited to the United States Foreign Corrupt Practices Act, the United Kingdom Bribery Act, and any applicable local anti-corruption laws.
Without limiting the foregoing, Customer represents and warrants that it, and its employees, agents, and representatives have not and will not, directly or indirectly, offer, pay, give, promise, or authorize the payment of any money, gift, or anything of value to: (i) any officer, employee or person acting in an official capacity for any government department, agency or instrumentality, including state-owned or state-controlled companies, and public international organizations, as well as a political party or official thereof or candidate for political office (“Government Official”), or (ii) any person while Customer knows or has reason to know that all or a portion of such money, gift, or thing of value will be offered, paid or given, directly or indirectly, to any Government Official, for the purpose of (1) influencing an act or decision of the Government Official in his or her official capacity, (2) inducing the Government Official to do or omit to do any act in violation of the lawful duty of such official, (3) securing an improper advantage, or (4) inducing the Government Official to use his influence to affect, or influence any act or decision of a government or instrumentality, in order to assist Picus or any of its affiliates in obtaining or retaining business. Customer agrees that should it learn or have reason to know of any payment or transfer (or any offer or promise to pay or transfer) in connection with this Agreement or Picus’ business that would violate applicable anti-corruption laws, it must immediately provide Picus with written notice.
17. AUDITS. Customer will keep and maintain written records and accounts regarding Customer’s use of the Picus Solutions and compliance with this Agreement. Picus, or a third-party certified public accounting firm designated by Picus, shall have the right upon fifteen (15) days written notice to Customer to conduct an inspection and audit of all relevant facilities and records of Customer. Such audit shall be conducted during regular business hours at Customer’s offices and in such a manner as not to interfere with Customer’s normal business activities. In no event shall audits be conducted hereunder more frequently than once every 6 months. Any such audit shall be conducted at Picus’s expense; provided, however, that if the audit reveals that Customer has failed to comply with any material term of this Agreement, Customer shall pay all reasonable costs and expenses incurred by Picus in conducting the audit.
18. PICUS SOLUTIONS LIFECYCLE.
18.1. Picus has no obligation to provide Support for any version of the Picus Solutions other than the most current and previous minor release (“Current Version”). Picus shall have no liability for damages resulting from or in connection with Customer’s failure to install and/or use a Current Version. Picus may, in its sole and exclusive discretion, discontinue Support for and retire a non-Current Version (“End of Life”). Picus may publicly post (on its website) a notice of End of Life, including the last date of general commercial availability of the affected version of the Picus Solutions and the timeline for discontinuing Support.
18.2. Due to operation of law, regulation, or to comply with reasonable security standards (e.g., patching a known vulnerability), Picus may require Customer to update to the most current version of the Picus Solution (“Emergency Update”). Picus will clearly communicate the need for usage the Current Versions and any such Emergency Updates. Picus shall have no liability for damages resulting from or in connection with Customer’s failure to implement an Emergency Update or usage of the non-Current Versions.
19. MISCELLANEOUS.
19.1. Publicity. Customer agrees that Picus may publicly disclose that it is providing the Picus Solutions to Customer and may use Customer’s name and logo to identify Customer in our website and promotional materials, provided that Picus does not state or imply that Customer endorses the Picus Solutions.
19.2. Feedback. To the extent Customer or any User provides suggestions or feedback to Picus regarding the functioning, features, or other characteristics of the Picus Solutions, Documentation, or other materials or services provided or made available by Picus (“Feedback”), Customer hereby grants Picus a perpetual, irrevocable, non-exclusive, royalty-free, fully-paid, fully-transferable, worldwide license (with rights to sublicense through multiple tiers of sublicensees) to Picus to use and exploit such Feedback in any manner for the purpose of improving and continuing the development of the Picus Solutions.
19.3. Order of Precedence. Any ambiguity, conflict, or inconsistency between documents comprising the Agreement shall be resolved in the following order of precedence: (i) the AGREEMENT; (ii) any document or URL incorporated into the AGREEMENT; and (iii) the Order Form. Any and all additional or conflicting terms provided by Customer, whether in a purchase order, an alternative license agreement, or otherwise, shall be void and shall have no effect.
19.4. Irreparable Harm. Any breach by a party to the Agreement or any violation of the other party’s Intellectual Property Rights or Confidential Information could cause irreparable injury or harm to the other party. The other party may seek a court order to stop any breach or avoid any future breach of the Agreement.
19.5. Assignment. The Agreement may not be assigned by either party without the prior written approval of the other party, such approval not to be unreasonably withheld, except in connection with: (i) a merger, consolidation, or similar transaction involving (directly or indirectly) a party; (ii) a sale or other disposition of all or substantially all of the assets of a party; or (iii) any other form of combination or reorganization involving (directly or indirectly) such party. Any purported assignment in violation of this Subsection shall be null and void and have no effect.
19.6. Force Majeure. Picus will not be liable for any delay or failure to perform obligations under this Agreement due to any cause beyond its reasonable control, including: acts of God; labor disputes; industrial disturbances; systematic electrical, telecommunications, or other utility failures; earthquakes, storms, or other elements of nature; blockages; embargoes; riots; acts or orders of government; acts of terrorism; war; or any other cause beyond its reasonable control if Picus makes reasonable efforts to perform (“Force Majeure Event”). The Party exposed to force majeure that prevents the fulfillment of its obligations arising from the Agreement immediately notifies the other Party in writing. In this case, the obligations of the Parties are postponed until the end of the force majeure and fulfilled by the Parties as soon as possible following the end of the force majeure. In case the force majeure lasts longer than 30 (thirty) days, the Parties may decide to terminate this Agreement. In order to avoid any doubt, force majeure provisions will not apply in the performance of money debts.
19.7. Relationship of the Parties. Each party is an independent contractor of the other under the Agreement, and nothing in the Agreement shall be construed to create a partnership, joint venture, agency relationship, fiduciary relationship, or any other arrangement related to sharing of profits and losses. Each party is responsible for its own expenses in meeting its obligations under the Agreement. Each party agrees that it has the full power and authority to enter into the Agreement and to carry out the actions contemplated herein.
19.8. Notices. Any notices required under this Agreement will be in writing and will be delivered by electronic mail, personal delivery (with a copy by email), or certified or registered mail (return receipt requested and with a copy by email) to the applicable notice address of the other party as set forth on the signature page below (or to such other notice address that a party may designate by at least ten (10) days’ prior written notice to the other party).
19.9. Waiver and Enforceability. The delay or failure of either party to exercise any right provided in this Agreement shall not be deemed a waiver of that right, nor will any partial exercise of any right or power hereunder preclude further exercises. If any provision of this Agreement is held to be unenforceable, illegal, or void, that shall not affect the enforceability of the remaining provisions. The Parties further agree that the unenforceable provision(s) shall be deemed replaced by a provision(s) that is binding and enforceable and that differs as little as possible from the unenforceable provision(s), with considerations of the object and purpose of this Agreement.
19.10. Governing Law.
(a) If the Customer resides within the United States. The validity, interpretation, and enforcement of this Agreement shall be governed by and construed in accordance with the laws of the State of Delaware of the United States, without regard to any conflict of law provisions, except that the United Nations Convention on the International Sale of Goods and the provisions of the Uniform Computer Information Transactions Act shall not apply to this Agreement. Customer hereby consents to the exclusive jurisdiction of the state and federal courts in Dover, Delaware. Customer hereby waives all rights to trial by jury with respect to any dispute arising out of or relating to this Agreement or the Picus Solutions, Picus Marks, or Picus Content. If Customer has any claim arising out of or relating to this Agreement or the Picus Solutions, Picus Marks, or Picus Content, Customer must bring the claim in an appropriate court as set forth in this Section within two (2) years after Customer’s right to bring the claim accrued. If Picus brings litigation against Customer regarding this Agreement or the Picus Solutions, Picus Marks, or Picus Content, in addition to any other relief to which Picus may be entitled, Picus shall be entitled to recover reasonable attorneys’ fees, expenses, and costs of litigation. If this Agreement is translated into a language other than English and there are conflicts between the translations of this Agreement, Customer agrees that the English version of this Agreement shall prevail and control.
(b) If the Customer resides outside the United States. In the event of any dispute, claim, question, or disagreement arising from or relating to this agreement or the breach thereof, the parties hereto shall use their best efforts to settle the dispute, claim, question, or disagreement. To this effect, they shall consult and negotiate with each other in good faith and, recognizing their mutual interests, attempt to reach a just and equitable solution satisfactory to both parties. If they do not reach such solution within a period of thirty (30) days, then, upon notice by either party to the other, the dispute shall be finally settled under the Rules of Arbitration (the “Rules”) of the International Chamber of Commerce (“ICC”) by three (3) arbitrators designated by the Parties. Each Party shall designate one arbitrator. The third arbitrator shall be designated by the two arbitrators designated by the Parties. If either Party fails to designate an arbitrator within thirty (30) days after the filing of the Dispute with the ICC, such arbitrator shall be appointed in the manner prescribed by the Rules. An arbitration proceeding hereunder shall be conducted in Zurich, Switzerland and shall be conducted in the English language. The decision or award of the arbitrators shall be in writing and is final and binding on both Parties. The arbitration panel shall award the prevailing Party its attorneys’ fees and costs, arbitration administrative fees, panel member fees and costs, and any other costs associated with the arbitration, the enforcement of any arbitration award and the costs and attorney’s fees involved in obtaining specific performance of an award; provided, however, that if the claims or defenses are granted in part and rejected in part, the arbitration panel shall proportionately allocate between the Parties those arbitration expenses in accordance with the outcomes; provided, further, that the attorney’s fees and costs of enforcing a specific performance arbitral award shall always be paid by the non-enforcing Party, unless the applicable action was determined to be without merit by final, non-appealable decision. The arbitration panel may only award damages as provided for under the terms of this Agreement and in no event may punitive, consequential, or special damages be awarded. In the event of any conflict between the Rules and any provision of this Agreement, this Agreement shall govern.
19.11. No Protected Health Information. Customer expressly acknowledge and agree that it shall neither submit to the Picus Solutions, nor use the Picus Solutions to store, maintain, process, or transmit, any data or information that constitutes protected health information as defined under the Health Insurance Portability and Accountability Act of 1996, as amended and supplemented (“HIPAA”), or otherwise use the Picus Solutions in any manner that would require Picus or the Picus Solutions to be compliant with HIPAA. Customer acknowledges and agrees that Picus shall have no liability to Customer for any such data or information. Customer further acknowledges and agrees that neither Picus or its Affiliates are acting on behalf of Customer as a Business Associate (as defined under HIPAA). Picus may immediately and upon notice suspend all or portion of Customer’s access to the Picus Solutions (without any liability to Customer in connection with such suspension), if Picus has a good faith belief that Customer has breached this paragraph.
19.12. Translations Other Than English. The English language version of this Agreement and any documents exchanged pursuant to this Agreement shall be controlling in all respects. Any translations of this Agreement into a language other than English shall have no legal effect and are for the convenience of the parties only.
19.13. No Amendment or Modification. Except as Picus is otherwise permitted to do so under this Agreement, this Agreement shall not be amended or modified except in a writing signed by authorized representatives of each party.
19.14. Cumulative Rights. Picus’s rights and remedies set forth in this Agreement are cumulative and are not intended to be exhaustive.
19.15. Headings. Paragraph headings are for convenience and shall have no effect on interpretation.
19.16. Execution in Counterparts. This Agreement and Order Forms may be executed in counterparts, each of which shall be deemed an original and all of which shall constitute one and the same instrument and Agreement between the parties. The parties may exchange signature pages by delivering a signed, scanned copy by email or via an electronic signature tool such as Adobe Signature, DocuSign, and such copy shall be effective to bind the parties.
19.17. Third Party Rights. Other than as expressly provided herein, this Agreement does not create any rights for any person who is not a party to it, and no person not a party to this Agreement may enforce any of its terms or rely on an exclusion or limitation contained in it.
19.18. Changes to these terms. Picus reserve the right to modify, update, or discontinue the Services and Agreement, or any part of them, at our discretion. The revised Agreement shall become effective upon such publishing or notification to the Customer. Customer will always find the latest version of these Agreement at https://www.picussecurity.com/trust-center/privacy-security. Any continued use by Customer of the Services following publication or notification of revised Agreement shall constitute Customer’s acceptance to the revised Agreement.
19.19. Schedules. All Schedules annexed hereto or referred to herein are hereby incorporated in and made a part of this Agreement as if set forth in full herein.
Schedule 1: Definitions
“Affiliates” means an entity that then is directly or indirectly controlled by, is under common control with, or controls that party, and here “Control” means an ownership, voting, or similar interest representing 50% or more of the total interests then outstanding of that entity.
“Agreement” means the applicable Order Form and this AGREEMENT (including any terms incorporated by reference in the AGREEMENT) which govern the provision of the Picus Solutions and Support provided to Customer or the Customer’s Affiliate.
“Beta Feature(s)” means any Picus Solutions feature that is identified by Picus, including via the applicable Picus Solutions user interface or via other communications to Customer, as “Beta”, “Alpha”, “Experimental”, “Limited Release” or “Pre-Release” or that is otherwise identified by Picus as unsupported.
“Business Days” means Monday through Friday, excluding public holidays in the country whose laws govern the Agreement.
“Cloud Service” means the Picus proprietary software as a service provided for use over the internet and any and all modified, updated, or enhanced versions thereof that Picus may provide to Customer or its Users.
“Content” means data gathered through use of the Picus Solutions or provided for use with the Picus Solutions, wheresoever stored.
“Control Systems” means cybersecurity prevention technologies such as endpoint protection software systems (such as endpoint antivirus, host-based intrusion prevention systems, endpoint detection and response, and other solutions that may be considered as endpoint protection software), secure email gateway, data-leakage or loss systems, network intrusion prevention systems, next-generation firewall systems, secure web gateway systems, and other similar prevention technologies.
“Documentation” means the operating instructions, user manuals, product specifications, “read-me” files, and other documentation that Picus makes available to Customer in hard copy or electronic form for the Picus Solutions, including any modified, updated, or enhanced versions of such documentation.
“Intellectual Property Rights” means all intellectual property rights, including copyrights, trademarks, service marks, trade secrets, patents, patent applications, moral rights, and all other proprietary rights, whether registered or unregistered.
“Malware” means software programs designed to damage or do other unwanted actions on a computer system, including viruses, worms, Trojan Horses, and spyware.
“Order Form” means an order form or other ordering document entered into between Customer and Picus or a Picus Affiliate for Customer’s purchase of the Picus Solutions or other services from Picus.
“Permitted Capacity” means the number of “Security Testing” delivered, term, Picus Agents, threat samples, or other license metrics set forth in the delivery of the service.
“Personal Data” means any information that can be used to identify an individual as that term is defined under Regulation (EU) 2016/679 (“General Data Protection Regulation” or “GDPR”) and under Regulations listed in the Picus Data Processing Addendum.
“Picus” means Picus Security Inc. (1401 Pennsylvania Avenue Unit 105 Suite 104, Wilmington, DE 19806) and its affiliates Picus Bilisim Guvenlik Tic. A.S. (Hacettepe Teknokent, Üniversiteler Mah. 1596. Cad. 1. Ar-Ge 97/12 Beytepe, Çankaya/ Ankara, Türkiye) and Picus Security US, LLC (3001 North Rocky Point Drive East Suite 200 Tampa, FL 33607 USA).
“Picus Agent” means the software component provided for the supported Operating Systems that is used to test the security level of the Control Systems when an assessment is executed.
“Picus Marks” means the trademarks and service marks that are specifically approved by Picus.
“Picus Solutions" or “Picus Platform” means the Picus proprietary programs or products made available to Customer as the Software or Cloud Service, including without limitation its features, modules, reports, results, functions, user interfaces, and related Support services (each as defined below), as specified on an Order Form.
“Process” means access, view, create, generate, amend, disclose, export, import, share, transfer (including across national borders), use, delete, store, combine, or any other activity, action, or process performed upon data or information.
“Software” means the Picus proprietary software provided in executable code form and all modified, updated, or enhanced versions thereof that Picus may provide to Customer or its Users.
“Subscription” means a subscription license purchased by Customer to install or access online and use the Picus Solutions and to receive Support during the applicable Subscription Term.
“Subscription Term” means the contract term for Customer’s access and use of the Picus Solutions as set forth on the applicable Order Form.
“Support” means the standard maintenance or support services provided by Picus for the Picus Solutions.
“Trial Version(s)” means any Picus Solutions version that is provided by Picus on a “Trial”, “Evaluation”, or “Proof of Concept” basis whether or not identified as such by Picus on an Order Form.
“Uptime SLA” means the service level commitments applicable to the Cloud Service attached hereto as Schedule 2.
“User(s)” means Customer’s employees, contractors, or agents (including those of Customer’s Affiliates) who are authorized by the Customer to use the Picus Solutions.
Schedule 2: Service Level Agreement
Picus endeavors to provide the best customer experience during the Subscription Term for Customer’s use of the Picus Solutions. As part of its commitment to meeting its customers’ needs, Picus has established the following Service Level Agreements (SLA) to outline the availability and support standards it maintains.
1. Availability SLA. Picus Security shall use best efforts to maintain a minimum availability for its Cloud Services of 99.5% per month for Users logging in and utilizing the dashboard metrics.
2. Support SLA. During the Subscription Term, Picus will provide Support for all incidents within the supported versions of the Service as further detailed in the Support Services Guide made available by Picus Support on request and as may be updated by Picus from time to time. Picus commits to respond to Support requests in accordance with the following table based on the severity levels of reported problems as determined by Picus in its sole discretion:
|
Severity Level |
Definition |
Initial Response Time |
Next Reply Time |
Periodic Update Time |
|
Urgent (Critical) |
An incident that incidents result in a complete outage of a mission-critical service with no workaround available, causing a severe disruption to business operations. |
2 Business Hours |
2 Business Hours |
4 Business Hours |
|
High |
An incident that is causing a significant loss of service and no workaround is available |
6 Business Hours |
6 Business Hours |
12 Business Hours |
|
Medium |
An incident that has a partial impact on mission-critical functionality |
8 Business Hours |
8 Business Hours |
16 Business Hours |
|
Low |
An incident that has no impact on Customer business functionality |
16 Business Hours |
16 Business Hours |
32 Business Hours |
The Initial Response Time stated above shall be based on the support hours stated in the Support Services Guide and is calculated as the duration before a qualified Support representative contacts the customer or partner in response to a Support request. All Support requests should be sent via the online ticketing system (https://support.picussecurity.com/) and via email the TAC (Technical Assistance Center) team. . If a support case is submitted with a severity level that does not align with the definitions provided above, the assigned TAC Engineer may update the severity level accordingly. Case requesters can track any changes to the severity level directly through the Support Portal.
Please note that the above Picus’ SLAs are subject to periodic review and may be updated to reflect the evolving needs of customers and the development of the Picus Solutions. Customer’s continued use of the Picus Solutions following any such update indicates acceptance of the SLAs in effect at that time.
Support Hours: Support is available 8 hours per day, 5 days a week, including statutory, public, and bank holidays. Our support services are provided in English during standard business hours (9:00–18:00, local time, across global regions). For critical incidents impacting core functionality, Picus may provide out-of-hours support on a best-effort basis. Requests received outside of business hours will be handled on the next business day, in accordance with the priority level and severity of the case.
3. Customer Responsibilities. Customer will comply with the following requirements to facilitate Picus’s delivery of Support:
3.1. Customer will use best efforts to ensure that its use of the Picus Solutions does not harm the Customer computer system on which a Picus Agent is installed.
3.2. Customer will provide Picus timely responses and access to accurate and complete information relative to Support requests.
3.3. Customer is responsible for its own data and applications, and Picus will only Provide support for the Picus Solutions.
3.4. Customer will use the current Picus Solutions version. The customer follows Picus who must provide timely communication and guidance in proactive cases, system/product changes, and emergency updates that will affect the operation of Picus solutions and in possible incident management issues.
4. General Exclusions and Limitations.
4.1. Picus has no obligation to provide Support: (i) outside the scope of the AGREEMENT, Order Form, these terms, or for issues arising out of or in connection with the unauthorized use of the Picus Solutions; (ii) if Customer fails to pay all applicable fees when due; (iii) for issues arising out of or in connection with unauthorized third-party products and services or issues arising exclusively from authorized third-party products and services; (iv) for modifications or changes to the Picus Solution not performed, directed, or authorized by Picus; and (v) for any use of the Picus Solutions in violation of this Agreement.
4.2. Customer acknowledges that Support does not include: (i) developing custom scripts, templates, or tests; (ii) Picus interpretation of any results from the Security Validation tests; or (iii) performing installations, configurations, migrations, or upgrades in any Customer environment.
1. AGREEMENT TO TERMS
Definition
For the purposes of these Terms of Use:
-Affiliate means an entity that controls is controlled by or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest, or other securities entitled to vote for the election of directors or other managing authority.
-Company (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to Picus Security and all its affiliates listed in Section 20.
-Device means any device that can access the Service, such as a computer, a cellphone, or a digital tablet.
-Service refers to the Website.
-Terms of Use (also referred to as "Terms") mean these Terms of Use that form the entire agreement between You and the Company regarding the use of the Service.
-Third-party Social Media Service means any services or content (including data, information, products, or services) provided by a third party that may be displayed, included, or made available by the Service.
-Website refers to PICUS, accessible from (www. picussecurity.com) and (picus.io)
You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
These Terms of Use constitute a legally binding agreement made between you, whether personally or on behalf of an entity (“you”) and Picus Security Inc., doing business as PICUS ("PICUS," “we," “us," or “our”), concerning your access to and use of the http://www.picussecurity.com website as well as any other media form, media channel, mobile website or mobile application related, linked, or otherwise connected thereto (collectively, the “Site”). We are registered in Delaware, United States, and have our registered office at 1401 Pennsylvania Ave Unit 105 STE 104 Wilmington, DE 198063.You agree that by accessing the Site, you have read, understood, and agreed to be bound by all of these Terms of Use. IF YOU DO NOT AGREE WITH ALL OF THESE TERMS OF USE, THEN YOU ARE EXPRESSLY PROHIBITED FROM USING THE SITE AND YOU MUST DISCONTINUE USE IMMEDIATELY.
Supplemental terms and conditions or documents that may be posted on the Site from time to time are hereby expressly incorporated herein by reference. We reserve the right, in our sole discretion, to make changes or modifications to these Terms of Use from time to time. We will alert you about any changes by updating the “Last Updated” date of these Terms of Use, and you waive any right to receive specific notice of each such change. Please ensure that you check the applicable Terms every time you use our Site so that you understand which Terms apply. You will be subject to and will be deemed to have been made aware of and to have accepted the changes in any revised Terms of Use by your continued use of the Site after the date such revised Terms of Use are posted.
The information provided on the Site is not intended for distribution to or use by any person or entity in any jurisdiction or country where such distribution or use would be contrary to law or regulation or which would subject us to any registration requirement within such jurisdiction or country. Accordingly, those persons who choose to access the Site from other locations do so on their own initiative and are solely responsible for compliance with local laws, if and to the extent local laws are applicable.
The Site is not tailored to comply with industry-specific regulations (Health Insurance Portability and Accountability Act (HIPAA), Federal Information Security Management Act (FISMA), etc.), so if your interactions would be subjected to such laws, you may not use this Site. You may not use the Site in a way that would violate the Gramm- Leach-Bliley Act (GLBA).
The Site is intended for users who are at least 18 years old. Persons under the age of 18 are not permitted to use or register for the Site.
2. INTELLECTUAL PROPERTY RIGHTS
Unless otherwise indicated, the Site is our proprietary property and all source code, databases, functionality, software, website designs, audio, video, text, photographs, and graphics on the Site (collectively, the “Content”) and the trademarks, service marks, and logos contained therein (the “Marks”) are owned or controlled by us or licensed to us, and are protected by copyright and trademark laws and various other intellectual property rights and unfair competition laws of the United States, international copyright laws, and international conventions. The Content and the Marks are provided on the Site “AS IS” for your information and personal use only. Except as expressly provided in these Terms of Use, no part of the Site and no Content or Marks may be copied, reproduced, aggregated, republished, uploaded, posted, publicly displayed, encoded, translated, transmitted, distributed, sold, licensed, or otherwise exploited for any commercial purpose whatsoever, without our express prior written permission.
Provided that you are eligible to use the Site, you are granted a limited license to access and use the Site and to download or print a copy of any portion of the Content to which you have properly gained access solely for your personal, non-commercial use. We reserve all rights not expressly granted to you in and to the Site, the Content, and the Marks.
3. USER REPRESENTATIONS
By using the Site, you represent and warrant that: (1) all registration information you submit will be true, accurate, current, and complete; (2) you will maintain the accuracy of such information and promptly update such registration information as necessary; (3) you have the legal capacity and you agree to comply with these Terms of Use; (4) you are not a minor in the jurisdiction in which you reside; (5) you will not access the Site through automated or non-human means, whether through a bot, script, or otherwise; (6) you will not use the Site for any illegal or unauthorized purpose; and (7) your use of the Site will not violate any applicable law or regulation.
If you provide any information that is untrue, inaccurate, not current, or incomplete, we have the right to suspend or terminate your account and refuse any and all current or future use of the Site (or any portion thereof).
4. USER REGISTRATION
You may be required to register with the Site. You agree to keep your password confidential and will be responsible for all use of your account and password. We reserve the right to remove, reclaim, or change a username you select if we determine, in our sole discretion, that such username is inappropriate, obscene, or otherwise objectionable.
5. PROHIBITED ACTIVITIES
You may not access or use the Site for any purpose other than that for which we make the Site available. The Site may not be used in connection with any commercial endeavors except those that are specifically endorsed or approved by us.
As a user of the Site, you agree not to:
-Systematically retrieve data or other content from the Site to create or compile, directly or indirectly, a collection, compilation, database, or directory without written permission from us.
-Trick, defraud, or mislead us and other users, especially in any attempt to learn sensitive account information such as user passwords.
-Circumvent, disable, or otherwise interfere with security-related features of the Site, including features that prevent or restrict the use or copying of any Content or enforce limitations on the use of the Site and/or the Content contained therein.
-Disparage, tarnish, or otherwise harm, in our opinion, us and/or the Site.
-Use any information obtained from the Site in order to harass, abuse, or harm another person.
-Make improper use of our support services or submit false reports of abuse or misconduct.
-Use the Site in a manner inconsistent with any applicable laws or regulations.
-Engage in unauthorized framing of or linking to the Site.
-Upload or transmit (or attempt to upload or to transmit) viruses, Trojan horses, or other material, including excessive use of capital letters and spamming (continuous posting of repetitive text), that interferes with any party’s uninterrupted use and enjoyment of the Site or modifies, impairs, disrupts, alters, or interferes with the use, features, functions, operation, or maintenance of the Site.
-Engage in any automated use of the system, such as using scripts to send comments or messages, or using any data mining, robots, or similar data gathering and extraction tools.
-Delete the copyright or other proprietary rights notice from any Content.
-Attempt to impersonate another user or person or use the username of another user.
-Upload or transmit (or attempt to upload or to transmit) any material that acts as a passive or active information collection or transmission mechanism, including without limitation, clear graphics interchange formats (“gifs”), 1×1 pixels, web bugs, cookies, or other similar devices (sometimes referred to as “spyware” or “passive collection mechanisms” or “pcms”).
-Interfere with, disrupt, or create an undue burden on the Site or the networks or services connected to the Site.
-Harass, annoy, intimidate, or threaten any of our employees or agents engaged in providing any portion of the Site to you.
-Attempt to bypass any measures of the Site designed to prevent or restrict access to the Site, or any portion of the Site.
-Copy or adapt the Site’s software, including but not limited to Flash, PHP, HTML, JavaScript, or other code.
-Except as permitted by applicable law, decipher, decompile, disassemble, or reverse engineer any of the software comprising or in any way making up a part of the Site.
-Except as may be the result of the standard search engine or Internet browser usage, use, launch, develop, or distribute any automated system, including without limitation, any spider, robot, cheat utility, scraper, or offline reader that accesses the Site, or using or launching any unauthorized script or other software.
-Use a buying agent or purchasing agent to make purchases on the Site.
-Make any unauthorized use of the Site, including collecting usernames and/or email addresses of users by electronic or other means for the purpose of sending unsolicited email, or creating user accounts by automated means or under false pretenses.
-Use the Site as part of any effort to compete with us or otherwise use the Site and/or the Content for any revenue-generating endeavor or commercial enterprise.
-Use the Site to advertise or offer to sell goods and services.
-Sell or otherwise transfer your profile.
6. USER GENERATED CONTRIBUTIONS
The Site does not offer users to submit or post content. We may provide you with the opportunity to create, submit, post, display, transmit, perform, publish, distribute, or broadcast content and materials to us or on the Site, including but not limited to text, writings, video, audio, photographs, graphics, comments, suggestions, or personal information or other material (collectively, "Contributions"). Contributions may be viewable by other users of the Site and through third-party websites. As such, any Contributions you transmit may be treated in accordance with the Site Privacy Policy. When you create or make available any Contributions, you thereby represent and warrant that:
-The creation, distribution, transmission, public display, or performance, and the accessing, downloading, or copying of your Contributions do not and will not infringe the proprietary rights, including but not limited to the copyright, patent, trademark, trade secret, or moral rights of any third party.
-You are the creator and owner of or have the necessary licenses, rights, consents, releases, and permissions to use and to authorize us, the Site, and other users of the Site to use your Contributions in any manner contemplated by the Site and these Terms of Use.
-You have the written consent, release, and/or permission of each and every identifiable individual person in your Contributions to use the name or likeness of each and every such identifiable individual person to enable inclusion and use of your Contributions in any manner contemplated by the Site and these Terms of Use.
-Your Contributions are not false, inaccurate, or misleading.
-Your Contributions are not unsolicited or unauthorized advertising, promotional materials, pyramid schemes, chain letters, spam, mass mailings, or other forms of solicitation.
-Your Contributions are not obscene, lewd, lascivious, filthy, violent, harassing, libelous, slanderous, or otherwise objectionable (as determined by us). Your Contributions do not ridicule, mock, disparage, intimidate, or abuse anyone.
-Your Contributions are not used to harass or threaten (in the legal sense of those terms) any other person and to promote violence against a specific person or class of people.
-Your Contributions do not violate any applicable law, regulation, or rule.
-Your Contributions do not violate the privacy or publicity rights of any third party.
-Your Contributions do not violate any applicable law concerning child pornography or otherwise intended to protect the health or well-being of minors.
-Your Contributions do not include any offensive comments that are connected to race, national origin, gender, sexual preference, or physical handicap.
Any use of the Site in violation of the foregoing violates these Terms of Use and may result in, among other things, termination or suspension of your rights to use the Site.
7. CONTRIBUTION LICENSE
You and the Site agree that we may access, store, process, and use any information and personal data that you provide following the terms of the Privacy Policy and your choices (including settings).
By submitting suggestions or other feedback regarding the Site, you agree that we can use and share such feedback for any purpose without compensation to you.
We do not assert any ownership over your Contributions. You retain full ownership of all of your Contributions and any intellectual property rights or other proprietary rights associated with your Contributions. We are not liable for any statements or representations in your Contributions provided by you in any area on the Site. You are solely responsible for your Contributions to the Site and you expressly agree to exonerate us from any and all responsibility and to refrain from any legal action against us regarding your Contributions.
8. SUBMISSIONS
You acknowledge and agree that any questions, comments, suggestions, ideas, feedback, or other information regarding the Site ("Submissions") provided by you to us are non-confidential and shall become our sole property. We shall own exclusive rights, including all intellectual property rights, and shall be entitled to the unrestricted use and dissemination of these Submissions for any lawful purpose, commercial or otherwise, without acknowledgment or compensation to you. You hereby waive all moral rights to any such Submissions, and you hereby warrant that any such Submissions are original with you or that you have the right to submit such Submissions. You agree there shall be no recourse against us for any alleged or actual infringement or misappropriation of any proprietary right in your Submissions.
9. SITE MANAGEMENT
We reserve the right, but not the obligation, to: (1) monitor the Site for violations of these Terms of Use; (2) take appropriate legal action against anyone who, in our sole discretion, violates the law or these Terms of Use, including without limitation, reporting such user to law enforcement authorities; (3) in our sole discretion and without limitation, refuse, restrict access to, limit the availability of, or disable (to the extent technologically feasible) any of your Contributions or any portion thereof; (4) in our sole discretion and without limitation, notice, or liability, to remove from the Site or otherwise disable all files and content that are excessive in size or are in any way burdensome to our systems; and (5) otherwise manage the Site in a manner designed to protect our rights and property and to facilitate the proper functioning of the Site.
10. PRIVACY POLICY
We care about data privacy and security. Please review our Privacy
Policy: https://www.picussecurity.com/privacy. By using the Site, you agree to be bound by our Privacy Policy, which is incorporated into these Terms of Use. Please be advised the Site is hosted in the United States. If you access the Site from any other region of the world with laws or other requirements governing personal data collection, use, or disclosure that differ from applicable laws in the United States, then through your continued use of the Site, you are transferring your data to the United States, and you agree to have your data transferred to and processed in the United States.
11. TERM AND TERMINATION
These Terms of Use shall remain in full force and effect while you use the Site. WITHOUT LIMITING ANY OTHER PROVISION OF THESE TERMS OF USE, WE RESERVE THE RIGHT TO, IN OUR SOLE DISCRETION AND WITHOUT NOTICE OR LIABILITY, DENY ACCESS TO AND USE OF THE SITE (INCLUDING BLOCKING CERTAIN IP ADDRESSES), TO ANY PERSON FOR ANY REASON OR FOR NO REASON, INCLUDING WITHOUT LIMITATION FOR BREACH OF ANY REPRESENTATION, WARRANTY, OR COVENANT CONTAINED IN THESE TERMS OF USE OR OF ANY APPLICABLE LAW OR REGULATION. WE MAY TERMINATE YOUR USE OR PARTICIPATION IN THE SITE OR DELETE YOUR ACCOUNT AND ANY CONTENT OR INFORMATION THAT YOU POSTED AT ANY TIME, WITHOUT WARNING, AT OUR SOLE DISCRETION.
If we terminate or suspend your account for any reason, you are prohibited from registering and creating a new account under your name, a fake or borrowed name, or the name of any third party, even if you may be acting on behalf of the third party. In addition to terminating or suspending your account, we reserve the right to take appropriate legal action, including without limitation pursuing civil, criminal, and injunctive redress.
12. MODIFICATIONS AND INTERRUPTIONS
We reserve the right to change, modify, or remove the contents of the Site at any time or for any reason at our sole discretion without notice. However, we have no obligation to update any information on our Site. We also reserve the right to modify or discontinue all or part of the Site without notice at any time. We will not be liable to you or any third party for any modification, price change, suspension, or discontinuance of the Site.
We cannot guarantee the Site will be available at all times. We may experience hardware, software, or other problems or need to perform maintenance related to the Site, resulting in interruptions, delays, or errors. We reserve the right to change, revise, update, suspend, discontinue, or otherwise modify the Site at any time or for any reason without notice to you. You agree that we have no liability whatsoever for any loss, damage, or inconvenience caused by your inability to access or use the Site during any downtime or discontinuance of the Site. Nothing in these Terms of Use will be construed to obligate us to maintain and support the Site or to supply any corrections, updates, or releases in connection therewith.
13. GOVERNING LAW
These Terms of Use and your use of the Site are governed by and construed in accordance with the laws of the State of Delaware applicable to agreements made and to be entirely performed within the State of Delaware, without regard to its conflict of law principles.
14. DISPUTE RESOLUTION
Informal Negotiations
To expedite resolution and control the cost of any dispute, controversy or claim related to these Terms of Use (each "Dispute" and collectively, the “Disputes”) brought by either you or us (individually, a “Party” and collectively, the “Parties”), the Parties agree to first attempt to negotiate any Dispute (except those Disputes expressly provided below) informally for at least thirty (30) days before initiating the arbitration. Such informal negotiations commence upon written notice from one Party to the other Party.
Binding Arbitration
Any dispute arising from the relationships between the Parties to this contract shall be determined by one arbitrator who will be chosen in accordance with the Arbitration and Internal Rules of the European Court of Arbitration being part of the European Centre of Arbitration having its seat in Strasbourg, and which are in force at the time the application for arbitration is filed, and of which adoption of this clause constitutes acceptance. The seat of arbitration shall be London, United Kingdom. The language of the proceedings shall be English. Applicable rules of substantive law shall be the law of the United Kingdom.
Restrictions
The Parties agree that any arbitration shall be limited to the Dispute between the Parties individually. To the full extent permitted by law, (a) no arbitration shall be joined with any other proceeding; (b) there is no right or authority for any Dispute to be arbitrated on a class-action basis or to utilize class action procedures, and (c) there is no right or authority for any Dispute to be brought in a purported representative capacity on behalf of the general public or any other persons.
Exceptions to Informal Negotiations and Arbitration
The Parties agree that the following Disputes are not subject to the above provisions concerning informal negotiations and binding arbitration: (a) any Disputes seeking to enforce or protect, or concerning the validity of, any of the intellectual property rights of a Party; (b) any Dispute related to or arising from, allegations of theft, piracy, invasion of privacy, or unauthorized use; and (c) any claim for injunctive relief. If this provision is found to be illegal or unenforceable, then neither Party will elect to arbitrate any Dispute falling within that portion of this provision found to be illegal or unenforceable, and such Dispute shall be decided by a court of competent jurisdiction within the courts listed for jurisdiction above, and the Parties agree to submit to the personal jurisdiction of that court.
15. CORRECTIONS
There may be information on the Site that contains typographical errors, inaccuracies, or omissions, including descriptions, pricing, availability, and various other information. We reserve the right to correct any errors, inaccuracies, or omissions and to change or update the information on the Site at any time, without prior notice.
16. DISCLAIMER
The Service is provided to You "AS IS" and "AS AVAILABLE" and with all faults and defects without warranty of any kind. To the maximum extent permitted under applicable law, the Company, on its own behalf and on behalf of its Affiliates and its and their respective licensors and service providers, expressly disclaims all warranties, whether express, implied, statutory or otherwise, with respect to the Service, including all implied warranties of merchantability, fitness for a particular purpose, title and non-infringement, and warranties that may arise out of course of dealing, course of performance, usage or trade practice. Without limitation to the foregoing, the Company provides no warranty or undertaking, and makes no representation of any kind that the Service will meet Your requirements, achieve any intended results, be compatible or work with any other software, applications, systems or services, operate without interruption, meet any performance or reliability standards or be error free or that any errors or defects can or will be corrected.
Without limiting the foregoing, neither the Company nor any of the company's provider makes any representation or warranty of any kind, express or implied: (i) as to the operation or availability of the Service, or the information, content, and materials or products included thereon; (ii) that the Service will be uninterrupted or error-free; (iii) as to the accuracy, reliability, or currency of any information or content provided through the Service; or (iv) that the Service, its servers, the content, or e-mails sent from or on behalf of the Company are free of viruses, scripts, trojan horses, worms, malware, timebombs or other harmful components.
Some jurisdictions do not allow the exclusion of certain types of warranties or limitations on applicable statutory rights of a consumer, so some or all of the above exclusions and limitations may not apply to You. But in such a case the exclusions and limitations set forth in this section shall be applied to the greatest extent enforceable under applicable law.
17. LIMITATIONS OF LIABILITY
IN NO EVENT WILL WE OR OUR DIRECTORS, EMPLOYEES, OR AGENTS BE LIABLE TO YOU OR ANY THIRD PARTY FOR ANY DIRECT, INDIRECT, CONSEQUENTIAL, EXEMPLARY, INCIDENTAL, SPECIAL, OR PUNITIVE DAMAGES, INCLUDING LOST PROFIT, LOST REVENUE, LOSS OF DATA, OR OTHER DAMAGES ARISING FROM YOUR USE OF THE SITE, EVEN IF WE HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
18. INDEMNIFICATION
You agree to defend, indemnify, and hold us harmless, including our subsidiaries, affiliates, and all of our respective officers, agents, partners, and employees, from and against any loss, damage, liability, claim, or demand, including reasonable attorneys’ fees and expenses, made by any third party due to or arising out of: (1) use of the Site; (2) breach of these Terms of Use; (3) any breach of your representations and warranties set forth in these Terms of Use; (4) your violation of the rights of a third party, including but not limited to intellectual property rights; or (5) any overt harmful act toward any other user of the Site with whom you connected via the Site. Notwithstanding the foregoing, we reserve the right, at your expense, to assume the exclusive defense and control of any matter for which you are required to indemnify us, and you agree to cooperate, at your expense, with our defense of such claims. We will use reasonable efforts to notify you of any such claim, action, or proceeding which is subject to this indemnification upon becoming aware of it.
19. USER DATA
We will maintain certain data that you transmit to the Site for the purpose of managing the performance of the Site, as well as data relating to your use of the Site. Although we perform regular routine backups of data, you are solely responsible for all data that you transmit or that relates to any activity you have undertaken using the Site. You agree that we shall have no liability to you for any loss or corruption of any such data, and you hereby waive any right of action against us arising from any such loss or corruption of such data.
20. AFFILIATES
Picus Bilişim Güvenlik Ticaret A.Ş.; Picus Security, Inc.; Picus Security US, LLC.
21. ELECTRONIC COMMUNICATIONS, TRANSACTIONS, AND SIGNATURES
Visiting the Site, sending us emails, and completing online forms constitute electronic communications. You consent to receive electronic communications, and you agree that all agreements, notices, disclosures, and other communications we provide to you electronically, via email, and on the Site, satisfy any legal requirement that such communication be in writing. YOU HEREBY AGREE TO THE USE OF ELECTRONIC SIGNATURES, CONTRACTS, ORDERS, AND OTHER RECORDS, AND TO ELECTRONIC DELIVERY OF NOTICES, POLICIES, AND RECORDS OF TRANSACTIONS INITIATED OR COMPLETED BY US OR VIA THE SITE. You hereby waive any rights or requirements under any statutes, regulations, rules, ordinances, or other laws in any jurisdiction which require an original signature or delivery or retention of non-electronic records, or to payments or the granting of credits by any means other than electronic means.
22. FOR EUROPEAN UNION (EU) USERS
If You are a European Union consumer, you will benefit from any mandatory provisions of the law of the country in which you are resident in.
23. UNITED STATES LEGAL COMPLIANCE
You represent and warrant that (i) You are not located in a country that is subject to the United States government embargo, or that has been designated by the United States government as a "terrorist supporting" country, and (ii) You are not listed on any United States government list of prohibited or restricted parties.
24. CALIFORNIA USERS AND RESIDENTS
If any complaint with us is not satisfactorily resolved, you can contact the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs in writing at 1625 North Market Blvd., Suite N 112, Sacramento, California 95834 or by telephone at (800) 952-5210 or (916) 445-1254.
25. MISCELLANEOUS
These Terms of Use and any policies or operating rules posted by us on the Site or in respect to the Site constitute the entire agreement and understanding between you and us. Our failure to exercise or enforce any right or provision of these Terms of Use shall not operate as a waiver of such right or provision. These Terms of Use operate to the fullest extent permissible by law. We may assign any or all of our rights and obligations to others at any time. We shall not be responsible or liable for any loss, damage, delay, or failure to act caused by any cause beyond our reasonable control. If any provision or part of a provision of these Terms of Use is determined to be unlawful, void, or unenforceable, that provision or part of the provision is deemed severable from these Terms of Use and does not affect the validity and enforceability of any remaining provisions. There is no joint venture, partnership, employment, or agency relationship created between you and us as a result of these Terms of Use or use of the Site. You agree that these Terms of Use will not be construed against us by virtue of having drafted them. You hereby waive any and all defenses you may have based on the electronic form of these Terms of Use and the lack of signing by the parties hereto to execute these Terms of Use.
26. CONTACT US
In order to resolve a complaint regarding the Site or to receive further information regarding the use of the Site, please contact us at:
Picus Security Inc.
1401 Pennsylvania Avenue Unit 105 Suite 104, Wilmington, DE 19806
Picus Security, Inc. is based in the state of Delaware in the United States. The Website can be accessed from countries around the world. Access to the Website may not be legal by certain persons or in certain jurisdictions. If you access the Website from outside the United States, you do so on your initiative and are responsible for compliance with all laws applicable to you, including local laws. Access to the Website from jurisdictions where the Website or any of its services or products are illegal is prohibited.
You may not access, download, use, or export materials posted to the Website in violation of U.S. export laws or regulations or violation of any other applicable export or import laws or regulations. You agree to comply with all export laws, restrictions, and regulations of any United States or foreign agency or authority.
Without limiting the foregoing, you represent and warrant that you are not located in, and shall not use the Website from, any country that is subject to U.S. export restrictions.
This DPA shall govern and take precedence over any conflicting terms found in any other agreement between the parties. If the parties previously executed any data processing or data protection agreement or any related agreements (whether standalone or as an amendment, exhibit, schedule, or attachment), this DPA replaces and supersedes such agreements.
1. DEFINITIONS
Any capitalized term not defined in this DPA will have the meaning given to it in the Agreement.
-Agreement means any one or more agreements (including any corresponding order form, appendix, or addenda) under which Picus provides the Picus Solution to Customer.
-CCPA means the California Consumer Privacy Act of 2018, along with its regulations, and as amended.
-Controller means an entity that, alone or jointly with others, determines the purposes for and means of Processing. "Controller" has the same meaning as "Business", as that term is defined under applicable Data Protection Laws.
-Customer Personal Data means any Personal Data processed by Picus (i) on behalf of Customer, and (ii) in the course of its provision of the Picus Solution to Customer.
-Customer Audit means a review of the security of the Picus Solution conducted by Customer at its expense.
-Data Protection Law(s) means any and all applicable privacy and data protection laws and regulations, including, where applicable, the CCPA, EU GDPR, UK Data Protection Laws, and all other applicable data protection and privacy legislation in force from time to time in the EU (as may be applicable depending on the location of Customer, Data Subjects, and the Processing of relevant Personal Data).
-Data Subject means an identified or identifiable person.
-EEA means the European Economic Area.
-EU GDPR means the (i) EU General Data Protection Regulation (Regulation 2016/679) of the European Parliament and the Council of 27 April 2016 on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data and any legislation replacing or updating any of the foregoing and any judicial or administrative interpretation of any of the above, including any binding guidance, guidelines, codes of practice, approved codes of conduct or approved certification mechanisms issued by any relevant supervisory authority.
-Personal Data means information that Processor Processes on behalf of Controller that identifies, relates to, describes, is reasonably capable of being associated with or could reasonably be linked, directly or indirectly, to a Data Subject, or as that term or a similar term is defined under applicable Data Protection Laws.
-Personal Data Breach means a breach of Picus's security obligations under this DPA leading to the destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data.
-Picus Solution means the Picus proprietary programs made available to Customer as the Software or Cloud Service, including without limitation its features, functions, user interface, and related Support services (each as defined below), as specified on an Order Form.
-Process or Processing means any operation or set of operations performed on Customer Personal Data, whether or not by automated means, including but not limited to accessing, collecting, using, storing, transferring, retaining, disclosing, selling, sharing, deleting, and destroying Personal Data.
-Restricted Country means any country (i) which is not a member of the European Economic Area; or (ii) which has not been approved by the European Commission pursuant to Article 45, GDPR as ensuring an adequate level of data protection in relation to personal data.
-Restricted Transfer means a transfer of personal data between Customer and Picus to a Restricted Country.
-Standard Contractual Clauses or SCC mean the standard contractual clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council adopted by the European Commission Implementing Decision 2021/914 of 4 June 2021 as updated, amended, replaced, and superseded from time to time.
-Sub-processors means any person or entity engaged by Picus or an Affiliate to Process Customer Personal Data in the provision of the Picus Solution to Customer.
-Third Party Audit Reports means reports and certifications resulting from Picus and/or its Sub-processors engaging qualified third party auditors to perform examinations and provide reports of its systems and services.
-TOMS means Picus's Technical and Organization Measures found at the following URL: https://www.picussecurity.com/trust-center/privacy-security.
-US Data Protection Laws means any U.S. federal and state privacy laws effective as of the Effective Date of this DPA and applies to Picus Processing of Customer Personal Data, and any implementing regulations and amendment thereto, including without limitation, the CCPA, the CPA, the CTDPA, and the VCDPA.
-UK Addendum refers to the United Kingdom's ("UK") International Data Transfer Addendum to the Standard Contractual Clauses, available at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf.
-UK Standard Contractual Clauses or UK SCC means the UK "International Data Transfer Addendum to The European Commission Standard Contractual Clauses" available at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf as adopted, amended or updated by the UK Information Commissioner Office ("ICO"), Parliament or Secretary of State.
2. ROLES AND DETAILS OF PROCESSING
2.1. Picus has agreed to provide the Picus Solution to Customer in accordance with the terms of the Agreement. Subject to the terms of this DPA, Customer appoints Picus to Process Customer Personal Data for the purpose of providing the Picus Solution.
2.2. With respect to Customer Personal Data under this DPA, the parties agree that Picus may act as Processor to Customer, where Customer may act either as the Controller or Processor. Picus may also act as a Sub-processor. Where Customer acts as Controller, Customer shall be responsible for all Controller obligations under this DPA. Where Customer acts as Processor, Customer shall be responsible for all Controller obligations under this DPA; and in such case Customer represents and warrants that the Controller has appointed Customer as Processor to Process Personal Data of the Controller on the Controller's behalf and that it is authorized to instruct Picus and otherwise act on behalf of Customer Affiliate(s) or Customer clients in relation to the Customer Personal Data in accordance with the Agreement and this DPA. The details of Processing and the description of transfer are stated at Annex I.
2.3. Each party shall be individually and separately responsible for complying with the obligations that apply to such party under the applicable Data Protection Law.
2.4. Additional EU Data Protection Laws specifications are detailed in Annex IV.
2.5. Additional UK Data Protection Laws specifications are detailed in Annex V.
2.6. Additional US Data Protection Laws specifications are detailed in Annex VI.
3. PICUS OBLIGATIONS
3.1. Picus may Process Customer Personal Data for the purpose of providing the Picus Solution and only in accordance with the terms of the Agreement and this DPA. This DPA is Customer's complete and final documented instruction to Picus in relation to Customer Personal Data. Additional instructions outside the scope of this DPA (if any) require prior written agreement between Picus and Customer, including agreement on any additional fees payable by Customer to Picus for carrying out such instructions.
3.2. Picus will inform Customer if it becomes aware or reasonably suspects that Customer's instructions regarding the Processing of Personal Data may violate any applicable Data Protection Laws.
3.3. Picus will ensure that all employees, agents, officers, and contractors involved in the handling of Customer Personal Data: (i) are aware of the sensitive nature of the Customer Personal Data and are contractually bound to safeguard the Customer Personal Data; (ii) have received appropriate training on their responsibilities as a Processor; and (iii) are bound by terms materially no less restrictive than the terms of this DPA.
3.4. Picus will implement appropriate administrative, technical, and organizational safeguards required of Picus by the Data Protection Laws to help ensure the security and privacy of Customer Personal Data. This requirement shall be deemed to have been fulfilled by Picus adopting the measures detailed in the TOMs.
3.5. Any Restricted Transfer between Picus and Customer shall be subject to the Standard Contractual Clauses, if the cross-border or onward transfer involves Personal Data about individuals in the EEA, the UK, or Switzerland. In the event the parties rely on the Standard Contractual Clauses for such transfers, references to a "Member State" and "EU Member State" will not be read to limit or prevent Data Subjects in Switzerland from seeking to exercise their rights. The Standard Contractual Clauses and UK Addendum are hereby incorporated into this DPA by reference and deemed executed by the parties as of the Effective Date.
3.6. Picus will assist Customer in meeting its obligation under applicable Data Protection Laws on Customer's reasonable request, including to carry out data protection impact assessments, taking into account the nature of Processing and the Personal Data available to Picus.
3.7. Customer and Picus and, where applicable, their representatives, will cooperate, upon request, with a Supervisory Authority in the performance of their respective obligations under this DPA.
3.8. Upon Picus's or Sub-processors' receipt of a legally-binding request for access to Personal Data from a Supervisory Authority, and only when permitted by applicable law, Picus will (i) notify Customer of the request for access and provide details about the requesting party, the types of Personal Data requested, and the purpose and methods of the disclosure (so as to provide Customer the opportunity to comply with its notice and consent obligations with respect to affected Data Subjects or oppose the disclosure and obtain a protective order or seek other relief), and (ii) where applicable, also comply with the notice obligations set forth in Clause 15.1 of the Standard Contractual Clauses.
3.9. Picus will not "sell" or "share" Personal Data, as those terms are defined under applicable Data Protection Laws.
3.10. Notwithstanding section 3.1, Picus may Process Customer Personal Data outside of Customer's instructions where that Processing is required by any law or order to which Picus is subject. In such case, Picus shall, except where prohibited by law from doing so, inform Customer of that requirement.
4. CUSTOMER OBLIGATIONS
4.1. Customer represents and warrants that: (i) it will comply with the terms of the Agreement, this DPA, and the Data Protection Laws, including any applicable requirements to provide notice to and/or obtain consent from Data Subjects for Processing by Picus; (ii) it will ensure that its use of the Picus Solution will not violate the rights of any Data Subjects; (iii) its instructions to Picus will comply with Data Protection Laws; and (iv) the Processing of Customer Personal Data in accordance with Controller's instructions will not cause Picus to be in breach of any Data Protection Laws. All Customer Affiliates who use the Picus Solution will comply with the Customer obligations set out in this DPA.
4.2. Customer has sole responsibility for (i) the quality, legality, and accuracy of Customer Personal Data; (ii) the means by which Customer acquires any such Personal Data; and (iii) the instructions it provides to Processor regarding the Processing of such Personal Data. Customer further represents and warrants that it has obtained any and all necessary permissions and authorizations necessary to permit Picus, its Affiliates, and Sub-processors, to execute their rights or perform their obligations under this DPA.
4.3. Customer must inform Picus of any notice, inquiry (including any notice, investigation, complaint, or request) relating to Picus's processing of Personal Data and provide Picus with a copy thereof within 48 hours of receipt. Notices should be sent to: privacy@picussecurity.com.
4.4. Customer is responsible for making an independent determination as to whether the TOMs meet Customer's requirements, including any of its security obligations under applicable Data Protection Laws. Customer agrees that the Picus Solution and the TOMs meet Customer's needs with respect to Customer's security obligations under applicable Data Protection Law.
5. NOTIFICATION OF PERSONAL DATA BREACH
5.1. Picus will notify the Customer without undue delay (and in any event within 72 hours) upon becoming aware of any Personal Data Breach involving Customer Personal Data. Picus's notification regarding or response to a Personal Data Breach under this Section 5 shall not be construed as an acknowledgment by Picus of any fault or liability with respect to the Personal Data Breach.
5.2. Picus will, taking into account the nature of processing and the information available to Picus, (i) take all commercially reasonable steps to secure the Customer Personal Data and to remediate, minimize any effects of, investigate, and identify the cause of any Personal Data Breach; (ii) cooperate with the Customer and provide the Customer with such assistance and information as it may reasonably require in connection with the containment, investigation, remediation, or mitigation of the Personal Data Breach; (iii) notify the Customer in writing of any request, inspection, audit, or investigation by a Supervisory Authority; (iv) keep the Customer informed of all material developments in connection with the Personal Data Breach and execute a response plan to address the Personal Data Breach in a timely manner; (v) cooperate with the Customer and assist the Customer with its obligation to notify the affected individuals in the case of a Personal Data Breach.
6. AUDIT RIGHTS
6.1. Picus shall maintain accurate written records of the Processing activities of any Customer Personal Data carried out under this DPA and shall make such records available to the Customer and applicable Supervisory Authorities upon written request. Such records shall be considered Picus's Confidential Information and shall be subject to any confidentiality obligations stated in this DPA and the Agreement.
6.2. Not more than once in any 12 month period other than in the event of a Personal Data Breach, Customers may audit Picus's compliance with this DPA and applicable Data Protection Laws by requesting a certificate issued for security verification reflecting the outcome of an audit conducted by a third-party auditor (e.g., ISO27001/ISO27701/22031/20000 certifications, SOC 2 reports). Any on-site or additional audit requested by Customer beyond Third Party Audit Reports shall be subject to prior written agreement on scope, timing, and reasonable cost reimbursement.
6.3. Nothing in this DPA will require Picus to either disclose to Customer or to a third-party auditor, or to allow Customer or its third-party auditor to access: (i) any data of any other Picus's Customer; (ii) Picus's internal accounting or financial information; (iii) any trade secret of Picus or its Affiliates; (iv) any information that, in Picus's reasonable opinion, could compromise the security of any of Picus's systems or cause any breach of its obligations under applicable law or its security or privacy obligations to any third party; or (v) any information that Customer or its third-party auditor seeks to access for any reason other than the good faith fulfillment of Customer's obligations under the Data Protection Laws.
7. DATA SUBJECTS RIGHTS AND REQUEST
7.1. It is agreed that where Picus receives a request from a Data Subject or an applicable authority in respect of Customer Personal Data, Picus will notify the Customer of such request promptly and direct the Data Subject or the applicable authority to the Customer to enable the Customer to respond directly to the Data Subject's or the applicable Supervisory Authority's request, unless otherwise required under applicable laws. The Parties shall provide each other with commercially reasonable cooperation and assistance in relation to the handling of a Data Subject's or applicable authority's request, to the extent permitted under Data Protection Laws.
7.2. If Customer does not have the ability to address a Data Subject Request, Picus may upon Customer's request, and to the extent possible and legally permitted, provide commercially reasonable efforts to assist Customer in responding to such Data Subject Request regarding Picus's processing of Personal Data. To the extent legally permitted, Customer will be responsible for any costs arising from Picus's provision of such assistance.
8. SUB-PROCESSING
8.1. The Customer acknowledges that Picus may transfer Customer Personal Data to and otherwise interact with third-party data Sub-processors in connection with the provision of the Picus Solution. The Customer hereby authorizes Picus to engage and appoint Sub-processors to Process Customer Personal Data, as well as permits each Sub-processor to appoint a Sub-Processor on its behalf.
8.2. The list of Picus Sub-processors can be found at the Annex III. During the term of this DPA, Picus will provide Customer with prior notification, via email, of any changes to the list of Sub-processors who may process Customer Personal Data before authorizing any new or replacement Sub-processors to process Customer Personal Data in connection with the provision of the Picus Solution. Customer may object to the use of a new or replacement Sub-processor, by notifying Picus promptly in writing within fourteen (14) days after receipt of Picus' notice. If Partner objects to a new or replacement Sub-processor, and if that objection is reasonably acceptable, and such objection is not resolved within twenty (20) days of Picus receiving the objection, Customer may terminate the Agreement with respect to the Picus Platform which cannot be provided by Picus without the use of the new or replacement Sub-processor. Picus shall have no penalty or liability for termination under this section, and this is Customer's sole and exclusive remedy for termination under this section.
8.3. Picus shall, with respect to each Sub-processor, ensure in each case that it has in place a written agreement with such Sub-processor which imposes equivalent data protection obligations to those contained in this DPA ("Sub-processor Agreement").
9. LIABILITY
9.1. Each party's and all of its Affiliates' liability, taken together in the aggregate, arising out of or relating to this DPA, whether in contract, tort, or under any other theory of liability is subject to the "Limitation on Damages" section of the Agreement.
9.2. The parties agree that Picus will, subject to the liability limits stated in the Agreement, be liable for any breaches of this DPA caused by the acts and omissions of its Sub-processors to the same extent Picus would be liable if performing the services of each Sub-processor directly under the terms of this DPA.
9.3. The parties agree that Customer will be liable for any breaches of this DPA caused by the acts and omissions of its Affiliates and Users as if such acts and omissions had been committed by Customer itself.
10. TERM, TERMINATION, AND CONFLICT
10.1. This DPA shall be effective as of the Effective Date and shall remain in force until the Agreement terminates or for as long as Picus Processes Customer Personal Data.
10.2. Picus shall be entitled to terminate this DPA or to cease the Processing of Customer Personal Data in the event that Processing of Customer Personal Data under this DPA violates applicable legal requirements if Customer does not remedy such violation within ten (10) days from receiving written notice from Picus. Alternately, Picus may, in its sole discretion, suspend the Processing of the Customer Personal Data until such violation is cured without terminating the DPA.
10.3. Customer hereby instructs Picus to delete the Customer Personal Data remaining with Picus within a reasonable time period in line with Data Protection Laws (but never to exceed six months) following the termination of the Agreement. If Customer wishes to retain any Customer Personal Data following the termination of the Agreement, it may instruct Picus within 30 days following the date of termination to return that Customer Personal Data to Customer.
10.4. Picus and each of its Sub-Processors may (acting as a Controller) retain one archival copy of such Customer Personal Data solely for the purposes of ensuring compliance with the Agreement or to the extent and for such period as may be required by any applicable law, or by any order or direction of any competent Court, tribunal government or regulatory body, to which it may be subject. If any Customer Personal Data is retained for such reasons, the Customer Personal Data must be treated as Customer's Confidential Information (as defined in the Agreement).
10.5. Assessment results, technical analysis, and benchmark-style evaluations on the Picus Solution are processed anonymously and in a context independent of the Customer. After the termination of any Customer, any analysis results remain in the system anonymously, without any connection with the Customer.
10.6. This DPA sets out the entire understanding of the parties and supersedes all prior and contemporaneous agreements and understandings with regards to the subject matter. No modification or waiver of any term in this DPA is effective unless both parties sign it.
10.7. To the extent of any conflict or inconsistency between the terms of this DPA and the Agreement, the DPA shall take precedence over the Agreement. Subject to any amendments in this DPA, the Agreement remains in full force and effect.
10.8. Customer may send any questions or concerns regarding this DPA to: privacy@picussecurity.com.
IN WITNESS WHEREOF, the parties hereby have caused this Data Processing Agreement to be executed as an agreement under seal as of the date first written above.
PICUS Security Inc
ANNEX I
DETAILS OF PROCESSING
This Annex includes certain details of the Processing of Customer Personal Data as required under the Data Protection Laws.
Categories of Data Subjects:
Customer employees and any data subject which are uploaded to the Picus Solution by Customer.
Categories of Personal Data Processed:
Credentials, contact information, authentication, and security credentials.
-Identity information: Full name
-Contact information: E-mail address, contact address (Country).
-Employment information: Company name, job title
-Online (technical/performance) identifiers: IP address, login credentials, login time, device and browser information, cookie data, etc.
Categories of Sensitive Personal Data:
None.
Nature of the Processing:
Collection, storage, organization, communication, transfer, hosting, and other uses in the performance of the Picus Solution as set out in the Agreement.
Purpose(s) of Processing:
To provide the Picus Solution.
Retention Period:
For the Term of the Agreement and until Customer requests deletion; provided there is no legal obligation to retain the Personal Data past termination or unless otherwise requested by the Customer.
Process Frequency:
Continuous basis.
ANNEX II
TECHNICAL AND ORGANIZATIONAL MEASURES
Picus has implemented and will maintain the following measures during the Term:
Measures of pseudonymization and encryption of personal data.
Measures for ensuring ongoing confidentiality, security, integrity, availability, privacy, and resilience of processing systems and services.
Measures for enabling the ability to restore the availability and access to Customer Personal Data in a timely manner in the event of a Personal Data Breach.
Processes for regularly testing, assessing, and evaluating the effectiveness of the technical and organizational measures in order to help ensure the security of any Processing, including the following:
-Measures for user identification and authorization
-Measures for the protection of data during transmission
-Measures for the protection of data during storage
-Measures for ensuring the physical security of locations at which personal data are processed
-Measures for ensuring event logging
-Measures for ensuring system configuration, including default configuration
-Measures for internal IT and IT security governance and management
-Measures for certification/assurance of processes and products
-Measures for ensuring data minimization
-Measures for ensuring data quality
-Measures for ensuring limited data retention
-Measures for ensuring accountability
-Measures for allowing data portability and ensuring erasure
For transfers to Sub-processors, Picus has established minimum security and privacy requirements which must be met by a Sub-processor before Picus engages with such Sub-processor. As part of its Third-Party Risk Management process, Picus reviews the SOC 1/2/3 and other related compliance reports and vendor questionnaires for each Sub-processor on an annual basis. Additionally, Picus performs commercially reasonable due diligence on the data security and protection practices of its Sub-processors at the time of engagement.
ANNEX III
LIST OF SUB-PROCESSORS
Picus engages and uses certain sub-processors to deliver its products and services. Customer can access the list via link: https://www.picussecurity.com/trust-center/sub-processors.
ANNEX IV
EU INTERNATIONAL TRANSFERS AND SCC
1. The parties agree that the terms of the Standard Contractual Clauses are hereby incorporated by reference and shall apply to the transfer of Customer Personal Data from the EEA to any Restricted Countries.
2. Module Two (Controller to Processor) of the Standard Contractual Clauses shall apply where the transfer is effectuated by Customer as the Controller of the Customer Personal Data and Picus is the Processor of the Customer Personal Data.
3. The Parties agree that for the purpose of transfer of Partner Personal Data between Partner (as Data Exporter) and Picus (as Data Importer), the following shall apply:
-Clause 7 of the Standard Contractual Clauses shall not be applicable.
-In Clause 9, option 2 (general written authorization) shall apply and the method for appointing and time period for prior notice of Sub-processor changes shall be as set forth in the Sub-Processing Section of the DPA.
-In Clause 11, the optional language will not apply, and data subjects shall not be able to lodge a complaint with an independent dispute resolution body.
-In Clause 17, option 1 shall apply. The parties agree that the Standard Contractual Clauses shall be governed by the laws of the EU Member State in which the Partner is established (where applicable).
-In Clause 18(b) the parties choose the courts of the Republic of Ireland, as their choice of forum and jurisdiction.
4. Annex I of the Standard Contractual Clauses shall be completed as follows:
-"Data Exporter": Customer
-"Data Importer": Picus Security Inc
-Roles: (A) With respect to Module Two: (i) Data Exporter is a Controller and (ii) the Data Importer is a Processor.
-Data Exporter and Data Importer Contact details: As detailed in the Agreement.
-Signature and Date: By entering into the Agreement and DPA, Data Exporter and Data Importer are deemed to have signed these Standard Contractual Clauses incorporated herein, including their Annexes, as of the Effective Date of the Agreement.
5. Annex I of the Standard Contractual Clauses shall be completed as follows:
-The purpose of the Processing, nature of the Processing, categories of Data Subjects, categories of Personal Data and the parties' intention with respect to the transfer of special categories are as described in Annex I (Details of Processing) of this DPA.
-The frequency of the transfer and the retention period of the Personal Data is as described in Annex I (Details of Processing) of this DPA.
-The sub-processor to which Personal Data is transferred is listed in Annex III.
6. Annex I.C of the Standard Contractual Clauses shall be completed as follows: the competent supervisory authority in accordance with Clause 13 is the supervisory authority in the Member State stipulated in Section 3 above.
7. Annex II of this DPA (Technical and Organizational Measures) serves as Annex II of the Standard Contractual Clauses.
8. Annex III of this DPA (List of Sub-processors) serves as Annex III of the Standard Contractual Clauses.
9. Transfers to the US: Measures and assurances regarding US government surveillance ("Additional Safeguards") are further detailed in Annex VI.
ANNEX V
UK INTERNATIONAL TRANSFERS AND SCC
1. The parties agree that the terms of the Standard Contractual Clauses as amended by the UK Standard Contractual Clauses, and as amended in this Annex V, are hereby incorporated by reference and shall apply to the transfer of Customer Personal Data from the UK to any Restricted Countries.
2. This Annex V is intended to provide appropriate safeguards for the purposes of transfers of Customer Personal Data to a third country in reliance on Article 46 of the UK GDPR and with respect to data transfers from Controller to Processor or from a Processor to its Sub-processors.
3. Terms used in this Annex V that are defined in the Standard Contractual Clauses shall have the same meaning as in the Standard Contractual Clauses.
4. Amendments to the UK Standard Contractual Clauses:
Part 1: Tables
-Table 1 Parties: shall be completed as set forth in Section 3 within Annex IV above.
-Table 2 Selected SCCs, Modules, and Selected Clauses: shall be completed as set forth in Section 2 and 3 within Annex IV above.
-Table 3 Appendix Information:
-Annex 1A: List of Parties: shall be completed as set forth in Section 2 within Annex IV above.
-Annex 1B: Description of Transfer: shall be completed as set forth in Annex I above.
-Annex II: Technical and organizational measures including technical and organizational measures to ensure the security of the data: shall be completed as set forth in Annex II above.
-Annex III: List of Subprocessors: shall be completed as set forth in Annex III above.
-Table 4 ending this Addendum when the Approved Addendum Changes: shall be completed as "neither party".
ANNEX VI
US DATA PROTECTION LAWS ADDENDUM
This US Privacy Law Addendum ("US Addendum") adds specifications applicable to US Data Protection Laws. All terms used but not defined in this US Data Protection Laws Addendum shall have the meaning set forth in the DPA.
CCPA Specifications
For the purpose of the CCPA, Customer is the Business and Picus is the Service Provider.
Picus shall Process Customer Personal Data on behalf of the Customer as a Service Provider under the CCPA and shall not: (i) Sell or Share the Customer Personal Data; (ii) retain, use or disclose the Customer Personal Data for any purpose other than for a Business Purpose specified in the Agreement; or (iii) combine the Customer Personal Data with other Personal Data that it receives from, or on behalf of, another customer, or collects from its own interaction with California residents, except as otherwise permitted by the CCPA.
If, and to the extent applicable, Picus shall assist Customer in respect of a Consumer request to limit the use of its Sensitive Personal Information ("SPI") or Sensitive Data (as applicable) by Picus.
Picus certifies that it understands the rules, requirements, and definitions of the CCPA and agrees to refrain from Selling any Customer Personal Data.
Additional Safeguards
Picus has implemented measures and assurances regarding U.S. government surveillance, and Picus agrees and hereby represents that it maintains the following additional safeguards:
1. Picus maintains industry-standard measures to protect the Customer Personal Data from interception (including in transit from Customer to Picus and between different systems and services). This includes maintaining encryption in transit and at rest. In addition, the fragment key enabling the decryption of Customer Personal Data is held independently by Customer, locally within Customer's environment, and is the only possible way to decrypt Customer Personal Data. As of the Effective Date, Picus has not received any national security orders.
No court has found Picus to be: (i) the type of entity eligible to receive process issued under section 702 of the United States Foreign Intelligence Surveillance Court ("FISA"); (ii) an "electronic communication service provider" within the meaning of 50 U.S.C § 1881(b)(4) or a member of any of the categories of entities described within that definition.
2. In the event that FISA becomes applicable to Picus, Picus will make reasonable efforts to resist, subject to applicable laws, any request for bulk surveillance relating to the Customer Personal Data, including (if applicable) under Section 702 of the FISA.
3. If Picus becomes aware of any law enforcement agency or other governmental authority ("Authority") attempt or demand to gain access to or receive a copy of the Customer Personal Data (or part thereof), whether on a voluntary or a mandatory basis, then, unless legally prohibited or under a mandatory legal compulsion that requires otherwise, Picus shall: (i) inform the relevant Authority that Picus is a Processor of the Customer Personal Data and that Customer, as the Controller, has not authorized Picus to disclose the Customer Personal Data to the Authority; (ii) inform the relevant Authority that any and all requests or demands for access to Customer Personal Data should be directed to or served upon Customer in writing; and (iii) use reasonable legal mechanisms to challenge any such demand for access to Customer Personal Data.
4. Notwithstanding the above, if, taking into account the nature, scope, context, and purposes of the related Authority's intended access to Customer Personal Data, Picus has a reasonable and good-faith belief that urgent access is necessary to prevent an imminent risk of serious harm to any individual or entity, these subsections shall not apply. In such event, Picus shall notify Customer, as soon as possible, following the access by the Authority, and provide Customer with relevant details, unless and to the extent legally prohibited to do so.
5. Picus will inform Customer, upon written request (and not more than once a year), of the types of binding legal demands for Customer Personal Data Picus has received and complied with, including demands under national security orders and directives, specifically including any process under Section 702 of FISA.
At PICUS, we value transparent and straightforward communication with our customers, partners, and community. For any concerns or issues, please contact us at info@picussecurity.com. Your feedback is crucial, and we are dedicated to addressing grievances quickly and effectively.
Data Subject Requests
In Picus, we respect your data privacy rights. If you want to exercise your data subject rights, please fill out the form here. Upon your submission, we will share the related data subject request form with you, depending on the legal source of your request.
Sub-Processors
Picus engages and uses certain sub-processors to deliver its products and services. These sub-processors are third-party services or entities authorized by Picus to process personal data on behalf of Picus’s customers, in accordance with the Data Processing Agreements (DPA) signed between Picus and each sub-processor. Picus conducts an annual compliance review of its sub-processors as part of its Third Party Risk Management program.
Security Policies and Practices
At Picus, we deeply integrate security into our company culture. Our dedication to safeguarding information and assets is also reflected in the comprehensive set of corporate documents and practices we maintain. Below, you can find a selection of these resources, highlighting the key elements that help us build and maintain a strong, well-tested, and continuously validated security posture.
a) Corporate Security Documents
At PICUS, protecting the confidentiality, integrity, and availability of information is a core priority. Information security is embedded across our business operations, products, and services, supporting our commitment to maintaining trust with customers, partners, and employees.
PICUS has established and maintains an Information Security Management System (ISMS) designed to systematically manage information security risks and ensure the effective protection of information assets. The ISMS incorporates structured risk management, asset management, and control processes to identify, assess, and mitigate risks in line with business and regulatory requirements.
Information security is an integral part of how Picus operates. Security considerations are built into the design, development, and operation of systems and services, and are continuously adapted to evolving threats and business requirements.
PICUS aligns its ISMS with internationally recognized standards, including ISO/IEC 27001, and continuously works to maintain and improve its compliance with applicable versions of the standard. This alignment enables Picus to demonstrate its ability to meet the information security expectations of internal and external stakeholders.
In support of its information security objectives, PICUS:
- Aligns information security practices with business strategy and corporate objectives
- Complies with applicable legal, regulatory, and contractual requirements
- Maintains and continuously improves its ISMS in accordance with ISO/IEC 27001 principles
- Identifies, assesses, and manages information security risks and evolving threats
- Protects the confidentiality, integrity, and availability of information assets and business processes
- Promotes information security awareness among employees, partners, and stakeholders
- Supports the quality, reliability, and efficiency of products and services through effective security controls
Information security is a shared responsibility across all employees and relevant stakeholders, and everyone is expected to act in accordance with this policy and supporting standards.
This policy provides the foundation for information security governance at PICUS and is supported by a set of detailed policies and procedures that define specific controls and responsibilities.
This policy is reviewed periodically and updated as necessary to ensure its continued effectiveness and alignment with business, regulatory, and security requirements.
Last update: 24.03.2026
PICUS is committed to maintaining the continuity and resilience of its critical business operations in the face of disruptions. The Company has established a Business Continuity Management System (BCMS) to ensure that essential services can continue or be restored in a timely manner, minimizing the impact on customers, operations, and stakeholders.
The BCMS is aligned with PICUS’s overall risk management and governance framework and operates in coordination with the Information Security Management System (ISMS), Privacy Information Management System (PIMS), and IT Service Management System (ITSMS). This integrated approach supports consistent risk identification, protection of critical assets, and effective response to operational and security-related incidents.
This policy establishes the principles, governance structure, and responsibilities for managing business continuity across PICUS and aligns with applicable laws, regulations, contractual obligations, and international standards, including ISO 22301.
PICUS maintains and continuously improves its business continuity capabilities by supporting corporate strategy and business objectives, ensuring compliance with legal and contractual requirements, identifying and managing business continuity risks, protecting critical processes and information assets, and defining recovery objectives such as Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO). The Company also ensures effective communication and coordination during disruptive events.
To address risks and opportunities, PICUS has established, implemented, and continuously monitors business continuity processes. Relevant plans and procedures are regularly reviewed, tested, and updated to ensure their effectiveness. The Company maintains appropriate documentation to demonstrate that these processes operate as intended and takes corrective actions where necessary to mitigate potential negative impacts.
Based on Business Impact Analysis (BIA) and risk assessment outputs, PICUS defines business continuity and recovery strategies covering activities before, during, and after a disruption. Business continuity and disaster recovery plans are designed to ensure timely communication, coordinated response, and effective management during incidents. These plans are subject to regular testing, validation, and updates to maintain their reliability and effectiveness.
PICUS's risk management framework covers the identification, assessment and mitigation of business continuity risks. The risk assessment and risk improvement plan define how business continuity risks are controlled along with information security risks. The Information Security Committee is responsible for the management and realization of this plan.
The business continuity policy is reviewed at regular intervals or when significant changes occur by Senior Management in order to ensure the continued effectiveness of the system and is updated as needed to ensure continuous suitability, accuracy, and effectiveness.
This policy is intended to be accessible and understandable to all employees and the target audience, including relevant external parties. All employees and external parties defined in the BCMS are obliged to comply with this policy and the processes supporting this policy.
Last update: 23.03.2026
PICUS is committed to delivering reliable, high-quality, and efficient information technology services in alignment with its business objectives and stakeholder expectations. The Company operates its service management practices in accordance with established IT Service Management (ITSM) principles and policies.
The IT Service Management System (ITSMS) is established to ensure the effective operation, management, measurement, and continuous improvement of IT services across PICUS. This policy, approved by Senior Management, defines the principles and requirements for managing IT services in a consistent and structured manner.
PICUS supports its service management objectives by aligning IT services with business strategy and corporate goals, ensuring compliance with applicable laws, standards, and contractual requirements, and effectively managing service-related objectives, processes, and risks. The Company maintains the operational continuity of IT services, manages changes in a controlled manner, and ensures that services are delivered in line with evolving business needs.
All services within the scope of the ITSMS are managed to ensure performance, quality, and reliability. Services defined in the service catalog are delivered in accordance with agreed Service Level Agreements (SLAs), and their performance is regularly monitored, measured, and reported. PICUS continuously improves its services in response to technological developments and business requirements, with the aim of increasing customer satisfaction.
PICUS also manages service accessibility, availability, and capacity through appropriate monitoring and planning activities, while optimizing resource utilization and controlling costs through effective financial and resource management practices.
This policy is reviewed at regular intervals or when significant changes occur in order to measure the operability of the system and services, in order to ensure continuous suitability, accuracy, and effectiveness, and is approved by the Senior Management.
Last Update: 23.03.2026
PICUS is committed to ensuring the secure, responsible, and appropriate use of its information systems and technology resources. This policy establishes the principles and expectations for the use of PICUS communication systems, information assets, and technology services in alignment with Information Security requirements and applicable policies.
PICUS communication and information systems, including software, enterprise applications, processes, information assets, and hardware such as internet services, email, telephony systems, computers, mobile devices, IoT devices, and collaboration tools, are intended primarily for business-related purposes. Any use that is unlawful, disrupts operations, violates company policies, or harms PICUS, its customers, or stakeholders is strictly prohibited.
PICUS requires that all employees, contractors, and third-party users understand and comply with the following acceptable use requirements as part of their employment or engagement:
General Security and Usage Requirements
- Access to Picus systems is granted based on business need and is subject to defined access control and monitoring mechanisms.
- The use of Picus systems may be monitored to ensure compliance with security policies and to protect company assets.
- All workforce members, including remote users, must follow secure access practices and applicable security procedures.
- Devices used for business purposes, including company-provided and authorized personal devices (BYOD), must not be left unattended in public or unsecured environments.
- Encryption must be enabled on devices accessing company data.
- Sensitive or confidential information must be protected during transmission and storage.
- Users must not share or disclose sensitive information through unauthorized channels, including public platforms or social media.
- Users must not share credentials or allow unauthorized access to Picus systems.
- Users are required to promptly report any suspected security incidents, policy violations, or misuse of systems.
Data Handling and Information Protection
- All data handling activities must comply with Picus data classification and data handling requirements.
- Any media containing sensitive information must be appropriately secured.
- Printing or reproduction of sensitive materials must be controlled to prevent unauthorized access.
User Responsibilities and Awareness
- Employees, contractors, and third-party users must acknowledge and comply with applicable policies and procedures.
- Background verification checks are conducted where applicable, in accordance with legal and regulatory requirements and proportional to the role and associated risk.
- Employees must complete onboarding processes and participate in periodic security and privacy awareness training.
- Access rights are revoked immediately upon termination, and all company assets must be returned in accordance with offboarding procedures.
Use of Artificial Intelligence (AI)
- AI technologies may be used only for lawful, ethical, and business-related purposes.
- Only approved AI tools may be used for business activities.
- AI tools must be used within their authorized scope and in accordance with Picus policies.
- Sensitive data, including customer data, personal data, or confidential company information, must not be input into public or unapproved AI systems.
- Where AI tools are approved for specific use cases, their use must follow defined controls and safeguards.
Violations of this policy may result in disciplinary action, up to and including termination of employment or contractual relationships, in accordance with applicable policies and legal requirements.
This policy is implemented under the oversight of the Information Security function, with support from relevant process owners. It is reviewed periodically and updated as necessary to ensure continued effectiveness and alignment with business, security, and regulatory requirements.
Last update: 16.03.2026
At PICUS, protecting personal data is a fundamental part of how we build and maintain trust with our customers, partners, and employees. PICUS processes personal data in a secure, lawful, and transparent manner, in accordance with applicable data protection laws and industry best practices.
This Personal Data Management Policy outlines PICUS’s governance approach, core principles, and key controls for managing personal data. For detailed information on personal data collection, legal bases, and data subject rights, please refer to our Privacy Policy. Inquiries can be directed to privacy@picussecurity.com.
This Policy applies to personal data processed by PICUS in connection with customer and product operations, supplier and business partner relationships, employee and candidate management, and website and business communications.
1. Compliance and Global Standards
PICUS is dedicated to adhering to the highest international legal frameworks and industry standards regarding data protection. Our Information Security Management System (ISMS) and Privacy Information Management System (PIMS) are formally certified under:
- ISO/IEC 27001 - Information Security Management System
- ISO/IEC 27701 - Privacy Information Management System
We conduct regular internal and independent external audits to ensure continuous compliance and effectiveness of our controls.
2. Core Data Protection Principles
Our data processing operations are governed by the principles of Privacy by Design and Default:
- Data Minimization: PICUS collects and processes the minimum data required to deliver its core services.
- Purpose Limitation: PICUS does not use customer data for purposes other than delivering and improving the subscribed services, unless explicitly authorized or required by law.
- Storage Limitation: Data is retained only for the duration of the active subscription or as legally required, after which it is securely deleted or fully anonymized.
3. Cloud Infrastructure and Architecture
PICUS products are built on highly resilient cloud environments, designed to withstand failures and prevent data leakage:
- Shared Responsibility Model: Our primary infrastructure is hosted on Amazon Web Services (AWS). Security is managed under a Shared Responsibility Model; while AWS secures the underlying physical cloud infrastructure, PICUS implements stringent security configurations, access controls, and encryption mechanisms to protect customer data within our environment.
- Logical Separation: Customer data is strictly isolated in multi-tenant environments. We enforce logical separation at the database/datastore level using unique account identifiers. Every query and transaction is cryptographically bound to this specific tenant ID, significantly reducing the risk of cross-tenant data exposure.
4. Data Security and Protection Controls
PICUS implements a risk-based approach to protect personal data through technical and organizational safeguards:
- Data is classified and protected based on sensitivity
- Access to production environments is restricted by default, granted on a least privilege and time-bound basis, and subject to formal approval
- All access and administrative actions are recorded in immutable audit logs and monitored through centralized Security Information and Event Management (SIEM) systems
- Data is encrypted in transit and at rest using industry-standard cryptographic protocols (e.g., AES-256 and TLS 1.2+)
- Customer data is logically segregated in multi-tenant environments
- Systems are continuously monitored for unauthorized access, vulnerabilities, and anomalies
- Secure development practices and confidentiality obligations are enforced across employees and third parties
- Employees and third parties are subject to confidentiality obligations and receive ongoing security and privacy awareness training
Customer data is processed within secure cloud environments designed to ensure high availability, integrity, and confidentiality.
5. Retention and Disposal
Personal data is retained only as long as necessary to fulfill the purposes of processing and to meet legal or contractual obligations.
Data is securely deleted, destroyed, or anonymized when no longer required.
6. Policy Governance
This Policy is approved by Senior Management and reviewed periodically to ensure alignment with regulatory requirements and evolving security practices.
Last update: 24.03.2026
PICUS is committed to integrating environmental, social, and governance (ESG) principles into its operations as a global, remote-first cybersecurity company. The Company aims to minimize its environmental impact, promote human-centered values, and uphold the highest standards of ethical conduct and data protection.
Through its remote-first operating model and cloud-based infrastructure, PICUS significantly reduces reliance on energy-intensive operations and minimizes its impact on natural resources. The Company does not maintain physical data centers or server rooms and promotes resource efficiency through the use of co-working environments where applicable. PICUS also encourages the use of energy-efficient devices, recycling practices, and responsible e-waste disposal across its operations.
PICUS is committed to fostering an inclusive, diverse, and safe work environment. The Company promotes diversity, equity, inclusion, and belonging, and supports employee wellbeing through flexible work arrangements and access to mental health support resources. PICUS strictly prohibits any form of discrimination, forced labor, or unethical practices and is committed to upholding internationally recognized labor and human rights standards.
Governance at PICUS is based on integrity, transparency, and accountability. The Company operates in alignment with internationally recognized frameworks, including ISO/IEC 27001, ISO/IEC 27701, and other relevant standards, and complies with applicable data protection regulations such as GDPR and CCPA. PICUS maintains formal whistleblowing channels, both internal and external, to enable confidential reporting without fear of retaliation.
PICUS continuously seeks to improve the efficiency and sustainability of its digital infrastructure and services. By leveraging cloud technologies that support environmental responsibility and embedding ESG considerations into internal processes and risk management practices, the Company aims to create long-term value for its stakeholders.
PICUS expects its suppliers and partners to adhere to comparable ESG and ethical standards, including compliance with applicable laws, respect for labor and environmental principles, and responsible business practices.
PICUS is committed to continuously improving its ESG practices and maintaining transparency through responsible business conduct.
This policy is reviewed periodically and updated as necessary to reflect changes in regulatory requirements, business operations, and ESG priorities.
Last update: 18.03.2026
The Anti-Bribery and Corruption Policy has been established to define the anti-bribery and corruption principles adopted by PICUS Security, Inc. (“PICUS”) and to communicate the Company’s expectations and responsibilities to employees, business partners, and relevant external parties. Approved by the Senior Management, this policy reflects PICUS’s firm commitment to ethical conduct and compliance with international anti-corruption standards.
PICUS operates with a zero-tolerance approach to bribery and corruption. All employees, contractors, and third parties acting on behalf of the Company are strictly prohibited from offering, giving, requesting, or accepting bribes, kickbacks, or anything of value to gain any unfair business advantage. This includes both commercial bribery and bribery of government or political officials, as defined by the U.S. Foreign Corrupt Practices Act (FCPA), the UK Bribery Act (UKBA), and other applicable laws.
Particular caution is required in all dealings involving government entities, officials of state-owned enterprises, and international organizations. Any gift, entertainment, travel, or other item of value offered to such individuals must be pre-approved in writing by the PICUS Compliance Officer. Facilitation payments, even where culturally common, are not allowed unless legally permitted and specifically authorized.
PICUS carefully vets its third-party partners, including agents, distributors, consultants, and vendors, to ensure they operate with integrity and in line with this policy. All third parties must sign written agreements that include clear anti-bribery compliance clauses.
PICUS adopts a risk-based approach to identifying and mitigating corruption-related threats, particularly when entering new markets or engaging with third parties. Prior to establishing any relationship with agents, consultants, distributors, or other partners, thorough due diligence is conducted to assess ethical practices, potential conflicts of interest, and connections to government entities. All financial transactions and expenditures related to gifts, hospitality, and business development must be accurately documented and justified. Failure to comply with this policy may result in disciplinary actions, including termination of employment or contracts, as well as legal consequences where applicable.
Employees and partners are required to maintain accurate records and report any suspected violations to compliance@picussecurity.com. Anonymous reporting is supported, and retaliation against good-faith whistleblowers is strictly prohibited. All reports are handled confidentially and investigated appropriately.
PICUS provides regular training, conducts internal audits, and performs risk assessments to ensure continued policy compliance and awareness. Breaches of this policy may result in disciplinary action, including termination of employment or business relationships.
This policy is reviewed and updated annually under the oversight of the Compliance Officer and reflects PICUS’s broader commitment to integrity, transparency, and ethical global business practices.
Last Update: 23.03.2026
PICUS is committed to complying with applicable export control and sanctions laws and ensuring that its products and services are not used in violation of such regulations. PICUS applies appropriate controls to prevent unauthorized use, export, re-export, or transfer of its products and services and restricts transactions with prohibited jurisdictions, individuals, and entities in accordance with applicable laws.
This policy defines the principles, governance structure, and practices for export control and sanctions compliance and applies to all PICUS employees, contractors, and relevant external parties, regardless of their location or role, regardless of their location or role.
Every person concerned can send their complaints and notifications directly to the Board by e-mail to notification@picussecurity.com about the issues covered by the policy.
PICUS software products and services are subject to export control and sanctions laws of various jurisdictions, including, without limitation, the United States, the European Union, and Türkiye. These regulations may impose restrictions on certain countries, organizations, and individuals, and are subject to change. Accordingly, all transactions must be assessed against applicable sanctions requirements prior to engagement, with guidance from the Legal function where necessary.
PICUS applies a risk-based approach to export control compliance. This includes identifying business partners and end-users, validating their location and intended use, and assessing potential risks associated with transactions. As part of this process, PICUS considers potential red flags, including unusual or inconsistent transaction patterns, to prevent unauthorized or inappropriate use of its products and services. PICUS also applies verification and screening controls during onboarding processes, including trial access, to ensure compliance with applicable export control and sanctions requirements.
To accomplish applicable foreign policy and national security goals, the applicable
governmental authority (such as the Department of the Treasury’s Office of Foreign Assets Controls (OFAC) in the USA) administers economic sanctions programs and embargoes for several countries. Certain destinations, organizations, and individuals are subject to trade sanctions, embargoes, and restrictions under applicable law. These sanctions are subject to change, usually involve financial components, and can range from narrow restrictions to broad sanctions and embargoes. All transactions must be assessed against applicable sanctions requirements prior to engagement, with guidance from the Legal function where necessary.
Taking into account overall business risks, PICUS Security products and services are not
available for export, reexport, transfer, and/or use in the following sanction countries/regions (subject to change without notice): Cuba, Iran, North Korea, Syria, Crimea Region so-called Donetsk People’s Republic (DNR) / People’s Republic of Luhansk (LNR) regions of Ukraine.
PICUS Security products and services are not available to entities and individuals with
whom transactions are prohibited under applicable export control and sanctions laws,
including those listed on any applicable sanctioned party lists (e.g., European Union
Sanctions List, U.S. Specially Designated National (SDN) lists, U.S. Denied Persons List,
BIS Entity List, United Nations Security Council Sanctions).
PICUS collects and verifies relevant information regarding business partners and end-users and conducts screening through applicable sanctions screening tools, including OFAC and other relevant platforms. Products and services are not provided to individuals or entities subject to applicable sanctions.
Business partners and customers are expected to comply with applicable export control and sanctions regulations and the principles outlined in this policy. Relationships with parties that fail to meet these requirements may be restricted or terminated.
Access to information related to sanctions compliance and investigations is restricted to authorized personnel and managed in accordance with the principle of least privilege. Such information is protected in line with PICUS’s Information Security and Privacy frameworks.
The Legal and Information Security functions are responsible for the implementation and oversight of this policy. PICUS supports compliance through periodic training and awareness activities to ensure that employees understand their responsibilities.
This policy is reviewed periodically and updated as necessary to ensure its continued effectiveness and alignment with applicable regulatory requirements.
Last update: 23.03.2026
b) Corporate Security Practices
An Information Security Director (ISD) leads Picus’s information security and privacy program with a vision of continuous improvement, stronger cybersecurity resilience, broader compliance, and keeping up with the latest technologies. This role includes developing and maintaining security policies, aligning the security strategy with organizational goals, and overseeing incident management. The ISD is also responsible for managing Picus's efforts in information security, business continuity, risk management, auditing, and compliance.
All access requests are managed based on the principle of least privilege. Secure login procedures, including multi-factor authentication (MFA), are implemented. In addition, a stringent password security policy is enforced and a password manager solution is provided for all employees to ensure secure and efficient password management.
At Picus, we implement an effective suite of endpoint security solutions to protect our devices and data. This includes Mobile Device Management (MDM) to enforce security policies on mobile devices, Endpoint Protection Platform (EPP) for antivirus and anti-malware protection, and Endpoint Detection and Response (EDR) for advanced threat detection and incident response. All corporate laptops are encrypted to safeguard sensitive information, and regular updates and patches are applied to ensure systems remain secure. Additionally, we conduct continuous monitoring and logging to detect and respond to any suspicious activities on endpoints promptly.
In Picus systems and platforms, both data in transit and at rest are encrypted using industry-standard algorithms. In addition, special encryptions are used in the SSHv2 protocol to provide secure access to the company cloud servers, where Picus products and systems are hosted.
All systems related to Picus products are cloud-based and have High Availability Architecture in AWS United States, Europe and Middle East data centers. Picus uses redundant RDS instances to ensure full backup recovery of its database. Daily database backups are also taken automatically.
Picus uses a fully encrypted VPN solution as well as HTTPS to communicate with and access its network. All traffic within the network is redirected from HTTP to HTTPS.
Picus operates Secure Development Life Cycle (SDLC) rules based on agility, information security, and secure code development techniques for product and system development, depending on best practices and well-known techniques.
Picus conducts a third-party risk management program and regularly evaluates its vendors through security reviews to minimize associated risks. This ensures that our vendors meet their contractual obligations and comply with applicable legal requirements.
Security and privacy training and awareness programs are conducted for all employees on an annual basis. In addition, regular training sessions as well as secure code training are conducted to Picus developers by field experts.
In addition to conducting internal penetration tests with our Lab teams, Picus also engages with third-party experts for external penetration tests regularly. Recent reports shall only be provided under NDA. To request access to these reports, please reach us at security@picussecurity.com
At Picus, our SIEM solution monitors and analyzes log data from various sources. This proactive approach helps us to quickly identify and respond to potential security threats, ensuring the integrity and confidentiality of our systems and data.
All new employees undergo background checks, including criminal, education, and employment history verification. Additionally, they are required to sign Non-Disclosure and Confidentiality agreements before employment.