These Service Terms apply to managed security services provided by Spider Security Services, LLC ("Spider Security" or "Provider"). They are part of the Agreement together with the Order and the Master Service Terms. Capitalized terms not defined here have the meanings in the Master Service Terms. These Service Terms supplement the Master Service Terms and, where stated, override the Master Service Terms defaults; anything they do not address is governed by the Master Service Terms, and an Order may override both as described in Section 3.2 of the Master Service Terms.
1. Services
1.1 Managed security infrastructure. Spider Security provides a fully managed cybersecurity infrastructure delivered from Provider's own cloud (the "Security Services"). Provider designs, operates, and maintains the environment: the path Client's traffic takes, the controls applied to it, and the ongoing care those controls need. In short: we provide the hardware, you provide the traffic.
1.2 Controls. Depending on the Order, the Security Services may include:
- URL and web content filtering;
- intrusion detection and prevention;
- endpoint protection software for Client devices;
- security monitoring and alerting;
- optional TLS inspection, only if added under Section 2.4; and
- the other services stated in the Order.
Spider Security does not provide security camera or video surveillance services.
1.3 Sizing and pricing. The Security Services are sized and priced by (a) the equipment required at each site, (b) the number of sites, and (c) the failover and redundancy capacity selected. The Order lists each site, the equipment, and the failover design. Adding or removing sites, equipment, or redundancy requires a change to the Order.
2. Policies and configuration
2.1 Security policies. Provider will configure the controls using its standard baseline, adjusted to Client's reasonable requirements (for example, URL categories to block or allow). Client is responsible for approving its policies and for the business impact of the categories, sites, and applications it chooses to allow or block.
2.2 False positives. Security controls may occasionally block legitimate traffic, sites, or files, or fail to flag malicious ones. Provider will adjust policies when Client reports an issue, but is not liable for business interruption caused by controls operating as configured.
2.3 Traffic inspection (default: no decryption). To apply the controls, Provider's systems inspect Client's network traffic. By default, Provider does not decrypt encrypted (TLS/SSL, including HTTPS) traffic. For encrypted traffic, the Security Services see only metadata, such as source and destination IP addresses, ports, the domain name or server name indication (SNI) requested, certificate information, connection times, traffic volumes, and matches to threat signatures, and not the decrypted content.
2.4 Optional TLS inspection. TLS inspection (decrypting and inspecting encrypted traffic) is an optional add-on that is off unless Client specifically requests it and agrees to it in writing in an Order, SOW, or signed change order that identifies the networks, users, or devices covered. If TLS inspection is enabled:
- (a) Client is responsible for giving all notices to, and obtaining all consents from, its employees, users, and other individuals that applicable law or Client's own policies require, and for deploying any certificates needed on its devices;
- (b) Client will choose the categories, sites, applications, users, and devices to exclude from decryption, and Provider will configure exclusions for sensitive categories such as health, medical, banking, financial, and government sites by default unless Client directs otherwise in writing;
- (c) decrypted content is inspected automatically to apply the security controls, is not reviewed by Provider personnel except as needed to investigate a specific security event or support request, and is handled under Section 3.3; and
- (d) Client may turn TLS inspection off at any time by written request.
3. Monitoring and logging consent
3.1 Authorization. Client authorizes Provider to monitor, inspect, log, and analyze network traffic (including decrypted traffic only if TLS inspection is enabled under Section 2.4), device activity, and endpoint telemetry from the networks, devices, and locations covered by the Order, for the purpose of providing the Security Services.
3.2 What is collected. The data collected is described in Section 3.6 of the Privacy Policy, and includes traffic metadata, domains (and, where TLS inspection is enabled or traffic is unencrypted, URLs) requested, security events, and endpoint telemetry.
3.3 Log sanitization and retention. Provider sanitizes and correlates logs that contain identifiable information. Unsanitized logs are expired and removed within twenty-four (24) hours of correlation. Some unsanitized logs may continue to exist in encrypted backups until the backup is replaced. Sanitized logs are retained as needed to provide and improve the Security Services. If Client needs longer retention of identifiable logs (for example, for compliance or investigations), that must be stated in the Order. [CONFIRM: EXTENDED LOG RETENTION OPTION]
4. Client authority and required notices
4.1 Authority. Client represents and warrants that it owns or has legal authority over every network, device, account, and location covered by the Security Services, and has the right to authorize Provider to monitor them. Client will not ask Provider to monitor any network, device, or person that Client is not legally entitled to monitor.
4.2 Notices and consents. Client is responsible for giving all notices to, and obtaining all consents from, its employees, contractors, guests, customers, and other individuals that applicable law requires for network monitoring, endpoint monitoring, and (if enabled) TLS inspection. This includes, where applicable, written employee monitoring notices required by state law and consents for any personal devices enrolled in endpoint protection.
4.3 Responsibility. Provider relies on Client's representations in this Section. Client's indemnity in Section 14.2 of the Master Service Terms covers claims arising from Client's lack of authority or failure to give required notices or obtain required consents.
5. Acceptable use
Client will not, and will not allow anyone to: use the Security Services or Provider Equipment for unlawful purposes; attempt to bypass, disable, or tamper with security controls or monitoring (except through an authorized policy change); use the Security Services to attack, scan, or probe third-party systems; route third-party networks that are not covered by the Order through the Security Services; or resell the Security Services. Penetration testing of Provider's cloud or equipment requires Provider's prior written approval.
6. Provider Equipment
6.1 Ownership. All firewalls, appliances, sensors, switches, access points, and other equipment that Provider supplies are Provider Equipment (as defined in the Master Service Terms). Provider Equipment is owned by the Equipment Lessor, Spider Leasing Services, LLC, and leased to Spider Security, which supplies it to Client as part of the Security Services. Title remains with the Equipment Lessor at all times, even when the equipment is installed at Client's site, and Client obtains no ownership interest. Client will keep Provider Equipment free of liens, security interests, and other encumbrances and will not remove the Equipment Lessor's or Provider's labels. The Equipment Lessor is not a party to the Order; Client will look solely to Spider Security for the Security Services, support, repair, and replacement. The Equipment Lessor only owns the equipment and does not access, process, or receive Client Data.
6.2 Installation and access. Client will give Provider reasonable access to its sites to install, inspect, maintain, replace, and remove Provider Equipment, and will provide the space, power, network connections, and environmental conditions stated in the Order.
6.3 Care. Client will use reasonable care to protect Provider Equipment from loss, theft, and damage, keep it in a secure location, and not move, open, modify, repair, or disconnect it, or permit anyone else to do so, without Provider's approval. Client will notify Provider promptly of any loss, damage, or malfunction.
6.4 Risk of loss. Client bears the risk of loss or damage to Provider Equipment while it is at Client's sites, other than normal wear and tear or damage caused by Provider. Client will pay Provider the replacement cost ([EQUIPMENT REPLACEMENT COST SCHEDULE]) for lost, stolen, or damaged Provider Equipment. Client may wish to include Provider Equipment in its property insurance.
6.5 Replacement and upgrades. Provider will repair or replace failed Provider Equipment at no additional charge (unless caused by Client) and may upgrade or replace Provider Equipment at its discretion to maintain the Security Services.
6.6 Return on termination. Within [EQUIPMENT RETURN PERIOD, E.G., 15] days after an Order ends, Client will make all Provider Equipment available for pickup by Provider or return it to Provider (or as Provider directs), on the Equipment Lessor's behalf, in good condition (normal wear excepted) using shipping materials and instructions Provider supplies. Provider will securely wipe returned equipment. If equipment is not returned within that period, Provider may invoice Client for the replacement cost. [CONFIRM: WHO PAYS RETURN SHIPPING / DE-INSTALLATION]
6.7 Endpoint software. Endpoint protection software is licensed, not sold, for use only during the term. Client will allow Provider to install, update, and remove it, and will not uninstall or disable it on covered devices without notifying Provider.
7. Failover and availability
7.1 Failover. Provider will implement the failover and redundancy design stated in the Order. Failover protection is limited to the components and capacity Client selects. Unless purchased, Client does not have redundant equipment, circuits, or capacity.
7.2 Client circuits. Client is responsible for its Internet service and other circuits, including backup circuits needed for failover. Provider is not responsible for outages of Client's Internet service providers.
7.3 Availability. Provider will use commercially reasonable efforts to keep its cloud and the Security Services available [SLA]. Maintenance and status updates are posted at status.spider.services.
7.4 Fail-open / fail-closed. The Order will state whether traffic is allowed to pass (fail-open) or blocked (fail-closed) if a security control becomes unavailable. [CONFIRM: DEFAULT FAIL BEHAVIOR]
8. No guarantee against all threats
The Security Services are designed to reduce the risk of attack and data loss. They cannot detect or stop every threat, including new or unknown attacks, attacks that originate from compromised credentials or insiders, social engineering, or threats on devices or networks not covered by the Order. Section 12.3 of the Master Service Terms applies. Client remains responsible for its broader security program, including user training, backups of systems not hosted by Spider Computing, and patching of systems Provider does not manage.
9. Incident notification and response
9.1 Alerts. Provider will notify Client's designated contacts of security events that Provider's monitoring identifies as significant, according to the escalation procedures in the Order, and within [ALERT NOTICE PERIOD BY SEVERITY].
9.2 Security Incidents. If Provider confirms a Security Incident affecting Client Data in Provider's systems, Provider will notify Client under Section 9.4 of the Master Service Terms and provide the information reasonably available to help Client assess its notice obligations (for example, under Missouri's breach notification law, RSMo § 407.1500).
9.3 Response. Containment actions within the Security Services (for example, blocking an address or isolating an endpoint) are included. Forensic investigation, extended incident response, and remediation beyond the Security Services are not included unless stated in the Order and may be provided as additional services at [RATE]. [CONFIRM: INCIDENT RESPONSE SCOPE]
9.4 Client obligations. Client will keep its escalation contacts current, notify Provider promptly of suspected incidents, and remains responsible for any legally required notices to its customers, employees, regulators (including, where required, the Missouri Attorney General and consumer reporting agencies), and insurers.
10. Term
The Security Services begin on the service activation date for each site and continue for the term stated in the Order, subject to the renewal and termination terms in the Master Service Terms. [MINIMUM TERM]