This Master Services Agreement (the “MSA”) establishes the general legal and commercial framework for services provided by Proactive Risk Inc. to a Client. The MSA becomes binding only when signed or otherwise accepted by the parties and applies to Quotes and Statements of Work that are executed under it.
Agreement and Definitions
1.1 Agreement. This MSA is between Proactive Risk Inc. (“Proactive Risk” or “Provider”) and the client identified in an executed Quote or SOW (“Client”). The MSA becomes effective when signed or accepted by both parties, and it applies to each Quote and SOW executed under it. A Quote or SOW may identify the parties’ authorized representatives and the effective date for that engagement.
1.2 Definitions. The following terms have the meanings below:
- Affiliate
- An entity that directly or indirectly controls, is controlled by, or is under common control with a party.
- Client Data
- Data, content, records, credentials, configurations, logs, systems information, and other materials provided by or for Client, or accessed by Proactive Risk on Client’s behalf, in connection with the Services.
- Confidential Information
- Non-public information disclosed by or for a party that is identified as confidential or that reasonably should be understood to be confidential given its nature and the circumstances of disclosure.
- Deliverables
- Reports, findings, recommendations, configurations, documentation, or other work product expressly identified as a deliverable in an applicable Quote or SOW.
- Documentation
- User, operational, technical, or other written or electronic materials provided as part of the Services or identified in a Quote or SOW.
- Quote
- A written commercial proposal or order document issued or approved by Proactive Risk that identifies an engagement and is signed or accepted by the parties.
- Services Guide
- A written description of service capabilities or operating practices that is expressly incorporated into a Quote or SOW.
- Services
- The professional, advisory, managed, assessment, testing, training, response, security, compliance, and related services expressly described in an executed Quote or SOW.
- SOW
- A written statement of work that defines the engagement-specific scope, deliverables, schedule, responsibilities, commercial terms, and other details for Services.
- Third-Party Services
- Tools, platforms, software, cloud services, hosting, telecommunications, carriers, and other services or products supplied by a party other than Proactive Risk, including resold services.
- Written Change Order
- A written change to an executed Quote or SOW that describes an approved change to scope, timing, assumptions, responsibilities, fees, expenses, service levels, or other engagement terms and is signed or otherwise approved by authorized representatives of both parties.
Services; Scope; Change Control
2.1 Service portfolio. Proactive Risk may provide CyberAdvisor℠ leadership; 24/7 managed detection and response / ManageIT℠; CATSCAN® adversarial penetration testing; MeasureRISK℠ readiness assessments; PhishIT℠ training and simulations; CyberTrain℠ training and related services; Dark Web Monitoring; RISKWatch℠ third-party risk and compliance; incident response; governance/risk/compliance/security assessments; Microsoft 365/security services; and related professional services. This portfolio describes capabilities only. It does not imply that every service is included in every engagement.
2.2 Engagement scope. Exact scope comes only from the applicable executed Quote or SOW. Each executed Quote or SOW must state:
- the Services and Deliverables;
- milestones, start date, and end date or term;
- assumptions and Client responsibilities;
- the acceptance or rejection timeline;
- fees, recurring fees, the required deposit, progress-invoicing milestones and schedule, invoice amounts or calculation, payment due dates, approved expenses, and any pass-through cap;
- service levels, if any; and
- the written change-order process.
2.3 Change control. Work outside the agreed scope requires Client’s written approval before work begins and may require a Written Change Order. No oral statement, email not clearly identified as an approved change, or informal direction changes an executed Quote, SOW, or this MSA.
Client Authorization, Access, Responsibilities, and Lawful Use
Client will provide authorized access, accurate and complete information, timely personnel and evidence, safe and agreed testing windows, appropriate backups, required approvals, and a knowledgeable point of contact. Client will make decisions and provide responses reasonably needed to keep the engagement on schedule.
Client represents and warrants that it has the authority to provide access to the systems, data, facilities, accounts, and environments identified in the Quote or SOW; that its instructions and intended use of the Services are lawful; that systems and software it supplies are properly licensed; and that it has obtained all permissions required for co-managed environments, hosted systems, and third-party systems. Client is responsible for permissions owed to third parties unless the Quote or SOW expressly assigns that task to Proactive Risk.
Proactive Risk may pause or limit work where access, safety, authorization, information quality, legal compliance, or security risk is inadequate. Proactive Risk will communicate the reason when reasonably practicable, and the parties will work in good faith to restore the conditions needed to resume.
Third-Party and Resold Services
Proactive Risk’s professional services are distinct from Third-Party Services. A Quote or SOW will identify third-party or resold tools, platforms, cloud services, software, carriers, hosting, and providers where applicable, together with pass-through costs or fees and any relevant vendor terms. Client may need to accept the applicable third party’s terms directly.
Proactive Risk remains responsible for the professional services it performs under the applicable Quote or SOW. Proactive Risk does not make warranties about a third party’s products, terms, availability, or performance and does not control a third party’s acts or omissions. This allocation does not eliminate Proactive Risk’s own obligations for its contracted Services or any express service-level commitment in a Quote or SOW.
Fees, Invoicing, Payment, Taxes, Expenses, and Price Changes
5.1 Fees, deposits, and progress invoices. The applicable Quote or SOW controls the fees and recurring fees for the engagement. Each applicable Quote or SOW must require a deposit and progress invoices and must specify the deposit amount, the milestones tied to each progress invoice, each invoice amount or calculation, the invoicing timing, and payment due dates. Client will pay the deposit and progress invoices by those stated due dates. Recurring fees and any price increases must be stated in the Quote, SOW, or renewal notice and may not be hidden in a Services Guide.
5.2 Disputes, expenses, and charges. Client must raise any invoice dispute timely and in writing with reasonable detail identifying the disputed amount and the basis for the dispute. Undisputed amounts remain payable while the parties work in good faith to resolve the disputed amount. Approved expenses up to an aggregate of $250 per month may be incurred without prior Client consent. Expenses above that threshold require Client’s prior written approval, and all expenses and pass-through costs remain subject to any cap stated in the applicable SOW. Overdue undisputed amounts may accrue a late charge of 1.5% per month (18% annualized equivalent), subject to applicable law, only as stated in the applicable Quote or SOW. Client will pay applicable taxes other than taxes on Proactive Risk’s net income.
5.3 Price changes. A recurring-fee increase of 5% or less must be stated in the applicable Quote, SOW, or renewal notice and delivered in writing under Section 17. A recurring-fee increase above 5% requires at least 60 days’ prior written notice under Section 17. Client may terminate the affected recurring service by written notice delivered at least 60 days before the increase takes effect, without an early-termination fee for that affected service, subject to accrued amounts and the applicable Quote or SOW. The applicable Quote or SOW may state engagement-specific pricing or price-adjustment mechanics and controls over this MSA only as provided in Section 18.
5.4 No unstated commercial terms. A Services Guide does not establish or change fees, due dates, late-charge rates, price-increase notice, expenses, or pass-through limits.
Acceptance; Service Levels; Suspension
The applicable Quote or SOW must state the timeline and process for accepting or rejecting a Deliverable. If the Quote or SOW does not state an acceptance or rejection period, this MSA does not imply an automatic acceptance period. Client will give reasonably specific written rejection reasons, and the parties will work in good faith to address a valid rejection within the agreed scope.
Service levels, response targets, service credits, maintenance windows, and availability commitments apply only if expressly included in the applicable Quote or SOW. Unless expressly committed in writing, the Services are not guaranteed to be uninterrupted or error-free.
Proactive Risk may suspend affected Services, proportionately and with notice where practicable, for material nonpayment after notice, security risk, unlawful use, missing or unsafe access, or a material third-party dependency. Proactive Risk will restore Services when the cause is cured or adequate safeguards are agreed, where restoration is reasonably possible.
Term, Renewal, Termination, and Transition
The MSA begins on execution and continues until terminated. Each Quote or SOW has its own term and renewal provisions. A party may terminate the MSA or an affected Quote or SOW for material breach if the breach is not cured within the written notice and cure period stated in the notice or applicable document, subject to any non-waivable law. Either party may terminate for insolvency to the extent lawful. Proactive Risk may terminate or suspend an affected engagement where continued performance would create a material security or legal risk that cannot reasonably be mitigated.
A Client termination-for-convenience right or a mutual termination-for-convenience mechanism is available only if the applicable Quote or SOW expressly provides it. The applicable Quote or SOW must state the required notice period and clearly define any termination fee, including its amount or calculation. No termination-fee percentage or dollar amount is implied by this MSA. On termination, Client will pay the stated termination fee, if any, together with accrued amounts, non-cancellable commitments, approved expenses, and approved pass-through costs through the effective date.
At Client’s written request, the parties will reasonably cooperate in transition and offboarding at the then-current or otherwise agreed rates. Transition may include a final status report, transfer of agreed Deliverables, return or deletion of Client Data, credential rotation, and coordination with a successor provider. Data return or deletion remains subject to Section 8 and lawful retention, backups, evidence preservation, and technical limitations. Sections that by their nature should survive termination will survive, including payment, confidentiality, ownership, disclaimers, indemnification, liability limits, dispute provisions, and general terms.
Client Data, Data Protection, Security, and Incident Cooperation
Client owns Client Data and Client’s materials. Proactive Risk may access and process Client Data only as reasonably necessary to perform the Services, follow Client’s documented instructions, meet the applicable Quote or SOW, protect the Services, or comply with law. Proactive Risk will use commercially reasonable safeguards appropriate to the nature of the Services and may use personnel, subcontractors, and providers as permitted by this MSA and the applicable Quote or SOW.
Client will reasonably cooperate with cybersecurity incidents and investigations related to the Services, including by preserving relevant logs and evidence, providing timely notices and decisions, rotating credentials when appropriate, and making knowledgeable personnel available. The parties will coordinate communications and evidence handling consistent with applicable law and the incident plan, if any. Proactive Risk does not promise a particular regulatory result, certification, audit outcome, or legal conclusion.
A DPA, security addendum, or other order-specific addendum is optional and client- or service-specific and may be attached when Proactive Risk is processing personal data or PHI, or when a government or regulated client requires it. It applies only when separately executed or required by the applicable Quote or SOW or by law; it is not mandatory under this MSA alone. On termination or expiration of the applicable project, Proactive Risk will retain project data for 12 months from the end of that project unless otherwise agreed in writing. At the end of that period, Proactive Risk will return or delete the project data as requested in writing, subject to legal holds, backups, evidence preservation, applicable law, and technical feasibility. Proactive Risk will continue to protect retained project data and delete it when the applicable retention reason ends, where reasonably practicable.
Confidentiality
Each party will use the other party’s Confidential Information only to perform or receive the Services or exercise rights under the agreement, protect it with at least reasonable care, and disclose it only to representatives, Affiliates, professional advisers, subcontractors, and providers who need to know it and are bound by confidentiality obligations. Each party remains responsible for its representatives’ compliance.
Confidential Information does not include information that the receiving party can demonstrate was already known without restriction, becomes public without breach, is received lawfully from another source without a duty of confidentiality, or is independently developed without use of the disclosing party’s Confidential Information. If disclosure is compelled by law, the receiving party will provide advance notice where lawful and reasonably cooperate with a protective order or similar measure.
On request or termination, each party will return or delete the other party’s Confidential Information, subject to legal retention, backup, evidence, and archival requirements. These obligations do not limit trade-secret protection for as long as the information remains a trade secret. Proactive Risk may use aggregated and de-identified learnings that do not identify Client or disclose Client Confidential Information.
Ownership, Deliverables, and Intellectual Property
Client retains all rights in Client Data and Client’s materials. Each party retains its pre-existing intellectual property, including software, tools, methods, templates, know-how, and materials developed outside the engagement. Third-party materials remain subject to the applicable vendor terms.
Upon Client’s payment of the applicable fees, Client receives the ownership or license expressly specified in the Quote or SOW for paid Deliverables. If the Quote or SOW is silent, Proactive Risk grants Client a nonexclusive, nontransferable license to use the paid Deliverables for Client’s internal business purposes. Proactive Risk retains its tools, methods, templates, know-how, scripts, generic configurations, and reusable materials, including improvements that do not disclose Client Confidential Information or claim ownership of Client-specific data.
Proactive Risk may identify Client as a customer only if the applicable Quote or SOW permits it or Client gives written permission. Nothing in this MSA transfers Client Data or Client-specific materials to Proactive Risk.
Warranties and Disclaimers
Each party represents that it has authority to enter into this MSA and the applicable Quote or SOW. Proactive Risk will perform its professional Services in a professional and workmanlike manner consistent with generally accepted industry practice. Client warrants that it has the authority to provide Client Data, access, systems, and instructions and that its instructions and use of the Services are lawful.
Cybersecurity, compliance, and advisory Services are risk-reduction services. They do not guarantee prevention, complete threat detection, response, remediation, uninterrupted availability, a particular security posture, audit result, certification, regulatory compliance, or discovery of every vulnerability unless expressly stated in a Quote or SOW. Proactive Risk does not provide legal, tax, accounting, or investment advice.
Except for the express written commitments in this MSA, a Quote, SOW, or signed addendum, each party disclaims warranties to the extent permitted by law. No disclaimer limits an express written service-level commitment, and no provision limits a right or liability that cannot legally be limited.
Indemnification
Each party will defend the other party against a third-party claim to the extent caused by the indemnifying party’s gross negligence, willful misconduct, or material breach of this MSA, and will indemnify the other party for damages, reasonable attorneys’ fees, and costs finally awarded or agreed in a permitted settlement. The indemnified party will give prompt written notice reasonably describing the claim, provide reasonable cooperation at the indemnifying party’s expense, and allow the indemnifying party to control the defense, subject to the protections below.
The indemnifying party may not settle a claim in a way that admits fault by, imposes a non-monetary obligation on, or restricts the rights of the indemnified party without that party’s prior written consent, not unreasonably withheld. The indemnified party may participate with counsel at its own expense.
Client is responsible for claims arising from Client Data, unlawful instructions, unauthorized systems or access supplied by Client, or Client’s violation of a third party’s rights, to the extent caused by those matters. Any additional intellectual-property infringement indemnity or data/privacy indemnity must be expressly approved in the applicable Quote or SOW or a counsel-approved addendum.
Limitation of Liability
13.1 Aggregate cap. Each party’s aggregate liability arising out of or related to this MSA or the affected Quote or SOW will not exceed the fees paid by Client under that affected Quote or SOW in the three months preceding the event giving rise to the claim, and will not exceed the total fees paid under that affected Quote or SOW.
13.2 Damages exclusion. To the extent permitted by law, neither party will be liable for consequential, incidental, special, exemplary, punitive, or lost-profit or lost-revenue damages arising from the agreement. Direct damages remain subject to the aggregate cap in Section 13.1, except as provided in Section 13.3.
13.3 Carve-outs. To the extent permitted by law, the aggregate liability cap in Section 13.1 and the consequential-damages exclusion in Section 13.2 do not apply to liability arising from payment obligations, confidentiality breaches, gross negligence or willful misconduct, fraud, intellectual-property infringement, or indemnity obligations. All other liability remains subject to the Section 13.1 cap: fees paid under the affected Quote or SOW in the three months preceding the event giving rise to the claim, not exceeding total fees paid under that affected Quote or SOW, and remains subject to the Section 13.2 exclusion. The carve-outs apply only to the liability or damages within those categories and do not permit duplicate recovery or recovery of the same loss more than once.
Insurance and Risk Allocation
Each party will maintain the following standard coverage, as applicable to its role and the engagement: General Liability $1,000,000; Cyber/Errors & Omissions $1,000,000; Workers’ Compensation where required by law. A certificate of insurance is available on request. The applicable Quote or SOW, or a counsel-approved addendum, may specify additional details where appropriate. This MSA does not transfer risks beyond the express terms approved for the engagement.
Force Majeure
Neither party is responsible for delay or failure to perform non-payment obligations caused by events beyond its reasonable control, including natural disasters, war, terrorism, civil unrest, labor disruption, governmental action, widespread utility or telecommunications outages, and outages or failures of Third-Party Services or dependencies, where appropriate. The affected party will give notice when reasonably practicable, mitigate the effects, and resume performance as soon as reasonably possible.
Force majeure does not excuse payment obligations already due or reasonable security, confidentiality, data-protection, incident-cooperation, or mitigation obligations. If the event materially continues for a prolonged period, either party may pursue the termination or transition rights stated in the applicable Quote or SOW or, if none are stated, reasonable termination on written notice subject to payment for Services performed.
Dispute Resolution; Governing Law
New Jersey law governs this MSA and each Quote or SOW, without regard to conflicts-of-law rules. Before formal proceedings, authorized business representatives will make a good-faith effort to escalate and resolve a dispute. If formal proceedings are necessary, they must be brought in the state or federal courts located in Morris County, New Jersey, and each party consents to that forum. This MSA does not require arbitration and includes no jury waiver or class waiver. Either party may seek temporary or preliminary equitable relief where appropriate to protect Confidential Information, intellectual property, systems, Client Data, or other rights.
Notices; Assignment; Subcontractors
Notices under this MSA must be in writing. Notices to Proactive Risk must be sent to Proactive Risk Inc., 36 First Avenue, Suite 203, Denville, NJ 07834, or by email to legal@proactiverisk.com. Notices to Client must be sent to the Client notice address and email stated in the applicable Quote or SOW. The applicable Quote or SOW must identify the required delivery method and any delivery or receipt mechanics. A notice is effective when delivered to the stated address or when receipt is confirmed through the stated electronic method, subject to any more specific notice terms approved in the Quote or SOW.
Neither party may assign this MSA or an applicable Quote or SOW without the other party’s prior written consent, not unreasonably withheld, except to an Affiliate or in connection with a merger, reorganization, or sale of substantially all of the assigning party’s assets, provided the assignee assumes the obligations and the assignment does not materially impair the other party’s rights. An assignment does not release pre-assignment obligations.
Proactive Risk may engage specialized project subcontractors, counsel, subject-matter experts, and service providers as needed for the Services, subject to confidentiality, security, and applicable flow-down obligations. Proactive Risk remains responsible for its personnel and its contracted Services. The allocation for Third-Party Services and resold services remains governed by Section 4 and the applicable Quote or SOW.
General Terms
If a provision is unenforceable, it will be modified to the minimum extent needed to be enforceable, and the remaining provisions remain effective. A waiver must be in writing and applies only to the specific instance. This MSA, executed Quotes and SOWs, incorporated Services Guides, and signed DPAs, security addenda, or other order-specific addenda are the entire agreement for the Services and replace prior discussions on that subject. Amendments require a signed writing by authorized representatives; no oral modification is effective.
The document hierarchy is: (1) the signed MSA governs general legal and commercial terms; (2) the signed Quote or SOW governs engagement-specific scope, Deliverables, milestones, dates or term, assumptions, Client responsibilities, acceptance or rejection, fees, deposits, progress-invoicing schedule, payment due dates, recurring-fee price-adjustment mechanics, expenses or pass-through cap, service levels, and Written Change Orders, and controls over the MSA only for an express, specific conflict identified in the Quote or SOW; (3) an incorporated Services Guide governs operational or service descriptions only to the extent expressly incorporated and not inconsistent with the MSA or Quote or SOW; (4) a signed DPA, security addendum, or other order-specific addendum controls only for its expressly covered privacy or security subject matter and only to the extent expressly stated; and (5) purchase-order boilerplate does not amend the agreement unless Proactive Risk expressly signs a written amendment. A Services Guide does not automatically control a conflict.
The parties may use electronic signatures and counterparts, each of which is deemed an original. No person other than the parties and expressly permitted successors has third-party-beneficiary rights. The parties are independent contractors; neither may bind the other, and nothing creates a partnership, joint venture, fiduciary, or employment relationship. Headings are for readability and do not change meaning. This MSA will be construed fairly without a presumption against either party. Sections concerning payment, data, confidentiality, ownership, disclaimers, indemnification, liability, dispute resolution, and other provisions intended by their nature to survive will survive termination.
Questions or accommodation requests may be sent to Proactive Risk Inc. at 36 First Avenue, Suite 203, Denville, NJ 07834, by phone at 973-298-1160, or through the contact method stated in the applicable Quote or SOW.
Provider contact
Proactive Risk Inc.
36 First Avenue, Suite 203
Denville, NJ 07834
973-298-1160