Standard Terms & Conditions
The terms that govern CoreDefense quotes, orders and service engagements.
This is the current version. Permanent link to this version: https://www.coredefensesg.com/terms/standard-terms/2026-09-01. These terms apply to quotes and orders; use of this website is covered by the separate website Terms and Conditions.
These Standard Terms & Conditions ("Terms") apply to all quotes, proposals, and orders issued by CoreDefense Security Group, LLC ("CoreDefense," "we," "us," or "our") to the customer identified on the accompanying quote ("Client," "you," or "your"). By accepting a quote, issuing a purchase order, or authorizing work, Client agrees to these Terms.
- 1. Quote Validity & Acceptance
- 2. Scope of Work
- 3. Pricing, Taxes & Expenses
- 4. Payment Terms
- 5. Hardware, Products & Manufacturer Warranties
- 6. Professional Services & Change Orders
- 7. Client Responsibilities
- 8. Security Disclaimer
- 9. Limited Warranty & Disclaimer
- 10. Limitation of Liability
- 11. Confidentiality
- 12. Intellectual Property
- 13. Cancellation
- 14. Force Majeure
- 15. Governing Law & Dispute Resolution
- 16. General Provisions
1. Quote Validity & Acceptance
1.1 The prices, configurations, and availability set forth in a quote are valid for 30 days from the quote date unless otherwise stated, after which the quote expires and is subject to change or withdrawal without notice. CoreDefense may correct typographical, clerical, or pricing errors in a quote at any time before it becomes a binding order, even within the validity period.
1.2 A quote becomes a binding order upon the earliest of: (a) Client's written or electronic acceptance or signature; (b) Client's issuance of a purchase order referencing the quote; or (c) Client's payment of any deposit or invoice associated with the quote. By accepting a quote through any of these means, Client agrees to these Terms, which govern the order regardless of any different or additional terms in Client's acceptance or purchase order. CoreDefense's acceptance of an order, or commencement of work, is the point at which a binding contract is formed, and CoreDefense may decline any order before that point.
1.3 Acceptance is limited to the products, deliverables, and services expressly described in the quote and any associated statement of work. Anything not expressly included is out of scope and governed by Sections 2 and 6. These Terms apply to the quote and all related orders, deliverables, and services, and are incorporated into the quote by reference.
2. Scope of Work
2.1 The quote, together with any associated statement of work, describes the specific products, deliverables, and services CoreDefense will provide ("Scope"). CoreDefense's obligations are limited to the Scope as expressly stated, and anything not expressly included is excluded. Without limitation, work involving additional sites, locations, devices, users, applications, configurations, integrations, data migration, or service phases is out of scope and requires a separate quote or an approved written change order under Section 6.
2.2 Where a quote references a CoreDefense SecurePath phase (SecurePath Consult, SecurePath Integrate, or SecurePath Manage), the deliverables for that phase are limited to those itemized in the applicable quote and statement of work. Each phase is separately scoped and separately ordered; acceptance of one phase does not obligate either party to proceed with any other phase, and recommendations or findings produced in one phase do not expand the deliverables of another. SecurePath Manage and other recurring services are additionally governed by the applicable managed-services agreement under Section 13.2.
3. Pricing, Taxes & Expenses
3.1 All prices are stated in U.S. dollars and are exclusive of all applicable sales, use, excise, gross-receipts, or similar taxes, duties, or government charges, all of which are Client's responsibility, except for taxes based on CoreDefense's net income. If Client claims a tax exemption, Client must provide a valid exemption certificate before invoicing; Client remains responsible for any taxes, interest, or penalties later assessed if an exemption is disallowed.
3.2 Unless expressly stated on the quote, prices do not include, and CoreDefense may separately bill for: shipping, freight, insurance, and handling; travel, mileage, lodging, and per-diem expenses; after-hours, weekend, holiday, or emergency labor premiums; expedited or rush charges; third-party software, subscription, licensing, and renewal fees; and any other costs not expressly itemized in the quote. Reimbursable expenses will be billed at cost unless a different basis is stated.
3.3 Hardware and third-party product pricing is based on supplier and manufacturer pricing in effect at quote time and remains subject to change until CoreDefense places the order, including changes resulting from supplier price adjustments, tariffs, duties, currency fluctuation, or product availability. CoreDefense will notify Client of any material price increase before proceeding; Client may then approve the revised price or cancel the affected items, and any deposit will be applied or refunded to the extent the items are cancelable. Absent timely approval, CoreDefense is not obligated to place or hold the order at the quoted price.
4. Payment Terms
4.1 Unless otherwise stated on the quote, payment terms are Net 30 days from invoice date. All amounts are payable in U.S. dollars without setoff, deduction, or withholding. Client must notify CoreDefense in writing of any good-faith dispute regarding an invoice within ten (10) days of the invoice date; undisputed amounts remain due on the original terms, and invoices not disputed within that period are deemed accepted.
4.2 Hardware and special-order products require a deposit of 50% of the product price (or 100% for non-cancelable or non-returnable items) before CoreDefense places the order; CoreDefense is not obligated to order until the deposit is received. Deposits are non-refundable to the extent CoreDefense has incurred non-cancelable supplier commitments. Hardware is invoiced upon order or delivery, not upon project completion, and payment for hardware is not contingent on completion of any related services.
4.3 Recurring services, including SecurePath Manage, are billed monthly in advance and are due on the invoice date. Recurring fees are not contingent on usage and are not subject to reduction or refund for periods during which Client does not use the services. CoreDefense may adjust recurring fees upon at least thirty (30) days' written notice, effective at the start of the next billing cycle or renewal term. Specific term, renewal, and termination provisions are governed by the applicable managed-services agreement under Section 13.2.
4.4 Past-due balances accrue interest at the lesser of 1.5% per month (18% per annum) or the maximum rate permitted by law, from the due date until paid. Client is responsible for all reasonable costs of collection, including collection-agency fees and reasonable attorneys' fees and court or arbitration costs, whether or not suit is filed.
4.5 If an account is past due, CoreDefense may, after providing five (5) business days' written notice and opportunity to cure, suspend services, withhold delivery or activation of products, or withhold further work until the account is brought current. Suspension does not relieve Client of its payment obligations, and CoreDefense is not liable for any consequence of a suspension arising from Client's non-payment, including any service interruption or security exposure during the suspension. Recurring service fees continue to accrue during any suspension for non-payment.
5. Hardware, Products & Manufacturer Warranties
5.1 Title to hardware passes to Client upon CoreDefense's receipt of payment in full; risk of loss passes upon delivery to Client or to Client's carrier. Until full payment is received, CoreDefense retains a purchase-money security interest in the hardware, and Client authorizes CoreDefense to file any financing statements necessary to perfect that interest.
5.2 Hardware and third-party products are provided as-is by CoreDefense and carry only the warranties, if any, offered by their respective manufacturers. CoreDefense passes through to Client all manufacturer warranties that are assignable, but does not itself warrant third-party hardware or software and disclaims all such warranties as set forth in Section 9.2. This Section does not apply to CoreDefense's own professional services, which are governed by Section 9.1.
5.3 Manufacturer support, RMA, firmware, and licensing are governed by the applicable manufacturer's end-user license and support agreements, which Client agrees to comply with. Certain features, security updates, and threat-intelligence services require active manufacturer subscriptions or licenses. Client is solely responsible for maintaining these unless expressly included in a CoreDefense managed-services agreement, and CoreDefense is not responsible for any reduced functionality, lapse in protection, or security exposure resulting from expired, insufficient, or unmaintained subscriptions or licenses.
5.4 Special-order, custom-configured, opened, registered, or activated equipment is non-returnable and non-refundable except as covered by the applicable manufacturer's warranty. Returns of eligible, unopened items, where permitted by the supplier, may be subject to a restocking fee of up to 15% plus shipping and handling, and are conditioned on the supplier accepting the return.
5.5 Delivery dates and lead times are estimates only and are subject to manufacturer production schedules and supply-chain availability. CoreDefense is not liable for any delay in delivery or performance caused by events outside its reasonable control, as further provided in Section 14 (Force Majeure), and in no event is CoreDefense liable for any loss, cost, or damage arising from delivery delay beyond the remedies in Sections 9 and 10.
6. Professional Services & Change Orders
6.1 Labor and professional-services pricing is based on the scope, environment, and information known or provided at quote time, and unless a quote expressly states a fixed price, all labor estimates are good-faith approximations, not guaranteed maximums. Material changes to scope, environment, or requirements—and any conditions discovered during the engagement that differ from those represented or reasonably assumed at quote time—may affect price and schedule and may require a change order under Section 6.2.
6.2 Any change to an accepted scope will be documented in a written change order describing the revised work, price, and schedule impact, and must be approved by both parties before the affected work proceeds. CoreDefense is not obligated to perform, and Client is not obligated to pay for, out-of-scope work absent an approved change order, except that where a change is needed to address an urgent or safety-related condition, the parties may authorize work to proceed by written confirmation (including email), to be documented in a formal change order promptly thereafter.
6.3 Scheduled work assumes timely Client cooperation and readiness. Delays, rescheduling, cancellations on short notice, or standby/idle time caused by Client or by Client's environment may be billed at CoreDefense's then-current rates, subject to any applicable minimum charge, and CoreDefense is not responsible for resulting schedule impacts. Client will provide at least two (2) business days' notice to reschedule or cancel scheduled on-site work; later changes may incur a charge for reserved time and any non-recoverable travel or third-party costs.
7. Client Responsibilities
7.1 Client agrees to provide, in a timely manner and at no cost to CoreDefense: (a) reasonable access to facilities, systems, networks, and knowledgeable personnel; (b) accurate and complete environment, configuration, and account information; (c) all required credentials, licenses, subscriptions, and third-party authorizations or consents; and (d) a suitable, safe, and ready physical and network environment for the work. Client acknowledges that CoreDefense's ability to perform, and its timelines and estimates, depend on Client meeting these responsibilities, and that any delay, inaccuracy, or failure by Client may result in delays or additional charges at CoreDefense's then-current rates, for which CoreDefense is not responsible.
7.2 Client is solely responsible for maintaining current, complete, and verified backups of its data, systems, and configurations prior to and throughout any CoreDefense engagement, unless backup is an expressly contracted CoreDefense service. Client acknowledges that any work involving networks, systems, or storage carries an inherent risk of data loss or corruption, and that maintaining independent backups is Client's safeguard against that risk. CoreDefense is not responsible or liable for any loss, corruption, or inaccessibility of data arising from pre-existing conditions, Client systems or media, third-party products or services, or causes outside CoreDefense's reasonable control. Client's remedies for any data-related claim are subject to the limitations in Sections 9 and 10.
7.3 Client represents and warrants that it owns or has full authority to grant CoreDefense access to all facilities, systems, networks, accounts, and data involved in the engagement, and that doing so does not violate any law, contract, or third-party right. Client will defend and hold CoreDefense harmless from any third-party claim arising from Client's breach of this representation, including claims that CoreDefense's authorized access was unauthorized as to a third party.
8. Security Disclaimer
8.1 CoreDefense designs, deploys, and manages security solutions using commercially reasonable practices consistent with recognized industry standards. Client acknowledges and agrees that no security product, configuration, or service, however well designed or maintained, can guarantee absolute protection against all threats, vulnerabilities, intrusions, malware, data loss, or unauthorized access, and that CoreDefense does not warrant or guarantee any such outcome.
8.2 Client acknowledges that security is a shared, ongoing responsibility and that the effectiveness of any solution depends in part on factors outside CoreDefense's control—including Client's own practices, third-party products, end-user behavior, and Client's timely application of updates and CoreDefense's recommendations. CoreDefense is not responsible for incidents arising from or contributed to by such factors.
8.3 CoreDefense does not warrant that any system will be uninterrupted, error-free, or immune from intrusion, breach, or compromise. Client's sole and exclusive remedies for any security-related claim, regardless of legal theory, are limited to those set forth in Sections 9 and 10.
9. Limited Warranty & Disclaimer
9.1 CoreDefense warrants that its professional services will be performed in a workmanlike manner consistent with generally accepted industry standards and, where applicable, with the published best-practice and deployment guidance of the relevant manufacturer, as reasonably applied to Client's environment. This warranty applies only to CoreDefense's own services and not to third-party hardware, software, or products, which are governed by Section 5. Client must report any claimed defect in workmanship in writing within 30 days of the affected work. CoreDefense's sole obligation, and Client's sole and exclusive remedy, for a valid warranty claim is, at CoreDefense's option, to re-perform the deficient services or to refund the fees paid for those specific services. This warranty does not apply to any deficiency caused by Client's changes, misuse, or modification of the work; by third-party products or services; by Client's failure to follow CoreDefense's recommendations; by work altered by anyone other than CoreDefense; or by deviations from manufacturer guidance required by Client's environment, constraints, or instructions.
9.2 EXCEPT AS EXPRESSLY STATED, COREDEFENSE DISCLAIMS ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
10. Limitation of Liability
10.1 To the maximum extent permitted by law, CoreDefense's total cumulative liability arising out of or relating to any quote, order, product, or service shall not exceed the amounts actually paid by Client to CoreDefense for the specific product or service giving rise to the claim during the twelve (12) months preceding the event.
10.2 In no event shall CoreDefense be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, lost or corrupted data, business interruption, or costs of recovery or restoration, regardless of legal theory and even if advised of the possibility of such damages.
10.3 The limitations in this Section apply to all claims, whether based in contract, tort (including negligence), strict liability, statute, or otherwise, and apply even if a remedy fails of its essential purpose. These limitations reflect an agreed allocation of risk between the parties and are reflected in CoreDefense's pricing.
11. Confidentiality
11. Confidentiality. Each party agrees to protect the other's non-public business, technical, and security information disclosed in connection with a quote or engagement using at least reasonable care, to use it only for the engagement, and not to disclose it except to personnel and contractors who need it and are bound by similar duties, or as required by law. These duties do not cover information that is public, already known, independently developed, or rightfully obtained elsewhere. Client's security architecture and CoreDefense's methodologies are treated as confidential by both parties and remain protected for three (3) years after the engagement, with trade secrets protected as long as they qualify under law.
12. Intellectual Property
12.1 CoreDefense retains all right, title, and interest in its pre-existing and independently developed materials, tools, templates, processes, and methodologies—including the SecurePath framework and related know-how—and in any improvements or derivatives developed during an engagement. Nothing in a quote, order, or engagement transfers ownership of, or any license to, the foregoing to Client except as expressly stated in Section 12.2.
12.2 Upon full payment and subject to Client's continued compliance with these Terms, CoreDefense grants Client a non-exclusive, non-transferable, non-sublicensable, perpetual right to use the deliverables specifically created for Client solely for its internal business purposes. This right does not convey ownership of any CoreDefense pre-existing or independently developed materials embedded in those deliverables (governed by Section 12.1), and Client may not resell, sublicense, or distribute the deliverables to any third party without CoreDefense's prior written consent.
12.3 Third-party software, hardware, and services remain subject to their respective manufacturer or vendor license and subscription terms, which Client is responsible for reviewing and complying with. CoreDefense is not a party to those terms, and Client's remedies for third-party products are those provided by the applicable manufacturer or vendor.
13. Cancellation
13.1 Client may cancel professional services not yet performed with at least ten (10) days' prior written notice. Client remains responsible for all services performed and work in progress through the cancellation date, non-cancelable third-party commitments, special-order products already ordered, supplier restocking or cancellation fees, and reasonable costs already incurred by CoreDefense. Non-refundable deposits are not returned and may be applied against amounts owed.
13.2 Recurring services, including SecurePath Manage, are governed by the term, renewal, and termination provisions of the applicable managed-services agreement or SOW, which control over these Terms for those services. If recurring services begin before such an agreement is signed, they are provided month-to-month under these Terms, terminable by either party on thirty (30) days' written notice, until a governing agreement is executed.
14. Force Majeure
14. Force Majeure. CoreDefense is not liable for any delay or failure to perform caused by events beyond its reasonable control, including supply-chain disruption, manufacturer delays, labor shortages, utility or telecommunications failures, cyberattacks on third parties, pandemics, natural disasters, governmental action, or acts of God. Affected obligations are suspended for the duration of the event; the affected party will give reasonable notice and resume performance promptly once it ends. If the event continues beyond thirty (30) days, either party may terminate the affected services on written notice.
15. Governing Law & Dispute Resolution
15.1 These Terms and any dispute arising out of or relating to them, whether in contract, tort, or otherwise, are governed by the laws of the Commonwealth of Massachusetts, without regard to its conflict-of-laws rules.
15.2 The parties will first attempt in good faith to resolve any dispute arising out of or relating to these Terms through direct negotiation between representatives with authority to settle. If the dispute is not resolved within thirty (30) days, the parties will attempt to resolve it through non-binding mediation administered by a mutually agreed mediator, with the costs of mediation shared equally. Any dispute not resolved through mediation shall be finally resolved by binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules, seated in Massachusetts, before a single arbitrator, with judgment on the award enforceable in any court of competent jurisdiction. Notwithstanding the foregoing, either party may seek temporary or injunctive relief in the state or federal courts located in Massachusetts to protect its confidential information or intellectual property pending arbitration. Each party irrevocably waives any right to a jury trial and to participate in any class, collective, or representative proceeding.
16. General Provisions
16.1 Order of Precedence. In the event of a conflict among the documents governing an engagement, the following order of precedence controls: (a) a mutually executed Master Services Agreement (MSA); (b) a signed statement of work (SOW); (c) the accepted quote; and (d) these Terms. Absent an MSA or SOW, these Terms and the accepted quote govern. Any pre-printed, additional, or conflicting terms contained in a Client purchase order or other Client document are expressly rejected and have no force or effect, even if CoreDefense accepts or fulfills the order.
16.2 Entire Agreement; Amendment. The accepted quote, these Terms, and any referenced SOW or MSA constitute the entire agreement between the parties regarding their subject matter and supersede all prior or contemporaneous discussions, proposals, representations, and agreements, whether oral or written. No amendment or modification is effective unless in writing and signed by both parties. No representation or promise not expressly set forth in these documents may be relied upon.
16.3 Assignment. Neither party may assign or transfer its rights or obligations without the other's prior written consent, which will not be unreasonably withheld, except that CoreDefense may assign these Terms, in whole or in part, to an affiliate or to a successor in connection with a merger, acquisition, reorganization, or sale of all or substantially all of its assets, without consent. These Terms bind and benefit the parties and their permitted successors and assigns.
16.4 Severability. If any provision of these Terms is held invalid or unenforceable, that provision will be modified to the minimum extent necessary to make it enforceable, or if it cannot be so modified, severed, and the remaining provisions will remain in full force and effect. The parties intend that the limitations of liability and disclaimers in Sections 8 through 10 be enforced to the maximum extent permitted, even if any portion is limited or severed.
16.5 Waiver. No failure or delay by either party in exercising any right under these Terms operates as a waiver of that right, and no single or partial exercise precludes any further exercise. A waiver is effective only if in writing and signed by the waiving party.
16.6 Notices. Notices under these Terms must be in writing and sent to the contact identified on the quote or as later designated in writing, by personal delivery, nationally recognized overnight courier, certified mail (return receipt requested), or email with confirmation of receipt. Notice is deemed given upon delivery if by hand or courier, three (3) business days after mailing if by certified mail, or upon confirmed receipt if by email.