Last updated 8 October 2026.
1. Parties, formation and document order
The supplier is MAGDOX Private Limited, with registered address at St No. 8, Arabinda Nagar, Barbani, Bardhaman, Hindustan Cables, West Bengal 713335, India (Magdox). The customer is the legal person identified in the accepted Order Form. Each signatory or accepting representative confirms authority to bind that party. The effective date is the date stated in the signed agreement or the first accepted Order Form referencing this MSA.
An Order Form identifies Code Security, FDIE or both, the customer organisations covered, quantities, deployment, subscription period, fees and any additional services. Each accepted order is governed by this MSA. An affiliate is covered only if identified in an order or separately contracted; common ownership does not create an unlimited group licence.
For a conflict, mandatory transfer clauses govern their subject matter first; the DPA governs personal-data processing next. An Order Form overrides a provision of this MSA only where it expressly identifies the variation. Otherwise this MSA prevails over the Product Schedules and general Terms. Privacy and cookie policies describe processing; they do not expand the commercial licence. Procurement boilerplate in a purchase order does not amend this agreement without express written acceptance.
2. Definitions
| Term | Meaning |
|---|---|
| Services | The named products, authorised software, hosted functionality and separately ordered assistance supplied under an Order Form. |
| Customer Data | Customer-supplied code, firmware, configuration, findings, inventories, reports and related records processed through the Services, including personal data within them. It excludes Magdox's pre-existing software, rule content and general documentation. |
| Authorised User | An individually identified employee, contractor or other person whom the customer authorises within its purchased scope. Accounts must not be shared. |
| Documentation | Published product instructions for the relevant release and deployment, including coverage limitations; marketing roadmaps are not delivery commitments. |
| Order Form | A mutually accepted ordering document that identifies the Services and incorporates this MSA; an online checkout is governed by its accepted terms unless it expressly incorporates this MSA. |
| Security Incident | A confirmed compromise of the confidentiality, integrity or availability of Customer Data in Magdox's custody. Personal data breach has the meaning in applicable data protection law. |
| Business day | A working day in India excluding weekends and public holidays, unless the applicable support schedule states otherwise. |
3. Supply, scope and support
Magdox will provide the ordered Services during the subscription term in accordance with the agreement and applicable documentation. The Product Schedules describe the different source-code and firmware workflows. Purchasing one does not include the other. Product updates may change implementation, but Magdox will not materially reduce the agreed core functionality during a paid term without an agreed alternative or an appropriate termination/refund arrangement.
Implementation, training, migration or consulting work requires an agreed statement of work identifying deliverables, dependencies, acceptance criteria, timetable and fees. Travel and expenses require prior written approval. Pre-existing tools and general techniques remain with their owner; ownership of specifically commissioned deliverables must be addressed in that statement of work.
Support is provided through the channels, hours and response targets stated in the order. No 24/7 staffing, resolution deadline, uptime percentage, service credit, regional failover capability or recovery deadline is implied by a product subscription. A support response target is not a restoration promise. Customer must provide authorised contacts and reasonably necessary, appropriately redacted diagnostic information.
4. Access and software licence
Subject to the order and payment obligations, Magdox grants a limited, non-exclusive right during the term for Authorised Users to access the hosted Services and install supplied software for the customer's authorised business use. Customer may use the Services for client assessments only within its licence and with the relevant client's authority. Resale, sublicensing, service-bureau access or transfer of private engine/rule materials requires written agreement.
Licence quantities follow the product schedule: Code Security counts CLI-capable developers; FDIE counts people who can sign in. Customer will manage invitations, individual accounts and reassignment without circumventing purchased capacity. Machine, CI and API access must use the documented methods. Magdox may verify entitlement through ordinary service records; access to a customer network or an intrusive licence audit requires separate agreement.
Customer will not bypass licence checks, extract restricted rule material, interfere with another tenant, exceed controls deliberately or use the Services unlawfully. Restrictions do not limit non-waivable legal rights, applicable open-source licences, or good-faith research authorised by the vulnerability disclosure policy. Analysis of vulnerable or potentially malicious customer samples through the intended workflow is permitted.
5. Customer duties and shared responsibility
Customer is responsible for its authority to analyse submitted material, required notices and lawful instructions, user membership, selected recipients, backups under its control and decisions based on results. It will protect credentials, configure MFA/SSO appropriately, revoke departed users and notify Magdox promptly of suspected compromise. Neither party is relieved of responsibility for its own failures by this allocation.
For customer-operated deployments, Customer supplies and maintains the agreed host, network, identity, storage, monitoring and recovery controls, and installs security updates through the agreed process. Magdox supplies the licensed release and contracted support. Offline use requires local dependencies, a valid grant and a controlled update process; an internet-independent deployment cannot rely on an internet-only identity provider or feed refresh.
Customer will avoid supplying unnecessary personal data or live payment-card data. Special categories, regulated datasets or data subject to localisation restrictions require an expressly suitable scope and safeguards before transfer. Firmware may incidentally contain credentials or personal data; that possibility does not waive confidentiality or security obligations.
6. Data ownership, permitted processing and AI
Customer and its licensors retain rights in Customer Data and the results derived from it, subject to pre-existing intellectual property and third-party data rights. Customer grants Magdox only the permissions needed to receive, host, analyse, reproduce, transmit, export, protect and delete the data to perform the agreement or meet a legal duty. This grant ends when the relevant processing and lawful retention end.
Magdox retains rights in its products, engines, rule content, compiled intelligence resources and documentation. Supplying output does not assign these underlying rights. Customer can retain and use its exported results after the subscription ends, subject to confidentiality and rights in any embedded third-party material.
Magdox does not sell Customer Data, train models on it or grant a general right to publish it. FDIE does not use generative AI to produce findings. Code Security's optional AI review or coding-assistant workflows use the customer's chosen provider under that customer's agreement; such a provider is not covered by a promise Magdox cannot make on its behalf. Customer controls approval and disclosure to those providers.
Feedback may be used to improve the Services without compensation, but this permission excludes Customer Data, confidential material and personal data. Operational measurements used to improve reliability must not reveal customer content or be used to reidentify individuals.
7. Confidentiality
Non-public information disclosed in connection with the agreement is confidential where marked as such or where its nature reasonably calls for protection. Customer firmware, code, analysis evidence and security findings are confidential without needing a label. Each recipient will use confidential information only for the agreement, restrict access to people who need it and are bound by confidentiality, and apply at least reasonable care.
The obligation does not cover information the recipient can demonstrate was already lawfully known without restriction, became public without breach, came lawfully from an unrestricted third party, or was developed independently without using the protected material. A general recollection or residual-knowledge exception does not authorise reuse of customer code, firmware, credentials or findings.
If disclosure is legally compelled, the recipient will, where lawful, give timely notice and reasonable assistance to seek protection, disclose only what is required and seek confidential handling. Confidentiality survives for five years after termination; trade secrets remain protected while they retain that status, and protected retained Customer Data remains covered until deleted.
8. Personal data and security
The DPA applies to personal data processed on Customer's behalf where incorporated or otherwise required by applicable law. The parties will complete processing particulars and required transfer instruments before covered processing. Magdox's independent business and account processing is described in the Privacy Policy. Customer's choice of a storage region does not remove disclosures to listed providers or its own integrations.
Magdox will maintain the measures in the Information Security Addendum for the agreed product and deployment and will not materially reduce the overall protection during the term. Customer-operated responsibilities must be stated in the order. A published description is not a certification or evidence that every control is immune to defects.
Moving an affected service to AWS or transactional email to Amazon SES follows the DPA's provider-change, location and transfer requirements. It does not retroactively replace an executed retention or recovery commitment. The AWS security addendum distinguishes point-in-time recovery, versioned storage, high availability and regional disaster recovery; fixed RPO/RTO or cross-region recovery obligations require an expressly accepted and implemented scope.
Magdox will notify the affected customer of a personal data breach without undue delay and no later than 72 hours after awareness, or sooner where required by law. It will share available scope, consequences, mitigation, contact and recommended actions, follow up as facts emerge and reasonably assist the response. Customer controls its own regulatory decisions. This outer limit does not permit avoidable delay or replace shorter statutory obligations.
9. Fees, taxes and billing
Fees, currency, payment dates, included quantities, renewal and approved expenses are stated in the order. Magdox invoices Enterprise subscriptions directly unless another channel is specified. Taxes legally chargeable on the supply are additional; taxes on Magdox's own income remain its responsibility. Where withholding is required, the parties will cooperate on lawful documentation and any order-specific treatment.
Customer should raise a billing dispute promptly with the invoice and reason, pay undisputed amounts when due and cooperate in resolution. A reasonable, documented dispute will not by itself justify suspending an otherwise compliant customer. Overdue undisputed fees may lead to suspension after notice and the cure period in the order; absent a specified period, Magdox will allow at least 15 days after written reminder.
Self-service purchases are sold by Dodo Payments as merchant of record under the accepted checkout terms. Code Security offers a 14-day online trial; FDIE is paid at checkout with a 14-day money-back guarantee on the first payment. The product schedule describes cancellation, the guarantee and product-specific capacity changes. Enterprise evaluations do not automatically become billable subscriptions without an accepted order.
Fees are non-refundable except where this agreement (including the FDIE money-back guarantee in the product schedule), the order or mandatory law provides otherwise. If Customer terminates an affected service for Magdox's uncured material breach, or Magdox discontinues it without an agreed replacement, prepaid unused subscription fees for the affected service are refunded pro rata. Payment handling through a merchant of record does not eliminate applicable refund rights.
10. Term, renewal and change control
This MSA remains in force while an order is active and for provisions that survive. Each subscription starts and ends as stated in its order. Renewal, notice periods and renewal pricing must be explicit; this MSA does not create an unstated Enterprise auto-renewal. Online subscriptions renew under the accepted checkout terms until cancelled.
Changes to an executed MSA or Order Form require mutual written agreement, including valid electronic agreement. Public-policy revisions do not silently amend an accepted negotiated contract or retroactively remove accrued rights. Mandatory-law changes will be addressed with the customer and, where needed, through a documented amendment. Earlier accepted versions remain available on request.
11. Warranties and analysis limitations
Each party warrants that it has authority to contract and will comply with laws applicable to its performance. Magdox will perform the agreed Services with reasonable skill and care and materially in accordance with the applicable documentation. Customer will notify Magdox of a reproducible material nonconformity; Magdox will have a reasonable opportunity to correct it. If an uncured material breach remains, Section 13 applies.
Security analysis is evidence for a decision, not a guarantee that software is secure, every vulnerability is found, a fix is effective, or a legal framework is satisfied. The Product Schedules explain incomplete coverage, feed timing, component identity, AI output and bounded runtime evidence. Customer remains responsible for appropriate verification and remediation. These limits do not cancel an express warranty, confidentiality duty, security commitment or liability that cannot lawfully be excluded.
Except for express commitments and non-waivable rights, no additional implied warranty of fitness, merchantability, uninterrupted operation or detection completeness is given. A separately identified experimental feature may have narrower support and reliability; its use does not waive the DPA or confidentiality. Ordinary paid services and all trials are not automatically classified as experimental.
12. Suspension
Magdox may restrict the minimum necessary scope to address an active security threat, unlawful use, material abuse or overdue undisputed fees after the applicable notice process. Where practicable it will give advance notice; otherwise it will notify the customer promptly unless legally prohibited. It will explain the reason and reasonable restoration steps and restore access when the cause is resolved.
Authorised research and intended analysis of malicious samples are not, by themselves, grounds for suspension. Security restrictions may require supervised export instead of ordinary access. Suspension is not permission to retain or use Customer Data beyond the DPA and retention schedule.
13. Termination and exit
Either party may terminate an affected order for a material breach not remedied within 30 days after written notice describing it, or where termination is otherwise expressly permitted. Serious breaches that cannot reasonably be cured may be addressed as applicable law allows. Ending one order does not automatically end unrelated orders unless the breach materially affects them too.
At expiry or termination, access rights end except for any expressly agreed offline/perpetual grant and rights to retained outputs. Magdox will provide at least 30 days for an authorised export of Customer Data, subject to earlier valid deletion instructions, law and necessary security restrictions. Customer should request an export before the window closes. Additional migration assistance is separately scoped; legally required processor assistance remains available under the DPA.
Customer chooses return or deletion of personal data under the DPA. Active systems and backups follow the product-specific retention schedule, with legally required retention restricted to its purpose and deletion instructions reapplied after restoration. Confidentiality, accrued fees, ownership, applicable limits and provisions intended to survive continue after termination.
14. Third-party claims and indemnification
Magdox will defend Customer against a third-party claim that the supplied Services, used within their authorised scope, infringe that third party's intellectual property, and pay damages finally awarded or settlements it approves. This does not cover a claim caused by Customer's content, unauthorised modification or a combination that creates infringement that would not exist in the supplied Service alone.
Customer will defend Magdox against third-party claims arising from Customer Data supplied without necessary rights or Customer's unlawful misuse of the Services, and pay damages finally awarded or settlements it approves. This obligation does not extend to the part caused by Magdox's own breach or unauthorised use of the data.
For either indemnity, the protected party must give reasonably prompt notice, allow the defending party to control the defence and provide reasonable assistance at the defender's cost. Delay reduces the obligation only to the extent it materially prejudices the defence. No settlement may admit fault, impose a non-monetary obligation or fail to release the protected party without its written consent, not unreasonably withheld.
For a covered infringement concern, Magdox may obtain continued usage rights, provide a materially equivalent non-infringing alternative, or terminate the affected service and refund prepaid unused fees if a reasonable alternative is unavailable. The parties retain rights that cannot lawfully be excluded.
15. Liability allocation
To the extent permitted by law, each party's aggregate liability under the agreement is limited to fees paid for the affected Services in the twelve months before the claim. For breach of confidentiality or a party's security obligations resulting in unauthorised access to the other's confidential information, a separate enhanced limit of twice those fees applies instead of the general limit. These limits are aggregate allocations, not a new limit for each incident.
Neither financial cap limits indemnification obligations in Section 14, fraud, gross negligence, wilful misconduct, infringement of the other party's intellectual property outside the granted rights, amounts properly payable for the Services, or liability that cannot lawfully be limited or excluded, including non-waivable data-subject rights.
Neither party is liable for indirect, consequential, special or punitive loss, or lost profit, revenue or goodwill, to the extent lawful. That exclusion does not apply to fraud, gross negligence, wilful misconduct, indemnity obligations, properly due fees or non-excludable liability. The enhanced cap is not a promise of unlimited consequential damages. Mandatory transfer clauses prevail where they require a different allocation. Any negotiated variation must be explicit in the order.
16. Force majeure and continuity
A party is excused for delay only to the extent an event outside its reasonable control prevents performance despite reasonable precautions and mitigation. It must promptly explain the impact, take reasonable recovery steps and resume performance. This does not excuse accrued payment, confidentiality or data protection duties that remain capable of performance, or a failure caused by that party's own lack of required safeguards. A cyberattack or supplier outage is not automatically an excuse for every related failure. The parties will agree a reasonable termination and unused-fee treatment for prolonged disruption.
17. Compliance, publicity and assignment
Each party will comply with applicable anti-bribery, export-control and sanctions requirements. Customer must have authority to transfer the relevant code, firmware and technical data. Restrictions depend on the parties, destination and use, rather than a blanket rule based solely on nationality.
Neither party may publish the other's logo, customer identity, confidential results or testimonial without permission. Consent to an order does not itself approve a case study. Coordinated vulnerability disclosure remains governed by the disclosure policy.
Neither party may assign the agreement without consent, not unreasonably withheld, except as part of a merger, reorganisation or sale of substantially all relevant assets where the successor assumes the obligations and the assignment does not materially diminish protection. Required notices and data-protection safeguards still apply. The parties are independent contractors; no partnership, agency or employment relationship is created.
18. Notices, disputes and execution
Contractual notices to Magdox go to legal@magdox.io; privacy and security notices go to privacy@magdox.io and security@magdox.io respectively. Customer notices go to its designated contractual contact. Keep these contacts current. Email is an agreed written channel where delivery succeeds; a known bounce is not effective notice. Urgent incident communications use the agreed incident contacts.
Unless the signed agreement specifies otherwise, Indian law governs and the competent courts of West Bengal, India have jurisdiction. Mandatory consumer protections, data protection rights and transfer-clause law/forum provisions are preserved. The parties will attempt a good-faith resolution without delaying urgent relief or statutory deadlines.
This MSA, the accepted orders and properly incorporated schedules form the agreement for their subject matter. Failure to enforce a term once is not a waiver. An invalid term is limited only as necessary and the remaining terms continue. Electronic signatures and counterparts may be used to the extent lawful. There are no intended third-party beneficiaries except rights expressly required by applicable data protection or transfer provisions.
Execution requires the customer's legal name and address, authorised representatives, acceptance date and an Order Form with the product/deployment and commercial particulars. Contact Magdox for the execution copy and completed DPA/transfer annexes; this public version contains no customer-specific information.