Last updated 9 October 2026.
1. Product selection and precedence
MAGDOX Private Limited is the supplier. Code Security and FDIE are product names, not separate contracting companies. An order may cover either or both, but no combined account, shared analysis store, common licence or cross-product entitlement is implied. Identify product, organisation, deployment and quantities in the order.
Mandatory transfer terms prevail for their subject matter, followed by the DPA for personal-data processing, then an expressly agreed Order Form variation, the executed MSA, these Product Schedules and the general Terms. A later website edit does not replace accepted commercial terms.
2. Schedule A: Code Security
Code Security supplies the magdox CLI and authorised rule/engine distribution, optional MCP integration, local reports, and a hosted dashboard/API for uploaded findings. Scanning runs on customer machines and CI runners. Installation of the public launcher does not by itself grant private engine or rule access.
| Item | Meaning |
|---|---|
| Developer / paid seat | A member with CLI-capable product access and an open invitation for that access. Dashboard-only members are free. |
| Team | $39/developer/month or $399/developer/year; up to 20 developers and 3 CI tokens; 14-day online trial. |
| Business | $99/developer/month or $999/developer/year; portfolio risk, software inventory, audit log and organisation controls; 14-day online trial. |
| Enterprise | Agreed seats, price, deployment and support; SAML SSO; offline/air-gapped licences issued by customer admins within agreed seats. |
| Scanning | All supported scanning surfaces in every plan; no per-scan charge. Supported formats and configured checks define coverage. |
Source files remain local for analysis. --upload sends findings and requested inventories. Snippets additionally require --include-code and receiving-project permission. Metadata can still contain sensitive file paths, branch names and personal data; excluding source files does not make it anonymous. --show-payload is a redacted preview that prevents upload, not a byte-for-byte copy of the authenticated upload body.
Licence renewal and rule/advisory downloads can contact the platform even without a findings upload. Offline operation requires a valid signed grant, installed engine and cached inputs. Ordinary offline leases are up to 7 days on Team, 30 on Business and 90 on Enterprise, always bounded by expiry and the signed grant. Perpetual offline rights exist only when expressly granted.
Optional AI review and coding-assistant integrations can disclose excerpts or findings to the customer's selected model/assistant provider. Customer approval and that provider's terms apply. Magdox does not train models on Customer Data and cannot replace the customer's responsibility to assess its own AI provider.
Enterprise Code Security SAML SSO is configured per organisation and verified email domain; it is off until enabled. Product-specific role, verification, invitation and recovery controls apply. This entitlement does not configure FDIE SSO.
3. Schedule B: FDIE
FDIE receives authorised firmware images within the chosen FDIE deployment. It performs supported extraction, component identification, vulnerability matching, technical control checks, release comparison and bounded runtime analysis, with supported SBOM, CBOM, VEX and report exports. All product capabilities are included in self-service and Enterprise, subject to compatibility, configuration and agreed resources.
| Item | Meaning |
|---|---|
| Seat | Every person who can sign in, whatever their role; pending invitations reserve capacity. |
| Self-service base | $499/month or $4,999/year: 2 seats, 100 GB retained storage and 30 new-image analyses per calendar month (UTC). |
| Additional capacity | Each seat: $49/month or $490/year. Each 100 GB: $20/month or $200/year. Each extra 20 monthly analyses: $99/month or $990/year. |
| Monthly analyses | Each newly uploaded image counts; failed analysis does not. Rechecks and comparisons of retained analysed images do not consume new-image allowance. Deleting an image does not refund its analysis. Allowance resets on the first of each month without rollover, including under annual billing. |
| Money-back guarantee | No free trial; payment is taken at checkout. The first payment is refunded in full on an administrator's request within 14 days if no more than three new images were analysed since it, once per organisation and person. The refund ends the subscription at once. |
| Enterprise evaluation | Separately arranged 14-day evaluation with no automatic paid conversion; dedicated/on-premises proof-of-concept scope agreed separately. |
Online FDIE runs on the shared cloud in India. Enterprise may use shared hosting, an agreed dedicated deployment or on-premises operation. Supported OIDC SSO and API access are included; provider setup, claim mapping and deployment limits still apply. This is not a promise of direct SAML or passkey functionality in every release.
Image-size, storage, monthly analysis, rate, runtime and concurrency limits protect shared resources. Reaching a limit can block or queue work; it does not authorise an unapproved overage purchase. Administrators must approve capacity changes shown in Billing. Contracted Enterprise limits are in the Order Form.
FDIE performs rule-based static analysis and sandboxed execution of supported firmware. It does not use generative AI to generate findings. Customer firmware and derived evidence remain Customer Data and are not used for model training. Requested emailed reports, integrations, support packages and monitoring have their own disclosed data paths.
4. Analysis and decision boundaries
- No scanner guarantees discovery of every vulnerability, component, secret, malicious behaviour or compliance gap. Findings require review of evidence and applicability.
- Unassessed, skipped, unsupported and incomplete work must not be treated as a clean result. Feed, rule, configuration and engine changes can change findings without a change in the input.
- In FDIE, function or binary changes are candidates for patch review, not proof of a fix. Runtime observations cover the exercised paths only; absence of an observation is not absence of a vulnerability.
- Framework scores cover assessed technical checks. They are not certification or a legal conformity decision. CRA disclosure records do not automatically submit a notification or determine reportability.
- Customers retain responsibility for release approval, remediation, legal duties and independent testing appropriate to high-assurance or safety-critical products.
5. Hosted, dedicated and customer-operated services
| Control | Magdox-hosted | Customer-operated |
|---|---|---|
| Core platform operation | Magdox maintains its platform, infrastructure and agreed backups | Customer runs the supplied stack; managed work only if ordered |
| Identity and user access | Magdox protects its service; customer administers membership and its IdP | Customer provides reachable local identity, TLS, recovery and role configuration |
| Analysis environment | Magdox maintains worker and sandbox restrictions | Customer maintains host isolation, runtime, resources, scratch storage and endpoint security |
| Updates and intelligence | Magdox operates approved platform and feed updates | Customer imports verified bundles/feed updates using the agreed transfer process |
| Backups and recovery | AWS backup/retention profile and scenario-specific objectives in the security addendum; no default cross-region recovery promise | Customer defines retention and tests restores unless expressly contracted otherwise |
| External connections | Listed providers and customer-enabled destinations | Customer enforces egress policy, disables unwanted integrations and documents permitted paths |
A dedicated installation does not automatically include high availability, a particular geography, 24/7 support or a tested disaster recovery service. Those must be specified and provisioned. A customer-operated deployment does not send firmware to Magdox for analysis, but support or enabled integrations can disclose data when the customer chooses.
This edition describes the AWS hosting profile that Code Security and FDIE have run on since 5 October 2026. Existing signed orders and processing terms continue until validly changed. Confirm the profile for your organisation before relying on a location, retention period or recovery objective.
AWS autoscaling operates within configured concurrency, database and analysis limits; quotas or queued work can still delay requests. Increasing infrastructure limits is separate from buying subscription capacity and does not silently authorise extra customer charges. Initial single-identity-host and network dependencies differ from the redundant growth profile. Availability, backup retention, recovery objectives and any contractual SLA remain governed by the activated deployment and accepted Order Form.
6. Order and handover checklist
- Legal parties, product(s), organisation(s), authorised users and quantities.
- Start date, term, fees, currency, tax treatment, billing channel, renewal and cancellation.
- Deployment country, providers, support access and international-transfer arrangements.
- Image/repository scope, technical limits, storage, retention, export and deletion process.
- Support contacts and hours, severity definitions, response targets and any agreed uptime credits.
- Backups, recovery scenarios, RPO/RTO, testing and responsibility allocation.
- For offline delivery: host/image architecture, signed licence term, deployment identity, release verification, local IdP and feed/update transfer process.