MASTER SERVICES AGREEMENT

Version 2026.1a – 7/22/2026

  1. Parties

This Enterprise Master Services Agreement, together with all Schedules, Addenda, Exhibits, Statements of Work, Service Orders, proposals, quotes, change orders, service descriptions, online terms incorporated by reference, and related documents (collectively, the “Agreement”), is entered into by and between Astra Data Solutions Inc., d/b/a Astra Cybersecurity (“Astra,” “Provider,” “Company,” “we,” “us,” or “our”), and the client identified in the applicable Statement of Work, Service Order, proposal, quote, or signature block (“Client,” “Customer,” “you,” or “your”).

Astra and Client may be referred to individually as a “Party” and collectively as the “Parties.”

  1. Agreement Structure

This Agreement governs all services provided by Astra to Client, including without limitation managed IT services, managed cybersecurity services, security operations services, managed detection and response, help desk, endpoint management, backup, cloud services, Microsoft 365 services, compliance consulting, vCIO/vCTO/vCISO services, incident response, digital forensics, penetration testing, vulnerability assessments, professional services, procurement, software licensing, hardware sales, and project services.

Each Statement of Work, Service Order, quote, proposal, renewal, project authorization, change order, ticket-based authorization, emergency authorization, email approval, or other written authorization is incorporated into this Agreement.

  1. Order of Precedence

In the event of conflict among documents, the following order of precedence applies unless a document expressly states that it overrides a specific section of this Agreement by section number:

  1. A mutually executed amendment to this Agreement.
  2. A mutually executed Statement of Work or Service Order.
  3. A mutually executed compliance addendum or data processing addendum.
  4. This Master Services Agreement.
  5. The applicable service schedule.
  6. A proposal, quote, or purchase order issued by Astra.
  7. Any other document incorporated by reference.

Client purchase orders, procurement portal terms, vendor onboarding terms, invoice instructions, online click-through terms, and similar Client documents are administrative only and do not modify this Agreement unless signed by an authorized officer of Astra and expressly identified as an amendment to this Agreement.

  1. Entire Agreement

This Agreement constitutes the entire agreement between Astra and Client regarding the subject matter hereof and supersedes all prior or contemporaneous understandings, proposals, representations, warranties, negotiations, and communications, whether written or oral.

No terms printed on or referenced in any Client purchase order, vendor management system, procurement portal, invoice portal, acknowledgment, email footer, or other Client document will apply to Astra or modify this Agreement.

  1. Definitions

For purposes of this Agreement:

“Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with a Party.

“Applicable Law” means any law, regulation, rule, ordinance, court order, government directive, industry requirement, contractual requirement, or regulatory requirement applicable to a Party or the Services.

“Authorized User” means Client’s employees, contractors, agents, representatives, or other users authorized by Client to access Client systems or receive Services.

“Business Day” means Monday through Friday, excluding federal holidays and Astra-observed holidays.

“Business Hours” means 9:00 a.m. to 5:00 p.m. Eastern Time on Business Days, unless otherwise stated in a Service Order.

“Client Data” means data, files, records, content, information, credentials, logs, configurations, and materials provided by or on behalf of Client or processed in connection with the Services.

“Client Environment” means Client’s technology environment, including hardware, software, networks, cloud services, endpoints, servers, applications, facilities, accounts, configurations, data, third-party platforms, users, vendors, and related assets.

“Confidential Information” means nonpublic information disclosed by one Party to the other that is designated confidential or that reasonably should be understood as confidential given the nature of the information and circumstances of disclosure.

“Cybersecurity Event” means any actual or suspected compromise, attack, malware event, ransomware event, business email compromise, phishing attack, unauthorized access, vulnerability exploitation, credential compromise, denial-of-service event, data exfiltration, insider threat, security misconfiguration, policy violation, or other security incident.

“Deliverable” means a report, document, configuration, script, assessment, plan, recommendation, or other work product specifically identified as a deliverable in an applicable SOW.

“Emergency Services” means services performed outside normal scope, outside Business Hours, on an expedited basis, or in response to a Cybersecurity Event, outage, business interruption, legal demand, regulator request, forensic need, or urgent Client request.

“Fees” means all amounts payable by Client to Astra, including recurring fees, project fees, hourly fees, emergency fees, licensing fees, hardware fees, pass-through costs, taxes, expenses, overages, late fees, collection costs, and other charges.

“Managed Services” means recurring IT, cybersecurity, monitoring, maintenance, support, and management services described in an applicable SOW or Service Order.

“Professional Services” means consulting, implementation, migration, remediation, audit support, project, advisory, assessment, engineering, or other non-recurring services.

“Regulated Data” means information subject to specific legal, regulatory, contractual, or industry obligations, including personal information, protected health information, nonpublic information, cardholder data, controlled unclassified information, financial customer information, biometric information, and similar data.

“Services” means all services, products, deliverables, subscriptions, licenses, equipment, advice, support, consulting, and work provided by Astra.

“Service Order” means any order, proposal, quote, schedule, statement of work, invoice schedule, or other document describing Services, pricing, term, scope, or quantities.

“Third-Party Service” means any hardware, software, cloud service, subscription, platform, license, internet service, telecommunications service, data center, vendor tool, carrier, manufacturer, API, or other product or service not owned and controlled by Astra.

  1. Appointment and Scope

Client appoints Astra to perform the Services described in applicable Service Orders. Astra will perform only the Services expressly described in an executed Service Order or otherwise authorized in writing. Services not expressly included are excluded.

Astra is not responsible for unmanaged assets, unsupported systems, unauthorized changes, shadow IT, unknown assets, user misconduct, vendor failures, or Client systems not disclosed to Astra.

  1. Independent Contractor

Astra is an independent contractor. Nothing in this Agreement creates a partnership, joint venture, fiduciary relationship, employment relationship, franchise, agency, or similar relationship. Astra has no authority to bind Client except as expressly authorized in writing.

  1. No Fiduciary, Legal, Tax, or Insurance Advice

Astra provides technology and cybersecurity services. Astra does not provide legal, tax, accounting, investment, insurance, or regulatory advice. Client remains responsible for obtaining advice from qualified professionals.

  1. Client Responsibilities

Client must:

  1. Provide timely access to systems, facilities, data, personnel, documentation, credentials, and vendors.
  2. Maintain accurate asset inventories.
  3. Maintain valid software licenses.
  4. Maintain supported hardware, operating systems, applications, warranties, and vendor support.
  5. Maintain adequate internet, power, environmental controls, facilities, and physical security.
  6. Use commercially reasonable cybersecurity practices.
  7. Maintain backups and verify backup recovery where backup services are not expressly included.
  8. Notify Astra before making technology, security, vendor, network, user, licensing, or infrastructure changes.
  9. Promptly notify Astra of suspected Cybersecurity Events.
  10. Maintain cyber insurance and other insurance appropriate to Client’s risk profile.
  11. Ensure Authorized Users comply with this Agreement.
  12. Cooperate with incident response, remediation, compliance, and support activities.
  13. Not disable, bypass, remove, modify, or interfere with Astra tools, agents, controls, monitoring, or configurations.
  14. Maintain administrative, technical, and physical safeguards appropriate to Client’s business.
  15. Comply with Applicable Law.

Failure by Client to meet these responsibilities relieves Astra from liability to the extent the failure causes or contributes to any delay, loss, breach, outage, noncompliance, failed recovery, or security event.

  1. Client Security Obligations

Client must implement and maintain the following minimum-security controls unless Astra approves an exception in writing:

  1. Multi-factor authentication for email, administrative access, remote access, cloud systems, and privileged accounts.
  2. Unique named user accounts.
  3. No shared administrative accounts except approved emergency accounts.
  4. Strong password practices.
  5. Timely user onboarding and offboarding.
  6. Least privilege access.
  7. Physical security for devices and facilities.
  8. Encryption where appropriate.
  9. Vendor access controls.
  10. Regular cybersecurity training.
  11. Prompt reporting of suspicious emails, alerts, and incidents.
  12. Business continuity planning.
  13. Written cyber incident and business continuity/disaster recovery escalation contacts.

Client’s refusal or failure to adopt recommended controls constitutes risk acceptance by Client.

  1. Fees and Payment

Client must pay all Fees in accordance with the applicable Service Order or invoice. Unless otherwise stated, recurring fees are due in advance, project fees are due as invoiced, and hourly fees are due upon receipt.

Astra may require ACH, credit card, or other automatic payment authorization. Client authorizes Astra to charge the payment method on file for all undisputed amounts due.

  1. Taxes

Fees are exclusive of sales, use, excise, value-added, gross receipts, telecom, regulatory, and similar taxes. Client is responsible for all taxes other than taxes based on Astra’s net income.

  1. Late Payments

Amounts not paid when due accrue interest at 3% per month or the maximum rate allowed by law, whichever is lower. Client must reimburse Astra for collection costs, attorney fees, court costs, arbitration fees, and related expenses.

  1. No Offset

Client may not withhold, offset, charge back, reverse, or deduct amounts owed to Astra based on claims, disputes, credits, vendor issues, or alleged service failures.

  1. Price Adjustments

Astra may adjust recurring service fees annually by the greater of 5% or the percentage increase in CPI, unless otherwise stated in a Service Order.

Astra may pass through increases in vendor, manufacturer, distributor, cloud, software, carrier, data center, tax, shipping, insurance, labor, compliance, or other third-party costs.

  1. Third-Party Licensing Commitments

Licenses and subscriptions may be subject to minimum terms, vendor commitments, cancellation restrictions, seat minimums, annual commitments, usage minimums, and vendor price changes. Client is responsible for all such commitments.

Early termination of the Agreement does not relieve Client of third-party license or subscription commitments.

  1. Term

The term begins on the Effective Date or the start date in the applicable Service Order. Unless otherwise stated, the initial term is thirty-six months. After the initial term, Services renew automatically for successive twelve-month renewal terms unless either Party gives written non-renewal notice at least ninety days before the end of the then-current term.

  1. Termination for Cause

Either Party may terminate this Agreement for material breach if the breach remains uncured thirty days after written notice. Astra may terminate immediately for nonpayment, illegal activity, security risk, abusive conduct, insolvency, repeated failure to cooperate, or Client conduct that materially increases risk.

  1. Termination for Convenience

Client may terminate for convenience only if expressly permitted in the applicable Service Order. If Client terminates early without cause, Client must pay all remaining recurring fees for the balance of the term, all outstanding project fees, all third-party commitments, all unrecovered onboarding or implementation costs, and all applicable early termination charges.

  1. Effect of Termination

Upon termination:

  1. Astra may stop Services.
  2. Client must pay all amounts due.
  3. Client must return or destroy Astra Confidential Information.
  4. Astra may remove tools, agents, access, monitoring, documentation, and configurations not owned by Client.
  5. Astra will provide reasonable transition assistance at then-current rates.
  6. Client remains responsible for vendor transitions, credentials, licensing, data retention, and replacement services.
  1. Suspension

Astra may suspend Services immediately if:

  1. Client fails to pay amounts due.
  2. Client creates a security, legal, safety, or operational risk.
  3. Client violates the Acceptable Use Policy.
  4. Client fails to cooperate during a Cybersecurity Event.
  5. Astra is required by law, vendor instruction, or government order.
  6. Client’s environment is compromised.
  7. Client disables required controls.
  8. Continued Services may harm Astra, Client, other clients, vendors, or third parties.

Suspension does not waive Astra’s right to payment.

  1. Service Changes

Astra may modify the method, tooling, staffing, subcontractors, vendors, architecture, or process used to provide Services, provided the change does not materially reduce the overall contracted Service level.

  1. Change Orders

Changes to scope, assumptions, timing, deliverables, quantities, users, locations, infrastructure, compliance requirements, or third-party dependencies require a change order or written authorization. Astra may bill additional work at then-current rates.

  1. Out-of-Scope Work

Unless expressly included, the following are out of scope:

  1. Projects.
  2. New deployments.
  3. Migrations.
  4. Major remediations.
  5. Cybersecurity incident response.
  6. Digital forensics.
  7. Litigation support.
  8. Regulatory investigation support.
  9. External audit participation/response.
  10. Vendor disputes.
  11. Data restoration.
  12. Business continuity testing.
  13. Onsite support.
  14. After-hours work.
  15. Unsupported systems.
  16. Custom development.
  17. Cabling.
  18. Electrical work.
  19. Physical security work.
  20. Compliance certification.
  21. Policy drafting unless expressly stated.
  22. Asset discovery of unknown or undisclosed systems.
  23. Remediation caused by Client or third-party changes.
  1. Service Levels

Service levels, response targets, and resolution targets are goals, not guarantees, unless an SOW expressly provides service credits as Client’s sole remedy. Resolution depends on Client cooperation, vendor performance, third-party availability, system condition, and event complexity.

  1. No Guaranteed Security

Client acknowledges that no provider can guarantee that systems will be secure, uninterrupted, error-free, malware-free, ransomware-free, breach-free, or compliant. Astra does not guarantee prevention of Cybersecurity Events, data loss, downtime, unauthorized access, business email compromise, social engineering, vendor outages, or exploitation of vulnerabilities.

  1. Cybersecurity Shared Responsibility

Cybersecurity is a shared responsibility among Astra, Client, users, vendors, software providers, manufacturers, carriers, cloud providers, insurers, legal counsel, and other stakeholders. Astra is responsible only for the specific Services it has agreed to provide.

  1. Third-Party Services

Astra is not responsible for failures, vulnerabilities, defects, outages, price changes, data loss, licensing changes, support limitations, end-of-life decisions, or acts or omissions of Third-Party Services. Third-Party Services are subject to the applicable vendor terms.

  1. Hardware Procurement

Hardware purchases are final unless otherwise agreed. Title passes to Client upon full payment. Hardware is subject to manufacturer warranties only. Astra disclaims all implied warranties for hardware to the maximum extent permitted by law.

Client is responsible for shipping, taxes, restocking fees, supply-chain delays, tariffs, manufacturer price changes, and compatibility issues caused by Client’s environment or third-party systems.

  1. Software Procurement

Software is licensed, not sold. Client is responsible for complying with vendor license terms. Astra may invoice software and subscription fees in advance and may require payment before ordering.

  1. Intellectual Property

Astra retains all rights in its preexisting intellectual property, methodologies, tools, scripts, templates, documentation, know-how, processes, playbooks, configurations, automations, detection logic, reports, forms, and generalized knowledge.

Upon full payment, Client receives a non-exclusive, non-transferable license to use Deliverables solely for Client’s internal business purposes.

  1. Client Data

Client owns Client Data. Astra may process Client Data to provide Services, maintain security, comply with law, improve operations, troubleshoot issues, and exercise rights under this Agreement.

  1. Confidentiality

Each Party must protect the other Party’s Confidential Information using reasonable care and may use it only to perform or receive Services, enforce this Agreement, comply with law, or exercise rights under this Agreement.

Confidential Information does not include information that is publicly available, already known without restriction, independently developed, rightfully received from a third party, or released with authorization.

  1. Security of Astra Systems

Astra will maintain commercially reasonable safeguards for Astra-controlled systems used to provide Services. Astra does not control Client systems, Client users, Client vendors, or Third-Party Services.

  1. Privacy

Where Astra processes personal information on behalf of Client, the applicable Data Processing Addendum governs to the extent required by law.

  1. Regulated Data

Client must notify Astra in writing before providing access to Regulated Data. Astra is not responsible for obligations related to Regulated Data unless the applicable Service Order expressly identifies the data type and obligations.

  1. HIPAA

Astra is not a Business Associate unless the Parties execute a Business Associate Agreement. If a BAA is required, the BAA controls with respect to protected health information.

  1. PCI DSS

Astra is not responsible for PCI DSS compliance unless an SOW expressly states that Astra will perform PCI-related services. Client remains responsible for PCI scope, segmentation, assessment, validation, questionnaires, compensating controls, and acquiring bank obligations.

  1. Compliance Services

Astra may assist Client with compliance readiness, control mapping, documentation, technical controls, evidence collection, and advisory services. Astra does not guarantee certification, audit results, regulator acceptance, insurer acceptance, or legal compliance.

  1. Incident Response

Incident response services are out of scope unless expressly included. If Astra performs Emergency Services, Client authorizes Astra to take reasonable actions to contain, isolate, disable, block, preserve, or remediate affected systems.

Astra does not provide legal advice and does not determine whether notification is legally required. Client must involve legal counsel for privilege, breach determination, notification, law enforcement, regulatory communications, and insurance matters.

  1. Backups and Recovery

Backup and recovery depend on many factors, including system condition, configuration, storage, retention, vendor performance, corruption, encryption, ransomware, connectivity, and Client actions. Astra does not guarantee any recovery point objective or recovery time objective unless expressly stated in an SOW.

  1. Disaster Recovery

Disaster recovery requires planning, documentation, testing, funding, and Client participation. Astra is not responsible for business interruption, lost profits, lost revenue, loss of use, reputational harm, or downstream losses.

  1. AI and Automation

AI-enabled tools, automation, scripts, and machine-generated recommendations may be used to assist Services. Such outputs may be incomplete, inaccurate, or unsuitable without human review. Client is responsible for decisions based on AI outputs unless Astra expressly assumes responsibility in an SOW.

Client must not input Regulated Data into AI tools unless approved in writing.

  1. Warranties

Astra warrants that it will perform Services in a professional and workmanlike manner consistent with generally accepted practices for similar providers. Client’s exclusive remedy for breach of this warranty is re-performance of the affected Service or, if re-performance is not commercially reasonable, a refund of fees paid for the specific defective Service.

  1. Disclaimer of Warranties

Except as expressly stated, Services, Deliverables, hardware, software, and Third-Party Services are provided “as is” and “as available.” Astra disclaims all implied warranties, including merchantability, fitness for a particular purpose, non-infringement, title, uninterrupted use, error-free operation, security, compliance, and data integrity.

  1. Limitation of Liability

To the maximum extent permitted by law, Astra’s total aggregate liability arising out of or related to this Agreement will not exceed the fees actually paid by Client to Astra for the specific affected Service during the three months preceding the event giving rise to liability, capped at $25,000.

This limitation applies regardless of theory of liability, including contract, tort, negligence, strict liability, statute, indemnity, warranty, or otherwise.

  1. Exclusion of Damages

To the maximum extent permitted by law, Astra will not be liable for indirect, incidental, consequential, special, exemplary, punitive, enhanced, or similar damages, including lost profits, lost revenue, lost savings, loss of use, business interruption, loss of goodwill, reputational harm, loss of data, cost of substitute services, regulatory fines, ransom payments, extortion payments, legal fees of third parties, or downstream damages.

  1. Cybersecurity Event Liability Exclusions

Astra is not liable for losses caused by:

  1. Ransomware.
  2. Malware.
  3. Phishing.
  4. Social engineering.
  5. Business email compromise.
  6. Credential compromise.
  7. Insider threats.
  8. Zero-day vulnerabilities.
  9. Nation-state attacks.
  10. Vendor breaches.
  11. Cloud outages.
  12. Software vulnerabilities.
  13. Hardware defects.
  14. Misconfigurations not caused solely by Astra.
  15. Client refusal to implement recommendations.
  16. User error.
  17. Client delay.
  18. Unsupported systems.
  19. Unknown assets.
  20. Client or third-party changes.

This exclusion does not apply to the extent a final, non-appealable judgment determines that the loss was directly caused by Astra’s gross negligence or willful misconduct.

  1. Client Indemnification

Client will defend, indemnify, and hold harmless Astra and its officers, directors, employees, contractors, subcontractors, vendors, and affiliates from claims, losses, damages, penalties, costs, and expenses arising from:

  1. Client Data.
  2. Client’s business operations.
  3. Client’s violation of law.
  4. Client’s breach of this Agreement.
  5. Client’s security failures.
  6. Client’s users.
  7. Client’s vendors.
  8. Client’s instructions.
  9. Client’s failure to implement recommendations.
  10. Client’s regulated data.
  11. Client’s misuse of Services.
  12. Third-party claims arising from Client systems.
  1. Astra Indemnification

Astra will defend Client against third-party claims alleging that Astra-owned Deliverables, as provided by Astra and used as authorized, infringe a U.S. copyright or trade secret, and will pay damages finally awarded, provided Client promptly notifies Astra, gives Astra control of the defense, and cooperates.

Astra has no obligation for claims arising from Client materials, third-party products, modifications, combinations, misuse, or compliance with Client instructions.

  1. Insurance

Astra will maintain commercially reasonable insurance appropriate for its business. Client must maintain insurance appropriate for its operations, including cyber liability insurance with limits appropriate to Client’s risk profile and industry.

  1. Cyber Insurance Cooperation

Client is responsible for understanding and complying with cyber insurance requirements. Astra may assist with questionnaires or evidence collection at then-current rates. Astra does not warrant that insurer requirements are satisfied.

  1. Non-Solicitation

During the term and for twenty-four months thereafter, Client may not solicit for employment or engagement any Astra employee or contractor involved in providing Services. If Client violates this section, Client must pay Astra liquidated damages equal to the greater of $75,000 or fifty percent of the individual’s annualized compensation. The Parties agree this amount is a reasonable estimate of damages and not a penalty, subject to applicable law.

  1. Publicity

Astra may identify Client as a customer in customer lists unless Client objects in writing. Astra may not issue a press release using Client’s name without Client’s written consent.

  1. Force Majeure

Astra is not liable for delay or failure caused by events beyond its reasonable control, including acts of God, disasters, war, terrorism, labor disputes, supply-chain delays, cyberattacks, ransomware, internet failures, cloud outages, vendor failures, government action, pandemics, power failures, carrier outages, civil unrest, or emergency conditions.

  1. Notices

Notices must be in writing and delivered by personal delivery, certified mail, overnight courier, or email with confirmation to the addresses stated in the applicable Service Order.

  1. Assignment

Client may not assign this Agreement without Astra’s prior written consent. Astra may assign this Agreement to an affiliate, successor, purchaser of assets, or in connection with merger, acquisition, restructuring, or sale of substantially all assets.

  1. Subcontractors

Astra may use subcontractors and vendors to provide Services. Astra remains responsible for subcontractor work to the same extent Astra would be responsible if it performed the work directly, subject to this Agreement.

  1. Dispute Resolution

The Parties will first attempt to resolve disputes through executive-level negotiation. If unresolved, disputes must proceed to non-binding mediation in Nassau County, New York, unless Astra elects to pursue litigation for collections, injunctive relief, intellectual property, confidentiality, data protection, or emergency relief.

If mediation fails, disputes will be resolved by binding arbitration in Nassau County, New York, under the rules of the American Arbitration Association, unless Astra elects litigation for the categories above.

  1. Governing Law and Venue

This Agreement is governed by the laws of the State of New York, without regard to conflict-of-law principles. Subject to the arbitration section, courts located in Nassau County, New York, or the federal courts serving that county, have exclusive jurisdiction.

  1. Attorney Fees

The prevailing Party in any dispute is entitled to recover reasonable attorney fees, expert fees, costs, arbitration fees, collection costs, and related expenses.

  1. Injunctive Relief

A breach involving confidentiality, intellectual property, security controls, non-solicitation, unauthorized access, or misuse of Services may cause irreparable harm. Astra may seek injunctive relief without posting bond.

  1. Severability

If any provision is unenforceable, it will be modified to the minimum extent necessary to make it enforceable, and the remainder will remain in effect.

  1. Waiver

A waiver must be in writing and signed. Failure to enforce a provision is not a waiver.

  1. Electronic Signatures

Electronic signatures, email approvals, click approvals, and digital acceptance are binding.

  1. Counterparts

This Agreement may be executed in counterparts, each of which is deemed an original.

  1. Survival

Sections relating to payment, confidentiality, intellectual property, limitations of liability, indemnity, dispute resolution, governing law, audit, records, privacy, data, non-solicitation, and any provisions intended to survive will survive termination.

  1. Managed Services Overview

Managed Services are recurring services intended to support, monitor, maintain, and improve portions of the Client Environment identified in an applicable Service Order. Managed Services are not an all-risk outsourcing of Client’s technology, security, or compliance obligations.

  1. Supported Assets

Only assets specifically identified, inventoried, onboarded, monitored, and accepted by Astra are supported. Assets not onboarded are excluded.

  1. Onboarding

Onboarding may include discovery, agent deployment, documentation, credential collection, baseline review, policy review, monitoring setup, backup review, licensing review, vendor access, and initial remediation planning. Onboarding does not include remediation unless expressly stated.

  1. Help Desk

Help desk support includes reasonable remote support for Authorized Users and supported systems. Help desk excludes training, project work, personal devices, home networks, unsupported software, line-of-business application development, vendor disputes, and after-hours support unless stated otherwise.

  1. Unlimited Support

Where a Service Order references “unlimited support,” the term means unlimited reasonable remote help desk requests for covered users and supported systems during Business Hours, subject to fair use. It does not include projects, abuse, excessive repeat issues caused by Client failure to follow recommendations, onsite work, after-hours work, cybersecurity incidents, or out-of-scope services.

  1. Remote Monitoring and Management

Astra may install agents, tools, scripts, and software to monitor and manage supported assets. Client authorizes Astra to access supported systems remotely.

Client must not remove, disable, alter, block, or interfere with Astra tools.

  1. Patch Management

Patch management includes commercially reasonable deployment of supported operating-system and third-party patches for covered assets. Astra is not responsible for patches unavailable from vendors, unsupported software, failed vendor patches, compatibility issues, downtime caused by patching, Client-deferred patches, or patches requiring projects.

  1. Endpoint Detection and Response

EDR services include deployment, monitoring, alert review, policy configuration, and response actions as described in the Service Order. EDR does not guarantee detection or prevention of all threats.

  1. Anti-Virus and Anti-Malware

Anti-virus and anti-malware tools reduce risk but cannot detect or prevent all malicious activity. Client remains responsible for safe user practices and required controls.

  1. Ransomware Protection

Ransomware protection services may include endpoint protection, behavioral detection, backup, monitoring, filtering, user training, and response recommendations. No ransomware protection is guaranteed to prevent encryption, data theft, extortion, downtime, or loss.

  1. Managed SOC

Managed SOC services may include alert monitoring, triage, escalation, response recommendations, threat intelligence, and limited containment actions. Unless expressly stated, Managed SOC does not include full incident response, forensic imaging, legal notification, ransom negotiation, litigation support, or regulatory reporting.

  1. Email Filtering and Continuity

Email filtering attempts to reduce spam, phishing, malware, business email compromise, and unwanted email. No email filtering can block all malicious or unwanted messages. Client must train users and report suspicious messages.

Email continuity depends on vendor availability and configuration.

  1. Firewall Maintenance

Firewall maintenance may include firmware updates, configuration review, rule changes, backup of configurations, VPN support, and vendor coordination. It excludes cabling, ISP issues, hardware failure, major redesign, security architecture projects, and third-party application troubleshooting unless stated otherwise.

  1. Network Management

Network management may include monitoring switches, wireless access points, routers, firewalls, VPNs, and network health. It excludes ISP outages, carrier issues, electrical issues, building wiring, rogue devices, and unsupported hardware.

  1. Wireless Management

Wireless management includes configuration and troubleshooting of supported wireless systems. Wireless performance is affected by construction materials, interference, density, device capabilities, cabling, internet bandwidth, and environmental conditions.

  1. Server Management

Server management includes monitoring, maintenance, patching, backup coordination, and support for covered servers. Unsupported operating systems, legacy systems, specialized applications, and domain redesign are excluded unless stated.

  1. Workstation Management

Workstation management includes remote monitoring, patching, endpoint security, and user support for covered devices. Personal devices and unmanaged devices are excluded.

  1. Microsoft 365 Services

Microsoft 365 services may include licensing, administration, security configuration, backup, email support, identity support, and user management. Microsoft controls the Microsoft 365 platform. Astra is not responsible for Microsoft outages, data loss, license changes, feature changes, or platform defects.

  1. Microsoft Entra ID Backup

Microsoft Entra ID backup services support resilience and recovery of identity configurations. Recovery may be limited by Microsoft APIs, platform restrictions, timing, licensing, and configuration state.

  1. Microsoft 365 Backup

Microsoft 365 backup services may include backup of mailboxes, OneDrive, SharePoint, Teams, and related data as supported by the backup vendor. Backup scope, retention, frequency, and recovery limitations are governed by the Service Order and vendor capabilities.

  1. M365 Fortify

M365 Fortify includes security configuration recommendations and implementation for Microsoft 365 beyond default settings. Changes may affect user experience, application compatibility, legacy authentication, mobile access, and workflows.

  1. SaaS Alerts and SaaS Security

SaaS security monitoring may detect anomalous user behavior, suspicious logins, risky applications, and potential compromise indicators. Such tools do not guarantee detection of all account compromise.

  1. Dark Web Monitoring

Dark web monitoring searches available sources for compromised credentials or exposed information. It cannot identify all stolen data or guarantee removal.

  1. Security Awareness Training

Security awareness training educates users but cannot eliminate user risk. Client must require participation, track completion, and enforce policies.

  1. vCIO, vCTO, and vCISO Services

Virtual executive services provide strategic guidance, planning, recommendations, roadmaps, and risk discussions. They do not transfer business decision-making authority to Astra and do not constitute legal or regulatory certification.

  1. Backup Services

Backup services are subject to storage limits, retention settings, vendor limitations, supported operating systems, internet bandwidth, and configuration. Client must approve backup scope and test recovery.

  1. Backup Exclusions

Backup services exclude unmanaged systems, databases requiring special agents unless included, SaaS platforms unless included, local-only data, unsupported systems, corrupted data, encrypted data, user-deleted data outside retention, and data outside configured scope.

  1. Business Continuity

Business continuity services must be separately scoped. Disaster recovery and continuity require written recovery objectives, testing, assigned roles, vendor coordination, and Client participation.

  1. Asset Management

Client must maintain accurate asset information. Astra is not responsible for unknown, rogue, or undisclosed assets.

  1. Vendor Management

Vendor management may include coordination with vendors for supported systems. Astra is not responsible for vendor performance, vendor refusal, vendor fees, vendor defects, or vendor delays.

  1. Onsite Services

Onsite services are excluded unless expressly included. Onsite work is billed at then-current rates and may be subject to minimum charges, travel charges, scheduling, safety requirements, and after-hours rates.

  1. Maintenance Windows

Astra may perform maintenance during standard or emergency maintenance windows. Maintenance may cause downtime, reboots, interruptions, or user impact.

  1. Client Change Freeze

During incidents, migrations, audits, major projects, or remediation, Astra may require a change freeze. Client-caused changes during a freeze are at Client’s risk.

  1. Cybersecurity Services Overview

Cybersecurity Services reduce risk but do not eliminate risk. Client acknowledges that cybersecurity depends on layered controls, user behavior, vendor security, business process, legal review, insurance, physical security, and executive governance.

  1. Security Baseline

Astra may recommend a minimum-security baseline that may include MFA, EDR, patching, ransomware protection, managed SOC, email filtering, firewall maintenance, backups, vulnerability assessments, dark web monitoring, SaaS monitoring, and security training. Client’s decision not to implement baseline controls is a documented risk acceptance.

  1. Vulnerability Assessments

Vulnerability assessments identify potential weaknesses based on available scanning methods, credentials, asset visibility, scanner limitations, and environmental conditions. Results are not exhaustive and may include false positives or false negatives.

  1. Vulnerability Remediation

Remediation is separate from assessment unless expressly included. Client is responsible for approving outages, maintenance windows, business impact, vendor changes, and application testing.

  1. Penetration Testing

Penetration testing must be authorized in writing and scoped before testing begins. Scope must identify targets, dates, methods, exclusions, contacts, emergency stop procedures, and legal authorization.

Astra is not responsible for outages, lockouts, instability, data corruption, vendor alerts, or operational impacts inherent in testing, except to the extent caused by Astra’s gross negligence or willful misconduct.

  1. External Penetration Testing

Penetration testing must be authorized in writing and scoped before testing begins. Scope must identify targets, dates, methods, exclusions, contacts, emergency stop procedures, and legal authorization.

External penetration testing simulates external attack methods against approved internet-facing targets. It does not evaluate internal controls, users, physical access, wireless, social engineering, cloud misconfiguration, or source code unless included.

  1. Internal Penetration Testing

Internal penetration testing simulates threats from inside the network. Client must provide safe testing windows, authorization, and segmentation details.

  1. Social Engineering Testing

Social engineering testing requires explicit written authorization and approved scenarios. Client is responsible for HR, labor, privacy, and legal considerations.

  1. Incident Response Services

Incident Response Services may include triage, containment, eradication, recovery support, log review, endpoint isolation, account disabling, malware analysis, indicator review, vendor coordination, executive briefings, and remediation planning.

Unless expressly included, Incident Response Services exclude forensic imaging, expert reports, legal notification, law enforcement coordination, ransom negotiation, public relations, identity theft response, credit monitoring, and litigation testimony.

  1. Emergency Authority

During a Cybersecurity Event, Client authorizes Astra to take reasonable emergency actions, including isolating devices, disabling accounts, blocking traffic, changing passwords, revoking tokens, disabling mail rules, preserving logs, deploying tools, and taking systems offline.

  1. Forensics

Digital forensics requires separate scoping. Forensic findings are based on available evidence and may be limited by logging gaps, overwritten data, encryption, anti-forensic activity, lack of prior tooling, or third-party restrictions.

  1. Chain of Custody

Astra will maintain chain-of-custody procedures when forensic services are expressly requested. Chain of custody does not guarantee admissibility.

  1. Breach Determination

Astra does not determine whether a breach occurred for legal notification purposes. Client must consult legal counsel.

  1. Regulatory Reporting

Client is responsible for regulatory reporting. Astra may assist with technical facts at then-current rates.

  1. Ransomware and Extortion

Astra does not recommend paying ransom except as directed by Client after consultation with legal counsel, insurer, and law enforcement as appropriate. Astra does not guarantee decryption, recovery, non-disclosure, or threat actor conduct.

  1. Business Email Compromise

Business email compromise often involves user conduct, payment controls, vendor impersonation, social engineering, and financial processes outside Astra’s control. Astra is not responsible for fraudulent wires, payment diversion, invoice fraud, or social engineering losses.

  1. Threat Hunting

Threat hunting is limited by available telemetry, tools, logs, access, and scope. Absence of findings does not mean absence of compromise.

  1. Managed Detection and Response

MDR services include detection, analysis, escalation, and response actions within the scope of subscribed tools. MDR is not a guarantee against compromise.

  1. Security Architecture

Security architecture recommendations are advisory unless implementation is included. Client is responsible for business acceptance, budget, user impact, and ongoing governance.

  1. Compliance Security Controls

Security controls implemented for compliance may not satisfy all legal, contractual, insurance, or audit expectations. Client remains responsible for validating control sufficiency.

COMPLIANCE ADDENDA

Addendum 1 – General Compliance Services

Astra may assist with compliance readiness, but Client remains responsible for determining applicable requirements, selecting controls, accepting risk, approving policies, maintaining evidence, and communicating with regulators, auditors, insurers, customers, and counsel.

Addendum 2 – HIPAA Security Rule Support

Where Client is a covered entity or business associate, Astra may assist with administrative, physical, and technical safeguard implementation. Astra is not a Business Associate unless a BAA is executed.

HIPAA support may include risk analysis support, access controls, audit controls, integrity controls, transmission security, security awareness, contingency planning, vendor review, and documentation assistance.

Client remains responsible for HIPAA compliance, policies, workforce training, sanctions, privacy rule obligations, breach notification, and legal determinations.

Addendum 3 – Business Associate Agreement

If executed, Astra as Business Associate will:

  1. Use PHI only as permitted by the BAA.
  2. Implement reasonable safeguards.
  3. Report security incidents as required.
  4. Ensure subcontractors agree to applicable restrictions.
  5. Make PHI available as required by HIPAA.
  6. Make internal practices available to HHS as required.
  7. Return or destroy PHI where feasible upon termination.
  8. Comply with applicable Security Rule provisions.

The BAA prevails over the MSA only for PHI-specific matters.

Addendum 4 – FTC Safeguards Rule Support

For covered financial institutions, Astra may support safeguards program components, including technical controls, access controls, encryption, MFA, monitoring, vulnerability assessment, incident response planning, vendor risk support, and evidence collection.

Client remains responsible for determining coverage, appointing a qualified individual, approving the information security program, conducting risk assessments, board reporting, employee training, vendor oversight, and breach reporting.

Addendum 5 – NY SHIELD Act Support

Astra may assist with reasonable safeguards for private information of New York residents, including administrative, technical, and physical safeguard recommendations. Client remains responsible for legal compliance, breach notification, and data owner obligations.

Addendum 6 – NYDFS 23 NYCRR Part 500 Support

For covered entities, Astra may assist with technical and operational cybersecurity controls, including MFA, vulnerability management, monitoring, audit trails, access controls, asset management, encryption, incident response planning, and third-party service provider support.

Client remains responsible for determining covered entity status, exemptions, governance, board reporting, annual certifications, notices to the Superintendent, and regulatory submissions.

Addendum 7 – PCI DSS Support

Astra may assist with PCI readiness, segmentation support, vulnerability scanning coordination, firewall configuration, access control, logging, encryption, and evidence collection.

Client remains responsible for PCI scope, SAQ selection, QSA engagement, acquiring bank communication, compensating controls, cardholder data environment management, and validation.

Addendum 8 – CMMC Support

Astra may assist defense contractors and subcontractors with CMMC readiness, control implementation, evidence preparation, asset scoping, SSP/POA&M support, and technical remediation.

Client remains responsible for determining FCI/CUI scope, contractual obligations, SPRS submissions, affirmations, assessment readiness, C3PAO engagement, and DoD reporting.

Addendum 9 – GDPR/Data Processing Addendum

Where Astra processes personal data on behalf of Client as processor, Astra will:

  1. Process personal data only on documented instructions.
  2. Use confidentiality obligations.
  3. Implement appropriate technical and organizational measures.
  4. Assist with data subject requests where required and feasible.
  5. Assist with security obligations where applicable.
  6. Use subprocessors under appropriate terms.
  7. Assist with deletion or return at termination, subject to legal retention.
  8. Make reasonable information available for audits.
  9. notify Client of instructions that Astra believes violate applicable data protection law.

Client is the controller and remains responsible for lawful basis, notices, consent, data subject rights, DPIAs, cross-border transfer decisions, and regulatory communication.

Addendum 10 – Standard Contractual Clauses

Where required for international transfers, the Parties will execute applicable Standard Contractual Clauses or another lawful transfer mechanism. If the SCCs conflict with this Agreement, the SCCs control only to the extent required by law.

Addendum 11 – Audit Support

Audit support is billable unless expressly included. Astra may provide technical evidence reasonably available to Astra. Astra is not required to create new evidence, certify compliance, attend unlimited meetings, or respond directly to auditors unless agreed.

EXHIBIT A

MICROSOFT LICENSING TERMS

Client acknowledges that Microsoft licensing procured through Astra may be subject to fixed commitment terms. During the applicable license term, Client may be obligated to maintain licensed quantities without reduction or early cancellation.

If Microsoft or a distributor changes pricing, billing rules, commitment terms, cancellation rules, product names, product features, taxes, fees, or other license terms, Astra may pass those changes through to Client.

Client remains responsible for all Microsoft subscriptions ordered for Client, including subscriptions ordered at Client’s request, subscriptions required for Services, and subscriptions renewed automatically under Microsoft or distributor rules.

EXHIBIT B

AI SERVICES AND AUTOMATION ADDENDUM

Astra may use AI-enabled tools or automation to support ticketing, monitoring, alert triage, documentation, email security, threat analysis, scripting, summarization, reporting, or operational efficiency.

AI outputs are not guaranteed to be accurate, complete, secure, suitable, or error-free. Astra will use commercially reasonable human oversight where appropriate.

Client must not provide PHI, cardholder data, CUI, credentials, secrets, or highly sensitive data to AI systems unless the Parties agree in writing.

Client remains responsible for business decisions based on AI outputs.

EXHIBIT C

THIRD-PARTY VENDOR DISCLAIMER

Client acknowledges that Astra’s Services may depend on third-party products and platforms. Astra does not control and is not liable for third-party defects, vulnerabilities, outages, end-of-life decisions, licensing changes, security failures, price increases, data loss, support delays, or contract terms.

Vendor terms are passed through to Client where applicable.

EXHIBIT D

CYBER INSURANCE REQUIREMENTS

Client should maintain cyber liability insurance appropriate to its industry, revenue, data, risk profile, and contractual obligations.

Recommended coverage includes:

  1. Incident response.
  2. Digital forensics.
  3. Breach counsel.
  4. Notification.
  5. Credit monitoring.
  6. Business interruption.
  7. Data restoration.
  8. Ransomware and extortion.
  9. Business email compromise.
  10. Regulatory defense.
  11. PCI assessments.
  12. Third-party liability.
  13. Social engineering fraud.
  14. Cybercrime.

Astra does not guarantee insurance coverage or claim acceptance.

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare