Enterprise contract for Proxara customers. Both products (Proxara Connect and Endpoint Protection), deployment models, per-product seats, third-party dependencies, fees, confidentiality, indemnification, and termination.
Updated July 2026
Last updated: July 2026
This Master Subscription Agreement ("Agreement") is entered into between Proxara, Inc. ("Proxara," "we," or "us") and the entity identified on the applicable Order Form ("Customer"). Each party is a "Party" and together the "Parties."
"Authorized User" means an individual employee or contractor of Customer authorized by Customer to use the Service under Customer's subscription. For Proxara Connect, the unit of authorization is a "Connected Employee": an Authorized User who has been enabled for the Customer's connector and has connected their own Microsoft account. For Endpoint Protection, the unit of authorization is a covered device.
"Confidential Information" means all non-public information disclosed by one Party to the other, whether orally, in writing, or electronically, that is designated as confidential or that a reasonable person would understand to be confidential given the nature of the information and circumstances of disclosure. Confidential Information includes the terms of this Agreement, pricing, technical specifications, security architecture, and Customer Data.
"Customer Data" means all data, including personal data, that the Service processes on Customer's behalf, including prompt text, AI responses, employee metadata, classification results, and audit records.
"Documentation" means the technical documentation, user guides, deployment guides, and API documentation Proxara provides in connection with the Service.
"Order Form" means the ordering document executed by the Parties that references this Agreement and specifies subscription details, including deployment model, subscription term, number of Authorized Users, industry profile, fees, and any additional terms.
"Service" means the Proxara data-protection and AI governance software specified in the applicable Order Form, comprising one or both of the following products, together with the classification and control-plane API, the compliance console, and related components as described in the Documentation:
The two products share one environment, one identity graph, one policy, and one record. Adding one product to an existing subscription for the other does not require a tenant migration, re-enrollment, or a second console.
"Service Level Agreement" or "SLA" means the service level commitments set forth in the Service Level Agreement referenced by the applicable Order Form.
Subject to the terms of this Agreement and payment of applicable fees, Proxara grants Customer a non-exclusive, non-transferable, non-sublicensable license to install (where applicable), configure, and use the Service for Customer's internal business purposes during the Subscription Term, solely for the number of Connected Employees, devices, or Authorized Users specified per product in the applicable Order Form.
The Service may be deployed under one of the following models, as specified in the Order Form:
(a) Proxara-Managed (Default). Proxara provisions and manages a dedicated, single-tenant AWS account on behalf of Customer. Each customer account has its own network, encryption keys, database, and audit store. No shared multi-tenant environment holds Customer Data. Customer receives read-only access to this environment. Proxara has operational access for deployment, maintenance, and support. Customer's IT team is not required to set up or maintain any infrastructure. Data within the environment belongs to Customer. Upon termination, Customer may elect to take ownership of the dedicated account, or Proxara will delete all Customer Data and certify deletion in writing.
(b) Customer-Managed Deployment. Proxara provides deployment templates (Terraform or equivalent) and the Service software. Customer deploys and operates the Service in Customer's own AWS account. Proxara does not have access to Customer's infrastructure or data unless explicitly granted for support purposes. In this model, AWS is Customer's own infrastructure provider, not a Proxara sub-processor.
(c) MSP-Managed Deployment. A third-party Managed Service Provider designated by Customer deploys and operates the Service using Proxara's deployment templates. Proxara's contractual relationship is with Customer; the MSP operates under Customer's authority.
Deployment of Proxara Connect consists of: (a) one tenant-wide administrator consent to the verified Proxara Connect application in Customer's Microsoft tenant, granting delegated, read-only permissions under which the connector can only ever access what each signed-in employee can already access; and (b) the addition of Customer's connector to Customer's Claude workspace by a Claude administrator. A Claude plan that supports organization custom connectors is a prerequisite. No software is installed on any device. Annex A states the product-specific terms.
The Endpoint Protection device agent reaches employee laptops through the firm's MDM platform (Jamf, Intune, Kandji, and compatible platforms). Employees install nothing themselves. For Proxara-Managed deployments, the device agent package and associated MDM configuration profile are provided by Proxara for Customer's IT team to assign to the relevant device group. Annex B states the product-specific terms.
Customer shall not, and shall ensure its Authorized Users do not:
Where Customer deploys Endpoint Protection, Customer is responsible for providing adequate notice to Authorized Users that their interactions with external AI tools may be monitored, reviewed, and subject to automated redaction through the Service, and shall comply with all applicable employee monitoring laws, including the Electronic Communications Privacy Act (ECPA), applicable state notification requirements, and any labor agreements. Where Customer deploys Proxara Connect, the service is invoked by the employee rather than observing the employee; Customer remains responsible for any notice Customer owes its own personnel regarding the processing of their work content, and for any notice or consent Customer owes its own clients under applicable law or professional obligation. Proxara provides a customizable Employee Monitoring Disclosure Template (which includes a Proxara Connect notice) and a Client Consent Template to assist Customer with these obligations; the obligations remain Customer's.
For Proxara-Managed deployments, Proxara is responsible for provisioning, securing, and maintaining the dedicated AWS account on which the Service runs. For Customer-Managed and MSP-Managed deployments, Customer is responsible for provisioning, securing, and maintaining the AWS infrastructure in accordance with the Documentation and Proxara's recommended security configuration. Where Endpoint Protection is deployed, Customer is responsible for deploying and removing the device agent on employee endpoints via MDM, including the associated MDM configuration profile that establishes trust for the Proxara CA. Where Proxara Connect is deployed, Customer is responsible for the administration of its own Microsoft tenant and its own AI-assistant workspace, including, where Customer requires that all connected source access run through Proxara, disabling overlapping native connectors in the AI assistant's own settings; a native connector runs inside the AI host and outside Proxara's path.
Customer shall comply with the Acceptable Use Policy and shall ensure that all Authorized Users comply with it.
Customer is responsible for configuring the Service in a manner appropriate for Customer's regulatory requirements and for determining whether the Service satisfies Customer's compliance obligations. Proxara does not provide legal or compliance advice. Without limiting the foregoing, the Service enforces Customer's approved policy and narrows disclosure; it does not create, ensure, or automate Customer's compliance with 26 U.S.C. §7216, the FTC Safeguards Rule, professional conduct rules, or any other law or professional obligation, and Proxara assumes no such obligation of Customer.
The Service interoperates with services Customer obtains from third parties under Customer's own agreements, including Customer's AI assistant (for example, Claude) and Customer's Microsoft 365 tenant. Proxara does not control those services. Unavailability, degradation, or changes of a third-party service (including the AI host's connector features and Microsoft Graph) are not a breach of this Agreement by Proxara, and the Service Level Agreement excludes them from availability commitments. Proxara will engineer the Service to degrade safely when a dependency is unavailable, as described in the Documentation.
Customer shall pay the fees specified in the applicable Order Form.
Invoices are due per the payment terms specified in the Order Form. Late payments accrue interest at the lesser of 1.5% per month or the maximum rate permitted by law.
Fees are exclusive of taxes. Customer is responsible for all sales, use, VAT, and similar taxes, excluding taxes based on Proxara's net income.
Proxara may adjust fees upon renewal by providing at least 60 days' written notice prior to the start of the renewal term.
As between the Parties, Customer retains all right, title, and interest in and to Customer Data. Proxara acquires no rights in Customer Data except the limited rights necessary to provide the Service.
As between the Parties, Proxara retains all right, title, and interest in and to the Service, Documentation, deployment templates, classification models, redaction prompts, and all related intellectual property. Customer's use of the Service does not transfer any ownership rights.
Proxara may collect and use aggregated, anonymized, de-identified data derived from the operation of the Service (such as aggregate entity detection rates, latency metrics, and error rates) for purposes of improving the Service, provided that such data does not identify Customer, any Authorized User, or any individual. Customer Data is never included in aggregated data without anonymization.
Where Proxara acts as a data processor (Proxara-Managed deployment model), the processing of personal data is governed by the Data Processing Addendum.
Each Party agrees to: (a) hold the other Party's Confidential Information in strict confidence; (b) not disclose it to third parties except as permitted herein; and (c) use it only for purposes of performing its obligations or exercising its rights under this Agreement.
A Party may disclose the other Party's Confidential Information to its employees, contractors, and advisors who have a need to know and are bound by confidentiality obligations at least as protective as those in this Agreement. Proxara may disclose Confidential Information to sub-processors listed in the Sub-processor List to the extent necessary to provide the Service.
Confidential Information does not include information that: (a) is or becomes publicly available through no fault of the receiving Party; (b) was known to the receiving Party prior to disclosure; (c) is independently developed by the receiving Party without use of the disclosing Party's Confidential Information; or (d) is rightfully received from a third party without restriction.
If a Party is compelled by law or court order to disclose Confidential Information, it shall provide prompt written notice to the other Party (to the extent legally permitted) and cooperate to limit the scope of disclosure.
Confidentiality obligations survive termination of this Agreement for three (3) years, except for trade secrets, which shall be protected for as long as they remain trade secrets under applicable law.
Proxara shall implement and maintain administrative, technical, and organizational security measures appropriate to the nature of the Service and the sensitivity of Customer Data, as described in the Security Overview. For Proxara-Managed deployments, these measures include encryption at rest and in transit, network isolation, access controls, and audit logging.
Proxara shall notify Customer without undue delay, and in any event within 72 hours, of becoming aware of any confirmed unauthorized access to Customer Data in a Proxara-Managed deployment. Proxara shall cooperate with Customer's investigation and remediation efforts.
Each Party represents and warrants that: (a) it has the legal power and authority to enter into this Agreement; (b) this Agreement constitutes a valid and binding obligation; and (c) its performance will not violate any applicable law or third-party rights.
Proxara warrants that: (a) the Service will perform materially in accordance with the Documentation during the Subscription Term; (b) it will provide the Service in a professional and workmanlike manner; and (c) it will not knowingly introduce malicious code into the Service.
EXCEPT AS EXPRESSLY SET FORTH IN THIS SECTION, THE SERVICE IS PROVIDED "AS IS." PROXARA DISCLAIMS ALL OTHER WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. PROXARA DOES NOT WARRANT THAT THE SERVICE WILL DETECT ALL SENSITIVE DATA, PREVENT ALL DATA LEAKAGE, OR ENSURE COMPLIANCE WITH ANY PARTICULAR REGULATION.
Proxara shall indemnify, defend, and hold harmless Customer from and against any third-party claims, damages, and expenses (including reasonable attorneys' fees) arising from allegations that Customer's authorized use of the Service infringes a third party's intellectual property rights. Proxara's obligations do not apply to claims arising from: (a) modifications made by Customer; (b) combination of the Service with non-Proxara products; or (c) use in violation of this Agreement.
Customer shall indemnify, defend, and hold harmless Proxara from and against any third-party claims, damages, and expenses (including reasonable attorneys' fees) arising from: (a) Customer Data; (b) Customer's use of the Service in violation of applicable law or this Agreement; or (c) Customer's failure to comply with applicable employee monitoring laws.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY SHALL BE LIABLE TO THE OTHER FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, DATA, OR GOODWILL, ARISING OUT OF OR RELATED TO THIS AGREEMENT, REGARDLESS OF THE THEORY OF LIABILITY.
EACH PARTY'S TOTAL AGGREGATE LIABILITY UNDER THIS AGREEMENT SHALL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER TO PROXARA DURING THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
The limitations in Sections 10.1 and 10.2 do not apply to: (a) a Party's indemnification obligations under Section 9; (b) a Party's breach of confidentiality obligations under Section 6; (c) Proxara's breach of its data security obligations; or (d) either Party's willful misconduct or fraud.
The initial Subscription Term is specified in the applicable Order Form. Unless otherwise stated, the initial term is twelve (12) months from the Effective Date.
Unless either Party provides written notice of non-renewal prior to the end of the then-current term (per the notice period specified in the Order Form), the subscription will automatically renew for successive twelve (12) month periods at the then-current pricing.
Either Party may terminate this Agreement upon written notice if the other Party materially breaches this Agreement and fails to cure the breach within thirty (30) days of receiving written notice specifying the breach.
Either Party may terminate this Agreement immediately upon written notice if the other Party becomes insolvent, makes an assignment for the benefit of creditors, or becomes subject to bankruptcy or receivership proceedings.
Upon termination or expiration:
This Agreement shall be governed by and construed in accordance with the laws of the State of California, without regard to its conflict of law provisions.
Any dispute arising out of or relating to this Agreement shall first be subject to good-faith negotiation between senior representatives of the Parties for a period of thirty (30) days. If the dispute is not resolved through negotiation, it shall be resolved exclusively in the state or federal courts located in California. Each Party consents to the personal jurisdiction of such courts.
Neither Party shall be liable for delays or failures in performance resulting from causes beyond its reasonable control, including natural disasters, acts of government, pandemics, war, terrorism, labor disputes, power failures, internet disruptions, or failures of third-party services.
Neither Party may assign this Agreement without the prior written consent of the other Party, except that either Party may assign this Agreement in connection with a merger, acquisition, or sale of all or substantially all of its assets.
All notices under this Agreement shall be in writing and sent to the addresses specified in the Order Form. Notices to Proxara may be sent to Proxara, Inc., 28 Geary St. Suite 650 PMB 5328, San Francisco, CA 94108, or by email to support@proxara.ai. Notices are effective upon receipt if delivered personally or by overnight courier, or three (3) business days after mailing by certified mail.
If any provision of this Agreement is found unenforceable, the remaining provisions shall continue in full force and effect.
The failure of either Party to enforce any right or provision of this Agreement shall not constitute a waiver of that right or provision.
This Agreement, together with all Order Forms, the Data Processing Addendum, the Acceptable Use Policy, the Service Level Agreement, and any other documents incorporated by reference, constitutes the entire agreement between the Parties and supersedes all prior agreements and understandings. In the event of a conflict, the order of precedence is: (1) the Data Processing Addendum; (2) the Order Form; (3) this Agreement.
This Agreement may only be amended by a written instrument signed by both Parties.
| Field | Value |
|---|---|
| Customer Legal Name | _______________________________ |
| Customer Address | _______________________________ |
| Customer Contact (Name, Email) | _______________________________ |
| Products | [ ] Proxara Connect / [ ] Endpoint Protection / [ ] Both |
| Deployment Model | [ ] Proxara-Managed / [ ] Customer-Managed / [ ] MSP-Managed |
| Industry Profile | [ ] Wealth Management / [ ] Legal / [ ] Healthcare / [ ] Accounting / [ ] Insurance / [ ] Recruitment / [ ] Marketing / [ ] General |
| Proxara Connect: Number of Connected Employees | _______________________________ |
| Endpoint Protection: Number of Authorized Users / Devices | _______________________________ |
| Subscription Term | _______________________________ |
| Subscription Start Date | _______________________________ |
| Fees | _______________________________ |
| Payment Terms | _______________________________ |
| Additional Terms | _______________________________ |
Proxara:
Signature: _______________________________
Name: _______________________________
Title: _______________________________
Date: _______________________________
Customer:
Signature: _______________________________
Name: _______________________________
Title: _______________________________
Date: _______________________________
This Annex applies where the Order Form includes Proxara Connect.
A.1 Seat. The billable unit is the Connected Employee. An Authorized User becomes a Connected Employee when enabled for Customer's connector and connected with their own Microsoft account, and ceases to be one when disabled in Proxara or in Customer's directory.
A.2 Scope of protection. Proxara Connect governs data retrieved and actions performed through Customer's Proxara connector. It does not govern text typed or files uploaded directly into an AI assistant, native connectors running inside the AI host, or AI traffic outside the connector path; Endpoint Protection is the product that addresses device-side coverage.
A.3 Access model. All Microsoft access is delegated and bounded by each signed-in employee's own permissions. Customer's tenant administrator grants and may unilaterally revoke the application consent in Customer's own Entra admin center. Consent grants read permissions only; action features that write to Microsoft (for example, drafting mail or creating tasks) require a separate, explicit permission expansion and a fresh administrator consent before they become available.
A.4 Customer administration. Customer is responsible for its Claude workspace administration (including the organization-connector plan prerequisite and, where Customer requires full routing, disabling overlapping native connectors) and for its Microsoft tenant administration (including the permissions its own employees hold, which bound what the connector can retrieve).
A.5 Retention. Proxara does not keep copies of Customer's mail and files. The Service fetches what is needed when an employee asks, protects it, holds working state encrypted in Customer's environment only as long as the work requires, and keeps the record of what it did. The mapping between a protected reference and its stand-in remains in Customer's environment.
This Annex applies where the Order Form includes Endpoint Protection.
B.1 Seat. The billable unit is as specified in the Order Form (Authorized Users or covered devices).
B.2 Scope of protection. Endpoint Protection governs AI-bound traffic observed at the device: prompts, uploads, provider traffic, and managed local MCP paths on devices where the agent is installed and its certificate is trusted. It does not govern hosted source access that never crosses a covered endpoint.
B.3 Customer administration. Customer deploys and removes the device agent through its MDM platform, including the trusted-certificate profile. Coverage on a device requires the agent installed and its certificate trusted; devices without both are reported as uncovered rather than silently covered.