

Policy
Sprocket Security End User Agreement
This Agreement governs your use of the Sprocket Security Services.
Sprocket Security, Inc.
End‑User License Agreement
This End User License Agreement (“EULA”) is a legally binding agreement between the individual or entity user that is authorized by the Customer (as defined below) to access and use the Sprocket Security Services (“End User,” “you,” or “your”) and Sprocket Security, Inc. (“Sprocket Security,” “we,” or “us”). This EULA governs your access to and use of (i) the platform provided by Sprocket Security, including all software, interfaces, tools, utilities, functionality and other technologies and any related intellectual property relating thereto (collectively, the “Sprocket Security Platform”) and (ii) the services described in an Order, including, but not limited to, the services available on the Sprocket Security Platform (collectively, the “Sprocket Security Services”). You agree to be bound by these Terms and all of the terms incorporated herein by reference.
By selecting “I Agree,” creating an account, or accessing or using the Sprocket Security Platform or the Sprocket Security Platform, you represent that you are an Authorized User designated by the customer that has executed an Order (“Customer”) governing the provision of the Sprocket Security Services (“Customer Agreement”) and you agree to be bound by this EULA. If you do not agree, do not access or use the Sprocket Security Services.
IF YOU ARE ENTERING INTO THIS EULA ON BEHALF OF A COMPANY OR OTHER LEGAL ENTITY, YOU REPRESENT THAT YOU HAVE THE AUTHORITY TO BIND SUCH ENTITY AND ITS AFFILIATES TO THESE TERMS AND CONDITIONS, IN WHICH CASE THE TERMS “YOU” AND “END USER” SHALL REFER TO SUCH ENTITY AND ITS AFFILIATES. IF YOU DO NOT HAVE SUCH AUTHORITY, OR IF YOU DO NOT AGREE WITH THESE TERMS AND CONDITIONS, YOU MUST NOT ACCEPT THIS EULA AND MAY NOT USE THE SPROCKET SECURITY SERVICES.
This EULA was last updated on May 12, 2026. It is effective between End User and Sprocket Security as of the date End User accepted this EULA (“Effective Date”). Sprocket Security and End User are each referred to herein as a “Party” and collectively as the “Parties.” In consideration of the mutual promises and upon the terms and conditions herein, the Parties agree as follows:
1. Definitions
1.1 “Authorized Users” means those individuals authorized by Customer to use the Sprocket Security platform pursuant to the license granted under this EULA, as set forth on the Order or Customer Agreement.
1.2 “Deliverables” means reports, findings, analytics, dashboards, and other outputs generated by the Service from End User Materials.
1.3 “Documentation” means user guides, runbooks, usage notes, and policies made available by Sprocket Security.
1.4 “End User” means the Authorized User designated by the Customer (as defined above).
1.5 “End User Account” means the account used by End User to access the Sprocket Security Platform, as permitted by Sprocket Security in accordance with this EULA.
1.6 “End User Materials” means any application, software, technology, or other product or service that is submitted by End User to Sprocket Security for testing in connection with the Sprocket Security Services, and any environment in which the foregoing exist, as well as any other software, technology, information, data, materials and intellectual property provided or made available by End User to Sprocket Security hereunder.
1.7 “Free Sprocket Services” means any services provided to End User by Sprocket Security without any fee or charge, including, without limitation, a trial, demo, newsletter, sample, or Sprocket Security’s Attack Surface Management platform.
1.8 “Ongoing Enablement” means Sprocket Security’s ongoing enablement hosted at: https://www.sprocketsecurity.com/ongoing-enablement.
1.9 “Order” means the applicable executed Order between Sprocket Security and Customer or an Authorized Reseller and the Customer.
1.10 “Paid Sprocket Services” means any Sprocket Security Services for which End User must provide compensation.
1.11 “Sprocket Security Personnel” means the Sprocket Security employees and contractors performing the Sprocket Security Services hereunder.
1.12 “Sprocket Security’s Privacy Policy” means Sprocket Security’s privacy policy hosted at: https://www.sprocketsecurity.com/privacy-policy.
1.13 “Sprocket Security’s Terms of Service” means Sprocket Security’s terms of service hosted at: https://www.sprocketsecurity.com/terms-of-service.
1.14 “Target(s)” means the networks, systems, applications, IP addresses, domains, environments, accounts, and assets that you are expressly authorized by Customer (as defined below) to test using the Sprocket Security Services and Sprocket Security Platform within the scope permitted by law and the Customer Agreement.
1.15 “Term” means the Term or Renewal Term as set forth on the Order or as defined in the Customer Agreement.
2. Relationship to the Customer Agreement; Scope of this EULA
Sprocket Security’s provision of the Sprocket Security Services is governed by the Customer Agreement with the customer entity that authorizes your access (“Customer”). This EULA applies solely to your use as an End User. The Customer Agreement controls as between Sprocket Security and Customer and, to the extent of any conflict between the Customer Agreement and this EULA, the Customer Agreement will prevail with respect to the rights and obligations between Sprocket Security and Customer. This EULA does not grant you any rights or remedies under the Customer Agreement and does not modify the Customer Agreement. Sprocket Security may enforce this EULA directly against you, and Customer may enforce your obligations to the extent contemplated by the Customer Agreement.
3. License Grant and Access
3.1 License Grant
Subject to this EULA and the Customer Agreement, Sprocket Security grants you a limited, revocable, non-exclusive, non-transferable, and non-sublicensable right to access and use the Sprocket Security Platform and the Sprocket Security Services: (a) as an Authorized User for Customer’s internal business purposes; (b) within the usage parameters, features, modules, environments, and time periods as set forth on the applicable Order; and (c) to conduct authorized security testing and analysis on Targets that you are duly and lawfully permitted to test. You may use the Documentation solely in connection with your authorized use of the Sprocket Security Services. No rights are granted except as expressly stated.
3.2 Account Registration and Credentials
You must keep your account information accurate and up to date. You are responsible for safeguarding login credentials, MFA tokens, keys, and access controls associated with your account and for all activities under your account. You will promptly notify Sprocket Security and Customer of any suspected unauthorized access or compromise. You must implement appropriate technical controls (including MFA where offered) and follow Sprocket Security’s security recommendations and Documentation.
3.3 Free Sprocket Services
You acknowledge that any access to the Sprocket Security Platform, and/or any Free Sprocket Services provided therewith, are offered by Sprocket Security free of charge to you subject to Sprocket Security’s Terms of Service and the terms of this EULA. Sprocket Security may, in its sole discretion, suspend or terminate your access to any Free Sprocket Services or stop offering any Free Sprocket Services altogether, in either case with or without notice to you. If you register for a free trial of any Sprocket Security Services or otherwise utilize free capabilities, you understand that this EULA will also govern that free trial. NOTWITHSTANDING ANYTHING HEREIN TO THE CONTRARY, FREE SPROCKET SERVICES, INCLUDING, BUT NOT LIMITED TO, THE ATTACK SURFACE MANAGEMENT PLATFORM, ARE OFFERED “AS-IS” WITHOUT ANY WARRANTY AND SPROCKET SECURITY SPECIFICALLY DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE WITH RESPECT TO ALL FREE SPROCKET SERVICES, INCLUDING, BUT NOT LIMITED TO, ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT, AND ALL WARRANTIES ARISING FROM COURSE OF DEALING, USAGE, OR TRADE PRACTICE. End User hereby acknowledges and agrees that Sprocket Security is under no obligation to provide any customer support or maintenance for the Free Sprocket Services. Any updates and improvements to the Free Sprocket Services shall be made, or not made, in the full discretion of Sprocket Security, and Sprocket Security is under no obligation to release or make available any updates or improvements of the Free Sprocket Services to End User.
3.4 Paid Sprocket Services
If you choose to purchase Paid Sprocket Security Services, then Sprocket Security shall provide such Paid Sprocket Security Services to you as described in accordance with the terms of this EULA and any additional terms in an Order which have been agreed in writing by Sprocket Security.
3.5 Suspension
Sprocket Security may suspend your access immediately if Sprocket Security reasonably believes that you violated this EULA, your account is compromised, your use risks the security, integrity, or availability of the Sprocket Security Services or third-party systems, or suspension is required by law.
4. End User obligations
4.1 Sprocket Security Platform Restrictions
Fair use of the Sprocket Security Platform requires that you exercise your authorized access solely to perform scoped security testing for Customer’s internal business purposes, using non-destructive methods and honoring all rules of engagement, maintenance windows, and rate limits described in the Order or Documentation. You must confine all activity to approved Targets and data sets, minimize collection of personal data, and handle any End User Materials in accordance with Customer’s policies, this EULA, and applicable security and privacy notices. You may view and use Deliverables for Customer’s internal remediation and risk management, but you may not reproduce, distribute, or publicly disclose Deliverables, platform content, or Sprocket Security intellectual property except as expressly permitted by the Customer Agreement. Your use of the Sprocket Security Platform must avoid actions that could cause undue harm, disrupt third-party systems, or exceed legal authorization, and you must promptly pause testing and escalate if you detect instability, potential data loss, or suspected unlawful activity. Operationally, you are responsible for safeguarding credentials, respecting technical controls (including rate limiting and access restrictions), and promptly reporting suspected security incidents, misdirected data, or privacy concerns to Customer. Any use that circumvents security controls, misrepresents authorization, exploits vulnerabilities beyond agreed proof-of-concept, or leverages the Sprocket Security Platform or Sprocket Security Platform to build a competing product, is not fair use and may result in suspension or termination, as well as legal consequences.
Without limiting the foregoing, in connection with End User’s use of the Sprocket Security Platform, End User shall not:
copy, reproduce, alter, modify, create derivative works from, rent, lease, loan, sell, distribute or publicly display the Sprocket Security Platform, Sprocket Security Services, any other material made available via the Sprocket Security Services, or any part of any of the foregoing, without the prior written consent of Sprocket Security;
decompile, disassemble, translate or otherwise reverse engineer or attempt to derive the source code for the Sprocket Security Platform or the Sprocket Security Services or any portion thereof;
attempt to obtain any information or content from the Sprocket Security Platform or Sprocket Security website using any robot, spider, scraper or other automated means for any purpose, except as otherwise expressly permitted in writing by Sprocket Security;
transmit or upload any software viruses or any other computer codes, files, or programs that are designed or intended to disrupt, damage, limit, or interfere with the proper function of any software, hardware, or telecommunications equipment or to damage or obtain unauthorized access to any system, data, password, or other information of Sprocket Security or any third party;
misrepresent or impersonate any person or entity, including any employee or representative of Sprocket Security;
use the Sprocket Security Platform or the Sprocket Security Services on or against any data, systems, or other information that End User (i) does not have the sole right to provide to Sprocket Security to perform its duties relating to the Sprocket Security Platform or its performance of the Sprocket Security Services, or (ii) has not obtained all necessary and required consents to provide to Sprocket Security to perform its duties relating to the Sprocket Security Platform or its performance of the Sprocket Security Services;
Test, probe, scan, or interact with any system, asset, or data that is not an approved Target or outside the authorized testing scope, window, or methods defined by the rules of engagement provided by the Customer, if any, and applicable law.
Use the Sprocket Security Services to build a competing product or service, benchmark for competitive purposes without Sprocket Security’s written consent, or use any output to train a competing model where prohibited by the Customer Agreement.
interfere or attempt to interfere with the proper working of the Sprocket Security Platform or Sprocket Security Services or any activities conducted on the Sprocket Security Platform or Sprocket Security Services;
use the Sprocket Security Platform or the Sprocket Security Services in any manner that: (i) infringes any patent, trademark, trade secret, copyright, right of publicity, or other right of any other person or entity or violates any law or contract; (ii) is false, misleading or inaccurate; (iii) is unlawful, threatening, abusive, harmful, harassing, defamatory, libelous, deceptive, fraudulent, tortious, obscene, offensive, profane or invasive of another’s privacy; (iv) makes any unsolicited communications or advertising not authorized by Sprocket Security, promotional materials or any other form of solicitation for any type of information; or (v) imposes, as determined in Sprocket Security’s sole discretion, an unreasonable or disproportionately large load on Sprocket Security’s IT infrastructure; or
violate any applicable law, regulation, court order, including without limitation the Computer Fraud and Abuse Act, anti-hacking laws, export controls, sanctions, privacy, and data protection laws.
5. Intellectual Property Rights
5.1 Sprocket Security Platform and Sprocket Security Services
Subject to the rights expressly granted to End User in this EULA, any and all intellectual property rights in or related to the Sprocket Security Platform and Sprocket Security Services, including all related technology and services, are and shall remain, as between End User and Sprocket Security, the sole and exclusive property of Sprocket Security.
6. Confidential Information
You may gain access to non-public information of Sprocket Security, including product information, security information, pricing, roadmaps, and technical data (“Sprocket Security Confidential Information”). You will not disclose Sprocket Security Confidential Information, except to Customer or other Authorized Users who need to know for permitted use and who are subject to confidentiality obligations. Further, you may not, directly or indirectly, use or reference, or permit the use of or reference to, any of Sprocket Security’s Confidential Information, including but not limited to any of Sprocket Security’s trade secrets, to create, modify, implement, publish, or offer any software platform or service that performs penetration testing, vulnerability scanning, or other similar security services. You will use at least reasonable care to protect it and only use it to exercise rights or perform obligations under this EULA. Confidentiality obligations do not apply to information that is public through no fault of yours, already known to you without confidentiality obligations, independently developed without use of Sprocket Security Confidential Information, or rightfully received from a third party without confidentiality obligations.
7. Warranties
7.1 End User Warranties
End User represents and warrants that (a) it owns or otherwise has and will have the necessary rights and consents in and relating to the End User Materials so that, as submitted by End User to Sprocket Security for provision of the Sprocket Security Services or use of the Sprocket Security Platform, such End User Materials do not and will not infringe, misappropriate, or otherwise violate any intellectual property rights, or any privacy or other rights of any third party or violate any applicable law and (b) it will not use the Sprocket Security Services for any purpose other than as described the applicable Order or in violation of the restrictions set forth in Section 4. End User shall immediately notify Sprocket Security in writing if End User becomes aware of any actual or suspected infringement, misappropriation, or other violation of rights by the authorization provided by End User to Sprocket Security with respect to the Sprocket Security Services.
7.2 Disclaimer of Warranties
OTHER THAN AS PROVIDED HEREIN, THE SPROCKET SECURITY SERVICES, INCLUDING BUT NOT LIMITED TO FREE SPROCKET SERVICES; THE SPROCKET SECURITY PLATFORM AND ANY CONTENT AND INFORMATION PRESENTED ON OR VIA THE SPROCKET SECURITY SERVICES OR THE SPROCKET SECURITY PLATFORM ARE PROVIDED ON AN “AS IS” BASIS WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, TIMELINESS, ACCURACY, COMPLETENESS, RELIABILITY, MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT OR SAFETY. ANY ORAL OR WRITTEN INFORMATION OR ADVICE PROVIDED BY SPROCKET SECURITY OR ITS AUTHORIZED REPRESENTATIVES, OR BY SPROCKET SECURITY PERSONNEL, WILL NOT BE DEEMED TO CREATE ANY WARRANTY. WITHOUT LIMITING THE FOREGOING, NEITHER SPROCKET SECURITY NOR ITS LICENSORS WARRANT THAT ACCESS TO THE SPROCKET SECURITY SERVICES OR THE SPROCKET SECURITY PLATFORM WILL BE UNINTERRUPTED OR THAT THE SPROCKET SECURITY SERVICES OR THE SPROCKET SECURITY PLATFORM WILL BE ERROR-FREE.
8. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED UNDER APPLICABLE LAW, IN NO EVENT WILL SPROCKET SECURITY OR ITS AFFILIATES, OR ANY OF ITS OR THEIR RESPECTIVE OFFICERS, DIRECTORS, EMPLOYEES, SHAREHOLDERS, AGENTS, AFFILIATES, SPROCKETS, COMPANY’S, SUCCESSORS, OR ASSIGNS (COLLECTIVELY, THE “RELEASEES”) HAVE ANY LIABILITY ARISING FROM OR RELATED TO THIS EULA OR YOUR USE OF OR INABILITY TO USE SPROCKET SECURITY PLATFORM FOR: (a) PERSONAL INJURY, PROPERTY DAMAGE, LOST PROFITS, COST OF SUBSTITUTE GOODS OR SERVICES, LOSS OF DATA, LOSS OF GOODWILL, BUSINESS INTERRUPTION, COMMERCIAL DAMAGES OR LOSSES, COMPUTER FAILURE OR MALFUNCTION, OR ANY OTHER CONSEQUENTIAL, INCIDENTAL, INDIRECT, EXEMPLARY, SPECIAL, MULTIPLE, OR PUNITIVE DAMAGES; OR (b) DIRECT DAMAGES IN AMOUNTS THAT IN THE AGGREGATE EXCEED THE AMOUNT ACTUALLY PAID BY YOU FOR THE APPLICATION (COLLECTIVELY, “DAMAGES”).
THE FOREGOING LIMITATIONS OF LIABILITY WILL APPLY WHETHER SUCH DAMAGES ARISE OUT OF BREACH OF CONTRACT, TORT (INCLUDING NEGLIGENCE), OR OTHERWISE AND REGARDLESS OF WHETHER SUCH DAMAGES WERE FORESEEABLE OR COMPANY WAS ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. SOME JURISDICTIONS DO NOT ALLOW CERTAIN LIMITATIONS OF LIABILITY SO SOME OR ALL OF THE ABOVE LIMITATIONS OF LIABILITY MAY NOT APPLY TO YOU.
9. Term and Termination
9.1 Term
This EULA shall continue in full force and effect during the Term unless earlier terminated in accordance with this EULA, the Customer Agreement or the applicable Order.
9.2 Termination
This EULA terminates automatically upon the earlier of: (a) termination or expiration of the Term; or (b) deprovisioning of your Authorized User status. Notwithstanding anything contained in this EULA, if you are using Free Sprocket Services, Sprocket Security reserves the right, without notice and in Sprocket Security’s sole discretion, to terminate access to or use of such Free Sprocket Services at any time and for any or no reason, and you acknowledge and agree that in such event, Sprocket Security shall have no liability or obligation to you.
9.3 Effect of Termination
Except as otherwise expressly provided herein, upon any expiration or termination of this EULA, all rights, licenses and obligations of the Parties shall immediately cease and terminate. Upon termination, you must stop using the Sprocket Security Services, cease all testing activities, and destroy or return Sprocket Security Confidential Information. Termination or expiration of this EULA will not relieve or release either Party from any liability which, at the date of termination, has already accrued to the other Party.
Notwithstanding anything to the contrary in the foregoing, the provisions of this Section 9.3 and of Sections 1.1–9, shall survive the termination or expiration of this EULA in accordance with their terms.
10. Privacy Policy
Sprocket Security’s handling of personal data relating to End Users in Sprocket Security’s capacity as an independent controller (including account, usage, telemetry, device, and support information) is described in Sprocket Security’s Privacy Policy, as updated from time to time. By using the Service, you acknowledge the Sprocket Security’s Privacy Policy.
11. General
11.1 Governing Law
This EULA is governed by and construed in accordance with the internal laws of the State of Delaware without giving effect to any choice or conflict of law provision or rule. Any legal suit, action, or proceeding arising out of or related to this EULA, the Sprocket Security Services, or the Sprocket Security Platform shall be instituted exclusively in the federal courts of the United States or the courts of Madison, Wisconsin. You hereby waive any and all objections to the exercise of jurisdiction over you by such courts and to venue in such courts. YOU ACKNOWLEDGE AND AGREE THAT ANY CONTROVERSY WHICH MAY ARISE UNDER THIS EULA IS LIKELY TO INVOLVE COMPLICATED AND DIFFICULT ISSUES AND, THEREFORE, YOU HEREBY IRREVOCABLY AND UNCONDITIONALLY WAIVE ANY RIGHT THAT YOU MAY HAVE TO A TRIAL BY JURY IN RESPECT OF ANY LITIGATION DIRECTLY OR INDIRECTLY ARISING OUT OF OR RELATING TO THIS EULA OR THE TRANSACTIONS CONTEMPLATED HEREBY.
11.2 Modifications to this EULA
Sprocket Security may modify this EULA from time to time. Sprocket Security will notify Customer or provide notice through Sprocket Security Platform or by other reasonable means. The updated EULA is effective on the date posted or the stated effective date. Your continued use of the Sprocket Security Platform and Sprocket Security Services after the effective date constitutes acceptance. If you do not agree to the updated terms, you must stop using the Sprocket Security Services.
11.3 Assignment
End User shall not assign this EULA or any of its rights or obligations under this EULA without the prior written consent of Sprocket Security. Sprocket Security shall have the right to freely assign this EULA. Any purported assignment, delegation, or transfer in violation of this Section 11.3 is void. This EULA is binding upon and inures to the benefit of the parties hereto and their respective successors and permitted assigns.
11.4 Force Majeure
You acknowledge that Sprocket Security relies on third-party providers in the delivery of Sprocket Security Services and the Sprocket Security Platform and the content provided in connection therewith, including, without limitation, wireless data network providers, and that Internet service is subject to transmissions limitations and dropped or interrupted transmissions. Internet may be temporarily refused, limited, interrupted, or curtailed because of government regulations or orders, atmospheric and/or topographical conditions, and Internet system modifications, repairs, and upgrades. Sprocket Security will not be liable for any delay or failure to perform due to events beyond its reasonable control, including acts of God, natural disasters, war, terrorism, labor disputes, governmental actions, utility or telecommunications failures, or Internet or hosting provider outages.
11.5 Notices
Sprocket Security may send you service announcements, administrative messages, and other information related to your use of the Sprocket Security Services via in-product notifications or email. Legal notices to Sprocket Security must be sent to the contact specified in the Customer Agreement. You agree to receive electronic communications related to the Sprocket Security Services.
11.6 Severability
If any term or provision of this EULA is invalid, illegal, or unenforceable in any jurisdiction, such invalidity, illegality, or unenforceability shall not affect any other term or provision of this EULA or invalidate or render unenforceable such term or provision in any other jurisdiction. Upon such determination that any term or other provision is invalid, illegal, or unenforceable, the parties hereto shall negotiate in good faith to modify this EULA so as to effect the original intent of the parties as closely as possible in a mutually acceptable manner in order that the transactions contemplated hereby be consummated as originally contemplated to the greatest extent possible.
11.7 Headings
The headings used in this EULA are for convenience only and shall not be considered part of this EULA.
11.8 Entire Agreement
This EULA constitutes the entire agreement between you and Sprocket Security regarding your end-user obligations for the Sprocket Security Services and supersedes all prior or contemporaneous understandings on that subject. If there are any terms and conditions in an Order or the Terms of Service that conflict with this EULA, then this EULA controls unless Sprocket and the Customer have agreed in writing that the terms in the Order control with respect to the Sprocket Security Services described in such Order. No waiver is effective unless in writing and signed by the waiving party.
The Customer Agreement governs as between Sprocket Security and Customer and takes precedence over this EULA in the event of a conflict regarding the Sprocket Security Services.
Last updated: May 12, 2026