⚠️ DRAFT — NOT YET REVIEWED BY COUNSEL
This document sets liability caps, processor obligations, and termination terms. Do not publish or send to a customer until it has been reviewed by a lawyer. Everything below is a working draft.
VendorScore Terms of Service
Effective date: August 31, 2026
1. Agreement to Terms
These Terms of Service ("Terms") are entered into between Praetorian Secure, LLC, a Michigan limited liability company ("VendorScore," "we," "us"), and the customer entity identified in the applicable order form or account registration ("Customer," "you"). By accessing or using the VendorScore platform (the "Service"), you agree to these Terms on behalf of Customer.
2. Definitions
- "Authorized Users" means Customer's employees and contractors authorized by Customer to access the Service under Customer's account.
- "Vendor Data" means information about Customer's vendors that Customer, its Authorized Users, or vendor personnel submit to the Service, including vendor contact information, assessment responses, contracts, credentials, and supporting documents.
- "Account Data" means information about Customer and its Authorized Users used to operate the Service, such as login credentials, names, and email addresses.
- "Vendor User" means an individual at one of Customer's vendors, invited by Customer, who accesses the Service's vendor portal to respond to assessment requests.
- "Subscription Term" means the period during which Customer has a paid subscription to the Service, as set out in the applicable order form.
3. The Service
VendorScore is a vendor risk management platform. Each Customer's data is logically isolated within a shared infrastructure — the Service is not deployed as a dedicated instance per Customer, but access to Vendor Data and Account Data is restricted to Customer's own Authorized Users and Vendor Users, enforced at the database layer. See our Security Overview for a description of how this isolation works.
4. Subscription, Fees, and Term
Fees are invoiced monthly in arrears based on metered usage for the preceding billing period. Payment is due Net 30 from the invoice date.
5. Customer Responsibilities
Customer is responsible for:
- The accuracy of information it submits or authorizes to be submitted to the Service, including vendor contact information;
- Maintaining the confidentiality of its Authorized Users' login credentials;
- Ensuring its Authorized Users comply with these Terms and our Acceptable Use Policy; and
- Any vendor it invites to the Service complying with our Acceptable Use Policy while using the vendor portal.
6. Acceptable Use
Use of the Service is subject to our Acceptable Use Policy, which is incorporated into these Terms by reference.
7. Prohibition on Controlled Unclassified Information (CUI)
The Service is designed and operated as a Federal Contract Information (FCI)-capable environment. The Service is not authorized, configured, or intended to receive, store, or process Controlled Unclassified Information (CUI), and Customer agrees not to submit CUI to the Service in any form, and to ensure its Authorized Users and any vendor it invites do not do so either. Our Acceptable Use Policy describes this prohibition and its consequences in more detail, including what VendorScore may do if it becomes aware that CUI has been submitted.
Customer remains solely responsible for classifying its own data correctly and for determining what may and may not be submitted to the Service under this restriction.
8. Data Ownership and VendorScore's Role as Processor
As between Customer and VendorScore, Customer owns and controls all Vendor Data. VendorScore acts as a service provider and processor of Vendor Data, processing it solely to provide the Service in accordance with Customer's instructions (as reflected in Customer's use and configuration of the Service) and this Agreement. VendorScore is not a controller of Vendor Data and does not use Vendor Data for any purpose other than providing, maintaining, and improving the Service, except as described in our Privacy Policy.
Where Vendor Data includes personal information of vendor contacts (such as names and email addresses of a vendor's personnel), Customer represents that it has the right to share that information with VendorScore for the purposes described in these Terms and our Privacy Policy, and that its collection and sharing of that information complies with applicable law.
9. Security
VendorScore maintains administrative, technical, and physical safeguards for the Service as described in our Security Overview, which is incorporated into these Terms by reference. VendorScore may update the specific controls described there from time to time, provided that any change does not materially reduce the overall level of security provided during the Subscription Term.
10. Availability
VendorScore uses commercially reasonable efforts to make the Service available, but does not warrant or guarantee any specific level of uptime and does not currently offer a service level agreement (SLA) or service credits for downtime. The Service currently runs as a single application instance without redundant failover; Customer should plan accordingly for any use case that requires guaranteed availability. We will communicate material, planned changes to this posture as they occur.
11. Data Retention and Deletion
During the Subscription Term, Vendor Data and Account Data are retained for as long as the applicable account or record exists. Authorized Users can delete individual records they have permission to manage (such as a specific contract, credential, or evidence document) directly within the Service; deletion of an individual record is immediate and does not require our involvement.
Full account closure — deletion of Customer's entire organization and all associated Vendor Data — is performed by VendorScore at Customer's request, is permanent, and cannot be undone once completed.
Upon termination or expiration of this Agreement:
- Customer may request an export of its Vendor Data, in a reasonable standard format, by written request made within thirty (30) days following termination. VendorScore will fulfill such a request within thirty (30) days of receiving it.
- If no export request is made within that window, or once any requested export has been provided, VendorScore will delete Customer's Vendor Data and Account Data within thirty (30) days of the later of the termination date or the export, except where retention is required by law or necessary to resolve a dispute between the parties.
12. Fees; Payment
See Section 4 and the applicable order form. Fees are invoiced monthly in arrears based on metered usage for the preceding billing period. Payment is due Net 30 from the invoice date.
13. Warranties and Disclaimers
Each party represents that it has the authority to enter into this Agreement. Except as expressly stated in these Terms, the Service is provided "as is" and "as available," without warranties of any kind, whether express, implied, or statutory, including any implied warranty of merchantability, fitness for a particular purpose, or non-infringement. VendorScore does not warrant that the Service will be uninterrupted, error-free, or completely secure — see Section 9 and Section 10 for what we do commit to.
14. Limitation of Liability
Except for breach of confidentiality obligations, indemnification obligations, willful misconduct, and either party's payment obligations under this Agreement, each party's aggregate liability arising out of or related to this Agreement will not exceed the total fees paid by Customer to Praetorian Secure, LLC in the twelve (12) months immediately preceding the event giving rise to the claim. Neither party will be liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits or lost data, even if advised of the possibility of such damages.
15. Indemnification
(Drafted mutual — confirm before publishing.)
Each party will defend the other against third-party claims arising from (a) that party's breach of this Agreement, or (b) that party's gross negligence or willful misconduct, and will indemnify the other party against damages finally awarded as a result, subject to Section 14.
16. Confidentiality
Each party may have access to the other's confidential information in connection with this Agreement. Each party agrees to protect the other's confidential information with the same degree of care it uses for its own confidential information of similar nature, and not less than reasonable care, and to use it solely to perform its obligations under this Agreement.
17. Government Contracting Context
The Service is built with awareness of the compliance obligations customers in the federal contracting space operate under, including FAR 52.204-21 and related frameworks. Nothing in these Terms or in the Service constitutes legal or compliance advice, and use of the Service does not by itself satisfy any regulatory or contractual obligation Customer may have. Customer remains solely responsible for its own compliance obligations, including its determinations about CUI, FCI, and its vendors' risk posture.
18. Term and Termination
This Agreement remains in effect for the Subscription Term and any renewal term. Either party may terminate for the other's uncured material breach on thirty (30) days written notice. Sections that by their nature should survive termination (including Sections 8, 11, 13, 14, 15, and 16) will survive.
19. Governing Law; Dispute Resolution
This Agreement is governed by the laws of the State of Michigan, without regard to its conflict of laws principles, with exclusive venue in the state and federal courts located in Genesee County, Michigan. The parties will first attempt to resolve any dispute through good-faith negotiation for a period of thirty (30) days. If unresolved, the dispute will be brought exclusively in the courts identified in the governing law and venue provision.
20. General Provisions
- Assignment. Neither party may assign this Agreement without the other's consent, except in connection with a merger, acquisition, or sale of substantially all assets.
- Force Majeure. Neither party is liable for delay or failure to perform due to causes beyond its reasonable control.
- Changes to These Terms. We may update these Terms from time to time. We will provide notice of material changes to Customer's designated administrator before they take effect.
- Entire Agreement. These Terms, together with the Acceptable Use Policy, Privacy Policy, and any applicable order form, constitute the entire agreement between the parties regarding the Service.
21. Notices
Legal notices to VendorScore should be sent to:
Praetorian Secure, LLC 3072 N Irish Rd, Davison, MI 48423 info@praetoriansecure.com