1. Agreement
These Terms of Service (“Terms”) govern access to and use of Moduvia, a product of Cynest, Inc. (“Cynest”, “we”, “us”).
If you buy Moduvia under an order form, statement of work, or other signed agreement, that document controls where it conflicts with these Terms. For the public website alone, browsing means you agree to the site-related parts of these Terms and our Privacy Policy.
Plain version: Contracts beat this page. This page fills gaps and covers the website.
2. Definitions
- Customer — the organization that orders Moduvia or related services.
- Services — Cynest-managed Moduvia SaaS, support, and related hosted features.
- Software — Moduvia software delivered for on-prem or air-gapped installation, including updates Cynest provides under your agreement.
- Modules — named Moduvia components (for example Privara, Deployr, Tracepoint, Grid, Guardrail, Percept).
- Customer Data — data, content, and configurations you or your users submit to or generate in Moduvia.
3. The Moduvia suite
Moduvia is modular. You license the modules listed on your order—not every module by default.
- Privara — Private AI
- Deployr — DevOps pipeline
- Tracepoint — Observability
- Grid — Kubernetes
- Guardrail — Security and compliance
- Percept — Intelligent surveillance (may be preview or coming soon)
Preview or “coming soon” modules may change, pause, or never GA. Don’t build production dependency on a preview without written confirmation.
4. Delivery models
Enterprise SaaS (Cynest managed)
Cynest hosts and operates the control plane. You get a non-exclusive, non-transferable right to use the Services during the subscription term for your internal business purposes, within the usage limits on your order.
Air-gap / on-prem (Cynest hardware or approved environment)
Cynest licenses the Software for installation in the environment described in your order—often disconnected or restricted networks. Hardware, if supplied by Cynest, remains subject to the hardware terms or lease/sale schedule in that order. You are responsible for physical security, facility access, and operating the install per documentation unless Cynest is contracted to operate it.
Consulting
Design, integration, and deployment help are sold under a statement of work. Deliverables, assumptions, and acceptance criteria live there—not in marketing pages.
5. Accounts and access
Keep credentials confidential. You’re responsible for activity under your accounts. Use SSO/MFA where we offer it—especially for production.
Admin users must make sure only authorized people get access, and that access matches least-privilege needs for your program.
6. Acceptable use
Don’t:
- Probe, scan, or attack the Services except under a written authorization for testing
- Circumvent technical controls, licensing, or usage meters
- Resell or white-label Moduvia without Cynest’s written consent
- Use Moduvia to violate law, export controls, or sanctions
- Upload malware or content you have no right to process
- Interfere with other customers on shared SaaS infrastructure
We may suspend access for material risk to the platform, other customers, or legal compliance—and we’ll notify you when practical.
7. Customer Data
You retain rights in Customer Data. You grant Cynest a limited license to host, copy, process, and display Customer Data only as needed to provide the Services, support, and consulting you ordered—and as described in the Privacy Policy and any DPA.
On air-gapped systems, Cynest does not receive Customer Data unless you transmit it for support or professional services.
You’re responsible for having the rights and notices required to process Customer Data in Moduvia—including classified, CUI, or regulated datasets under your AO’s rules.
8. Intellectual property
Cynest and its licensors own Moduvia, the documentation, brands, and underlying IP. These Terms don’t transfer ownership to you.
Feedback you give us may be used to improve Moduvia without obligation to you. Don’t submit feedback you don’t want used that way.
9. Compliance and security
Cynest designs Moduvia toward FedRAMP paths, CMMC 2.0, NIST SP 800-171, and DoD IL5/IL6 readiness, and supports FIPS-validated cryptography and Zero Trust controls on supported modes.
That is not a warranty that a specific authorization, certification, or Impact Level accreditation is already granted for your tenant or site. Authorizations depend on the deployment model, shared responsibility, and your authorizing official. What’s committed for your order is what your contract and ATO package say.
You must configure and operate your side of the shared responsibility model—identity, data classification, and enclave procedures included.
10. Fees
Fees, currency, and payment terms are on your order. Overdue amounts may suspend Services after notice. Taxes are extra unless stated otherwise.
Public web pages don’t list prices. That’s intentional.
11. Warranties and disclaimers
Cynest warrants it will provide SaaS and Software in material conformance with documentation during the paid term, under the support policy in your order.
Except as expressly stated in a signed agreement, Moduvia is provided “as is.” We disclaim implied warranties of merchantability, fitness for a particular purpose, and non-infringement to the fullest extent allowed by law.
We don’t warrant uninterrupted or error-free operation—especially across customer-controlled air-gap networks we don’t operate.
12. Liability
To the fullest extent permitted by law, neither party is liable for indirect, incidental, special, consequential, or punitive damages, or lost profits, revenue, or data, even if advised of the possibility.
Each party’s aggregate liability under these Terms is limited to the amounts paid or payable by Customer to Cynest for the Moduvia offerings giving rise to the claim during the twelve (12) months before the event—unless your signed agreement sets a different cap.
These limits don’t apply to fraud, willful misconduct, or liabilities that can’t be limited under applicable law.
13. Term and termination
Subscriptions run for the term on your order and renew as stated there. Either party may terminate for material breach not cured within thirty (30) days after written notice (or sooner if the breach can’t reasonably be cured).
On termination of SaaS, we’ll make Customer Data export available for a limited window if your order requires it—then delete remaining copies from Cynest-managed systems per the retention schedule, except backups that expire in ordinary course or records we must keep by law.
14. Government and defense customers
If you are a U.S. government entity or prime/sub on a government contract, additional terms in your order or rider apply (flow-downs, security plans, data handling). Commercial Terms fill gaps only where those instruments are silent.
Export laws apply. You won’t use or export Moduvia contrary to U.S. export control or sanctions rules.
15. General
- Governing law — Laws of the State specified in your order (or Delaware, USA, if none), excluding conflict-of-law rules, unless mandatory local law says otherwise for public-sector buyers.
- Notices — In writing to the addresses on your order, or by email with delivery confirmation where allowed.
- Assignment — You need Cynest’s consent to assign, except to an affiliate or successor in a merger; Cynest may assign to an affiliate or successor.
- Entire agreement — Order + these Terms + Privacy Policy + DPA/SOW (as applicable) are the full agreement on the subject.
- Severability — If one clause fails, the rest stay in force.
16. Contact
Contract or legal notices for Moduvia:
Cynest, Inc. — Attn: Legal / Moduvia
Or via cynest.com and your account team.