Subject to the Platform and Support Agreement, the terms and conditions in this product schedule (“Product Schedule”) apply to the ReliaQuest Products identified in the applicable Order between ReliaQuest and Customer (or as otherwise made available to Customer by ReliaQuest via GreyMatter, as described below). Capitalized terms used in this Product Schedule and not otherwise defined herein will have the meaning given to such terms in the Ongoing Enablement description or the Platform and Support Agreement (or other duly-executed definitive agreement between ReliaQuest and Customer), respectively.
1. GreyMatter.
The Specifications for GreyMatter are set forth in this Product Schedule as follows:
1.1. GreyMatter Detect is the component of GreyMatter that supports the management of ReliaQuest Labeled Content authored by ReliaQuest and various technology vendors, with visibility into detection logic, deployment status, and validation. ReliaQuest uses GreyMatter Detect to deploy ReliaQuest Labeled Content across Customer’s environment connecting through a Storage Technology, a Source, or an eligible GreyMatter Integration, as applicable. The validation sub-component of GreyMatter Detect is subject to the same warning and disclaimer applicable to GreyMatter Investigate and GreyMatter Verify.
1.2. GreyMatter Health is the component of GreyMatter that supports monitoring of Customer’s Storage Technology or eligible GreyMatter Integration, as applicable.
1.3. GreyMatter Hunt is the component of GreyMatter that supports threat hunting potentially leveraging data from Customer’s Source or eligible GreyMatter Integration, as applicable.
1.4. GreyMatter Intel is the component of GreyMatter that supports threat intelligence automation, aggregation, normalization, and dissemination of machine-readable threat intelligence. GreyMatter Intel is subject to the same warning and disclaimer applicable to GreyMatter Digital Risk Protection.
1.5. GreyMatter Investigate is the Automated component of GreyMatter that supports the triage and analysis of ReliaQuest Labeled Content. GreyMatter Investigate is intended to enhance Customer’s then-existing ability to triage and analyze potential security incidents impacting Customer’s networks or systems within the scope of the applicable Order based on ReliaQuest Labeled Content. However, the GreyMatter Investigate Automated analysis relies upon, among several variables, the quality and scope of available Customer Data and the history and trends of activity involving Customer’s networks or systems. As a result, GreyMatter Investigate is a Service Tool and may produce a report, verdict, or determination with respect to potential security incidents that is incorrect or incomplete (including a failure to detect or escalate) or that requires manual validation or further investigation. Customer should not rely upon GreyMatter Investigate as a substitute for Customer’s own judgment, responsibility, or expertise on all matters impacting Customer’s networks or systems, and ReliaQuest shall have no liability or responsibility for any report, verdict, or determination produced by GreyMatter Investigate, including a false positive or false negative designation.
1.6. GreyMatter Respond is the Automated component of GreyMatter that integrates with Customer’s Direct Sources or eligible GreyMatter Integration, as applicable, to enrich, contain, or remediate threats using configured plays, playbooks, and workflows. GreyMatter Respond may allow for Automated remediation of threats or other actions involving Direct Sources or eligible GreyMatter Integration, as applicable. GreyMatter Respond is a Service Tool, and there is an inherent risk in activating Automated features of GreyMatter that such features may take actions not initially intended or foreseen or may not take correct or complete actions. As a result, Customer should not use GreyMatter Respond in a hazardous environment or in connection with other technologies or applications in which unintended or unforeseen Automated action could cause personal injury or property damage.
1.7. GreyMatter Agent is a Service Tool component of GreyMatter that enables connectivity between GreyMatter and Customer’s Direct Sources or eligible GreyMatter Integration, as applicable.
1.8. GreyMatter Assets is the component of GreyMatter that generates an inventory of Customer’s users, devices, and/or endpoints, based on information collected from Customer’s Sources or eligible GreyMatter Integration, as applicable, to enhance detections, automations, investigations, and Reporting. Users, devices, and/or endpoints not identified by way of Customer’s Sources or eligible GreyMatter Integration, as applicable, are not monitored by GreyMatter Assets, which can impact the operation or functionality of other GreyMatter components, such as GreyMatter Respond. ReliaQuest is not responsible for any users, devices, and/or endpoints not identified by way of or otherwise visible through Customer’s Sources or eligible GreyMatter Integration, as applicable.
1.9. GreyMatter Case Management is the component of GreyMatter that allows Customer to track, organize, and resolve security operations issues, requests, or other projects.
1.10. Reporting means any tangible or intangible report provided by ReliaQuest to Customer with respect to GreyMatter or the Ongoing Enablement provided by ReliaQuest, including any report provided by ReliaQuest utilizing ReliaQuest’s proprietary model index reporting capabilities.
1.11. Security Tool Content means the methodology, design, logic, and construction (including all code and scripts) of ReliaQuest Labeled Content (excluding Vendor Authored Detections) designed to detect, correlate, and flag actionable activity.
1.12. GreyMatter Chat is the Automated component of GreyMatter that allows Customer to submit natural language queries and instructions to other eligible components of GreyMatter. GreyMatter Chat relies upon, among several variables, the quality and scope of available Customer Data and the history and trends of activity involving Customer’s networks or systems, and, due to the probabilistic nature of Automated systems, the GreyMatter Chat outputs may be incomplete or contain errors or omissions. As a result, GreyMatter Chat is a Service Tool and may produce output with respect to Customer Data and the circumstances involving Customer’s networks or systems that is incorrect or incomplete (including a failure to identify relevant information or limitations) or that requires manual validation or further investigation, and Customer should not rely upon GreyMatter Chat as a substitute for Customer’s own judgment, responsibility, or expertise on all matters impacting Customer’s networks or systems. ReliaQuest shall have no liability or responsibility for any outputs produced by GreyMatter Chat.
2. Add-On Products.
To the extent that one or more of the following Add-On Products are specifically identified in an Order, the Specifications for the applicable Add-On Products are set forth below. ReliaQuest, in its sole discretion, may make Add-On Products available to Customer via GreyMatter without a separate Order specifically identifying the applicable Add-On Products. Add-On Products are not available to customers accessing or using GreyMatter for Government, unless otherwise expressly stated in an applicable Order for GreyMatter for Government.
2.1. GreyMatter Digital Risk Protection is a sub-component of GreyMatter Intel that supports the detection or identification of data loss or brand impersonation and the monitoring of Customer’s web and digital attack surface. GreyMatter Digital Risk Protection may reveal information obtained from third parties or publicly available sources, including dark-web search results, possible data leaks (and their contents) and other objectionable or disreputable information. GreyMatter Digital Risk Protection may support accessing or using third-party websites or content (including external hyperlinks, web forums, dark-web search results, defined files, file hashes, commands, digital artifacts, and other threat intelligence information and materials). The websites and content are obtained from a variety of sources, which may include known threat actors, and ReliaQuest does not produce or control such websites or content. The websites or content may be subject to third-party intellectual property, privacy, publicity, or other proprietary rights and may contain or consist of defamatory, obscene, abusive, malicious (such as viruses, malware, ransomware, or other Malicious Code), potentially harmful, or otherwise objectionable content. The websites and content are provided “AS-IS,” “AS AVAILABLE,” with “ALL FAULTS,” and otherwise subject to the disclaimer of warranties in the Agreement. ReliaQuest has no support obligations with respect to the websites or content and does not commit to the ongoing availability of such websites or content. Any access or use of the websites or content may be subject to additional terms of use, privacy notices, and other licenses or restrictions. If Customer accesses or uses the websites or content, or their sources, Customer does so at its own risk and assumes all risk associated with such access and use. ReliaQuest does not endorse, is not responsible for, and shall not be liable for the behavior or features of the websites or content, any harm or damages caused by such websites or content, or any reliance placed on the completeness, accuracy, or veracity of such websites or content.
2.2. GreyMatter Verify is the component of GreyMatter that allows Customer to test the effectiveness of Customer’s cybersecurity tools and content by simulating malicious and/or anomalous activity within Customer’s digital environment. GreyMatter Verify may cause Customer’s cybersecurity tools and content to interpret simulated activity as a legitimate threat or malicious activity, which may cause such tools or content to respond with automated actions with respect to Customer’s systems and network. As a result, ReliaQuest specifically disclaims any and all liability to Customer with respect to any simulated attack or any other action taken through GreyMatter Verify, including, but not limited to, any damages, losses, or expenses of any kind related to system downtime, damage, data corruption, or data loss, except to the extent resulting from ReliaQuest’s gross negligence or intentional misconduct.
2.3. GreyMatter Phishing Analyzer is a Service Tool that ReliaQuest may leverage to investigate user-reported emails to identify malicious email threats and campaigns attempting to infiltrate an organization.
2.4. GreyMatter Discover is a component of GreyMatter that leverages the GreyMatter Assets inventory and other GreyMatter information to help Customer to identify and mitigate potential exposures within Customer’s environment. Exposure assessments prepared by GreyMatter Discover are based on the information in scope of the applicable Order, do not identify all potential exposures, and are not a guarantee or prediction of any harm or of the probability of harm.
2.5. Managed Takedown Services are the end-to-end management of takedown requests across the available risk categories, including identification of targets, preparation and filing of takedown request forms, status monitoring and management of the removal or blocking action, and confirmation of takedown. Examples may include cease and desist requests, including DMCA takedown requests; ISP/host-level content suspension; registrar-level domain suspension; registry-level domain suspension; and/or domain takedown.
2.5.1. Customer shall promptly provide to ReliaQuest the following information and documents required for Managed Takedown Services: (a) reasonably required letter of authorization to ReliaQuest, its agents or its third-party supplier to pursue enforcement (a sample of which will be provided upon request); and (b) registration details for user accounts of websites/platforms and any other information or documents reasonably requested by ReliaQuest.
2.5.2. ReliaQuest reserves the right to suspend or not perform the Managed Takedown Services if it believes: (i) Customer has not provided sufficient, accurate or complete information to initiate or continue with the Managed Takedown Services; (ii) any Managed Takedown Services may result in any adverse action from a third party; (iii) the desired result of the Managed Takedown Services is unlikely to be achieved through reasonable efforts; or (iv) ReliaQuest or its suppliers are or may be legally restricted or prevented from providing the Managed Takedown Services.
2.5.3. Customer agrees that (a) infringing websites specified by Customer that are to be the subject of Managed Takedown Services are under third-party control and those third parties may resist any part of the Managed Takedown Services; (b) due to the international nature of the internet and the political, legal and/or language issues, ReliaQuest may be prevented from successfully performing in whole or in part the Managed Takedown Services; and (c) the Managed Takedown Services may not achieve the desired result.
2.5.4. ReliaQuest will commence specified actions for a Takedown Request after the Managed Takedown Services have been provisioned, activated and a takedown candidate has been identified. In each instance, upon receipt from Customer of one of the following: (i) an authorization action taken by Customer’s authorized web portal user to initiate the takedown process (“Takedown Request”); or (ii) confirmation from Customer authorizing ReliaQuest or its suppliers to commence action against a takedown candidate; or (iii) written confirmation authorizing ReliaQuest or its suppliers to proceed with the Managed Takedown Services using a commercially reasonable form approved by ReliaQuest.
2.5.5. Customer shall indemnify ReliaQuest and keep it indemnified for all costs, expenses, liabilities, losses, damages, claims, demands, proceedings, judgments and reasonable legal costs which ReliaQuest incurs or suffers in respect of any claim brought or threatened against ReliaQuest or its suppliers or sub-contractors by any third party, during or after the end of the term of the Agreement and arising out of or in connection with Customer’s actions in fulfilling the Managed Takedown Services in accordance with this Agreement.
2.5.6. Notwithstanding anything to the contrary in the Agreement, ReliaQuest shall be entitled to subcontract the performance of the Managed Takedown Services to any reasonable third-party subcontractor selected by ReliaQuest that performs such managed takedown services. FraudWatch International PTY Ltd. is the current vendor used by ReliaQuest to perform such Managed Takedown Services, but this may change from time to time.
2.6. GreyMatter Agentic Teammates are role-based Automated components of GreyMatter designed to augment specific security operations center functions by providing Automated analysis and context recommendations and to support and extend the existing capacities of human security operators to monitor, investigate, and respond to security events. The output provided by GreyMatter Agentic Teammates relies upon, among several variables, the information input or prompted by Customer, the quality and scope of available Customer Data, and the history and trends of activity involving Customer’s networks or systems. As a result, GreyMatter Agentic Teammates is not an agent of ReliaQuest, is a Service Tool, and may produce output that is incorrect or incomplete (including a failure to detect or escalate security-relevant alerts or other information) or that requires manual validation or further investigation. Due to the probabilistic nature of GreyMatter Agentic Teammates, the output may be incomplete or contain errors or omissions, Customer should not rely upon GreyMatter Agentic Teammates as a substitute for Customer’s own judgment, responsibility, or expertise on all matters impacting Customer’s networks or systems, and ReliaQuest shall have no liability or responsibility for any outputs produced by GreyMatter Agentic Teammates.
2.7. GreyMatter Transit is the component of GreyMatter that collects security telemetry from Supported Sources or supported Log Source Technologies, as applicable, applies security detection logic to the security telemetry in transit, and allows Customer to filter and route security telemetry to supported Storage Technologies. For further clarity, neither GreyMatter nor GreyMatter Transit includes any data back-up services, and ReliaQuest will not be responsible for loss or alteration of any Customer Data.
2.8. GreyMatter SIEM-Less is the indexing and querying component of GreyMatter that enables search, investigation, threat hunting, and reporting against data stored in Customer-owned Storage Technologies, without requiring a SIEM.
2.9. GreyMatter Attack is a Service Tool within GreyMatter that maps potential attack paths in, and executes offensive techniques against, the systems, accounts, identities, applications, and endpoints Customer designates as the target of an attack campaign (“Attack Scope”) to validate whether a mapped path is exploitable (each, an “Attack Execution”).
2.9.1. Customer’s launch of an Attack Execution, or request that ReliaQuest launch an Attack Execution on Customer’s behalf, constitutes Customer’s authorization of the resulting Attack Scope and Attack Execution, and the campaign record generated in GreyMatter is the authoritative record of the Attack Scope and configuration Customer authorized. Customer is solely responsible for (a) determining the Attack Scope and ensuring its accuracy, (b) preparing and securing the Attack Scope, including maintaining appropriate backups, (c) obtaining all permissions or licenses required by law or by the owner of any asset within the Attack Scope, and (d) using GreyMatter Attack solely to validate and improve the security of Customer’s own environment. Customer will not include within the Attack Scope (1) any asset Customer does not own or control absent the asset owner’s lawful written permission or (2) any asset in or related to the Attack Scope where unintended Automated action could cause personal injury or property damage.
2.9.2. Attack path mapping and Attack Execution may require access to data within the Attack Scope, may cause Customer’s cybersecurity tools and content to treat the activity as a genuine threat and respond with automated actions, and may result in unintended disruption, downtime, configuration change, data corruption, data loss, or other harmful events. Automated and agentic features may also take actions not intended or foreseen or fail to act correctly or completely. GreyMatter Attack is not a penetration test, audit, or certification of security or compliance. Because Automated systems are probabilistic, GreyMatter Attack may be incomplete or contain errors or omissions and may not identify all attack paths, exposures, or vulnerabilities. Customer will not rely on GreyMatter Attack as a substitute for Customer’s own judgment, responsibility, or expertise on matters affecting its networks and systems, and ReliaQuest is not responsible for any GreyMatter Attack output or for any investigation, response, or notification undertaken in reaction to activity generated by GreyMatter Attack. Customer accepts these risks and is solely responsible for the resulting impacts to Customer and any third party. ReliaQuest specifically disclaims any and all liability caused by attack path mapping or Attack Execution (including, but not limited to, any damages, losses, or expenses of any kind related to disruption, downtime, configuration change, data corruption, data loss, or other harmful events), except to the extent resulting from ReliaQuest’s gross negligence or intentional misconduct.