📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Legal

Terms of Service

These terms govern your access to and use of Lavawall® software and services, operated by ThreeShield Information Security Corporation, a Canadian federal corporation located in Calgary, Alberta.

Effective date: July 28, 2026 · Supersedes the version effective July 18, 2026

We like to keep things simple, but some things need to be written by lawyers. The headings below are for ease of reference and do not change the meaning of the terms.

The short version

You own your data and can export it at any time. We host it in Canada. We do not sell it, use it for advertising, or train AI models on it. You can cancel any time. We do not read your files or email for our own purposes, but the modules you turn on do process file and email metadata, and limited message content where a feature needs it — for breach and unusual-activity detection, SaaS discovery, phishing and email-security checks, backups and exports you request, and the built-in CRM and helpdesk — and only to do the job you enabled them for.

What we cannot do is guarantee that your systems will never be compromised, or accept the financial consequences if they are — that risk stays with you, because you control your environment and we do not. We are also not responsible for products you did not buy from us, or for backups you did not make or test. Section 19 says so plainly rather than burying it.

1. Parties and agreement

  1. This agreement (the "Agreement") is made between ThreeShield Information Security Corporation ("ThreeShield"), a Canadian federal corporation located in Calgary, Alberta, and you (the "Client").
  2. By adding a payment card, logging into the Lavawall® service, deploying a Lavawall® agent, or otherwise using Lavawall®, the Client agrees to be bound by this Agreement.
  3. Where the Client is an organization, the individual accepting this Agreement warrants that they have authority to bind that organization.

2. Description of services

  1. Lavawall® is a Software-as-a-Service security platform. It is modular and includes external network, domain, email and web scanning, together with information about the security and reliability of Windows, Linux and Mac computers. Depending on the modules the Client enables, Lavawall® may also provide governance, risk and compliance capabilities, compliance automation, breach detection, monitoring, backup, remote support, remote desktop, patch management, authentication monitoring, phishing reporting and analysis, training, and analytics.
  2. Together these tools provide an automated audit of the security of a computer system to identify possible configuration errors and vulnerability to attacks such as computer viruses and unwanted information gathering (the "Vulnerability Assessment"). In this Agreement, "Vulnerability Assessment" refers collectively to the Lavawall® services and modules made available to the Client.
  3. The "Computer System" means the systems to be assessed, comprising those with Internet Protocol addresses and domains specified within Lavawall® and those computers running the Windows, Linux or Mac Lavawall® software.
  4. As part of the Vulnerability Assessment, ThreeShield may use and access proprietary scripts and commands, and may use third-party integrated vulnerability scanners.
  5. Professional services are separate. Lavawall® is a platform. Any professional, advisory, managed or remediation services associated with it are provided by ThreeShield under a separate written agreement and are not included in these terms. Access to Lavawall® does not entitle the Client to analyst time, monitoring by ThreeShield personnel, incident response, or remediation work, and no service level applies other than the availability commitment in section 9.

3. Relationship to other agreements

  1. Where ThreeShield and the Client have signed a separate services agreement, managed services agreement or statement of work that covers Lavawall®, that document prevails over these terms to the extent of any conflict.
  2. Where the Client is a custodian, trustee or equivalent under health privacy legislation and has signed an information manager agreement, data processing agreement or similar instrument with ThreeShield, that instrument prevails over these terms to the extent of any conflict.
  3. Otherwise, these terms govern.

4. Scope limitations

  1. Information security depends on a combination of external and internal controls. An assessment cannot fully expose vulnerabilities that could be exploited by malware or through access gained in a likely attack scenario, including phishing, malware, damaged hardware, password weaknesses, or vulnerable third-party applications.
  2. ThreeShield does not and cannot guarantee that it will discover every vulnerability present at the time of an assessment, or that no further vulnerability will arise afterwards. New installations, configuration changes and new software may cause or reveal further vulnerabilities.

5. Role of the Client

  1. Deployment is the Client's. The Client is responsible for installing and maintaining the Lavawall® agent software on the devices it wishes assessed, using its own software distribution or remote management tooling and its own change windows. ThreeShield provides the installer, deployment packages, configuration guidance and documentation, verifies coverage, and reports which devices are missing an agent.
  2. The Client will provide ThreeShield with the access necessary to deliver the service. Although ThreeShield has endeavoured to ensure compatibility with most security software, the Client may need to change firewall, antivirus and other system settings to allow Lavawall® to access and assess the Computer System.
  3. The Client will back up its data and maintain a copy of it.
  4. The Client will not report scanning activity originating from ThreeShield's disclosed scanning addresses to an authority or service provider as an attack. On request, ThreeShield will provide the addresses used so the Client can identify that traffic. This does not limit any obligation the Client has to report an actual or suspected privacy breach to a regulator or to affected individuals, and does not limit the Client's discretion to make any report it considers appropriate.
  5. The Client will make reasonable allowance for the possibility that scanning and assessment may temporarily affect the availability of the Computer System.
  6. The Client will not use Lavawall® to scan or assess a system it does not own or have written authority to assess, will not resell or provide access to Lavawall® to a third party except as section 22 permits, and will not reverse engineer, decompile or attempt to derive the source code of Lavawall®.
  7. Customer lists. By entering into a paid Lavawall® subscription the Client grants ThreeShield permission to identify it as a customer, and to use its name, logo and trade marks for that purpose, in ThreeShield's customer lists, website and marketing material. The Client may withdraw that permission at any time by notice through the contact form, and ThreeShield will stop making new use of the Client's name, logo and trade marks within thirty (30) days of receiving it. Withdrawal operates prospectively only: ThreeShield is not required to recall, destroy, reprint or amend any material produced, printed, published, distributed or supplied to a third party before the withdrawal took effect, and is not required to remove the Client's name from archived, historical or cached material, or from material outside its control. The Client warrants that it owns, or has the owner's permission to grant ThreeShield the use of, any name, logo or trade mark it makes available.

6. Payment

  1. The Client shall pay ThreeShield the amount indicated in the Current Investment section of the Lavawall® billing page, in Canadian currency plus the applicable Goods and Services Tax. These amounts are due and payable in advance. Current plans and rates are published on the pricing page.
  2. Seats. Except for the free plan, Lavawall® is charged per Seat. A Seat is the greater of the number of the Client's assessed devices or the number of its licensed Microsoft 365 or Google Workspace users, and is not the sum of the two. A person who uses more than one device is one Seat, and a device shared by more than one person is one Seat. There is no separate per-user charge.
  3. How the count is measured. Charges for a billing period are calculated on the highest number of Seats, domains and integrations in use at any point during that period. The count is measured afresh each period, so a reduction takes effect automatically in the following period without the Client having to ask. ThreeShield does not carry a high-water mark from one period into the next.
  4. Monthly plans. Where the Client pays monthly, the charge for each month is the amount payable on the highest count reached during that month at the rates then published.
  5. Annual plans. Where the Client pays annually, the amount paid establishes the Client's Annual Entitlement — the number of Seats, domains and integrations covered for the whole of the annual term at no further charge. Usage up to the Annual Entitlement is not charged again at any point during the term, however it fluctuates. Where usage in a monthly period exceeds the Annual Entitlement, ThreeShield charges for the excess only, calculated on the highest count reached during that monthly period at the rates then published, and that excess charge falls away automatically in the next monthly period in which usage returns to or below the Annual Entitlement. The Client is not required to give notice, and no adjustment is applied to the Annual Entitlement itself during the term.
  6. No credit for reductions. Usage below the Annual Entitlement does not generate a credit, refund, rebate or carry-forward of any kind, whether during the term or on renewal. The Annual Entitlement is what the Client has purchased, and the discount for paying annually is granted on that basis.
  7. Renewal. An annual plan renews for a further annual term at the number of Seats, domains and integrations in use at the start of that new term, at the rates then published. ThreeShield will notify the Client of the renewal quantity and amount before the renewal date, and the Client may change the quantity or cancel before the renewal takes effect.
  8. If the Client does not select a Lavawall® plan before adding a payment card, the "Minimal Pay-as-you-go" plan applies by default. That plan has no minimum or base cost and bills on usage only.
  9. Managed-service rate. Where ThreeShield provides a managed service that includes operating the Lavawall® console on the Client's behalf, Lavawall® is licensed at the discounted rate stated in that services agreement rather than at the published self-service rate. If the managed service ends and the Client wishes to retain Lavawall® on a self-service basis, the published rates apply from the date the managed service ends, and ThreeShield will give not less than thirty (30) days' notice before the change in rate takes effect.
  10. ThreeShield may change pricing thirty (30) days after sending the Client notice by email. If the Client does not accept a change it may cancel under section 21 before the change takes effect.
  11. The Client shall pay simple interest on overdue amounts at 1.16% per month, being 13.92% per annum, from the date the amount becomes overdue until paid, or the maximum rate permitted by law if lower. For the purposes of the Interest Act, the equivalent annual rate is 13.92%.

7. Client warranties

The Client represents and warrants that:

  1. it has full authority to retain ThreeShield, enter into this Agreement, install Lavawall® agents, scan the selected domains, and carry out the Vulnerability Assessment;
  2. it is the owner of the Computer System or has written permission from the owner to access and use it and to carry out the Vulnerability Assessment;
  3. it has obtained the consent of all third parties as required or necessary, including its service providers;
  4. it has given any notice and obtained any consent required under applicable privacy legislation for ThreeShield to collect and process the categories of information described in section 14; and
  5. it owns, or has written permission from the owner of, any name, logo or trade mark it authorizes ThreeShield to use.

8. ThreeShield warranties

  1. ThreeShield will perform the Vulnerability Assessment in good faith and only for the purpose of assessing the security of the Computer System.
  2. ThreeShield will use Client email addresses, telephone numbers and other contact information for authentication and notification purposes only. ThreeShield will not sell or trade Client email addresses, telephone numbers or postal addresses.
  3. ThreeShield will not access, read or index the content of the Client's documents, files or mailboxes except to the extent a module the Client has enabled requires it in order to function, and then only for the purpose of that module.
  4. ThreeShield has configured each artificial intelligence model it uses, and has contracted with each provider, on the basis that Client data is not used to train any model. ThreeShield does not warrant a provider's compliance with its own contractual terms, and will notify the Client promptly if it becomes aware that a provider has not complied.
  5. Except as expressly stated in this Agreement, Lavawall® is provided on an "as is" basis and ThreeShield makes no other warranty, express or implied, including any implied warranty of merchantability or fitness for a particular purpose.

9. Availability

  1. ThreeShield will use commercially reasonable efforts to make Lavawall® available, and will give reasonable advance notice of planned maintenance where practicable.
  2. Availability is not warranted, and no service credit arises for unavailability. Where Lavawall® is materially unavailable for a sustained period the Client's remedy is to cancel under section 19.

10. Where Client data is stored and processed

  1. Canada by default. Lavawall® data — including security information and event data, log data, Microsoft 365 and Google Workspace data, reported phishing messages, asset and configuration data, tickets, and assessment findings — is stored on servers controlled by ThreeShield or in Amazon Web Services regions in Montréal, Québec and Calgary, Alberta. For clients outside Canada, or on request, this can be stored in other geographies.
  2. Results from third-party integrated vulnerability scanners run for a client under a managed services agreement are stored on ThreeShield computers in Calgary, Alberta.
  3. Communications and notifications. Some notification and communication elements operate outside Canada and carry only what is described here. Amazon Web Services is used for certain text and email communications. Twilio is used for text messages, and Voip.MS is used for telephone and text services; both carry a telephone number and the message or alert text only. Certain authentication verification messages are delivered through a provider hosted in Ireland and carry an email address and an authentication code only, with no report content, ticket content or other Client data. Agent and installer distribution and edge routing use a global content delivery network, which carries executables and traffic in transit but not stored Client data.
  4. What this commitment covers, and what it does not. The processing described in sections 11 and 12, and in subsection 3 above, is disclosed and permitted. Subject to that, ThreeShield will not add a sub-processor that stores, processes or can access Client data outside Canada, and will not extend an existing non-Canadian element to a new category of Client data, without giving the Client notice and, where the Client's own legal obligations require it, obtaining the Client's consent. Substituting or adding a provider within a category and location already disclosed in these terms — for example replacing one supplementary model provider hosted in the United States with another, on the same redaction and tokenization terms — is not the addition of a new sub-processor or the extension to a new category for the purposes of this subsection, and requires only that ThreeShield update the list it maintains. ThreeShield will not send to any model provider a category of data it has not disclosed here.

11. Artificial intelligence and automated analysis

  1. Ticket analysis. Support ticket analysis uses Amazon Web Services models with processing in Canada.
  2. Security incident analysis. Security incident analysis uses Anthropic Claude through Amazon Bedrock, with processing in Canada.
  3. Supplementary models. ThreeShield may use additional models hosted outside Canada, including in the United States, for supplementary analysis. Only redacted, tokenized and anonymized data is sent to those models. Nothing identifying the Client is included, and no support ticket body and no meeting transcript is sent outside Canada by this route.
  4. What is redacted and tokenized. Before any data is sent to a third-party hosted artificial intelligence model for analysis, ThreeShield redacts and/or tokenizes IP addresses, email addresses, usernames, personal names, and information identifying the Client's organization, including its company and domain names. For security incident analysis this applies to IP addresses, email addresses, personal names and company names. For ticket analysis it applies to email addresses and to numbers matching sensitive personal information patterns. Tickets containing medical terms or keywords such as "patient" are blocked and are not submitted for model processing at all.
  5. The residual risk, stated plainly. Tokenization operates on patterns. Free text a person types into a ticket may contain sensitive information that does not match a pattern, and ThreeShield does not warrant that all such text is sanitized. The Client should instruct its people not to put personal information, health information, credentials or other sensitive content into a support request. Where a matter cannot be described without that content, contact ThreeShield by telephone or through the console instead, and it will be handled without model processing.
  6. No model ThreeShield uses is configured to retain Client data for training, and ThreeShield contracts with its providers on that basis, subject to section 8.4.

12. Meeting recording, transcription and Client-side AI

  1. Never silent, and always refusable. ThreeShield does not record or transcribe a meeting or telephone call covertly. Before or at the start of a meeting or call it will either ask the Client whether recording and transcription are acceptable, or join a transcription service as an obvious, clearly named participant visible in the participant list, so that the Client can see it and ask for it to be turned off. Any participant, from either party, may ask for recording or transcription to stop at any time and for any reason, and it will stop.
  2. The Client can switch it off permanently. The Client may direct ThreeShield in writing, at any time, that no meeting or telephone call with it is to be recorded, transcribed or submitted for model processing. ThreeShield will comply with that direction until the Client withdraws it, and the direction may be given for all meetings or for a particular meeting, without a reason and at no cost.
  3. No Canadian option exists today. The transcription and meeting-summarization tooling available to ThreeShield, and the native transcription, recording and assistant features built into Microsoft Teams and Microsoft 365 Copilot, currently process in the United States. Where the Client permits, or does not object to, the use of any of them, the Client accepts that the recording, transcript and summary are processed outside Canada, and the Client remains responsible for any notice or consent its own privacy obligations require.
  4. ThreeShield will use reasonable efforts to stop as soon as it becomes apparent that health information or other sensitive information is being disclosed, whether or not asked. Anything captured before it stopped will be deleted and the deletion recorded.
  5. Liability. Recording, transcription and meeting-summarization tooling, and any native Microsoft Teams or Microsoft 365 Copilot feature, are provided by third parties and are used only at the Client's direction and for the Client's convenience. ThreeShield is not liable for any loss, damage, claim, penalty or breach arising from the use of that tooling, from where it processes or stores data, from the accuracy or inaccuracy of anything it produces, or from a security incident affecting the provider of it. The Client may decline it entirely at no cost and with no effect on any other part of the service, and this subsection is the reason the choice is the Client's.

13. Client data, ownership and export

  1. The Client owns its data. Data the Client provides, and data Lavawall® collects from the Client's environment — including assessment findings, logs, events, asset and configuration records, tickets and documents ("Client Data") — remain the Client's property. ThreeShield acquires no ownership of it.
  2. ThreeShield holds and uses Client Data only to provide and support Lavawall®, to meet its obligations to the Client, and as this Agreement permits.
  3. ThreeShield may use aggregated and de-identified information derived from platform use to operate, secure and improve Lavawall®, provided it does not identify the Client, any individual, or any Client system, and is not sold.
  4. Export at any time. The Client may export its Client Data from Lavawall® at any time in a structured, machine-readable format. On cancellation or termination, ThreeShield will provide a complete export on request, at no charge, and will maintain read-only access for a reasonable period to allow the Client to retrieve it.
  5. Deletion. On request following termination, ThreeShield will delete Client Data from its live systems within ninety (90) days and from backups in the ordinary course of backup rotation, and will confirm in writing what was deleted and when. ThreeShield may retain what it is required to retain by law.

14. Privacy

  1. ThreeShield handles personal information in accordance with its privacy policy and with the Personal Information Protection Act (Alberta), PIPEDA, and other applicable privacy legislation.
  2. Lavawall® necessarily collects personal information about the Client's people, including names, email addresses, sign-in and authentication events, device assignments, and activity within monitored systems. It collects this to provide the security service and for no other purpose.
  3. Section 10 discloses where that information is stored and processed. Where the Client is subject to Alberta's Personal Information Protection Act, section 13.1 of that Act requires the Client to notify individuals about service providers outside Canada; sections 10, 11 and 12 give the Client what it needs to do so.
  4. Safeguards. ThreeShield will implement and operate, using reasonable skill and care, administrative, technical and physical safeguards for Client Data in its possession or control that are consistent with good industry practice for an information security services provider, including encryption of Client Data at rest and in transit using industry-standard protocols where the receiving system supports them, multi-factor authentication on every interactive account with access to Client Data and equivalent compensating controls for non-interactive accounts, role-based access limited to personnel who require it, logging of access, screening of personnel with such access, and secure disposal of media that has held Client Data. This is an obligation of reasonable skill and care and not a guarantee of outcome; section 19 states how that distinction affects liability.
  5. ThreeShield will notify the Client without undue delay, and in any event within seventy-two (72) hours, of a security incident within its own systems or those of a sub-processor that has resulted, or is more likely than not to have resulted, in Client Data being accessed, acquired, used or disclosed by a person not authorized by the Client. Every decision about notifying a regulator or an individual is the Client's.

15. Health information

  1. Lavawall® is not designed to receive health information, and the Client should not place health information into a ticket, a document field or a free-text field within it.
  2. Where the Client is a custodian, trustee or equivalent under health privacy legislation and ThreeShield may have access to health information, the parties will enter into a written information manager agreement, or equivalent instrument, before that access is granted. That instrument prevails over these terms to the extent of any conflict.
  3. ThreeShield will not knowingly transmit health information to any artificial intelligence model provider, whether in Canada or elsewhere, and applies the blocking control described in section 11.5.

16. What ThreeShield is not responsible for

  1. Products and services the Client did not buy from ThreeShield. ThreeShield is not responsible for, and gives no warranty, representation or undertaking in respect of, any hardware, software, subscription, licence, network, cloud service, application or professional service that the Client has not purchased from ThreeShield, whether or not ThreeShield recommended it, integrated with it, monitors it, reports on it, or assists the Client with it. That includes the Client's operating systems, productivity and collaboration platforms, endpoint protection, backup products, network equipment, internet connectivity, line-of-business and clinical applications, and the services of any other supplier. Where Lavawall® reads from or writes to such a product, ThreeShield is responsible for its own integration and for nothing else, and is not liable for the availability, accuracy, security, performance, licensing or continuation of that product.
  2. Backups. Making, verifying, securing, retaining and testing backups of the Computer System and the Client's data is the Client's responsibility, whether or not the Client uses a backup product supplied through ThreeShield or monitored by Lavawall®. ThreeShield may report on backup coverage, and a report is a convenience and not a warranty that a backup exists, is complete, is recoverable, or will restore. ThreeShield is not liable for any loss, corruption or unavailability of data, or for any cost of recreating or recovering it, arising from the absence, failure, incompleteness or non-recoverability of a backup, or from the Client's failure to test a restore.
  3. Nothing in this section limits ThreeShield's obligations in respect of Lavawall® itself or the safeguards in section 14.

17. Credit card and financial information

  1. Lavawall® is not designed to receive or store credit card or financial information. Other than the card fields in the billing page, which are hosted and processed entirely by ThreeShield's payment processor, the Client should not enter or upload a credit card number, card verification value, expiry date, cardholder name in combination with a card number, bank account number, or other payment or financial account information into Lavawall® — including into a ticket, a document field, a note, an attachment or any free-text field.
  2. Card details entered into the billing page are transmitted to and held by the payment processor. ThreeShield does not receive, store or have access to full card numbers or card verification values.
  3. Where ThreeShield becomes aware that card or financial account information has been entered into Lavawall® outside the billing page, it will remove it from the record, note the removal, and notify the Client. The Client remains responsible for any consequence of having entered it, including any obligation it has under PCI DSS.
  4. Section 11 applies to any such information in the same way as to other sensitive content: tokenization operates on patterns, and ThreeShield does not warrant that free text is sanitized.

18. Confidentiality

  1. Each party will keep the other's confidential information confidential, will use it only for the purposes of this Agreement, and will disclose it only to those of its personnel, contractors and advisers who need it and who are bound by equivalent obligations.
  2. The Client will not disclose the proprietary scripts and commands ThreeShield uses, the addresses assessments are conducted from, or other details of ThreeShield's assessment methodology.
  3. ThreeShield will not disclose details of the Client's Computer System, the Client's data, non-public aspects of the Client's business, or the identities and details of the Client's people and suppliers.
  4. These obligations do not apply to information that is or becomes public other than through a breach of this Agreement, that a party already lawfully held, or that a party is legally compelled to disclose — and in that last case the disclosing party will, unless prohibited, give the other party notice and an opportunity to seek relief, and will disclose only what it is required to disclose.
  5. These obligations survive termination for five (5) years, and indefinitely in respect of health information and personal information.

19. Limitation of liability

This section allocates risk between the parties. It is written to be read, not to be found later.

  1. Compromise of the Client's environment. No security program prevents every attack, and Lavawall® reduces but does not eliminate the risk of a security incident. The Client retains operational control of the Computer System, deploys the agents, approves changes and makes the purchasing decisions. ThreeShield's total liability arising out of or in connection with a security incident affecting the Computer System or the Client's data, however caused, including where Lavawall® failed to identify or report the vulnerability, control or system concerned, is limited to the cap in subsection 6, and that is the Client's sole and exclusive remedy for such an event.
  2. Consequences ThreeShield does not carry at all. ThreeShield is not liable in any event for the following consequences of a security incident affecting the Computer System: an extortion or ransom demand; a fine, penalty, assessment or sanction imposed on the Client by a regulator, commissioner, court, tribunal or payment card brand or acquirer; the cost of notifying individuals or regulators; the cost of forensic investigation, credit monitoring, crisis management or public relations; the cost of rebuilding, recovering or restoring the Computer System or the Client's data; and business interruption or loss of productivity.
  3. What ThreeShield does stand behind. Subsections 1 and 2 do not limit ThreeShield's liability where loss is directly caused by (a) ThreeShield's use or disclosure of Client Data otherwise than as this Agreement permits; (b) ThreeShield's failure to implement or operate the safeguards described in section 14, where that failure results in Client Data being accessed, acquired, used or disclosed by a person not authorized by the Client; or (c) ThreeShield's fraud or wilful misconduct.
  4. Being attacked is not, by itself, a failure. ThreeShield's obligation in respect of safeguards is to implement and operate those described in section 14 using reasonable skill and care. It is not a guarantee that ThreeShield's own systems will not be compromised, and a security incident affecting ThreeShield does not of itself establish that ThreeShield failed to safeguard Client Data. Subsection 3 is not engaged where ThreeShield had implemented and was operating those safeguards and the incident arose from a previously undisclosed vulnerability in third-party software, from an attack of a sophistication that safeguards of that kind would not reasonably be expected to withstand, from the act of a state or state-sponsored actor, or from the compromise of a third party outside ThreeShield's control. In those cases the cap in subsection 6 applies.
  5. A failure to meet a procedural, notification, record-keeping or documentation requirement of this Agreement does not engage subsection 3, and any liability for it is subject to the cap in subsection 6.
  6. Cap. Subject to subsection 7, each party's total aggregate liability arising out of or in connection with this Agreement, whether in contract, tort, breach of statutory duty or otherwise, is limited to the greater of (a) the fees paid by the Client in the three (3) months preceding the event giving rise to the claim, and (b) two thousand five hundred dollars ($2,500). This cap does not apply to the Client's obligation to pay fees, interest or taxes, or to the Client's obligations under section 20.
  7. Claims within subsection 3 are limited to the proceeds actually recovered under the insurance ThreeShield maintains, and in no event exceed the limits of that insurance. ThreeShield will maintain errors and omissions and commercial general liability insurance with cyber and privacy extensions, will pursue any such claim with its insurer in good faith, and will provide a certificate of insurance on request. The Client acknowledges that the cyber and privacy extension carries sub-limits within the errors and omissions aggregate, that fines, penalties and punitive damages are excluded from that insurance, and that defence costs erode the limit.
  8. Excluded losses. Neither party is liable for loss of profit, revenue, anticipated savings, goodwill, reputation or business opportunity, whether direct or indirect and whether or not foreseeable; nor for any fine, penalty, assessment or sanction imposed on the other by a regulator, court, tribunal or payment card brand, nor for punitive, exemplary or aggravated damages.
  9. Matters outside ThreeShield's responsibility. Without limiting the above, ThreeShield is not liable for: a failure to identify a vulnerability, misconfiguration, indicator of compromise or end-of-life component; any matter affecting a device or service to which ThreeShield has not been given access or on which the Client has not deployed an agent; loss arising from the Client's failure to maintain or test backups; loss arising from a remediation or control that ThreeShield reported and the Client declined, deferred or did not fund; the acts or omissions of the Client, its personnel, or any third party the Client engages; any product or service the Client did not purchase from ThreeShield, as section 16 provides; the absence, failure or non-recoverability of a backup, as section 16 provides; the recording, transcription and Client-side AI tooling described in section 12; and any interruption, delay or loss of productivity arising from scanning or assessment performed in accordance with this Agreement.
  10. Each party will take reasonable steps to mitigate its loss. No claim may be brought more than two (2) years after the claimant became aware, or ought reasonably to have become aware, of the circumstances giving rise to it.
  11. The caps in this section are aggregate across all claims and are not per-claim, per-event or per-year. The parties agree that these limits are a reasonable allocation of risk given the fees payable, the Client's retained control of the Computer System, and the Client's right to cancel at any time.
  12. Claims against individuals. The Client will bring any claim arising out of or in connection with this Agreement or Lavawall® only against ThreeShield, and not against any director, officer, shareholder, employee, contractor or agent of ThreeShield personally. Each such person may rely on and enforce this subsection and the limitations in this section as if named in it. This does not limit liability arising from a person's own fraud, any obligation imposed on a person directly by statute, or the powers of a regulator or prosecutor.

20. Indemnity

  1. The Client will indemnify ThreeShield against third-party claims, and the reasonable cost of defending them, arising from the Client's breach of this Agreement, from the Client's failure to obtain a consent or give a notice it warranted it had obtained or given, from the Client's use of the tooling described in section 12, or from a security incident affecting the Computer System other than one falling within subsection 19.3.
  2. The Client's indemnity does not extend to any claim to the extent it arises from ThreeShield's fraud, wilful misconduct, breach of confidentiality, or unauthorized use or disclosure of Client Data.
  3. ThreeShield will indemnify the Client against third-party claims, and the reasonable cost of defending them, arising from ThreeShield's breach of section 18, from its unauthorized use or disclosure of Client Data, from its fraud or wilful misconduct, or from a claim that Lavawall® infringes a third party's intellectual property rights. This indemnity is subject to the caps and exclusions in section 19.
  4. A party seeking indemnity will notify the other promptly, will not settle without the indemnifying party's consent, and will give the indemnifying party reasonable co-operation and the right to assume the defence with counsel reasonably acceptable to the indemnified party.

21. Term, cancellation and suspension

  1. This Agreement continues until cancelled. The Client may cancel at any time through the console or by contacting ThreeShield through the contact form. Cancellation takes effect at the end of the current billing period, and ThreeShield does not charge an early-termination fee.
  2. Prepaid annual terms are not refundable. Where the Client has prepaid for an annual term and cancels part way through it, the amount prepaid is not refunded, credited or pro-rated, and the Client keeps access for the remainder of the term it paid for. The Client receives two months free in exchange for paying annually, and that discount is the consideration for the commitment. This does not apply where ThreeShield cancels under subsection 3, or where the Client terminates for ThreeShield's material breach under subsection 4, in which case ThreeShield will refund the unused portion of the prepaid amount calculated at the undiscounted monthly rate.
  3. ThreeShield may cancel on thirty (30) days' notice.
  4. Either party may terminate immediately on written notice if the other becomes insolvent, or commits a material breach that is not remedied within thirty (30) days of written notice describing it.
  5. Suspension for non-payment. If the Client fails to pay an undisputed invoice within thirty (30) days of its due date, ThreeShield may, on ten (10) business days' written notice, suspend the Client's access to Lavawall® until payment is received. Suspension does not terminate this Agreement and does not relieve the Client of any accrued payment obligation.
  6. Getting the Client's data out while access is suspended. Where access is suspended, ThreeShield will on the Client's written request provide the Client with a single complete export of its Client Data in a structured, machine-readable format within ten (10) business days. ThreeShield may require payment of undisputed overdue amounts before providing that export, except where the Client states in writing that it requires the data to meet a legal or regulatory obligation or to respond to a request or investigation by a regulator, commissioner or court. ThreeShield will not delete Client Data during a suspension, and will not withhold the export once this Agreement has terminated.
  7. Sections 13, 14, 15, 16, 17, 18, 19, 20 and 24, and any accrued payment obligation, survive termination.

22. Subcontracting and assignment

  1. ThreeShield may subcontract parts of the service. It remains responsible for the performance of its subcontractors as if their acts and omissions were its own.
  2. Any subcontractor with access to Client Data is a sub-processor and is subject to section 10.4.
  3. Neither party may assign this Agreement without the other's consent, which will not be unreasonably withheld, except that either party may assign to an affiliate or to a successor of its business by amalgamation, reorganization or sale of substantially all its assets, on notice to the other.

23. Default

  1. ThreeShield may decline to provide the Vulnerability Assessment if the Client fails to provide payment, information or access required under this Agreement within a reasonable period.
  2. Where the Client has paid and then fails to provide the information or access required, ThreeShield may retain a reasonable part of the payment as a genuine pre-estimate of its costs, and not as a penalty.

24. Dispute resolution and governing law

  1. Where a dispute arises, the parties will first attempt to resolve it by negotiation between people with authority to settle it. If that has not succeeded within thirty (30) days, they will attempt mediation before a mediator experienced in information technology disputes, sharing the mediator's fees equally.
  2. If mediation has not resolved the dispute within sixty (60) days of the mediator being appointed, either party may commence proceedings in the Court of King's Bench of Alberta, and the parties attorn to the jurisdiction of the courts of Alberta.
  3. Nothing in this section prevents either party from seeking injunctive relief in respect of a breach or threatened breach of confidentiality, health information or personal information obligations.
  4. This Agreement is governed by and construed in accordance with the laws of the Province of Alberta and the laws of Canada applicable in it.

25. General

  1. Entire agreement. This Agreement is the entire agreement between the parties in respect of Lavawall® and supersedes all prior negotiations, proposals and understandings relating to it, subject to section 3.
  2. Amendment. ThreeShield may amend these terms on thirty (30) days' notice by email or through the console. If the Client does not accept an amendment it may cancel under section 21 before the amendment takes effect. Continued use after that date is acceptance.
  3. Force majeure. Neither party is liable for a failure or delay caused by an event beyond its reasonable control, including a natural disaster, epidemic, war, civil unrest, labour disruption, failure of a telecommunications or utility provider, or an act of a governmental authority. The affected party will notify the other and use reasonable efforts to resume performance.
  4. Independent contractor. ThreeShield is an independent contractor. Nothing in this Agreement creates a partnership, joint venture, agency or employment relationship.
  5. Severability. If a court determines that a provision is invalid or unenforceable, that provision is severed and the remainder continues in force.
  6. Waiver. A waiver is effective only if in writing, and is not a waiver of any other term or of a subsequent breach of the same term.
  7. Headings. Headings are for ease of reference only and do not affect interpretation.
  8. Interpretation. "Including" means including without limitation. A reference to a statute includes its regulations and any successor legislation. No rule of construction operates against the party that drafted a provision.
  9. Counterparts. This Agreement may be accepted in counterparts, including by adding a payment card or logging into Lavawall®, and all counterparts together constitute one instrument.

26. Contact

ThreeShield Information Security Corporation is located in Calgary, Alberta, Canada. Reach us through the contact form, or by phone:

What third-party AI models see — and what they never see

Analysis that uses a language model runs on redacted data. Before anything leaves our systems, a redaction system removes or tokenizes IP addresses, email addresses, usernames, personal names, company and domain names, and sensitive personally-identifiable information (SPII) that may appear in a ticket, including free text a person typed. Email our internal scans indicate may contain medical information is never sent to a third-party model at all. Every model is contractually configured so your information is not used to train it.

Redacted ticket and breach information is processed in Canada. If you would prefer another country, contact support and we will arrange it. Redacted context around suspected breach indicators and threat intelligence may be processed in the United States — that processing contains no IP address, company name, user, email address, or ticket information.

We never record a meeting covertly. Transcription tooling, and the native transcription, recording and assistant features in Microsoft Teams and Microsoft 365 Copilot, currently process in the United States. Before or at the start of a meeting we either ask you, or join a clearly named participant you can see and tell us to turn off — and you can direct us in writing to never record or transcribe at all. See section 12 of the terms above.

Subprocessors: AWS (hosted in Canada) · AWS AI services (hosted in Canada) · Anthropic (models hosted in Canada through AWS for anything relating to your tickets and breaches; US-hosted for some other tasks that do not involve them) · OpenAI (verification only, no access to your tickets or breach information). Full detail on the privacy policy.