# END USER LICENSE AGREEMENT FOR SSL NEXUS

Last updated: September 16, 2026

This End User License Agreement (the “Agreement”) is between the organisation or person accepting it (“Licensee”) and the SSL Nexus licensor identified on the applicable order, invoice or subscription record (“Licensor”). By installing, activating or using SSL Nexus (the “Software”), Licensee accepts this Agreement.

## 1. Licence grant

Subject to this Agreement and payment of applicable subscription fees, Licensor grants Licensee a limited, non-exclusive, non-transferable and revocable right to run the number of self-hosted production instances authorised by the active entitlement and manage certificates up to the capacity and use the platforms, integrations, plugins and portal features included in that entitlement. Additional instances, disaster-recovery rights, capacity and automation capabilities require the corresponding subscription entitlement.

## 2. Ownership and restrictions

The Software is licensed, not sold. Licensor retains all intellectual-property rights in the Software. Except where applicable law expressly permits otherwise, Licensee must not reverse engineer, decompile, disassemble, derive source code from, circumvent licence validation, alter signed licence claims, sublicense, resell or provide the Software as a service to an unrelated third party without written permission.

Open-source components, Ansible content and customer-authored plugins remain subject to their own licences. SSL Nexus invokes Ansible as a separately installed automation/deployment component rather than relicensing Ansible under this Agreement. Ansible Core and the Ansible Windows collections used by SSL Nexus are distributed under GNU GPL terms; pywinrm is distributed under the MIT License. The applicable third-party terms remain controlling for those components and are identified in `THIRD_PARTY_NOTICES.md`. Nothing in this Agreement transfers ownership of Licensee data, certificates, private keys, playbooks or plugins to Licensor.

## 3. Licence validation and minimal service data

The Software periodically contacts the SSL Nexus licensing service to validate entitlement. Validation may transmit the licence identifier, installation identifier and limited host diagnostics used to identify and support the licensed installation, including hostname, operating-system/version, kernel, architecture, SSL Nexus version/revision, aggregate service-health state and low-sensitivity feature-use booleans. It does not intentionally transmit certificate private keys, CA credentials or customer playbook contents.

The zero-cost Free tier is an Authority-issued perpetual entitlement and is limited to five active automated certificates, one managed parent domain and one standard target. Free allocation history and the domain/target lock may be validated by the licensing service to prevent reinstalling or clearing local state from resetting those limits. Finite paid certificate ceilings, including Starter and Business, may also be validated and accounted by the licensing authority so clearing or restoring local state does not reset licensed capacity. Paid subscriptions are periodically validated against the licensing authority. If that authority cannot be reached, the connectivity grace period configured for the licence applies; older authority records without an explicit value use the legacy seven-day fallback. When a paid subscription expires, is revoked, or its grace period ends, the Software enters read-only mode: new issuance, renewal, deployment and configuration actions are disabled, while existing certificates, deployments, records and read access remain intact. Licence expiry does not revoke or disable certificates already issued by a certificate authority.

## 4. Vendor portal responsibility

Licensee controls vendor onboarding, approved email identities, source networks, master domains, certificate names, request limits and access resets. Licensee is responsible for protecting vendor credentials and configuring delegated scope correctly. Licensor is not responsible for unauthorised issuance or disruption caused by Licensee configuration, compromised third-party access or delegated-request policy decisions.

## 5. Deployment adapters and customer plugins

Licensee is responsible for testing target connectivity, permissions, playbooks, custom adapters, service reloads and rollback procedures. Customer-authored or modified plugins are not warranted by Licensor unless separately agreed in writing.

## 6. Security and data

Licensee must protect administrative credentials, CA secrets, vendor activation tokens, private keys and backups. Private keys displayed to vendors are intended to be retained by the vendor and are not recoverable from SSL Nexus. Licensee must comply with applicable data-protection, employment, monitoring and computer-misuse laws.

## 7. Warranty disclaimer

To the maximum extent permitted by law, the Software is provided “as is” and “as available”. Licensor disclaims implied warranties including merchantability, fitness for a particular purpose, non-infringement and uninterrupted operation. Licensee remains responsible for certificate monitoring, recovery testing, deployment validation and target-system configuration.

## 8. Limitation of liability

To the maximum extent permitted by law, neither party is liable for indirect, incidental, special or consequential loss, including loss of profit, revenue or business interruption. Licensor’s aggregate liability arising from the Software will not exceed fees paid for the affected subscription during the twelve months preceding the event giving rise to the claim. Nothing excludes liability that applicable law does not permit to be excluded.

## 9. Third-party names

Third-party names and marks—including IIS, Nginx, Apache, PaperCut, SAP BusinessObjects, IWMC, Sectigo and DigiCert—belong to their respective owners. Compatibility references do not imply affiliation, endorsement or sponsorship.

## 10. Term and termination

This Agreement applies to the Free tier and continues for paid features while the relevant subscription remains valid. Licensor may terminate it for material breach after any notice or cure period required by applicable law or the applicable order. On termination, Licensee must stop initiating operations that are no longer licensed and uninstall the Software when legally required. Existing certificates remain governed by the issuing certificate authority and are not technically revoked merely because this Agreement ends.

## 11. General

The applicable order identifies governing law, payment terms, support entitlement and the contracting Licensor entity. If an order conflicts with this Agreement, the order controls for that conflict. If a provision is unenforceable, the remaining provisions continue. Changes to this Agreement apply prospectively unless required by law or accepted through renewal.

This document should be reviewed by Licensor’s qualified legal counsel before commercial release.
