This document is in draft and is pending review by counsel. It is published for transparency during Armada’s pre-launch period and does not yet constitute a binding agreement.
Structure of this document
- Part I — Website Terms of Use. Applies to anyone visiting armada-solutions.com.
- Part II — Platform Subscription Terms. Applies only to an MSP that has signed an order form or pilot agreement for the Armada platform.
- Part III — Terms common to both.
If you have not signed anything with us, only Part I applies to you.
Part I — Website Terms of Use
1. Acceptance
By using https://armada-solutions.com you agree to these terms. If you do not agree, stop using the site. That is the whole mechanism — there is no account to close and no cookie banner to dismiss, because the site sets no cookies.
2. What the website is
A marketing site describing a product in development. Four static pages and a contact form. Nothing on it is an offer, a quote, or a commitment to deliver a feature.
Statements on the site about product capability describe the product as built at the time of writing. Coverage is expanding integration by integration and figures change. Where the site states what the platform can verify today, that number is current as of the page’s last update, not a permanent commitment.
3. Your use of the site
You may read it, share links to it, and quote it with attribution. You may not scrape it at a rate that degrades it for others, attempt to access non-public infrastructure, or submit false information through the contact form.
4. The contact form
Submitting the form starts a conversation. It does not create a customer relationship, a reservation, a pilot slot, or any obligation on either side. What we do with the four fields you submit is described in the Privacy Policy.
Part II — Platform Subscription Terms
These terms take effect only when an MSP signs an order form, pilot agreement, or equivalent document that references them.
5. Definitions
- “Armada”, “we” — Armada Solutions LLC, a Kansas limited liability company.
- “Customer”, “you” — the managed service provider that subscribes to the platform.
- “End Client” — a customer of the Customer, whose Microsoft 365 tenant is enrolled for assessment.
- “Enrolled Tenant” — an End Client Microsoft 365 tenant that the Customer has enrolled in the platform.
- “Attestation” — a signed record of a scan result: score, per-control statuses, catalog version, timestamp, and hash chained to the previous record.
- “Report” — the client-facing document the platform produces from Attestations, carrying the Customer’s branding.
6. What the service is
The platform:
- reads Microsoft 365 signals from an Enrolled Tenant through read-only, least-privilege Microsoft Graph application permissions, via the delegated admin (GDAP) relationship the Customer already holds;
- evaluates those signals against a versioned control catalog;
- discards the raw signals — they are held in process memory for the duration of a single scan and are never written to disk or to a database;
- stores the result as a signed, hash-chained Attestation; and
- renders Reports the Customer may present to End Clients under the Customer’s own brand.
7. What the service is not
This section is the most important one in this document. Read it before you buy.
Armada is a reporting and evidence layer. It is not a managed security service.
Specifically, Armada does not:
- monitor any environment, continuously or otherwise. Scans are discrete events that run when triggered;
- detect, alert on, respond to, contain, or remediate any security incident;
- defend, protect, harden, patch, configure, or administer any tenant. The Graph permissions are read-only — the platform is technically incapable of changing anything in an Enrolled Tenant;
- provide a SOC, an MDR service, incident response, or on-call coverage of any kind;
- replace endpoint protection, backup, email security, SIEM, or any other control in the Customer’s stack;
- provide legal, insurance, audit, or compliance advice.
A Report says what the platform verified at a moment in time. It does not say the environment is secure, and it is not a certification of anything.
8. Point-in-time scope, and what “verified” means
- Every scan is a point-in-time assessment of the specific controls listed in the catalog version stamped on that Attestation. It says nothing about the moments before or after it.
- The catalog contains 13 controls. As of the last-updated date, the first integration collects three live signals — MFA registration, Conditional Access, and privileged role hygiene — and those signals score exactly 2 controls: MFA coverage and privileged access. Conditional Access is supporting context and is never turned into a control status on its own. The remaining 11 controls render as
not_verified. not_verifiedmeans the platform could not check it. It does not mean pass and does not mean fail. The platform never estimates, infers, or defaults a control status.- Scores are computed only over verified controls. If nothing can be verified, the result is “insufficient verified data” — never a zero.
- Every Attestation records whether it was produced from live Graph data or mock fixture data, and that field is never omitted.
A control the platform did not check may still be failing badly in the environment. The Report will say the control was not verified. Reading that as “fine” is a misreading, and the Customer is responsible for not presenting it that way to an End Client. See the Acceptable Use Policy.
9. Customer responsibilities
The Customer:
- Must have authority from each End Client to authorize read-only security assessment of that End Client’s Microsoft 365 tenant, through its client agreements or a specific written authorization. The Customer represents this authority for every tenant it enrolls. Armada does not and cannot verify it.
- Is responsible for the accuracy of the tenant identifiers and client names it enters.
- Is responsible for what it does with Reports — what it shares, with whom, and what claims it attaches to them.
- Owns its relationship with its End Clients, including all obligations, service levels, and liabilities in those relationships. Armada is not a party to them.
- Must keep its API credentials and console access secure, and tell us promptly if it believes they have been compromised.
- Must comply with the Acceptable Use Policy, incorporated by reference in §10.
- Must not present a Report as a compliance certification, an audit, or an attestation of security. See §7 and the Acceptable Use Policy.
An End Client may revoke the platform’s access to its own tenant at any time, from its own Microsoft portal, without the Customer’s or Armada’s involvement. Scans of that tenant stop immediately. That is by design and is not a service failure.
10. Acceptable use
The Acceptable Use Policy forms part of this agreement and is incorporated by reference. Violating it is a material breach and may result in suspension under §17.
11. Intellectual property
- Armada owns the platform. The software, the control catalog, the scoring methodology, the attestation format, the console, the documentation, and the Armada name and marks are and remain Armada’s property. The subscription is a license to use the platform, not a transfer of anything.
- The Customer owns its brand. Logos, colors, domain, and business identity applied to the console and Reports through the white-label feature remain the Customer’s. The Customer grants Armada a limited license to display those marks for the sole purpose of rendering the Customer’s own console and Reports.
- Reports. The Customer may use, brand, and distribute Reports about its own Enrolled Tenants to those End Clients freely, for the duration of the subscription and after it ends. (Post-termination scope needs counsel’s confirmation.)
- Feedback. If the Customer sends us product feedback, we may use it to improve the platform without obligation or payment. Feedback is not confidential unless the Customer marks it as such.
- No Armada branding requirement. The white-label premise is the product: an End Client never sees Armada’s brand unless the Customer chooses to show it.
12. Fees and payment — PLACEHOLDER
Pricing is not settled. Fees, billing frequency, and any trial or pilot terms will be stated in the order form or subscription agreement that accompanies these terms. No fees are payable except as agreed there in writing.
Terms to be settled before launch:
- Pricing model (per enrolled tenant per month is the working assumption)
- Billing frequency, currency, and payment method
- Payment processor (none selected)
- Whether payment is in advance or in arrears
- Minimum commitment or minimum tenant count, if any
- Late payment consequences and interest
- Price-change notice period for existing customers
- Whether pilot customers convert at a preserved rate, and for how long
- Taxes — Kansas sales tax treatment of SaaS needs a determination
- Refund policy
Pilot and early-access arrangements are governed by the separate pilot agreement, which controls over this section where they conflict.
13. Service levels — PLACEHOLDER
There is no service level agreement at this stage. No uptime commitment, no support response time commitment, no scan frequency guarantee. Pre-launch, support is “a founder answers your email.” If an SLA is offered later it will be a separate document.
14. Warranties and disclaimers
Armada warrants that it will provide the platform with reasonable skill and care, and that it has the right to license the platform to the Customer.
Everything else is disclaimed. The platform is provided “AS IS” and “AS AVAILABLE”. To the maximum extent permitted by law, Armada disclaims all other warranties, express or implied, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement.
Armada specifically does not warrant that:
- scans will identify all security issues, misconfigurations, or vulnerabilities in an Enrolled Tenant;
- a control marked
passwill remain passing after the moment of the scan; - a Report demonstrates, establishes, or guarantees security, compliance with any framework or regulation, insurability, or fitness for any audit;
- the platform will be uninterrupted, error-free, or available at any particular time;
- Microsoft Graph will return complete, timely, or accurate data — the platform reports what Microsoft returns, and where Microsoft returns nothing, the control renders as not verified;
- the control catalog reflects any particular regulatory framework’s current requirements.
A scan is a point-in-time assessment of specific listed controls. It is not a guarantee of security and it is not a certification of compliance. No statement in a Report, in the console, on the website, or by any Armada representative modifies this.
Signing keys. Attestations are signed with ECDSA P-256. As of the last-updated date, signing uses a development keypair; hardware-backed signing via Azure Key Vault is on the roadmap and is not yet in place. Customers should not represent Attestation signatures to third parties as hardware-protected or independently verifiable until we confirm that change has shipped.
No SOC 2. Armada holds no SOC 2 Type I or Type II report and no other third-party security certification. An independent audit is on the roadmap.
15. Limitation of liability
To the maximum extent permitted by law:
- Neither party is liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, lost data, or business interruption, however caused.
- Armada’s total aggregate liability arising out of or relating to this agreement is capped at the fees the Customer paid to Armada in the 12 months before the event giving rise to the claim — or US $500 if no fees have been paid, as during a free pilot.
- These limits do not apply to a party’s fraud, willful misconduct, or gross negligence, or to the Customer’s payment obligations, or where limitation is prohibited by law.
Armada is not liable for a security incident in an Enrolled Tenant. The platform does not defend that tenant, cannot change anything in it, and does not monitor it. The Customer and the End Client remain responsible for the environment’s security.
16. Indemnification
The Customer indemnifies Armada against third-party claims arising from:
- the Customer enrolling a tenant it lacked authority to enroll;
- the Customer’s use or distribution of Reports, including any claim that a Report was presented as a certification, audit, guarantee, or compliance attestation it is not;
- the Customer’s breach of the Acceptable Use Policy;
- the Customer’s relationships and agreements with its End Clients.
Armada indemnifies the Customer against third-party claims that the platform, used as permitted, infringes a US patent, copyright, or trademark. This does not cover claims arising from the Customer’s branding, the Customer’s data, or use of the platform outside these terms.
Standard mechanics — prompt notice, control of defence, cooperation, no settlement admitting liability without consent — to be drafted by counsel.
17. Term, suspension, and termination
- Term. Starts on the order form effective date and continues until terminated. Renewal mechanics are a placeholder pending §12.
- Termination for convenience. Either party may terminate on 30 days’ written notice. (Pilot agreements use 7 days and control over this where they apply.)
- Termination for cause. Either party may terminate immediately for material breach not cured within 15 days of notice.
- Suspension. Armada may suspend access immediately, with notice as soon as practicable, if it reasonably believes the Customer is enrolling tenants without authority, violating the Acceptable Use Policy, or creating legal risk for Armada or a third party.
- On termination: tenant access is revoked and scanning stops. Enrollment records are deleted after 90 days. Attestation records are retained unless the Customer requests deletion; deleting them breaks the hash chain, and we will say so rather than pretend otherwise. Reports already delivered to End Clients are unaffected.
- Survival: §§7, 8, 11, 14, 15, 16, 18, 19, 20 survive termination.
Part III — Common terms
18. Governing law
These terms are governed by the laws of the State of Kansas, without regard to its conflict of laws rules. The UN Convention on Contracts for the International Sale of Goods does not apply.
19. Dispute resolution — NEEDS COUNSEL’S DECISION
Drafting position, to be confirmed or replaced:
- Talk first. Either party raises the dispute in writing to the other. The parties attempt to resolve it in good faith for 30 days before filing anything.
- Then courts. If that fails, disputes are resolved in the state or federal courts located in Sedgwick County, Kansas, and both parties consent to that jurisdiction and venue.
- No class actions. Claims are brought individually, not as a class or representative action.
Arbitration is deliberately not drafted in. Counsel should decide whether an arbitration clause is preferable for a two-person company facing MSP customers, and whether the class action waiver is enforceable and worth including.
20. General
- Entire agreement. These terms plus the signed order form or pilot agreement plus the Acceptable Use Policy are the whole agreement. Where they conflict, the signed order form or pilot agreement controls, then these terms, then the AUP.
- Assignment. Neither party may assign without the other’s consent, except to a successor in a merger or sale of substantially all assets.
- Severability. If a provision is unenforceable, the rest stands.
- No waiver. Not enforcing a term once does not waive it.
- Independent contractors. Nothing here creates a partnership, joint venture, agency, or employment relationship.
- Notices. To Armada: hello@armada-solutions.com. To the Customer: the email on the order form.
- Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control, including failures of Microsoft, Azure, or Cloudflare.
- Publicity. Armada will not use the Customer’s name or logo as a reference without the Customer’s prior written consent.
21. Changes to these terms
For website terms (Part I): we may update them by posting a new version with a new “Last updated” date. Continued use of the site means acceptance.
For platform terms (Part II): material changes take effect for an existing Customer 30 days after we send email notice. If the Customer objects to a material change, it may terminate before the change takes effect without penalty, and we will refund any prepaid unused fees.
22. Contact
Armada Solutions LLC
[TO BE COMPLETED] · Wichita, Kansas, United States (full street address to be inserted before publication)
hello@armada-solutions.com