LICENSEWARE

Bitdefender business agreement, audit and MDR terms

This article is about the Master Service Agreement for Bitdefender Business Solutions and Services: licence grant and restrictions, orders and term, evaluation, audit, transfer, support and end of life, and the terms for Bitdefender MDR and its Cybersecurity Warranty. For the overview, see Bitdefender licensing. It is not legal advice.

On This Page

The Master Service Agreement for Bitdefender Business Solutions and Services is the standard contract for Bitdefender’s business products and services. Bitdefender’s legal page lists it as the License and Services Agreement for Business Solutions.[2] The Agreement consists of the main terms, the applicable exhibits and statements of work, the privacy policy, and any Commercial Documentation presented to the customer.[1] It governs all orders for business solutions and services, whether placed directly with Bitdefender or through a Bitdefender partner.[1] Its exhibits cover the Bitdefender Solutions (Exhibit A), MDR and the Cybersecurity Warranty (Exhibit B), offensive security and advisory services (Exhibit C), threat intelligence (Exhibit D), and GravityZone Security Data Lake (Exhibit E).[1]

Acceptance and parties

The Agreement becomes binding on the earlier of the date the customer accepts it or the date in the Commercial Documentation. An MSP acting for a customer must inform the customer of the terms and obtain its acceptance.[1] Anyone who installs or registers the products on behalf of an entity, including an employee, MSP, reseller or contractor, must accept the Agreement for that entity before the products may be used.[1] Affiliates that buy under the Agreement, or use or benefit from the products, are bound by it, and the accepting entity remains responsible for them.[1] The Agreement overrides terms in procurement portals and other non-Bitdefender documents. Bitdefender is not bound by a reseller’s agreement with the customer unless a Bitdefender legal representative signs it.[1] Catalog proof: An MSP must obtain the customer's acceptance of the agreement.

Licence grant and restrictions

Grant. Once Bitdefender accepts the order and receives payment, it grants a limited, non-exclusive, non-transferable right to use the ordered products solely for the customer’s internal business operations, including its Affiliates. The grant is subject to the Order and the Documentation.[1] The products are licensed, not sold.[1] Catalog proof: Licence grant is limited to internal business operations.

Restrictions. The customer may not transfer, sublicense, rent, lease, loan, auction or resell the products. It may not use them to provide services to third parties, or let anyone other than contractors or consultants acting on its behalf use them. Timesharing and service-bureau arrangements are excluded.[1] Products supplied on or for a designated hardware device are licensed for that device only.[1] Circumventing licence keys or authentication is prohibited. So is publishing competitive, performance or benchmark tests without Bitdefender’s written permission.[1] Catalog proof: No resale, sublicensing, service bureau or third-party use; Benchmark results may not be published without consent.

Seats. Use is capped at the licensed seats in the Order. The licence may run on one console instance at a time.[1] Seat counting is covered in Bitdefender GravityZone yearly licensing and add-ons.

Orders, payment and term

Orders. Customers normally order through a Bitdefender partner, with prices and payment terms agreed with that partner. Direct orders are possible with Bitdefender’s prior approval.[1] Orders are non-cancellable.[1] Unless the Order says otherwise, fees are due within 30 days of invoice, and late payments carry a charge of 1% per month.[1] Fees are non-refundable, and purchased products cannot be decreased or exchanged. All services and fees must be used within the Validity Period, and unused fees do not survive it.[1] Catalog proof: Orders are non-cancellable and seats cannot be reduced or exchanged.

Validity Period and Start Date. The Validity Period starts on the Start Date and lasts for the period purchased, whether the product is used or not. The Start Date is the day the customer activates the product, but no later than 60 days after the partner places the Purchase Order in Bitdefender’s ordering system.[1] Yearly subscriptions are deactivated automatically when the Validity Period ends. Monthly subscriptions last as long as the monthly fees are paid, and non-payment suspends the account.[1] Catalog proof: The Validity Period runs from the Start Date whether or not the product is used; Yearly subscriptions deactivate at expiry; monthly accounts are suspended for non-payment.

Product changes. Bitdefender may change features and offer migrations to new versions under the same terms. Its only obligation is to give notice in advance, which may be through the console, email or its websites.[1] It may also stop supporting or discontinue products and features under its published end-of-life policy.[1]

Evaluation

Evaluation, beta, trial and early-access use is covered by a temporary, royalty-free, non-assignable licence for internal non-production use. It ends at the end of the set evaluation period, or 30 days after installation if none is set. Evaluation products may not be transferred.[1] Unless otherwise agreed, fair-usage limits apply: three concurrent console users, 50 endpoints and one month from activation.[1] Bitdefender’s liability for evaluation versions is capped at USD 10.[1] Some evaluations are configured to convert automatically. If a Customer’s Contractor activates one, it becomes a paid subscription unless stopped before expiry.[1] Catalog proof: Evaluation use is limited to 3 console users, 50 endpoints and one month; MSP-activated trials convert to paid subscriptions unless stopped.

Audit

Bitdefender may audit the customer’s usage to check that it complies with the Documentation. Audits take place on reasonable notice, during normal business hours, and no more than once a year unless a prior review found a material discrepancy.[1] The customer must put internal safeguards in place against unauthorized copying, installation or use. It must also keep records sufficient to certify compliance, and on request provide and certify reports of copies by product and version and of its network architecture.[1] Any deployment beyond the subscription must be corrected promptly. If unlicensed or excess use across all audited products exceeds 5% of actual licensed use in aggregate, the customer reimburses the difference and Bitdefender’s reasonable audit costs.[1] Catalog proof: Bitdefender may audit usage once a year and require certified reports; Over-deployment above 5% triggers reimbursement and audit costs.

Some products carry their own over-usage terms outside the audit clause. For Security for Mobile, Security for Email and Security Data Lake, excess usage is invoiced backdated, and Bitdefender may suspend the account.[1] Bitdefender may also suspend access if the customer breaches the rights granted or fails to pay. It will make commercially reasonable efforts to give notice and a chance to remedy first.[1] For the general discipline, see software license audit.

Transfer, termination and other terms

Assignment. The customer may not assign the Agreement without Bitdefender’s written permission. It may transfer it by operation of law, on written notice, as part of a merger, reorganization or sale of all or substantially all of its assets or shares.[1] Catalog proof: Assignment needs consent except in a merger or asset sale.

Termination. For services, either party may terminate on 30 days’ written notice for an uncured material breach.[1] A customer that does not comply with the Agreement has no right to use the products and must uninstall them. After termination for material breach, Bitdefender may stop access immediately without notice.[1]

Warranty and liability. Bitdefender warrants that the products substantially conform to the Documentation for 90 days from the Start Date. Claims must be notified within that period and no later than 30 days after the non-conformity is found.[1] Bitdefender’s total liability is capped at the fees paid for the deficient product or service in the 12 months before the claim.[1]

Confidentiality and publicity. The terms of the Agreement, including pricing, are confidential information.[1] Unless the customer opts out by email, Bitdefender may display the customer’s name and logo as a customer.[1]

Governing law. The governing law depends on where the customer is located. Florida law applies in the United States and Canada, UK law in the UK, Australia and New Zealand, Dutch law in the Netherlands, Belgium and the Nordic countries listed, German law in Germany and Austria, and Singapore law in Singapore and Indonesia. Romanian law, with courts in Bucharest, applies elsewhere.[1]

Support and end of life

Standard technical support is included in the fees for the Validity Period.[1] To open a support case, the customer must give identification details and a valid Bitdefender Business Product licence. The support period starts at purchase or activation and cannot run past the end-of-life policy.[5] Standard support handles licensing changes: adding seats and splitting, merging or extending licences.[5] Bitdefender continues to support a product or version announced for end of life for 6 calendar months after its End-of-Sale date.[6] Prepaid Professional Services retainer hours must be used within one year of the Statement of Work or Order.[1] Catalog row: Bitdefender Enterprise Standard Support; proof: Support for end-of-life products continues six months after End-of-Sale; Standard support handles licence changes such as adding, splitting or merging seats. See also software maintenance and support.

MDR services

Prerequisites. MDR requires a valid, activated licence to a Bitdefender Solution and a valid MDR subscription.[1] Onboarding is complete only when three things are done: MDR is enabled in GravityZone, the Bitdefender Solution is installed and enabled on all endpoints, and emergency contacts, pre-approved actions and notification preferences are set in the MDR Portal.[1] Bitdefender’s product page states that the service includes the GravityZone Business Security Enterprise platform, together with continuous monitoring and response.[4] Catalog proof: MDR requires an active GravityZone licence on all endpoints.

Rights of usage. MDR is licensed for internal use during the Validity Period. Access is limited to the customer’s employees, its Affiliates’ employees and its contractors, each acting on the customer’s behalf. Each MDR user account is for one individual.[1] MDR customers may be offered a complimentary provisioning pack of up to 8 hours of Professional Services. The Statement of Work must be returned within seven days and the provisioning completed within 45 days.[1]

Security Data Lake for MDR. A customer that buys Security Data Lake with MDR authorizes Bitdefender’s MDR teams to use the ingested content for enrichment, detection and threat hunting on supported third-party log sources.[1] Ingestion overage is billed at the next tier. See Bitdefender GravityZone yearly licensing and add-ons.

Cybersecurity Warranty

The Cybersecurity Warranty is available to customers with a current, fully paid-up MDR subscription whose MDR is correctly installed and fully operational on their endpoints. The warranty is provided by Cysurance, a third party, and Bitdefender disclaims liability under it.[3] It does not apply to MSPs or their customers and cannot be transferred. It is included in the MDR price only for customers buying MDR for fewer than 1000 endpoints. MDR PLUS customers, and MDR customers with more than 1000 endpoints, are eligible for a Warranty PLUS subscription instead.[3] The warranty term follows the MDR Validity Period. On renewal of the MDR agreement, the customer must accept the Warranty Agreement again.[3] Claims must be notified to Cysurance within 48 hours of discovering the event, and reimbursement depends on minimum cybersecurity controls being in place.[3] The MDR product page describes the coverage as up to $100,000 in response expenses for a ransomware event, at no additional cost.[4] Catalog row: MDR Cybersecurity Warranty; proof: The included MDR warranty excludes MSPs and estates over 1000 endpoints.

Extended Email Security is covered by a separate access agreement with Mesh Security Limited, a Bitdefender-owned company registered in Ireland. That agreement was last updated in August 2025.[7] Offensive security and advisory services, and threat intelligence solutions, each have their own terms and conditions, which the Master Service Agreement incorporates through Exhibits C and D.[1]

References

  1. Master Service Agreement for Bitdefender Business Solutions and ServicesPreamble; Part I Defined Terms; Part II Orders and Payments; Part III General Legal Terms (s.5 Evaluation, s.6 Warranties, s.8 Liability, s.10 Technical Support, s.12 MSP, s.15 Suspension and Termination, s.16 Audit Rights, s.19 Miscellaneous); Exhibit A; Exhibit B MDR; Exhibit E Security Data Lake. Undated.Retrieved 2026-09-30.
  2. Legal EulaIndex of Bitdefender agreements.Retrieved 2026-09-30.
  3. Bitdefender Terms and Conditions for Cybersecurity Warranty Service (Warranty Agreement)s.2 eligibility; s.3 activation, validity, renewal; s.4 claims; Cysurance terms. Undated.Retrieved 2026-09-30.
  4. Bitdefender Managed Detection and Response (MDR) ServiceUndated.Retrieved 2026-09-30.
  5. Bitdefender Enterprise Support PoliciesUndated.Retrieved 2026-09-30.
  6. Bitdefender end of life policy statementLinked from MSA s.15.6 (old URL redirects here). Last modified 2026-02-06.Effective 2026-02-06. Retrieved 2026-09-30.
  7. Email Security Solutions - Access AgreementMesh Security Limited, a Bitdefender owned company. Last updated August 2025.Retrieved 2026-09-30.

See also

Catalog Rows Cited

16Rules2Programs

Esc