Darktrace sells cyber security products that analyse network, email, cloud, identity, operational technology and AI activity. It licenses them as subscriptions under one contract set: a Master Services Agreement (MSA), an Order that states the quantity and the Subscription Period, a Product Specification that is incorporated into the MSA, Product Specific Terms for some offerings, and Support Terms.[1][5] The MSA is a binding contract between the customer and Darktrace Holdings Limited, and it governs the “Offering”, defined as the Appliances, Software and Services, or any combination of them.[1]
For a software asset manager the important point is that the commercial quantities are not public. Darktrace publishes no price list and no definition of the licensed unit for most products. The MSA says use is limited to the “Usage Metrics” in the Order, and the Product Specification says NETWORK and IDENTITY subscriptions are sold in Usage Metrics bands set out in the Product Order Form.[1][2] The only unit definitions in the public documents are for Darktrace / CLOUD, which is measured by an Identity Workload count, and guidance figures for the capacity of appliances.[2][6] Customers should therefore treat the Order Form as the primary licensing record.
This overview is followed by four deeper articles: the Master Services Agreement, product lines and Usage Metrics, appliances, sensors and deployment, and support, product-specific terms and managed services.
Editions and products
The Product Specification covers eight product families: Darktrace / NETWORK, / OT, / IDENTITY, / EMAIL, / EMAIL-DMARC, / CLOUD, / Forensic Acquisition & Investigation and / Secure AI, followed by a section of product-agnostic details.[2] The Product Specific Terms contain six schedules: Attack Surface Management, Incident Readiness & Recovery, CLOUD, Forensic Acquisition & Investigation, Darktrace Labs and Secure AI.[3]
Earlier product names survive in older contracts. The Product Specification states that NETWORK Real-Time Detection was previously DETECT/Network and Enterprise Immune System, that Autonomous Response was previously RESPOND/Network and Antigena, that OT was DETECT/OT and Industrial Immune System, and that IDENTITY was DETECT/Apps, RESPOND/Apps, DETECT/Zero Trust and RESPOND/Zero Trust, and it applies to customers who bought under the old names.[2] Forensic Acquisition & Investigation was previously Cado, sold by Cado Security Limited, which Darktrace acquired.[2] The Product Specification refers to the “Darktrace ActiveAI Security Platform” as the platform that hosts these products.[2]
Metrics
Three kinds of measure appear in the documents.
- Usage Metrics are the limits or measurements in the Order. The MSA defines them as the limits, metrics or other measurements or conditions of permitted usage, and the Order records the Offering quantity “based on Darktrace’s applicable usage metrics”.[1] See Usage Metrics.
- Identity Workload count applies to CLOUD: Identities and Workloads taken together, with assets weighted by the computation needed to analyse them.[2] See Identity Workload count.
- Appliance counts are the hardware devices shipped under the Order, which remain Darktrace property.[1]
Nothing in the public documents states that IP addresses, devices, users or mailboxes are the billing unit for NETWORK, EMAIL or IDENTITY. The appliance datasheet speaks of “unique internal devices” analysed, but describes the numbers as guidance only, and the Product Specification refers to bandwidth, connection counts and Fencing Metrics for the band bought.[2][6]
Counting and exceeding the band
The MSA states that “Customer will be subject to the payment of additional fees if the applicable Usage Metrics are exceeded”.[1] The Product Specification adds a technical consequence for NETWORK: each deployment has a capacity set by the band purchased, and if traffic exceeds the Fencing Metrics for the band the result can include overloading, delayed Autonomous Response actions, packet drops and unsupervised learning being turned off. Darktrace bears no liability if the customer gave incorrect sizing information or let usage exceed the band.[2] Exceeding a band is therefore both a commercial and an operational risk.
Deployment and hosting
Customers can run Darktrace as a physical appliance, as a Darktrace-hosted cloud instance on AWS or Microsoft Azure, or with virtual sensors (vSensors) and host agents (osSensors) that feed a Master. The Product Specification describes physical appliances as customer-managed for updates and backups, and cloud instances as managed by Darktrace.[2] Title to appliances never passes to the customer; they are provided “solely as the medium for delivery and operation of the Software” and must be returned at the end of the Subscription Period.[1] The details are in appliances, sensors and deployment.
Terms, billing and renewal
Unless the Order says otherwise, fees are invoiced annually at the beginning of each year of the Subscription Period and are payable within 30 days of an emailed invoice. Fees are non-refundable and non-cancellable except where the MSA expressly provides otherwise, and Orders are non-cancellable.[1] Darktrace may raise fees on 30 days’ notice if its cloud provider raises charges, once per year on at least 60 days’ notice, or to recover costs of customer network changes.[1] The MSA does not state an automatic renewal mechanism; the Subscription Period is whatever the Order specifies, and the MSA remains in effect until all active Subscription Periods expire or it is terminated.[1]
Programs
- Evaluation: free use for 4 weeks unless Darktrace specifies otherwise, provided as is and without support.[1]
- Partner purchases: the Offering may be bought directly or through an authorised reseller; the MSA still governs Darktrace’s obligations.[1]
- Standard Support: provided to all customers, 24/7 for helpdesk and hardware support.[4]
- Managed services: the Managed Threat Detection service and other service definitions are listed on Darktrace’s legal page.[5]
- Darktrace Labs: a non-production offering that depends on revocable usage credits.[3]
Audit and compliance
Section 16.3 of the MSA obliges the customer to permit Darktrace, or an independent representative appointed by Darktrace, to verify that use complies with the agreement, and Darktrace may not exercise this right more than once in any 12-month period. For Partner orders Darktrace may also ask the customer for confirmation of the orders placed, including copies of agreements with the Partner with pricing removed.[1] Breach of the restrictions allows immediate suspension and sits outside the liability cap.[1]
Out of scope
This article does not cover pricing, the Data Processing Addendum, the Business Associate Agreement, the Standard Contractual Clauses, the Partner terms, or the service definitions for Proactive Health Optimization, Professional Service Days, Security Operation Support and Managed Detection and Response, which are listed on Darktrace’s legal page but were not reviewed.[5] Product names on darktrace.com’s marketing pages change independently of the contract documents, which should be read for the names that apply to an Order.