Three Darktrace documents sit beneath the Master Services Agreement and change what a customer receives for its fees. The Support Services Terms describe the support every customer gets, the Product Specific Terms add schedules for individual offerings, and service definitions such as Managed Threat Detection describe optional services. Under the MSA the Support Terms are incorporated into the contract, and where the Support Terms conflict with the MSA or an Order, the MSA or Order controls.[1][4]
Standard Support
Darktrace provides all customers with Standard Support Services: a helpdesk, software updates, hardware support, health checks and system diagnostics, and the Customer Portal. Availability may be subject to geographic limitations that vary across jurisdictions and must be checked at the time of purchase.[1]
Helpdesk
Support requests are raised and answered through the Customer Portal, in English, and telephone hotline support is available in English during the coverage window to customers who have a Customer Portal account and pass authentication checks. Darktrace may run remote diagnostics using electronic remote support tools and will use reasonable endeavours to correct verifiable and reproducible errors, possibly through a patch or workaround; not all reported errors may be corrected. If a customer fails to implement a temporary workaround and the Offering fails as a result, Darktrace has no liability for the failure.[1] Helpdesk and hardware support are available 24/7, and Darktrace will use commercially reasonable efforts to provide telephone and ticket support in Japanese (10:30 to 18:30 Japan time, Monday to Friday) and Spanish (9:00 to 17:00 US Eastern, Monday to Friday).[1]
Software updates
Darktrace makes a copy of each Update available at no additional charge. Updates can be delivered automatically if Call Home is enabled; otherwise the customer installs them within a reasonable time after they are made available on the Customer Portal. Updates are subject to Darktrace’s End of Life Policy.[1]
Hardware support
Hardware support is return-to-base with advance replacement. Darktrace provides the parts and materials needed to maintain the hardware, other than racking, cables, data feeds and third-party products such as taps, and ships replacement hardware that may be an equivalent or later revision. The customer must raise a ticket, give model and serial numbers and failure history, package the failed unit and return all parts originally shipped, including rails, transceivers and power cables, and will be invoiced for missing parts. Darktrace is not responsible for configuration or data on returned hardware.[1] Hardware support is not owed for faults caused by improper use, site conditions, third-party products, customer-introduced malware, unauthorised modification or events such as fire and water damage.[1]
Health checks and diagnostics
Health check diagnostics are continual and include CPU performance, memory utilisation, appliance load, the number of unique devices seen on the network as a numeric value, bandwidth per interface, interface errors, connections per minute, disk utilisation and alert metrics.[1] The list matters for sizing, because unique devices and bandwidth are the same kind of quantity that the appliance datasheet uses for its capacity guidance. The Support Terms do not say that Darktrace uses health-check data to assess licence compliance, and the MSA’s compliance verification right is separate.[4]
Customer Portal
Through the Customer Portal the customer can raise tickets, manage users, add or remove notification contacts, sign up for training, read documentation and download software and appliance updates. Managing users and contacts is restricted to the customer’s Primary Users, designated individuals named on the portal, and the customer controls which personnel receive access.[1]
Conditions on support
- Payment. Support coverage starts on the Commencement Date and runs for the period in the Order. Darktrace is liable to provide Support Services only if the customer is current with its fees. If a customer lets a support term lapse but keeps using the services, Darktrace may invoice for the period, and if the customer later reinstates support it must pay all back fees.[1]
- Call Home. The Offering can connect to a secure encrypted channel to receive patches and updates and provide access for diagnostics and threat intelligence. If remote analyst support is needed to answer a ticket, it depends on Call Home access, and disabling Call Home impacts Darktrace’s ability to perform support.[1]
- Customer duties. On request the customer assists with remote resolution, runs self-tests, installs customer-installable firmware updates, and keeps its own backups, because Darktrace provides no backup service.[1]
- Onsite support. At Darktrace’s discretion support may be remote or onsite, and any onsite support carries travel fees and expenses.[1]
- Discontinuation. Darktrace may discontinue specific support services no longer included in the Offering on six months’ written notice, refunding a pro-rated amount for unused prepaid support.[1]
- Additional services. Services outside the Support Services are agreed in advance and charged at published rates for the country concerned.[1]
The Support Terms name Darktrace, Inc., Darktrace Australia Pty Ltd, Darktrace Singapore Pte Ltd and Darktrace Korea Ltd as Affiliates that may be involved in providing support.[1]
Product Specific Terms
The Product Specific Terms (v1.9.1) are an addendum to the MSA with six schedules. Each says that use and delivery are subject to the MSA.[2]
| Schedule | Offering | Licensing-relevant terms |
|---|---|---|
| 1 | Attack Surface Management | The customer grants Darktrace a right to use the search terms it supplies and warrants it holds any third-party rights in them; Darktrace gives no warranty about the accuracy of the data. |
| 2 | Incident Readiness & Recovery | If the customer expands its NETWORK deployment, it pays Darktrace’s then-current standard fees for the corresponding expansion unless the Order says otherwise. The customer is responsible for outcomes of actions taken through integrated third-party tools. |
| 3 | CLOUD | Agents are optional but may improve visibility; the customer accepts increased cloud hosting and transfer fees; the product is a supplementary tool, not a substitute for human intervention. |
| 4 | Forensic Acquisition & Investigation | Applies to customers who bought as Cado Security Software; Support Services are not provided, only basic portal support for the most recent version; Darktrace may use usage data to confirm that use accords with the licence. |
| 5 | Darktrace Labs | Non-production testing, training and demonstration only; availability depends on revocable usage credits; Darktrace may suspend and delete content on suspected breach; the MSA’s liability limits do not apply. |
| 6 | Secure AI | Provided solely to enhance the safety of information systems and protect customer assets; the customer determines purposes and means and carries privacy and employment law duties; an Acceptable Use Policy applies. |
All six schedules are in the Product Specific Terms.[2] Two features deserve attention in an inventory. Labs content may not be used in production or commercially, and the Labs schedule removes the MSA’s exclusions and cap on liability, so Labs use in production environments carries different risk from the other offerings.[2] The Forensic Acquisition & Investigation schedule lets Darktrace collect and use usage data to confirm that use accords with the rights granted, which is a second route to usage information besides the MSA clause.[2]
Managed Threat Detection
Managed Threat Detection is an English-language, 24/7 service delivered by Darktrace’s global SOC using a follow-the-sun shift pattern. The SOC reviews a subset of standard models tagged “Enhanced Monitoring” and alerts the customer’s named SOC contacts when a significant, likely high-impact anomaly is detected. Alerts are sent by email with a password-secured attachment, appear as a ticket in the Customer Portal and can be sent by call or SMS, and a monthly SOC report summarises investigations.[3]
The service is only available to customers using NETWORK and/or IDENTITY; if configured within NETWORK it can also cover OT, CLOUD, IDENTITY and ENDPOINT. It depends on an active Call Home connection around the clock and on the customer enabling Auto Update Models.[3] Coverage depends on NETWORK visibility, so Darktrace recommends regular SPAN coverage checks. Although analysts may suggest actions, the customer remains responsible for follow-up analysis and remediation, and Darktrace may choose not to alert on activity it judges insignificant.[3] Alerts handled outside the customer’s office hours may be reviewed by SOC staff in another jurisdiction, in which case alert data is transferred under the Data Processing Addendum.[3]
Other service definitions
The legal page also lists service definitions for Proactive Health Optimization (Essentials, Standard and Premium), Professional Service Days, Security Operation Support and Managed Detection and Response, together with the Data Processing Addendum, Business Associate Agreement and Partner terms. They are separate documents that were not reviewed for this article.[5]
Product scope that affects support
The Product Specification states that, unless expressly agreed in writing, the Offering does not include the monitoring, interpretation or corrective action with respect to any Alerts, and that not all anomalies or intrusions may be reported or prevented.[6] Customers who rely on Darktrace for monitoring therefore need an agreed managed service or their own SOC.
Out of scope
This article does not cover the contents of the Customer Portal, the Darktrace Support Guide, the End of Life Policy or any service level credits, none of which were part of the documents reviewed.[5]