LICENSEWARE

ThreatDown Software License Agreement

This article is about the licence terms in the ThreatDown Software License Agreement for Malwarebytes business software, and the related business-use rules in the Malwarebytes Software License Agreement. It summarises the published text and is not legal advice.

On This Page

The ThreatDown Software License Agreement is the standard licence for Malwarebytes’ business software and the software-as-a-service (SaaS) delivery behind it, sold under the ThreatDown brand.[1] Together with the “Purchase Receipt” it forms the Agreement. The Purchase Receipt is the ordering document the customer executed or agreed to, plus any ThreatDown licence key information. The Agreement governs use of the software unless the parties have executed a separate written agreement.[1] The licensor is ThreatDown Inc., a Delaware corporation, for software acquired in the United States or Canada, and ThreatDown Limited, an Irish company, everywhere else.[1] Malwarebytes for Home and Malwarebytes for Teams are licensed under the separate Malwarebytes Software License Agreement, which uses much of the same wording.[2] For the vendor overview, see Malwarebytes licensing.

Editions

The Agreement does not list editions. It sets special rules for three licence types. A Site License is identified in the Purchase Receipt’s product description.[1] Email Security is licensed per email address.[1] Identity Threat Detection and Response (ITDR) is licensed per Account.[1] Some features may be restricted by geography to comply with law or third-party commitments.[1]

Metrics

Device. Devices are “devices (including mobile devices), computers or virtual machines”, with each instance of an operating system on a partitioned or virtualized machine counted as a Device.[1] “Execute” means to load, install or run the Software locally on a single Device.[1] Catalog: Device.

Email address. Email Security needs a paid licence for each and every email address using it.[1] Catalog: Email address; Email Security needs a licence per email address.

Account. An Account is any account, identity or credential in an identity provider, directory service or authentication system connected to or monitored by the Software, regardless of type or status.[1] ITDR needs a licence for each Account that exists in connected identity providers at any point during the term. The customer must keep enough licences as Account counts change.[1] Catalog: Account; ITDR covers every Account that exists at any point in the term.

Site License. A Site License allows internal use within the purchased band, not a fixed number of Devices. Bands are set by employee count and re-evaluated at the end of the subscription term.[1] Catalog: Site License employee band; Site Licenses are banded by employee count and re-evaluated at term end.

Counting / floors

Scope of the licence requirement. Except under a Site License, a licence is needed for every Device, email address or Account on which the Software operates or which it monitors, analyses or protects.[1] When the Software runs on a network, the customer also needs licences for every Device, email address or Account that can access it over the network.[1] The customer may not exceed or circumvent the Software’s usage or consumption limits, entitlements or parameters.[1] Catalog: A licence is needed for every Device, email address or Account protected; Devices that can access the Software over a network need licences.

Servers. Paid Software may not be executed on a server operating system unless it is a ThreatDown server product. Breach Remediation may run on servers to the extent its release notes allow.[1] Trial software may not run on server operating systems at all.[1] Catalog: Server operating systems need a ThreatDown server product.

Users. The Software may be used only by the customer’s employees and consultants who have agreed to the terms (“Authorized Users”). Any Authorized User may operate a Device running an authorized copy, including by remote connection when supporting that Device.[1]

Floors. The Agreement sets no minimum quantity.

Transfers between devices

Once the Software has been executed on a Device it may not be moved to another Device, even after uninstalling, with one exception. During each year of the subscription the customer may transfer Software to a new Device if three conditions are met:[1]

  1. The transferred Devices do not exceed 10% of the licensed Devices for that Software (the “Transfer Allowance”).
  2. Each transfer is single: the Software cannot move on to a third Device in the same year.
  3. The Software has been uninstalled from the first Device.

Unused Transfer Allowance does not carry over to the next subscription year.[1] For a licence manager this matters during hardware refreshes. Replacing more than 10% of a fleet in one year needs extra Devices, or a quantity that covers the overlap, unless the order says otherwise. Catalog: Up to 10% of licensed Devices may be transferred each year.

Use restrictions

The customer may not use the Software on behalf of third parties or make its functionality available to them. Computer repair, help desk and troubleshooting services are given as examples.[1] It may not transfer, sublicense, lease, lend, rent or distribute the Software, or offer its functionality through hosting, an application services provider, a service bureau or SaaS.[1] It may not combine the Software with scripts or tools that make it run automatically or unattended, except to help manage the Software on networked Devices.[1] Benchmarking for external use and building competing products are also barred.[1] Managed service providers therefore need ThreatDown’s partner programmes rather than a customer licence (see ThreatDown OneView MSP licensing). Catalog: No use on behalf of third parties.

Term, renewal and payment

The initial term starts on the date in the Purchase Receipt. If no date is given, it starts when a copy is first executed on a Device. It lasts for the stated period, or one year if none is stated.[1] Subscriptions renew automatically unless the customer opted out on the Purchase Receipt. A customer who opted in can stop renewal with at least 30 days’ written notice, and email is sufficient.[1] In Nebula the account owner manages auto-renewal for purchases made on the website. Purchases made through a sales representative are changed through Sales.[6] Catalog: Initial term starts on the Purchase Receipt date, default one year; Subscriptions auto-renew unless opted out 30 days ahead.

All amounts are charged at the start of the term, and fees already paid for the current period are not refunded. Reseller purchases follow the reseller’s pricing and payment terms.[1] Without a stated price, the then-current standard published price list applies.[1] Catalog: Fees are charged at the start of the term and not refunded.

Expiry and termination

Either party may terminate for an uncured material breach after 30 days’ notice. The licence also ends automatically if the customer breaches any term.[1] If a paid licensee does not pay, the licence ends and all copies must be erased within 30 days.[1] On expiry or termination, the Software and any licence key may deactivate automatically.[1] The Nebula Account page shows each subscription’s status, expiry date and seats used against seats purchased. The licence key is shown in the Download Center.[5] Catalog: Non-payment ends the licence; erase copies within 30 days; Nebula shows seats used against seats purchased.

Updates and support. Only paying customers with a current subscription are entitled to standard updates, maintenance and support.[1] Ordered maintenance and support follow the Support Service Agreement.[1] Under that agreement, Incident Response, Endpoint Protection, EDR and Education Site License customers get Standard support during their subscription.[3] ThreatDown may stop supporting software under its Lifecycle Policy.[1] Business versions reach End of Life 12 months after End of Maintenance.[4] Catalog: Updates and support only for paying subscribers; Business versions reach End of Life 12 months after End of Maintenance.

Audits and compliance

Section 14 gives ThreatDown an audit right during the term and for one year afterwards. On reasonable prior notice, ThreatDown may audit the customer’s systems and access its accounts to check the number and type of Devices using the Software and compliance with the Agreement.[1] For each “Prohibited Device”, meaning a Device beyond the number and type ordered and paid for, the customer pays liquidated damages at ThreatDown’s current list prices. The charge covers the licence or SaaS fees plus related support for the longer of the period the Device has been in use or 12 months.[1] The customer also bears the reasonable cost of the audit when any Prohibited Device is found. ThreatDown bears the cost if the customer is compliant.[1] Catalog: ThreatDown may audit during the term and for one year after; Over-deployment found in audit is charged at list price for at least 12 months.

Three points follow for compliance work. The 12-month minimum makes even short-lived over-deployment expensive. List price, not the customer’s discounted price, is the basis. Because the right survives the term by a year, deployment records should be kept after a subscription ends. See software license audit.

Assignment and governing law

The customer may not assign or transfer the Agreement or any rights, including by operation of law, without ThreatDown’s prior written consent. ThreatDown may assign to its affiliates without notice.[1] Governing law and courts depend on the customer’s domicile: Delaware law with courts in the Northern District of California for the Americas, Irish law and Dublin courts for Europe, the Middle East and Africa, and Singapore for Asia and Oceania.[1] Catalog: No assignment without ThreatDown consent.

Malwarebytes for Home and Teams

The Malwarebytes Software License Agreement limits Malwarebytes for Home, free or paid, to personal, non-commercial use. It may not be used on any Device used in a business.[2] A business with no more than 10 Devices may use paid Home software for business purposes under the Teams terms.[2] Malwarebytes for Teams may be used only by businesses with no more than 25 Devices. It carries the same 10% Transfer Allowance as ThreatDown.[2] Free Malwarebytes found on business Devices is therefore unlicensed use unless the business qualifies for the Small Business Exception with a paid licence. Catalog: Malwarebytes for Home is personal, non-commercial use only; Malwarebytes for Teams is only for businesses with up to 25 Devices.

Virtualization & partitioning

Each operating system instance on a partitioned or virtualized machine is a separate Device.[1] Catalog: Each OS instance on a virtualized or partitioned machine is a Device.

Out of scope

  • The data processing addendum and privacy terms incorporated into the Agreement.
  • The Managed Services Agreement, covered in ThreatDown bundles and managed services licensing.
  • Arbitration and class-action terms that apply to U.S. Malwarebytes for Home customers.

References

  1. ThreatDown Software License AgreementUndated. Catalog: ThreatDown Software License AgreementRetrieved 2026-10-01.
  2. Malwarebytes Software License Agreement (EULA)Undated. Catalog: Malwarebytes Software License AgreementRetrieved 2026-10-01.
  3. ThreatDown Support Service AgreementUndated. Catalog: ThreatDown Support Service AgreementRetrieved 2026-10-01.
  4. ThreatDown Lifecycle PolicyUndated. Catalog: ThreatDown Lifecycle PolicyRetrieved 2026-10-01.
  5. Manage subscriptions and billing (ThreatDown Support Portal)Updated 2026-08-20. Catalog: Manage subscriptions and billing (Nebula)Effective 2026-08-20. Retrieved 2026-10-01.
  6. Set up auto-renewal for subscription (ThreatDown Support Portal)Updated 2026-07-06Effective 2026-07-06. Retrieved 2026-10-01.

See also

Catalog Rows Cited

4Metrics21Rules

Esc