Trellix licensing is the framework under which Trellix licenses its security software, appliances and cloud services. These include Endpoint Security, ePolicy Orchestrator (ePO), data protection, Network Security (NX), Email Security, Endpoint Security (HX), Intrusion Prevention System (IPS) and Helix. Trellix’s legal page lists the documents that make up the licence. The End-User License Agreement (EULA) and its Supplement (Network) cover software. The Product Entitlement Definitions set the licence types. The Technical Support and Maintenance Terms cover support. The Cloud Terms of Service cover cloud services.[1] The EULA page states that the EULA “together with any applicable Supplement(s) govern your usage rights in Software and Cloud Services”.[2]
Each purchase is confirmed in a Grant Letter. Trellix defines it as the confirmation of the licences purchased and the applicable Product Entitlement Definitions. The Grant Letter identifies “the SKU number, quantity, Subscription Period or Support Period, and other access and use details”.[4] The grant number that comes with a purchase is the customer’s key to the product download site. It is used together with the email address associated with the product.[11] Catalog: The Grant Letter states SKU, quantity and subscription or support period. For the general concepts, see entitlement and software license audit.
The contracting entity depends on where the software is bought. Trellix’s royalty-free licence names Musarubra US LLC for purchases in the Americas, Musarubra Ireland Limited for Europe, the Middle East and Africa, and other Musarubra entities for Australia, Japan and Asia Pacific. It names McAfee (Beijing) Security Software Co. Ltd. for purchases in China in RMB, and Trellix Public Sector LLC.[5] The appliance documentation still uses the earlier FireEye licence key names, such as FIREEYE_APPLIANCE and FIREEYE_SUPPORT.[8]
Editions
Trellix publishes no price list or edition matrix on its public legal pages. Licence types are named in the Product Entitlement Definitions referenced by the Grant Letter.[3][4] The product families covered by the cited documentation fall into three licensing patterns:
| Product family | How it is licensed in the documentation | Catalog |
|---|---|---|
| Endpoint Security, DLP, encryption managed by ePO - On-prem | ePO licence key lists the licensed products; usage reported as nodes in ePO[10][3] | Node |
| ePO - SaaS and SaaS products | Subscriptions with a My Subscription utilization view[16] | ePO - SaaS shows subscriptions and utilization; migration needs an active subscription |
| Network Security, Email Security - Server, Endpoint Security (HX), CM, IVX appliances | Licence keys per physical or virtual appliance[8] | Appliance |
| Intrusion Prevention System | Capacity licences by throughput; virtual sensors in 1 Gbps licences[12] | Gbps |
| Email Security - Cloud | Subscriptions with a 90-day grace period after expiry[13] | Email Security - Cloud has a 90-day grace period after expiry |
Trellix offers two main forms of licensing, subscription and perpetual. The License Management Services (LMS) page says a subscription product licence has a two-year term, with Technical Support included in the first year only. A perpetual licence is indefinite, “backed by renewable annual Technical Support contracts”.[3] Catalog: Subscription licences: two-year term, support included in the first year only; Perpetual licences need renewable annual support for maintenance.
Metrics
| Trellix term | Catalog row | Source wording |
|---|---|---|
| Node | Node | LMS gives “companies utilizing more nodes than purchased” as an example of noncompliance. ePO licensing reports capture machine counts and usage per product.[3] |
| Appliance | Appliance | FIREEYE_APPLIANCE is “Required to register your system and use the product features”.[8] Virtual appliance licences “are based on a unique appliance ID”.[9] |
| Throughput | Sensor throughput (Gbps) | NS-series sensors “require a license to activate the baseline throughput”.[12] |
| Virtual sensor licence | Virtual IPS Sensor license | One 1 Gbps licence per VM600 and five per VM5000 instance. |
When asked “How is my software licensed?”, LMS points to the Product Entitlement Definitions, which define the full set of licensing meters.[3] This catalog records only the meters that the cited HTML documents name. Other meters in the Product Entitlement Definitions, such as per-mailbox, per-user or per-CPU-core types, are not catalogued until that document can be cited.
Counting / floors
Nodes from ePO. LMS asks customers to run ePO reporting and compare deployment numbers with their active grants. It calls this the best practice for staying compliant with the EULA.[3] ePO counts can be inflated by inactive agents, for example retired machines. LMS provides version-specific instructions for the ePO inactive Agent cleanup tool to remove them.[3] Home and student use devices covered by the EULA must be included in a deployment certification.[3] Catalog: Remove inactive ePO agents before counting nodes; Home and student use devices count in a deployment certification.
Licence keys. An ePO - On-prem licence key “populates the Software Catalog with the licensed Trellix products your company owns”. Without a key, ePO runs in evaluation mode and stops working when the evaluation expires.[10] Appliances need license keys “for system operation”, and optional licences are disabled when the product licence is invalid.[8] Catalog: The ePO licence key defines the licensed products in the Software Catalog; Appliances need a product licence; optional licences depend on it.
Floors. The cited documents publish no general minimum quantity. Minimums appear only as technical requirements. A VM5000 virtual IPS sensor, for example, needs five licences. See Trellix appliance, network and email security licensing.
Virtualization & partitioning
Virtual appliances are licensed in the same way as physical ones, through an appliance ID. Their product licence must be renewed every hour from a token server, which also detects duplicate virtual appliances. Brief overlaps are allowed for legitimate migrations between ESXi hosts.[9] Catalog: Virtual appliance licences are validated hourly by a token server. How endpoint licences count virtual machines is set in the Product Entitlement Definitions and the Supplement (Network), which are not quoted here.[1]
Cloud / BYOL
Cloud services are governed by the Cloud Terms of Service. On 2026-09-01 a new Cloud Services Agreement and Trellix Service Schedule replaced the earlier agreement, schedules and supplements.[6] Catalog: New Cloud Services Agreement from 2026-09-01. ePO - SaaS shows active subscriptions, a utilization summary and order history under My Subscription.[16] Trellix Helix needs no separate licence on connected appliances, and the appliance’s “Helix tier” value can be ignored.[14] Trellix publishes no bring-your-own-licence programme for public clouds in the cited documents.
Programs
Technical Support. Trellix treats signature (.DAT) updates, engine revisions and new software versions as software maintenance, and provides them only under Technical Support. A current Technical Support agreement is required for updates and upgrades, under both subscription and perpetual licences.[3] DAT and engine files can at present be downloaded without a Grant ID, but Trellix states that “This does not legally entitle a customer to do so.”[3] Catalog: Updates, upgrades and DAT files require a current Technical Support agreement.
Deployment verification and renewals. LMS runs Software Deployment Verification, the Renewal Enablement Policy and migration support. These are described in Trellix License Management Services and support.
Evaluation. An ePO evaluation is limited to 90 days.[10] The Mobile Device EULA limits evaluation software to 30 days unless agreed otherwise in writing.[4] Catalog: Evaluation licences.
Compliance
The Antipiracy Policy lists several forms of software piracy. They include under-reporting installations bought through volume purchase agreements, using subscription software past its expiration date, and accessing support entitlements such as .DATs, updates or upgrades without a current agreement.[15] LMS gives two examples of noncompliance: using more nodes than purchased, and accessing future versions after support has expired.[3] Catalog: Use after subscription expiry and support access without agreement are piracy; Noncompliance includes excess nodes and post-expiry version access. For the general concept, see true-up.
Lifecycle
Trellix publishes end-of-sale, end-of-life and end-of-support dates for current and discontinued products. A product not listed on that page is obsolete.[7] Catalog: Products missing from the end-of-life table are obsolete.
Out of scope
This page does not quote the Trellix EULA, the EULA Supplement (Network), the Product Entitlement Definitions or the Technical Support and Maintenance Terms. These PDFs were not machine-readable from this environment.[1] It also does not cover Skyhigh Security products, which have their own legal pages,[1] Trellix professional services, or prices.