- Brand
- S1XDR
- Website
- s1xdr.com
- Operated by
- Fortify 24x7, which is the entity you contract with for anything bought here
- Card descriptor
- FORTIFY 24X7
- Contact
- soc@s1xdr.com
Fortify 24x7 (referred to below as "we" and "us") owns and runs the S1XDR brand. Placing an order here, or using what that order provisions, is your acceptance of this agreement. It is deliberately short, and the clauses limiting us are written no less plainly than the clauses limiting you.
What the subscription covers
You are buying a managed detection and response service, priced by unit, delivered by Fortify 24x7 on the SentinelOne platform. All six detection tiers carry the SentinelOne Complete agent together with continuous watch from our security operations center. Tiers named Fortify-XDR layer Fluency correlation across endpoint, email, cloud workload, network, and directory sources on top of that. Tiers named Fortify-XDR+ go further again: our analysts remediate the events they identify rather than reporting them onward.
Add-on modules for allowlisting, email security, endpoint management, data loss prevention, and backup are separate line items with their own scope, described on their solution pages. Nothing in an add-on changes the scope of a detection tier, and nothing in a detection tier includes an add-on.
Billing
Each line bills every month, ahead of the month it covers, against whichever unit was displayed at purchase: an endpoint, a Kubernetes node, a mailbox, a managed device, a named user, a tenant, or a company file. Payment runs through Stripe. FORTIFY 24X7 is the name your bank will show.
The subscription renews on its own until you end it. Raising or lowering a quantity lands on the following invoice, never the one that has already been taken, and the quantities are the numbers you entered. We do not audit your estate to correct them.
Cancellation
End the subscription whenever you wish. The billing portal does it, and so does an email. Doing so cancels the following renewal; the month already bought stays live and coverage finishes with it. Agent licenses deactivate at that moment, and telemetry ages out on the schedule described in our Privacy Policy. Anything owed back to you is a separate question, answered by the Refund Policy.
Telemetry and custody
Operating this service means we hold security telemetry from your estate: process events, mail metadata, cloud control-plane records, network session records, and directory events, depending on the tier you bought. It is transmitted over TLS and stored encrypted. It remains yours.
Analysts read it when the work demands it, when you ask them to, and when a lawful order leaves us no choice. It is never sold. It is never mined for anything beyond defending your environment, and defending our other clients through the detection content we write. The Privacy Policy sets that out line by line.
Your responsibilities
- Deploy the agent. We supply signed packages; getting them onto the machines is yours. An endpoint with no agent is an endpoint we cannot see, and it is still billed if it is in your declared count.
- Authorize the connectors. On XDR tiers, cross-layer correlation only works once the email, cloud, network, and directory sources are connected. Until then the service behaves like the tier below it.
- Keep the account reachable. Payment details current, and the account email address monitored. That address receives escalations and sign-in links.
- Name your escalation contacts. At the XDR+ tiers we act on identified events. Tell us who may authorize an exception, and tell us which hosts must never be isolated without a call first.
Response scope and its limits
At the Fortify-XDR+ tiers our analysts perform direct remediation on events we identify. That means isolating a host, terminating a process chain, quarantining a file, revoking a session, or rolling an endpoint back to its pre-incident state, within the estate covered by your subscription and using the tooling that subscription provides.
It does not mean unlimited incident response. Forensic investigation, legal or regulatory breach handling, rebuilding infrastructure, and recovery of systems outside the covered estate are separate engagements, quoted separately. We will always tell you when an event has crossed that line, and we will not stop working while we tell you.
Service levels and liability
We deliver this service with the skill and care a competent provider would apply. No product and no analyst team intercepts every attack, and a vendor promising otherwise is selling something that is not security. Several things sit outside our reach: your network links, the uptime of the platforms we ingest from, machines that are switched off or were never enrolled, and outages at our upstream vendors.
To the fullest extent allowed by law, whatever we may owe on any single claim is capped at the fees received from you across the preceding three (3) months, and consequential or indirect losses fall outside that cap entirely.
Amendments
This agreement can be revised. Anything material reaches your account address by email no fewer than 30 days ahead of the date it applies, and staying on the service beyond that date counts as agreement to it.
Contact
Fortify 24x7 · soc@s1xdr.com