A Fortify 24x7 brand. Detection engineering and analyst response, run from a staffed security operations center.Client sign inContact
S1XDR
Agreements · document one

Terms of Service

What you and Fortify 24x7 owe each other once an S1XDR line is running. Written to be read, not survived.

Key factsEffective August 23, 2026
Brand
S1XDR
Website
s1xdr.com
Operated by
Fortify 24x7, which is the entity you contract with for anything bought here
Card descriptor
FORTIFY 24X7
Contact
soc@s1xdr.com

Fortify 24x7 (referred to below as "we" and "us") owns and runs the S1XDR brand. Placing an order here, or using what that order provisions, is your acceptance of this agreement. It is deliberately short, and the clauses limiting us are written no less plainly than the clauses limiting you.

Section 01

What the subscription covers

You are buying a managed detection and response service, priced by unit, delivered by Fortify 24x7 on the SentinelOne platform. All six detection tiers carry the SentinelOne Complete agent together with continuous watch from our security operations center. Tiers named Fortify-XDR layer Fluency correlation across endpoint, email, cloud workload, network, and directory sources on top of that. Tiers named Fortify-XDR+ go further again: our analysts remediate the events they identify rather than reporting them onward.

Add-on modules for allowlisting, email security, endpoint management, data loss prevention, and backup are separate line items with their own scope, described on their solution pages. Nothing in an add-on changes the scope of a detection tier, and nothing in a detection tier includes an add-on.

Section 02

Billing

Each line bills every month, ahead of the month it covers, against whichever unit was displayed at purchase: an endpoint, a Kubernetes node, a mailbox, a managed device, a named user, a tenant, or a company file. Payment runs through Stripe. FORTIFY 24X7 is the name your bank will show.

The subscription renews on its own until you end it. Raising or lowering a quantity lands on the following invoice, never the one that has already been taken, and the quantities are the numbers you entered. We do not audit your estate to correct them.

Section 03

Cancellation

End the subscription whenever you wish. The billing portal does it, and so does an email. Doing so cancels the following renewal; the month already bought stays live and coverage finishes with it. Agent licenses deactivate at that moment, and telemetry ages out on the schedule described in our Privacy Policy. Anything owed back to you is a separate question, answered by the Refund Policy.

Section 04

Telemetry and custody

Operating this service means we hold security telemetry from your estate: process events, mail metadata, cloud control-plane records, network session records, and directory events, depending on the tier you bought. It is transmitted over TLS and stored encrypted. It remains yours.

Analysts read it when the work demands it, when you ask them to, and when a lawful order leaves us no choice. It is never sold. It is never mined for anything beyond defending your environment, and defending our other clients through the detection content we write. The Privacy Policy sets that out line by line.

Section 05

Your responsibilities

  • Deploy the agent. We supply signed packages; getting them onto the machines is yours. An endpoint with no agent is an endpoint we cannot see, and it is still billed if it is in your declared count.
  • Authorize the connectors. On XDR tiers, cross-layer correlation only works once the email, cloud, network, and directory sources are connected. Until then the service behaves like the tier below it.
  • Keep the account reachable. Payment details current, and the account email address monitored. That address receives escalations and sign-in links.
  • Name your escalation contacts. At the XDR+ tiers we act on identified events. Tell us who may authorize an exception, and tell us which hosts must never be isolated without a call first.
Section 06

Response scope and its limits

At the Fortify-XDR+ tiers our analysts perform direct remediation on events we identify. That means isolating a host, terminating a process chain, quarantining a file, revoking a session, or rolling an endpoint back to its pre-incident state, within the estate covered by your subscription and using the tooling that subscription provides.

It does not mean unlimited incident response. Forensic investigation, legal or regulatory breach handling, rebuilding infrastructure, and recovery of systems outside the covered estate are separate engagements, quoted separately. We will always tell you when an event has crossed that line, and we will not stop working while we tell you.

Section 07

Service levels and liability

We deliver this service with the skill and care a competent provider would apply. No product and no analyst team intercepts every attack, and a vendor promising otherwise is selling something that is not security. Several things sit outside our reach: your network links, the uptime of the platforms we ingest from, machines that are switched off or were never enrolled, and outages at our upstream vendors.

To the fullest extent allowed by law, whatever we may owe on any single claim is capped at the fees received from you across the preceding three (3) months, and consequential or indirect losses fall outside that cap entirely.

Section 08

Amendments

This agreement can be revised. Anything material reaches your account address by email no fewer than 30 days ahead of the date it applies, and staying on the service beyond that date counts as agreement to it.

Section 09

Contact

Fortify 24x7 · soc@s1xdr.com