MASTER SERVICE AGREEMENT & OPERATIONAL POLICY
Service: ATIMÔGATE MANAGED NETWORK SECURITY
Document Control ID: CIT-POL-ATG-1.0
Effective Date: January 1st, 2026
Service Provider: Cree Innovation and Technology Corp. ("Cree IT")
Jurisdiction: Northwest Territories, Canada
1.0 PURPOSE AND BINDING AGREEMENT
1.1 Intent of Policy This Master Service Agreement and Operational Policy (herein referred to as the “Agreement”) constitutes a legally binding contract between Cree Innovation and Technology Corp. (“Cree IT”) and the Customer (“Client”). This Agreement exhaustively dictates the parameters, conditions, technical realities, and legal liabilities surrounding the deployment, configuration, management, and ongoing operational use of the AtimôGate enterprise security appliance.
1.2 Acceptance of Terms By authorizing the deployment of the hardware, allowing the installation of the appliance on the Client premises, or engaging in any ongoing service relationship with Cree-IT regarding this hardware, the Client unconditionally accepts and agrees to be bound by every term, limitation, and exclusion outlined in this highly restrictive document.
2.1 AtimôGate Appliance: The physical, proprietary edge-routing and security hardware device provisioned by Cree IT, engineered to be installed inline between the Client’s provided Internet Service Provider (ISP) modem and the Client’s internal local area network (LAN).
2.2 Defense Technology Stack: The specialized cybersecurity software architecture operating on the AtimôGate Appliance, specifically utilizing the Zenarmor® Next-Generation Firewall (NGFW) engine and the Suricata® Intrusion Detection and Prevention System (IDS/IPS) for granular packet analysis.
2.3 Deep Packet Inspection (DPI): The advanced computational process wherein the Defense Technology Stack examines the data payload and metadata of network packets as they pass through the inspection point, evaluating them against real-time threat signatures.
2.4 Pro Commercial Subscription: The active, managed, and licensed tier of the Defense Technology Stack that enables premium threat intelligence, dynamic application controls, active botnet blocking, and advanced reporting telemetry.
2.5 Zero-Day Exploit: A cyberattack vector or malware strain that exploits a previously unknown software vulnerability before the vendor has become aware of it or issued a patch/signature to prevent it.
3.0 SCOPE OF SERVICES (INCLUSIONS)
Cree-IT explicitly limits its deliverables under the AtimôGate Managed Network Security service to the following parameters:
3.1 Hardware Provisioning and Deployment
-
3.1.1 Hardware Assembly: Cree IT shall provide, assemble, and flash the base operating system onto the AtimôGate Appliance.
-
3.1.2 Network Integration: Cree IT will execute the initial inline installation of the hardware at the physical network edge, establishing connectivity between the upstream ISP handoff and the downstream internal network switch.
3.2 Active Threat Management and Licensing
-
3.2.1 License Management: Cree IT shall maintain and administer the Pro Commercial Subscription for the Zenarmor and Suricata engines on behalf of the Client.
-
3.2.2 Signature Updates: The appliance will be continuously updated with the latest threat intelligence signatures to actively block recognized malware, ransomware vectors, botnet command-and-control servers, and known spyware nodes.
3.3 Ongoing Configuration and Traffic Management
-
3.3.1 Remote Administration: Cree-IT shall provide remote management of the firewall’s access control lists (ACLs) and routing protocols.
-
3.3.2 Content Filtering: Upon Client request, Cree-IT will configure and enforce categorical content filtering (e.g., restricting access to adult content, illicit materials, or gambling domains) across the Client’s managed network footprint.
3.4 Security Analytics and Reporting
-
3.4.1 Telemetry Aggregation: The appliance will silently aggregate network telemetry regarding blocked threats, intercepted malicious domains, and overall bandwidth utilization.
-
3.4.2 Monthly Reporting: Cree-IT will generate and distribute standardized, automated PDF reports to the Client detailing the volume and nature of the mitigated threats.
4.0 EXCLUSIONS AND OUT-OF-SCOPE SERVICES
To prevent scope creep and unambiguously define the limits of the AtimôGate service, the following actions, events, and remediations are strictly out-of-scope:
4.1 Endpoint Remediation and Virus Removal
-
4.1.1 Boundary of Protection: The AtimôGate Appliance is a perimeter defense tool. If a Client’s workstation, server, or mobile device becomes infected (e.g., via an infected USB drive, malicious email attachment opened locally, or lateral internal movement), Cree-IT is under no obligation under this Agreement to clean, format, or remediate the infected endpoint.
-
4.1.2 Separate Engagement: Endpoint remediation is explicitly excluded and must be engaged as a separate Professional Services contract.
4.2 Internal Network Infrastructure Troubleshooting
-
4.2.1 Scope of Hardware: This Agreement covers the AtimôGate gateway appliance only. It does not cover the management, troubleshooting, or replacement of downstream internal hardware, including but not limited to switches, Wi-Fi access points, physical cabling, or Network Attached Storage (NAS) drives.
4.3 Third-Party ISP Performance Management
-
4.3.1 Upstream Failures: Cree-IT is not responsible for, nor will it troubleshoot, internet outages, latency spikes, or dropped packets originating from the upstream ISP (e.g., Northwestel, Starlink) or the physical modem provided by said ISP.
5.0 TECHNICAL LIMITATIONS AND “BEST EFFORT” ACKNOWLEDGMENT
The Client hereby acknowledges the absolute technical limitations of cybersecurity architecture:
5.1 Hardware Bandwidth and Throughput Processing Caps
-
5.1.1 The DPI Overhead Reality: Deep Packet Inspection requires immense computational power. The AtimôGate Appliance is strictly rated for a maximum physical throughput of 500 Mbps when full DPI and IDS/IPS engines are actively scanning traffic.
-
5.1.2 High-Speed Connection Bottlenecks: If the Client utilizes an internet connection exceeding 500 Mbps (e.g., Starlink High Performance, local Gigabit Fibre), the AtimôGate Appliance will physically cap achievable network speeds at or near 500 Mbps to ensure all traffic is securely processed. Cree-IT assumes zero liability, nor will it entertain complaints, regarding perceived “slow internet speeds” that are the direct, engineered result of this necessary security bottleneck.
5.2 Encrypted Traffic Constraints (SSL/TLS)
-
5.2.1 Privacy over Payload: To comply with federal privacy standards and avoid compromising secure financial/medical portals, the AtimôGate Appliance does not perform “Man-in-the-Middle” (MITM) decryption of encrypted SSL/TLS payloads.
-
5.2.2 SNI Inspection: The system restricts its analysis to packet headers and Server Name Indication (SNI) data to block connections to known malicious servers. The Client acknowledges that highly sophisticated threats embedded deep within encrypted payloads may bypass gateway detection.
5.3 No Guarantee of Absolute Immunity
-
5.3.1 The “Best Effort” Reality: The cybersecurity landscape mutates hourly. While the Defense Technology Stack represents enterprise-grade mitigation, it is not infallible. Cree-IT explicitly disclaims any guarantee of 100% immunity from cyberattacks, Zero-Day Exploits, targeted ransomware campaigns, or socially engineered breaches. The AtimôGate is a risk mitigation instrument, not a flawless shield or a liability insurance policy.
6.0 ENVIRONMENTAL & SITE CONDITIONS CLAUSE (MANDATORY)
The Client is entirely responsible for the physical reality in which the hardware operates. Failure to meet these criteria voids all support obligations.
6.1 Physical Environment Requirements
-
6.1.1 Temperature and Moisture: The AtimôGate Appliance must be housed in a secure, moisture-free, and temperature-controlled internal environment. Damages resulting from exposure to extreme northern cold, condensation, localized flooding, or physical abuse/tampering by Client staff or third-party contractors are strictly the liability of the Client.
6.2 Power Stability and Database Integrity
-
6.2.1 Uninterruptible Power Supply (UPS) Requirement: The AtimôGate relies on a complex internal database to log threats and manage traffic. Sudden power loss—a frequent reality of northern power grids—can cause catastrophic database corruption. The Client is strictly required to provide clean, stable power via an Uninterruptible Power Supply (UPS) battery backup.
-
6.2.2 Liability for Power Events: Cree-IT is not responsible for hardware failure, database corruption, or the labor required to rebuild the firewall configuration resulting from power grid bumps, brownouts, or hard physical reboots lacking UPS protection.
7.0 FINANCIAL TERMS, PRICING, AND OWNERSHIP
7.1 The Absolute Pricing Rule All pricing, fee structures, and billing terms associated with this policy are strictly governed by the current Cree-IT Master Pricing Policy. Please refer to the Master Pricing Policy for all financial obligations and terms.
7.2 Title Transfer and Ownership
-
7.2.1 Conditional Ownership: Ownership of the physical AtimôGate hardware transfers to the Client only upon the complete, unconditional clearing of funds for the initial hardware provisioning invoice. Until such time, the hardware remains the exclusive property of Cree-IT.
-
7.2.2 Manufacturer Warranty: The physical silicon and hardware components are covered exclusively by the original manufacturer’s limited warranty. Cree-IT will act as an intermediary to facilitate RMA (Return Merchandise Authorization) claims, but assumes no financial liability for defective manufacturing.
8.0 CANCELLATION AND CONSEQUENCES OF DEGRADATION
8.1 Voluntary Cancellation The Client reserves the right to cancel the Managed Security Services portion of this Agreement at any time, subject to the terms of the Cree-IT Master Pricing Policy.
8.2 Immediate Degradation Protocol (CRITICAL) Upon the cessation of active management (whether by voluntary cancellation or suspension due to delinquency):
-
8.2.1 Revocation of Licenses: The Commercial Pro License for Zenarmor and Suricata will be immediately and irrevocably revoked by Cree-IT.
-
8.2.2 Cessation of Intelligence: The appliance will immediately cease receiving live security updates, threat signature patches, and automated intelligence feeds.
-
8.2.3 Loss of Visibility: All remote management access, telemetry aggregation, and monthly reporting deliverables will be permanently terminated.
-
8.2.4 Passthrough State: The appliance will revert to a rudimentary “pass-through” state or a heavily restricted free-tier functionality, reducing the Client’s network protection to a negligible baseline.
8.3 Reactivation Constraints Should the Client request reactivation of the service following cancellation, a comprehensive re-provisioning and firmware auditing process will be required to reinstate the commercial license keys and baseline security configurations.
9.0 FORCE MAJEURE CLAUSE (MANDATORY)
9.1 Exemption from Liability for Uncontrollable Events Cree-IT shall not be deemed in default of this Agreement, nor shall it be held liable for any failure, delay, or total cessation of service obligations arising from events strictly beyond its control.
9.2 Northern Realities and Extreme Conditions Given the operating jurisdiction of the Northwest Territories, this Force Majeure clause explicitly includes, but is not limited to: Acts of God, extreme northern weather events (including localized blizzards and temperatures exceeding hardware operational limits), prolonged regional telecommunications outages, catastrophic failures of upstream internet backbone providers (including satellite infrastructure and terrestrial fiber cuts), local or regional power grid failures, highway or ice-road closures halting logistics, supply chain embargoes, and unforeseen natural disasters such as wildfires. Under no circumstances will Cree-IT be financially or legally responsible for network downtime driven by these external environmental or infrastructural realities.
10.0 PRIVACY AND DATA HANDLING
10.1 Consent to Automated Metadata Inspection By utilizing the AtimôGate Appliance, the Client explicitly consents to the automated, algorithmic inspection of their internal network traffic metadata for the sole purpose of identifying and mitigating cybersecurity threats.
10.2 Strict Prohibition on Data Mining Cree-IT operates as a security infrastructure provider, not a data broker. Cree-IT does not parse, read, copy, or “Man-in-the-Middle” the Client’s private communications, financial records, or secure data payloads. Furthermore, Cree-IT strictly prohibits the sale, distribution, or monetization of Client network telemetry or logs to any third-party entity. Logs are retained strictly for the generation of automated security reports and real-time forensic troubleshooting.
11.0 GOVERNING LAW AND LIMITATION OF LIABILITY
11.1 Jurisdiction This Agreement, and any disputes arising from the deployment or failure of the AtimôGate Appliance, shall be exclusively governed by and construed in accordance with the laws of the Northwest Territories and the federal laws of Canada applicable therein.
11.2 Exclusion of Consequential Damages Cree-IT shall bear no liability for any indirect, special, incidental, punitive, or consequential damages resulting from a network breach, hardware failure, or configuration error. This explicit exclusion of liability covers, without limitation: loss of anticipated profits or revenue, loss of business contracts, costs of business interruption, reputational damage, or the catastrophic loss/encryption of corporate data via ransomware. The Client assumes all ultimate risk associated with operating a digital network.
END OF POLICY



