Version 2.0 · Last updated: July 18, 2026
This Agreement is executed in English; the text below is the binding version. For the processing of personal data, see also our Privacy Policy.
DYNACOP END USER LICENSE AGREEMENT (EULA)
Version: 2.0 Last updated: 18 July 2026
IMPORTANT — READ CAREFULLY. This End User License Agreement (“Agreement”) is a legally binding contract between you (“Customer”, “you”) and Forty2 LLC, a New Mexico limited liability company and the owner and operator of the Dynacop product (“Dynacop”, “we”, “us”), with its registered office at 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States.
This Agreement governs your access to and use of:
- the Dynacop Software installed on your Windows devices (as defined below); and
- the Dynacop Cloud Service, the hosted multi-tenant platform available at
app.dynacop.comandapi.dynacop.com.
BY INSTALLING THE SOFTWARE, ENTERING A REGISTRATION (CLAIM) CODE, CREATING AN ACCOUNT, CLICKING “I ACCEPT”, OR OTHERWISE USING THE SOFTWARE OR THE SERVICE, YOU (A) ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS AGREEMENT, (B) AGREE TO BE BOUND BY IT, AND (C) REPRESENT THAT YOU HAVE THE AUTHORITY TO BIND THE ORGANIZATION ON WHOSE BEHALF YOU ACT. IF YOU DO NOT AGREE, DO NOT INSTALL OR USE THE SOFTWARE OR THE SERVICE.
If you use the Software or the Service for personal purposes, “Customer” means you individually. If you use them on behalf of a company, organization, or other legal entity, “Customer” means that entity, and you represent that you have the authority to bind it.
THE SOFTWARE MODIFIES THE WINDOWS SIGN-IN PROCESS AND CAN PREVENT USERS FROM LOGGING IN TO PROTECTED DEVICES. PAY PARTICULAR ATTENTION TO SECTION 7 (CRITICAL ACKNOWLEDGMENTS — ACCESS AND LOCKOUT RISK), SECTION 12 (DISCLAIMER OF WARRANTIES) AND SECTION 14 (LIMITATION OF LIABILITY).
1. Definitions
1.1 “Agent” means the Dynacop Windows agent software, consisting of (a) the dynacop-agent Windows service, which runs with LocalSystem privileges, communicates with the Cloud Service, applies policy, and performs offline verification; and (b) the Dynacop Credential Provider component (dynacop_cp_wrapper.dll), a dynamic-link library registered with the Windows operating system as a credential provider and credential provider filter, which integrates with the Windows logon user interface (LogonUI/Winlogon) on the secure desktop.
1.2 “Updater” means the separate dynacop-updater Windows service, which runs with LocalSystem privileges and automatically retrieves, verifies, and installs updates to the Agent as described in Section 8.
1.3 “Software” means, collectively, the Agent, the Updater, the Dynacop installer packages and bundles (including Dynacop-Setup.exe and the associated MSI packages), and any updates, upgrades, patches, or new versions of any of them supplied by Dynacop.
1.4 “Cloud Service” or “Service” means Dynacop’s hosted, multi-tenant software-as-a-service platform, including the backend API (api.dynacop.com), the administrative web panel (app.dynacop.com), enrollment and verification services, policy distribution, update distribution, audit logging, and transactional email notifications.
1.5 “Protected Device” or “Resource” means a Windows computer (workstation or server, physical or virtual, accessed at the console or via Remote Desktop) on which the Agent is installed and which is enrolled in the Service.
1.6 “Administrator” means an individual authorized by Customer to access the administrative web panel and manage Customer’s Workspace, including its policies, Protected Devices, users, and access grants.
1.7 “End User” means an individual who signs in to a Protected Device and is subject to multi-factor authentication enforced by the Software, including Customer’s employees, contractors, and other authorized persons.
1.8 “Workspace” or “Tenant” means Customer’s logically isolated environment within the multi-tenant Cloud Service.
1.9 “Claim Code” means a one-time or limited-use registration code generated in the administrative panel and entered during installation to bind a Protected Device to Customer’s Workspace.
1.10 “MSP” means a managed service provider or IT services firm that uses the Service to manage Workspaces on behalf of its own customers under delegated access.
1.11 “Documentation” means the user documentation for the Software and the Service made available by Dynacop.
1.12 “Order” means an ordering document, online purchase or subscription flow, or other written agreement between Customer and Dynacop specifying the subscription plan, quantities, fees, and billing terms.
1.13 “Customer Data” means data submitted to the Service by or on behalf of Customer, including data collected by the Agent from Protected Devices as described in Section 9.
2. Scope; Relationship to Other Terms
2.1 This Agreement applies to both the Software (licensed) and the Cloud Service (provided as a service). The Software is licensed, not sold.
2.2 If Customer and Dynacop have executed a separate written master agreement or subscription agreement covering the same subject matter, that agreement prevails over this EULA to the extent of any conflict.
2.3 Commercial terms — plans, per-user or per-device pricing, volume discounts, free tiers, and billing mechanics — are defined in the applicable Order or on Dynacop’s published pricing page and are not modified by this Agreement (see Section 11).
2.4 Processing of personal data is further described in the Dynacop Privacy Policy and, where applicable, a Data Processing Addendum (“DPA”), which are incorporated by reference. In the event of conflict regarding personal data processing, the DPA prevails.
3. License Grant and Right to Use
3.1 Software License. Subject to Customer’s continued compliance with this Agreement and payment of applicable fees, Dynacop grants Customer a limited, non-exclusive, non-transferable, non-sublicensable (except as stated in Section 3.4) license, during the subscription term, to install and run the Software, in object code form only, on Protected Devices that Customer owns or is expressly authorized to manage, solely for Customer’s internal business purposes and solely in connection with the Service.
3.2 Service Access. Subject to the same conditions, Dynacop grants Customer a limited right during the subscription term for its Administrators and End Users to access and use the Cloud Service in accordance with this Agreement, the Documentation, and the applicable Order.
3.3 Copies. Customer may make a reasonable number of copies of the installer packages solely for deployment and backup purposes. All copies remain subject to this Agreement.
3.4 MSP Use. If Customer is an MSP, Customer may install the Software on devices owned by its own customers and administer Workspaces on their behalf, provided that (a) Customer has obtained the device owner’s express authorization in each case; (b) Customer has a written agreement with each such device owner covering the use of the Software and the Service, and ensures that the legally required privacy, monitoring, and authentication disclosures are made to the affected end users; (c) Customer remains fully responsible and liable to Dynacop for all use of the Software and Service under its delegated access; and (d) Customer complies with the disclosure obligations in Section 9.9 with respect to those end users.
3.5 Reservation of Rights. Dynacop and its licensors retain all right, title, and interest in and to the Software, the Service, and the Documentation, including all intellectual property rights. No rights are granted except as expressly set out in this Agreement.
4. License Restrictions
Customer shall not, and shall not permit any third party to:
(a) copy (except as permitted in Section 3.3), modify, adapt, translate, or create derivative works of the Software or the Service;
(b) reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, underlying ideas, algorithms, or protocols of the Software or the Service, except to the extent such restriction is prohibited by applicable law and then only upon prior written notice to Dynacop;
(c) sell, resell, rent, lease, lend, distribute, sublicense, or otherwise make the Software or the Service available to any third party, except as expressly permitted for MSPs under Section 3.4;
(d) remove, alter, or obscure any proprietary notices, product identification, or branding;
(e) install or use the Software on any device that Customer does not own or is not expressly authorized to manage, or use the Software or the Service to monitor, restrict, or authenticate access by individuals without a lawful basis to do so;
(f) circumvent, disable, or interfere with security-related features of the Software or the Service, including the credential provider enforcement, HMAC request signing, replay protection, lockout mechanisms, or update integrity checks, other than through the configuration options and recovery mechanisms provided by Dynacop;
(g) use the Software or the Service to develop a competing product, or perform or publish benchmarks of the Service without Dynacop’s prior written consent;
(h) conduct penetration testing, vulnerability scanning, or load testing against the Cloud Service without Dynacop’s prior written authorization (testing of Customer’s own Protected Devices is permitted);
(i) use the Software or the Service in violation of applicable law, including laws on computer misuse, employee monitoring, data protection, privacy, and export control;
(j) interfere with or disrupt the integrity or performance of the Service or the data of other tenants, or attempt to gain unauthorized access to any Workspace, system, or network;
(k) upload or transmit malicious code to the Service; or
(l) exceed the usage quantities or scope set out in the applicable Order or plan.
5. Accounts, Administrators, and Enrollment
5.1 Account Registration. Access to the administrative panel requires an account identified by a verified email address. Panel authentication is passwordless: it relies on proof of email ownership (a one-time code or sign-in link sent by email) combined with a mandatory time-based one-time password (TOTP) second factor. Customer is responsible for maintaining control of the email accounts and authenticator devices used by its Administrators and End Users.
5.2 Accuracy. Customer shall provide accurate, current, and complete registration information and keep it up to date.
5.3 Responsibility for Use. Customer is responsible for all activity occurring under its Workspace, its Administrators’ accounts, and its Claim Codes, whether or not authorized by Customer, except to the extent caused by Dynacop’s breach of this Agreement. Customer shall promptly notify Dynacop of any suspected unauthorized access at the contact address in Section 20.
5.4 Administrator Powers. Customer acknowledges that Administrators have broad powers over Customer’s Workspace, including: enrolling and removing Protected Devices; creating, modifying, and revoking End User access; resetting End User authenticators; configuring security policies (including fail-open/fail-closed behavior, enforcement mode, MFA timeouts, lockout thresholds, and offline access); enabling or disabling automatic updates per device; generating one-time bypass (recovery) codes; and inviting other Administrators or delegating access to MSPs. Customer is solely responsible for selecting trustworthy Administrators and configuring appropriate roles and permissions.
5.5 Device Enrollment. Protected Devices are enrolled by installing the Software and supplying a valid Claim Code. Customer shall treat Claim Codes, enrollment invitation links, and bypass codes as confidential credentials, distribute them only through secure channels to intended recipients, and revoke them when no longer needed.
5.6 Authenticator Enrollment. End User authenticators are enrolled only through verified enrollment links or supervised enrollment flows provided by the Service. Customer shall not share enrollment QR codes or TOTP secrets between individuals; each authenticator enrollment is personal to a single individual (this is how the Service attributes shared-account logins to specific persons — see Section 9.4).
5.7 API Keys. The Service allows Administrators to create API keys for programmatic, read-only access to certain Workspace data (see Section 9.13). API keys are confidential credentials: Customer is responsible for their safekeeping, rotation, and prompt revocation, and for all requests made with them. API requests are rate-limited and logged.
6. Third-Party Authenticator Applications
6.1 The Service provisions a TOTP credential compatible with standard authenticator applications (for example Google Authenticator, Microsoft Authenticator, or Authy) and verifies the one-time codes generated by those applications or by hardware TOTP devices. Dynacop does not provide its own authenticator mobile application. End Users must obtain and use a third-party authenticator application (or hardware TOTP device) of their choice.
6.2 Third-party authenticator applications are governed solely by their own license terms and privacy policies. Dynacop is not responsible for their availability, accuracy, security, or clock synchronization. Loss of, or loss of access to, an authenticator device may prevent an End User from signing in until an Administrator resets that user’s authenticator or a bypass code is used.
7. CRITICAL ACKNOWLEDGMENTS — ACCESS AND LOCKOUT RISK
READ THIS SECTION CAREFULLY. IT DESCRIBES INHERENT RISKS OF LOGIN-ENFORCEMENT SOFTWARE AND CUSTOMER’S RESPONSIBILITIES IN MANAGING THEM.
7.1 Nature of the Software. The Software inserts itself into the Windows sign-in path. By design, it can delay, condition, or block interactive sign-in (at the console, the lock screen, and over Remote Desktop) to Protected Devices until multi-factor authentication succeeds. Customer expressly acknowledges and accepts that software of this nature carries an inherent risk that, due to misconfiguration, network unavailability, software defects, operating system changes or updates, incorrect offboarding, clock skew, loss of authenticator devices, or other causes, authorized users may be temporarily or persistently unable to sign in to Protected Devices (“lockout”) — including remote servers with no physical console access.
7.2 Fail Mode Configuration. The Software supports two failure behaviors when the Cloud Service cannot be reached, configurable per policy:
(a) Fail-open (default): if the Service is unreachable, multi-factor authentication is skipped and sign-in proceeds with standard Windows authentication only. Customer acknowledges that fail-open reduces security during outages: an attacker able to disrupt network connectivity may bypass MFA.
(b) Fail-closed: if the Service is unreachable, sign-in is denied unless the user has previously completed a verified login and has an offline verification secret cached on the device (where offline access is enabled by policy), or presents a valid one-time bypass code. Customer acknowledges that fail-closed increases lockout risk, particularly on devices without enrolled offline access and without accessible bypass codes.
Customer is solely responsible for choosing the fail mode appropriate to each device’s role and risk profile, and for understanding the trade-off described above.
7.3 Enforcement Mode. When enforcement mode is enabled, the Software’s credential provider filter disables other Windows credential providers, removing password-only sign-in on the device. Customer acknowledges that Microsoft’s guidance cautions against disabling system credential providers, and that combining enforcement mode with fail-closed behavior on a device with no offline access and no available recovery path can render interactive sign-in to that device impossible without using the recovery mechanisms described in Section 7.5 or reinstalling/repairing the operating system.
7.4 Coverage Limits — Authentication Paths Not Protected. The Software enforces MFA on interactive Windows sign-in (console, lock/unlock, and Remote Desktop through the Windows logon UI). Customer acknowledges that certain Windows authentication paths are, by operating-system design, outside the Software’s control and are NOT protected by it, including without limitation: network logons (SMB file access, drive mapping, WinRM, scheduled tasks, services, batch logons), Restricted Admin mode RDP, reconnection to existing sessions in some configurations, and authentication performed by other systems. Hardening these paths (for example via Group Policy) is Customer’s responsibility. The Software is one layer of defense and is not a substitute for domain hardening, endpoint protection, patching, backups, or network security.
7.5 Recovery and Break-Glass Obligations. Dynacop provides recovery mechanisms, including one-time bypass/recovery codes, offline access caching, policy toggles, documented registry-level disable procedures, and offboarding flows in which intentionally retired or removed devices are never subjected to fail-closed blocking. Customer is solely responsible for operating a break-glass procedure, including: generating and securely storing bypass codes before they are needed; maintaining at least one alternative administrative access path to critical servers (for example out-of-band console, hypervisor console, or a secondary access mechanism); testing recovery procedures; and following the documented offboarding order (retire, then uninstall, then delete) when decommissioning devices.
7.6 Windows Updates and Environment Changes. Customer acknowledges that Windows feature updates, security updates, third-party security software, or changes to authentication infrastructure may affect the operation of credential providers. Customer should validate sign-in behavior on representative devices after significant environment changes.
7.7 Session Handling. By policy, the MFA prompt is time-limited; on expiry during a Remote Desktop login, the RDP session is disconnected and must be re-established. Repeated failed MFA attempts trigger a temporary, automatically expiring lockout for the affected account on the affected device, per configured policy.
7.8 Attack Detection and Automated IP Blocking (“Shield”).
(a) The Agent observes failed and unauthenticated sign-in activity against Protected Devices — including console and Remote Desktop attempts and, where supported, network-path attempts such as SSH on Windows and SMB — and reports attack telemetry to the Service (Section 9.2(e)). Although the network authentication paths listed in Section 7.4 are not protected by Dynacop MFA, Shield may, where supported, observe failed attempts on those paths and apply IP-based blocking independently of MFA enforcement.
(b) Where Customer enables the automatic blocking policy (disabled by default), the Agent creates time-limited inbound block rules in the Windows Firewall of the Protected Device for source IP addresses whose failed attempts exceed Customer’s configured thresholds. Block durations escalate on repeated attacks up to a configured maximum, and persistently attacking addresses may receive long-duration blocks. Administrators may also add and remove blocks manually in the panel. Blocks are enforced on the device itself; expired or released blocks remove the corresponding firewall rule.
(c) Safeguards. Addresses on Customer’s safelist, addresses from which a recent successful sign-in was made, and (by default) private network addresses are not automatically blocked.
(d) Customer responsibility. Customer acknowledges that automated blocking can affect legitimate users who share a source address with an attacker (for example behind NAT, VPN concentrators, or office gateways), and that Customer is responsible for configuring thresholds and safelists appropriate to its environment. By enabling automatic blocking or creating manual blocks, Customer consents to the corresponding modification of Windows Firewall rules on its Protected Devices.
7.9 Acknowledgment. CUSTOMER ACKNOWLEDGES THE RISKS DESCRIBED IN THIS SECTION 7, AGREES THAT IT IS BEST PLACED TO MANAGE THEM THROUGH CONFIGURATION AND OPERATIONAL PRACTICES, AND AGREES THAT, TO THE MAXIMUM EXTENT PERMITTED BY LAW AND SUBJECT TO SECTION 14, DYNACOP IS NOT LIABLE FOR LOSSES ARISING FROM INABILITY TO ACCESS DEVICES, DATA, OR SYSTEMS WHERE CUSTOMER HAS NOT IMPLEMENTED AND MAINTAINED THE RECOVERY MEASURES DESCRIBED IN SECTION 7.5.
8. Automatic Updates
8.1 Consent to Automatic Updates. The Software includes the Updater, which periodically (approximately every five minutes) contacts the Cloud Service to check for Agent updates and, when an update is published and automatic updates are enabled for the device, downloads and installs the update silently, without further notice or interaction, including replacement of the credential provider component. BY INSTALLING THE SOFTWARE, CUSTOMER CONSENTS TO SUCH AUTOMATIC UPDATES.
8.2 Control. Automatic updates can be disabled per device by an Administrator in the administrative panel. Where automatic updates are disabled, Customer is responsible for applying updates manually in a timely manner; Dynacop may notify Administrators by email when updates are available or when automatic updates fail.
8.3 Integrity. Update packages are retrieved over TLS and verified against a cryptographic hash (SHA-256) published in a manifest authenticated to the enrolled device; downgrades are refused. Dynacop installer packages are digitally signed (Authenticode) with a certificate identifying Forty2 LLC as the publisher; Customer may verify signatures using standard Windows tooling as described on Dynacop’s security page.
8.4 Requirement to Update. Because the Software is security software, Dynacop may require that devices run a minimum supported version to continue using the Service, and may cease supporting versions that are outdated or insecure. Updates may add or modify features to address security, legal, compatibility, or operational requirements. Dynacop will not materially reduce the core functionality of a paid subscription during its current committed term, except where reasonably necessary to address a security risk, comply with law, or maintain compatibility, in which case Dynacop will provide reasonable notice where practicable. Updates are part of the Software and are governed by this Agreement.
9. Data Collection, Privacy, and Customer Data
9.1 Overview. Operating a login MFA service inherently requires processing information about devices, accounts, and sign-in events. This Section describes what the Software and the Service collect and how it is handled. Further detail is provided in the Privacy Policy and the DPA.
9.2 Data Collected from Protected Devices. The Agent transmits to the Cloud Service:
(a) Device identity: the device hostname; the Windows machine GUID (a unique installation identifier read from the Windows registry); operating system role information (whether the device is a domain controller); and the installed Agent version;
(b) Local account inventory: periodically, a list of local Windows accounts on the device — for each account, its username, security identifier (SID), type (local/domain), and enabled/disabled status. Built-in system accounts are excluded. The Agent does not mass-enumerate Active Directory: on domain controllers no account inventory is collected, and domain accounts are recorded individually only when they actually sign in. Account inventory synchronization into the panel is controlled by the auto-discovery policy;
(c) Sign-in events: for each protected sign-in attempt: the Windows username and SID, the account type, the session type (console or RDP), the one-time code entered (for verification), the sign-in UI language, the result and reason, timestamps, and — for RDP sessions — the connecting client’s IP address. The one-time code itself is processed transiently solely for verification and is not retained as part of the stored sign-in event;
(d) Operational events: heartbeats (device liveness), update check and installation outcomes (version from/to, result), and enrollment/deregistration events;
(e) Attack telemetry: failed and unauthenticated sign-in attempts against the device, including the source IP address, the targeted service (for example RDP or SSH), timestamps and attempt counts, a limited sample of attempted usernames, and resulting block and unblock events;
(f) Network posture: the device’s currently listening (open) TCP ports, collected passively and periodically from the operating system’s connection table (no active scanning is performed), and the device’s public IP address as observed by the Service.
9.3 Data Collected via the Panel and Service. The Service stores: Administrator and End User email addresses and display names; workspace and policy configuration; access grants; TOTP factor data; panel session records including IP address and browser user-agent; trusted-device records; audit logs of sign-in attempts and administrative actions (including the acting administrator’s email and IP address); and transactional email dispatch data.
9.4 Attribution of Shared Accounts. A distinguishing feature of the Service is that where multiple individuals share a single Windows account, the individually enrolled TOTP factor identifies which person performed each sign-in, and this attribution is recorded in the audit log. Customer is responsible for informing End Users of this attribution (Section 9.9).
9.5 Local Storage on Protected Devices. The Agent stores state locally under C:\ProgramData\Dynacop, including the device enrollment secret, cached policy, cached offline verification secrets, and hashed bypass codes — each encrypted at rest using the Windows Data Protection API (DPAPI, machine scope) — together with plaintext diagnostic log files (which may include usernames and sign-in flow details). Configuration values (backend URL, fail mode, enforcement flag) are stored in the Windows registry under HKLM\SOFTWARE\Dynacop. Diagnostic logs remain on the device and are not uploaded to the Service. Upon proper uninstallation, the Agent attempts to deregister the device from the Service and removes the C:\ProgramData\Dynacop state directory.
9.6 No Telemetry or Marketing Analytics. The Software contains no advertising, no marketing analytics, and no crash-reporting or telemetry frameworks beyond the operational data described in Section 9.2. The administrative panel does not embed third-party analytics, advertising trackers, external fonts, or external CDN resources, except (i) the bot-protection component described in Section 9.7(a) and (ii) map tiles loaded from the mapping provider described in Section 9.7(d) when an Administrator opens the panel’s map views.
9.7 Sub-Processors / Third-Party Services. Dynacop uses the following categories of third-party providers to operate the Service:
(a) Cloudflare, Inc. — network edge, TLS termination/proxying, and bot protection (Cloudflare Turnstile) on panel sign-in. When an Administrator signs in to the panel, a Turnstile challenge token and the client’s IP address are shared with Cloudflare for verification, and the Turnstile script is loaded from Cloudflare’s servers;
(b) a transactional email delivery provider (currently Mailtrap) — receives recipient email addresses and message content for the transactional emails described in Section 9.8;
(c) hosting and database infrastructure providers engaged by Dynacop (identified in the Privacy Policy);
(d) HERE — map tiles for the panel’s map views are loaded by the Administrator’s browser directly from HERE’s servers; as a technical consequence of that connection, the Administrator’s IP address and browser metadata reach HERE. Dynacop does not send usernames, sign-in records, or attacker IP lists to HERE;
(e) Stripe — payment processing for paid subscriptions; payment card data is collected and held by Stripe and does not reach Dynacop’s servers.
Dynacop may change or add sub-processors; the then-current list is maintained in the Privacy Policy or DPA. Dynacop does not sell Customer Data and does not share it with third parties for advertising purposes.
9.8 Transactional Email. The Service sends security and operational email notifications, including sign-in verification codes and links, enrollment invitations, access-granted/changed/revoked notices, authenticator-reset notices, team and delegation changes, agent update notices, and — where enabled — weekly security digest reports summarizing sign-in and attack activity (with per-customer breakdowns for MSPs). Digest emails contain aggregated summaries; raw attacker IP addresses and attempted usernames remain in the panel. These are service communications necessary for operation of the Service, not marketing.
9.9 Customer’s Responsibilities as Data Controller. As between the parties, Customer is the controller and Dynacop is the processor/service provider with respect to Customer Data processed by Dynacop solely to provide the Service on Customer’s documented instructions as embodied in this Agreement and Customer’s configuration (including End User identities, account inventories, and sign-in logs). Dynacop acts as an independent controller with respect to account administration, billing, fraud and abuse prevention, service security, legal compliance, and Dynacop’s own business communications, as further described in the Privacy Policy. Customer represents and warrants that it: (a) has the legal right and any required authorizations to install the Software on each Protected Device and to process its End Users’ and device data through the Service; (b) has provided all legally required notices to, and obtained any legally required consents from, End Users regarding authentication enforcement, sign-in logging, IP address collection, and shared-account attribution, in accordance with applicable data protection and employment law (including, where applicable, the EU/UK GDPR and the Turkish Personal Data Protection Law No. 6698 (KVKK)); and (c) will use the collected data only for lawful security and administration purposes.
9.10 Retention and Deletion. Audit and sign-in logs are retained for the operation of the Service and Customer’s security visibility; certain audit fields (for example the acting administrator’s email or the attempted username) are retained even after the related account or device record is disabled or deleted, in order to preserve the integrity of the audit trail. Deleting a Protected Device removes its access grants, discovered account records, and policies. Upon termination, Section 13.4 applies. Retention specifics are described in the Privacy Policy/DPA.
9.11 Security Measures. Dynacop implements technical and organizational measures appropriate to the nature of the Service, including: TLS encryption of data in transit between the Agent, the panel, and the Service; per-device HMAC-SHA256 request signing with timestamp and nonce; hashing of session tokens, claim codes, invitation tokens, and bypass codes at rest; email sign-in codes that are short-lived, single-use, attempt-limited, and stored only in hashed form; DPAPI encryption of secrets stored on Protected Devices; TOTP replay protection; configurable failed-attempt lockout; role-based access control in the panel; and redaction of sensitive values from diagnostic logs. No security measures are perfect; Dynacop does not warrant that the Service is immune from compromise (see Section 12). Dynacop will notify Customer of personal data breaches as required by applicable law and the DPA.
9.12 Service Data. Dynacop may collect and use technical and usage data (e.g., aggregate feature usage, performance and reliability metrics) to operate, secure, and improve the Software and the Service, provided such data is de-identified or aggregated when used outside the operation of Customer’s Workspace.
9.13 Threat Feed Export. The Service provides a read-only Threat Feed API through which Customer may export attack telemetry from its own Workspace(s): attacker IP addresses, attempt counts and times, targeted services, block status, targeted device names, and coarse geolocation. Attempted usernames are never included in the feed. Exports are authenticated with API keys (Section 5.7) and rate-limited; Customer may exclude individual Protected Devices from the feed. For MSP provider-scoped keys, feed records additionally identify the customer Workspaces targeted. Customer is solely responsible for its downstream use of exported data — including the effects of feeding exported addresses into its own firewalls or other blocking systems.
10. Customer Obligations and Acceptable Use
Customer shall:
(a) install the Software only on devices it owns or is expressly authorized to manage, and remove it promptly from devices for which such authorization ends;
(b) use the Service only to authenticate and manage access of individuals it is entitled to manage, and not for unlawful surveillance;
(c) maintain accurate device and user records in the Workspace, and promptly revoke access (grants, sessions, trusted devices, bypass codes, Claim Codes) for departing personnel;
(d) implement and maintain the break-glass and recovery measures described in Section 7.5;
(e) follow the documented offboarding sequence when decommissioning Protected Devices;
(f) keep its systems reasonably secure (patching, malware protection, backup), acknowledging that the Software depends on the integrity of the underlying operating system;
(g) ensure that time synchronization is reasonably maintained on Protected Devices and authenticator devices (TOTP is time-based); and
(h) comply with all applicable laws in its use of the Software and the Service.
11. Fees, Plans, and Billing
11.1 Use of the Service beyond any free tier requires an active subscription under the applicable Order or published plan. Fees, metering definitions (for example, billable users or billable devices), billing cycles, volume discounts, and payment terms are as set out in the Order or the pricing page in effect at the time of purchase.
11.2 Except where required by law or expressly stated in an Order, fees already charged are non-refundable. For month-to-month usage-based subscriptions, billable quantities may increase or decrease prospectively and are measured according to the billing rules stated in the applicable Order or published pricing page. Committed quantities under a fixed-term Order, if any, may not be reduced until renewal.
11.3 Fees are exclusive of taxes; Customer is responsible for all applicable taxes, duties, and withholdings, other than taxes on Dynacop’s income.
11.4 Dynacop may suspend or limit the Service for non-payment after reasonable notice. A suspension solely for non-payment is implemented in a non-locking state: it does not cause Protected Devices to deny Windows sign-ins solely because the subscription is unpaid. During such a suspension, Dynacop may suspend access to the administrative panel, reporting, the Threat Feed API, update distribution, and other cloud features.
11.5 Dynacop may change pricing with effect from the next renewal term upon reasonable advance notice.
12. DISCLAIMER OF WARRANTIES
12.1 EXCEPT AS EXPRESSLY SET OUT IN THIS AGREEMENT OR AN ORDER, THE SOFTWARE, THE SERVICE, AND THE DOCUMENTATION ARE PROVIDED “AS IS” AND “AS AVAILABLE”, WITH ALL FAULTS, AND WITHOUT WARRANTY OF ANY KIND. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, DYNACOP AND ITS LICENSORS DISCLAIM ALL WARRANTIES AND CONDITIONS, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, QUIET ENJOYMENT, ACCURACY, AND NON-INFRINGEMENT.
12.2 WITHOUT LIMITING THE FOREGOING, DYNACOP DOES NOT WARRANT THAT: (a) THE SOFTWARE OR THE SERVICE WILL BE UNINTERRUPTED, TIMELY, ERROR-FREE, OR AVAILABLE AT ANY PARTICULAR TIME; (b) ALL SIGN-IN ATTEMPTS WILL BE CORRECTLY ALLOWED OR DENIED; (c) THE SOFTWARE WILL PREVENT ALL UNAUTHORIZED ACCESS TO PROTECTED DEVICES (INCLUDING VIA THE AUTHENTICATION PATHS DESCRIBED IN SECTION 7.4 OR DURING FAIL-OPEN OPERATION); (d) THE SOFTWARE WILL BE COMPATIBLE WITH ALL WINDOWS VERSIONS, UPDATES, CONFIGURATIONS, OR THIRD-PARTY SOFTWARE; OR (e) THE SERVICE IS INVULNERABLE TO COMPROMISE.
12.3 DYNACOP MAKES NO REPRESENTATION THAT THE SERVICE, BY ITSELF, SATISFIES ANY SPECIFIC REGULATORY, CERTIFICATION, OR COMPLIANCE REQUIREMENT APPLICABLE TO CUSTOMER (INCLUDING ANY AUDIT OR CERTIFICATION FRAMEWORK), UNLESS EXPRESSLY STATED IN WRITING BY DYNACOP.
12.4 SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OF CERTAIN WARRANTIES; IN THAT CASE THE ABOVE EXCLUSIONS APPLY TO THE MAXIMUM EXTENT PERMITTED. STATUTORY RIGHTS OF CONSUMERS, WHERE APPLICABLE AND NON-WAIVABLE, ARE NOT AFFECTED.
13. Term, Suspension, and Termination
13.1 Term. This Agreement takes effect upon Customer’s first acceptance (Section 1 preamble) and continues until all subscriptions expire or the Agreement is terminated as set out below.
13.2 Termination for Cause. Either party may terminate this Agreement if the other party materially breaches it and fails to cure the breach within thirty (30) days of written notice, or immediately upon the other party’s insolvency to the extent permitted by law. Dynacop may terminate immediately upon Customer’s breach of Sections 3, 4, or 10(a)–(b).
13.3 Suspension. Dynacop may suspend or restrict access to the Service (in whole or in part) with immediate effect where reasonably necessary to: (a) address a security threat to the Service or other tenants; (b) comply with law; or (c) respond to Customer’s material breach, including non-payment. Dynacop will use reasonable efforts to notify Customer and to limit the scope and duration of the suspension. Customer acknowledges that suspension of the Service affects Protected Devices according to their configured fail mode (Section 7.2), and that maintaining recovery mechanisms under Section 7.5 remains Customer’s responsibility during any suspension. A suspension solely for non-payment is subject to Section 11.4 and will not invoke fail-closed denial solely because of non-payment.
13.4 Effect of Termination. Upon expiry or termination: (a) all licenses and access rights end; (b) Customer shall promptly follow the documented offboarding procedure and uninstall the Software from all Protected Devices (proper uninstallation deregisters the device and removes local Dynacop state); (c) upon Customer’s written request made within thirty (30) days, Dynacop will make available an export of Customer’s Workspace data in a reasonable machine-readable format, to the extent supported; and (d) thereafter Dynacop will delete or anonymize Customer Data in accordance with the Privacy Policy/DPA, save for data Dynacop is legally required or permitted to retain (including minimal audit records).
13.5 Survival. Sections 1, 3.5, 4, 7.9, 9 (as applicable to retained data), 12, 14, 15, 16, 17, 18, and 19 survive termination.
14. LIMITATION OF LIABILITY
14.1 Exclusion of Indirect Damages. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL EITHER PARTY (OR DYNACOP’S LICENSORS OR SUPPLIERS) BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, GOODWILL, BUSINESS INTERRUPTION, LOSS OF USE, OR LOSS OR CORRUPTION OF DATA, ARISING OUT OF OR RELATED TO THIS AGREEMENT, HOWEVER CAUSED AND UNDER ANY THEORY OF LIABILITY (CONTRACT, TORT, NEGLIGENCE, STRICT LIABILITY, OR OTHERWISE), EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
14.2 Specific Acknowledged Risks. WITHOUT LIMITING SECTION 14.1 AND SUBJECT TO SECTION 14.4, DYNACOP SHALL NOT BE LIABLE FOR DAMAGES ARISING FROM: (a) INABILITY OF ANY PERSON TO SIGN IN TO A PROTECTED DEVICE (LOCKOUT), WHERE CUSTOMER FAILED TO IMPLEMENT OR MAINTAIN THE RECOVERY MEASURES DESCRIBED IN SECTION 7.5; (b) UNAUTHORIZED ACCESS OCCURRING THROUGH AUTHENTICATION PATHS NOT PROTECTED BY THE SOFTWARE (SECTION 7.4) OR DURING FAIL-OPEN OPERATION SELECTED OR DEFAULTED UNDER CUSTOMER’S POLICY; (c) CUSTOMER’S CONFIGURATION CHOICES, MISUSE, OR FAILURE TO FOLLOW THE DOCUMENTATION; (d) THIRD-PARTY AUTHENTICATOR APPLICATIONS, OPERATING SYSTEM CHANGES, OR OTHER THIRD-PARTY PRODUCTS OR SERVICES; OR (e) FORCE MAJEURE EVENTS.
14.3 Cap. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT SHALL NOT EXCEED THE TOTAL FEES PAID OR PAYABLE BY CUSTOMER TO DYNACOP FOR THE SERVICE IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE FIRST EVENT GIVING RISE TO LIABILITY (OR, IF CUSTOMER USES ONLY A FREE TIER, ONE HUNDRED (100) US DOLLARS OR ITS EQUIVALENT).
14.4 Exceptions. NOTHING IN THIS AGREEMENT EXCLUDES OR LIMITS LIABILITY THAT CANNOT BE EXCLUDED OR LIMITED UNDER APPLICABLE LAW, INCLUDING LIABILITY FOR WILLFUL MISCONDUCT OR GROSS NEGLIGENCE (WHERE NON-EXCLUDABLE), DEATH OR PERSONAL INJURY CAUSED BY NEGLIGENCE, OR FRAUD. THE CAP IN SECTION 14.3 DOES NOT APPLY TO CUSTOMER’S PAYMENT OBLIGATIONS OR TO CUSTOMER’S BREACH OF SECTIONS 3 OR 4.
14.5 Allocation of Risk. THE PARTIES AGREE THAT THE DISCLAIMERS AND LIMITATIONS IN SECTIONS 7, 12, AND 14 REFLECT A REASONABLE ALLOCATION OF RISK GIVEN THE NATURE AND PRICE OF THE SERVICE, AND THAT DYNACOP WOULD NOT PROVIDE THE SOFTWARE AND SERVICE ON THESE TERMS WITHOUT THEM. THEY APPLY EVEN IF A REMEDY FAILS OF ITS ESSENTIAL PURPOSE.
15. High-Risk Use
The Software and the Service are not designed, tested, or licensed for use in environments where a failure of authentication or access control could lead to death, personal injury, or severe physical or environmental damage, including life-support systems, emergency services dispatch, nuclear facilities, aircraft or air-traffic operation, or weapons systems (“High-Risk Use”). Customer shall not use the Software or the Service for High-Risk Use, and Dynacop disclaims all liability arising from such use.
16. Indemnification
16.1 By Customer. Customer shall defend, indemnify, and hold harmless Dynacop, its affiliates, and their officers, directors, employees, and agents from and against any third-party claim, and resulting damages, costs, and reasonable attorneys’ fees, arising out of: (a) Customer’s installation of the Software on devices it was not authorized to manage; (b) Customer’s failure to provide legally required notices to, or obtain legally required consents from, End Users (Section 9.9); (c) Customer Data or Customer’s use of the Service in violation of law or this Agreement; or (d) claims by Customer’s own customers or end users arising from Customer’s breach of this Agreement, unauthorized installation, unlawful processing, misrepresentations, modifications, or acts or omissions outside the documented functionality of the Software and the Service.
16.2 By Dynacop. For paid subscriptions, Dynacop shall defend Customer against any third-party claim alleging that the Software or the Service, as provided by Dynacop and used in accordance with this Agreement, infringes that third party’s intellectual property rights, and shall indemnify Customer against damages and costs finally awarded or agreed in settlement. If such a claim arises or is likely, Dynacop may, at its option: procure the right for Customer to continue use; modify or replace the affected item without material loss of functionality; or terminate the affected subscription and refund prepaid, unused fees. Dynacop has no obligation for claims arising from: combination with items not supplied by Dynacop; modifications not made by Dynacop; use in breach of this Agreement or the Documentation; or use of superseded versions where the current version would avoid the claim. Dynacop’s obligations under this Section 16.2 are subject to the cap in Section 14.3; for free-tier use, Dynacop’s obligation is limited to exercising one of the options described above. This Section 16.2 states Dynacop’s entire liability and Customer’s exclusive remedy for intellectual-property infringement claims.
16.3 Procedure. The indemnified party shall promptly notify the indemnifying party of the claim (delay only relieves the indemnifying party to the extent it is prejudiced), grant sole control of the defense and settlement (provided any settlement fully releases the indemnified party without admission of fault), and provide reasonable cooperation at the indemnifying party’s expense.
17. Confidentiality
17.1 “Confidential Information” means non-public information disclosed by one party to the other that is designated confidential or that reasonably should be understood to be confidential given its nature and the circumstances, including the Software’s non-public technical details, security mechanisms, Claim Codes and other credentials, Customer Data, pricing, and business plans. Confidential Information excludes information that is or becomes public without breach, was lawfully known without restriction before disclosure, is independently developed, or is lawfully received from a third party without restriction.
17.2 Each party shall use the other’s Confidential Information only to perform under this Agreement, protect it with at least reasonable care, and disclose it only to personnel, affiliates, and contractors with a need to know who are bound by confidentiality obligations at least as protective. A party may disclose Confidential Information to the extent required by law or court order, with prior notice to the other party where legally permitted.
17.3 Customer shall not publicly disclose non-public details of vulnerabilities in the Software or the Service without first giving Dynacop a reasonable opportunity to remediate (coordinated disclosure). Good-faith security research on Customer’s own Protected Devices is not restricted by this Section.
18. Feedback; Publicity; Open Source
18.1 Feedback. If Customer provides suggestions, ideas, or other feedback about the Software or the Service, Dynacop may use it without restriction or obligation, provided it does not identify Customer without consent.
18.2 Publicity. Neither party may use the other’s name or logo publicly without prior written consent, except that Dynacop may identify Customer as a customer in factual lists with Customer’s consent.
18.3 Open-Source Components. The Software and the Service include third-party and open-source components licensed under their own terms. To the extent such terms conflict with this Agreement for those components, the applicable open-source terms govern for those components. A list of components and licenses is available in the Documentation or upon request.
19. General
19.1 Compliance and Export. Each party shall comply with applicable export control and sanctions laws. Customer represents that it is not located in, and will not use the Software or Service in or for the benefit of, any embargoed jurisdiction or prohibited party.
19.2 Governing Law; Venue. This Agreement is governed by the laws of the State of New Mexico, United States, excluding its conflict-of-laws rules and the UN Convention on Contracts for the International Sale of Goods. The state and federal courts located in Bernalillo County, New Mexico have exclusive jurisdiction over disputes arising out of or relating to this Agreement, and each party consents to personal jurisdiction and venue there, without prejudice to mandatory consumer venue rules where applicable.
19.3 Assignment. Customer may not assign or transfer this Agreement without Dynacop’s prior written consent, except to a successor in connection with a merger, reorganization, or sale of substantially all assets, upon notice to Dynacop. Dynacop may assign this Agreement to an affiliate or in connection with a corporate transaction. Any prohibited assignment is void.
19.4 Force Majeure. Neither party is liable for delay or failure to perform (other than payment obligations) caused by events beyond its reasonable control, including natural disasters, war, terrorism, labor disputes, governmental action, power or internet failures, and failures of third-party infrastructure providers.
19.5 Notices. Legal notices to Dynacop must be sent to Forty2 LLC, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States, with a copy by email to legal@dynacop.com. Notices to Customer may be sent to the Administrator email addresses on file or displayed in the administrative panel, and are deemed given when sent.
19.6 Changes to this Agreement. Dynacop may update this Agreement from time to time. For material changes, Dynacop will provide notice (for example, by email to Administrators or in the panel) at least thirty (30) days before the changes take effect for existing subscriptions. Continued use of the Software or the Service after the effective date constitutes acceptance. If Customer objects to a material change, Customer may terminate the affected subscription effective as of the change’s effective date and receive a pro-rata refund of prepaid, unused fees.
19.7 Severability; Waiver. If any provision is held unenforceable, it will be enforced to the maximum extent permissible and the remainder remains in effect. Failure to enforce a provision is not a waiver.
19.8 Entire Agreement; Order of Precedence. This Agreement, together with the Orders, the Privacy Policy, and the DPA, constitutes the entire agreement between the parties regarding its subject matter and supersedes all prior or contemporaneous agreements and understandings. In the event of conflict: (a) the DPA prevails with respect to the processing and protection of personal data; (b) the applicable Order prevails with respect to commercial terms, subscription quantities, fees, and service-specific commitments; (c) this Agreement prevails over the Documentation; and (d) the Documentation applies to operational and technical matters not addressed above. Terms in Customer purchase orders or vendor forms are void even if signed after this Agreement, unless expressly agreed in writing by Dynacop.
19.9 Independent Contractors. The parties are independent contractors; this Agreement creates no partnership, joint venture, agency, or employment relationship.
19.10 Language. This Agreement is executed in English. Translations (including Turkish) may be provided for convenience; the English version prevails in case of discrepancy, except where mandatory local law requires otherwise.
19.11 Third-Party Beneficiaries. There are no third-party beneficiaries to this Agreement, except that Dynacop’s licensors may enforce the protections expressly stated in their favor.
20. Contact
Forty2 LLC
1209 Mountain Road Pl NE, Ste N
Albuquerque, NM 87110, United States
Website: https://dynacop.com
Support: support@dynacop.com · Legal: legal@dynacop.com · Privacy: privacy@dynacop.com · Security (vulnerability reports): security@dynacop.com (see /.well-known/security.txt)
Changelog (informational, not part of the Agreement)
v2.0 (18 July 2026) — Added: §5.7 API Keys · §7.8 Attack Detection and Automated IP Blocking (Windows Firewall modification, safeguards, customer consent; former §7.8 renumbered §7.9) · §9.2(e) attack telemetry (attacker IPs + attempted-username samples) and §9.2(f) network posture (open TCP ports, public IP) · §9.7(d) HERE map tiles and §9.7(e) Stripe · §9.8 weekly security digests · §9.13 Threat Feed Export. Updated: §8.3 code signing is live (Authenticode, publisher Forty2 LLC) · §9.6 panel external-resource exception for map tiles · §11.4 non-payment does not lock device sign-ins · §20 privacy@ and security@ contacts (security.txt). §13.5 survival reference updated (7.8→7.9). Post-review amendments (same version): preamble personal-use definition of Customer · §3.4(b) practical MSP flow-down · §6.1 TOTP provisioning wording · §7.8(a) MFA/Shield coverage bridge · §8.4 paid-term feature commitment · §9.2(c) transient processing of entered codes · §9.9 dual controller/processor roles · §9.11 precise hashing language · §11.2 monthly usage-based quantities · §11.4 + §13.3 non-locking suspension for non-payment · §16.1(d)/§16.2 indemnity scope · §19.8 layered order of precedence.
© 2026 Forty2 LLC. Dynacop and the Dynacop logo are trademarks of Forty2 LLC. Windows, Active Directory, and Remote Desktop are trademarks of Microsoft Corporation. All other trademarks are the property of their respective owners.