End-User Terms
End-User Terms for the Pylon platform (Command, Scout, and Anvil). The terms governing customer use of the platform under an Order or a channel partner agreement.
Plain-language summary. These terms govern how your organization uses the Pylon platform. They apply whether you buy from Pylon directly or through a channel partner. Individual users acknowledge these terms at first login; that acknowledgment does not create a separate agreement.
Advosec, LLC, a Pennsylvania limited liability company, doing business as The Pylon Group ("Pylon")
These End-User Terms ("Terms") govern access to and use of the Pylon platform and its Command, Scout, and Anvil modules and related services (the "Services") by the organization identified in an Order (the "Customer").
How these Terms apply
1.1 Incorporation. These Terms apply to Customer's use of the Services in every case, whether Customer obtains the Services directly from Pylon or through an authorized Pylon channel partner ("Partner"). Where Customer obtains the Services through a Partner, these Terms are incorporated into the agreement between Customer and that Partner and flow through to Customer as the terms governing use of the Services.
1.2 Order of precedence. In a conflict, the following order controls: (a) a written agreement signed by Pylon and Customer that expressly amends these Terms for that Customer; (b) the Order; (c) a Data Processing Addendum or Business Associate Agreement executed for that Customer; (d) these Terms; (e) any Acceptable Use Policy Pylon provides to Customer; (f) any documentation. Where Customer purchases through a Partner, the commercial terms of the Customer-Partner agreement (price, term, invoicing, service scope, renewal) govern the commercial relationship between Customer and Partner, and these Terms govern use of the Services.
1.3 Version control. These Terms are versioned and dated. The version identified in an Order, or attached as an exhibit to a Customer-Partner agreement, is the version that applies to that Customer for the duration of the then-current subscription or evaluation term ("Pinned Version"), regardless of later changes to the published Terms. Section 22 governs changes.
1.4 No contract formed by individual users. Individual users accessing the Services acknowledge these Terms at first login. That acknowledgment is not a separate agreement and does not modify, supplement, or supersede these Terms or the Customer's Order, and no individual user has authority to bind Customer by that acknowledgment. Individual users have the obligations stated in Section 4.3 and no others.
The Services
2.1 Grant. Subject to these Terms and payment of applicable fees, Pylon grants Customer a non-exclusive, non-transferable, non-sublicensable right during the Term to access and use the Services for Customer's internal business purposes, and for the benefit of Customer's affiliates identified in the Order.
2.2 Scope. The modules, quantities, usage limits, and any capacity metrics (such as employee count for Command, vendor count for Scout, or target count for Anvil) are stated in the Order. Use beyond the ordered scope requires an amended Order.
2.3 Restrictions. Customer will not, and will not permit any person to: (a) resell, sublicense, rent, or provide the Services to a third party except as expressly permitted for a Partner under its Partner agreement; (b) reverse engineer, decompile, or attempt to derive source code, except to the extent that restriction is unenforceable by law; (c) copy, modify, or create derivative works of the Services; (d) use the Services to build a competing product or to benchmark for publication without Pylon's written consent; (e) circumvent usage limits or access controls; (f) remove proprietary notices; or (g) use the Services in violation of law or the Acceptable Use Policy.
2.4 Changes to the Services. Pylon may modify or improve the Services provided it does not materially reduce the core functionality Customer has ordered during the then-current Term. Pylon will give at least thirty (30) days' notice before deprecating a material feature, and where practicable will provide a substantially equivalent replacement.
Accounts and access
3.1 Authorized Users. Customer may permit its employees and contractors ("Authorized Users") to access the Services. Customer is responsible for its Authorized Users' compliance with these Terms and for all activity under its accounts.
3.2 Credentials. Customer will require unique credentials for each Authorized User, will not permit credential sharing, and will enable multi-factor authentication where offered. Customer will notify Pylon promptly on becoming aware of unauthorized access.
3.3 Administrators. Customer will designate at least one administrator with authority to manage users, configuration, connected systems, and data export. Pylon may rely on instructions from a designated administrator.
Customer responsibilities
4.1 Acceptable use. Customer and its Authorized Users will comply with the use restrictions in Section 2.3 and the data restrictions in Section 6, and with any written Acceptable Use Policy Pylon provides to Customer. Pylon may update its Acceptable Use Policy on notice; an update will not materially expand Customer's obligations during the then-current Term, and the restrictions in Sections 2.3 and 6 control in a conflict.
4.2 Customer systems. Customer is responsible for its own network, devices, identity provider, and the security of the systems it connects to the Services.
4.3 Individual user obligations. Each Authorized User will protect their credentials, use the Services only for the Customer's authorized purposes, refrain from uploading data outside the categories Customer has approved, and refrain from sharing access with any person who is not an Authorized User.
Customer Data
5.1 Definition. "Customer Data" means data, records, documents, configurations, and outputs that Customer or its Authorized Users submit to the Services, or that the Services ingest from systems Customer connects.
5.2 Ownership. As between the parties, Customer owns all right, title, and interest in Customer Data. Pylon acquires no ownership interest in it.
5.3 License to Pylon. Customer grants Pylon a limited, non-exclusive license to host, process, transmit, display, and otherwise use Customer Data solely to provide, secure, support, and maintain the Services for Customer, and as otherwise permitted in these Terms.
5.4 Service data. Pylon may generate and use aggregated, de-identified operational and usage data to operate, secure, benchmark, and improve the Services, provided that such data does not identify Customer, any Authorized User, any individual, or any of Customer's third parties, and is not disclosed in a form from which Customer could reasonably be identified.
5.5 Return and deletion. During the Term and for thirty (30) days after expiration or termination, Customer may export Customer Data in a machine-readable format at no charge. Pylon will delete Customer Data within ninety (90) days after that period, except for backups deleted on their ordinary cycle and records Pylon is required to retain by law. Pylon will confirm deletion in writing on request.
Data Customer must not submit
6.1 Prohibited data. Unless Pylon has expressly agreed in writing for that Customer, Customer will not submit to the Services, and will configure connected systems so that the Services do not ingest: (a) protected health information as defined under HIPAA ("PHI"); (b) cardholder data subject to PCI DSS; (c) government-issued identification numbers, financial account numbers, or biometric identifiers; (d) data subject to ITAR, EAR, or classified handling requirements; or (e) special categories of personal data under applicable data protection law.
6.2 Healthcare customers. The Services are designed to process security, compliance, and vendor-risk metadata, not clinical or patient data. Where Customer is a covered entity or business associate under HIPAA, and Customer requires the Services to process PHI, the parties will execute a Business Associate Agreement before any PHI is submitted, and Pylon will process PHI only in accordance with that agreement. Absent an executed Business Associate Agreement, Customer will not submit PHI and Pylon has no obligations under HIPAA with respect to the Services.
6.3 Configuration responsibility. Customer is responsible for scoping its connected systems and integration configurations so that data excluded under Section 6.1 is not transmitted to the Services. Pylon will provide reasonable configuration guidance on request but does not inspect Customer Data for prohibited categories.
Connected systems and integrations
7.1 Authorization. Where Customer connects a third-party system, Customer authorizes Pylon to access that system using the credentials, tokens, or permissions Customer provides, solely to provide the Services. Customer represents it has the authority to grant that access.
7.2 Third-party terms. Third-party systems are governed by Customer's own agreements with those providers. Pylon is not responsible for a third-party system's availability, accuracy, or changes to its interfaces, and is not liable for a third-party provider's suspension of access.
7.3 Least privilege. Pylon will request the minimum permissions reasonably necessary for the applicable functionality and will document the permissions each integration requires.
AI-assisted features
8.1 What they do. The Services include AI-assisted features, including Hudson, which generate drafts, summaries, findings, recommendations, scores, and reports from Customer Data and from documents Customer supplies.
8.2 Human review required. AI-generated output is a draft for review by a qualified person. Customer will not rely on AI-generated output as a determination of compliance, a security assessment conclusion, a control attestation, a legal or regulatory opinion, or professional advice, and will have a qualified person review and approve any output before Customer relies on it or provides it to a third party, a regulator, an auditor, or a board.
8.3 Accuracy. AI-generated output may be incomplete or incorrect. Pylon does not warrant the accuracy, completeness, or fitness of AI-generated output and, to the extent permitted by law, disclaims liability arising from Customer's reliance on it without the review required by Section 8.2.
8.4 Model training. Pylon will not use Customer Data to train, fine-tune, or otherwise improve any general-purpose or foundation model, and will not permit its model providers to do so. Pylon's use of Customer Data is limited to providing the Services to Customer.
8.4a Optional features. Features that transmit Customer Data to an additional subprocessor, including meeting and call transcription, are disabled by default and may be enabled only by a Customer administrator. Where such a feature is not enabled, no Customer Data is transmitted to the subprocessors supporting it.
8.5 Subprocessing. AI-assisted features rely on third-party model providers identified in the subprocessor list maintained in Pylon's Data Processing Addendum at https://thepylongroup.com/legal/data-processing-addendum/. Those providers are subprocessors under that addendum.
Security
9.1 Program. Pylon will maintain an information security program with administrative, technical, and physical safeguards appropriate to the nature of the data processed and consistent with generally accepted industry practice, including access control, encryption of Customer Data in transit and at rest, logging and monitoring, vulnerability management, secure development practices, and personnel background screening and training.
9.2 Incident notification. Pylon will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting Customer Data, will provide information reasonably available about scope and remediation as the investigation proceeds, and will cooperate with Customer's reasonable investigation and notification obligations. "Security Incident" means a confirmed unauthorized access to, acquisition of, or disclosure of Customer Data in Pylon's custody. Where the Security Incident involves personal data, the notification obligations in the Data Processing Addendum apply and run on the same seventy-two (72) hour standard.
9.3 Audit artifacts. On request, and no more than once per twelve (12) month period unless required by a regulator or following a Security Incident, Pylon will provide its then-current third-party audit report or, where none exists, will complete a reasonable security questionnaire. Pylon will state its current attestation status in writing on request.
9.4 Penetration testing. Customer may not conduct penetration testing, vulnerability scanning, or load testing against the Services without Pylon's prior written consent and an agreed scope and window.
Privacy
10.1 Data protection. Where Pylon processes personal data on Customer's behalf, the parties' Data Processing Addendum at https://thepylongroup.com/legal/data-processing-addendum/ applies and is incorporated by reference. Pylon's privacy notice is available at https://thepylongroup.com/privacy/.
10.2 Location. Customer Data is hosted in the United States unless the Order states otherwise.
10.3 Subprocessors. Pylon maintains a current subprocessor list within its Data Processing Addendum at https://thepylongroup.com/legal/data-processing-addendum/ and will give at least thirty (30) days' notice before adding a subprocessor that processes Customer Data. Customer may object on reasonable data protection grounds, and the parties will work in good faith toward a resolution; if none is reached, Customer may terminate the affected Services without penalty.
Confidentiality
Each party will protect the other's Confidential Information with at least reasonable care, use it only for purposes of these Terms, and disclose it only to personnel and advisors bound by comparable obligations. These obligations do not apply to information that is public through no fault of the recipient, independently developed, or rightfully received from a third party. Compelled disclosure is permitted with prompt notice where lawful. Customer Data is Customer's Confidential Information.
Service levels and support
12.1 Availability and support. Availability commitments, support scope, and response targets are stated in the Order or the applicable service level exhibit. Where Customer purchased through a Partner, the Partner provides first-line support and Pylon provides escalated support to the Partner.
12.2 Exclusions. Service level commitments exclude scheduled maintenance, emergency maintenance, Customer or third-party system failures, and events outside Pylon's reasonable control.
Evaluations, proofs of concept, and trials
13.1 Application. This Section applies where the Order designates the engagement as an evaluation, proof of concept, pilot, or trial ("Evaluation").
13.2 Term. An Evaluation runs for the period stated in the Order and ends automatically at the end of that period unless the parties agree in writing to extend or convert it.
13.3 Service levels. Unless the Order states otherwise, availability commitments and service credits do not apply during an Evaluation. Pylon will use commercially reasonable efforts to make the Services available and will provide support at the level stated in the Order.
13.4 Scope. Customer will limit the Evaluation to the systems, users, and data categories identified in the Order. Section 6 applies to an Evaluation in full.
13.5 Conversion. The Order will state the price and terms on which the Evaluation converts to a production subscription and the notice required to convert or decline. Absent a stated conversion price, conversion is at Pylon's then-current published list price for the applicable scope.
13.6 End of Evaluation. At the end of an Evaluation that does not convert, Section 5.5 governs export and deletion, and Pylon may deprovision the tenant after the export period.
13.7 Warranties. Except for Sections 9, 10, and 11, the Services are provided during an Evaluation "as is," and Pylon's warranties in Section 15 do not apply.
Fees
Fees, invoicing, payment terms, and renewal are stated in the Order or, where Customer purchased through a Partner, in Customer's agreement with that Partner. Pylon has no right to invoice Customer directly for Services purchased through a Partner, and Customer's payment obligations run to the Partner.
Warranties and disclaimers
15.1 Mutual. Each party warrants it has authority to enter into these Terms.
15.2 Pylon. Pylon warrants that during the Term the Services will perform materially in accordance with their documentation, and that Pylon will not knowingly introduce malicious code into the Services. Customer's exclusive remedy for breach of this warranty is Pylon's correction of the non-conformity or, if Pylon cannot correct it within thirty (30) days of notice, termination of the affected Services and a pro-rata refund of prepaid fees for the unused period, paid through the Partner where applicable.
15.3 Disclaimer. Except as expressly stated, the Services are provided without warranties of any kind, express or implied, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement. Pylon does not warrant that the Services will be uninterrupted or error-free, or that use of the Services will result in compliance with any law, standard, or framework.
15.4 Not professional advice. The Services, including AI-assisted output, do not constitute legal, regulatory, audit, accounting, or professional security advice, and are not a substitute for Customer's own judgment or for a qualified assessor's independent determination.
Indemnification
16.1 By Pylon. Pylon will defend Customer against a third-party claim that the Services, as provided by Pylon and used in accordance with these Terms, infringe that third party's intellectual property rights, and will pay damages finally awarded or amounts in a settlement Pylon approves. Pylon may procure the right to continue use, modify the Services to be non-infringing, or terminate the affected Services and refund prepaid unused fees. Pylon has no obligation for a claim arising from Customer Data, Customer's combination of the Services with items not supplied by Pylon, or use in breach of these Terms.
16.2 By Customer. Customer will defend Pylon against a third-party claim arising from Customer Data or from Customer's use of the Services in breach of Section 2.3, Section 4, or Section 6, and will pay damages finally awarded or amounts in a settlement Customer approves.
16.3 Process. The indemnified party will give prompt notice, tender control of the defense, and provide reasonable cooperation at the indemnifying party's expense. The indemnifying party will not settle in a way that admits liability or imposes an obligation on the indemnified party without consent.
Limitation of liability
17.1 Exclusion. Neither party is liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, or goodwill, even if advised of the possibility.
17.2 Cap. Except as stated in Section 17.3, each party's total liability arising out of or related to these Terms will not exceed the fees paid or payable for the Services in the twelve (12) months preceding the event giving rise to the claim.
17.3 Exceptions. The exclusion in 17.1 and the cap in 17.2 do not apply to: (a) Customer's payment obligations; (b) either party's indemnification obligations under Section 16; (c) a party's breach of Section 11; (d) Pylon's breach of Section 9 or Section 10, for which each party's liability will not exceed the greater of the limits of insurance actually maintained by that party at the time the claim is made or three (3) times the fees paid or payable in the preceding twelve (12) months; or (e) a party's gross negligence, willful misconduct, or fraud.
17.4 Evaluations. For an Evaluation, Pylon's total liability will not exceed the fees paid for that Evaluation, except for the matters in Section 17.3(c), (d), and (e).
Suspension
Pylon may suspend access, in whole or in part, on notice where continued access presents a material security risk, where Customer's use violates Section 2.3 or Section 6 and is not remedied within a reasonable period after notice, or where required by law. Pylon will limit any suspension to the scope and duration reasonably necessary and will restore access promptly once the cause is resolved. Where Customer purchased through a Partner, Pylon will notify the Partner and, where practicable, Customer.
Term and termination
19.1 Term. These Terms apply for the subscription or Evaluation term stated in the Order and any renewal.
19.2 Termination for cause. Either party may terminate for the other's material breach not cured within thirty (30) days after written notice.
19.3 Effect. On termination, Customer's right to access the Services ends, Section 5.5 governs export and deletion, and Sections 5.2, 6, 11, 15.3, 16, 17, 20, and 21 survive.
19.4 Partner-sourced subscriptions. Where Customer purchased through a Partner and the Pylon-Partner relationship ends, Customer's subscription continues on these Terms through the remainder of its then-current term. Pylon will work with Customer and the Partner in good faith on continuity, including transition to another Partner or to a direct relationship with Pylon at Customer's election.
Intellectual property and feedback
Pylon and its licensors retain all right, title, and interest in the Services, including all software, models, methods, documentation, and improvements. Customer grants Pylon a perpetual, irrevocable, royalty-free license to use feedback and suggestions Customer provides, without attribution or compensation, provided Pylon does not identify Customer as the source without consent and does not incorporate Customer Data.
General
21.1 Governing law. These Terms are governed by the laws of the Commonwealth of Pennsylvania, without regard to conflict of laws principles, and the parties consent to exclusive jurisdiction and venue in the state and federal courts located in Delaware County, Pennsylvania.
21.2 Publicity. Pylon will not use Customer's name or logo in marketing without Customer's prior written consent.
21.3 Assignment. Neither party may assign these Terms without the other's consent, except to a successor in a merger or sale of substantially all assets, on notice.
21.4 Notices. Notices must be in writing and are effective on delivery to the addresses stated in the Order. Notices to Pylon may be sent to [email protected], attention Legal, or to the mailing address Pylon designates in writing. Notices to Customer may be sent to the contact designated in the Order or, absent one, to Customer's administrative account contact.
21.5 Force majeure. Neither party is liable for delay due to events beyond its reasonable control, provided it notifies the other promptly and uses commercially reasonable efforts to resume.
21.6 Severability and waiver. If a provision is unenforceable it is enforced to the maximum extent permissible or severed, and the remainder stays in effect. No waiver is effective unless in writing.
21.7 Entire agreement. These Terms, with the Order and any incorporated addenda, are the entire agreement on their subject matter and supersede prior or contemporaneous agreements on that subject matter.
Changes to these Terms
22.1 Published changes. Pylon may publish updated Terms. An update takes effect for a Customer at the start of that Customer's next renewal term, or on thirty (30) days' notice for Customers without a fixed term.
22.2 Pinned Versions. Where a specific version of these Terms is identified in an Order or attached as an exhibit to a Customer-Partner agreement, that version continues to apply for the duration of the then-current subscription or Evaluation term regardless of later published updates, and will not change without Customer's written agreement.
22.3 Material adverse changes. Where an update materially and adversely affects Customer's rights, Customer may decline the update and terminate the affected Services effective at the end of the then-current term, without penalty and with no obligation to renew.
22.4 Version history. Pylon maintains a version history of these Terms at https://thepylongroup.com/legal/end-user-terms/, including the effective date and a summary of changes for each version. Each published version remains available at a permanent path, and this version is available at https://thepylongroup.com/legal/end-user-terms/1.0/.
Pylon End-User Terms, Version 1.0. Effective August 1, 2026. Advosec, LLC d/b/a The Pylon Group, Pennsylvania, United States.