Liability protections
These protections apply to audits, quotes, cutovers, managed retainers, remote assist, and portal access. Full binding terms: /terms. Effective date: 15 July 2026.
This summary is for clarity. If anything conflicts with a signed MSA/SOW, the signed agreement controls. Not legal advice - have counsel review for your jurisdiction.
1. Services are best-effort under approved roadmaps
TUCE provides professional services and managed operations to agreed scopes (audit, BOM, SOW, retainer). "Never-down," HA, performance, and security goals are operating standards and design targets, not absolute warranties that downtime, incidents, or data loss can never occur. SLAs are operational goals (see /sla), not liquidated-damage warranties unless a signed SOW expressly says otherwise.
2. Limitation of liability
- TUCE's total aggregate liability for any claim arising from the services is limited to the fees actually paid by Customer to TUCE for the specific service giving rise to the claim in the twelve (12) months before the claim (or the audit fee, for audit-only work).
- TUCE is not liable for indirect, incidental, special, consequential, exemplary, or punitive damages - including lost profits, lost revenue, lost data, business interruption, reputational harm, or cost of cover - even if advised of the possibility.
- Nothing in these terms limits liability for fraud, willful misconduct, or liabilities that cannot be limited under applicable law.
3. Disclaimer of warranties
Except as expressly stated in a signed SOW, services and software agents are provided "AS IS" and "AS AVAILABLE." TUCE disclaims implied warranties of merchantability, fitness for a particular purpose, and non-infringement to the maximum extent allowed by law.
4. Customer responsibilities (risk allocation)
- Maintain current, restorable backups of all critical systems and data before and after changes (TUCE may assist under contract; Customer remains data owner).
- Authorize change windows; provide accurate inventories, credentials, and access; designate authorized approvers.
- Keep licenses, cloud accounts, and third-party contracts in Customer's name where applicable (IONOS/AWS/Azure/GCP/DreamHost, etc.).
- Accept that refusing recommended HA / redundancy / backup / MFA controls increases Customer's residual risk.
5. Change control · policy & approval chain (MSP risk mitigation)
Engineers follow approved roadmaps and runbooks. Production-impacting work uses this chain on msp.tuce.app:
- Propose in command center / change-control record
- Sandbox / no-data-loss rehearsal when required
- Customer Approver (owner/admin) portal approval - or documented emergency
- Provider top approval before bypassing best practice
- User-impacting reboots/upgrades/cutovers in after-hours windows unless logged emergency + post-incident review
- Pre- and post-change backup/evidence
Work against this chain, or after Customer declines recommended HA/backup/MFA controls with documented risk notice, is Customer-assumed residual risk to the extent permitted by law.
6. Assessment agent (read-only)
The assessment agent is designed for inventory only. Customer authorizes installation and network visibility for that purpose. Customer is responsible for validating that production change freezes / change boards allow the scan environment.
7. Data protection · no routine deletion
Operational posture favors protection and immutability of backups. Customer data remains Customer's. TUCE does not warrant that third parties, malware, Insider actions, or Customer staff cannot delete or encrypt data. Customer must not rely on TUCE as its sole backup or sole legal hold.
8. Third parties & hardware
Hardware warranties, cloud SLAs, ISP uptime, licensing portals (e.g. productkeys.com channel), and OEM support remain with those providers. TUCE is not liable for third-party outages, defective gear beyond pass-through manufacturer remedies, or vendor policy changes.
9. Force majeure
Neither party is liable for delay or failure caused by events beyond reasonable control (natural disaster, war, pandemic, utility/carrier failure, cyberattack at national scale, government action, labor dispute), provided the affected party gives prompt notice and resumes when practicable.
10. Indemnification
- Customer indemnifies TUCE against claims arising from Customer content, unlawful use, failure to maintain backups, unauthorized instructions, or Customer's breach of these terms.
- TUCE indemnifies Customer against third-party claims that TUCE-authored deliverables infringe IP, subject to the liability cap above and prompt notice/cooperation.
11. Insurance
TUCE maintains commercially reasonable professional liability / cyber insurance appropriate to MSP operations. Certificates available on request. Insurance does not expand contractual liability beyond the written cap.
12. Dispute resolution - settle outside court
Claims are resolved by negotiation, then mediation, then confidential binding arbitration (AAA Commercial Rules), not by lawsuit (subject to narrow exceptions for injunction/award enforcement/small claims). This reduces cost and public litigation risk for both parties. Full clause is in the MSA e-signed on msp.tuce.app.
13. Acceptance & court-oriented e-sign
Registering, paying, e-signing MSA/SOW on the portal, downloading agents, or approving quotes constitutes acceptance of Terms, these liability protections, and the signed MSA/SOW. Portal signatures produce an evidentiary certificate (hash + HMAC + attribution) designed for ESIGN/UETA enforceability - not a guarantee of any particular court outcome; have counsel review for your jurisdiction.