Security Addendum
Depending on what services you use, specific terms and conditions of service may apply.
DELIVERED SECURITY ADDENDUM
Effective Aug 1, 2026
This Delivered Addendum (the "Security Addendum") is incorporated by reference into, and forms part of, the Standard Terms as Additional Terms under Section 4.4 of the Standard Terms. Capitalized terms not otherwise defined in this Security Addendum have the meanings given to them in the Standard Terms.
1. DEFINITIONS
"Security Incident" means a confirmed breach of security that leads to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Your Data.
"Security Program" means the administrative, physical, and technical security program that Delivered maintains for the Services, as described in this Security Addendum.
"Subprocessor" means a third party engaged by Delivered to process Your Data in connection with providing the Services.
2. SHARED RESPONSIBILITY
This Security Addendum describes the Security Program that Delivered maintains for the Services and the boundaries of Delivered's responsibility. This Security Addendum does not describe or govern the security of your own systems, networks, or personnel. You remain responsible for your own security practices, including credential management and access controls for your Authorized Users as described in Section 3.1 of the Standard Terms, and the security of your own networks and systems used to access the Services. Delivered is not responsible for security incidents arising from your failure to meet your obligations under this Section 2 or Section 3.1 of the Standard Terms.
3. SECURITY PROGRAM
3.1 Infrastructure
Delivered hosts the Services using third-party data center and cloud infrastructure providers that maintain industry-standard certifications (such as ISO/IEC 27001 and/or SOC 2 Type II), providing physical security, environmental controls, and redundant power and network connectivity.
3.2 Access Controls
Delivered restricts access to Your Data to personnel who require such access to perform their job functions, applies multi-factor authentication for administrative access to production systems, and periodically reviews access rights.
3.3 Personnel
Delivered personnel with access to Your Data are subject to confidentiality obligations and receive security awareness training appropriate to their role.
3.4 Encryption
Your Data is encrypted in transit using TLS 1.2 or higher and at rest using industry-standard encryption.
3.5 Monitoring; Incident Response
Delivered maintains monitoring and logging for its production environment. In the event of a confirmed Security Incident affecting Your Data, Delivered will notify you without undue delay and in accordance with applicable law, and will provide information reasonably available to Delivered regarding the nature and scope of the Security Incident and the status of Delivered's response.
3.6 Vulnerability Management
Delivered performs periodic vulnerability scanning of its production environment and applies security patches on a risk-based schedule.
3.7 Business Continuity
Delivered maintains backup and business continuity procedures designed to restore the Services following a disruption.
3.8 Subprocessors
Delivered may engage Subprocessors to provide the Services. Delivered will ensure that its Subprocessors are contractually bound to data protection and security obligations materially consistent with this Security Addendum. A current list of Subprocessors is available upon written request.
3.9 Updates to this Security Addendum
Delivered may update this Security Addendum and its Security Program from time to time in accordance with Section 14 of the Standard Terms, provided that no such update will result in a material reduction of the security of the Services during your then-current Term.
4. RELATIONSHIP TO STANDARD TERMS AND DATA PROCESSING ADDENDUM
This Security Addendum constitutes Additional Terms incorporated into the Standard Terms pursuant to Section 4.4 of the Standard Terms. To the extent Delivered processes personal data subject to the Data Processing Addendum referenced in Section 3.3 of the Standard Terms, the Data Processing Addendum will control with respect to data protection obligations to the extent of any conflict with this Security Addendum.