These Lens Subscription Terms ("Terms") govern Customer's access to and use of the Lens platform ("Lens" or the "Service") provided by Crescent Value Partners, LLC, a Louisiana limited liability company with an address at 1000 Bourbon Street #290, New Orleans, LA 70116 ("CVP," "we," "us," or "our").
By executing an Order Form, creating an account, clicking to accept, or using Lens, the person or entity accepting these Terms ("Customer," "you," or "your") agrees to the Agreement. An individual accepting for an entity represents that they have authority to bind that entity.
1. Agreement Structure
The "Agreement" consists of:
- Each Order Form;
- These Terms;
- The Lens Acceptable Use Policy ("AUP");
- Any Data Processing Agreement ("DPA") executed by the parties; and
- Any service-level or support schedule expressly incorporated into an Order Form.
If documents conflict, the following order applies:
- A signed amendment;
- The DPA, solely for processing Personal Data;
- The applicable Order Form;
- An incorporated service-level schedule, solely for service levels;
- These Terms; and
- The AUP.
The Lens Privacy Supplement describes CVP's privacy practices but does not modify the parties' contractual rights or obligations.
"Customer Data" means data submitted to Lens by or for Customer or collected by a Lens Agent on Customer's behalf. "Authorized User" means an individual Customer permits to use Lens. "Agent" means CVP-provided software deployed in a Customer-controlled environment. "Order Form" includes an executed order, online checkout, or subscription confirmation identifying purchased Services.
2. Service and Orders
Subject to the Agreement and payment of fees, CVP grants Customer a limited, non-exclusive, non-transferable right during the subscription period to use Lens, included Agents, and Documentation for Customer's internal business purposes.
The applicable Order Form identifies the subscribed plan, features, quantities, subscription period, fees, support level, and any additional terms. Customer may permit Authorized Users to use Lens within those entitlements and remains responsible for their compliance.
Lens provides network and cyber-exposure assessment and reporting capabilities. Results may contain errors, omissions, false positives, or false negatives and do not guarantee that a system is secure or compliant. Lens does not provide legal, audit, certification, insurance, or other professional advice.
CVP may improve or modify Lens. During a paid term, CVP will not materially reduce purchased core functionality without providing a reasonably comparable alternative or allowing Customer to terminate the affected Service and receive a prorated refund of prepaid, unused fees. This does not apply to beta features, third-party services, or changes required for security or legal compliance.
Beta or preview features may be changed or discontinued at any time and are provided without a service-level commitment.
3. Customer Responsibilities
Customer will:
- Maintain accurate account and billing information;
- Protect credentials and promptly remove unnecessary access;
- Remain responsible for activity under its account;
- Use Lens only in accordance with the Agreement and applicable law; and
- Obtain all rights, permissions, and authorizations required for Customer Data and assessment activity.
All target authorization, Agent and credential handling, prohibited uses, MSP assessment authorization, and abuse-enforcement requirements are governed by the AUP.
If Customer is an MSP, it is responsible for its relationship with each end client, obtaining the end client's instructions and authorization, managing MSP access, and paying CVP for subscribed Tenants. CVP does not contract with or bill an MSP's end clients unless separately agreed.
4. Fees, Taxes, and Subscription Term
Customer will pay the fees stated in each Order Form. Unless the Order Form says otherwise:
- Fees are payable in United States dollars;
- Monthly and annual fees are billed in advance;
- Fees are non-cancelable during a committed term and non-refundable except as expressly stated in the Agreement;
- Customer authorizes recurring charges to its selected payment method; and
- Customer is responsible for applicable transaction taxes other than taxes based on CVP's net income.
Customer must notify CVP of a good-faith billing dispute within five business days after the invoice date and timely pay undisputed amounts.
CVP may suspend access if an undisputed payment remains overdue after reasonable notice and a fourteen-day opportunity to cure.
Renewal
Each subscription automatically renews for successive periods equal to the expiring subscription period unless either party gives notice of non-renewal at least thirty days before renewal. Renewal fees are CVP's then-current fees unless the Order Form states otherwise.
5. Customer Data, Privacy, and Security
As between the parties, Customer owns Customer Data. Customer grants CVP a non-exclusive right to process Customer Data only as needed to provide, secure, support, and administer Lens; comply with Customer's documented instructions; enforce the Agreement; and comply with law.
Customer represents that it has all rights and lawful bases necessary to provide Customer Data and instruct CVP to process it.
CVP may use technical and usage information to operate, secure, measure, and improve Lens. CVP may disclose that information only where it does not identify Customer or an individual or as otherwise permitted by the DPA and applicable law.
Where CVP processes Personal Data on Customer's behalf, the DPA governs that processing. The DPA controls over these Terms for Personal Data matters, including subprocessors, Security Incidents, data-subject assistance, restricted transfers, and deletion.
CVP will use commercially reasonable technical and organizational measures designed to protect Customer Data against unauthorized access, alteration, disclosure, destruction, or unlawful use. Applicable measures are described in the DPA security annex.
The current provider and external-data-source list is available online.
6. Confidentiality
"Confidential Information" means non-public information disclosed by one party to the other that is identified as confidential or reasonably should be understood as confidential. Customer Data is Customer's Confidential Information. Non-public Lens technology, security information, detection logic, and business information are CVP's Confidential Information.
The receiving party will:
- Use Confidential Information only to perform or exercise rights under the Agreement;
- Protect it with at least reasonable care; and
- Disclose it only to personnel and contractors who need access and are bound by confidentiality obligations.
These obligations do not apply to information the receiving party can demonstrate was lawfully known without restriction, independently developed, rightfully received from another source, or publicly available without breach.
A legally compelled disclosure is permitted if the receiving party provides advance notice where legally allowed and reasonable assistance in seeking protection.
These obligations continue for three years after disclosure. Customer Data and trade secrets remain protected while they qualify as confidential under applicable law.
7. Intellectual Property
CVP and its licensors retain all rights in Lens, Agents, Documentation, detection and analysis logic, software, improvements, and associated intellectual property. Except for rights expressly granted by the Agreement, neither party transfers ownership to the other.
Customer may provide feedback. CVP may use feedback without restriction or obligation, provided it does not identify Customer publicly without permission.
CVP will not use Customer's name or logo in public marketing without prior authorization.
8. Suspension and Termination
CVP may restrict or suspend access where:
- Customer materially violates the Agreement or AUP;
- Use creates material legal, security, safety, or operational risk;
- Suspension is required by law;
- Undisputed fees remain overdue after the applicable cure period; or
- Continued access threatens Lens, another tenant, or a third party.
Where practical, CVP will notify Customer and limit the restriction to the affected account, Tenant, Agent, target, or functionality.
Either party may terminate for an uncured material breach after thirty days' written notice. A breach involving unlawful or unauthorized assessment activity, deliberate security circumvention, or another breach that cannot reasonably be cured may result in immediate termination.
Upon termination, Customer must stop using Lens and pay accrued amounts. Customer Data will be returned or deleted as provided in the DPA.
Provisions concerning payment, confidentiality, intellectual property, disclaimers, liability, indemnification, and general legal matters survive as necessary to give them effect.
9. Warranties and Disclaimers
Each party represents that it has authority to enter the Agreement and will comply with laws applicable to its performance.
CVP warrants that it will provide Lens in a professional and workmanlike manner materially consistent with applicable Documentation. Customer's exclusive remedy for breach is for CVP to use commercially reasonable efforts to correct the material nonconformity. If CVP cannot do so within a reasonable period, Customer may terminate the affected Service and receive a prorated refund of prepaid, unused fees.
Except for that express warranty, Lens, Agents, Documentation, and assessment results are provided "as is" and "as available." To the maximum extent permitted by law, CVP disclaims implied warranties of merchantability, fitness for a particular purpose, title, non-infringement, accuracy, and uninterrupted or error-free operation.
CVP does not warrant that Lens will detect every asset, vulnerability, exposure, or unauthorized activity.
10. Indemnification
CVP will defend Customer against a third-party claim that Customer's authorized use of Lens infringes a United States patent, copyright, or trademark and will indemnify Customer against resulting damages and reasonable costs finally awarded or approved in settlement.
CVP has no obligation for claims arising from Customer Data, Customer instructions, unauthorized modifications or use, combinations not supplied by CVP, or continued use after CVP offers a non-infringing replacement. CVP may obtain continued-use rights, modify or replace the affected Service, or terminate it and refund prepaid, unused fees.
Customer will defend and indemnify CVP against third-party claims arising from Customer Data, unauthorized assessment activity, Customer's violation of the AUP, or Customer's infringement or violation of third-party rights.
Indemnification requires prompt notice, reasonable cooperation at the indemnifying party's expense, and control of the defense. A settlement may not admit fault by or impose non-monetary obligations on the protected party without consent.
Any additional DPA or Security Incident indemnity applies only if expressly included in the DPA.
11. Limitation of Liability
Except in cases of fraud or willful misconduct, each party's total cumulative liability under the Agreement will not exceed the fees paid or payable by Customer during the twelve months preceding the event giving rise to the claim.
To the maximum extent permitted by law, neither party will be liable for lost profits, lost revenues, loss of business, or indirect, special, incidental, exemplary, punitive, or consequential damages.
The foregoing does not limit Customer's payment obligations or liability that cannot lawfully be limited.
12. General
The Agreement is governed by the laws of the State of Louisiana, without regard to conflict-of-laws principles. The parties consent to exclusive jurisdiction and venue in state and federal courts located in Orleans Parish, Louisiana. Restricted-transfer provisions in the DPA control where applicable.
Neither party is liable for delay caused by events beyond its reasonable control, excluding payment obligations.
The parties are independent contractors. The Agreement creates no partnership, agency, employment, franchise, or fiduciary relationship.
If a provision is unenforceable, it will be modified to the minimum extent necessary and the remaining provisions continue in effect. Failure to enforce a provision is not a waiver.
The Agreement is the entire agreement concerning Lens and supersedes prior discussions concerning its subject. Customer purchase-order boilerplate does not modify it.
CVP may update these Terms or the AUP. Material adverse changes to these Terms will take effect no earlier than Customer's next renewal unless required sooner by law or material security risk. DPA and subprocessor changes are governed by the DPA.
The Agreement may be accepted electronically and executed in counterparts.
13. Notices and Contact
Legal notices to CVP must be sent to legal@cvpapp.com and:
Crescent Value Partners, LLC
1000 Bourbon Street #290
New Orleans, LA 70116
Notices to Customer may be sent to the legal, owner, or administrative contact identified in its account or Order Form.
- Privacy: privacy@cvpapp.com
- Security: security@cvpapp.com
- Abuse reports: report@cvpapp.com
- Support: support@cvpapp.com
- Billing: billing@cvpapp.com