# UNIVERSAL END USER LICENSE AGREEMENT (EULA) FOR tamper
### Inspired by and Structured in Accordance with the Standard Contract for AWS Marketplace (SCMP)

**IMPORTANT — READ CAREFULLY:** This Universal End User License Agreement ("Agreement" or "EULA") is a legally binding contract between you (either an individual or a single legal entity, whether acting directly or through an authorized procurement agent, hereinafter referred to as **"Customer"**, **"Licensee"**, or **"Buyer"**) and **SIENNA Information Technology Solutions**, having its registered headquarters at **165 Avenue de Bretagne, 59000 LILLE, France**, registered under **SIRET number 98463259600016** (hereinafter referred to as **"Licensor"**, **"Seller"**, or **"SIENNA"**).

This Agreement governs Customer's procurement, deployment, installation, access to, and operational use of the **`tamper`** enterprise security software, regardless of the distribution channel, procurement platform, virtualization hypervisor, or image format from which it was obtained.

By purchasing, subscribing to, downloading, deploying, booting, accessing via SSH, or otherwise using **`tamper`**, Customer expressly agrees to be bound by all terms, conditions, and strict intellectual property prohibitions set forth in this Agreement. If Customer does not agree to these terms, Customer must immediately discontinue all deployment and terminate any active virtual machines or cloud instances.

---

## 1. DEFINITIONS AND UNIVERSAL APPLICABILITY

1. **"Software"** or **"`tamper`"** means the **`tamper`** Data Security, Posture Management (DSPM), File Integrity Monitoring (FIM), Data Asset Management (DAM), and Data Loss Prevention (DLP) solution created and owned by SIENNA. It includes all proprietary source code, PHP Symfony backend controllers, Vue.js/Twig frontend interfaces, Python FIM scanners, Bash deployment and packaging scripts (`build-local-images.sh`, `prepare-image-export.sh`), Center for Internet Security (CIS) compliance rulesets, AI prompt templates, Docker container images (`tamper_symfony`, `tamper_n8n`), cloud-init/systemd first-boot services (`tamper-firstboot.service`), database schemas, and associated official documentation.
2. **"Universal Distribution & Multi-Platform Scope"** means that this Agreement applies strictly and unconditionally to **`tamper`** across **ALL possible procurement channels, infrastructure environments, hypervisors, and file formats**, including but not limited to:
   * **Public Cloud & Marketplaces:** Amazon Machine Images (`AMI`) deployed via AWS Marketplace, AWS EC2, or AWS GovCloud; Microsoft Azure Virtual Machine Images (`VHD`/`Managed Disks`); Google Cloud Platform (`GCP`) Compute Engine images.
   * **On-Premises & Virtualization Hypervisors:** Proxmox Virtual Environment (`PVE` / `.qcow2` / `.raw`), VMware vSphere / ESXi / Workstation (`.ova` / `.ovf` / `.vmdk`), Microsoft Hyper-V (`.vhdx`), Kernel-based Virtual Machine (`KVM`), or Citrix Hypervisor.
   * **Bare-Metal & Container Formats:** Direct tarball archives (`.tar.gz`), Docker Compose stacks, or Kubernetes Helm charts.
3. **"Subscription Tier"** means the specific operational feature set and capacity limits (`Discovery`, `Monolith`, or `Enterprise`) licensed to Customer, as enforced by SIENNA's cryptographic activation keys and internal governance controls.

---

## 2. GRANT OF LICENSE (SCMP SECTION 2 EQUIVALENT)

Subject to Customer's timely payment of all applicable subscription fees (whether billed hourly/annually via AWS Marketplace or invoiced directly under a Bring-Your-Own-License / BYOL agreement) and continuous compliance with this Agreement, SIENNA grants Customer a limited, non-exclusive, non-transferable, non-sublicensable, revocable license during the active subscription term to deploy, boot, and operate **`tamper`** within Customer's private cloud VPC or on-premises infrastructure solely for Customer's internal data security auditing, asset management, and FinOps governance.

---

## 3. IRONCLAD PROPRIETARY RIGHTS & STRICT PROHIBITIONS ON REVERSE ENGINEERING

**`tamper`** contains highly protected trade secrets, proprietary algorithms, and intellectual property owned exclusively by **SIENNA Information Technology Solutions**. To safeguard these rights across all deployment formats (`AMI`, `.qcow2`, `.ova`), Customer strictly covenants and agrees to the following absolute prohibitions:

1. **NO REVERSE ENGINEERING OR DECOMPILATION:** Customer shall NOT decompile, disassemble, reverse engineer, decrypt, un-obfuscate, extract, or attempt to derive the underlying source code, business logic, architectural designs, or algorithms of any proprietary PHP, JavaScript, Python, or Shell script contained within the **`tamper`** virtual appliance, disk image, or container filesystem.
2. **NO EXTRACTION OR ISOLATION ACROSS ANY FORMAT:** Customer shall NOT copy, isolate, extract, mount externally (`qemu-nbd`, `guestfish`, loopback mounts, or Docker volume copies), or separate any proprietary files, scripts (`build-local-images.sh`, `prepare-image-export.sh`), database initialization scripts (`init.js`), or FIM/CIS monitoring modules from the **`tamper`** virtual machine or container rootfs for use outside of the authorized appliance environment.
3. **NO MODIFICATION OR DERIVATIVE WORKS:** Customer shall NOT modify, adapt, translate, alter, patch, or create derivative works based upon any part of the **`tamper`** source code, database models, or application layout without prior express written authorization from SIENNA.
4. **NO INSPECTION OR DIGGING INTO SOFTWARE:** Customer has absolutely no right to inspect, review, audit, or analyze the source code, internal databases, or backend file structures of the software. All interactions must remain strictly at the provided application layer.
5. **NO BYPASSING OF LICENSE & ROLE GOVERNANCE:** Customer shall NOT tamper with, bypass, disable, or circumvent any internal licensing verification checks (`hasAdvancedFeatures()`, `isGlobalAIAnalysisEnabled()`), role-based access controls (`ROLE_ADMIN`, `ROLE_USER`, `ROLE_SERVICE`), or storage quota limits.
6. **RESTRICTION ON ADMINISTRATIVE / ROOT ACCESS:** Whether deployed on AWS (`admin` SSH user), Proxmox (`root` terminal), or VMware, Customer acknowledges that administrative, SSH, or root access is granted solely for underlying operating system maintenance, network configuration, and security patching. **Administrative or root access does NOT grant Customer any license, ownership, or legal right to inspect, read, copy, or modify the proprietary application source code residing inside `/root/tamperDocker` or the internal Docker volumes.** Any unauthorized access to or copying of internal application source code discovered during audit constitutes a material, non-curable breach of this Agreement.

---

## 4. AUTHORIZED USAGE GUIDELINES & INTERFACE RESTRICTIONS

Customer agrees to operate **`tamper`** exclusively through its officially supported interfaces. Authorized use of the product is strictly limited to:
1. **Web Interface:** Customer shall interact with the product solely via the provided graphical Web User Interface (UI).
2. **Supported APIs:** Customer may use official, documented APIs for automation and integration purposes, where applicable.
3. **OS/Network Configuration:** Direct operating system interaction (e.g., via SSH, hypervisor console, or terminal) is strictly limited to basic system administration, network configuration, OS security updates, and lifecycle management of the appliance.

Customer is explicitly prohibited from directly querying the internal databases (e.g., MongoDB), accessing or modifying internal Docker containers, directly invoking internal scripts and binaries, or otherwise digging into the underlying software architecture or internal storage. All such activities constitute a violation of this Agreement.

---

## 5. PROHIBITION OF RESALE AND MANAGED SERVICES (NO SAAS / MSSP RESALE)

Customer shall use **`tamper`** exclusively for its own internal business operations. Customer is strictly prohibited from:
- Renting, leasing, lending, reselling, sublicensing, or redistributing the **`tamper`** virtual appliance, disk images (`.qcow2`/`.ova`/`AMI`), or activation keys to any third party.
- Offering, operating, or commercializing **`tamper`** (or any of its embedded engines such as `n8n` or `MongoDB`) as a hosted Software-as-a-Service (SaaS), Managed Security Service Provider (MSSP) platform, cloud database service, or workflow orchestration service to third parties without executing a separate Commercial Managed Service Agreement with SIENNA.

---

## 6. CUSTOMER DATA PRIVACY & ZERO-TELEMETRY ARCHITECTURE

**`tamper`** is engineered as a cloistered, zero-telemetry virtual appliance. All cryptographic hashing, S3/R2 bucket auditing, AI report generation, and database processing execute 100% locally inside Customer's private VPC or on-premises hypervisor. SIENNA does not collect, transmit, or have access to Customer's network packets, cloud credentials, or audited data payloads. Customer retains sole ownership and complete responsibility for the security of all data processed within the appliance.

---

## 7. THIRD-PARTY AND OPEN-SOURCE SOFTWARE ATTRIBUTIONS (SCMP SECTION 6)

The **`tamper`** appliance incorporates specific third-party open-source components to facilitate local container orchestration and data persistence. These components are governed strictly by their respective open-source licenses, as documented in the **`THIRD_PARTY_LICENSES`** notice bundled with the Software:

1. **n8n Workflow Automation (Sustainable Use License / EE License by n8n GmbH):** Embedded exclusively as an internal, headless workflow orchestration core inside the customer-controlled appliance. It is not exposed to end-users as a standalone SaaS, nor offered to third parties as a managed service.
2. **MongoDB Database (Server Side Public License - SSPL v1 by MongoDB, Inc.):** Deployed locally within the self-contained virtual appliance to store internal **`tamper`** configuration and audit logs. Because Customer operates the appliance entirely within their own private infrastructure without SIENNA offering MongoDB as a public cloud database service, this deployment fully complies with SSPL v1 on-premises terms.
3. **Symfony Framework & PHP/Node Ecosystem (MIT / BSD / Apache 2.0):** Incorporated under standard permissive licenses.

Nothing in this Agreement restricts Customer's rights under, nor grants rights that supersede, the terms of any applicable third-party open-source license.

---

## 8. AUDIT RIGHTS AND TERMINATION FOR BREACH

SIENNA reserves the right to audit Customer's deployment and usage of **`tamper`** upon reasonable written notice to verify compliance with subscription tiers and Section 3 prohibitions.

If Customer commits a material breach of this Agreement—specifically including any attempt to reverse engineer, decompile, extract, or copy proprietary source code from the appliance filesystem—SIENNA may immediately terminate this Agreement without cure period. Upon termination:
1. All licenses granted hereunder immediately terminate.
2. Customer must immediately shut down, destroy, and permanently delete all instances, copies, `.qcow2` files, `.ova` templates, AMIs, and EBS/VMDK snapshots of **`tamper`**.
3. SIENNA reserves the right to seek maximum civil damages, statutory penalties, and criminal prosecution under international copyright and trade secret laws.

---

## 9. WARRANTIES AND DISCLAIMERS (SCMP SECTION 8)

**9.1 Limited Warranty:** SIENNA warrants that during the subscription term, **`tamper`** will perform substantially in accordance with its official documentation when operated on recommended hardware (`t3.medium` or equivalent 2 vCPU / 4GB RAM hypervisor specs).

**9.2 Warranty Disclaimer:** EXCEPT FOR THE LIMITED WARRANTY IN SECTION 9.1, AND TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE SOFTWARE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT ANY OTHER WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. SIENNA DOES NOT WARRANT THAT THE SOFTWARE WILL BE ERROR-FREE OR IMMUNE TO ALL CYBERSECURITY ATTACKS.

---

## 10. LIMITATION OF LIABILITY (SCMP SECTION 9)

IN NO EVENT SHALL **SIENNA INFORMATION TECHNOLOGY SOLUTIONS**, ITS DIRECTORS, EMPLOYEES, OR AFFILIATES BE LIABLE TO CUSTOMER FOR ANY INDIRECT, INCIDENTAL, SPECIAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES (INCLUDING LOSS OF DATA, BUSINESS INTERRUPTION, LOST REVENUE, OR CLOUD INFRASTRUCTURE OVERAGES) ARISING OUT OF OR RELATING TO THIS AGREEMENT OR the USE OF **`tamper`**, EVEN IF SIENNA HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

SIENNA'S TOTAL AGGREGATE LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THIS AGREEMENT, WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), OR OTHERWISE, SHALL BE STRICTLY CAPPED AT THE TOTAL AMOUNT ACTUALLY PAID BY CUSTOMER TO SIENNA FOR THE **`tamper`** SOFTWARE LICENSE DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE CLAIM.

---

## 11. GOVERNING LAW AND EXCLUSIVE JURISDICTION

This Agreement, along with any non-contractual disputes or claims arising out of or in connection with it, shall be governed by, construed, and enforced strictly in accordance with the laws of **France**.

Any legal action, lawsuit, dispute, or proceeding arising out of or relating to this EULA or the procurement of **`tamper`** (whether procured via AWS Marketplace, direct invoice, or reseller) shall be brought exclusively before the **Commercial Court of Lille (Tribunal de Commerce de Lille Métropole), France**, and each party irrevocably submits to the exclusive jurisdiction of such courts.

---

*Copyright (c) 2024-2026 SIENNA Information Technology Solutions (165 Avenue de Bretagne 59000 LILLE — SIRET: 98463259600016). All rights reserved.*
