Yama Universal Terms

UNIVERSAL TERMS AND CONDITIONS

Client Cybersecurity Responsibility and Liability Disclaimer

Published At: www.resources.yamaindustrials.com/terms Effective Date: October 16, 2025 Version: 1.0 Last Updated: October 16, 2025 Applies To: All Yama Industrials, Inc. services, products, and client relationships

1. BINDING ACCEPTANCE AND SCOPE

1.1 Automatic Acceptance

These Universal Terms and Conditions apply to all services provided by Yama Industrials, Inc. ("Yama"). By making any payment to Yama, accepting any services from Yama, signing any agreement referencing www.resources.yamaindustrials.com, or continuing services, clients immediately and irrevocably accept all terms herein without exception.

1.2 Invoice Notification

All Yama invoices include: "Terms and Conditions: www.resources.yamaindustrials.com/terms" Payment of any invoice constitutes explicit acceptance of all terms.

1.3 No Negotiation

Yama provides NO OPPORTUNITY to object to, negotiate, or modify these terms. Services are provided only on these terms or not at all. Any attempted modification is VOID.

2. WRITTEN CONTRACTS GOVERN ALL SERVICES

2.1 Exclusive Written Agreement Provision

Yama SHALL ONLY BE HELD ACCOUNTABLE for services explicitly defined in written, executed service agreements.

NO LIABILITY ATTACHES to Yama for:

  • Verbal conversations, discussions, or informal recommendations

  • Services not documented in signed contracts

  • Expectations or assumptions not stated in writing

  • Oral representations outside written commitments

  • Industry-standard practices not explicitly contracted

2.2 Verbal Communications Disclaimer

VERBAL CONVERSATIONS PROVIDE ZERO LIABILITY ATTACHMENT. All verbal communications between Yama personnel and clients are EXPLICITLY EXCLUDED from creating any obligations, warranties, representations, or liability.

3. NO DUTY TO IDENTIFY, DOCUMENT, OR REMEDIATE CLIENT DEFICIENCIES

3.1 Zero Obligation to Identify Security Issues

YAMA HAS ZERO OBLIGATION to identify, document, notify, or remediate client cybersecurity deficiencies UNLESS EXPLICITLY CONTRACTED IN WRITING for such services.

3.2 No Duty Even If Aware

Even if Yama personnel BECOME AWARE of client security deficiencies, Yama has NO OBLIGATION to document, notify, recommend remediation, or take any action UNLESS EXPLICITLY CONTRACTED for such services.

3.3 Informal Recommendations Are Courtesies

If Yama personnel VOLUNTARILY provide informal observations or recommendations, such communications:

  • Are provided AS COURTESY ONLY without obligation

  • Create NO DUTY OR LIABILITY for Yama

  • Do NOT constitute acceptance of responsibility

  • Do NOT expand service scope

  • May be INCOMPLETE, INACCURATE, OR OUT-OF-DATE without liability

3.4 Client Retains Sole Responsibility

Client retains SOLE AND ABSOLUTE RESPONSIBILITY for all cybersecurity matters before, during, and after Yama services, REGARDLESS of Yama's knowledge, observations, or recommendations.

4. THIRD-PARTY PRODUCTS AND SERVICES DISCLAIMER

4.1 Yama as Solutions Provider Only

Yama is a SOLUTIONS PROVIDER that implements, configures, manages, or recommends third-party products and services. YAMA IS NOT THE MANUFACTURER, DEVELOPER, OR ORIGINAL VENDOR of hardware, software, cloud services, or other third-party products.

4.2 Third-Party Products Include But Are Not Limited To:

  • Security software and services: 0patch, antivirus, EDR, firewalls, VPNs, SIEM, backup solutions

  • Operating systems: Microsoft Windows, Linux, macOS

  • Hardware: Servers, firewalls, network equipment, workstations, storage devices

  • Cloud services: Microsoft 365, Azure, AWS, Google Cloud, other SaaS/IaaS/PaaS

  • Network equipment: Routers, switches, wireless access points

  • Applications: Microsoft Office, Adobe, QuickBooks, industry-specific software

  • Telecommunications: Internet service providers, phone systems, carriers

4.3 Absolute Disclaimer for Third-Party Products

YAMA HAS ZERO LIABILITY FOR:

4.3.1 Product Defects, Vulnerabilities, and Failures

  • Software bugs, errors, or malfunctions in third-party products

  • Security vulnerabilities (including zero-days) in third-party products

  • Compatibility issues between third-party products

  • Performance problems or degradation of third-party products

  • Hardware failures or defects in third-party equipment

  • Cloud service outages or data loss by third-party providers

4.3.2 Vendor Actions and Omissions

  • Third-party vendor discontinuation of products or support

  • Third-party vendor failure to patch security vulnerabilities

  • Third-party vendor end-of-life or end-of-support decisions

  • Third-party vendor pricing changes or licensing modifications

  • Third-party vendor breach of their own terms or warranties

  • Third-party vendor bankruptcy, acquisition, or business closure

4.3.3 Third-Party Support and Updates

  • Delayed or absent security patches from third-party vendors

  • Inadequate technical support from third-party vendors

  • Compatibility breaks caused by third-party updates

  • Feature changes or removals by third-party vendors

  • Third-party vendor refusal to provide updates or fixes

4.3.4 Specific Examples of Third-Party Liability Exclusions

YAMA IS NOT LIABLE FOR:

  • 0patch or other third-party security services: Micropatch failures, incomplete coverage, service discontinuation, ACROS Security business failure, compatibility issues with Microsoft updates

  • Microsoft products: Windows vulnerabilities (including zero-days), delayed security patches, forced upgrades, licensing changes, end-of-support decisions, compatibility issues

  • Firewall manufacturers: Hardware failures, firmware bugs, zero-day exploits, vendor support quality, licensing disputes

  • Cloud service providers: Azure/AWS/Google outages, data breaches, vendor pricing increases, service discontinuation

  • Antivirus/EDR vendors: False positives/negatives, performance impact, compatibility issues, subscription lapses, vendor business failure

4.7 Zero-Day Vulnerabilities and Unpatched Issues

YAMA HAS ZERO LIABILITY FOR:

  • Zero-day vulnerabilities in any third-party product

  • Vulnerabilities publicly disclosed but not yet patched by vendor

  • Vendor delays in releasing security patches

  • Vendor refusal to patch discontinued products

  • Exploitation of vulnerabilities before patches are available

  • Client's decision to continue using products with known vulnerabilities

  • Inadequacy of third-party security solutions (including 0patch or other patch services)

Client explicitly acknowledges that all software and hardware contains vulnerabilities, some known and some unknown (zero-days), and Yama has no duty or ability to prevent exploitation of such vulnerabilities unless Yama is explicitly contracted to provide vulnerability assessment and remediation services.

5. COMPREHENSIVE LIABILITY DISCLAIMER

5.1 Services Not Contracted in Writing

Yama has ZERO LIABILITY for any services not documented in signed service agreements, including recommendations or advice provided verbally, assumed responsibilities not stated in contracts, or industry-standard practices not explicitly contracted.

5.2 Client Cybersecurity Deficiencies

Yama has ZERO LIABILITY for any client cybersecurity deficiencies REGARDLESS OF WHETHER Yama was aware, documented them, notified client, provided informal recommendations, or continued services despite knowledge.

ABSOLUTE RULE: KNOWLEDGE DOES NOT CREATE LIABILITY

Yama's awareness, observation, documentation, or notification of client deficiencies - WHETHER ACQUIRED THROUGH CONTRACTED SERVICES, INCIDENTAL DISCOVERY, OR ANY OTHER MEANS - CREATES ABSOLUTELY NO LIABILITY OR OBLIGATION.

5.3 Third-Party Products and Services

Per Section 4 above, Yama has ZERO LIABILITY for any third-party product defects, vulnerabilities, failures, vendor actions, zero-days, or service provider failures.

6. LIMITATION OF LIABILITY - MAXIMUM CAP

6.1 Maximum Liability Amount

Yama's TOTAL LIABILITY under any service agreement shall be strictly limited to the LESSER OF:

  1. Total fees paid by client to Yama in 12-month period preceding the event, OR

  2. $25,000 USD maximum aggregate liability cap

6.2 No Indirect or Consequential Damages

In no event shall Yama be liable for indirect, incidental, special, consequential, or punitive damages; loss of profits, revenue, or business opportunities; business interruption; data loss or corruption; regulatory fines or penalties; third-party claims or litigation costs; or reputational harm.

7. CLIENT BURDEN OF PROOF

In any dispute alleging Yama's liability, client must prove ALL of the following by clear and convincing evidence:

1

Existence of written contract for specific services allegedly deficient

Client must show a written, executed contract explicitly defining the services at issue.

2

Yama's specific breach of that written contract

Client must identify precise contractual obligations Yama allegedly violated.

3

Client's full compliance with ALL contractual obligations

Client must prove it satisfied every obligation under the contract.

4

Adequate client cybersecurity posture independent of Yama's services

Client must demonstrate an adequate baseline cybersecurity posture independent of any Yama-provided services.

5

No pre-existing or discovered deficiencies (unless contracted to be remediated)

Client must show that alleged deficiencies were not pre-existing or otherwise excluded from remediation.

6

Direct causation between Yama's breach and client's damages

Client must prove direct causation linking Yama's breach to the damages claimed.

7

Mitigation of damages by client

Client must demonstrate it took reasonable steps to mitigate damages.

FAILURE TO PROVE ANY SINGLE ELEMENT = COMPLETE DISMISSAL OF CLAIMS

9. TIMELY WRITTEN NOTICE REQUIRED

9.1 Claims Must Be in Writing

All claims must be submitted in writing to:

Yama Industrials, Inc. - Legal Department Email: [email protected]

9.2 30-Day Deadline

Claims must be submitted within 30 days of when client knew or should have known of alleged breach.

FAILURE TO PROVIDE TIMELY WRITTEN NOTICE = COMPLETE WAIVER OF CLAIM

10. INTEGRATION WITH SERVICE-SPECIFIC POLICIES

10.1 Incorporation by Reference - Current Versions Apply

These Universal Terms incorporate by reference all current versions of policies and documentation published at www.resources.yamaindustrials.com, including:

  • Cybersecurity Guidance, Advisory, and Consulting Services Policy (CISO Policy) - Current version as published

  • Firewall as a Service (FWaaS) Terms - Current version as published

  • Installation Services Terms - Current version as published

  • All other service-specific terms, conditions, and policies - Current versions as published

10.2 References Are to Current Versions

ANY REFERENCE IN THIS DOCUMENT OR ANY YAMA DOCUMENTATION TO:

  • Specific version numbers (e.g., "Rev. 8a", "Version 1.0")

  • Specific revision dates

  • Specific document titles or filenames

SHALL BE DEEMED TO REFER TO THE CURRENT VERSION of that document as published at www.resources.yamaindustrials.com at the time of reference, regardless of the version number or date mentioned.

10.3 No Obligation to Update Cross-References

Yama has NO OBLIGATION to update this document or any other documentation when referenced documents are revised. All references automatically refer to current published versions.

11. POLICY UPDATES AND CLIENT RESPONSIBILITY

11.1 Yama's Right to Update Without Notice

Yama reserves the absolute right to update, modify, or replace these Universal Terms and Conditions AND ALL REFERENCED DOCUMENTS at any time, in Yama's sole discretion, without prior notice to clients.

11.2 Client's Continuing Obligation to Check for Updates

CLIENT IS SOLELY RESPONSIBLE for regularly reviewing www.resources.yamaindustrials.com to check for updates and changes to these terms and all referenced documents.

Yama has NO OBLIGATION to:

  • Notify clients of updates or changes

  • Send update notices via email or other communication

  • Provide advance notice of changes

  • Highlight or summarize changes

  • Maintain change logs or version histories

  • Update cross-references when referenced documents are revised

11.4 Updates Apply Immediately Upon Publication

Any updates to these terms or referenced documents TAKE EFFECT IMMEDIATELY UPON PUBLICATION at www.resources.yamaindustrials.com. Continued engagement with Yama services after an update (whether or not client reviewed the update) constitutes acceptance of the updated terms.

11.5 Invoice Reference Constitutes Constructive Notice

Every Yama invoice includes: "Terms and Conditions: www.resources.yamaindustrials.com/terms"

This reference constitutes CONSTRUCTIVE NOTICE to client that current terms and all referenced documents are published at www.resources.yamaindustrials.com and client is deemed to know the current terms by virtue of invoice reference.

13. DEEMED CLIENT ACKNOWLEDGMENTS

By engaging Yama's services, client is LEGALLY DEEMED TO ACKNOWLEDGE the following items. Each item is a deemed acknowledgment upon engagement:

1

Written contracts exclusively govern.

2

Verbal communications not binding.

3

No duty to identify or remediate client deficiencies unless explicitly contracted.

4

Knowledge does not create liability.

5

Client retains sole cybersecurity responsibility.

6

Informal recommendations are courtesies creating no obligations.

7

Pre-existing deficiencies remain client responsibility.

8

Liability limitations accepted ($25,000 or 12-month fees, whichever less).

9

Burden of proof understood (must prove all 7 elements).

10

Third-party products carry inherent risks that client accepts.

11

Yama not liable for third-party product defects, vulnerabilities, or failures.

12

Yama not liable for zero-days or unpatched vulnerabilities.

13

Yama not liable for third-party vendor actions or business failures.

14

Client solely responsible for checking website for updates.

15

Updates apply immediately upon publication without notification.

16

All references to version numbers subject to ongoing revision.

17

Current published versions always control.

14. NO SEPARATE SIGNATURE REQUIRED

No separate signature or acknowledgment is required. Payment for services, acceptance of services, or continuation of services constitutes immediate, complete, and binding acceptance of all terms herein and all current versions of referenced documents.


Document Control

Title: Yama Industrials, Inc. - Universal Terms and Conditions Version: 1.0 | Publication Date: October 16, 2025 Effective Date: October 16, 2025 (Immediate) Published At: www.resources.yamaindustrials.com/terms Update Policy: Yama may update at any time without notice

For Current Version: www.resources.yamaindustrials.com/terms Client Responsibility: Check this website regularly for updates Invoice Reference: "Terms and Conditions: www.resources.yamaindustrials.com/terms"

© 2025 Yama Industrials, Inc. All rights reserved.