Think Smart Inc.

Third-Party Access Addendum

Terms covering access to the Services by Customer's third parties.

Last updated: December 9, 2025

← All agreements
Draft — pending review. This document is a working draft adapted for Think Smart Group Inc. and should be confirmed by legal counsel before launch.

This Third-Party Access Addendum (“Addendum”) supplements and is incorporated into the Master Service Agreement (“MSA”) between Think Smart Group, Inc. (“TSI”) and the Customer. This Addendum governs access granted to Customer, ISV, or End-User third-party vendors. Capitalized terms not defined in this Addendum have the meanings given in the MSA and incorporated policies.

1. Authorization & Scope

Access for a Vendor requires written authorization by the Customer/ISV identifying the Vendor, purpose, systems, and time period. TSI may deny or revoke access that threatens platform security or stability.

2. Security Requirements (Minimums)

- Unique named accounts; no shared credentials; least-privilege roles.

- MFA for all remote/admin access; no exceptions.

- Access via approved bastion/jump or TSI-approved remote control software; session logging enabled; screen recording where feasible.

- Time-boxed credentials; disable/remove promptly when no longer needed.

- No local admin on servers unless pre-approved and time-boxed.

- Vendors must maintain supported OS, patched tools, and endpoint protection.

3. Conduct & Restrictions

- No pen-testing, scanning, or load testing without TSI’s prior written approval and rules of engagement.

- No deliberate degradation of service, crypto-mining, or quota circumvention.

- Confidentiality: Vendor access is subject to Customer/ISV confidentiality obligations; Customer/ISV is responsible for separate NDAs with Vendor.

4. Responsibility & Indemnity

Customer/ISV is responsible for Vendor acts/omissions and will indemnify TSI for claims arising from Vendor access, including misuse, data loss, and license violations.

5. Monitoring; Suspension

TSI may monitor Vendor sessions for compliance and may suspend Vendor access immediately to protect the platform or enforce this Addendum.

6. Changes to this Addendum

TSI may update this Addendum from time to time and will provide notice of material changes. Materially adverse changes will not take effect during a then-current Order Form term; they apply upon renewal, unless earlier required by law or to address security, legal, or system‑integrity risks. Updates will not modify commercial pricing or payment terms.

This Addendum is accepted and agreed to by Customer as of the Effective Date of the Master Service Agreement into which it is incorporated.

Questions?

Prefer to ask a person?

For questions about this document or about Think Smart, reach out and we will help.