Product Specific Terms
Effective starting: December 12, 2025 (unless otherwise indicated below)
The following Product-Specific Terms apply to the SailPoint Offerings specified below and hereby supplement the SailPoint Customer Agreement or other agreement entered between Customer and SailPoint (the “Agreement”) for Customer’s use of the SailPoint Offerings.Capitalized terms used and not defined in the Product-Specific Terms have the meanings given to them in the Agreement.
SailPoint Offering | Product Specific Terms |
|---|---|
AI Terms AND SaaS Terms | |
FedRAMP authorized SailPoint Identity Security Cloud | |
SailPoint Agentic Fabric Entro Product Specific Terms | |
SailPoint SAAM Product Specific Terms | |
SailPoint SAIR Offerings Product Specific Terms (applicable to SAIR, DIF, DIFA any suites including such offerings) |
AI Terms AND SaaS Terms
A. AI Terms
1. Definitions. For the purposes of these AI Terms, the following definitions apply:
“AI Features” means any features or functionalities within the SaaS Services that utilize artificial intelligence and/or machine learning data models. AI Features that leverage generative artificial intelligence to create new content based on Customer Data are “Generative AI Features.”
“Input” is text or other content that Customer inputs to Generative AI Features.
“Output” is Customer-specific suggestions, results, or other output generated and returned by any AI Features.
2. Permitted Use. Customer may use the AI Features solely for Customer’s internal business purposes in accordance with the Agreement and these AI Terms.
3. Customer Responsibilities. As between Customer and SailPoint, Customer is responsible for ensuring that Users are made aware of best practices for using AI Features and Output, and use the AI Features, Input and Output in compliance with all applicable laws, regulations, government order or decree, and guidelines, including, without limitation, laws relating to bias, discrimination, fairness, and privacy (collectively, “AI laws”). Without limiting the foregoing and as between the parties, Customer is solely responsible for ensuring that all notifications, consents, or other required information for Input to be lawfully made and transmitted to SailPoint are provided and collected in accordance with AI laws and that Customer’s use of any Output is in compliance with and does not cause Customer to violate any AI laws.
4. Shared Model(s). Customer Data shall not be included in the training data set for any algorithm underlying the AI Features that will be deployed outside of Customer’s tenant (“Shared Models”) unless Customer takes an action to opt-in to the use of such Shared Model(s); Customer acknowledges and agrees that certain capabilities of the SailPoint Offerings relating to or impacted by Shared Models may not be available to Customer without accepting the use of Customer Data for such purposes. Customer agrees and acknowledges that if such capabilities are affected by Customer not opting in for such data usage, Customer will not receive a refund of any pre-paid fees relating to the affected services or reduction of future fees.
5. Acceptable Use. Customer agrees to not use any AI Features in a manner that violates the Anthropic Acceptable Use Policy. Customer must not use (or facilitate any other person to use) the AI Features: (1) for any use prohibited by AI laws or for any high-risk purpose or for any purpose that may cause the AI Feature to be deemed “high-risk” (including, without limitation, within the meaning of Regulation EU 2024/1689 (“EU AI Act”)); (2) to generate content that expresses or promotes hate, harassment, or violence, exploits or harms any individual, encourages self-harm, presents illegal, sexual, political, harmful, false, deceiving or misleading information, misuses personal data, or contains malware, unsolicited bulk content, ransomware, or viruses; or (3) in a way that infringes, misappropriates, or violates any third-party rights. Customer shall not put its name or trademark on any AI Feature or make any substantial modification to any AI Feature (including, without limitation, any change that materially alters the intended purpose, design, or performance thereof).
6. Intellectual Property and Ownership. As between SailPoint and Customer, Customer shall own any Input and Output, except to the extent such Output is based on any SailPoint confidential information or other SailPoint data or materials, such as Documentation. Due to the nature of machine learning, Output may not be unique across users, and the AI Features may generate the same or similar Output for other parties. For example, multiple SailPoint customer(s) may ask similar questions and receive the same or similar responses from the AI Features. Such responses are not Customer-specific and therefore not considered Output owned by the Customer. For clarity, Product Analytics (as defined below) and any feedback or suggestions that Customer provides to SailPoint in connection with use of the SailPoint Offerings (including in-app feedback, bug fixes and features requests) do not constitute Input.
7. No High-Risk Use. AI Features are not intended for use in, or in association with, the operation of any hazardous environments or critical systems that may lead to serious bodily injury or death or cause environmental or property damage. AI Features may be used in connection with supporting healthcare services but are not medical devices and are not intended to be used by themselves for any clinical decision-making or other clinical use. Customer is responsible for liability that may arise in connection with any such uses. Customer shall cooperate with and inform SailPoint of any incident arising from Customer’s use of any AI Feature or request from a supervisory authority addressed to the Customer concerning any AI Feature. Customer shall reasonably cooperate with SailPoint including by allowing SailPoint to systematically collect, document and analyze relevant data to allow SailPoint to meet its obligations under AI laws (including the EU AI Act), if any.
8. Disclaimers. CUSTOMER ACKNOWLEDGES THAT THE AI FEATURES RELY ON TECHNOLOGIES THAT ARE INHERENTLY PROBABILISTIC IN NATURE, AND AS SUCH, OUTPUT MAY NOT BE ENTIRELY ACCURATE, PRECISE, COMPREHENSIVE, OR FACTUAL. CUSTOMER’S USE OF THE OUTPUT IS AT ITS SOLE RISK. CUSTOMER SHOULD NOT RELY ON OUTPUT AS THE SOLE SOURCE OF TRUTH OR FACTUAL INFORMATION, AND SHALL EVALUATE OUTPUT FOR ACCURACY, FAIRNESS, AND APPROPRIATENESS FOR CUSTOMER’S PURPOSE AT ALL TIMES.
9. General. SailPoint may modify these AI Terms from time to time by posting a revised version on our website. Customer's continued use of the AI Features after the effective date of the revised AI Terms constitutes Customer’s acceptance of the revised terms.
B. SaaS Terms.
1. SaaS Data Retention & Deletion. The Documentation sets forth data retention and availability commitments with respect to certain types of data. Where not specified elsewhere in the Documentation, during the Customer’s term for the SaaS Services, log data, reports, and similar historical data produced by the SaaS Services may be deleted in accordance with SailPoint’s standard data archival and deletion cycle. Customer may contact their Customer Success Manager for any further details on such retention.
2. SaaS Data Usage. From time to time, SailPoint may use Customer Data or other aspects of Customer’s use of the SailPoint Offerings to generate patterns, statistics, and similar metadata that does not identify Customer or any of Customer’s Users (“Product Analytics”). Product Analytics are owned by SailPoint and, for purposes of the AI Terms, the term “Customer Data” does not include Product Analytics.
FedRAMP authorized SailPoint Identity Security Cloud
1. Interpretation.
1.1 Terms. All defined terms herein have the meaning set forth in these FedRAMP Product Specific Terms. Capitalized terms that are not defined herein shall have the meaning ascribed to them elsewhere in the Agreement or applicable U.S. Federal law or guidelines under the Federal Risk and Authorization Management Program (“FedRAMP”), unless otherwise specified. The “Agreement” is the SailPoint Software as a Service or Software license Framework Customer Agreement or negotiated Agreement between SailPoint and Customer.
1.2 Incorporation. The terms and conditions set forth in these FedRAMP Product Specific Terms are hereby incorporated into and made an integral part of the Agreement, as if fully set forth therein, solely with respect to Customer’s use of SailPoint FedRAMP Offerings that are hosted in SailPoint’s environment pursuant to FedRAMP and shall be construed together with the terms of the Agreement. “SailPoint FedRAMP Offerings” are services hosted in SailPoint’s environment with a FedRAMP authorization and identified in an Order. Except for the changes made by these FedRAMP Product Specific Terms, the Agreement remains unchanged and in full force and effect. Between the Agreement, Data Processing Addendum (DPA), the FedRAMP Product Specific Terms, or applicable Federal Authorities, the Federal Authority controls to the extent applicable to the matter in the following Order of Precedence: Federal Authority, FedRAMP Product Specific Terms, DPA, Agreement.
2. FedRAMP Compliance and Framework. SailPoint FedRAMP Offerings must comply with FedRAMP control guidelines and are monitored and regulated by the U.S. Federal Government. They are subject to modification or update by Federal Authorities and applicable Federal Agencies. “Federal Authority” means any U.S. Federal law, regulation, policy, requirement, or guideline that is applicable to the subject matter and the SailPoint FedRAMP Offering being purchased including Federal Agency specific authority. “Federal Agency” means any U.S. executive department, military department, government corporation, government-controlled corporation, any other establishment in the executive branch (including the Executive Office of the President), or any independent regulatory agency. Pursuant to FedRAMP and applicable Federal Authority direction, SailPoint is limited to what information and access it can provide to non-Federal Agency Customers.
3. Operations.
3.1 Hosting, Storage, and Support. To the extent required by FedRAMP to maintain authorization: (1) SailPoint FedRAMP Offerings shall be hosted within the United States. No Customer Data stored in SailPoint FedRAMP Offerings will be transferred outside of the United States; and (2) Support for the SailPoint FedRAMP Offerings will be provided by SailPoint’s support team located in the U.S., by personnel who are U.S. citizens.
3.2 Customer Data. Customer is prohibited from transferring and storing data in the SailPoint FedRAMP Offerings that is not in compliance with U.S. Federal or State law.
4. Security Addendum. The data security program and certifications set forth described in SailPoint’s Security Addendum available at https://www.sailpoint.com/legal/customer-partner-agreements, including ISO standards, or negotiated security terms between SailPoint and Customer, do not apply to SailPoint FedRAMP Offerings. For SailPoint FedRAMP Offerings, SailPoint shall comply with the applicable security impact controls required by the National Institute of Standards (NIST) Special Publication 800-53 (SP 800-53) and approved for use under the FedRAMP program, including continuous monitoring and the significant change process, which are set forth on the official FedRAMP website, https://www.fedramp.gov/.
5. Data Processing Addendum (DPA). The SailPoint DPA available at https://www.sailpoint.com/legal/customer-partner-agreements, or negotiated DPA between SailPoint and Customer, sets forth the obligations that apply generally to SailPoint and non-FedRAMP Offerings. For Government Customers, the DPA does not apply. “Government Customer” means a U.S. federal, state, local, tribal, territorial and/or lab that is owned by a U.S. Government entity. Government Customer may also include federally funded research centers (FFRDCs), labs, and/or contractors to the extent they are submitting Government information to the SailPoint FedRAMP Offerings.
6. Audits, Penetration Testing, and Vulnerability Management. SailPoint uses a FedRAMP Third-Party Assessment Organization (3PAO) to conduct independent audits, penetration testing, and vulnerability assessments to support Federal Agency authorization and ongoing continuous monitoring at the frequency and scope required by FedRAMP. This 3PAO verifies SailPoint’s compliance with organizational and technical security measures required by FedRAMP for SailPoint’s authorization level. Upon written request from Customer and at the frequency required by FedRAMP for its annual audit, SailPoint may provide (on a confidential basis) penetration test summaries to Customer in the form of an Executive Summary.
Customer acknowledges and agrees there is no Customer testing or auditing of the FedRAMP environment. SailPoint cannot participate in joint Customer-SailPoint exercises, engage in ongoing remediation assessment, oversight, or review with non-Federal Authority Customers. SailPoint’s obligations to provide appropriate technical and organizational measures to protect Customer Personal Information are verified through audits and assessments by SailPoint’s 3PAO. Further, Customer agrees to accept SailPoint’s authorization under the FedRAMP program in lieu of a Customer audit. SailPoint’s evidence of its FedRAMP authorization can be found on the FedRAMP Marketplace at https://marketplace.fedramp.gov/products.
7. Security Incident Response and Notification. SailPoint implements FedRAMP-specific controls, reporting channels, and documentation requirements. For SailPoint FedRAMP Offerings, the applicable FedRAMP “Security Incident” definition in accordance with most updated FedRAMP guidance applies. See https://www.fedramp.gov/, https://www.fedramp.gov/docs/rev5/playbook/csp/continuous-monitoring/incident-communication/.
8. Customer Representations and Warranties. Customer represents and warrants that:
8.1 Customer is either a U.S. incorporated entity or an unincorporated U.S. entity having its principal place of business in the U.S.;
8.2 Customer acknowledges that SailPoint makes no representation or warranty related to the U.S. person status of any Customer or End User that may be granted access to the SailPoint FedRAMP Offerings;
8.3 Customer is responsible to verify the adequacy of the SailPoint FedRAMP Offerings for the storing, processing or accessing of Customer Data and that its use of the SailPoint FedRAMP Offerings will comply with any applicable Federal Authority and any other laws and regulations that may govern Customer Data;
8.4 Customer acknowledges that SailPoint FedRAMP Offerings are hosted in the Amazon Web Services (“AWS”) GovCloud (U.S.) Region. Customer is responsible for meeting applicable Customer eligibility requirements based on the SailPoint FedRAMP Offerings being purchased by Customer, including providing accurate and current SailPoint FedRAMP Customer verification information. Customer shall maintain management processes to review and ensure compliance with applicable third-party information security standards in connection with Customer’s use of such SailPoint FedRAMP Offerings;
8.5 Customer is not subject to U.S. export restrictions or sanctions;
8.6 Customer is not suspended or debarred from contracting with any U.S. government entity;
8.7 Customer’s use of SailPoint FedRAMP Offerings is compliant with applicable U.S. export control laws and regulations, including but not limited to the International Traffic in Arms Regulation; and
8.8 Customer will comply with all applicable security, usage, and data handling FedRAMP requirements, including properly configuring the service and maintaining the FedRAMP information boundary, managing own users and access permissions to prevent misuse, and not introducing data that exceeds the applicable security impact level. Customer will promptly report any actual or suspected unauthorized access, non-compliance, or security incidents affecting SailPoint’s FedRAMP-authorized environment.
9. Compliance. If requested by SailPoint, Customer will promptly provide SailPoint with documentation to verify the accuracy of the representations and warranties contained in Section 8 above. Non-compliance shall be deemed a material breach and SailPoint reserves the right to immediately terminate unauthorized use.
10. Applicable Websites. Any links to external websites are provided for convenience only. SailPoint does not control or endorse the content of third-party sites and does not guarantee their accuracy, completeness, or timeliness. Readers are responsible for independently verifying any information obtained from external sources.
AWS GovCloud (US) FAQs - Amazon Web Services
SailPoint Agentic Fabric Entro Product Specific Terms
1. Interpretation.
(a) Incorporation. The terms and conditions set forth in these SailPoint Agentic Fabric Entro Product Specific Terms are hereby incorporated into and made an integral part of the Agreement, DPA, and Security Addendum as if fully set forth therein, solely with respect to Customer’s use of SailPoint Agentic Fabric Entro Offerings, and shall be construed together with the terms of the Agreement, DPA, and Security Addendum. “SailPoint Agentic Fabric Entro Offerings” are those SKUs beginning with SailPoint Agentic Fabric Entro and identified in an Order. These SailPoint Agentic Fabric Entro Product Specific Terms apply when the SailPoint Agentic Fabric Entro Offerings are (1) licensed as a standalone product offering, or (2) included as a component in a suite or other product bundle offering. Except for the changes made by these SailPoint Agentic Fabric Entro Product Specific Terms, the Agreement, DPA, and Security Addendum remain unchanged and in full force and effect. Among the Agreement, DPA, Security Addendum, and SailPoint Agentic Fabric Entro Product Specific Terms, the SailPoint Agentic Fabric Entro Product Specific Terms control solely with respect to Customer's access to and use of the SailPoint Agentic Fabric Entro Offerings in the following order of precedence: (i) the SailPoint Agentic Fabric Entro Product Specific Terms, (ii) the DPA, (iii) the Agreement, and (iv) the Security Addendum.
2. Agreement Amendments.
These SailPoint Agentic Fabric Entro Product Specific Terms amend the Agreement to the extent necessary so that:
(a) Customer Data Obligations. Customer is solely responsible for all data, files, and content, that it (or anyone acting on its behalf or through its credentials) uploads to, transmits to, or Processes using the SailPoint Agentic Fabric Entro Offerings. Customer acknowledges and agrees that Customer, in its sole discretion, controls and determines the data transferred, stored, and Processed in the SailPoint Agentic Fabric Entro Offerings, which may include “Prohibited Data” or “Sensitive Data” under the Agreement. Customer may transfer, store, and Process Prohibited Data or Sensitive Data solely in the SailPoint Agentic Fabric Entro Offerings and strictly in accordance with these SailPoint Agentic Fabric Entro Product Specific Terms and applicable law.
(b) High Risk Processing. The SailPoint Agentic Fabric Entro Offerings are not intended to be used for High Risk Processing. Any use of the SailPoint Agentic Fabric Entro Offerings for High Risk Processing by Customer or its Users (as defined in Section 2(d)) will be at Customer’s own risk, and Customer will be solely liable for the results of any failure of the SailPoint Agentic Fabric Entro Offerings when used for High Risk Processing. Customer acknowledges that SailPoint does not monitor and will not assess the contents of Customer Data submitted to the SailPoint Agentic Fabric Entro Offerings in order to identify High Risk Processing subject to any specific legal requirements. Customer shall monitor compliance with, and promptly remediate any violation of, its policies and legal requirements relating to the High Risk Processing, and Customer remains fully responsible and liable for all acts and omissions of its Users and such other persons as if they were Customer's own. “High Risk Processing” means (i) processing that is likely to result in a high risk to the rights and freedoms of natural persons, (ii) automated decision-making, including profiling, which produces legal effects concerning a natural person or similarly significantly affects him or her, or (iii) activities where the failure of the SailPoint Agentic Fabric Entro Offerings could lead to death, serious personal injury, or severe environmental or property damage.
(c) Data Minimization. Customer is solely responsible for determining what data is necessary and for implementing appropriate filtering, redaction, de-identification, and access controls prior to and during such use to avoid submitting unnecessary, excessive, prohibited, or sensitive data. SailPoint is not responsible for assessing, and has no obligation to monitor, whether the data Customer submits complies with this Section, and SailPoint shall have no liability for any loss or harm to the extent arising out of Customer's failure to comply with these data minimization obligations.
(d) Protected Health Information and Payment Card Data. The Processing of Protected Health Information and Payment Card Data is not necessary for the use of the SailPoint Agentic Fabric Entro Offerings. Customer acknowledges that the SailPoint Agentic Fabric Entro Offerings are not compliant with the Health Insurance Portability and Accountability Act (“HIPAA”) or the Payment Card Industry Data Security Standard (“PCI DSS”). Notwithstanding (a) above, Customer must not (and must not permit anyone else to) upload to the SailPoint Agentic Fabric Entro Offerings (or use the SailPoint Agentic Fabric Entro Offerings to process) (i) any patient, medical or other protected health information regulated by HIPAA, and (ii) financial data, including payment card data, subject to PCI DSS.
(e) Malicious Code. Customer represents and warrants that it will use commercially reasonable measures (including up-to-date malware scanning and content screening) to ensure that no data, files, or content containing any viruses, spyware, ransomware, timebombs, Trojan horses, other harmful or malicious code, or illegal content are uploaded into the SailPoint Agentic Fabric Entro Offerings. SailPoint shall have no liability or responsibility for any loss, damage, corruption, security incident, or other harm to the extent arising out of or relating to any malicious code, illegal content, or harmful data transmitted to, stored in, or processed in connection with the SailPoint Agentic Fabric Entro Offerings by or on behalf of Customer. Without limiting SailPoint's other rights or remedies, SailPoint may scan, quarantine, remove, disable access to, or refuse to process any such data, files, or content, and may suspend Customer's access to the SailPoint Agentic Fabric Entro Offerings, where SailPoint reasonably believes it contains malicious code, illegal content, or harmful data.
(f) Compliance with Law. Customer acknowledges that while the SailPoint Agentic Fabric Entro Offerings may provide features that could assist Customer in complying with certain regulatory or industry standards (such as HIPAA, SOC 2, GDPR, or other applicable privacy and security frameworks) Customer agrees that it is solely responsible for compliance with all laws applicable to Customer’s use of the SailPoint Agentic Fabric Entro Offerings, including responsibility for (i) ensuring that its use of the SailPoint Agentic Fabric Entro Offerings complies with all local, state, national, and international laws, regulations, and industry standards applicable to Customer’s business, including but not limited to applicable wiretap and eavesdropping statutes, and any comparable laws in jurisdictions; and (ii) determining whether the security and privacy controls of the SailPoint Agentic Fabric Entro Offerings are sufficient to meet Customer's legal and regulatory obligations. Customer will not issue any Processing instruction or use the SailPoint Agentic Fabric Entro Offerings in any manner that would cause SailPoint to violate any laws, including, but not limited to, applicable Data Protection Laws or employment or workplace-monitoring laws. Customer represents and warrants that it has provided all fair processing notices and obtained all consents and rights necessary under applicable laws for SailPoint to Process Personal Information and provide the SailPoint Agentic Fabric Entro Offerings pursuant to the Agreement and this DPA.
(g) Workplace Monitoring. Without limiting the foregoing, where Customer's use of the SailPoint Agentic Fabric Entro Offerings constitutes or could constitute monitoring of employees, contractors, or other members of its (or its Affiliates' or business partners') workforce, Customer represents and warrants that it will, prior to and throughout such use: (i) provide all legally required notices or obtain consents regarding such monitoring; (ii) establish and maintain a valid lawful basis for such monitoring and ensure the monitoring is limited to legitimate, specified purposes and is proportionate to those purposes; (iii) complete any consultation with, or obtain any approval from, works councils, trade unions, employee representatives, or data protection authorities required under applicable law; and (iv) conduct and maintain any data protection impact assessment or equivalent assessment required under applicable Data Protection Laws.
(h) Hosting. SailPoint Agentic Fabric Entro Offerings shall be hosted in a tenant separate from other SailPoint Offerings. SailPoint engages AWS as the hosting services provider for SailPoint Agentic Fabric Entro Offerings. AWS instances are located in the processing locations specified in section 3(e) of these SailPoint Agentic Fabric Entro Product Specific terms.
(i) Software License Grant. For those Customers with no Software terms in their current internal use license Agreement with SailPoint, the following shall apply. During the Term of any Software Offering license term purchased by Customer and subject to the Agreement and these Terms and Conditions, SailPoint grants Customer a limited, non-exclusive, non-transferable (except as otherwise set forth herein), non-sublicensable license to (a) install, execute, copy, display or otherwise use the Software Offering solely for Customer’s internal business purposes and in accordance with the Documentation. Subject to Customer’s payment of all applicable fees, SailPoint shall provide Software Offering Support to Customer in accordance with the terms and conditions of the Agreement during the Term stated on any Order. “Software Offering” means the object code version of the specific SailPoint computer software provided in connection with operating the SaaS Services, including any updates, modifications, new versions, or releases. SailPoint shall have no liability for any performance degradation, conflict, or malfunction arising from the interaction of Software Offering with other software installed on Customer's devices.
3. DPA Amendments.
These SailPoint Agentic Fabric Entro Product Specific Terms amend the DPA to the extent necessary so that:
(a) Categories of data subjects whose Personal Information is transferred. Due to the nature of Personal Information in Customer’s environment, SailPoint may not be able to determine the exact categories of data subjects associated with the Personal Information being processed, which may vary depending on Customer’s use of the SailPoint Agentic Fabric Entro Offerings. Customer acknowledges and agrees that Customer controls and determines the categories of data subjects to whom the Customer Personal Information relates, in Customer’s sole discretion. Notwithstanding the forgoing, the categories of data subjects to whom the Personal Information relates may include Customer’s, authorized Affiliates’, and/or business partners’ employees, contractors, and/or other individuals in Customer’s, authorized Affiliates’, and/or business partners’ workforce, where licensed under the Agreement.
(b) Categories of Personal Information transferred. Due to the nature of Personal Information in Customer’s environment, SailPoint may not be able to determine the exact categories of Personal Information being processed, which may vary depending on Customer’s use of the SailPoint Agentic Fabric Entro Offerings. Customer acknowledges and agrees that Customer controls and determines the categories of Personal Information to be processed in Customer’s sole discretion. Notwithstanding the forgoing, the categories of Personal Information may include: identification and contact data (e.g., name, address, title, contact details), employment details (e.g., job title, role, manager), and/or IT information (e.g., entitlements, IP addresses (including IP derived geolocation), activity data (such as access request activity, authentication activity, password change requests, provisioning activity, and cookie data).
(c) Sensitive data transferred. The SailPoint Agentic Fabric Entro Offerings are not intended to process sensitive data, special categories of personal data, or similar terms, as such terms are defined under Data Protection Laws (“Sensitive Data”). Processing of Sensitive Data is not required to deliver the SailPoint Agentic Fabric Entro Offerings to Customer. Subject to any applicable restrictions and/or conditions in these SailPoint Agentic Fabric Entro Product Specific Terms, the Agreement, DPA, Documentation, or other applicable product specific terms, Customer may also include Sensitive Data in personal information submitted for processing in SailPoint Agentic Fabric Entro Offerings. Due to the nature of Sensitive Data in Customer’s environment, SailPoint may not be able to determine the Sensitive Data being Processed, which may vary depending on Customer’s use of the SailPoint Agentic Fabric Entro Offerings. Customer acknowledges and agrees that Customer controls and determines the categories of Sensitive Data to be processed in Customer’s sole discretion. Notwithstanding the forgoing, Sensitive Data may include: personal information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, data concerning health and/or data concerning a natural person’s sex life or sexual orientation, government-issued identifiers, precise geo-location, financial information, and children’s information.
(d) Retention. Within (30) thirty days of termination of an Order Form for SailPoint Agentic Fabric Entro Offerings, SailPoint shall delete Customer Data from production systems; provided that that SailPoint will not be required to remove copies of the Customer Data from its backup servers until such time as the backup copies are scheduled to be overwritten in the normal course of business, which may be for a period of up to (60) days from the initial point of deletion.
(e) Sub-Processors. SailPoint Agentic Fabric Entro Offerings include the following sub-processors:
| Sub-Processor Name | Location | Processing Activity |
|---|---|---|
| Entro Security Limited | Israel | Affiliates may assist in the provision and management of products and services, including support, devops and professional services. |
| Entro Security Incorporated | US | Affiliates may assist in the provision and management of products and services, including support, devops and professional services. |
| Amazon Web Services (AWS) | US | Primary cloud: storage, databases, SQS, KMS encryption, Bedrock inference. |
| Cloudflare | Global | Edge network for public endpoints: DNS, CDN, WAF, DDoS protection, bot mitigation. |
| Descope | US | End-user authentication and identity (SSO, OIDC, SCIM, MFA, MCP OAuth 2.0). |
| FullStory | US or EU | In-product session analytics within the web application. |
| Google Cloud Platform | US | Secondary cloud: GKE connector workloads, managed data stores, Vertex AI, privately hosted SLM endpoint. |
| IpRegistry | US | IP intelligence / threat enrichment API. |
| Tines | US | Alerting automation for a specific customer solution. |
| Twilio SendGrid | US | Transactional email to platform users (notifications, invitations). |
4. Security terms.
The data security program and certifications set forth described in SailPoint’s Security Addendum available at https://www.sailpoint.com/legal/customer-partner-agreements, or negotiated security terms negotiated between SailPoint and Customer, do not apply to SailPoint Agentic Fabric Entro Offerings. For SailPoint Agentic Fabric Entro Offerings, SailPoint complies with reasonable technical and organizational security measures that are designed to protect Customer Data from Security Incidents and preserve the security and confidentiality of Customer data (“Entro Security Documentation”). Upon request from Customer, SailPoint will provide a copy of the Entro Security Documentation.
5. Updateability.
SailPoint may update these SailPoint Agentic Fabric Entro Product Specific Terms from time to time, by posting to SailPoint’s Customer and Partner Agreements page located at https://www.sailpoint.com/legal/customer-partner-agreements (or any successor page), which will constitute notice to Customer. Changes will apply immediately to any SailPoint Agentic Fabric Entro Offerings purchased after the update. For any previously purchased SailPoint Agentic Fabric Entro Offerings, any updates (a) will not materially degrade the overall performance or security posture of the SailPoint Agentic Fabric Entro Offerings, except to the extent the updates are required to comply with applicable legal or regulatory obligations, and (b) will not apply until the renewal of Customer’s then-current Order Term, except for any updates (1) applicable to new features Customer chooses to use or (2) required to address security, legal, regulatory, or system functionality issues. By continuing to use the SailPoint Agentic Fabric Entro Offerings after any update, Customer agrees to be bound by the updated terms.
SailPoint SAAM Product Specific Terms
1. Interpretation.
(a) Incorporation. The terms and conditions set forth in these SailPoint SAAM Product Specific Terms are hereby incorporated into and made an integral part of the Agreement, DPA, and Security Addendum as if fully set forth therein, solely with respect to Customer’s use of SailPoint SAAM Offerings, and shall be construed together with the terms of the Agreement, DPA, and Security Addendum. “SailPoint SAAM Offerings” are those SKUs beginning with SAAM and identified in an Order. These SailPoint SAAM Product Specific Terms apply when the SailPoint SAAM Offerings are (1) licensed as a standalone product offering, or (2) included as a component in a suite or other product bundle offering. Except for the changes made by these SailPoint SAAM Product Specific Terms, the Agreement, DPA, and Security Addendum remain unchanged and in full force and effect. Among the Agreement, DPA, Security Addendum, and SailPoint SAAM Product Specific Terms, the SailPoint SAAM Product Specific Terms control solely with respect to Customer's access to and use of the SailPoint SAAM Offerings in the following order of precedence: (i) the SailPoint SAAM Product Specific Terms, (ii) the DPA, (iii) the Agreement, and (iv) the Security Addendum.
2. Agreement Amendments.
These SailPoint SAAM Product Specific Terms amend the Agreement and DPA to the extent necessary so that:
(a) SAAM Terms. SailPoint will perform the specified services as detailed in the SailPoint Accelerated Application Management SKU Description and Service Description documents available at https://community.sailpoint.com/t5/Identity-Security-Cloud-Updates/SailPoint-Accelerated-Application-Management/ba-p/273972. For the avoidance of doubt, technical components of SailPoint SAAM Offerings are deemed SaaS services and services components are deemed professional services under the applicable Agreement. SailPoint engages Google Cloud Platform (GCP) as the hosting services provider for SAAM. The GCP instance is located in the European Union and, notwithstanding any statements or terms to the contrary, Customer acknowledges that Customer Data in SAAM will be hosted in the European Union and processed by SailPoint, its affiliates, and sub-processors from their respective locations, which may include locations outside the European Union.
3. Updateability.
SailPoint may update these SailPoint SAAM Product Specific Terms from time to time, by posting to SailPoint’s Customer and Partner Agreements page located at https://www.sailpoint.com/legal/customer-partner-agreements (or any successor page), which will constitute notice to Customer. Changes will apply immediately to any SailPoint SAAM Offerings purchased after the update. For any previously purchased SailPoint SAAM Offerings, any updates (a) will not materially degrade the overall performance or security posture of the SailPoint SAAM Offerings, except to the extent the updates are required to comply with applicable legal or regulatory obligations, and (b) will not apply until the renewal of Customer’s then-current Order Term, except for any updates (1) applicable to new features Customer chooses to use or (2) required to address security, legal, regulatory, or system functionality issues. By continuing to use the SailPoint SAAM Offerings after any update, Customer agrees to be bound by the updated terms.
SailPoint SAIR Offerings Product Specific Terms (applicable to SAIR, DIF, DIFA any suites including such offerings)
1. Interpretation.
(a) Incorporation. The terms and conditions set forth in these SailPoint SAIR Offerings Product Specific Terms are hereby incorporated into and made an integral part of the Agreement, DPA, and Security Addendum as if fully set forth therein, solely with respect to Customer’s use of SailPoint SAIR Offerings, and shall be construed together with the terms of the Agreement, DPA, and Security Addendum. “SailPoint SAIR Offerings” are those SKUs including DIF and DIFA and identified in an Order. These SailPoint SAIR Offerings Product Specific Terms apply when the SailPoint SAIR Offerings are (1) licensed as a standalone product offering, or (2) included as a component in a suite or other product bundle offering, as set forth above. Except for the changes made by these SailPoint SAIR Offerings Product Specific Terms, the Agreement, DPA, and Security Addendum remain unchanged and in full force and effect. Among the Agreement, DPA, Security Addendum, and SailPoint SAIR Offerings Product Specific Terms, the SailPoint SAIR Offerings Product Specific Terms control solely with respect to Customer's access to and use of the SailPoint SAIR Offerings in the following order of precedence: (i) the SailPoint SAIR Offerings Product Specific Terms, (ii) the DPA, (iii) the Agreement, and (iv) the Security Addendum.
2. Agreement Amendments.
These SailPoint SAIR Offerings Product Specific Terms amend the Agreement and DPA to the extent necessary so that:
(a) SAIR Terms. SailPoint engages Google Cloud Platform (GCP) as the hosting services provider for Shadow AI Remediation (SAIR), a component of both the DIF and DIFA SKUs. GCP instances are located in the processing locations specified at https://www.sailpoint.com/legal/sub-processors. Notwithstanding any statements or terms to the contrary, Customer acknowledges that Customer Data in SailPoint SAIR Offerings will be hosted on a GCP instance in the European Union or, if available*, the GCP processing location that best matches the location of Customer’s associated ISC instance, and will be processed by SailPoint, its affiliates, and sub-processors from their respective locations, which may include locations outside the GCP instance location.
*Customer Data may be migrated from the originally-deployed instance upon a regional GCP instance becoming available
3. Updateability.
SailPoint may update these SailPoint SAIR Offerings Product Specific Terms from time to time, by posting to SailPoint’s Customer and Partner Agreements page located at https://www.sailpoint.com/legal/customer-partner-agreements (or any successor page), which will constitute notice to Customer. Changes will apply immediately to any SailPoint SAIR Offerings purchased after the update. For any previously purchased SailPoint SAIR Offerings, any updates (a) will not materially degrade the overall performance or security posture of the SailPoint SAIR Offerings, except to the extent the updates are required to comply with applicable legal or regulatory obligations, and (b) will not apply until the renewal of Customer’s then-current Order Term, except for any updates (1) applicable to new features Customer chooses to use or (2) required to address security, legal, regulatory, or system functionality issues. By continuing to use the SailPoint SAIR Offerings after any update, Customer agrees to be bound by the updated terms.