Legal

    Master Services Agreement

    Last updated: July 9, 2026

    This Master Services Agreement (this “MSA”) is entered into as of the Effective Date by and between Stablerail, Inc., a Delaware corporation (“Stablerail”), and the Customer identified in the applicable Order Form. Stablerail and Customer are each a “Party” and together the “Parties.”

    Background. Stablerail operates a software platform for controlled stablecoin operations, including payment workflows, approvals, counterparty records, risk screening, invoicing, evidence, and integrations with independent wallet, card, fiat-rail, and other providers. Customer wishes to obtain the Services identified in one or more Order Forms. The Parties therefore agree as follows.

    1. Agreement Structure and Scope

    1.1 Agreement Components. This MSA, each Order Form, each statement of work, the schedules attached to this MSA, and any addendum expressly incorporated by reference form the “Agreement.” An Order Form becomes binding when signed or electronically accepted by authorized representatives of both Parties.

    1.2 Order Forms. Each Order Form will identify the Services, Subscription Term, Fees, usage limits, Customer entities, support tier, and any negotiated special terms. No Order Form modifies another Order Form unless it expressly identifies the provision being modified.

    1.3 Customer Affiliates. A Customer Affiliate may enter into an Order Form under this MSA. Each such Order Form creates a separate contract between Stablerail and that Affiliate, and references to “Customer” for that Order Form mean the signing Affiliate. Customer will remain responsible for its own Authorized Users and, if an Order Form so states, jointly and severally responsible for the applicable Affiliate’s obligations.

    1.4 Order of Precedence. In a conflict: (a) service-specific Program Provider terms govern only the applicable Partner Service; (b) a signed Order Form governs over this MSA for that Order Form; (c) an executed data processing addendum governs solely as to processing of Personal Data; (d) this MSA governs over the schedules; and (e) the schedules govern over Documentation.

    1.5 Purchase Orders. Customer purchase orders, vendor portals, click-through procurement terms, and similar documents are for administrative convenience only. Any additional or conflicting terms in them are rejected and have no effect.

    1.6 Electronic Contracting. The Parties consent to electronic records, electronic signatures, and electronic delivery. An electronic acceptance by an authorized representative has the same effect as a handwritten signature.

    1.7 Business Use Only. The Services are offered solely for business and professional use by legal entities and their personnel. They are not consumer accounts or consumer financial products.

    2. Definitions

    “Affiliate” means an entity that directly or indirectly controls, is controlled by, or is under common control with a Party, where “control” means ownership of more than fifty percent of the voting interests or the power to direct management.

    “Applicable Law” means any law, regulation, rule, binding order, sanctions requirement, license condition, or governmental requirement applicable to a Party, the Services, a Transaction, or the relevant activity or jurisdiction.

    “Authorized User” means an individual whom Customer authorizes to access or use the Services, including an administrator, requester, approver, signer, viewer, cardholder, or other role.

    “Blockchain Network” means a distributed-ledger or blockchain protocol, network, layer, bridge, smart-contract system, or related infrastructure used in connection with a Transaction.

    “Confidential Information” has the meaning in Section 14.1.

    “Customer Data” means information, documents, content, instructions, and records submitted to, stored in, or generated through the Services for Customer, including counterparty records, invoices, policies, approval records, and transaction context.

    “Customer Digital Assets” means digital assets beneficially owned or controlled by Customer or its authorized counterparties, including Stablecoins and network-native assets used for fees.

    “Customer Wallet” means a self-custodial blockchain wallet designated by Customer or generated or connected through a Wallet Infrastructure Provider for Customer’s benefit and control.

    “Documentation” means Stablerail’s then-current user documentation, technical instructions, policies, and in-product guidance made available for the Services.

    “Fees” means subscription, implementation, usage, transaction, conversion, partner, support, and other charges stated in an Order Form or presented and accepted in connection with a Transaction.

    “Order Form” means an ordering document, online order, or statement of work that references this MSA and is accepted by both Parties.

    “Partner Service” means a product or service supplied, operated, issued, or regulated by a Program Provider and made available through or in connection with the Services.

    “Personal Data” means information relating to an identified or identifiable natural person, or equivalent regulated personal information under Applicable Law.

    “Private Key Material” means any private key, seed phrase, mnemonic, recovery phrase, exportable key, hardware-wallet secret, signing key share, passphrase, device-bound signing secret, or combination of credentials or cryptographic material sufficient to reconstruct a private key or authorize a blockchain signature.

    “Program Provider” means an independent bank, card issuer, payment institution, money-services provider, wallet infrastructure provider, blockchain analytics provider, digital-asset service provider, protocol, vault, custodian, or other third party that supplies a Partner Service.

    “Services” means the Stablerail-hosted software, APIs, Professional Services, Documentation, and selected Partner Service integrations identified in an Order Form.

    “Stablecoin” means a digital asset represented as maintaining or referencing a value relative to fiat currency or another asset, including USDT, USDC, or another asset supported by the Services.

    “Transaction” means a proposed, approved, signed, submitted, broadcast, settled, reversed, or otherwise processed movement, conversion, payment, card transaction, fiat transfer, or protocol interaction involving Customer.

    3. Orders; Access; Services

    3.1 Provision of Services. Subject to the Agreement, Stablerail will provide Customer access to the Services identified in each Order Form during the applicable Subscription Term.

    3.2 Limited Right of Use. Stablerail grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the Subscription Term to permit Authorized Users to access and use the Services for Customer’s internal business operations.

    3.3 Documentation. Customer will use the Services in accordance with the Documentation and will ensure that Authorized Users receive appropriate operational and security training.

    3.4 Usage Limits. Customer will comply with user, entity, API, transaction, volume, storage, jurisdictional, and other limits in the Order Form or Documentation.

    3.5 Professional Services. Professional Services will be described in an Order Form or statement of work. Unless stated otherwise, deliverables are accepted when delivered, except that Customer may identify a material nonconformity within ten business days and Stablerail will use commercially reasonable efforts to correct it.

    3.6 Subcontractors. Stablerail may use Affiliates and subcontractors to perform the Services. Stablerail remains responsible for their performance to the same extent as for its own performance, except that independent Program Providers are governed by Section 9 and their own terms.

    3.7 No Implied Regulated Service. Access to the Services does not itself authorize Stablerail to take custody of assets, accept deposits, transmit money, execute trades as principal or agent, provide investment advice, or perform any other regulated activity for Customer.

    4. Eligibility; Onboarding; KYB

    4.1 Eligibility. Customer represents that it is duly organized, validly existing, and authorized to enter into the Agreement, and that its use of the Services is lawful in each relevant jurisdiction.

    4.2 KYB and Verification. Customer will provide complete, accurate, and current information requested for know-your-business, beneficial-ownership, identity, source-of-funds, source-of-wealth, sanctions, fraud, and other verification.

    4.3 Ongoing Information. Customer will promptly update changes to its legal name, ownership, control, business model, licenses, jurisdictions, addresses, key personnel, expected activity, source of funds, or other information relevant to risk or eligibility.

    4.4 Approval Is Not Guaranteed. Stablerail or a Program Provider may approve, reject, condition, limit, or withdraw access in its discretion where reasonably based on risk, law, capacity, partner requirements, or incomplete information.

    4.5 No Consumer or Nominee Accounts. Customer may not open or use an account for an undisclosed person, use false or nominee information, or make the Services available to consumers without Stablerail’s prior written approval.

    4.6 Source and Purpose of Funds. Customer represents that all Customer Digital Assets and fiat funds used with the Services are derived from lawful activity and are used for lawful business purposes.

    5. Accounts; Authorized Users; Instructions

    5.1 Customer Administrators. Customer will designate at least one administrator with authority to configure the organization, invite or remove Authorized Users, assign roles, establish policies, connect Customer Wallets, and give administrative instructions.

    5.2 Authorized Users. Customer is responsible for selecting trustworthy Authorized Users, assigning least-privilege roles, maintaining separation of duties, and reviewing access at appropriate intervals.

    5.3 Credentials and Devices. Customer and Authorized Users will protect passwords, passkeys, devices, multi-factor authentication, recovery methods, and other access credentials.

    5.4 Reliance on Instructions. Stablerail may treat an instruction, approval, configuration change, or request submitted through authenticated Customer access as authorized.

    5.5 Policies and Quorums. Customer is solely responsible for configuring approval thresholds, signing quorums, self-approval limits, recipient controls, spending limits, velocity rules, and emergency procedures appropriate to its risks.

    5.6 Audit Logs and Evidence. The Services may record requests, approvals, policy states, risk results, signatures, operator actions, documents, and transaction evidence.

    5.7 Unauthorized Access Notice. Customer will notify Stablerail immediately at the designated security or support channel upon suspected compromise, unauthorized access, fraudulent instruction, loss of a signing device, or attempted social engineering.

    6. Self-Custody; Private Keys; Signing

    The Parties expressly agree to the following custody boundary: Customer retains ownership and control of Customer Digital Assets at all times. Stablerail does not hold Customer Private Key Material and cannot independently create a valid signature for a Customer Wallet. Stablerail may prepare transaction data, apply workflow controls, request human approvals, transmit signing requests to a Wallet Infrastructure Provider, broadcast a signed transaction, and preserve evidence — but it does not sign for Customer.

    6.1 Ownership and Control. As between the Parties, Customer retains all right, title, beneficial ownership, and control in Customer Digital Assets.

    6.2 No Custody. Stablerail does not accept possession or custody of Customer Digital Assets under this Agreement. The Agreement does not create a bailment, trust, escrow, deposit, fiduciary, broker-customer, debtor-creditor, or custodial relationship between Stablerail and Customer with respect to Customer Digital Assets.

    6.3 No Private Keys Held by Stablerail. Stablerail does not receive, possess, store, back up, or have access to Customer’s Private Key Material that would allow Stablerail to reconstruct a Customer private key or create a valid blockchain signature.

    6.4 MPC and Wallet Infrastructure. A Customer Wallet may use multi-party computation, distributed key generation, passkeys, secure enclaves, or similar technology supplied by a Wallet Infrastructure Provider.

    6.5 No Unilateral Signing or Transfer Authority. Stablerail has no general or unilateral power to initiate, approve, sign, reject on Customer’s behalf, reverse, recover, freeze, seize, encumber, or redirect an on-chain transfer of Customer Digital Assets.

    6.6 AI Cannot Move Funds. No artificial-intelligence feature has authority to sign a Transaction or move Customer Digital Assets. AI may draft, classify, flag, explain, or recommend, but a Transaction requires the approvals and cryptographic signatures specified by Customer and the applicable wallet architecture.

    6.7 Customer Responsibility for Keys and Recovery. Customer is solely responsible for selecting signers, protecting Customer-controlled devices and recovery methods, maintaining appropriate redundancy and succession procedures, testing recovery, and ensuring that enough authorized signers remain available.

    6.8 Never Share Private Key Material. Customer and Authorized Users must never upload, email, message, paste, or disclose Private Key Material to Stablerail or its personnel.

    6.9 No Backdoor or Guaranteed Recovery. Unless an applicable Wallet Infrastructure Provider expressly provides a recovery feature under separate terms, Stablerail has no backdoor, master key, administrator key, or ability to restore lost Private Key Material.

    6.10 No Commingling, Lien, or Setoff. Stablerail will not commingle Customer Digital Assets with Stablerail assets and has no lien, security interest, right of setoff, rehypothecation right, or other claim over Customer Digital Assets under this Agreement.

    7. Transactions; Networks; Digital Asset Risks

    7.1 Customer Instructions. Customer is responsible for the business purpose, legality, accuracy, and authorization of each Transaction and for verifying the recipient, address, asset, network, amount, fees, memo, invoice, and supporting information before approval and signing.

    7.2 Finality and Irreversibility. Once a signed Transaction is submitted to a Blockchain Network, it may be irreversible and may not be cancellable, recalled, charged back, or recovered.

    7.3 Addresses and Networks. Sending to an incorrect, incompatible, changed, compromised, unsupported, or fraudulent address or network may result in permanent loss.

    7.4 Network Fees and Quotes. Customer is responsible for network fees, gas, rent, priority fees, bridge fees, conversion spreads, and other Transaction costs unless an Order Form expressly states otherwise.

    7.5 Network Conditions. Blockchain Networks may experience congestion, reorganization, forks, downtime, governance changes, validator or sequencer failure, censorship, replay, protocol bugs, or changes in transaction ordering and finality.

    7.6 Stablecoin and Issuer Risk. A Stablecoin may depeg, lose liquidity, become nonredeemable, be frozen or blacklisted by its issuer, or be affected by reserve, insolvency, regulatory, smart-contract, or market risk.

    7.7 Smart Contracts, Bridges, and Protocols. Interacting with a smart contract, bridge, decentralized protocol, vault, or token exposes Customer to code, oracle, governance, exploit, upgrade, liquidity, validator, slashing, and counterparty risks.

    7.8 Unsupported Assets and Wrong Deposits. Sending unsupported assets, NFTs, tokens, or assets on an unsupported network to a Customer Wallet may make them invisible, inaccessible, or unrecoverable through the Services.

    7.9 Public and Immutable Records. Blockchain addresses, transaction amounts, timestamps, and other data may be public, permanent, and analytically linkable.

    7.10 Taxes and Accounting. Customer is solely responsible for tax characterization, reporting, withholding, accounting, valuation, and recordkeeping for Customer’s Transactions and assets.

    8. Risk Screening; AML Tools; Artificial Intelligence

    8.1 Decision-Support Tools. The Services may use sanctions lists, blockchain analytics, counterparty information, policy rules, behavioral analysis, and AI to generate risk indicators, explanations, suggested actions, or PASS, FLAG, BLOCK, or similar outcomes.

    8.2 No Guarantee. Screening may be incomplete, delayed, inaccurate, unavailable, or based on probabilistic attribution. A low-risk or PASS result does not guarantee that a person, address, asset, source of funds, or Transaction is lawful or safe.

    8.3 False Positives and False Negatives. Customer accepts that screening can produce false positives and false negatives, that addresses and ownership can change, and that illicit exposure may be indirect or unknown.

    8.4 Customer Compliance Responsibility. Stablerail tools do not replace Customer’s own compliance program, risk assessment, customer or counterparty due diligence, sanctions analysis, suspicious-activity procedures, licensing, recordkeeping, or legal advice.

    8.5 AI Outputs. AI-generated content may be incorrect, incomplete, or unsuitable. Customer will review and validate AI output before relying on it, particularly for payment instructions, risk decisions, legal or compliance conclusions, and external communications.

    8.6 No Autonomous Execution. An AI feature may prepare a draft request or recommended workflow but cannot supply Customer’s cryptographic signature or satisfy required human approval by itself.

    8.7 No Advice or Safe Harbor. Risk, AI, and AML features are not legal, regulatory, investment, tax, accounting, or financial advice and do not create a safe harbor, certification, or representation that Customer has satisfied any legal duty.

    9. Partner Services

    9.1 Independent Providers. Partner Services are supplied by independent Program Providers, not by Stablerail. Stablerail may provide integration, onboarding support, user-interface access, data exchange, or first-line support, but the Program Provider is responsible for its regulated or third-party service.

    9.2 Separate Terms. Customer may be required to enter into or accept Program Provider terms, disclosures, privacy notices, cardholder agreements, account agreements, protocol terms, or acceptable-use rules.

    9.3 No Funds Held by Stablerail. Any fiat money, card balance, safeguarded funds, custodial assets, collateral, reserve, or digital assets held in connection with a Partner Service are held, if at all, by the applicable Program Provider under its terms — not by Stablerail.

    9.4 Wallet Infrastructure. A Wallet Infrastructure Provider may supply MPC, passkey, secure-enclave, recovery, or transaction-signing infrastructure. Customer’s rights and remedies regarding that infrastructure may be subject to provider terms.

    9.5 Cards and Fiat Rails. Cards, IBANs, bank or payment accounts, ACH, SEPA, Faster Payments, SWIFT, PIX, SPEI, FX, on-ramp, off-ramp, and related services are subject to eligibility, jurisdiction, currency, corridor, limits, cutoffs, compliance review, and Program Provider availability.

    9.6 Reversals, Chargebacks, and Negative Balances. Card and fiat Transactions may be reversed, rejected, recalled, returned, disputed, or charged back under network or provider rules. Customer is responsible for authorized charges, fees, negative balances, and amounts owed under Program Provider terms.

    9.7 Yield and Protocol Products. Yield features are optional and require Customer instruction and any required provider acceptance. Returns are variable and not guaranteed; principal may be lost; withdrawals may be delayed.

    9.8 Data Sharing. Customer authorizes Stablerail to transmit Customer Data, onboarding information, Transaction information, and instructions to Program Providers as reasonably necessary to provide, secure, support, and comply with law for the selected Partner Services.

    9.9 Insurance and Safeguarding. No asset or balance is FDIC-, SIPC-, government-, or otherwise insured merely because it appears in the Services. Any insurance, safeguarding, segregation, or statutory protection is solely as expressly stated by the applicable Program Provider and Applicable Law.

    10. Customer Responsibilities; Restrictions

    10.1 Lawful and Authorized Use. Customer will use the Services only for lawful, authorized business purposes and in accordance with the Agreement, Applicable Law, and Schedule 4.

    10.2 Counterparty Diligence. Customer is responsible for verifying counterparties, economic purpose, invoices, wallet ownership, payment instructions, changes in beneficiary information, and any off-platform communication.

    10.3 Third-Party and Omnibus Funds. Customer will not hold, pool, administer, or transmit Customer Digital Assets on behalf of Customer’s own underlying clients, investors, or other third parties unless expressly authorized in writing by Stablerail.

    10.4 Licenses and Authorizations. Customer will obtain and maintain all licenses, registrations, approvals, disclosures, consents, policies, and controls required for its business and use of the Services.

    10.5 Records and Supporting Documents. Customer will maintain accurate books, invoices, contracts, payroll records, source-of-funds evidence, recipient records, approvals, and other documents sufficient to support Transactions.

    10.6 No Circumvention. Customer will not bypass eligibility controls, sanctions or geolocation restrictions, transaction limits, security measures, approval workflows, provider requirements, or usage restrictions.

    10.7 No Security Abuse. Customer will not probe, scan, disrupt, overload, reverse engineer, scrape, benchmark publicly, copy, resell, or attempt unauthorized access to the Services.

    10.8 Exports and Backups. Customer will regularly export records and maintain backups appropriate to its legal and operational needs.

    10.9 No On-Chain Sensitive Data. Customer will not intentionally encode personal, confidential, privileged, export-controlled, or legally restricted information in an immutable public blockchain field through the Services unless it has determined that doing so is lawful and appropriate.

    10.10 Cooperation. Customer will reasonably cooperate in security investigations, sanctions or fraud review, incident response, Program Provider inquiries, audits of usage, and remediation of misuse.

    11. Compliance; Sanctions; Regulatory Allocation

    11.1 Mutual Compliance. Each Party will comply with Applicable Law governing its own performance under the Agreement. Customer is responsible for laws governing its business, assets, Transactions, counterparties, and jurisdictions.

    11.2 Sanctions Representation. Customer represents that neither Customer nor, to Customer’s knowledge after reasonable diligence, any beneficial owner, controller, director, Authorized User, source of funds, or intended recipient is a person or entity with whom dealings are prohibited or restricted under applicable sanctions.

    11.3 Restricted Jurisdictions and Persons. Customer will not use the Services from, for, or in connection with a comprehensively sanctioned or otherwise restricted jurisdiction or person.

    11.4 Screening and Information Requests. Stablerail and Program Providers may screen Customer, Authorized Users, counterparties, addresses, IP information, and Transactions and may request information before or after activity.

    11.5 Protective and Reporting Actions. Stablerail may reject or delay processing through the Services, restrict access, preserve records, or make reports or disclosures where reasonably believed necessary to comply with law, legal process, sanctions, fraud prevention, a Program Provider requirement, or protection of the Services.

    11.6 Customer AML and Sanctions Program. Where Customer’s activities require an AML, sanctions, counter-terrorist-financing, transaction-monitoring, travel-rule, suspicious-activity, or similar program, Customer is solely responsible for establishing, operating, testing, and documenting that program.

    11.7 Regulatory Change. If a change in law, regulator position, sanctions, network rule, or Program Provider requirement makes a Service unlawful, impracticable, or materially riskier, Stablerail may modify, limit, migrate, or discontinue the affected Service.

    11.8 Anti-Bribery and Export Controls. Customer will not use the Services in violation of anti-bribery, anti-corruption, export-control, or trade-control laws.

    11.9 Notification Duty. Customer will promptly notify Stablerail of a material regulatory inquiry, license suspension, sanctions designation, law-enforcement action, fraud event, insolvency, or change in business that could materially affect eligibility or risk under the Agreement.

    12. Fees; Taxes; Payment

    12.1 Fees. Customer will pay the Fees in each Order Form and any Transaction-specific Fees accepted through the Services. Subscription and implementation Fees are invoiced in advance unless stated otherwise; usage and pass-through Fees may be invoiced in arrears or charged at execution.

    12.2 Usage Measurement. Stablerail’s metering and transaction records control for billing absent manifest error. Customer must raise a good-faith usage dispute within thirty days after the applicable invoice or statement.

    12.3 Invoices and Payment Terms. Unless an Order Form states otherwise, invoices are due within fifteen days after the invoice date, in U.S. dollars, by the payment method specified by Stablerail.

    12.4 Stablecoin Payment. If Stablerail accepts payment in a Stablecoin, the invoice remains denominated in the stated fiat currency. Customer must deliver the specified asset, network, and amount by the stated deadline and bears network fees, depeg risk, and underpayment caused by transfer or conversion costs.

    12.5 Taxes. Fees exclude sales, use, value-added, goods-and-services, withholding, and similar taxes. Customer will pay taxes arising from its purchases, other than taxes on Stablerail’s net income.

    12.6 Late Payment. Overdue undisputed amounts accrue interest at the lesser of 1.5% per month or the maximum lawful rate, plus reasonable collection costs. Stablerail may suspend Services for material nonpayment after notice and a reasonable cure period.

    12.7 No Refunds. Fees are non-cancellable and non-refundable except as expressly stated in the Agreement. Service credits, if applicable, are not cash refunds and may be applied only to future Fees.

    12.8 No Setoff. Customer may not withhold, net, or set off amounts owed to Stablerail against claims, except as required by a final nonappealable judgment.

    13. Customer Data; Privacy; Security

    13.1 Customer Ownership. As between the Parties, Customer owns Customer Data. Customer grants Stablerail and its subcontractors a non-exclusive right to host, copy, process, transmit, display, analyze, and otherwise use Customer Data only to provide, secure, support, improve, and comply with law for the Services.

    13.2 Customer Responsibilities. Customer represents that it has all rights, notices, consents, and lawful bases required to provide Customer Data and authorize processing under the Agreement.

    13.3 Privacy Terms. Each Party will comply with privacy and data-protection laws applicable to its role. If Stablerail processes Personal Data on Customer’s behalf and Applicable Law requires a data processing addendum, the Parties will execute Stablerail’s then-current addendum or another mutually agreed addendum.

    13.4 Security Program. Stablerail will maintain commercially reasonable administrative, technical, and organizational safeguards designed to protect Customer Data in its possession or control, substantially consistent with Schedule 3. No security measure is infallible, and Schedule 3 is not a guarantee against all incidents.

    13.5 Customer Security. Customer is responsible for secure configuration, role design, Authorized User access, Customer systems, devices, API credentials, connected applications, email security, and Customer-controlled wallet and recovery security.

    13.6 Security Incidents. Stablerail will notify Customer without undue delay after confirming a Security Incident that materially affects Customer Data, provide information reasonably available to Stablerail, take reasonable containment and remediation measures, and cooperate with Customer’s legally required response.

    13.7 Data Export. During the Subscription Term, Customer may export Customer Data using available functionality. Following termination, Stablerail will make then-standard exports available for thirty days where technically and legally feasible, after which access may end.

    13.8 Retention and Deletion. Stablerail may retain Customer Data for the Subscription Term and thereafter as needed for backup cycles, dispute resolution, security, fraud prevention, tax, accounting, sanctions, legal process, Program Provider obligations, and Applicable Law.

    13.9 AI Model Training. Stablerail will not use Customer Data to train a generalized model made available to other customers without Customer’s prior written consent. Stablerail may use deidentified or aggregated information to improve fraud, security, risk, reliability, and product performance.

    13.10 Sensitive Data. Customer will not submit health, biometric, children’s, highly sensitive government, or other specially regulated data unless expressly required for approved onboarding or a selected Service and permitted by Applicable Law.

    14. Confidentiality

    14.1 Definition. “Confidential Information” means nonpublic information disclosed by or on behalf of a Party that is marked confidential or that a reasonable person would understand to be confidential, including business plans, pricing, security information, technology, Customer Data, product roadmaps, and the nonpublic terms of the Agreement.

    14.2 Exclusions. Confidential Information excludes information that the recipient can document: (a) is public without breach; (b) was lawfully known without restriction before disclosure; (c) is received lawfully from a third party without a duty; or (d) is independently developed without use of the discloser’s Confidential Information.

    14.3 Use and Protection. The recipient will use Confidential Information only to perform or exercise rights under the Agreement, protect it with at least reasonable care, and disclose it only to personnel, Affiliates, advisers, auditors, insurers, financiers, and subcontractors who need to know and are bound by confidentiality obligations at least as protective.

    14.4 Compelled Disclosure. The recipient may disclose Confidential Information as required by law, subpoena, court order, or regulator, provided it gives prompt notice where legally permitted and reasonably cooperates, at the discloser’s expense, in seeking confidential treatment.

    14.5 Duration. Confidentiality obligations continue for five years after disclosure, except for trade secrets and Private Key Material, which remain protected for so long as they qualify as trade secrets or remain secret.

    14.6 Equitable Relief. Unauthorized use or disclosure may cause irreparable harm for which monetary damages are inadequate. The discloser may seek injunctive or equitable relief in addition to other remedies.

    15. Intellectual Property

    15.1 Stablerail Ownership. Stablerail and its licensors own all right, title, and interest in Stablerail Technology, improvements, derivative works, and related intellectual property. No ownership transfers to Customer.

    15.2 Restrictions. Customer will not, and will not permit others to: (a) copy, modify, translate, or create derivative works of Stablerail Technology; (b) reverse engineer, decompile, or discover source code, models, or nonpublic APIs; (c) resell, sublicense, lease, or provide the Services to third parties; (d) remove notices; (e) use the Services to build or train a competing product; (f) conduct public benchmarking without consent; or (g) access the Services after suspension or termination.

    15.3 Customer Data and Materials. Customer retains ownership of Customer Data and materials it supplies. Customer grants Stablerail the rights in Section 13.1 and a worldwide, royalty-free license during the Agreement to use Customer trademarks solely as technically necessary to configure Customer-facing outputs and as otherwise approved by Customer.

    15.4 Feedback. Customer may provide suggestions or feedback. Customer grants Stablerail a perpetual, irrevocable, worldwide, royalty-free right to use feedback without restriction or attribution, provided Stablerail does not disclose Customer Confidential Information.

    15.5 Reservation of Rights. Except for the limited rights expressly granted, each Party reserves all rights. No license arises by implication, estoppel, or otherwise.

    16. Support; Changes; Beta Services

    16.1 Support. Stablerail will provide support according to the Order Form and Schedule 2. Response targets are not resolution guarantees.

    16.2 Service Levels. A service-level commitment applies only if the Order Form expressly states that Schedule 2 applies. Partner Services, Blockchain Networks, and Customer systems are excluded from Stablerail availability calculations.

    16.3 Maintenance. Stablerail may perform scheduled and emergency maintenance. Stablerail will use commercially reasonable efforts to give advance notice of material scheduled maintenance and to minimize disruption.

    16.4 Service Changes. Stablerail may update the Services to improve functionality, security, compliance, or efficiency. During a committed Subscription Term, Stablerail will not materially reduce the core functionality purchased by Customer without providing a substantially similar alternative or a pro rata refund.

    16.5 Required Changes. Stablerail may immediately change, limit, or disable a feature where reasonably necessary to address a vulnerability, active attack, sanctions or legal requirement, provider instruction, network event, or material risk.

    16.6 Beta Services. Alpha, beta, preview, pilot, experimental, or no-charge features are provided “as is,” may be changed or discontinued at any time, and are excluded from warranties, support commitments, service levels, and indemnities.

    16.7 Roadmaps. Statements about future products, features, partners, assets, jurisdictions, certifications, or dates are nonbinding and do not create a purchase condition unless expressly included as a signed Order Form commitment.

    17. Representations and Warranties

    17.1 Mutual Authority. Each Party represents that it has full power and authority to enter into the Agreement and that the person accepting it is authorized to bind that Party.

    17.2 Stablerail Service Warranty. Stablerail warrants that during the applicable Subscription Term the hosted Services will materially conform to the Documentation when used as authorized. This warranty does not apply to Partner Services, Beta Services, Customer configuration, unsupported use, or issues caused by Customer, a Program Provider, a Blockchain Network, or circumstances outside Stablerail’s reasonable control.

    17.3 Professional Services Warranty. Stablerail warrants that Professional Services will be performed in a professional and workmanlike manner. Customer must notify Stablerail of a material breach within thirty days after the affected work is delivered.

    17.4 No Malicious Code. Stablerail will not knowingly introduce into the hosted Services code designed to disable, damage, or provide unauthorized access to Customer systems, excluding standard access controls, license enforcement, protective measures, and third-party code outside Stablerail’s reasonable control.

    17.5 Customer Warranties. Customer represents and warrants that: (a) Customer Data and instructions are lawful and accurate in all material respects; (b) Customer has rights and authority over Customer Wallets and Customer Digital Assets; (c) Customer’s use and Transactions do not violate law or third-party rights; and (d) Customer will not use the Services to evade licensing, sanctions, tax, reporting, or other legal obligations.

    17.6 Exclusive Warranty Remedy. For a verified breach of Section 17.2 or 17.3, Stablerail will use commercially reasonable efforts to correct or reperform the affected Service. If Stablerail cannot do so within a reasonable time, Customer may terminate the affected Order Form and receive a pro rata refund of prepaid Fees for the unused affected period.

    18. Disclaimers

    18.1 General Disclaimer. EXCEPT FOR THE EXPRESS WARRANTIES IN SECTION 17, THE SERVICES, PARTNER INTEGRATIONS, DATA, AI OUTPUTS, SCREENING, DOCUMENTATION, AND BETA SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE MAXIMUM EXTENT PERMITTED BY LAW, STABLERAIL DISCLAIMS ALL IMPLIED OR STATUTORY WARRANTIES.

    18.2 Not a Bank or Custodian. STABLERAIL IS A SOFTWARE AND ORCHESTRATION PROVIDER. STABLERAIL IS NOT A BANK, DEPOSIT-TAKING INSTITUTION, OR CUSTODIAN OF CUSTOMER DIGITAL ASSETS UNDER THIS AGREEMENT, DOES NOT HOLD CUSTOMER PRIVATE KEY MATERIAL, AND DOES NOT HAVE GENERAL UNILATERAL SIGNING POWER.

    18.3 No Advice. Stablerail does not provide legal, compliance, tax, accounting, investment, fiduciary, brokerage, securities, commodities, or financial advice.

    18.4 No Compliance Guarantee. Stablerail does not warrant that screening, policies, logs, evidence, or use of the Services will satisfy Customer’s legal or regulatory duties, prevent fraud or sanctions exposure, or identify every risky Transaction.

    18.5 No Asset or Network Warranty. Stablerail does not warrant the value, stability, liquidity, legality, redeemability, reserves, security, operation, finality, or continued availability of a digital asset, Stablecoin, Blockchain Network, smart contract, bridge, or protocol.

    18.6 No Uninterrupted Service. Stablerail does not warrant uninterrupted, error-free, or vulnerability-free operation, or any specific settlement or response time, except for an express service level selected in an Order Form.

    18.7 No Insurance. Customer Digital Assets and balances are not insured, guaranteed, or protected by Stablerail. Any third-party insurance or safeguarding protection exists only as expressly stated by the relevant Program Provider and Applicable Law.

    18.8 Sophisticated Business Customer. Customer acknowledges that digital assets and cross-border financial technology involve material technical, legal, market, and operational risks and that Customer has sufficient expertise or advisers to evaluate them.

    19. Indemnification

    19.1 Stablerail IP Indemnity. Stablerail will defend Customer and its officers and directors against a third-party claim that Customer’s authorized use of the paid hosted Services infringes a U.S. patent, copyright, or trademark or misappropriates a trade secret, and will pay damages and reasonable costs finally awarded or agreed in a settlement approved by Stablerail.

    19.2 IP Remedies. If a claim under Section 19.1 is made or likely, Stablerail may: (a) procure the right to continue use; (b) modify or replace the affected Service with materially equivalent functionality; or (c) terminate the affected Service and refund prepaid Fees for the unused affected period.

    19.3 IP Exclusions. Stablerail has no obligation for a claim arising from: (a) Customer Data; (b) Customer or third-party modifications; (c) use with items not supplied or approved by Stablerail where the combination causes the claim; (d) use after notice to stop; (e) use outside the Agreement or Documentation; (f) Beta Services; or (g) a Program Provider or Partner Service.

    19.4 Customer Indemnity. Customer will defend Stablerail, its Affiliates, and their officers, directors, employees, and agents against a third-party claim, investigation, or demand arising from: (a) Customer Data; (b) Customer’s or an Authorized User’s Transaction, business, product, counterparty, or unlawful use; (c) Customer’s breach of Sections 4, 6, 10, 11, or 17.5; (d) Customer’s custody, control, or transmission of third-party or consumer assets without authorization; (e) Customer’s infringement of third-party rights; or (f) taxes, chargebacks, or regulatory obligations attributable to Customer.

    19.5 Procedure. The indemnified Party will: (a) give prompt notice, with delay excusing obligations only to the extent materially prejudicial; (b) give the indemnifying Party sole control of defense and settlement; and (c) reasonably cooperate at the indemnifying Party’s expense.

    19.6 Exclusive IP Remedy. Sections 19.1-19.3 state Customer’s exclusive remedy for third-party intellectual-property claims covered by those Sections.

    20. Limitation of Liability

    20.1 Excluded Damages. TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES, OR FOR LOST PROFITS, REVENUE, BUSINESS, GOODWILL, EXPECTED SAVINGS, DATA, OPPORTUNITY, OR MARKET VALUE, EVEN IF ADVISED OF THE POSSIBILITY.

    20.2 Digital-Asset Events Outside Stablerail’s Control. Stablerail is not liable for loss, theft, freezing, inaccessibility, depeg, diminution in value, failed settlement, or misdirection of Customer Digital Assets caused by: (a) Customer or Authorized User acts or omissions; (b) compromised Customer credentials, devices, signers, recovery methods, or Private Key Material; (c) an authorized signature; (d) incorrect address, asset, amount, network, or policy configuration; (e) activity outside the Services; (f) a Stablecoin issuer, Blockchain Network, protocol, bridge, smart contract, validator, oracle, exchange, or Program Provider; (g) sanctions or legal action; or (h) market, liquidity, or protocol conditions.

    20.3 General Liability Cap. EXCEPT AS PROVIDED IN SECTIONS 20.4 AND 20.5, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE AGREEMENT WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER TO STABLERAIL UNDER THE AFFECTED ORDER FORM DURING THE TWELVE MONTHS BEFORE THE FIRST EVENT GIVING RISE TO LIABILITY. IF NO FEES WERE PAID OR PAYABLE, THE CAP IS US$1,000.

    20.4 Enhanced Cap. Stablerail’s aggregate liability for: (a) breach of Section 14; (b) a Security Incident caused by Stablerail’s breach of Section 13.4; (c) obligations under Section 19.1; or (d) breach of Section 6.3 or 6.5, will not exceed two times the amount determined under Section 20.3.

    20.5 Liabilities Not Limited. The exclusions and caps do not apply to: (a) Customer’s payment obligations; (b) a Party’s fraud, willful misconduct, or gross negligence; (c) Customer’s indemnity obligations arising from unlawful activity, third-party or consumer assets, sanctions violations, or infringement; (d) Customer’s breach of Section 15.2; or (e) liability that cannot lawfully be limited.

    20.6 Claim Period. To the extent permitted by law, a claim arising from the Agreement must be filed within one year after the claimant knew or reasonably should have known of the facts giving rise to the claim, except claims for unpaid Fees or infringement or misappropriation of intellectual property.

    21. Suspension and Protective Measures

    21.1 Suspension Grounds. Stablerail may suspend or restrict some or all Services if reasonably necessary because of: (a) actual or suspected security compromise, fraud, unauthorized access, or threat; (b) breach of the Agreement; (c) overdue undisputed Fees; (d) sanctions, legal process, or Applicable Law; (e) Program Provider action; (f) risk to Stablerail, users, networks, or third parties; (g) materially false or incomplete onboarding information; or (h) emergency maintenance.

    21.2 Scope and Notice. Stablerail will limit suspension to the affected Service, user, Transaction, or risk where reasonably practicable and will provide notice and an opportunity to cure where lawful and consistent with security.

    21.3 Protective Controls. Protective measures may include disabling logins, APIs, card controls, workflow submission, signing-request routing, or Partner Service access; requiring credential resets or additional approvals; preserving evidence; or applying an emergency platform lock. Such measures do not give Stablerail custody of or signing authority over Customer Digital Assets.

    21.4 Fees During Suspension. Fees continue during a suspension caused by Customer, an Authorized User, nonpayment, or Customer’s legal or security issue. If Stablerail suspends solely for its convenience, Stablerail will provide an equitable service credit for the affected paid period.

    21.5 No Liability for Good-Faith Protection. Stablerail is not liable for a good-faith protective action reasonably taken under this Section, except to the extent the action constitutes Stablerail’s breach, gross negligence, or willful misconduct.

    22. Term; Termination; Exit

    22.1 MSA Term. This MSA begins on the Effective Date and continues until all Order Forms have expired or terminated, unless terminated earlier under this Section.

    22.2 Order Form Term and Renewal. Each Order Form begins on its stated start date and continues for its Subscription Term. Unless the Order Form states otherwise, it renews automatically for successive twelve-month periods unless either Party gives at least thirty days’ notice before the current term ends.

    22.3 Termination for Cause. Either Party may terminate an affected Order Form for a material breach not cured within thirty days after written notice. The cure period is ten days for nonpayment. A breach that cannot be cured may be terminated immediately.

    22.4 Insolvency. Either Party may terminate upon written notice if the other ceases business, makes a general assignment for creditors, becomes subject to a bankruptcy or insolvency proceeding not dismissed within sixty days, or has a receiver appointed over substantially all assets, to the extent permitted by law.

    22.5 Effect of Termination. On expiration or termination: (a) Customer’s right to use affected Services ends; (b) Customer will stop representing that it has access; (c) outstanding Fees become due; (d) each Party will return or protect Confidential Information as required; and (e) Sections intended by their nature to survive will survive.

    22.6 Refunds. If Customer terminates for Stablerail’s uncured material breach, Stablerail will refund prepaid subscription Fees for the unused terminated period. If Stablerail terminates for Customer breach, Customer remains liable for committed Fees for the remainder of the Subscription Term, to the extent enforceable.

    22.7 Wallet Export and Migration. Before termination becomes effective, Customer is responsible for completing any wallet export, signer transition, Program Provider migration, data export, or replacement integration available under the wallet architecture.

    22.8 Assets Remain Customer-Controlled. Because Stablerail does not hold Customer Private Key Material or custody Customer Digital Assets, Stablerail cannot move Customer assets to a replacement wallet on Customer’s behalf.

    22.9 Survival. Sections regarding fees, data, confidentiality, intellectual property, disclaimers, liability, indemnity, and dispute resolution survive expiration or termination, together with accrued rights and any provision that by its nature should survive.

    23. Governing Law; Disputes

    23.1 Executive Escalation. Before filing a claim, a Party will give written notice describing the dispute and the Parties will attempt in good faith for thirty days to resolve it through executives with settlement authority. This does not prevent urgent equitable relief or a filing needed to preserve a limitation period.

    23.2 Delaware Law. The Agreement and any dispute arising out of or relating to it are governed by the laws of the State of Delaware, without regard to conflict-of-laws rules. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

    23.3 Exclusive Forum. Each Party irrevocably submits to the exclusive jurisdiction of the state courts located in New Castle County, Delaware, and the United States District Court for the District of Delaware for any dispute arising out of or relating to the Agreement, and waives objections based on venue or inconvenient forum.

    23.4 Jury Trial Waiver. TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY KNOWINGLY, VOLUNTARILY, AND IRREVOCABLY WAIVES ANY RIGHT TO A TRIAL BY JURY IN ANY ACTION OR PROCEEDING ARISING OUT OF OR RELATING TO THE AGREEMENT.

    23.5 Equitable Relief. A Party may seek temporary, preliminary, or permanent injunctive relief to protect Confidential Information, intellectual property, security, or prevent unauthorized access or unlawful activity, without first completing executive escalation where delay would cause harm.

    23.6 Prevailing Party. In an action to enforce the Agreement, the prevailing Party may recover its reasonable attorneys’ fees and costs, in addition to other relief, to the extent permitted by law.

    24. General

    24.1 Notices. Legal notices must be in writing and delivered by personal delivery, nationally recognized courier, or email with confirmation to the notice addresses in the applicable Order Form. Notices are effective on receipt. Operational, security, billing, and service notices may be delivered by email, in-product message, or the support channel.

    24.2 Assignment. Neither Party may assign the Agreement without the other Party’s consent, not to be unreasonably withheld, except that either Party may assign it without consent to an Affiliate or in connection with a merger, reorganization, financing, or sale of substantially all relevant business or assets, provided the assignee is not a direct competitor of the nonassigning Party and assumes the obligations.

    24.3 Force Majeure. Neither Party is liable for delay or failure caused by events beyond reasonable control, including natural disaster, war, terrorism, civil unrest, labor disruption, government action, internet or cloud failure, widespread cyberattack, Blockchain Network or Program Provider failure, sanctions change, or utility outage.

    24.4 Independent Contractors. The Parties are independent contractors. The Agreement does not create a partnership, joint venture, franchise, fiduciary, employment, agency, or exclusive relationship. Neither Party may bind the other except as expressly stated.

    24.5 No Third-Party Beneficiaries. Except for indemnified persons under Section 19, the Agreement creates no third-party beneficiary rights.

    24.6 Severability. If a provision is held unenforceable, it will be modified to the minimum extent necessary to make it enforceable and preserve intent, and the remaining provisions remain effective.

    24.7 Entire Agreement. The Agreement is the complete agreement about its subject and supersedes prior or contemporaneous proposals, communications, and agreements. Each Party acknowledges it has not relied on a representation not expressly included in the Agreement, without limiting liability for fraud.

    24.8 Amendments. An amendment to this MSA or an Order Form must be in a writing signed or electronically accepted by authorized representatives of both Parties.

    24.9 Publicity. Neither Party may use the other Party’s name, logo, or trademarks in public marketing without prior written consent.

    24.10 Export and Government Use. Customer will comply with export and trade-control laws. The Services are commercial computer software and documentation developed at private expense. Government users receive only the rights granted under the Agreement and applicable procurement law.

    24.11 Language. The controlling language is English. A translation is for convenience only unless an Order Form expressly states otherwise.

    24.12 Electronic Signatures. The Agreement may be executed in counterparts and through an electronic-signature platform, click acceptance, or exchanged PDF. Each counterpart is deemed an original and all constitute one instrument.

    Schedule 1 — Service-Specific Terms

    1.1 Core Platform. The core platform may provide dashboards, approvals, policies, counterparties, transaction records, audit logs, invoices, and evidence. Customer determines its configurations and remains responsible for books, records, internal controls, and accounting.

    1.2 Wallet and MPC Integration. Wallet functionality is self-custodial and may be supplied by a Wallet Infrastructure Provider. Customer must complete provider onboarding, protect Customer-controlled credentials, maintain sufficient signers and recovery methods, and test export or migration procedures.

    1.3 Payments and Batch Payouts. Customer must verify each beneficiary, address, asset, network, and amount before approving a batch. A single batch may contain independently final Transactions and partial failures.

    1.4 Invoices and Receiving Addresses. Invoice and disposable-address features assist reconciliation but do not guarantee payment, legal enforceability, tax treatment, or payer identity.

    1.5 Risk and Screening. Screening frequency, networks, assets, data sources, and usage limits are stated in the Order Form or Documentation. Customer must not represent a risk result as a governmental clearance or certification.

    1.6 Cards. Cards are issued and operated by a Program Provider. Cardholder, network, merchant-category, dispute, chargeback, limits, geographic, and prohibited-use terms apply. Customer is responsible for cardholders and must promptly revoke cards and access when personnel changes occur.

    1.7 Fiat Accounts and Payment Rails. Account details and payment rails are supplied by Program Providers and may be virtual, collection, safeguarded, pooled, or other account structures described by the provider. Settlement, recall, return, and cutoff rules are controlled by the provider and payment system.

    1.8 Conversion. Any conversion quote may include a spread and may expire. Execution can be delayed or rejected for market, liquidity, compliance, or provider reasons. Customer bears price movement until execution is final under the applicable provider terms.

    1.9 Yield. Yield access is opt-in and governed by Program Provider or protocol terms. Displayed APY is variable, estimated, and not guaranteed. Customer authorizes each deposit or withdrawal and is responsible for accounting, tax, liquidity, and risk assessment.

    1.10 AI Features. AI features are decision-support tools. They may use third-party model providers under confidentiality and data-protection controls. Customer must review output. No AI feature can satisfy a required human approval or cryptographic signature.

    Schedule 2 — Service Level and Support Terms

    2.1 Applicability. This Schedule applies only if the Order Form states “Schedule 2 applies.” It applies to the paid Stablerail-hosted core application, excluding Partner Services, Blockchain Networks, Customer systems, Beta Services, Professional Services deliverables, and features designated as excluded.

    2.2 Availability Commitment. Stablerail will use commercially reasonable efforts to make the covered core application available 99.9% of each calendar month (“Availability Commitment”). Availability is measured using Stablerail’s monitoring at the service boundary.

    2.3 Calculation. Monthly availability percentage equals: (total minutes in the month minus Excluded Minutes minus Unavailable Minutes) divided by (total minutes in the month minus Excluded Minutes), multiplied by 100. “Unavailable” means the covered core application is materially inaccessible to substantially all of Customer’s Authorized Users.

    2.4 Excluded Minutes. Excluded Minutes include scheduled maintenance with reasonable notice; emergency maintenance; Customer acts, configurations, integrations, credentials, devices, or networks; Program Provider or Blockchain Network failure; internet, cloud, or telecommunications events outside Stablerail’s reasonable control; force majeure; suspension permitted by the Agreement; Beta Services; and periods when Customer has not reported an issue and Stablerail’s monitoring shows availability.

    2.5 Service Credit Table.

    • 99.9% or higher: No credit
    • Below 99.9% but at least 99.0%: 5% of monthly covered subscription Fee
    • Below 99.0% but at least 98.0%: 10% of monthly covered subscription Fee
    • Below 98.0%: 20% of monthly covered subscription Fee

    2.6 Credit Request. Customer must request a service credit within fifteen days after the affected month, identify the dates and impact, and be current on payment. Credits are applied to future invoices, are not refundable or transferable, and are capped at 20% of the monthly covered subscription Fee.

    2.7 Support Severity.

    • P1 — Critical: 1 hour initial response (24x7 for Priority/Enterprise; otherwise business hours)
    • P2 — High: 4 business hours
    • P3 — Normal: 1 business day
    • P4 — Low: 2 business days

    2.8 Maintenance. Stablerail aims to give at least forty-eight hours’ notice for material scheduled maintenance. Emergency maintenance may occur without advance notice.

    Schedule 3 — Security Measures

    Stablerail will maintain a risk-based security program appropriate to the nature of the Services and Customer Data in Stablerail’s possession or control. The program will include the following categories, as applicable to the relevant systems. These measures do not alter the self-custody boundary in Section 6 and do not represent that Stablerail holds Customer Private Key Material.

    • Governance: Documented security ownership, risk review, policies, and periodic program review.
    • Personnel: Confidentiality obligations, role-appropriate security training, and access removal upon termination or role change.
    • Access Control: Least privilege, role-based access, strong authentication, privileged-access restrictions, and periodic review.
    • Encryption: Encryption in transit using industry-standard protocols and encryption at rest for supported production data stores, where appropriate.
    • Application Security: Secure development practices, code review, dependency management, secrets handling, testing, and controlled deployment.
    • Vulnerability Management: Reasonable scanning, triage, patching, and remediation based on risk and exploitability.
    • Logging and Monitoring: Security and operational logging, alerting, and investigation procedures appropriate to material systems.
    • Infrastructure: Use of reputable cloud or infrastructure providers, network segmentation or logical isolation, and hardened production configurations.
    • Backups and Resilience: Reasonable backup, recovery, and continuity measures for covered Customer Data and critical services, with periodic testing.
    • Incident Response: Documented identification, containment, investigation, remediation, communication, and lessons-learned processes.
    • Vendor Risk: Risk-based diligence and contractual controls for material subprocessors and technology providers.
    • Data Lifecycle: Retention, access, export, deletion, and disposal practices appropriate to contractual and legal requirements.
    • Physical Security: Reliance on cloud and office providers’ physical safeguards and access controls, as applicable.
    • Assurance: Upon reasonable request and subject to confidentiality, available security documentation, questionnaires, or independent reports that Stablerail is authorized to share. No certification is represented unless expressly stated in writing.

    3.1 Security Review. No more than once annually, Customer may request reasonable information to assess Stablerail’s security for the Services. Stablerail may satisfy requests through standard documentation and may decline requests that expose other customers, confidential detection methods, privileged material, or disproportionate risk.

    3.2 Material Changes. Stablerail may change measures as technology and risks evolve, provided the overall security of the covered Services is not materially reduced during a Subscription Term.

    3.3 Customer-Controlled Security. This Schedule does not cover Customer systems, Authorized User devices, Customer-controlled credentials, Private Key Material, Customer Wallet recovery, or Program Provider systems. Customer remains responsible for those areas.

    Schedule 4 — Acceptable Use Policy

    Customer and Authorized Users must not use, facilitate, or knowingly permit use of the Services for any activity below. Stablerail may request information, restrict activity, or suspend access under Section 21 when it reasonably suspects a violation.

    4.1 Illegal and Sanctioned Activity. Any activity that violates Applicable Law, a court order, sanctions, export controls, or Program Provider rules. Transactions involving a prohibited or sanctioned person, entity, address, vessel, jurisdiction, or property without valid authorization. Money laundering, terrorist financing, proliferation financing, sanctions evasion, tax evasion, bribery, corruption, fraud, theft, embezzlement, ransomware, extortion, trafficking, exploitation, or financing of criminal activity.

    4.2 Unlicensed or Undisclosed Financial Activity. Operating an unlicensed money transmission, exchange, brokerage, securities, derivatives, payments, remittance, custody, fiduciary, investment, or banking business through the Services. Holding, pooling, controlling, or transmitting consumer, client, investor, beneficiary, or third-party assets without Stablerail’s written approval and all required licenses and agreements. Using undisclosed nominee, shell, pass-through, nested, or omnibus arrangements, or providing the Services to another business as a service bureau or white-label product without authorization.

    4.3 Obfuscation and Fraud. Using mixers, tumblers, peel chains, chain hopping, fabricated invoices, false identities, false business information, or transaction splitting with intent to conceal source, ownership, destination, or purpose or evade controls. Impersonation, social engineering, account takeover, payment-instruction fraud, merchant fraud, card abuse, chargeback abuse, or receipt of stolen or misappropriated assets. Circumventing geolocation, sanctions, transaction limits, screening, approvals, or security controls.

    4.4 Prohibited Commerce and Harm. Transactions involving illegal drugs, illegal weapons, child sexual abuse material, human trafficking, stolen goods, malicious cyber services, or other unlawful goods or services. Unlicensed gambling, unlawful adult services, counterfeit goods, or other categories prohibited by a Program Provider or disclosed policy. Activity designed to cause harm, evade law enforcement, or materially endanger Stablerail, Program Providers, networks, or third parties.

    4.5 Technical Abuse. Malware, denial-of-service activity, unauthorized scanning, credential stuffing, scraping, excessive automated traffic, interference, or exploitation of vulnerabilities. Reverse engineering, copying, reselling, or using the Services to build a competing service, except where a restriction is prohibited by law. Introducing content or code that infringes rights, compromises systems, or violates privacy or data-protection law.

    4.6 Key and Data Safety. Uploading or disclosing Private Key Material to Stablerail, support personnel, or Customer Data fields. Placing unnecessary personal, confidential, privileged, or regulated data on a public blockchain. Using shared credentials, disabling required security, or allowing unauthorized persons to act as Authorized Users.

    4.7 Review and Enforcement. Stablerail may consider context, intent, legal requirements, and risk in applying this policy. Stablerail may require remediation, additional diligence, limits, suspension, or termination.

    4.8 Updates. Stablerail may update this policy to address legal, security, network, or Program Provider requirements. A material update will be notified where practicable and will not retroactively convert previously lawful completed activity into a breach.