Track 1 platform and get the weekly governance digest. No credit card required.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This agreement governs the terms under which organizations and administrators access and deploy Duo Security's multi-factor authentication and identity security services. The agreement establishes that Duo's liability for service failures, outages, or breaches is capped at the fees paid by the customer in the prior twelve months. Organizations requiring compliance with data protection regulations such as GDPR or HIPAA must request a separate Data Processing Addendum to establish Duo's obligations as a data processor.
This document governs the contractual relationship between Duo Security (a Cisco company) and customers who purchase or use Duo's identity security and multi-factor authentication services, establishing rights and obligations under a click-through or order-form agreement. The terms authorize Duo to collect and process authentication logs, device telemetry, and usage data generated by end users of the service, and the agreement states that customers (as administrators) bear primary responsibility for configuring the service, managing end-user accounts, and ensuring authorized use. The liability limitation provisions cap Duo's aggregate liability at fees paid in the prior twelve months, and the agreement disclaims all implied warranties, which are standard enterprise SaaS constructs though materially significant for businesses relying on Duo for access control to sensitive systems. The document engages GDPR, CCPA, and potentially HIPAA given Duo's healthcare vertical positioning, and customers in regulated industries should evaluate whether the data processing terms and subprocessor arrangements satisfy their sector-specific compliance obligations. Organizations in the EU/EEA should specifically assess whether applicable Data Processing Addenda are in place, as the base terms alone may not satisfy GDPR Article 28 processor agreement requirements.
Institutional analysis available with Compliance
Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.
Start Compliance free trialMonitoring
Duo Security has updated this document before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
Compliance Governance Intelligence
Need provision-level monitoring and regulatory mapping?
Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.
Start Compliance free trialCross-platform context
See how other platforms handle Data Collection and Processing and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.