8 Total
1 High severity
4 Medium severity
3 Low severity
Summary

This agreement governs the terms under which organizations and administrators access and deploy Duo Security's multi-factor authentication and identity security services. The agreement establishes that Duo's liability for service failures, outages, or breaches is capped at the fees paid by the customer in the prior twelve months. Organizations requiring compliance with data protection regulations such as GDPR or HIPAA must request a separate Data Processing Addendum to establish Duo's obligations as a data processor.

Technical / Legal Breakdown

This document governs the contractual relationship between Duo Security (a Cisco company) and customers who purchase or use Duo's identity security and multi-factor authentication services, establishing rights and obligations under a click-through or order-form agreement. The terms authorize Duo to collect and process authentication logs, device telemetry, and usage data generated by end users of the service, and the agreement states that customers (as administrators) bear primary responsibility for configuring the service, managing end-user accounts, and ensuring authorized use. The liability limitation provisions cap Duo's aggregate liability at fees paid in the prior twelve months, and the agreement disclaims all implied warranties, which are standard enterprise SaaS constructs though materially significant for businesses relying on Duo for access control to sensitive systems. The document engages GDPR, CCPA, and potentially HIPAA given Duo's healthcare vertical positioning, and customers in regulated industries should evaluate whether the data processing terms and subprocessor arrangements satisfy their sector-specific compliance obligations. Organizations in the EU/EEA should specifically assess whether applicable Data Processing Addenda are in place, as the base terms alone may not satisfy GDPR Article 28 processor agreement requirements.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial
High — 1 provision
Medium — 4 provisions
Low — 3 provisions

Monitoring

Duo Security has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle Data Collection and Processing and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CFAA
United States Federal
View official text ↗
DSA
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 06:38 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000695
Version ID CA-V-001331
SHA-256 5f8a6adfabd4b78bc5f83c8f3a7ad45dc3f96c373231b228894cc42777d63d0b
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans