8 Total
1 High severity
4 Medium severity
3 Low severity
Summary

This is the legal agreement between you (or your organization) and Duo Security governing your use of Duo's multi-factor authentication and identity security services. The most important thing to know is that the agreement caps Duo's financial liability for service failures at the amount you paid in the prior twelve months, which could be significant if your organization relies on Duo to protect access to critical systems and experiences a major outage or breach. If you are an administrator deploying Duo for your organization, review whether a separate Data Processing Addendum is needed to meet your privacy compliance obligations.

Technical / Legal Breakdown

This document governs the contractual relationship between Duo Security (a Cisco company) and customers who purchase or use Duo's identity security and multi-factor authentication services, establishing rights and obligations under a click-through or order-form agreement. The terms authorize Duo to collect and process authentication logs, device telemetry, and usage data generated by end users of the service, and the agreement states that customers (as administrators) bear primary responsibility for configuring the service, managing end-user accounts, and ensuring authorized use. The liability limitation provisions cap Duo's aggregate liability at fees paid in the prior twelve months, and the agreement disclaims all implied warranties, which are standard enterprise SaaS constructs though materially significant for businesses relying on Duo for access control to sensitive systems. The document engages GDPR, CCPA, and potentially HIPAA given Duo's healthcare vertical positioning, and customers in regulated industries should evaluate whether the data processing terms and subprocessor arrangements satisfy their sector-specific compliance obligations. Organizations in the EU/EEA should specifically assess whether applicable Data Processing Addenda are in place, as the base terms alone may not satisfy GDPR Article 28 processor agreement requirements.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
High — 1 provision
Medium — 4 provisions
Low — 3 provisions

Monitoring

Duo Security has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Data Collection and Processing and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CFAA
United States Federal
View official text ↗
DSA
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 06:38 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000695
Version ID CA-V-001331
SHA-256 5f8a6adfabd4b78bc5f83c8f3a7ad45dc3f96c373231b228894cc42777d63d0b
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans