Institutional Execution · ESIGN Compliant

Full Master Service AgreementElectronic Signature

Full Contract Text — Review Required12 ARTICLES + BAA ATTACHMENT

THIS MASTER SERVICE AGREEMENT is entered into by and between XVILAN Systemic Infrastructures LLC (a financial technology software provider) and the entity accepting this Agreement (the Subscriber). The Platform is a non-custodial, high-throughput ISO 20022 message-processing grid. Full operative language — including limitations of liability, indemnification, arbitration, and the Business Associate Agreement — is reproduced below and in the complete MSA.

01. Definitions & Interpretation

Message means a single ISO 20022 XML message (pacs.002/004/008/009, camt.053) or MT message. Toll means the usage-based per-message fee published on the live toll card at /api/v1/pricing. Enterprise License means an upfront-fee license key (xv_ent_…) under Article 4. UETR means the Unique End-to-End Transaction Reference required by CBPR+.

02. Scope of Services

XVILAN grants a non-exclusive, non-transferable right to use the Platform modules (SHIELD, CLEANSE, TRANSLATE, HARMONIZE) for the Subscriber's own institutional message-processing operations. The Platform is software and message-routing infrastructure only — not a bank, MSB, or money transmitter.

03. Toll Schedule & Payment Terms

Tolls are charged per message at the rates on the live toll card. Self-Serve is prepaid via credits. Enterprise tiers are invoiced quarterly on the license ledger. Taxes and overdue interest apply per the full MSA.

04. Enterprise License & Activation

Enterprise Core ($500K) and Sovereign Overlay ($2.5M) licenses carry SHIELD = max($50, 0.5 bps / 0.25 bps × gross) and CLEANSE 1 bps. Activation occurs on confirmed payment or wire authorization. Each license carries a negotiated daily ceiling (default 1,000,000 msgs/day). Resale, sharing, or sublicensing of license keys is prohibited.

05. Data Processing, PHI Safeguards & Zero-Payload Logging

Zero-payload mandate: message payloads are never written to logs, stdout, stderr, telemetry, or analytics. Only operational metadata is retained. No PHI is stored on public infrastructure. TLS 1.3 in transit, AES-256 at rest, HSM-backed secrets. BAA obligations per Attachment A.

06. UETR & CBPR+ Compliance Duties

Subscriber must ensure every payment message carries a valid UETR where CBPR+ requires it. Subscriber is responsible for sanctions, AML, and KYC compliance. Subscriber shall not submit fraudulent or unlawful messages.

07. Service Levels & Performance

XVILAN will use commercially reasonable efforts to maintain 99.9% availability per calendar month. Throughput and latency targets are set per tier and are non-binding aspirations except where expressly committed in writing.

08. Confidentiality & Security

Each party protects the other's Confidential Information. Subscriber must keep license keys, API keys, and credentials confidential and notify XVILAN immediately of any suspected compromise.

09. Term & Termination

Either party may terminate for cause on 30 days' written notice after uncured breach. XVILAN may terminate immediately for non-payment, license abuse, or conduct endangering the Platform. Data, confidentiality, liability, indemnity, and governing-law articles survive termination.

10. Limitation of Liability

Neither party is liable for indirect, incidental, special, consequential, or punitive damages. Aggregate liability is capped at the greater of amounts paid in the preceding 12 months or USD 50,000, excluding indemnity and data obligations. XVILAN is not a settling party — settlement finality rests with Regulation J / UCC Article 4A rails.

11. Indemnification

Subscriber indemnifies XVILAN against third-party claims arising from submitted payloads, breach of this Agreement, misuse of license keys, or infringement claims based on Subscriber data. XVILAN indemnifies Subscriber against infringement claims on the delivered Platform.

12. Governing Law, Dispute Resolution & General Provisions

Governed by New York law. Disputes go to binding AAA arbitration in New York, NY, after a 30-day executive negotiation period. Electronic signature is binding under ESIGN Act and UETA. Entire-agreement, amendment, and severability provisions apply.

Attachment A · Business Associate Agreement

1. Role

To the extent the Subscriber transmits any Protected Health Information to the Platform (which the MSA generally prohibits), the Subscriber is the Covered Entity and XVILAN is the Business Associate.

2. Permitted Uses

The Business Associate may use and disclose PHI only as required to perform the Platform services or as required by law.

3. Safeguards

Administrative, physical, and technical safeguards, including AES-256 at rest and TLS 1.3 in transit.

4. Breach

The Business Associate shall report any breach of unsecured PHI within 60 days of discovery per 45 C.F.R. § 164.410.

5. Subcontractors

Any subcontractor receiving PHI agrees to the same restrictions and conditions as the Business Associate.

6. Access & Amendment

PHI made available for access, amendment, and accounting of disclosures per 45 C.F.R. §§ 164.524/164.526/164.528.

7. Term & Survival

BAA obligations survive termination until all PHI is destroyed or returned.

IP address logged · Timestamp recorded · SHA-256 signature hash stored in agreement ledger