XVILAN Systemic Infrastructures LLC · Legal

Master Service Agreement.

Version 2.0 · Full Master ContractEffective: 2026-08-29ISO 20022 / CBPR+ Message InfrastructureINCLUDES BAA ATTACHMENT A

THIS MASTER SERVICE AGREEMENT (this “Agreement”) is entered into as of the date of electronic execution (the “Effective Date”) by and between XVILAN Systemic Infrastructures LLC (a financial technology software provider, “XVILAN”) and the entity or individual accepting this Agreement (the “Subscriber”), each a “Party” and together the “Parties.”

Recital A
XVILAN operates a non-custodial, high-throughput ISO 20022 message-processing grid (the “Platform”) providing deterministic validation (SHIELD), structured address remediation (CLEANSE), cross-rail translation (TRANSLATE) and network mapping (HARMONIZE) for payment and settlement messages.
Recital B
The Platform does not hold, transmit on its own balance sheet, or settle funds. All settlement is performed exclusively by regulated rails (Fedwire, TARGET2, CBPR+ participant banks) in accordance with Regulation J and UCC Article 4A.
Recital C
The Subscriber wishes to access the Platform under the toll schedule and terms set forth herein, and XVILAN wishes to provide such access in accordance with this Agreement.
ART. 01

Definitions & Interpretation

1.1 “Message” means a single ISO 20022 XML message (e.g. pacs.002, pacs.004, pacs.008, pacs.009, camt.053) or a single MT message submitted to the Platform for processing through any module.

1.2 “Toll” means the usage-based fee charged per Message per module, as published on the live toll card available at /api/v1/pricing and incorporated by reference.

1.3 “Enterprise License” means an upfront-fee license key (xv_ent_…) issued under Article 4 granting access to Enterprise Core or Sovereign tier processing with quarterly utility invoicing.

1.4 “UETR” means the Unique End-to-End Transaction Reference, a mandatory CBPR+ field propagated across the entire message chain.

1.5 “PHI” means Protected Health Information as defined by HIPAA. “Message Payload” means the substantive content of a Message, including narrative fields, payment references, and beneficiary/ordering party details.

1.6 Capitalized terms not otherwise defined herein have the meanings ascribed in the toll card, the Privacy Policy, and the Business Associate Agreement set forth in Attachment A.

ART. 02

Scope of Services

2.1 Subject to the terms of this Agreement, XVILAN grants the Subscriber a non-exclusive, non-transferable, revocable right to access and use the Platform modules for the Subscriber’s own institutional message-processing operations. The modules are:

SHIELD

MX validation, duplicate detection, and inbound pacs.002 status mapping.

CLEANSE

Structured address remediation and PostAdr-style correction of routing fields.

TRANSLATE

Bidirectional MT ↔ MX ISO 20022 translation engine.

HARMONIZE

Cross-rail network mapping and pacs.004 settled-return reconciliation.

2.2 The Platform is provided as software and message-routing infrastructure only. XVILAN is not a bank, money services business, or money transmitter, and does not provide clearing, settlement, custody, or escrow services.

ART. 03

Toll Schedule & Payment Terms

3.1 Tolls. The Subscriber shall pay the applicable Tolls for each Message processed, at the rates published on the live toll card (/api/v1/pricing). The rates are deterministically computed by the Platform engine and cannot be modified by the Subscriber. As of the Effective Date: SHIELD USD 50.00/msg; CLEANSE 1 bps of gross USD; TRANSLATE USD 10.00/msg; HARMONIZE USD 25.00/msg (Self-Serve base, multi-currency equivalents available on the toll card).

3.2 Self-Serve Prepayment. Self-Serve access is prepaid. The Subscriber purchases prepaid credits via the Platform checkout; each Message deducts the applicable Toll from the credit balance. No arrears, no minimum.

3.3 Enterprise Invoicing. Enterprise Core and Sovereign tier licenses are invoiced quarterly based on accrued Message count and gross volume recorded on the license ledger. Tolls for Enterprise tiers are set out in Article 4 and may be more favorable than Self-Serve rates.

3.4 Taxes. Tolls are exclusive of all taxes. The Subscriber is responsible for all applicable sales, use, VAT, and withholding taxes, except taxes on XVILAN’s net income.

3.5 Overdue. Unpaid invoices are subject to interest at the rate of 1.5% per month or the maximum permitted by law, whichever is less.

ART. 04

Enterprise License & Activation

4.1 Tiers. Two Enterprise tiers are available:

ENTERPRISE CORE$500,000

SHIELD = max($50, 0.5 bps × gross); CLEANSE 1 bps; quarterly MSA invoicing; annual term; up to the negotiated daily message ceiling.

SOVEREIGN OVERLAY$2,500,000

SHIELD = max($50, 0.25 bps × gross); CLEANSE 1 bps; quarterly MSA invoicing; multi-year term; sovereign multi-lane enclave allocation; priority throughput.

4.2 Activation. An Enterprise License is issued in PENDING status upon execution of the applicable upfront payment. Activation (PENDING → ACTIVE) occurs upon confirmation of payment or, in the case of wire activation by XVILAN, upon written authorization. The Subscriber’s API gateway authentication is gated on an ACTIVE license.

4.3 Daily Ceiling & Abuse. Each license carries a negotiated daily message ceiling (default 1,000,000 Messages/UTC day). Processing is hard-blocked above the ceiling and XVILAN’s security operations are notified automatically. Subscriber shall not resell, share, or sublicense license keys, or permit usage inconsistent with this Article.

4.4 Suspension. XVILAN may suspend a license immediately if the Subscriber breaches this Agreement, exposes a key, or engages in conduct that could cause harm to the Platform or its other Subscribers.

ART. 05

Data Processing, PHI Safeguards & Zero-Payload Logging

5.1 Zero-Payload Logging. XVILAN operates under a strict zero-payload mandate. Message Payload content is never written to application logs, stdout, stderr, telemetry streams, or analytics. Only operational metadata (Message count, rail, toll line items, routing status) is retained.

5.2 No PHI Storage. No Protected Health Information or clinical artifacts are uploaded to, or persisted on, the public infrastructure. Subscribers are prohibited from submitting PHI to the Platform.

5.3 Encryption. All data in transit is encrypted with TLS 1.3; all retained metadata is encrypted at rest with AES-256. Secrets are held in HSM-backed vaults in the designated region.

5.4 BAA. The parties’ obligations with respect to any Protected Health Information are governed exclusively by the Business Associate Agreement attached as Attachment A and incorporated by reference.

ART. 06

UETR & CBPR+ Compliance Duties

6.1 The Subscriber shall ensure that every payment Message submitted to the Platform carries a valid UETR where required by CBPR+ or SWIFT messaging standards. The Platform will flag, and may reject, Messages missing a UETR.

6.2 The Subscriber is responsible for compliance with all applicable sanctions, anti-money-laundering, and know-your-customer obligations relating to the underlying transactions, including OFAC and EU sanctions screening. The Platform does not perform sanctions screening and makes no representation that submitted Messages comply with applicable law.

6.3 The Subscriber shall not submit Messages that are fraudulent, unlawful, or otherwise violate the rights of third parties.

ART. 07

Service Levels & Performance

7.1 XVILAN will use commercially reasonable efforts to maintain Platform availability of 99.9% per calendar month, excluding scheduled maintenance and events outside XVILAN’s reasonable control.

7.2 Throughput targets, latency envelopes, and capacity commitments are set out in the applicable Service Level schedule for the Subscriber’s tier and are non-binding performance aspirations except where expressly committed in writing.

ART. 08

Confidentiality & Security

8.1 Each Party shall protect the other’s Confidential Information using the same degree of care it uses for its own confidential information, and no less than reasonable care. “Confidential Information” includes non-public pricing, license keys, credentials, technical data, and business plans.

8.2 The Subscriber shall keep all license keys, API keys, and credentials confidential and shall notify XVILAN immediately of any suspected compromise.

ART. 09

Term & Termination

9.1 This Agreement commences on the Effective Date and continues until terminated as provided herein.

9.2 Either Party may terminate this Agreement for cause upon 30 days’ written notice if the other Party materially breaches this Agreement and fails to cure within the notice period. XVILAN may terminate immediately for non-payment, license abuse, or conduct endangering the Platform.

9.3 Upon termination, the Subscriber’s prepaid credit balance, net of any outstanding amounts, shall be refunded within 60 days; accrued unpaid Tolls remain due. Article 5 (Data), Article 8 (Confidentiality), Article 10 (Liability), Article 11 (Indemnity), and Article 12 (Governing Law) survive termination.

ART. 10

Limitation of Liability

10.1 Exclusion. TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY SHALL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, LOST REVENUE, OR LOST DATA, ARISING OUT OF OR RELATING TO THIS AGREEMENT.

10.2 Cap. EXCEPT FOR A PARTY’S INDEMNIFICATION OBLIGATIONS AND BREACHES OF ARTICLE 5, EACH PARTY’S AGGREGATE LIABILITY UNDER THIS AGREEMENT SHALL NOT EXCEED THE GREATER OF (A) THE AMOUNTS PAID BY THE SUBSCRIBER TO XVILAN IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM, OR (B) USD 50,000.

10.3 Not a Settling Party. XVILAN is not responsible for the performance, failure, delay, or insolvency of any clearing or settlement rail, or for the finality of any settlement, which is final and irrevocable once confirmed per Regulation J and UCC Article 4A.

ART. 11

Indemnification

11.1 The Subscriber shall indemnify, defend, and hold harmless XVILAN and its officers, directors, employees, and agents from and against all third-party claims, losses, damages, and expenses (including reasonable attorneys’ fees) arising from (a) the Message Payloads the Subscriber submits, (b) the Subscriber’s breach of this Agreement or applicable law, (c) the Subscriber’s misuse of license keys, or (d) any third-party claim that Subscriber’s data infringes any right of a third party.

11.2 XVILAN shall indemnify the Subscriber against third-party claims that the Platform as delivered infringes a valid patent or copyright, subject to the limitations in Article 10.

ART. 12

Governing Law, Dispute Resolution & General Provisions

12.1 Governing Law. This Agreement is governed by and construed in accordance with the laws of the State of New York and the federal laws of the United States, without regard to conflict-of-law principles.

12.2 Dispute Resolution. The Parties shall attempt in good faith to resolve any dispute arising out of this Agreement through executive negotiation. Failing resolution within 30 days, the dispute shall be submitted to binding arbitration administered in New York, NY, in accordance with the rules of the American Arbitration Association. Each Party consents to the exclusive jurisdiction of such arbitration. This Article does not preclude either Party from seeking injunctive relief in any court of competent jurisdiction.

12.3 Entire Agreement. This Agreement, including the toll card and Attachment A, constitutes the entire agreement between the Parties and supersedes all prior agreements and understandings.

12.4 Electronic Signature. The Parties agree that this Agreement may be executed by electronic signature in accordance with the ESIGN Act and UETA. A typed signatory name together with an IP address and timestamp constitutes a legally binding electronic signature.

12.5 Amendments. XVILAN may amend this Agreement upon 30 days’ notice; continued use of the Platform after the effective date of the amendment constitutes acceptance.

12.6 Severability & Waiver. If any provision is held unenforceable, the remaining provisions remain in full force. No waiver is effective unless in writing.

Attachment A · Business Associate Agreement

1. Role

To the extent the Subscriber transmits any Protected Health Information to the Platform (which this Agreement generally prohibits), the Subscriber is the Covered Entity and XVILAN is the Business Associate.

2. Permitted Uses

The Business Associate may use and disclose PHI only as required to perform the Platform services or as required by law, and shall not use or disclose PHI in a manner that would violate HIPAA if done by the Covered Entity.

3. Safeguards

The Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI, including AES-256 encryption at rest and TLS 1.3 in transit.

4. Breach

The Business Associate shall report any breach of unsecured PHI to the Covered Entity within 60 days of discovery, without unreasonable delay, and in no case later than the deadline required by 45 C.F.R. § 164.410.

5. Subcontractors

The Business Associate shall ensure any subcontractor that receives PHI agrees to the same restrictions and conditions that apply to the Business Associate.

6. Access & Amendment

The Business Associate shall make PHI available to the Covered Entity for access and amendment as required by 45 C.F.R. §§ 164.524 and 164.526, and provide an accounting of disclosures as required by § 164.528.

7. Term & Survival

The obligations of this Attachment survive termination of this Agreement and continue until all PHI held by the Business Associate is destroyed or returned.

XVILAN Systemic Infrastructures LLC

By: ______________________________

Title: ______________________________

Date: ______________________________

Subscriber

Entity: ______________________________

By (typed signature): ______________________________

Title: ______________________________

Date: ______________________________

© 2026 XVILAN Systemic Infrastructures LLC. All Rights Reserved.Sign this agreement electronically →