Last updated: 23 July 2026. View change log.
This Schedule is part of the Cloud Master Services Agreement between you and Cultrix Limited (“Cultrix”, “we”, “us”). It describes the scope, responsibilities and limits relating to Security and Network.
1. Firewall management
- We run perimeter firewalls and, where applicable, internal firewalls for the Cloud Platform.
- Where firewall management is included, we will:
- maintain baseline rulesets and security policies;
- make rule changes you request, subject to security review;
- apply firmware and software updates during maintenance windows; and
- monitor firewall availability and core health.
- You:
- must tell us which services or ports you need exposed to the internet or to specific networks;
- must not attempt to get around firewall controls; and
- accept that we may decline or adjust firewall rules that create unreasonable risk.
2. VPN and secure connectivity
- Where VPN services are included, we will:
- configure site-to-site or client VPNs using supported standards;
- provide connection details and, where applicable, client configurations; and
- test connectivity with nominated endpoints.
- The relevant quote or design document will describe the types of VPN we support and any limitations.
- You are responsible for:
- configuring your on-premise or third-party devices to establish the VPN;
- managing endpoint security on devices connecting via VPN; and
- keeping VPN credentials or keys secure.
3. Web filtering and outbound security
- Where provided, we may apply web filtering or DNS filtering to traffic leaving the Cloud Platform.
- We may:
- block known malicious domains and content categories (for example malware, phishing);
- apply content categories we agree with you; and
- log and review security-related events.
- Filtering is meant to reduce risk, not to guarantee that we prevent every threat. You remain responsible for user behaviour and for application-level security measures.
4. Logging and monitoring
- We may collect and keep logs from firewalls, VPN devices, remote desktop gateways and other security devices for operational and security purposes.
- Where a more advanced log analysis or SIEM service is included, we will describe it in your Order or in a separate Security Schedule.
- Retention periods for standard logs may vary depending on platform capabilities and storage considerations. If you need extended log retention or specific formats, we may provide this as a separate service.
5. Certificates and encryption
- We may help with:
- installing SSL/TLS certificates on web servers or gateways;
- renewing certificates we manage on your behalf; and
- configuring supported encryption protocols.
- You are responsible for:
- buying certificates where they are not included in the service; and
- renewing any certificates you manage directly.
- We may retire older, insecure protocols or ciphers in line with industry good practice, even if this affects legacy systems. We will give reasonable notice where such changes are likely to affect you.
6. Customer responsibilities
- You remain responsible for:
- deciding your own acceptable level of security, and making sure your use of the Cloud Services matches that level;
- enforcing policies for user access, passwords and multi-factor authentication;
- application-level security (for example input validation, access control, logging); and
- security of any local networks and devices that connect to the Cloud Platform.
- If we identify a configuration or behaviour that poses a serious security risk (for example an exposed administrative interface, weak VPN configuration or open relay), we may take reasonable temporary mitigation steps, including blocking traffic, while we work with you on a longer-term fix.
7. Exclusions
- Unless we state otherwise explicitly, this Schedule does not cover:
- full Security Operations Centre (SOC) services;
- threat hunting or advanced incident response;
- complex network or security architecture design (these are project services); or
- compliance or certification projects (for example PCI, ISO, DORA, and so on).
- We are not responsible for security weaknesses that arise from:
- application design or coding practices;
- unsupported or end-of-life software; or
- decisions you make that go against our documented recommendations.