rConfig Vector Prism, Product Schedule
Version 1.0 Last Updated: 1st January 2026
This Product Schedule forms part of, and is subject to, the rConfig Vector MSP Edition Software Licence Agreement (the "Vector EULA").
Parties and Scope
This Product Schedule ("Schedule") is made between:
OS Informatics Limited, trading as rConfig, a company incorporated in Ireland under company number 751053, with its registered office at 44 Longshore Drive, Jacobs Island, Cork, Ireland ("rConfig"); and
the customer identified in the applicable order, invoice, MSP agreement, or grant letter ("Company").
This Schedule governs Company's use of rConfig Vector Prism ("Prism"), being the white-labellable, multi-tenant operator portal that presents read-only visibility of configuration and compliance data drawn from a Vector Server to Company's End Clients.
Relationship to the Vector EULA
This Schedule supplements and does not replace the Vector EULA. All terms of the Vector EULA apply to Prism as if Prism were part of the Software, except as expressly varied by this Schedule.
Where this Schedule conflicts with the Vector EULA, this Schedule prevails, but only in respect of Prism and only where it expressly identifies the provision of the Vector EULA that it varies. The Vector EULA prevails in all cases in respect of confidentiality, ownership of Intellectual Property Rights, the aggregate limitation of liability and the exclusions from it, data protection roles, and the general restrictions on use.
Capitalised terms not defined in this Schedule have the meanings given in the Vector EULA. A reference to a numbered Section is a reference to a Section of this Schedule unless it expressly refers to the Vector EULA.
1. Prerequisite Licence
1.1 Vector Licence Required
Prism is not available on a standalone basis and cannot operate independently of a Vector Server. Company's right to install and operate Prism is conditional on Company holding, and maintaining in good standing:
- a current licence for the rConfig Vector MSP Edition; and
- a current, paid Vector subscription or maintenance arrangement.
A customer that wishes to operate Prism for internal purposes only, including for its own business units, divisions, or subsidiaries, must nonetheless hold a Vector MSP Edition licence. A Professional or Enterprise licence alone does not entitle a customer to operate Prism.
1.2 Effect of Suspension or Termination
Where Company's Vector licence or subscription is suspended under Vector EULA Section 6.4, Company must not onboard any new Tenant to Prism until the suspension is lifted.
Where Company's Vector licence terminates, Company's right to operate Prism terminates immediately, and Section 9 applies.
1.3 rConfig Does Not Host Prism
rConfig does not host, operate, manage, monitor, or provide Prism as a service. Prism is deployed and operated solely by Company under Section 3.
rConfig gives no availability, uptime, latency, capacity, recovery point, or recovery time commitment in respect of Prism, and no such commitment may be inferred from any Support response target.
2. Licence Grant and Entitlement
2.1 Licence Grant
Subject to this Schedule and to the Vector EULA, rConfig grants Company a non-exclusive, non-transferable, non-sublicensable licence to install, operate, configure, and brand Prism solely:
- in connection with a Vector Server operated by Company under Company's Vector licence; and
- for the purpose of providing read-only visibility to Company's End Clients as part of Company's managed service, or to Company's own internal business units.
Prism is licensed as object code only, save to the extent any component is necessarily supplied in interpretable form. Company obtains no rights in the source code of Prism.
2.2 Per-Tenant Entitlement
Prism is licensed on a per-Tenant basis. Company's entitlement is the number of Tenants stated in the applicable order, MSP agreement, contract, or grant letter.
A Tenant is counted where a logically separated Prism scope is provisioned for an End Client, or for a group of End Clients presented as a single portal audience, regardless of whether any End Client user has logged in and regardless of how many users that Tenant has.
Where the applicable order, MSP agreement, contract, and grant letter are all silent as to Tenant count, the number of Tenants provisioned in the first deployment report produced under Vector EULA Section 6.6 applies, and Company must not exceed that number by more than ten per cent (10%) without rConfig's prior written agreement.
2.3 Exceeding the Tenant Entitlement
Company is treated as exceeding its Tenant entitlement where the number of provisioned Tenants exceeds the licensed number at any point during a rolling thirty (30) day period.
Where rConfig determines that Company is exceeding its Tenant entitlement, rConfig may require Company to purchase additional Tenant capacity, may adjust fees retroactively for the period of exceedance, may suspend Support in accordance with Vector EULA Section 6.4, or may treat persistent exceedance as a material breach under Vector EULA Section 5.2.
Temporary exceedance during a documented End Client onboarding or migration does not constitute a breach provided it is remedied within thirty (30) days and Company notifies rConfig in writing.
Prism Tenant entitlement is separate from, and additional to, Company's device and tenant entitlement under Vector EULA Section 2.1. Devices whose data is presented in Prism continue to count towards that Vector Product Entitlement.
2.4 Reporting
Company will include Prism Tenant counts, Prism instance counts, and the deployment location of each Prism instance in any deployment report requested under Vector EULA Section 6.6, and will notify rConfig under Vector EULA Section 2.5 where Prism is deployed in a new region or jurisdiction.
3. Deployment and Hosting
3.1 Permitted Deployment
Company may deploy Prism:
- on infrastructure owned or controlled by Company, whether on-premises or in a private cloud; or
- in public cloud infrastructure, provided that the account, subscription, tenancy, or project is owned and controlled by Company.
Company must not deploy Prism in infrastructure owned or controlled by an End Client, and must not permit any End Client to install, host, operate, or independently administer a Prism instance.
3.2 Company Responsibility for Operation
Company is solely responsible for, and rConfig has no responsibility or liability in respect of:
- provisioning, sizing, scaling, and operating the Prism hosting environment;
- the operating system, runtime, web server, database, and container platform, including patching and hardening;
- DNS, certificate issuance and renewal, TLS configuration, and the security of the public endpoint;
- availability, performance, backup, restore, and disaster recovery of the Prism instance;
- network exposure, ingress filtering, rate limiting, and any web application firewall or edge protection; and
- monitoring, logging, alerting, and incident response.
3.3 Internet-Facing Exposure
Company acknowledges that Prism is intended to be reachable by End Client personnel and is therefore likely to be exposed to untrusted networks.
Company must:
- follow the Prism deployment and hardening guidance published on the Documentation Website;
- configure authentication, session management, password policy, and multi-factor authentication in accordance with that guidance and with Company's own security policy;
- apply any Prism update that rConfig identifies as addressing a security vulnerability within thirty (30) days of rConfig making it available, or within such shorter period as rConfig reasonably specifies for a vulnerability it classifies as critical; and
- not operate a Prism version that has reached End-of-Life.
Where Company fails to meet an obligation under this Section, the Limited Warranty in Vector EULA Section 9.1 does not apply to Prism, Support in respect of Prism is excluded under Vector EULA Section 4.5, and Company assumes all resulting risk.
3.4 No Availability Commitment to End Clients
Company is solely responsible for any availability, uptime, response, restoration, or reporting commitment it gives to any End Client in respect of Prism.
rConfig gives no such commitment, is not a party to any such commitment, and has no liability for any service credit, penalty, rebate, or damages Company becomes liable to pay an End Client. Vector EULA Section 9.6 applies, and any such amount is an indirect loss as between Company and rConfig.
4. Read-Only Scope
4.1 Prism Is Read-Only to End Clients
Prism is designed to provide End Clients with read-only visibility of configuration, compliance, inventory, and reporting data. End Client users must not be able to initiate any operation that reads from, writes to, or otherwise alters the state of any managed device.
4.2 Prohibited Configuration
Company must not configure, extend, integrate, customise, or operate Prism, and must not combine it with any other component, in a manner that permits any End Client user to:
- initiate or schedule a configuration download, backup, or device poll;
- execute a snippet, command, script, or workflow against any device;
- push, commit, restore, or otherwise apply any configuration to any device;
- view, retrieve, export, or otherwise access any device credential, secret, key, or passphrase;
- create, modify, or delete a device, credential, task, schedule, or automation object;
- alter compliance rules, policies, or templates; or
- access, view, or infer any data belonging to another Tenant.
4.3 Consequence of Write Access
Any use of Prism that permits an End Client to perform an action listed in Section 4.2 is outside the scope of the licence in Section 2.1 and is a material breach for the purposes of Vector EULA Section 5.2.
In addition, in respect of any such use:
- the Limited Warranty in Vector EULA Section 9.1 does not apply;
- Support is excluded under Vector EULA Section 4.5;
- the indemnity in Vector EULA Section 10.2 does not apply; and
- Company assumes all risk and Company's indemnity under Vector EULA Section 10.1 applies, including in respect of any claim by an End Client.
4.4 Company's Own Administrative Access
Nothing in this Section restricts Company's own personnel, or a permitted Managing Party, from performing administrative or operational actions through the Vector Server or through Prism administrative functions, subject to the Vector EULA and to Vector EULA Section 12.2 where AI Output is involved.
4.5 Tenant Separation
Company is responsible for provisioning, verifying, and maintaining Tenant separation within Prism in accordance with Vector EULA Section 2.2, and for ensuring that each Prism user is scoped only to the Tenant to which that user belongs. Company must verify Tenant scoping on each onboarding and after any change to Prism configuration, roles, or integrations.
5. White Labelling and Trade Marks
5.1 White Labelling Permitted
Notwithstanding the prohibition in Vector EULA Section 2.6 on removing, obscuring, or altering proprietary notices, Company may fully white-label the Prism user interface presented to End Clients, including by:
- replacing or removing rConfig names, logos, marks, product names, and visual branding in the interface;
- applying Company's own name, logo, colours, typography, favicon, and email templates;
- presenting Prism under a domain or subdomain controlled by Company; and
- naming the portal as Company chooses, subject to Section 5.3.
5.2 Notices That Must Be Preserved
The permission in Section 5.1 extends to the presentation layer only. Company must not remove, obscure, or alter:
- any copyright notice, licence header, licence file, or attribution contained in the files, packages, or source of Prism;
- any third-party or FOSS attribution or licence text required by Vector EULA Section 8.4; or
- any notice in a location not presented to End Clients in the ordinary course of using the portal.
5.3 Representations Company Must Not Make
Company must not:
- claim, register, or assert ownership of, or any Intellectual Property Right in, Prism or any part of it;
- represent that Company developed, wrote, or owns the underlying software;
- apply for or register any trade mark, domain, or design right that incorporates or is confusingly similar to any rConfig mark; or
- represent that rConfig provides, warrants, supports, hosts, or is otherwise responsible to any End Client in respect of the portal.
Removal of rConfig branding under Section 5.1 does not transfer, licence, exhaust, or otherwise affect any Intellectual Property Right of rConfig, and Vector EULA Section 8.1 continues to apply in full.
5.4 Trade Marks
rConfig grants Company no licence to use any rConfig name, logo, or trade mark, save that Company may identify the Software by name to an End Client where required by that End Client's procurement, audit, or regulatory obligations, in accordance with Vector EULA Section 15.11.
Company grants rConfig no licence to use Company's names, logos, or trade marks, save that rConfig may view and reproduce Company's branding as deployed in a Prism instance to the extent necessary to provide Support or Professional Services.
5.5 Responsibility for Company Branding
Company is solely responsible for its own branding, naming, domain, and content applied to Prism, and for ensuring that they do not infringe any third-party right or breach any applicable law, including advertising, consumer, and accessibility law.
Company's indemnity under Vector EULA Section 10.1 extends to any claim arising from Company's branding, naming, domain, or content, and to any claim that a third party has been misled as to the identity of the provider of the portal.
6. End Clients
6.1 No Direct Relationship
Vector EULA Sections 3.2 and 15.3 apply in full to Prism. End Clients are not licensees of Prism, have no direct relationship with rConfig, and have no right of action against rConfig arising from Prism.
Company must not provide End Clients with rConfig support contact details or ticketing access, and Vector EULA Section 3.4 applies to every Prism issue raised by an End Client.
6.2 Required End Client Terms
The terms Company is required to impose under Vector EULA Section 3.3 must extend expressly to Prism, and must additionally:
- state that access is read-only and that the End Client must not attempt to obtain or exercise any write, execute, or credential-access capability;
- prohibit the End Client from probing, scanning, penetration testing, or attacking the portal, or from attempting to access another Tenant's data;
- prohibit automated scraping, bulk extraction, or systematic download of portal data other than through any export function Company expressly provides;
- require the End Client to keep its portal credentials secure and to notify Company promptly of any suspected compromise; and
- where AI Output is displayed, impose the acknowledgement required by Section 8.
6.3 End Client User Administration
Company is solely responsible for creating, scoping, reviewing, and deprovisioning End Client portal users, including on termination of an End Client engagement or on a user leaving that End Client.
rConfig has no liability arising from Company's failure to deprovision a user, from over-scoped user permissions, or from credentials shared between End Client personnel.
7. Support, Versions, and Warranty
7.1 Support
Prism is supported under Company's existing Support entitlement for the Vector MSP Edition. No separate Support entitlement, coverage, or response target applies to Prism.
Vector EULA Sections 3.4, 4.2, 4.3, 4.5, and 4.9 apply to Prism. Company must complete first-line and second-line triage of any Prism issue, including confirming hosting health, certificate validity, authentication configuration, and Tenant scoping, before escalating to rConfig.
Support does not extend to Company's hosting environment, Company's branding, Company's customisations, or any matter listed in Section 3.2.
7.2 Versions and Updates
Updating Prism is Company-controlled. rConfig does not update a deployed Prism instance and has no ability to do so.
Company must maintain Prism on a version compatible with Company's Vector Server version as set out in the compatibility matrix published on the Documentation Website, and must comply with Section 3.3 in respect of security updates and End-of-Life versions.
rConfig gives no warranty of forward or backward compatibility beyond the versions stated in that compatibility matrix, and Company acknowledges that an Upgrade to the Vector Server may require a corresponding Prism update and an End Client change window.
7.3 Warranty
The Limited Warranty in Vector EULA Section 9.1 applies to Prism, measured from the date of Delivery of the Software, and is subject to the exclusions in Vector EULA Section 9.2 and to Sections 3.2, 3.3, 4.3, and 5.5 of this Schedule.
The warranty is given to Company only and confers no right on any End Client.
7.4 Customisation
Where Company customises Prism beyond the branding permitted by Section 5.1, including by modifying templates, views, styling beyond supported configuration, or by adding integrations, Vector EULA Section 1.6 applies, the Limited Warranty ceases to apply to the customised portions, and Support in respect of those portions is excluded.
8. Artificial Intelligence
Prism contains no AI Feature and generates no AI Output.
Prism may display AI Output generated elsewhere in the Software, including AI-generated summaries, explanations, compliance narratives, or recommendations.
Where Prism displays AI Output to an End Client, Company must:
- ensure that the display clearly identifies the content as generated by an artificial intelligence system and as not verified by rConfig;
- ensure that its End Client terms include an acknowledgement to that effect, and that the End Client is not entitled to rely on that content without its own verification;
- not present AI Output as advice, as a compliance determination, as an audit finding, or as a representation by Company or by rConfig unless Company has itself reviewed and verified it and accepts responsibility for it; and
- not attribute AI Output, or any consequence of it, to rConfig.
Vector EULA Section 12 applies in full, including the review and validation obligations in Vector EULA Section 12.2. Read-only display does not relieve Company of those obligations in respect of any AI Output it acts upon.
9. Data Protection
The data protection provisions of Vector EULA Section 13 apply to Prism.
In addition, and in respect of Prism specifically:
- Prism is deployed and operated exclusively by Company, and rConfig has no access to any Prism instance, to its database, or to any data within it, save where Company expressly grants access in the course of Support or Professional Services;
- Company is the controller in respect of all Personal Data processed in Prism, including End Client portal user account data, authentication data, access logs, and audit records, save where Company acts as an End Client's processor, in which case Company is the processor and rConfig, where it obtains access, is a sub-processor;
- Company is solely responsible for the lawful basis for processing End Client portal user data, for providing the required notices to those users, for handling their data subject requests, and for retention and deletion of that data; and
- Company must ensure that its contract with each End Client permits the creation and processing of portal user accounts and permits any access rConfig may require for Support purposes.
Prism transmits no data to rConfig.
10. Term, Termination, and Effect
10.1 Term
This Schedule takes effect when Company first installs or operates Prism and continues for so long as Company holds a valid Vector licence, unless terminated earlier in accordance with the Vector EULA or this Schedule.
The licence in Section 2.1 is perpetual in the same manner, and subject to the same conditions, as the licence granted under Vector EULA Section 1.5, and usage rights including Tenant capacity, Support, Updates, and Upgrades are tied to an active subscription.
10.2 Termination
This Schedule terminates automatically on termination of the Vector EULA for any reason.
rConfig may terminate this Schedule where Company materially breaches it and fails to cure the breach within thirty (30) days of written notice. Breach of Section 3.1, 4.2, 5.2, or 5.3 is a material breach for the purposes of Vector EULA Section 5.2.
10.3 Effect of Termination
On termination of this Schedule or of the Vector EULA, Company must, within thirty (30) days:
- cease all use of Prism and terminate all End Client access to it;
- decommission every Prism instance and destroy all copies, including images, artefacts, and backups, subject to any retention required by law;
- cease all use of any Prism-derived branding, templates, or interface elements supplied by rConfig, notwithstanding the white-labelling permission in Section 5.1; and
- certify in writing to rConfig, on request, that it has done so.
Company is solely responsible for notifying its End Clients, for exporting or migrating any data those End Clients require, and for any consequence of the loss of portal access.
Where Company is granted a transition licence under Vector EULA Section 5.5, Company may continue operating existing Prism Tenants during the transition period but must not provision any new Tenant, and the obligations in this Section apply on expiry of that period.
11. Definitions
In this Schedule, and in addition to the terms defined in the Vector EULA:
"Prism" means rConfig Vector Prism, in object code form, together with any update or upgrade to it supplied to Company under the Vector EULA.
"Tenant" means, for the purposes of Prism entitlement, a logically separated Prism scope provisioned for an End Client, or for a group of End Clients presented as a single portal audience, as described in Section 2.2.
"Vector EULA" means the rConfig Vector MSP Edition Software Licence Agreement in force between the parties.
"Vector Server" means the rConfig Vector controller component licensed to Company under the Vector EULA, from which Prism draws data.
END OF SCHEDULE