TSRB Systems LLC
Aerospace and Defense Addendum
Effective date: September 16, 2026
This Aerospace and Defense Addendum ("Addendum") supplements the TSRB Systems LLC Terms and Conditions for Products and Services ("Terms"). It applies only when an executed TSRB Quote expressly incorporates this Addendum.
This Addendum defines how aerospace, aviation, space, defense, AS9100, export-control and related customer flow-down requirements apply to TSRB software, deployment services, support and any expressly identified hardware.
1. Scope and Order of Precedence
1.1 Capitalized terms not defined here have the meanings in the Terms. If this Addendum conflicts with the Terms, this Addendum controls only for the regulated work expressly identified in the applicable Quote.
1.2 Customer-specific flow-downs apply only when provided to TSRB in full before pricing, listed or attached to the Quote and expressly accepted by TSRB. A general reference to a supplier portal, quality manual, website or future revision does not incorporate that material.
1.3 A revised or newly introduced requirement after acceptance is a scope change and may require revised fees, schedule, architecture, hosting, staffing or technical controls.
2. Nature of TSRB Deliverables
2.1 TSRB primarily supplies commercial software and professional services. Requirements written for raw materials, manufactured aerospace parts or special physical processes apply only to TSRB-supplied hardware when relevant and expressly stated in the Quote.
2.2 Unless expressly stated, TSRB does not perform aerospace design approval, airworthiness certification, source inspection, product release, material testing, nondestructive testing or special manufacturing processes.
2.3 TSRB's products provide information and workflow support. Customer remains responsible for product conformity, production release, inspection, safety, regulatory decisions and compliance of Customer-manufactured items.
3. Quality Management and Certification Status
3.1 TSRB will maintain documented controls reasonably appropriate to its software development, testing, deployment, support and corrective-action activities.
3.2 Nothing in the Terms, this Addendum or TSRB's performance represents that TSRB is certified to AS9100, ISO 9001, CMMC, FedRAMP or another standard unless TSRB expressly confirms that certification in writing.
3.3 TSRB will comply with specific quality requirements only to the extent they apply to the identified deliverable and are expressly accepted in the Quote.
4. Specifications, Configuration and Acceptance
4.1 Software and service conformity is measured against the signed Quote, statement of work, interface specification, written acceptance criteria and applicable TSRB documentation—not against requirements that were not disclosed or accepted.
4.2 TSRB will use reasonable configuration and revision controls for specifications and deliverables within scope. Customer shall promptly identify authoritative document revisions and notify TSRB of discrepancies.
4.3 When a certificate of conformance is expressly required, TSRB may provide a deployment, service or milestone-conformance statement identifying the applicable deliverable and accepted requirements. Physical-material, lot or special-process certification is not required for software unless expressly agreed.
4.4 Acceptance testing and deemed acceptance are governed by the Terms and the applicable Quote.
5. Nonconformity and Corrective Action
5.1 TSRB will evaluate a documented material nonconformity against the accepted requirements and, when appropriate, provide correction, containment or corrective-action information proportionate to its impact.
5.2 TSRB will notify Customer without unreasonable delay after confirming a material post-delivery nonconformity that adversely affects agreed functionality, data integrity, security or regulatory conformity.
5.3 Customer shall provide sufficient evidence, system access and cooperation for investigation. TSRB is not responsible for conditions caused by Customer systems, third parties, unauthorized changes or use outside agreed requirements.
6. Product, Process and Location Changes
6.1 TSRB may update and maintain its commercial software under the Terms.
6.2 TSRB will provide reasonable advance notice, when practicable, of a planned material change to the contracted architecture, hosting location, security controls or functionality that is reasonably expected to adversely affect an expressly accepted regulatory requirement.
6.3 Routine updates, security patches, defect corrections, infrastructure maintenance and changes that do not materially impair accepted requirements do not require Customer approval.
7. Records and Retention
7.1 TSRB will retain project, testing, release, corrective-action and conformity records specifically identified in the Quote for the agreed retention period. If the Quote requires retention but does not state a period, the default period is ten years after completion of the applicable regulated work.
7.2 Customer production data, high-volume telemetry, temporary files, system logs and backups are governed by the service's standard retention practices unless the Quote expressly states otherwise.
7.3 Extraordinary archival, retrieval, restoration, media, format, segregation or disposition requirements are billable and must be identified in the Quote.
8. Audit and Right of Access
8.1 Customer, its applicable customer and a competent regulatory authority may review records directly relevant to TSRB's performance of the regulated order, subject to the limitations in this Section.
8.2 Except for an urgent regulatory matter or confirmed security incident, an audit requires at least fifteen business days' notice, must occur during normal business hours and must avoid unreasonable disruption.
8.3 Auditors must comply with confidentiality, privacy, safety and security requirements. No audit grants access to source code, penetration-testing tools, unrelated financial information, other customers' data, personnel records, shared production infrastructure or facilities controlled by an unaffiliated cloud provider.
8.4 Independent audit reports, certifications, questionnaires or other reasonable assurance materials may satisfy requirements concerning cloud providers, multi-tenant infrastructure or controls not capable of direct inspection.
8.5 Customer bears its audit costs and TSRB's reasonable assistance costs unless the audit identifies a material uncured breach by TSRB.
9. Subprocessors and Flow-Downs
9.1 TSRB may use the subprocessors permitted by the Terms. TSRB will impose applicable confidentiality and security obligations on subprocessors to the extent appropriate to their services and commercially available.
9.2 TSRB will flow down an accepted requirement only when it is applicable to the subcontracted activity and capable of being imposed. Standard cloud and commercial service providers may satisfy requirements through their published terms, security programs, certifications and independent assurance reports.
9.3 Requirements for U.S.-person access, specified hosting locations or prior subprocessor approval apply only when expressly stated and priced in the Quote.
10. Physical Hardware Requirements
10.1 If TSRB supplies hardware, only the physical-product requirements identified in the Quote apply to that hardware.
10.2 Calibration, shelf-life, counterfeit-parts prevention, foreign-object-debris controls, material substitution, packaging, lot traceability, country of origin and special-process certification are inapplicable to software and professional services.
10.3 TSRB may satisfy applicable hardware requirements through original-manufacturer documentation and authorized-distributor records.
11. Export-Controlled and Restricted Information
11.1 Customer shall identify before contracting whether the work will involve ITAR-controlled technical data, Export Administration Regulations controlled technology, controlled unclassified information, classified information or another restricted data category.
11.2 Customer shall not provide restricted information unless a signed Quote or regulated-data addendum expressly authorizes it and identifies required hosting, access, nationality, location, personnel, backup, logging, incident-response and destruction controls.
11.3 Unless expressly authorized, TSRB's standard service is not offered for classified information or ITAR-controlled technical data. General production, utilization and machine-status data will not be presumed to be export-controlled solely because Customer serves an aerospace or defense market.
11.4 Customer is responsible for export classification and for identifying defense articles, technical data, controlled programs and access restrictions. TSRB may rely on Customer's written classifications and instructions.
11.5 If restricted information is introduced without authorization, Customer shall immediately notify TSRB. TSRB may suspend affected access and take reasonable containment, removal or transfer measures at Customer's expense.
12. Security Frameworks
12.1 Compliance with CMMC, NIST SP 800-171, DFARS, FedRAMP, customer cybersecurity requirements or another framework applies only when the required level, system boundary, responsibilities and evidence are stated in a signed Quote or addendum.
12.2 Customer remains responsible for its own environment, access controls, endpoint security, network segmentation, user administration, physical security and incident response except to the extent assigned to TSRB in writing.
12.3 TSRB will not be deemed a custodian of regulated information outside the expressly defined system boundary.
13. Customer Responsibilities
13.1 Customer shall provide complete and accurate flow-downs, data classifications, program restrictions, facility requirements and security obligations before TSRB prices or begins work.
13.2 Customer shall designate qualified quality, security, export-control and technical contacts and provide timely determinations concerning applicability, access and disposition.
13.3 Customer remains responsible for determining whether TSRB's offered architecture and controls are appropriate for Customer's contractual and regulatory obligations.
14. Security and Regulatory Incidents
14.1 TSRB will notify Customer without unreasonable delay after confirming a security incident affecting regulated Customer information within TSRB's expressly accepted system boundary.
14.2 Notification is not an admission of fault or liability. The parties will cooperate reasonably with investigation, containment and legally required reporting according to their assigned responsibilities.
14.3 Customer bears costs caused by Customer systems, unauthorized regulated data, inaccurate classification or Customer's breach. TSRB bears costs allocated to TSRB under an expressly accepted requirement, subject to the Terms.
15. Commercial Impact of Regulated Requirements
15.1 Specialized hosting, U.S.-person staffing, background checks, security assessments, audit support, validation packages, extended retention, custom reporting, controlled-data migration and customer-specific documentation are outside standard pricing unless included in the Quote.
15.2 A new or changed regulated requirement may result in a change order, schedule extension, technical redesign or suspension until the parties agree on an appropriate solution.
15.3 The liability limitations, warranty limitations, intellectual-property protections and dispute provisions in the Terms remain applicable to regulated work unless a signed agreement expressly states otherwise.
16. Survival
16.1 Obligations concerning confidentiality, restricted data, record retention, audits relating to completed work, intellectual property, payment, liability and disposition survive according to their terms.
TSRB Systems LLC
Aerospace and Defense Addendum
Effective date: September 16, 2026
This Aerospace and Defense Addendum ("Addendum") supplements the TSRB Systems LLC Terms and Conditions for Products and Services ("Terms"). It applies only when an executed TSRB Quote expressly incorporates this Addendum.
This Addendum defines how aerospace, aviation, space, defense, AS9100, export-control and related customer flow-down requirements apply to TSRB software, deployment services, support and any expressly identified hardware.
1. Scope and Order of Precedence
1.1 Capitalized terms not defined here have the meanings in the Terms. If this Addendum conflicts with the Terms, this Addendum controls only for the regulated work expressly identified in the applicable Quote.
1.2 Customer-specific flow-downs apply only when provided to TSRB in full before pricing, listed or attached to the Quote and expressly accepted by TSRB. A general reference to a supplier portal, quality manual, website or future revision does not incorporate that material.
1.3 A revised or newly introduced requirement after acceptance is a scope change and may require revised fees, schedule, architecture, hosting, staffing or technical controls.
2. Nature of TSRB Deliverables
2.1 TSRB primarily supplies commercial software and professional services. Requirements written for raw materials, manufactured aerospace parts or special physical processes apply only to TSRB-supplied hardware when relevant and expressly stated in the Quote.
2.2 Unless expressly stated, TSRB does not perform aerospace design approval, airworthiness certification, source inspection, product release, material testing, nondestructive testing or special manufacturing processes.
2.3 TSRB's products provide information and workflow support. Customer remains responsible for product conformity, production release, inspection, safety, regulatory decisions and compliance of Customer-manufactured items.
3. Quality Management and Certification Status
3.1 TSRB will maintain documented controls reasonably appropriate to its software development, testing, deployment, support and corrective-action activities.
3.2 Nothing in the Terms, this Addendum or TSRB's performance represents that TSRB is certified to AS9100, ISO 9001, CMMC, FedRAMP or another standard unless TSRB expressly confirms that certification in writing.
3.3 TSRB will comply with specific quality requirements only to the extent they apply to the identified deliverable and are expressly accepted in the Quote.
4. Specifications, Configuration and Acceptance
4.1 Software and service conformity is measured against the signed Quote, statement of work, interface specification, written acceptance criteria and applicable TSRB documentation—not against requirements that were not disclosed or accepted.
4.2 TSRB will use reasonable configuration and revision controls for specifications and deliverables within scope. Customer shall promptly identify authoritative document revisions and notify TSRB of discrepancies.
4.3 When a certificate of conformance is expressly required, TSRB may provide a deployment, service or milestone-conformance statement identifying the applicable deliverable and accepted requirements. Physical-material, lot or special-process certification is not required for software unless expressly agreed.
4.4 Acceptance testing and deemed acceptance are governed by the Terms and the applicable Quote.
5. Nonconformity and Corrective Action
5.1 TSRB will evaluate a documented material nonconformity against the accepted requirements and, when appropriate, provide correction, containment or corrective-action information proportionate to its impact.
5.2 TSRB will notify Customer without unreasonable delay after confirming a material post-delivery nonconformity that adversely affects agreed functionality, data integrity, security or regulatory conformity.
5.3 Customer shall provide sufficient evidence, system access and cooperation for investigation. TSRB is not responsible for conditions caused by Customer systems, third parties, unauthorized changes or use outside agreed requirements.
6. Product, Process and Location Changes
6.1 TSRB may update and maintain its commercial software under the Terms.
6.2 TSRB will provide reasonable advance notice, when practicable, of a planned material change to the contracted architecture, hosting location, security controls or functionality that is reasonably expected to adversely affect an expressly accepted regulatory requirement.
6.3 Routine updates, security patches, defect corrections, infrastructure maintenance and changes that do not materially impair accepted requirements do not require Customer approval.
7. Records and Retention
7.1 TSRB will retain project, testing, release, corrective-action and conformity records specifically identified in the Quote for the agreed retention period. If the Quote requires retention but does not state a period, the default period is ten years after completion of the applicable regulated work.
7.2 Customer production data, high-volume telemetry, temporary files, system logs and backups are governed by the service's standard retention practices unless the Quote expressly states otherwise.
7.3 Extraordinary archival, retrieval, restoration, media, format, segregation or disposition requirements are billable and must be identified in the Quote.
8. Audit and Right of Access
8.1 Customer, its applicable customer and a competent regulatory authority may review records directly relevant to TSRB's performance of the regulated order, subject to the limitations in this Section.
8.2 Except for an urgent regulatory matter or confirmed security incident, an audit requires at least fifteen business days' notice, must occur during normal business hours and must avoid unreasonable disruption.
8.3 Auditors must comply with confidentiality, privacy, safety and security requirements. No audit grants access to source code, penetration-testing tools, unrelated financial information, other customers' data, personnel records, shared production infrastructure or facilities controlled by an unaffiliated cloud provider.
8.4 Independent audit reports, certifications, questionnaires or other reasonable assurance materials may satisfy requirements concerning cloud providers, multi-tenant infrastructure or controls not capable of direct inspection.
8.5 Customer bears its audit costs and TSRB's reasonable assistance costs unless the audit identifies a material uncured breach by TSRB.
9. Subprocessors and Flow-Downs
9.1 TSRB may use the subprocessors permitted by the Terms. TSRB will impose applicable confidentiality and security obligations on subprocessors to the extent appropriate to their services and commercially available.
9.2 TSRB will flow down an accepted requirement only when it is applicable to the subcontracted activity and capable of being imposed. Standard cloud and commercial service providers may satisfy requirements through their published terms, security programs, certifications and independent assurance reports.
9.3 Requirements for U.S.-person access, specified hosting locations or prior subprocessor approval apply only when expressly stated and priced in the Quote.
10. Physical Hardware Requirements
10.1 If TSRB supplies hardware, only the physical-product requirements identified in the Quote apply to that hardware.
10.2 Calibration, shelf-life, counterfeit-parts prevention, foreign-object-debris controls, material substitution, packaging, lot traceability, country of origin and special-process certification are inapplicable to software and professional services.
10.3 TSRB may satisfy applicable hardware requirements through original-manufacturer documentation and authorized-distributor records.
11. Export-Controlled and Restricted Information
11.1 Customer shall identify before contracting whether the work will involve ITAR-controlled technical data, Export Administration Regulations controlled technology, controlled unclassified information, classified information or another restricted data category.
11.2 Customer shall not provide restricted information unless a signed Quote or regulated-data addendum expressly authorizes it and identifies required hosting, access, nationality, location, personnel, backup, logging, incident-response and destruction controls.
11.3 Unless expressly authorized, TSRB's standard service is not offered for classified information or ITAR-controlled technical data. General production, utilization and machine-status data will not be presumed to be export-controlled solely because Customer serves an aerospace or defense market.
11.4 Customer is responsible for export classification and for identifying defense articles, technical data, controlled programs and access restrictions. TSRB may rely on Customer's written classifications and instructions.
11.5 If restricted information is introduced without authorization, Customer shall immediately notify TSRB. TSRB may suspend affected access and take reasonable containment, removal or transfer measures at Customer's expense.
12. Security Frameworks
12.1 Compliance with CMMC, NIST SP 800-171, DFARS, FedRAMP, customer cybersecurity requirements or another framework applies only when the required level, system boundary, responsibilities and evidence are stated in a signed Quote or addendum.
12.2 Customer remains responsible for its own environment, access controls, endpoint security, network segmentation, user administration, physical security and incident response except to the extent assigned to TSRB in writing.
12.3 TSRB will not be deemed a custodian of regulated information outside the expressly defined system boundary.
13. Customer Responsibilities
13.1 Customer shall provide complete and accurate flow-downs, data classifications, program restrictions, facility requirements and security obligations before TSRB prices or begins work.
13.2 Customer shall designate qualified quality, security, export-control and technical contacts and provide timely determinations concerning applicability, access and disposition.
13.3 Customer remains responsible for determining whether TSRB's offered architecture and controls are appropriate for Customer's contractual and regulatory obligations.
14. Security and Regulatory Incidents
14.1 TSRB will notify Customer without unreasonable delay after confirming a security incident affecting regulated Customer information within TSRB's expressly accepted system boundary.
14.2 Notification is not an admission of fault or liability. The parties will cooperate reasonably with investigation, containment and legally required reporting according to their assigned responsibilities.
14.3 Customer bears costs caused by Customer systems, unauthorized regulated data, inaccurate classification or Customer's breach. TSRB bears costs allocated to TSRB under an expressly accepted requirement, subject to the Terms.
15. Commercial Impact of Regulated Requirements
15.1 Specialized hosting, U.S.-person staffing, background checks, security assessments, audit support, validation packages, extended retention, custom reporting, controlled-data migration and customer-specific documentation are outside standard pricing unless included in the Quote.
15.2 A new or changed regulated requirement may result in a change order, schedule extension, technical redesign or suspension until the parties agree on an appropriate solution.
15.3 The liability limitations, warranty limitations, intellectual-property protections and dispute provisions in the Terms remain applicable to regulated work unless a signed agreement expressly states otherwise.
16. Survival
16.1 Obligations concerning confidentiality, restricted data, record retention, audits relating to completed work, intellectual property, payment, liability and disposition survive according to their terms.