FlareID — Product Schedule

Version 1.0 · 16 September 2026 · Schedule to the Knurlsoft Module End User Licence Agreement

This Schedule forms part of the Knurlsoft Module End User Licence Agreement (the "Agreement") for FlareID, and states the terms specific to this product. The version of this Schedule in effect on the date of your Order applies to that Order. Capitalised terms have the meanings given in the Agreement.

1. The Software

FlareID is an Ignition gateway module that authenticates SQL Server and Azure SQL datasource connections using Microsoft Entra ID credentials — a certificate, a client secret, or a managed identity — in place of stored SQL passwords. It is delivered as a signed Ignition module (.modl) for the Ignition 8.1 and 8.3 lines under a single product identity; a licence covers the Software on a Gateway on either line, and moving a Gateway between lines does not require a new Licence Key.

The Software installs and, with your consent, manages supporting components on the Gateway, described in Section 3.

2. Product-specific warranties

In addition to the ninety-day conformity warranty in Section 10.1 of the Agreement, Knurlsoft warrants, for so long as you hold a valid Licence Key for the Software, that the Software as delivered by Knurlsoft:

  1. does not write authentication tokens to persistent storage. Tokens obtained from the identity provider are held in memory only, and are not written to disk, to gateway configuration, to log files, or to datasource connection strings;
  2. does not serialise secret material into its diagnostic output. Certificates, client secrets, and tokens are redacted from the Software's diagnostic documents, status surfaces, and log output; and
  3. transmits no data to Knurlsoft. The Software contains no telemetry, usage analytics, or automatic error reporting, and does not contact Knurlsoft or any Knurlsoft-controlled service at any time, including after a Licence Key is activated. The only network connections the Software initiates are to the identity-provider and database endpoints you configure.

These are the warranties referred to in Section 10.1 of the Agreement as stated in the Product Schedule, and the exclusive remedy in Section 10.2 applies to them. They are given because each is verified by an automated test that runs on every build of the Software.

3. Changes the Software makes to your Gateway, with your consent

Certain features modify your Gateway's configuration. Each is performed only after you confirm it in the Software's own interface, and each is described in the Documentation and in the confirmation prompt. They are:

One of these has effects beyond the Software, and you should understand it before consenting. Upgrading the Microsoft JDBC driver changes that driver's default connection encryption setting to encrypt=true for every datasource on the Gateway that uses that driver, including datasources unrelated to the Software. Datasources that rely on the previous default may require configuration changes to continue connecting.

By confirming a change described in this Section you accept responsibility for its documented effects on your Gateway. You agree to review the Documentation for each change, to maintain current Gateway backups, and to validate each change in a non-production environment before applying it in production. Uninstallation reverts or removes these changes as described in the Documentation; you are responsible for verifying your Gateway's configuration afterwards.

4. Dependencies outside our control

The Software depends on services and software supplied by others — the Ignition platform, the Microsoft JDBC driver, Microsoft Entra ID, and your database servers and network. Their availability, configuration, and interface behaviour are outside Knurlsoft's control, and Section 10.3 of the Agreement applies to non-conformities they cause.

In particular, your ability to authenticate depends on your Entra ID tenant being reachable and correctly configured. Section 11.3 of the Agreement requires you to maintain a means of authentication independent of the Software and of that service; for this product that means retaining a documented way to restore database connectivity if Entra ID is unavailable.

5. Platform editions and licensing constraints

These constraints come from the Ignition platform's licensing system, not from Knurlsoft, and we state them here so they are known before purchase:

6. Export classification

FlareID is classified ECCN 5D992.c — mass-market encryption software under Note 3 to Category 5, Part 2 of the Commerce Control List — self-classified by Knurlsoft, and is exportable No Licence Required (NLR) except to embargoed and sanctioned destinations and except where a licence is otherwise required (see Section 15.9 of the Agreement). This classification reflects cryptographic capability present in the delivered artifact, including third-party components that FlareID itself does not invoke; it is not a statement that the Software performs data-confidentiality encryption. Resellers and distributors may rely on this classification for the Software as delivered by Knurlsoft.

7. Third-party components

The components redistributed with the Software, with their copyright notices and licence texts, are listed in the third-party notices delivered with the Software and published at https://knurl.io/legal/notices/. Section 9 of the Agreement governs them.

Knurlsoft LLC · legal@knurl.io · Published at https://knurl.io/legal/schedules/flareid.html