PARTNERS

Embed, resell, or white-label AI security — OEM, scanner, MSSP, consulting, and reseller tracks are open now

Commercial / Legal

Commercial legal resources for OEM, reseller, white-label, support, data, and scan-scope agreements.

Commercial programs need contract templates that define license rights, partner obligations, customer usage, support, security, data handling, and acceptable scan scope.

CLI
Headless invocation for partners and automation
SARIF
Scanner-friendly output for partner ingestion
OEM
Commercial path for embedded AI security coverage
Legal center

Contracts that match the commercial model

The legal center organizes the agreement types needed for OEM, reseller, MSSP, private-label, support, DPA, security, acceptable use, and order forms.

Prospective OEM and scanner-provider partners

OEM Evaluation Agreement

Time-boxed technical evaluation: pilot restrictions, confidential materials, test data, feedback rights, and the conversion path to a commercial license.

OEM partners

OEM Embedded Software License

Redistribution rights, customer-org limits, usage restrictions, license keys, support responsibilities, audit rights, and termination for embedded software.

Channel and reseller partners

Reseller Agreement

Resale rights, pricing and discounting, lead ownership, customer-support boundaries, payment terms, and territory rules.

Consultancies and advisory firms

Private-Label Addendum

Partner-branded service delivery while preserving the underlying license, evidence, support, and acceptable-use restrictions.

Strategic OEM and platform partners

White-Label Addendum

Deeper branding rights, attribution controls, output customization, binary metadata, and minimum commercial commitments.

Managed security service providers

MSSP Addendum

Customer-org management, managed-delivery rights, support boundaries, reporting responsibilities, and usage rollups for MSSP programs.

OEM, reseller, MSSP, and marketplace partners

Revenue Share Schedule

Base fees, customer-org fees, usage credits, revenue share, payment timing, and reporting obligations.

Scanner-provider OEM partners

OEM Scanner License Addendum

White-label and OEM rights for SecEng Scan: deployment models, sublicensing boundaries, branding rights, usage reporting, IP ownership, customer-facing claims policy, vulnerability disclosure, and wind-down terms.

Scanner providers entering a 30-day OEM pilot

Scanner Provider Pilot SOW

Pilot scope, invocation model, output formats, deliverables checklist, partner and aisecurity.llc responsibilities, data handling, acceptance criteria, and next-phase commercial options.

Scanner-provider OEM partners entering annual license

Annual OEM License Order Form

Annual commercial package for OEM or white-label SecEng Scan usage: license term, fees, usage tier, support tier, update entitlement, permitted customer orgs, sublicensing rights, usage reporting, and renewal terms.

Training platforms, cyber ranges, and certification providers entering a workforce readiness platform partnership

Workforce Readiness Content License Agreement

Content license for role taxonomy, Q&A bank, job-market data, readiness diagnostic model, hiring calibration methodology, and workforce reporting templates: permitted use, branding rights, sublicensing boundaries, IP ownership, content update obligations, customer-facing claims policy, and wind-down terms.

Platform partners entering a two-week workforce readiness pilot

Workforce Readiness Partner Pilot SOW

Pilot scope, integration surface selection, content deliverables, partner and aisecurity.llc responsibilities, data handling, acceptance criteria, and next-phase commercial options.

Platform partners entering a full integration or annual license

Workforce Platform Integration Order Form

Platform integration commercial package: integration scope, SKUs, license term, branding tier, content update schedule, support tier, usage reporting, annual renewal, and exclusivity terms.

Teams commissioning a pre-launch AI security review

Launch Security Review — Assessment Terms Addendum

Authorized testing scope, safe harbor, reliance limits, and claim caveats for a Launch Security Review engagement.

Teams receiving Launch Risk Memo or Abuse-Path Findings

Launch Security Review — Evidence Handling Policy

How launch review findings, abuse-path notes, and testing artifacts are captured, retained, redacted, and destroyed.

Teams executing a Launch Security Review engagement

Launch Security Review — Statement of Work

Scope, targets, testing window, deliverables checklist, retesting conditions, data handling, acceptance criteria, and fees.

Teams commissioning or scoping an external pen test or red team engagement

Pen Test Readiness — Assessment Terms Addendum

Authorized scope, testing boundary framework, safe harbor, claim limits, and reliance statement for pen test and red team readiness work.

Enterprise teams purchasing Academy Team Pack, LMS Package, or Private Cohort

Academy Enterprise Training Terms

Seats and access, course materials, LMS packages, private cohorts, completion records, data handling, acceptable use, support, updates, claim boundaries, and order of precedence.

Enterprise teams receiving a SCORM or LMS-ready Academy delivery package

Academy LMS Package Addendum

LMS delivery rights, seat limits, SCORM package scope and status, modification restrictions, branding, reporting, update obligations, and expiration.

Training platforms, cyber ranges, and enterprise L&D partners licensing Academy content

Academy Content License Addendum

Licensed Academy content definition, permitted use, white-label rights, sublicensing limits, prohibited uses, claim boundaries, IP ownership, update rights, and wind-down terms.

All Academy learners, enterprise training managers, and platform partners

Academy Credential and Completion Policy

What Academy course completion, Q&A check results, lab badges, and credentials mean and explicitly do not mean: not a product-security certification, not an employment decision, not a compliance attestation.

Enterprise and partner customers

Support and SLA Addendum

Support tiers, response windows, severity levels, escalation, maintenance, availability, and partner obligations.

All commercial customers

Order Form Template

Captures the commercial program, SKUs, license scope, deployment model, support tier, pricing, term, and special conditions for an order.

Enterprise, OEM, and regulated customers

Data Processing Addendum

Processing roles, retention, subprocessors, local execution, evidence handling, deletion, and privacy obligations for commercial deployments.

Procurement, security, and legal teams

Security Exhibit

Summary of commercial security controls, token handling, license signing, output integrity, scan scope, and the incident process.

All commercial users and partners

Acceptable Use and Scan Scope Terms

Allowed targets, authorization requirements, prohibited activity, customer responsibility, and safe testing boundaries.

Architecture

Default OEM architecture

A partner product keeps its own UI, scheduling, reporting, customer accounts, and workflow while the SecEng engine supplies AI-specific security results.

Step 1

Partner orchestrator

The partner scanner, Java application, AppSec platform, CI job, or managed-service workflow owns scheduling, customer context, and UI.

Step 2

SecEng sidecar

A headless binary or localhost API receives bounded scan requests, validates local license state, and runs AI security modules.

Step 3

Structured outputs

The engine renders partner-safe JSON bundles, SARIF, markdown reports, validation logs, remediation backlogs, and OEM white-label outputs from the same validated evidence graph — without exposing internal prompts, scoring internals, or engine implementation.

Step 4

Partner reporting

The partner presents results inside its own product, report, portal, or service workflow without exposing the AI Security LLC UI.

Step 5

Usage reconciliation

Customer-org usage, credits, license status, and revocation sync to the commercial control plane when the deployment model allows it.

Compare

Choose the right commercial model

AI Security LLC separates its commercial motion—how organizations buy, embed, operate, and scale the platform—from the technical capabilities themselves.

Capability
Enterprise
OEM
MSSP
Consulting
Primary buyer
Internal security or platform team
Security product company
Managed security provider
Advisory or pentest firm
Default packaging
Site license plus private workers
Headless binary or local API
Provider account plus customer orgs
Private-label assessment toolkit
Usage model
Seats, credits, and negotiated capacity
Base fee, customer orgs, usage credits
Base fee, customer orgs, managed usage
Partner license and report capacity
Branding
AI Security LLC
Co-branded or white-label
Provider-branded service
Private-label delivery
Best first step
Enterprise scope call
30-day OEM pilot
Managed service pilot
Private-label assessment pilot
Licensing

Licensing models

Use the licensing shape that matches how the customer or partner wants to buy and operate.

Annual agreement

Enterprise Site License

Organizations that want AI security tooling, evidence generation, private workers, Academy access, and negotiated usage capacity.

  • Organization-level entitlements
  • Private worker support
  • Negotiated credits
  • Procurement and security review
Base plus active customer orgs

OEM Embedded License

Scanner vendors and security platforms that want to embed the SecEng engine inside their existing product.

  • Partner license
  • Customer-org tracking
  • Usage rollups
  • Redistribution rights
Provider base plus managed orgs

MSSP License

Managed security providers selling AI security assessments and monitoring as a managed service.

  • Customer-org reporting
  • Managed delivery rights
  • Usage credits
  • Support boundaries
Annual minimum or uplift

White-Label License

Strategic partners that need customer-facing brand control, custom report language, and embedded packaging.

  • Branding rights
  • Output customization
  • Higher support obligations
  • Audit rights
Deployment

Deployment options

Commercial packaging should follow the customer data boundary, partner architecture, and procurement expectations.

Platform

SaaS control plane

The AI Security LLC web platform governs organizations, credits, entitlements, users, reports, and commercial records.

Best for direct enterprise programs
Fastest procurement and billing path
Centralized evidence and reporting
Desktop or CLI

Local worker

Sensitive repositories, traces, prompts, and artifacts stay local while entitlement and usage sync remains platform-controlled.

Good for private code and customer delivery
Supports offline queues
Pairs with Tauri and CLI workflows
Partner product

OEM sidecar

A partner invokes the SecEng engine through CLI or localhost HTTP and ingests native JSON, SARIF, and evidence outputs.

Best for scanner providers
No forced AI Security LLC UI
Supports co-branding or white-label
Disconnected

Air-gapped deployment

Signed offline license grants and controlled update processes support highly sensitive environments.

No live data egress requirement
Hard-capped local usage
Explicit expiry and scope
Support

Support tiers

Support can be matched to the commercial obligation, from pilot support to strategic OEM escalation.

Standard

Early partners, pilots, startups, and small commercial programs.

Business-hours response
  • Email support
  • Pilot guidance
  • Documentation support
  • Best-effort integration review

Premium

OEM partners, MSSPs, and enterprise programs with customer-facing obligations.

Priority response
  • Partner escalation channel
  • Release guidance
  • Integration reviews
  • Commercial success reviews

Enterprise

Strategic OEM, white-label, air-gapped, and enterprise site-license deployments.

Negotiated SLA
  • Escalation path
  • Security review support
  • Roadmap alignment
  • Custom support terms
Path

Commercial path

The fastest route is a scoped pilot that proves technical ingestion and commercial packaging before expanding.

1
Week 0

Commercial fit call

Identify partner type, target customers, intended packaging, deployment constraints, support model, and success criteria.

2
Week 1

Technical pilot

Prove the CLI or localhost API path against a representative target and confirm JSON, SARIF, and evidence ingestion.

3
Week 2-4

Commercial pilot

Define pricing, customer-org model, support boundary, white-label depth, license controls, and pilot reporting.

4
Month 2+

Production rollout

Convert to partner agreement, issue production licenses, document integration, and begin customer-org activation.

Commercial SKUs

Representative SKUs

Commercial products should be represented as registry-backed SKUs rather than ad hoc pricing copy.

OEM-PILOT-30D

OEM Pilot

A focused 30-day pilot to prove the SecEng headless engine can be invoked by a partner product and produce ingestible AI security findings.

OEM-BASE-MONTHLY

OEM Base License

Base commercial license for a partner to embed or invoke the SecEng engine across approved internal and customer environments.

OEM-CUSTOMER-ORG-STANDARD

OEM Customer Org

Per-customer organization pricing for active OEM customers using partner-distributed SecEng AI security capabilities.

OEM-WHITELABEL-PRIVATE

Private-Label Add-on

Private-label packaging where the partner owns customer-facing presentation while AI Security LLC remains available for legal, support, and technical attribution.

MSSP-BASE-MONTHLY

MSSP Base License

Commercial base license for MSSPs offering AI security assessments, monitoring, evidence reporting, and customer-org services.

ENTERPRISE-SITE-LICENSE

Enterprise Site License

Organization-wide licensing for SecEng workbench access, private workers, evidence generation, Academy content, and custom deployment requirements.

What happens next

Move from interest to a scoped commercial path

Every commercial conversation should resolve into a clear program, deployment model, license scope, support expectation, and evidence requirement.

Scope

Define the commercial motion

Decide whether this is OEM, reseller, MSSP, enterprise, private-label, or procurement-led.

Prove

Run a bounded pilot

Use one integration path, one target class, one reporting output, and one commercial success metric.

Convert

Move to operating terms

Finalize license scope, customer-org model, support tier, usage controls, and deployment model.

Build the right commercial path

Use a focused pilot to align the technical integration, licensing structure, support model, and customer-facing packaging.