Commercial legal resources for OEM, reseller, white-label, support, data, and scan-scope agreements.
Commercial programs need contract templates that define license rights, partner obligations, customer usage, support, security, data handling, and acceptable scan scope.
Commercial documents
Use these agreement families to convert pilots, partner conversations, procurement reviews, and enterprise deployments into operating terms.
Licensing
Enterprise, embedded, OEM, white-label, offline, air-gapped, academic, startup, and usage-credit licensing.
Security
Security controls for partner licensing, local workers, OEM binaries, tokens, signed outputs, and audit events.
Commercial Contact
Start an OEM, reseller, MSSP, enterprise, private-label, procurement, or deployment conversation.
Contracts that match the commercial model
The legal center organizes the agreement types needed for OEM, reseller, MSSP, private-label, support, DPA, security, acceptable use, and order forms.
OEM Evaluation Agreement
Time-boxed technical evaluation: pilot restrictions, confidential materials, test data, feedback rights, and the conversion path to a commercial license.
OEM Embedded Software License
Redistribution rights, customer-org limits, usage restrictions, license keys, support responsibilities, audit rights, and termination for embedded software.
Reseller Agreement
Resale rights, pricing and discounting, lead ownership, customer-support boundaries, payment terms, and territory rules.
Private-Label Addendum
Partner-branded service delivery while preserving the underlying license, evidence, support, and acceptable-use restrictions.
White-Label Addendum
Deeper branding rights, attribution controls, output customization, binary metadata, and minimum commercial commitments.
MSSP Addendum
Customer-org management, managed-delivery rights, support boundaries, reporting responsibilities, and usage rollups for MSSP programs.
Revenue Share Schedule
Base fees, customer-org fees, usage credits, revenue share, payment timing, and reporting obligations.
OEM Scanner License Addendum
White-label and OEM rights for SecEng Scan: deployment models, sublicensing boundaries, branding rights, usage reporting, IP ownership, customer-facing claims policy, vulnerability disclosure, and wind-down terms.
Scanner Provider Pilot SOW
Pilot scope, invocation model, output formats, deliverables checklist, partner and aisecurity.llc responsibilities, data handling, acceptance criteria, and next-phase commercial options.
Annual OEM License Order Form
Annual commercial package for OEM or white-label SecEng Scan usage: license term, fees, usage tier, support tier, update entitlement, permitted customer orgs, sublicensing rights, usage reporting, and renewal terms.
Workforce Readiness Content License Agreement
Content license for role taxonomy, Q&A bank, job-market data, readiness diagnostic model, hiring calibration methodology, and workforce reporting templates: permitted use, branding rights, sublicensing boundaries, IP ownership, content update obligations, customer-facing claims policy, and wind-down terms.
Workforce Readiness Partner Pilot SOW
Pilot scope, integration surface selection, content deliverables, partner and aisecurity.llc responsibilities, data handling, acceptance criteria, and next-phase commercial options.
Workforce Platform Integration Order Form
Platform integration commercial package: integration scope, SKUs, license term, branding tier, content update schedule, support tier, usage reporting, annual renewal, and exclusivity terms.
Launch Security Review — Assessment Terms Addendum
Authorized testing scope, safe harbor, reliance limits, and claim caveats for a Launch Security Review engagement.
Launch Security Review — Evidence Handling Policy
How launch review findings, abuse-path notes, and testing artifacts are captured, retained, redacted, and destroyed.
Launch Security Review — Statement of Work
Scope, targets, testing window, deliverables checklist, retesting conditions, data handling, acceptance criteria, and fees.
Pen Test Readiness — Assessment Terms Addendum
Authorized scope, testing boundary framework, safe harbor, claim limits, and reliance statement for pen test and red team readiness work.
Academy Enterprise Training Terms
Seats and access, course materials, LMS packages, private cohorts, completion records, data handling, acceptable use, support, updates, claim boundaries, and order of precedence.
Academy LMS Package Addendum
LMS delivery rights, seat limits, SCORM package scope and status, modification restrictions, branding, reporting, update obligations, and expiration.
Academy Content License Addendum
Licensed Academy content definition, permitted use, white-label rights, sublicensing limits, prohibited uses, claim boundaries, IP ownership, update rights, and wind-down terms.
Academy Credential and Completion Policy
What Academy course completion, Q&A check results, lab badges, and credentials mean and explicitly do not mean: not a product-security certification, not an employment decision, not a compliance attestation.
Support and SLA Addendum
Support tiers, response windows, severity levels, escalation, maintenance, availability, and partner obligations.
Order Form Template
Captures the commercial program, SKUs, license scope, deployment model, support tier, pricing, term, and special conditions for an order.
Data Processing Addendum
Processing roles, retention, subprocessors, local execution, evidence handling, deletion, and privacy obligations for commercial deployments.
Security Exhibit
Summary of commercial security controls, token handling, license signing, output integrity, scan scope, and the incident process.
Acceptable Use and Scan Scope Terms
Allowed targets, authorization requirements, prohibited activity, customer responsibility, and safe testing boundaries.
Default OEM architecture
A partner product keeps its own UI, scheduling, reporting, customer accounts, and workflow while the SecEng engine supplies AI-specific security results.
Partner orchestrator
The partner scanner, Java application, AppSec platform, CI job, or managed-service workflow owns scheduling, customer context, and UI.
SecEng sidecar
A headless binary or localhost API receives bounded scan requests, validates local license state, and runs AI security modules.
Structured outputs
The engine renders partner-safe JSON bundles, SARIF, markdown reports, validation logs, remediation backlogs, and OEM white-label outputs from the same validated evidence graph — without exposing internal prompts, scoring internals, or engine implementation.
Partner reporting
The partner presents results inside its own product, report, portal, or service workflow without exposing the AI Security LLC UI.
Usage reconciliation
Customer-org usage, credits, license status, and revocation sync to the commercial control plane when the deployment model allows it.
Choose the right commercial model
AI Security LLC separates its commercial motion—how organizations buy, embed, operate, and scale the platform—from the technical capabilities themselves.
Licensing models
Use the licensing shape that matches how the customer or partner wants to buy and operate.
Enterprise Site License
Organizations that want AI security tooling, evidence generation, private workers, Academy access, and negotiated usage capacity.
- Organization-level entitlements
- Private worker support
- Negotiated credits
- Procurement and security review
OEM Embedded License
Scanner vendors and security platforms that want to embed the SecEng engine inside their existing product.
- Partner license
- Customer-org tracking
- Usage rollups
- Redistribution rights
MSSP License
Managed security providers selling AI security assessments and monitoring as a managed service.
- Customer-org reporting
- Managed delivery rights
- Usage credits
- Support boundaries
White-Label License
Strategic partners that need customer-facing brand control, custom report language, and embedded packaging.
- Branding rights
- Output customization
- Higher support obligations
- Audit rights
Deployment options
Commercial packaging should follow the customer data boundary, partner architecture, and procurement expectations.
SaaS control plane
The AI Security LLC web platform governs organizations, credits, entitlements, users, reports, and commercial records.
Local worker
Sensitive repositories, traces, prompts, and artifacts stay local while entitlement and usage sync remains platform-controlled.
OEM sidecar
A partner invokes the SecEng engine through CLI or localhost HTTP and ingests native JSON, SARIF, and evidence outputs.
Air-gapped deployment
Signed offline license grants and controlled update processes support highly sensitive environments.
Support tiers
Support can be matched to the commercial obligation, from pilot support to strategic OEM escalation.
Standard
Early partners, pilots, startups, and small commercial programs.
- Email support
- Pilot guidance
- Documentation support
- Best-effort integration review
Premium
OEM partners, MSSPs, and enterprise programs with customer-facing obligations.
- Partner escalation channel
- Release guidance
- Integration reviews
- Commercial success reviews
Enterprise
Strategic OEM, white-label, air-gapped, and enterprise site-license deployments.
- Escalation path
- Security review support
- Roadmap alignment
- Custom support terms
Commercial path
The fastest route is a scoped pilot that proves technical ingestion and commercial packaging before expanding.
Commercial fit call
Identify partner type, target customers, intended packaging, deployment constraints, support model, and success criteria.
Technical pilot
Prove the CLI or localhost API path against a representative target and confirm JSON, SARIF, and evidence ingestion.
Commercial pilot
Define pricing, customer-org model, support boundary, white-label depth, license controls, and pilot reporting.
Production rollout
Convert to partner agreement, issue production licenses, document integration, and begin customer-org activation.
Representative SKUs
Commercial products should be represented as registry-backed SKUs rather than ad hoc pricing copy.
OEM Pilot
A focused 30-day pilot to prove the SecEng headless engine can be invoked by a partner product and produce ingestible AI security findings.
OEM Base License
Base commercial license for a partner to embed or invoke the SecEng engine across approved internal and customer environments.
OEM Customer Org
Per-customer organization pricing for active OEM customers using partner-distributed SecEng AI security capabilities.
Private-Label Add-on
Private-label packaging where the partner owns customer-facing presentation while AI Security LLC remains available for legal, support, and technical attribution.
MSSP Base License
Commercial base license for MSSPs offering AI security assessments, monitoring, evidence reporting, and customer-org services.
Enterprise Site License
Organization-wide licensing for SecEng workbench access, private workers, evidence generation, Academy content, and custom deployment requirements.
Move from interest to a scoped commercial path
Every commercial conversation should resolve into a clear program, deployment model, license scope, support expectation, and evidence requirement.
Define the commercial motion
Decide whether this is OEM, reseller, MSSP, enterprise, private-label, or procurement-led.
Run a bounded pilot
Use one integration path, one target class, one reporting output, and one commercial success metric.
Move to operating terms
Finalize license scope, customer-org model, support tier, usage controls, and deployment model.
Build the right commercial path
Use a focused pilot to align the technical integration, licensing structure, support model, and customer-facing packaging.