aisecurity.llc
hello@aisecurity.llc
Commercial Agreement · Negotiation Draft
MSSP Addendum
Customer-org management, managed-delivery rights, support boundaries, reporting responsibilities, and usage rollups for MSSP programs.
1. Purpose
This addendum allows a managed security service provider to use aisecurity.llc capabilities to provide managed AI security services to multiple customer organizations.
2. Managed Services Scope
Permitted managed services may include:
- AI product security assessments
- RAG security reviews
- agentic workflow reviews
- recurring AI risk checks
- evidence generation
- report delivery
- remediation guidance
- Academy enablement
- customer-org usage reporting
- managed scan operations
3. Customer Organizations
The MSSP must track customer organizations if pricing, usage, reporting, or entitlements depend on active customer count.
Customer organization records should include:
- customer name or identifier
- active status
- enabled modules
- usage allocation
- support tier
- deployment model
- data boundary
- start and end dates
4. Customer Authorization
The MSSP is responsible for obtaining authorization from each customer organization before scanning, testing, collecting evidence, or processing customer data.
The MSSP must ensure scan activity stays within approved scope.
5. Branding
Branding mode may be:
- aisecurity.llc branded
- co-branded
- MSSP private-label
- MSSP white-label if separately licensed
6. Usage Reporting
The MSSP must provide or allow collection of usage reporting required by the order form.
Usage may include:
- scans
- reports
- evidence bundles
- customer organizations
- worker devices
- modules enabled
- usage credits consumed
- support incidents
7. Support
Unless otherwise agreed:
- MSSP provides first-line customer support
- aisecurity.llc provides partner-facing support
- aisecurity.llc does not directly support MSSP customers
- escalations require reproducible details
- support obligations follow the support addendum
8. Data Processing
The MSSP is responsible for customer notices, data-processing terms, and privacy obligations unless aisecurity.llc directly processes customer data.
When aisecurity.llc processes customer data, a data-processing addendum should be executed.
9. Restrictions
The MSSP may not:
- allow customer self-service outside licensed scope
- provide raw binaries to customers unless authorized
- bypass usage controls
- remove license controls
- exceed customer-org limits
- scan unauthorized targets
- resell outside the managed service scope
- claim certification or attestation unless separately authorized
10. Fees
Fees may include:
- MSSP base license
- active customer organization fees
- usage credits
- support tier fees
- private-label add-on
- implementation services
- Academy content license
- overage fees
11. Termination
Upon termination, the MSSP must stop using aisecurity.llc capabilities for new managed customer work.
Wind-down for existing customer engagements must be stated in the order form.
12. Suggested MSSP Schedule Fields
The MSSP schedule should include:
- MSSP legal name
- approved services
- customer organization limit
- usage model
- branding mode
- support obligations
- data-processing model
- deployment model
- reporting cadence
- fees
- renewal terms
- termination handling