aisecurity.llc
hello@aisecurity.llc
Commercial Agreement · Negotiation Draft
OEM Embedded Software License
Redistribution rights, customer-org limits, usage restrictions, license keys, support responsibilities, audit rights, and termination for embedded software.
1. Purpose
This agreement governs a partner’s right to embed, invoke, distribute, or make available aisecurity.llc software as part of a partner product, scanner, platform, managed service, marketplace integration, or security workflow.
2. Licensed Software
Licensed software may include:
- SecEng AI security engine
- headless CLI binary
- localhost HTTP sidecar
- output schemas
- rule packs
- evidence bundle templates
- SARIF exporters
- integration documentation
- license validation components
- partner-specific configuration
3. License Grant
Subject to payment and compliance, aisecurity.llc grants the partner a limited, non-exclusive, non-transferable, non-sublicensable license to embed or invoke the licensed software only as authorized in the applicable order form.
Any redistribution, white-labeling, private-labeling, customer-facing use, or managed-service use must be expressly stated in the order form.
4. Partner Product
The partner product is the software, platform, scanner, service, or workflow identified in the order form.
The partner may not embed the licensed software into unapproved products, subsidiaries, brands, marketplaces, services, or third-party offerings without written approval.
5. Customer Organizations
Customer organizations are the partner’s end customers that receive access to SecEng-powered functionality through the partner product.
The partner must track active customer organizations if the order form includes per-customer-org pricing, usage allocation, reporting, or entitlement obligations.
6. Usage and Metering
The partner must use commercially reasonable controls to ensure usage is measured according to the order form.
Usage may be measured by:
- active customer organization
- enabled module
- scan count
- usage credits
- report exports
- evidence bundle exports
- worker devices
- private deployments
- offline license grants
- API calls
- other agreed units
7. License Controls
aisecurity.llc may require license controls including:
- signed binaries
- signed license files
- partner ID
- customer organization ID
- enabled modules
- expiry dates
- maximum scans
- maximum concurrency
- watermark identifiers
- revocation list checks
- feature flags
- offline grant limitations
The partner must not remove, bypass, disable, obscure, or interfere with license controls.
8. Output Controls
SecEng-generated outputs may include:
- JSON findings
- SARIF files
- markdown reports
- executive summaries
- evidence bundles
- artifact manifests
- compliance mappings
- risk scores
- remediation guidance
The partner may display or transform outputs inside the partner product as permitted by the order form.
The partner must not misrepresent output as independently generated if the commercial terms require attribution or powered-by language.
9. Branding
Branding mode must be specified in the order form.
Allowed branding modes may include:
- co-branded
- powered by aisecurity.llc
- private label
- full white label
Full white-label rights require explicit written authorization and may require higher fees, support obligations, attribution restrictions, custom packaging, and audit rights.
10. Restrictions
The partner may not:
- reverse engineer the licensed software except where applicable law prohibits this restriction
- remove license controls
- bypass usage controls
- redistribute outside the approved partner product
- expose raw internal rule packs or protected assets
- sell access as a generic standalone product unless authorized
- use the licensed software to violate law or scan unauthorized targets
- permit third parties to access the licensed software except approved customer organizations
- remove watermarks or output integrity metadata unless authorized
11. Security Obligations
The partner must maintain reasonable technical and organizational controls for:
- license keys
- customer organization mapping
- output handling
- logs
- local API exposure
- scan authorization
- user access
- incident response
- vulnerability remediation
- secure distribution
12. Data
The partner is responsible for its own customer relationships, notices, permissions, scan authorization, and data-processing obligations unless otherwise stated.
If aisecurity.llc receives or processes personal data, customer data, artifacts, or telemetry, the parties should execute an applicable data-processing addendum.
13. Support
Support obligations must be stated in an order form or support addendum.
Default support boundaries:
- partner provides first-line customer support
- aisecurity.llc provides second-line partner support
- aisecurity.llc does not directly support partner customers unless agreed
- partner must provide reproducible issue details
- air-gapped support requires special terms
14. Updates
aisecurity.llc may provide updates, patches, rule updates, schema updates, and security fixes.
The partner is responsible for distributing updates to its customers unless the order form provides otherwise.
The partner must not continue distributing known vulnerable versions after receiving a reasonable update notice unless customer environment constraints prevent immediate update.
15. Fees
Fees may include:
- base OEM license
- active customer organization fees
- usage credits
- module fees
- support fees
- white-label fees
- private deployment fees
- setup fees
- professional services
- overage fees
16. Reporting
The partner must provide reporting required by the order form.
Reporting may include:
- active customer organizations
- enabled modules
- usage counts
- scan volumes
- offline deployments
- support incidents
- revenue share calculations
- license status
- customer churn or deactivation
17. Audit Rights
aisecurity.llc may audit partner compliance no more than once per year unless there is reasonable suspicion of material breach.
Audit scope should be limited to license compliance, usage reporting, redistribution, customer organization counts, and payment obligations.
18. Confidentiality
Non-public software, pricing, license controls, security architecture, output schemas, roadmaps, and partner terms are confidential.
19. Intellectual Property
aisecurity.llc owns the licensed software and related intellectual property.
The partner owns its product and customer relationships.
Unless otherwise agreed, improvements to the licensed software remain owned by aisecurity.llc.
20. Termination
aisecurity.llc may suspend or terminate license rights for non-payment, misuse, unauthorized distribution, license bypass, security breach, or material contract breach.
Upon termination, the partner must stop distributing the licensed software and disable access for new customer organizations.
Wind-down rights, if any, must be stated in the order form.
21. Suggested Order Form Fields
An OEM order form should specify:
- partner legal name
- approved partner product
- branding mode
- enabled modules
- permitted customer organizations
- fees
- usage limits
- output rights
- deployment targets
- support tier
- reporting obligations
- license term
- renewal term
- termination handling
- white-label rights
- professional services
- special conditions