aisecurity.llc
hello@aisecurity.llc
Commercial Agreement · Negotiation Draft
Pen Test Readiness — Assessment Terms Addendum
Authorized scope, testing boundary framework, safe harbor, claim limits, and reliance statement for pen test and red team readiness work.
1. Purpose and Scope
This Addendum supplements the parties' Master Services Agreement or Statement of Work (the "Base Agreement") and governs the provision of Pen Test & Red Team Readiness Packet services ("Readiness Services") described in the applicable Order Form. To the extent of a conflict between this Addendum and the Base Agreement, this Addendum controls for matters expressly addressed here.
2. Authorized Scope
2.1 Readiness Only. Readiness Services consist solely of document review, intake analysis, gap identification, and preparation artifacts. No live testing, active scanning, exploitation, or network-level interaction with Client systems is performed under this Addendum.
2.2 No Active Engagement. This Addendum does not authorize or constitute a penetration test, red team engagement, or any authorized security assessment against Client systems. Separate Rules of Engagement and a signed Scope Authorization are required before any active testing begins.
2.3 Packet Deliverables. Deliverables under this Addendum may include a Readiness Packet, Gap Analysis Report, ROE Draft, Scoping Brief, Vendor Qualification Summary, and related artifacts as enumerated in the Order Form.
3. Evidence and Data Handling
3.1 Intake Materials. Materials provided by Client to support the Readiness assessment ("Intake Materials") will be used solely for the purpose of producing Readiness Deliverables. Intake Materials will not be retained beyond the engagement close date unless otherwise agreed in writing.
3.2 Sensitive Information. Client should not include credentials, live secrets, production access tokens, or personally identifiable information in Intake Materials unless required for scoping purposes, in which case such data must be clearly labeled and will be handled under the Data Retention and Redaction Policy.
3.3 Redaction. AI Security LLC will redact or mask sensitive values in any Deliverable before delivery. Client is responsible for reviewing Deliverables for any inadvertently included sensitive data prior to further distribution.
4. Accuracy and Reliance
4.1 Dependent on Provided Information. All Readiness Deliverables are based on information provided by Client and publicly available sources. AI Security LLC does not independently verify the accuracy or completeness of Intake Materials.
4.2 No Guarantee of Enumeration. The Readiness Packet identifies risks, gaps, and preparation steps based on available signals. It is not an exhaustive enumeration of all security issues, compliance gaps, or exploitable vulnerabilities in Client systems.
4.3 Point-in-Time Assessment. Readiness Deliverables reflect the state of Client systems and processes as described during the engagement window. They do not account for changes made after Deliverable delivery.
5. Permitted Use
5.1 Internal Use. Readiness Deliverables are licensed to Client for internal planning, vendor selection, and engagement preparation purposes only. External distribution requires AI Security LLC's prior written consent.
5.2 No Certification. No Readiness Deliverable constitutes a security certification, compliance attestation, or endorsement of Client's security posture. Readiness Deliverables must not be characterized as such in Client communications, marketing materials, or regulatory submissions.
5.3 No Authorization to Test. Nothing in this Addendum or any Readiness Deliverable constitutes authorization to conduct security testing against any third-party system. Scoping artifacts identify targets for Client's own commissioned engagements, not for independent testing.
6. Claim Boundaries
6.1 No Regulatory Guarantee. Readiness Deliverables do not guarantee regulatory compliance, passing scores, or audit outcomes. Gaps identified are advisory; remediation outcome depends on Client implementation.
6.2 Engagement Success Not Guaranteed. A completed Readiness assessment does not guarantee a successful penetration test or red team exercise. Actual engagement outcomes depend on scope, tester skill, system changes, and other factors outside AI Security LLC's control.
6.3 No Legal Advice. Nothing in Readiness Deliverables constitutes legal advice. Client should engage qualified legal counsel for regulatory interpretation.
7. Acceptance and Delivery
7.1 Acceptance. Readiness Deliverables are deemed accepted unless Client provides written objection with specificity within ten (10) business days of delivery.
7.2 Revision Scope. One revision round is included per Deliverable. Revisions are limited to corrections, clarifications, and updates to information provided; they do not extend scope.
8. Term and Termination
This Addendum remains in effect for the duration of the Order Form to which it is attached. Obligations under Sections 3, 4, 5, and 6 survive termination.
9. Order of Precedence
In the event of conflict: Order Form > this Addendum > the Base Agreement > any referenced policy exhibits.
This document is a public specimen. Final contract terms are subject to negotiation and execution between the parties.
Entity: AI Security LLC · California · hello@aisecurity.llc