aisecurity.llc
hello@aisecurity.llc
Commercial Agreement · Negotiation Draft
Scanner Provider Pilot SOW
Pilot scope, invocation model, output formats, deliverables checklist, partner and aisecurity.llc responsibilities, data handling, acceptance criteria, and next-phase commercial options.
1. Purpose
This Statement of Work ("SOW") governs a time-boxed OEM pilot engagement between {{PROVIDER_ENTITY}} ("Provider") and Partner ("Partner") for the SecEng Code Scanner OEM Evaluation Package. The pilot is designed to confirm technical evaluation fit, output quality, and commercial terms for a later OEM or white-label scanner-provider relationship.
This SOW supplements and is incorporated into the OEM Evaluation Agreement or Master Agreement executed between Provider and Partner.
2. Pilot Scope
Invocation model for the current pilot:
- Relocatable evaluation bundle with packaged
savvybinary, SecEng content pack, schemas, fixtures, SARIF validation, SBOM, checksum, and clean-room validation. - Partner-native API/ingestion adapter is excluded until Partner provides its interface/schema sample.
Modules in scope:
- AI Code Risk: AI-generated insecure code patterns, source/sink detection, unsafe eval/exec, unsafe tool invocation, secrets handling, auth/authz risk patterns
- Prompt/RAG/Agent Risk: prompt injection surfaces, system prompt exposure, RAG source boundary issues, tool/action permission risks, agent authority blast radius (select if applicable)
- Evidence Adapter: JSON findings, SARIF, Markdown, evidence bundle, CWE/OWASP LLM mapping, remediation guidance
Output formats in scope:
- JSON findings schema
- SARIF 2.1.0
- Markdown report
- validation queue
- generic scanner-provider adapter JSON
Target class (select one or more per SOW schedule):
- AI-generated code repository
- RAG application
- Agentic workflow or MCP server
- LLM gateway or proxy
- Other (specify in SOW schedule)
3. Timeline
| Milestone | Target Day |
|---|---|
| SOW signed and pilot environment provisioned | Day 0 |
| Invocation model confirmed and working | Day 3–5 |
| Sample corpus scan completed | Day 7–10 |
| Output review with Partner technical team | Day 14 |
| Partner-branded report section draft | Day 20 |
| False-positive review and rubric | Day 24 |
| Pilot summary, findings review, and annual license proposal | Day 28–30 |
Timeline assumes Partner provides sample corpus, technical owner, and environment access by Day 0.
4. Deliverables
Provider will deliver the following to Partner during the pilot period:
- Relocatable evaluation package
- CLI/API invocation guide
- Input schema and configuration reference
- JSON findings output
- SARIF 2.1.0 output
- Markdown report
- Validation queue output
- Generic scanner-provider adapter output
- Scanner-specific pilot brief or partner-branded report-section draft
- 10–25 curated AI security finding patterns for the pilot corpus
- CWE/OWASP LLM Top 10 mapping for findings in scope
- Remediation guidance examples
- Retest criteria examples
- False-positive review rubric
- Support and escalation plan for pilot period
- SBOM, checksum, signing-state, and distribution model summary
- Annual OEM license proposal
- White-Label Scanner Productization SOW (if Partner requests next phase)
5. Partner Responsibilities
- Provide sample corpus or test target by Day 0 (internal code, synthetic fixtures, or authorized sample)
- Designate technical owner and commercial owner before SOW is signed
- Provide environment access required for selected invocation model
- Define pilot success criteria jointly with Provider before Day 5
- Attend output review meeting on Day 14
- Provide written feedback on findings quality and report mapping by Day 21
- Do not submit customer production data unless an approved DPA and evidence handling plan is in place
6. Provider Responsibilities
- Provision pilot package and invocation guide by Day 3
- Respond to technical integration questions within 1 business day
- Deliver all listed deliverables within the timeline
- Not use Partner's sample corpus for any purpose other than pilot delivery
- Maintain confidentiality of all Partner-provided materials per the executed NDA or Master Agreement
7. Technical Assumptions
- Partner has reviewed and agreed to the Acceptable Use and Scan Scope Terms before pilot begins
- Sample corpus is either Partner-internal code, synthetic fixtures, or test data Partner has the right to scan
- Customer production data is out of scope unless a DPA is executed and evidence handling plan is approved
- Active testing of live systems is out of scope unless separately authorized via a Rules of Engagement schedule
- Invocation model is confirmed before pilot binary or sidecar is provisioned
8. Data Handling
Data handling during the pilot depends on the selected invocation model:
Partner-controlled (headless binary, localhost sidecar, private worker): Scan inputs and outputs remain in Partner-controlled environment. Provider does not receive scan artifacts.
Hosted API (if selected): Scan inputs are processed by Provider infrastructure. Partner must execute the Data Processing Addendum and obtain customer authorization before submitting any customer data. Pilot default is synthetic or Partner-internal data only.
Provider will not use, retain, or share any Partner-provided scan artifacts beyond the pilot scope and term.
9. Support and Communication
- Pilot support channel: designated Slack channel or email alias (specified in SOW schedule)
- Technical escalation: Provider designated technical contact (specified in SOW schedule)
- Weekly check-in: Provider and Partner technical leads (Day 7, Day 14, Day 21)
- Issues response SLA during pilot: 1 business day for integration blockers, 2 business days for output quality questions
10. Acceptance Criteria / Pilot Success Criteria
The pilot is considered successful when:
- Relocatable evaluation package extracts and validates in a clean-room test
- Sample corpus can be scanned without critical errors
- Agreed output formats are produced (JSON, SARIF 2.1.0, Markdown, validation queue, generic scanner-provider adapter JSON)
- Partner technical team can review and interpret findings
- Partner-branded report section is reviewed and feedback provided
- Support and update model is understood by both parties
- Annual OEM license proposal is reviewed by Partner commercial owner
Unresolved blockers are documented in the pilot summary and addressed in the next-phase SOW.
11. Out of Scope
The following are explicitly out of scope for this SOW:
- Active testing of Partner's production systems or customer environments
- CVE submission, public disclosure, or vulnerability notification to third parties
- Unlimited production resale rights (governed by OEM Scanner License Addendum)
- Customer data processing beyond synthetic or Partner-internal fixtures
- Full white-label productization (governed by White-Label Scanner Productization SOW)
- Partner-native production adapter without a partner-provided schema/interface sample
- Integration with Partner's production reporting or remediation workflow (covered in the native-adapter phase)
12. Fees and Payment
Fees for the 30-Day OEM Pilot are as specified in the Order Form or SOW schedule (typical range: $50k–$100k fixed fee).
Payment terms: 50% invoiced on SOW signature; 50% invoiced on delivery of pilot summary and annual license proposal (Day 28–30).
Travel and expenses: not included unless specified in SOW schedule.
Fees do not include production OEM license fees, which are separately quoted in the Annual OEM License Order Form.
13. Next Phase Options
At the conclusion of the pilot, Partner may elect:
- Annual OEM License: Ongoing embedded or white-label usage under the Annual OEM License Order Form
- White-Label Scanner Productization: Full productization engagement (8–12 weeks, $180k–$350k+)
- No further engagement: Pilot concludes; Partner destroys pilot materials per the OEM Evaluation Agreement
Provider will provide a written next-phase proposal by Day 28.
This document is a template summary. Final terms are subject to negotiation and execution. This document does not constitute legal advice.