Answers for partners evaluating AI Security LLC.
Commercial, technical, data, IP, delivery, support, and branding questions for OEM, scanner-provider, MSSP, reseller, consulting, private-label, white-label, workforce, and technology partners.
Related partner routes
If the FAQ raises a route-specific question, jump to the relevant partner program page.
OEM
Embed the SecEng AI security engine in another scanner, platform, managed service, or security product.
MSSP
Launch managed AI security offerings using SecEng modules, reports, evidence, and customer org usage controls.
Resellers
Resell AI Security LLC products, assessments, Academy assets, evidence services, and enterprise programs.
Private Label
Deliver AI security assessments and reports under your advisory or consulting brand.
White Label
License branded SecEng capabilities with deeper report, packaging, and commercial customization.
Partner Interoperability
Canonical contract layer and joint-alliance framework for scanner findings, attack traces, partner evidence, APC results, workforce content, and learner outcomes.
Categorized partner FAQ
This route handles objections and routing questions. It deliberately avoids repeating the generic architecture, licensing, deployment, support, commercial-path, and SKU sections.
What partner models are available?
OEM, scanner provider, offensive platform, MSSP, consulting, reseller, private label, white label, workforce white label, and technology alliance.
What is the difference between OEM, white label, and private label?
OEM embeds licensed capability. Private label brands a professional-service delivery. White label gives deeper product-level or platform-level brand and commercial control.
Are minimum commitments required?
Minimums depend on the rights requested. Strategic white-label and embedded distribution usually require stronger commitments than pilot, reseller, or consulting enablement paths.
How are active customer organizations counted?
Customer-org counting is defined in the agreement and usage model, typically around active customers receiving licensed outputs, service delivery, or embedded capability.
Can we register opportunities?
Accepted reseller and channel partners can register qualified opportunities. Protection depends on approved registration, active pursuit, and partner terms.
Who owns renewals?
Renewal ownership is defined by agreement and depends on account ownership, support boundary, delivery model, and whether SecEng or the partner contracts directly.
Can we combine reseller and MSSP rights?
Yes, if explicitly approved. Resale, MSSP, consulting, private-label, and white-label rights are separate grants and should not be assumed from one another.
Must we use the aisecurity.llc UI?
No for OEM and many partner motions. Headless, local, sidecar, and structured-output paths can support partner-native presentation where licensed.
What inputs can the engine accept?
Depending on module and scope: code, architecture artifacts, prompts, RAG flows, traces, agent definitions, tool manifests, schemas, reports, and evidence artifacts.
What outputs are available?
Structured findings, JSON, SARIF where supported, markdown reports, evidence bundles, remediation backlogs, validation logs, and partner-safe report components.
Which adapters are native versus projected?
Adapter maturity is labeled honestly: publicly documented, SecEng projection, fixture validated, native partner confirmed, or live partner validated.
Is SARIF supported?
SARIF is supported for scanner-style outputs where the selected module and mapping support it.
Can workloads run locally or offline?
Local worker, OEM sidecar, offline, and air-gapped deployment models are available where licensed and technically appropriate.
How are updates handled?
Update process depends on deployment model and agreement: hosted updates, local worker updates, signed offline updates, or coordinated white-label releases.
Does customer data leave the partner environment?
That depends on deployment. Local, sidecar, offline, and air-gapped paths can limit data movement. The chosen model should document exactly what leaves the environment.
Who owns partner data?
Partner and customer data ownership is controlled by the agreement and data-processing terms. SecEng does not need ownership of partner customer data to provide licensed capability.
Who owns generated findings?
Customer-facing findings and reports are governed by the commercial agreement. SecEng retains protected IP in the underlying engine, methods, schemas, and tooling.
What SecEng IP remains protected?
SecEng retains protected IP in its engine implementation, methods, schemas, playbooks, evidence model, scoring internals, and non-public tooling unless a written agreement grants different rights.
Is hidden model reasoning retained?
Partner-facing outputs should rely on approved evidence, findings, logs, and report artifacts rather than exposing hidden model reasoning.
How are secrets handled?
Partners should not submit secrets in public forms. Scoped deployments should define secret boundaries, redaction, local execution, retention, and support diagnostics.
Who provides first-line support?
Usually the partner provides first-line customer support for partner-led delivery. SecEng provides product, licensing, technical, and approved escalation support.
What does SecEng escalate?
SecEng escalates product defects, license or entitlement issues, adapter breaks, evidence-integrity disputes, methodology questions, and approved specialist technical review.
What training is available?
Training may include sales enablement, technical enablement, delivery playbooks, Academy content, labs, QA rules, and report/evidence guidance.
What happens when an adapter contract changes?
The parties confirm version compatibility, update mappings, rerun fixtures or test-tenant validation, and coordinate customer-facing release notes where needed.
What constitutes production validation?
Production validation means the scoped integration or service flow has been tested against agreed inputs, outputs, data boundary, support path, and customer-facing success criteria.
What can be private-labeled?
Service and report wrapper elements such as cover, visual identity, executive summary, partner intro, delivery-team details, and remediation packaging.
What can be fully white-labeled?
Product naming, packaging, embedded outputs, deeper attribution control, and distribution or sublicensing rights where explicitly granted.
What attribution remains contractual?
Attribution, powered-by language, disclosure, and audit rights depend on the agreement. Public-facing presentation can differ from contractual attribution.
Can reports and output schemas be customized?
Presentation and selected output mappings can be customized where licensed. Technical evidence, safety caveats, and finding integrity cannot be altered to create unsupported claims.
Still evaluating the right partner route?
Request the Partner Brief or apply for qualification without creating a portal account first.