aisecurity.llc
hello@aisecurity.llc
Legal Agreement · Negotiation Draft
AI Launch Security Review SOW
Scoped statement of work for the pre-release AI Launch Security Review — first findings in 5 business days, launch-ready review in 5–10. Auto-populated from your scope intake.
| Effective Date | the Effective Date | Client | Client |
| Engagement | the engagement agreed during scoping | Primary contact | the primary engagement contact |
This Statement of Work ("SOW") describes a scoped, pre-release AI Launch Security Review. It is entered under the parties' Zero-Dollar Services Retainer / Scoped Services Framework (or as a standalone agreement) and the Assessment Terms Addendum. This is a business document; final signer-ready language is confirmed during scoping and is reviewable by counsel.
1. Target system
the AI system identified during scoping
In-scope AI surfaces: the AI systems, features, APIs, and endpoints enumerated and confirmed in writing during scoping
2. Review window and timeline
- First findings in 5 business days from kickoff and access.
- Launch-ready review in 5–10 business days.
- Review window: the review window defined in the applicable SOW
- Detailed timeline: the timeline defined in the applicable SOW
A deeper 2–4 week AI Product Security Assessment is available as separate follow-on work.
3. Deliverables
the deliverables defined in the applicable SOW
The first deliverable is a decision package, not just a report: it states what must be fixed before launch and what evidence buyers can rely on.
4. Scope summary
the scope agreed during scoping
5. Assumptions
- Client provides timely access to the materials in the Technical Access Checklist (architecture, demo/staging, prompts, RAG sources, agent tools, authz, logs).
- Review reflects the system state during the review window and is point-in-time.
- Reference inputs: architecture diagrams, data-flow documentation, and prior assessment reports as available
- Participants: the Client engineering and product leads
6. Exclusions
the exclusions defined in the applicable SOW
This review is not a certification, not a guarantee of future security, not an open-ended program, and not a platform migration.
7. Access boundaries and authorization
- Environment: a staging or development environment unless production access is separately authorized in writing
- Data access: minimum-necessary access; no raw credentials or production customer data without explicit authorization
- Authorized testing: static analysis, architecture review, prompt-injection testing, and AI-specific risk modeling within the agreed scope
- Restrictions: no production exploitation unless separately authorized in a signed Rules of Engagement addendum
No production exploitation or adversarial testing occurs unless separately authorized in a signed AI Red Team Rules of Engagement addendum.
8. Acceptance criteria
Accepted when the agreed deliverables are delivered and the Client has had a reasonable factual-review window.
Accepted when the agreed deliverables are delivered and the Client has had a reasonable factual-review window.
9. Fees and payment
- Fee / private-offer path: as specified in the applicable Order Form or SOW
- Payment terms: Net 30 on invoice
Fees are scoped after triage, with fixed-fee options where possible. Typical budget categories: launch, AppSec, product security, red team, customer assurance, or security review.
10. Confidentiality and data handling
Confidentiality is governed by the Mutual NDA. Evidence handling, retention, and redaction follow the Evidence Handling Policy and Data Retention & Redaction Policy. Client confidential engagement materials are not used to train public models or improve unrelated offerings except as expressly permitted in writing.
Provider: aisecurity.llc · Authorized signatory: David Wolf · hello@aisecurity.llc Client: Client · Authorized signatory: ________________________