aisecurity.llc
hello@aisecurity.llc
Legal Agreement · Negotiation Draft
Launch Gate Assessment Terms Addendum
Authorized scope, safe harbor, reliance limits, and claim caveats for pre-release AI Launch Security Reviews. Required for all launch-gate engagements.
This document describes the key terms governing the scope, authorization, reliance limits, and claim boundaries for an AI Launch Security Review engagement. Final binding terms are set in the executed Statement of Work and this Addendum.
1. Purpose
This Addendum establishes the authorized scope of the Launch Security Review, the safe harbor protecting the customer from findings that arise during scoped review, and the limits on how outputs may be relied upon by the customer and its external audiences.
2. Authorized Scope
The Launch Security Review is limited to the system targets, components, access levels, and testing window specified in the Statement of Work. The following are in scope only if explicitly named in the SOW:
- LLM application endpoints, prompts, and retrieval pipelines
- AI-generated code and associated API surfaces
- Agent tool-call surfaces, permission boundaries, and data access paths
- Customer-facing copilot or assistant surfaces
- Internal AI workflows with customer data access
Testing is passive-to-light-active. Destructive testing, DoS, brute force, social engineering, and third-party system targeting are out of scope unless separately authorized in writing.
3. Customer Authorization
Customer represents that it has authority to authorize the Launch Security Review against all named targets and that customer owns or controls all systems within the defined scope. aisecurity.llc will not test systems outside the authorized scope. Customer is responsible for obtaining any required third-party authorizations (e.g., cloud provider testing consent) before the review window opens.
4. Safe Harbor
aisecurity.llc's conduct of the Launch Security Review within the authorized scope and timing does not constitute unauthorized access, security testing without authorization, or violation of applicable computer access laws. Customer grants aisecurity.llc a limited, time-bound authorization to access and assess the named systems for the purposes described in the SOW.
5. Reliance Limits
Launch Review outputs — including the Launch Risk Memo, Abuse-Path Findings, Release Gate Checklist, Sprint Backlog, and Buyer-Ready Evidence Summary — are:
- Scoped to the systems, access, and testing window defined in the SOW
- Not a guarantee that all vulnerabilities or risks have been identified
- Not a certification that the system is secure, compliant, or safe for any particular use
- Not a substitute for a full penetration test, SOC 2 audit, regulatory review, or continuous security program
- Point-in-time assessments; findings may change as the system changes
6. Customer-Facing and Public Claims
Outputs from the Launch Security Review may be referenced in buyer-facing evidence, trust documentation, or public statements only where:
- Claims are accurate, scoped, and caveated to the review scope and date
- Claims do not imply broader coverage, certification, or compliance status than the review scope supports
- Claims that name aisecurity.llc or reference the review have been reviewed and approved by aisecurity.llc before publication
Claims that "the system was reviewed by aisecurity.llc" or similar must be accompanied by the scope and date of the review.
The Publication and Claim-Readiness Policy addendum applies if buyer-facing evidence or public claims are a primary output of the engagement.
7. Findings and Remediation
aisecurity.llc will deliver findings as described in the SOW. aisecurity.llc does not guarantee that remediation of findings eliminates all risk. Customer is responsible for prioritizing, scheduling, and executing remediation work. aisecurity.llc may provide a Sprint-Ready Fix Backlog as a remediation-sequencing aid, not a comprehensive remediation plan.
8. Evidence Retention
Testing artifacts, notes, and draft findings are subject to the Evidence Handling Policy. Customer will receive the deliverables defined in the SOW. aisecurity.llc will retain internal working notes per the Evidence Handling Policy's retention schedule.
9. Governing Documents
This Addendum is part of the Launch Security Review commercial package and is read in conjunction with:
- The Statement of Work (defines scope, targets, window, deliverables, fees)
- The Evidence Handling Policy (governs how findings are captured, stored, redacted, and destroyed)
- The Mutual NDA (governs confidentiality)
- The Data Processing Addendum (if customer or personal data is in scope)
In the event of conflict, the order of precedence is: SOW → this Addendum → NDA → other addenda.
This is a summary of key terms for planning and discussion. The executed Addendum and Statement of Work govern. This document does not constitute legal advice.