aisecurity.llc
hello@aisecurity.llc
Legal Agreement · Negotiation Draft
Launch Gate Statement of Work
Scope template for the AI Launch Security Review: targets, testing window, deliverables (Launch Risk Memo, Abuse-Path Findings, Release Gate Checklist, Sprint Backlog, Buyer Evidence Summary), retesting terms, and 50/50 payment schedule.
This document describes the scope, targets, deliverables, responsibilities, timeline, and acceptance criteria for an AI Launch Security Review engagement. Final binding terms are set in the executed SOW.
1. Engagement Objective
The AI Launch Security Review determines launch-readiness from a security perspective: what can break, what must be fixed before launch, and what evidence product, security, leadership, and buyers can rely on.
By engagement close, the customer will have:
- A Launch Risk Memo with go/no-go release gate recommendation
- A prioritized Abuse-Path Findings list
- A Release Gate Checklist (blockers vs. acceptable-risk items)
- A Sprint-Ready Fix Backlog
- A Buyer-Ready Evidence Summary scoped to the review
2. Scope
System targets (to be specified on execution)
| Target | Type | Access level |
|---|---|---|
| __________________ | LLM app / RAG / agent / copilot / workflow | __________________ |
| __________________ | __________________ | __________________ |
In scope
- LLM application surfaces as named above
- Prompt injection, RAG leakage, output sink, and agent authority surfaces within the named targets
- Buyer-visible and trust-center-relevant outputs as specified
- Access roles: as granted by customer per Section 4
Out of scope
- Systems not named above
- Infrastructure, network, or non-AI application layers (unless explicitly named)
- Destructive testing, DoS, brute force, credential stuffing, social engineering
- Third-party provider infrastructure (cloud provider, model host) unless separately authorized
- Source code review beyond excerpts necessary to document findings
3. Deliverables
| # | Deliverable | Description | Delivery timing |
|---|---|---|---|
| 1 | Launch Risk Memo | Risk summary, go/no-go recommendation, key findings | End of review window |
| 2 | Abuse-Path Findings | Finding list: severity, title, path description, reproduction notes | End of review window |
| 3 | Release Gate Checklist | Blocker vs. acceptable-risk classification for each finding | End of review window |
| 4 | Sprint-Ready Fix Backlog | Prioritized remediation sequencing with engineering context | End of review window |
| 5 | Buyer-Ready Evidence Summary | Scoped, caveated evidence language for trust and sales use | End of review window |
4. Customer Responsibilities
Customer must provide before the review window opens:
- Named targets and access credentials (per agreed access level)
- Technical overview of each target (architecture brief, prompt structure, data sources, tool list)
- Designated technical contact for finding questions during the review window
- Written authorization to test all named targets (per Assessment Terms Addendum, Section 3)
- Any third-party authorizations required (e.g., cloud provider testing consent)
5. Timeline
| Milestone | Target |
|---|---|
| SOW and Addendum executed | Day 0 |
| Customer provides access and architecture brief | Day 1–2 |
| Review window opens | Day 2–3 |
| First findings readout (preliminary) | Day 5 |
| Review window closes | Day 7–10 |
| All deliverables delivered | Day 8–10 |
| Customer acceptance confirmation | Within 5 business days of delivery |
Expedited option: First findings readout on Day 3. Release Gate Checklist on Day 5. All deliverables by Day 5–7.
Timeline assumes customer provides access and architecture brief by Day 2. Delays in access provisioning extend the window accordingly.
6. Fees
| Item | Amount |
|---|---|
| Engagement fixed fee | Per private offer (Standard: $8k–$15k / Full: $20k–$35k / Expedited: $25k–$40k) |
| Payment 1 | 50% on SOW execution |
| Payment 2 | 50% on delivery acceptance |
7. Acceptance Criteria
The engagement is accepted when the customer confirms in writing:
- All deliverables listed in Section 3 have been received
- The Launch Risk Memo and Release Gate Checklist are actionable for the customer's launch decision
- No material deficiency exists in the deliverables
If the customer identifies a material deficiency, the customer must notify aisecurity.llc within 5 business days of delivery. aisecurity.llc will address material deficiencies within 5 business days of notice.
8. Data Handling
No customer end-user PII is required for or included in the Launch Security Review. If PII is inadvertently encountered during review, it will be handled per the Evidence Handling Policy and the Data Processing Addendum (if executed).
9. Retesting
The SOW does not include retesting of remediated findings. A retesting engagement may be scoped separately after remediation is complete.
This SOW description is for planning and discussion. The executed SOW governs. All commercial terms are final when the SOW is signed. This document does not constitute legal advice.