aisecurity.llc
hello@aisecurity.llc
Legal Agreement · Negotiation Draft
OEM Scanner License Addendum
Technical licensing terms for scanner OEM embeddings: permitted use, redistribution scope, white-label rights, customer-org tracking, usage credit reconciliation, and production license requirements.
1. Purpose
This OEM Scanner License Addendum ("Addendum") governs the rights and obligations of the Partner under a SecEng Scan OEM or white-label deployment. It supplements and is incorporated into the Order Form, Master Agreement, or OEM Evaluation Agreement executed between {{PROVIDER_ENTITY}} and Partner ("the Agreement"). In the event of conflict, this Addendum controls with respect to scanner-provider OEM matters.
2. License Grant
Subject to Partner's full compliance with this Addendum and payment of applicable fees, {{PROVIDER_ENTITY}} grants Partner a limited, non-exclusive, non-transferable, non-sublicensable (except as expressly permitted in Section 4) license to:
- Invoke SecEng Scan in the permitted deployment model specified in the Order Form
- Distribute or embed SecEng Scan outputs to Partner's end customers as part of Partner's scanner or security product
- Use approved branding, co-branding, or white-label packaging as specified in the Order Form
All rights not expressly granted are reserved by {{PROVIDER_ENTITY}}.
3. Permitted Deployment Models
Partner may deploy SecEng Scan under one or more of the following models, as specified in the Order Form:
Headless Binary. Partner invokes SecEng Scan as a subprocess from Partner-controlled infrastructure. Inputs and outputs remain in Partner-controlled environment.
Localhost HTTP Sidecar. SecEng Scan runs as a local or private service, exposing REST endpoints for job lifecycle management and result retrieval. Runs in Partner-controlled environment.
Private Worker/Container. SecEng Scan runs in Partner-controlled infrastructure as a container or managed worker. Partner controls orchestration, isolation, and data boundaries.
Hosted API Service. {{PROVIDER_ENTITY}} hosts or manages the API endpoint. This model requires an approved Data Processing Addendum and evidence handling terms if customer data or scan artifacts are processed outside Partner-controlled environment.
Partner may not change the selected deployment model without written approval from {{PROVIDER_ENTITY}}.
4. White-Label and Branding Rights
Co-branded. Partner may present findings and reports as "Powered by SecEng Scan" or similar approved attribution language. Attribution language must be approved by {{PROVIDER_ENTITY}} in writing before use.
Private-label. If specified in the Order Form, Partner may remove or replace {{PROVIDER_ENTITY}} attribution in partner-facing reports, subject to minimum commitment and audit rights in Section 8.
Full white-label. If specified in the Order Form, Partner may present outputs under Partner's brand without {{PROVIDER_ENTITY}} attribution, subject to higher minimum commitments, output controls, and approval of customer-facing claims per Section 9.
Branding rights do not extend to Partner claiming ownership of the underlying detection engine, IP, or OWASP LLM mappings.
5. Sublicensing and Resale Boundaries
Partner may provide SecEng Scan outputs, integrated findings, or scanner-provider reports to Partner's end customers as part of Partner's scanner or security product.
Partner may not:
- Resell SecEng Scan as a standalone product without written approval
- Grant end customers independent access to SecEng Scan outside Partner's product interface
- Sublicense OEM rights to third parties without prior written approval
- Redistribute the SecEng Scan binary, runtime, or model assets beyond the licensed deployment model
Resale rights, if applicable, must be separately documented in an Order Form amendment.
6. Usage Reporting
Partner must provide monthly usage reports to {{PROVIDER_ENTITY}} no later than the 10th business day of each calendar month, covering:
- Number of active customer organizations scanned
- Approximate scan volume or invocation count
- Deployment model in use
- Any white-label or co-branding usage
Reports must be accurate to within 5%. {{PROVIDER_ENTITY}} may audit Partner's usage records on 10 business days' notice, no more than once per calendar year.
7. Support and Update Obligations
Support. Partner is the first line of support for its end customers. {{PROVIDER_ENTITY}} provides second-line support to Partner under the Support and SLA Addendum or the support tier specified in the Order Form.
Updates. {{PROVIDER_ENTITY}} will make available SecEng Scan updates to Partner through the agreed release channel. Partner is responsible for distributing approved updates to its deployment within the version compatibility window specified in the Order Form.
Deprecated versions. {{PROVIDER_ENTITY}} will provide at least 90 days' notice before deprecating a version Partner is running in production.
8. Data Handling and Telemetry
Partner-controlled deployments (headless binary, localhost sidecar, private worker): scan inputs, artifacts, and findings remain in Partner-controlled environment. {{PROVIDER_ENTITY}} does not have access to scan inputs or customer data in these deployment models.
Hosted API deployments: scan inputs and artifacts are processed by {{PROVIDER_ENTITY}} infrastructure. Partner must obtain appropriate customer authorization, execute the Data Processing Addendum, and comply with the Evidence Handling Policy before submitting customer data to the hosted API.
Telemetry: SecEng Scan may emit operational diagnostics (version, invocation counts, error codes). Diagnostic data does not include scan inputs, finding content, or customer-identifiable information. Partner may disable optional telemetry per the deployment configuration guide.
9. IP Ownership
{{PROVIDER_ENTITY}} retains all right, title, and interest in SecEng Scan, including the detection engine, OWASP LLM mappings, rule content, schemas, documentation, and associated IP.
Partner retains ownership of Partner's scanner product, UI, reports, customer relationships, and any Partner-originated content integrated with SecEng Scan outputs.
SecEng Scan outputs (findings, SARIF files, Markdown reports, evidence bundles) are work product delivered to Partner under this Addendum. Partner may use outputs as permitted in Section 2. Partner does not acquire ownership of the underlying engine, rules, or detection logic by receiving outputs.
10. Restrictions
Partner may not:
- Reverse engineer, decompile, or disassemble the SecEng Scan binary or runtime
- Use SecEng Scan outside the permitted deployment model
- Remove, alter, or obscure license files, checksums, or version metadata
- Train, fine-tune, or use SecEng Scan outputs to develop a competing detection model
- Make public claims about SecEng Scan capabilities beyond what is approved in Section 11
- Use SecEng Scan for active testing of systems Partner does not own or have written authorization to test
11. Customer-Facing Claims Policy
SecEng Scan outputs are security signals and require human review before customer-facing or public claims.
Approved claim language for Partner's marketing and product materials must be submitted to {{PROVIDER_ENTITY}} for review before use. {{PROVIDER_ENTITY}} will respond within 10 business days.
Partner may not claim:
- All vulnerabilities are detected
- Outputs constitute a CVE assignment, public disclosure, or certified security review
- SecEng Scan provides "complete" or "continuous" AI security coverage without qualification
- Compliance certifications derived solely from SecEng Scan outputs
CVE-likelihood scoring identifies candidates for private validation and pre-disclosure review. It does not constitute a CVE assignment or official vulnerability confirmation. Human review by a qualified practitioner is required before submission to a CVE numbering authority or public disclosure program.
12. Vulnerability Disclosure
If Partner discovers a potential security vulnerability in SecEng Scan, Partner must report it to {{PROVIDER_ENTITY}} via the responsible disclosure channel specified in the Security Exhibit within 48 hours of discovery.
Partner must not publicly disclose any discovered vulnerability without {{PROVIDER_ENTITY}}'s prior written consent and a mutually agreed disclosure timeline.
13. Confidentiality
Each party will treat the other's confidential information with at least the same degree of care it applies to its own confidential information, but no less than reasonable care. This Addendum and its terms are confidential.
SecEng Scan detection logic, rule content, schemas, and engine internals are {{PROVIDER_ENTITY}} confidential information regardless of marking.
14. Term and Termination
Term. This Addendum is effective on the date of the executed Order Form and continues for the term specified therein, unless earlier terminated.
Termination for cause. Either party may terminate on 30 days' written notice if the other materially breaches and fails to cure within the notice period.
Effect of termination. On termination, Partner must cease invoking SecEng Scan, destroy all copies of the binary and associated materials, and provide {{PROVIDER_ENTITY}} a written certification of destruction within 15 business days.
15. Wind-Down
If this Addendum is terminated for any reason, Partner may continue to serve existing customers in production deployments for up to 90 days from the termination date ("Wind-Down Period"), subject to continued compliance with Sections 6, 8, 10, and 11.
Partner must not onboard new customers or expand deployment scope during the Wind-Down Period.
16. Order of Precedence
In the event of conflict: this Addendum > Order Form > Master Agreement > OEM Evaluation Agreement. Capitalized terms not defined here have the meaning given in the Master Agreement or Order Form.
This document is a template summary. Final terms are subject to negotiation and execution. This document does not constitute legal advice.