aisecurity.llc
hello@aisecurity.llc
Legal Agreement · Negotiation Draft
Scanner Provider Pilot SOW
30-day OEM pilot scope for scanner vendors: integration path, success criteria, support boundaries, usage credits, and conversion path to production OEM license.
1. Purpose
This Statement of Work ("SOW") governs a time-boxed OEM pilot engagement between {{PROVIDER_ENTITY}} ("Provider") and Partner ("Partner") for the SecEng Scan OEM Pack 30-Day OEM Pilot. The pilot is designed to confirm technical integration fit, output quality, and commercial terms for an ongoing OEM or white-label scanner-provider relationship.
This SOW supplements and is incorporated into the OEM Evaluation Agreement or Master Agreement executed between Provider and Partner.
2. Pilot Scope
Invocation model (select one per Order Form or SOW schedule):
- Headless binary
- Localhost HTTP sidecar
- Private worker/container
- Hosted API service (requires approved DPA)
Modules in scope:
- AI Code Risk: AI-generated insecure code patterns, source/sink detection, unsafe eval/exec, unsafe tool invocation, secrets handling, auth/authz risk patterns
- Prompt/RAG/Agent Risk: prompt injection surfaces, system prompt exposure, RAG source boundary issues, tool/action permission risks, agent authority blast radius (select if applicable)
- Evidence Adapter: JSON findings, SARIF, Markdown, evidence bundle, CWE/OWASP LLM mapping, remediation guidance
Output formats in scope (confirm in SOW schedule):
- JSON findings schema
- SARIF
- Markdown report
- Evidence bundle
Target class (select one or more per SOW schedule):
- AI-generated code repository
- RAG application
- Agentic workflow or MCP server
- LLM gateway or proxy
- Other (specify in SOW schedule)
Excluded from this SOW unless separately scheduled: production adapter hardening, unrestricted source access, unrelated customer data, public integration or compatibility claims, redistribution rights, and ongoing support after the pilot term.
3. Timeline
| Milestone | Target Day |
|---|---|
| SOW signed and pilot environment provisioned | Day 0 |
| Invocation model confirmed and working | Day 3–5 |
| Sample corpus scan completed | Day 7–10 |
| Output review with Partner technical team | Day 14 |
| Partner-branded report section draft | Day 20 |
| False-positive review and rubric | Day 24 |
| Pilot summary, findings review, and annual license proposal | Day 28–30 |
Included meetings by default: kickoff (Day 0), contract review (Day 3–5), midpoint review (Day 14), and acceptance review (Day 28–30). Additional sessions are added only when unresolved integration work requires them.
Timeline assumes Partner provides sample corpus, technical owner, and environment access by Day 0.
4. Deliverables
Provider will deliver the following to Partner during the pilot period:
- Headless pilot package or sidecar configuration
- CLI/API invocation guide
- Input schema and configuration reference
- JSON findings output
- SARIF output
- Markdown report
- Evidence bundle output
- Partner-branded sample report section
- 10–25 curated AI security finding patterns for the pilot corpus
- CWE/OWASP LLM Top 10 mapping for findings in scope
- Remediation guidance examples
- Retest criteria examples
- False-positive review rubric
- Support and escalation plan for pilot period
- Update and distribution model summary
- Annual OEM license proposal
- White-Label Scanner Productization SOW (if Partner requests next phase)
5. Partner Responsibilities
- Provide sample corpus or test target by Day 0 (internal code, synthetic fixtures, or authorized sample)
- Designate technical owner and commercial owner before SOW is signed
- Provide environment access required for selected invocation model
- Define pilot success criteria jointly with Provider before Day 5
- Attend output review meeting on Day 14
- Provide written feedback on findings quality and report mapping by Day 21
- Do not submit customer production data unless an approved DPA and evidence handling plan is in place
6. Provider Responsibilities
- Provision pilot package and invocation guide by Day 3
- Respond to technical integration questions within 1 business day
- Deliver all listed deliverables within the timeline
- Not use Partner's sample corpus for any purpose other than pilot delivery
- Maintain confidentiality of all Partner-provided materials per the executed NDA or Master Agreement
7. Responsibility Matrix
| Area | Partner | Provider | Shared |
|---|---|---|---|
| Representative fixture | Accountable | Consulted | — |
| Fixture sanitization | Responsible | Consulted | Joint approval |
| Engine invocation | Consulted | Accountable | — |
| Input and output contract | Responsible | Responsible | Joint approval |
| Mapping approval | Accountable | Responsible | Joint |
| Evidence review | Consulted | Responsible | Joint |
| Acceptance decision | Responsible | Responsible | Joint |
| Production deployment | Accountable | Consulted | Joint planning |
| End-customer support | Accountable | No direct contact unless agreed | — |
| Public claims and logos | Responsible | Responsible | Written mutual approval |
8. Technical Assumptions
- Partner has reviewed and agreed to the Acceptable Use and Scan Scope Terms before pilot begins
- Sample corpus is either Partner-internal code, synthetic fixtures, or test data Partner has the right to scan
- Customer production data is out of scope unless a DPA is executed and evidence handling plan is approved
- Active testing of live systems is out of scope unless separately authorized via a Rules of Engagement schedule
- Invocation model is confirmed before pilot binary or sidecar is provisioned
9. Data Handling
Data handling during the pilot depends on the selected invocation model:
Partner-controlled (headless binary, localhost sidecar, private worker): Scan inputs and outputs remain in Partner-controlled environment. Provider does not receive scan artifacts.
Hosted API (if selected): Scan inputs are processed by Provider infrastructure. Partner must execute the Data Processing Addendum and obtain customer authorization before submitting any customer data. Pilot default is synthetic or Partner-internal data only.
Provider will not use, retain, or share any Partner-provided scan artifacts beyond the pilot scope and term. Retained-if-agreed items are limited to configuration and audit metadata, approved evidence objects, and acceptance artifacts; full unrelated source trees, credentials, secrets, and unrelated customer information are never required by default.
10. IP and Ownership
- Partner retains its data, product, UI, customer relationship, branding, and pre-existing intellectual property.
- Provider retains its engines, methods, canonical contracts, internal prompts, scoring logic, detector implementation, source, and pre-existing intellectual property.
- Partner receives ownership or licensed use of the agreed pilot outputs only as defined in this SOW and the applicable license.
- This pilot does not transfer Provider source code, hidden reasoning, internal scoring logic, unrestricted redistribution rights, or unrelated tooling.
- Ownership of derivative integration work, adapters, mappings, documentation, and productization artifacts is defined in the Annual OEM License Order Form or OEM Scanner License Addendum, as applicable.
11. Support and Communication
- Pilot support channel: designated Slack channel or email alias (specified in SOW schedule)
- Technical escalation: Provider designated technical contact (specified in SOW schedule)
- Weekly check-in: Provider and Partner technical leads (Day 7, Day 14, Day 21)
- Issues response SLA during pilot: 1 business day for integration blockers, 2 business days for output quality questions
- Production support tier, response targets, supported versions, and update cadence are defined in the Annual OEM License Order Form, not this pilot SOW
12. Acceptance Criteria / Pilot Success Criteria
The pilot is considered successful when:
- Agreed invocation model is working and reproducible
- Sample corpus can be scanned without critical errors
- Agreed output formats are produced (JSON, SARIF, Markdown, evidence bundle)
- Partner technical team can review and interpret findings
- Partner-branded report section is reviewed and feedback provided
- Deduplication is demonstrated on repeated analysis
- Rescan and retest state can return to the Partner system of record where in scope
- Data boundary in Section 9 is respected
- Support and update model is understood by both parties
- Annual OEM license proposal is reviewed by Partner commercial owner
- A production decision (proceed, revise and retest, extend scope, or stop) is documented
Unresolved blockers are documented in the pilot summary and addressed in the next-phase SOW.
13. Out of Scope
The following are explicitly out of scope for this SOW:
- Active testing of Partner's production systems or customer environments
- CVE submission, public disclosure, or vulnerability notification to third parties
- Unlimited production resale rights (governed by OEM Scanner License Addendum)
- Customer data processing beyond synthetic or Partner-internal fixtures
- Full white-label productization (governed by White-Label Scanner Productization SOW)
- Integration with Partner's production reporting or remediation workflow (covered in Phase 3)
- Production adapter hardening, monitoring, and ongoing support unless separately scheduled
14. Fees and Payment
Fees for the 30-Day OEM Pilot are as specified in the Order Form or SOW schedule (typical range: $50k–$100k fixed fee).
Payment terms: 50% invoiced on SOW signature; 50% invoiced on delivery of pilot summary and annual license proposal (Day 28–30).
Travel and expenses: not included unless specified in SOW schedule.
Fees do not include production OEM license fees, which are separately quoted in the Annual OEM License Order Form.
15. Claim and Logo Restrictions
Neither party may publish a partnership claim, compatibility claim, customer name, logo, benchmark result, marketplace listing, case study, or production-support statement until the relevant integration-maturity level has been demonstrated and both parties have approved the exact language in writing. This applies to partnership announcements, compatibility badges, customer or partner logos, named integration claims, benchmark or uplift claims, and production-support claims. Exact approved relationship descriptions, verified maturity level, approved technical scope, approved logo treatment, approved benchmark methodology, and approved support status may be published only after written approval.
16. Next Phase Options
At the conclusion of the pilot, Partner may elect:
- Annual OEM License: Ongoing embedded or white-label usage under the Annual OEM License Order Form
- White-Label Scanner Productization: Full productization engagement (8–12 weeks, $180k–$350k+)
- No further engagement: Pilot concludes; Partner destroys pilot materials per the OEM Evaluation Agreement
Provider will provide a written next-phase proposal by Day 28.
This document is a template summary. Final terms are subject to negotiation and execution. This document does not constitute legal advice.