The following agreements and policies govern engagements. Engagement-specific terms auto-populate from your scope intake; signer-ready drafts are produced during scoping and executed through our document-signing flow.
- No-Cost Scoping Retainer
- Pre-engagement scoping: $0 fees, no obligation, NDA path, access boundaries, and a draft review plan before any paid work. Converts to a paid SOW only after approval.
- AI Launch Security Review SOW
- Scoped statement of work for the pre-release AI Launch Security Review — first findings in 5 business days, launch-ready review in 5–10. Auto-populated from your scope intake.
- Scoped Services Framework
- Master services framework for discovery, product review, red-team validation, governance evidence, and paid scopes without a standing retainer.
- Sponsorship Agreement
- Commercial sponsorship terms with explicit research-independence and disclosure boundaries.
- Mutual NDA
- Mutual confidentiality protections for pre-sales, delivery, and research collaboration contexts.
- Commercial Services Addendum
- Converts the services framework into scoped paid work with rate card, invoicing, and activation terms.
- Data Processing Addendum
- Controller/processor allocation, data protection obligations, subprocessing, security measures, AI provider boundaries, and customer-data handling for scoped services.
- Assessment Terms Addendum
- Scope, authorization, evidence use, testing boundaries, safe harbor, retesting, reporting limitations, and reliance limits for AI product security assessments.
- Statement of Work Template
- Mission-specific scope, deliverables, timeline, access, assumptions, and acceptance criteria for scoped AI security engagements.
- AI Red Team Rules of Engagement
- Rules of engagement for authorized AI red-team validation, including targets, test windows, allowed techniques, prohibited actions, safety controls, evidence handling, escalation paths, and stop conditions.
- Penetration Test & Red Team Rules of Engagement
- Rules of engagement for scoped penetration testing and adversarial red team work — authorization, targets, allowed and prohibited techniques, testing window, access plan, evidence handling, emergency stop, and reporting. Covers web/API, cloud, authenticated, business-logic, and AI/agentic testing.
- Cloud Testing Boundary Addendum
- Bounds cloud/infrastructure testing — separates customer-owned active testing targets from configuration-review targets and from provider infrastructure, with account/region scope, access model, and provider-rules responsibility.
- Special Approval Addendum
- Explicit authorization gate for high-impact activities (DoS/stress, phishing, social engineering, physical, malware/C2, third-party/shared-tenant). Excluded from standard scope unless signed here and separately approved.
- Agentic Workflow ROE Addendum
- Bounds testing of tool-using agents and automated workflows — tools/actions in scope, authorized adversarial techniques, action boundaries, rollback, persistence prohibition, and audit-gap reporting.
- Consultant Mission Brief
- Defines specialist role, client relationship model, confidentiality, deliverables, and independence boundary for consultant-led missions.
- Sponsorship Launch Addendum
- Campaign schedule, sponsor assets, labeling, approval process, and launch deliverables.
- Security Operations Schedule
- Operational control schedule for authorized AI security work, covering access, credentials, logging, AI/ML testing boundaries, incident handling, evidence retention, and client escalation.
- Evidence Handling Policy
- Evidence collection, classification, storage, redaction, retention, deletion, and publication boundaries for AI security assessments, red-team work, governance evidence, and public-safe deliverables.
- Publication & Claim-Readiness Policy
- Claim-readiness criteria for public research, trust pages, scorecards, attestations, sponsor materials, security review outputs, and buyer-facing evidence.
- Data Retention & Redaction Policy
- Retention, redaction, deletion, and post-engagement handling for client materials, research artifacts, assessment evidence, exports, and public-safe publication files.