Security Addendum (Enterprise SaaS)

Alaska Contracts & Agreements Updated August 20, 2026 Free Word and PDF

ENTERPRISE SAAS SECURITY ADDENDUM

ALASKA

Use gate. Complete the Data and Service Inventory, Shared Responsibility
Matrix, Security Control Profile, and Incident Schedule before Provider receives
production access or Customer Data. Use a tailored agreement for health,
financial, payment-card, biometric, children's, government, education, defense,
criminal-justice, export-controlled, safety-critical, or other regulated data or
systems.


1. PARTIES AND MASTER AGREEMENT

Addendum Effective Date: [__/__/____]

Master Agreement: [________________________________]

Order Form or Services: [________________________________]

Customer

Legal Name: [________________________________]

Security Contact: [________________________________]

Privacy Contact: [________________________________]

Incident Contact: [________________________________]

Provider

Legal Name: [________________________________]

Security Contact: [________________________________]

Privacy Contact: [________________________________]

24-Hour Incident Contact: [________________________________]

Each is a "Party"; together, the "Parties."


2. DOCUMENTS AND PRECEDENCE

This Addendum includes each checked schedule:

☐ Schedule A — Data and Service Inventory

☐ Schedule B — Shared Responsibility Matrix

☐ Schedule C — Security Control Profile

☐ Schedule D — Security Evidence and Testing Plan

☐ Schedule E — Subprocessor and Location Register

☐ Schedule F — Incident, Notification, and Cooperation Plan

☐ Schedule G — Recovery, Return, and Destruction Plan

☐ Schedule H — Security Risk, Insurance, and Dispute Schedule

For security, incident, data-protection, and continuity subjects, this Addendum
controls over inconsistent general terms in the Master Agreement. A signed
regulated-data or sector addendum controls for its narrower subject. If two
security documents conflict without a clear precedence rule, the Parties shall
resolve the conflict in writing; phrases such as "more protective" do not by
themselves identify which operational requirement controls.

No changing web page, framework label, questionnaire answer, report, policy,
certification, or third-party term becomes a contractual control unless the
Parties identify its version, scope, and status in a signed schedule.


3. DEFINITIONS

"Customer Data" means the data, content, files, prompts, records,
credentials, and other information identified in Schedule A that Customer or
its users submit to, make available to, or authorize Provider to access through
the Services.

"Customer Environment" means systems, networks, identities, devices, and
configurations Customer controls and identifies in Schedule B.

"Provider Environment" means systems, networks, identities, devices,
facilities, applications, and configurations Provider controls and uses to
deliver the Services or process Customer Data.

"Security Incident" means the event and threshold defined in Schedule F.

"Security Evidence" means the reports, certifications, summaries,
attestations, test results, diagrams, inventories, and records identified in
Schedule D.

"Subprocessor" means a third party Provider authorizes to process Customer
Data for the Services, as identified in Schedule E.

"Vulnerability" means a weakness in an in-scope system, component,
configuration, process, or control that could be used to affect confidentiality,
integrity, or availability, classified through the method in Schedule C.


4. DATA AND SERVICE SCOPE

Schedule A shall identify for each service and data set:

  • Service, feature, environment, owner, and business purpose
  • Data categories, sources, individuals, sensitivity, and classification
  • Customer, Provider, and third-party roles
  • Collection, access, use, disclosure, storage, and output
  • Hosting and support locations
  • Retention, backup, archive, return, and deletion
  • Approved users, administrators, and service accounts
  • Integrations, APIs, subprocessors, and material dependencies
  • Production, test, support, analytics, telemetry, and AI use

Provider shall process Customer Data only for the purposes, Services, and
instructions in Schedule A. Provider may not use Customer Data for advertising,
profiling, model training, product development, benchmarking, or another purpose
unless the schedule expressly permits that use and states the conditions.

Out-of-scope systems and data: [________________________________]

Prohibited data: [________________________________]

Approved temporary support access: [________________________________]


5. SHARED RESPONSIBILITY

Schedule B shall assign ownership for each control and dependency, including:

  • Identity source, user provisioning, authentication, and access review
  • Customer configuration and secure defaults
  • Network connection, endpoint, browser, and device controls
  • Data classification, minimization, input quality, and lawful instructions
  • Encryption, keys, certificates, secrets, and credential rotation
  • Logging, alerting, monitoring, and response
  • Application, infrastructure, platform, and third-party patching
  • Backup, export, recovery, continuity, and testing
  • Integration, API, webhook, and file-transfer security
  • Vulnerability disclosure, remediation, and exception approval
  • Subprocessor, location, and cross-border controls
  • Incident decisions, individual or regulator notice, and communications

An unassigned row is not presumed to belong to Provider. The Parties shall
resolve every material unassigned responsibility before production use.

Each Party shall promptly notify the other when a dependency it controls is
missing, misconfigured, compromised, or likely to prevent the other Party's
performance.


6. SECURITY GOVERNANCE AND CONTROL PROFILE

6.1 Security Program

Provider shall maintain a documented security program appropriate to the
Services, Customer Data, threat model, and controls selected in Schedule C.

Security executive: [________________________________]

Control framework, version, and scope: [________________________________]

Risk-assessment method and cadence: [________________________________]

Policy review cadence: [________________________________]

Exception approval and expiration: [________________________________]

6.2 Control Status

Each Schedule C control shall be marked:

☐ Required and implemented

☐ Required by agreed date [__/__/____]

☐ Customer responsibility

☐ Shared responsibility

☐ Compensating control approved

☐ Not applicable with rationale

Provider shall not represent that a framework, certification, or report covers a
service, location, period, system, or control outside its documented scope.

6.3 Material Change

Provider shall give the notice in Schedule C before a material change to the
security architecture, control ownership, hosting location, identity model,
encryption, key custody, logging, recovery, material component, or subprocessor
that could materially change Customer's risk.

Emergency-change notice: [________________________________]

Customer objection and resolution: [________________________________]


7. IDENTITY AND ACCESS MANAGEMENT

Schedule C shall state requirements for:

☐ Unique user and administrator identities

☐ Multi-factor authentication by access type

☐ Least privilege and role-based access

☐ Separate privileged and ordinary accounts

☐ Privileged-access approval, recording, and time limits

☐ Service-account inventory and ownership

☐ Joiner, mover, and leaver timing

☐ Periodic access certification

☐ Session, lockout, and reauthentication controls

☐ Emergency and break-glass access

☐ Customer federation or single sign-on

Administrative-access method: [________________________________]

Support-access approval and monitoring: [________________________________]

Access-review frequency and evidence: [________________________________]

Password length, rotation, complexity, and lockout settings shall follow the
selected authentication design and current threat assessment in Schedule C;
this form does not impose one static rule on every identity type.


8. CRYPTOGRAPHY, KEYS, AND SECRETS

Schedule C shall identify:

  • Data and connections requiring encryption
  • Protocols, algorithms, modes, and minimum strengths
  • Certificate issuance, inventory, expiration, and revocation
  • Key generation, storage, access, rotation, backup, recovery, and destruction
  • Provider-managed, Customer-managed, and third-party key custody
  • Secrets storage, scanning, access, and rotation
  • Separation of encrypted data from keys and recovery material

Data in transit profile: [________________________________]

Data at rest profile: [________________________________]

Key-management service and custodian: [________________________________]

Customer-held key or bring-your-own-key terms: [_______________________]

Provider shall notify Customer of a known compromise of an in-scope key,
certificate, secret, or recovery mechanism under Schedule F.


9. INFRASTRUCTURE, NETWORK, AND CLOUD SECURITY

Schedule C shall state applicable controls for:

☐ Asset and cloud-resource inventory

☐ Secure configuration baseline and drift detection

☐ Network segmentation and tenant isolation

☐ Firewall, security-group, and access-list governance

☐ Administrative network and remote access

☐ Endpoint protection and device management

☐ Malware and ransomware protections

☐ Denial-of-service protections

☐ Cloud control-plane monitoring

☐ Container, orchestration, and image security

☐ Infrastructure-as-code review and scanning

☐ Production and nonproduction separation

Hosting architecture reference: [________________________________]

Tenant-isolation evidence: [________________________________]

Customer connectivity dependencies: [________________________________]


10. SECURE DEVELOPMENT AND CHANGE MANAGEMENT

For software used to deliver the Services, Schedule C shall address:

☐ Documented development lifecycle

☐ Security requirements and threat modeling

☐ Peer review and protected branches

☐ Static, dynamic, dependency, and secret scanning

☐ Build-pipeline and artifact integrity

☐ Test-data controls

☐ Release approval and rollback

☐ Dependency inventory and update process

☐ Third-party and open-source component review

☐ Vulnerability disclosure and intake

☐ Emergency change process

Production change notice: [________________________________]

Material feature removal or degradation: [____________________________]

Software component inventory or equivalent evidence: [________________]


11. VULNERABILITY MANAGEMENT

11.1 Discovery

Scanning scope and cadence: [________________________________]

Penetration-testing scope and cadence: [________________________________]

External reports or disclosure channel: [________________________________]

11.2 Classification

Vulnerabilities shall be prioritized using the method in Schedule C, which may
consider technical severity, exploitability, exposure, data sensitivity,
service criticality, active exploitation, reachability, compensating controls,
and business impact.

11.3 Remediation Targets

Priority Target Start Event Exception Approver Customer Notice
Critical [____] [____] [____] [____]
High [____] [____] [____] [____]
Medium [____] [____] [____] [____]
Low [____] [____] [____] [____]

An exception shall state scope, rationale, compensating control, owner,
expiration, and review date. Provider shall notify Customer of an overdue
material Vulnerability affecting the Services under the threshold in Schedule C.


12. LOGGING, MONITORING, AND DETECTION

Schedule C shall identify:

  • Logged systems, events, identities, administrative actions, and data access
  • Log contents, time synchronization, integrity, access, and retention
  • Alert sources, thresholds, triage, escalation, and coverage hours
  • Security operations responsibilities and contact paths
  • Customer access to logs, events, reports, or integrations
  • Detection testing and tuning cadence

Security-log retention: [________________________________]

Administrative-action logging: [________________________________]

Customer event feed or export: [________________________________]

Monitoring coverage: [________________________________]

Provider shall not include sensitive content in logs beyond the documented need
and shall protect logs according to their data classification.


13. DATA HANDLING AND LIFECYCLE

Schedule A and C shall identify controls for:

☐ Data minimization and purpose limitation

☐ Production-data restrictions in test and development

☐ Upload, download, export, and bulk-access controls

☐ Data segregation and tenant separation

☐ Backup and archive handling

☐ Removable media and printing

☐ Data loss prevention

☐ Retention and legal-hold interaction

☐ Return, deletion, and destruction verification

Primary retention: [________________________________]

Backup retention: [________________________________]

Support copy and diagnostic data: [________________________________]

Deletion method and evidence: [________________________________]

The selected destruction standard shall be identified by name, version, media
type, and verification method in Schedule G; a superseded version is not
incorporated merely because it appeared in a prior template.


14. BACKUP, RECOVERY, AND CONTINUITY

Schedule G shall identify:

☐ Backup frequency and protected scope

☐ Backup encryption and access

☐ Geographic or logical separation

☐ Restore testing and evidence

☐ Recovery time objective

☐ Recovery point objective

☐ High availability and failover

☐ Disaster declaration and communications

☐ Dependency and concentration risks

☐ Business continuity exercises

Service RTO RPO Test Frequency Last Evidence Date
[________________] [____] [____] [____] [__/__/____]

Provider shall report a failed recovery test that materially affects the agreed
targets, together with remediation and retest timing.


15. PERSONNEL AND PHYSICAL SECURITY

Schedule C shall identify applicable controls for:

☐ Confidentiality commitments

☐ Role-appropriate security training

☐ Specialized administrator, developer, and incident training

☐ Background screening by role and location after legal review

☐ Disciplinary and termination procedures

☐ Remote-work controls

☐ Facility access approval and review

☐ Visitor management

☐ Environmental and power protections

☐ Media storage and disposal

Provider shall not promise a fixed type or lookback period of personnel screening
without confirming that it is appropriate and permitted for each role and work
location.


16. SUBPROCESSORS AND LOCATIONS

Schedule E shall list each Subprocessor's legal name, service, data, purpose,
hosting and support locations, access type, contract status, and material
dependency.

16.1 Existing Subprocessors

Customer approves only the entities listed in the signed Schedule E.

16.2 Change Procedure

Prior notice: [____] days

Emergency notice: [________________________________]

Customer objection grounds and period: [________________________________]

Resolution and termination option: [________________________________]

16.3 Flow-Down and Oversight

Provider shall impose written obligations appropriate to the Subprocessor's
service, data, access, and risk, and shall maintain the assessment and monitoring
evidence selected in Schedule D. Provider's responsibility for a Subprocessor is
stated in Schedule H.

Provider shall not move Customer Data or material support access to a location
outside Schedule E without following the change procedure.


17. SECURITY EVIDENCE, ASSESSMENT, AND AUDIT

17.1 Routine Evidence

Schedule D shall select and scope the evidence Provider supplies:

☐ Independent controls report

☐ Security certification

☐ Penetration-test executive summary

☐ Vulnerability-management summary

☐ Business-continuity and restore-test summary

☐ Security questionnaire

☐ Architecture or data-flow diagram

☐ Insurance evidence

☐ Remediation status

For each item, state period, system and service scope, confidentiality, reliance,
redactions, frequency, and delivery date.

17.2 Customer Assessment

Customer may conduct the assessment selected in Schedule D subject to notice,
frequency, scope, confidentiality, safety, third-party restrictions, tenant
protection, cost, and noninterference conditions.

Ordinary frequency: [________________________________]

Additional assessment triggers: [________________________________]

On-site or technical testing permission: [________________________________]

No penetration test, scan, exploit attempt, social engineering, or facility
access is authorized without separate written rules of engagement.

17.3 Findings

Provider shall respond to an in-scope material finding with owner, severity,
remediation, compensating control, target date, and evidence. Disputed findings
follow the escalation in Schedule H.


18. SECURITY INCIDENT MANAGEMENT

18.1 Incident Definition and Levels

Schedule F shall distinguish:

  • Security event not requiring Customer notice
  • Suspected Security Incident requiring investigation notice
  • Confirmed Security Incident affecting Customer Data or Services
  • Material availability or integrity event
  • Event requiring transaction-specific legal notification analysis

18.2 Provider Notice

Knowledge threshold: [________________________________]

Initial notice period: [________________________________]

Notice method and 24-hour recipient: [________________________________]

Update cadence: [________________________________]

Provider's notice shall include facts then known, affected services, systems and
data, detection and occurrence dates if known, containment, evidence status,
contact, and next update. Provider shall not delay the initial notice solely
because investigation is incomplete.

18.3 Response and Cooperation

Schedule F shall assign:

  • Incident command and technical containment
  • Forensic investigator selection and privilege decisions
  • Evidence preservation and chain of custody
  • Scope, affected-individual, and harm analysis
  • Restoration and secure reactivation
  • Insurer, law enforcement, regulator, and third-party contact
  • Individual, customer, partner, or public notice decisions
  • Notice drafting, translation, mailing, call center, and monitoring services
  • Cost allocation and reimbursement procedure
  • Root-cause report, remediation, and lessons learned

No fixed statutory notice deadline, content, recipient, or threshold is imported
into every incident. Counsel shall determine applicable duties from the actual
data, roles, individuals, locations, contracts, and event facts.

18.4 Communications

Neither Party may identify the other in public incident communications without
approval, except when legally required. The Parties shall coordinate accurate,
timely statements without obstructing a required notice or urgent safety step.


19. RETURN, DELETION, AND EXIT

Schedule G shall state:

Customer export format: [________________________________]

Export availability and timing: [________________________________]

Transition access: [________________________________]

Primary-system deletion deadline: [________________________________]

Backup expiration or deletion: [________________________________]

Subprocessor deletion: [________________________________]

Legal retention exceptions: [________________________________]

Deletion or destruction evidence: [________________________________]

Retained data remains subject to the applicable controls and may be used only
for the documented retention purpose. Provider shall delete it when the approved
retention condition ends.


20. REGULATED USE AND COMPLIANCE MAPPING

Schedule H shall identify transaction-specific privacy, breach, security,
records, sector, export, sanctions, accessibility, public-sector, employment,
and other requirements and map each obligation to a Party, data set, system,
location, control, and evidence source.

Regulated data or use: [________________________________]

Applicable addenda: [________________________________]

Customer legal instructions: [________________________________]

Provider compliance evidence: [________________________________]

A contractual term such as "Personal Information," "Confidential," or
"High-Risk" does not by itself establish a statutory category or assign a legal
role. The legal mapping must be completed separately.


21. AI, AUTOMATION, AND MATERIAL TECHNOLOGY CHANGE

If the Services include AI or automated decision functionality, Schedule A or a
separate AI addendum shall identify models and providers, versions, inputs,
outputs, approved uses, affected persons, decision role, human oversight, data
and training use, evaluation, limitations, monitoring, incidents, changes, and
disable controls.

Provider shall notify Customer before enabling a material AI function that uses
Customer Data or changes an approved decision role, unless the signed schedule
already authorizes that change.

AI features approved: [________________________________]

Customer Data permitted for model improvement: [_______________________]

Material technology change procedure: [________________________________]


22. INSURANCE, INDEMNITY, AND LIABILITY

22.1 Insurance

Schedule H shall select coverage, limits, retention, period, insurer standards,
evidence, notice, additional-insured treatment, and tail requirements based on
the Services and risk.

Coverage Limit Retention Period Evidence
Cyber / privacy $[____] $[____] [____] [____]
Technology errors and omissions $[____] $[____] [____] [____]
Commercial general liability $[____] $[____] [____] [____]
Crime / fidelity $[____] $[____] [____] [____]

Insurance does not expand or reduce contractual liability unless Schedule H
expressly says so.

22.2 Security Indemnity

☐ No separate security indemnity

☐ Provider security indemnity in Schedule H

☐ Mutual data/security indemnities in Schedule H

Any indemnity must identify covered third-party claims, required connection to
conduct, exclusions, defense control, counsel, notice, cooperation, settlement,
cost categories, and relationship to liability limits.

22.3 Liability Allocation

☐ Master Agreement limits apply unchanged

☐ Security sublimit or supercap: [________________________________]

☐ Defined claims outside limits: [________________________________]

☐ Defined excluded damage categories and exceptions: [___________________]

The Parties shall address foreseeable security losses, including investigation,
restoration, notification, call center, monitoring, regulator response,
substitute service, data reconstruction, and customer credits.


23. TERM, SUSPENSION, AND SURVIVAL

This Addendum begins on the Addendum Effective Date and continues while Provider
processes Customer Data or has an uncompleted security, incident, return,
deletion, or remediation obligation.

Provider may suspend Services for a security reason only under the grounds,
scope, notice, emergency, restoration, and data-access rules in Schedule H.
Suspension shall be limited to the affected access where reasonably practicable.

Data use restrictions, confidentiality, incident cooperation, return, deletion,
evidence protection, liability allocation, dispute provisions, and terms
intended by their nature to continue survive to the extent stated.


24. DISPUTES AND GENERAL TERMS

24.1 Governing Terms

The Master Agreement's governing-law, forum, notice, assignment, amendment,
waiver, severability, counterpart, and dispute provisions apply unless Schedule
H expressly states an approved security-specific override.

24.2 Time-Sensitive Relief

A Party may request time-sensitive relief subject to the law, procedure,
jurisdiction, security, and bond or undertaking rules that actually apply. This
Addendum does not promise automatic injunctive relief or waive a required bond.

24.3 Jury Waiver and Arbitration

☐ Master Agreement applies unchanged

☐ No contractual jury waiver or arbitration for this Addendum

☐ Separate counsel-approved security dispute addendum attached

24.4 Fees and Costs

☐ Master Agreement applies unchanged

☐ Each Party bears its own fees and costs except as otherwise required

☐ Defined prevailing-party provision in Schedule H

24.5 Electronic Execution

The Parties may sign this Addendum using the method selected below after
transaction-specific execution review:

☐ Wet ink

☐ Approved electronic-signature platform: [________________________________]

☐ Other authenticated method: [________________________________]


25. SIGNATURES

Each signatory represents that the signatory is authorized to sign for the
identified Party.

Customer

Legal Name: [________________________________]

By: [________________________________]

Printed Name: [________________________________]

Title: [________________________________]

Date: [__/__/____]

Provider

Legal Name: [________________________________]

By: [________________________________]

Printed Name: [________________________________]

Title: [________________________________]

Date: [__/__/____]


SCHEDULE A — DATA AND SERVICE INVENTORY

Service / Feature Environment Data Purpose Roles Locations Retention
[____] [____] [____] [____] [____] [____] [____]

Support and Administrative Access: [________________________________]

Telemetry, Analytics, and AI Use: [________________________________]

Prohibited Data and Uses: [________________________________]


SCHEDULE B — SHARED RESPONSIBILITY MATRIX

Control / Dependency Customer Provider Shared Steps Evidence
Identity source [____] [____]
User provisioning [____] [____]
Authentication [____] [____]
Customer configuration [____] [____]
Encryption and keys [____] [____]
Logging and alerting [____] [____]
Vulnerability remediation [____] [____]
Backup and recovery [____] [____]
Incident response [____] [____]
Notice decisions [____] [____]

SCHEDULE C — SECURITY CONTROL PROFILE

Framework, Version, and Scope: [________________________________]

Control Baseline and Exceptions: [________________________________]

Identity and Access: [________________________________]

Cryptography and Keys: [________________________________]

Infrastructure and Network: [________________________________]

Secure Development: [________________________________]

Vulnerability Targets: [________________________________]

Logging and Detection: [________________________________]

Data Handling: [________________________________]

Personnel and Physical Security: [________________________________]

Material Change Notice: [________________________________]


SCHEDULE D — SECURITY EVIDENCE AND TESTING PLAN

Evidence Scope / Period Delivery Confidentiality / Reliance
[____] [____] [____] [____]

Customer Assessment: [________________________________]

Additional Assessment Triggers: [________________________________]

Finding and Remediation Process: [________________________________]

Technical Testing Rules of Engagement: [______________________________]


SCHEDULE E — SUBPROCESSOR AND LOCATION REGISTER

Legal Name Service Data / Access Hosting Support Contract Status
[____] [____] [____] [____] [____] [____]

Change Notice: [________________________________]

Objection and Resolution: [________________________________]

Assessment and Flow-Down Evidence: [________________________________]


SCHEDULE F — INCIDENT, NOTIFICATION, AND COOPERATION PLAN

Security Incident Definition: [________________________________]

Knowledge Threshold and Initial Notice: [____________________________]

24-Hour Contacts and Method: [________________________________]

Update Cadence: [________________________________]

Incident Command and Forensics: [________________________________]

Notice Decision and Communications: [________________________________]

Cost Allocation: [________________________________]

Root Cause, Remediation, and Final Report: [___________________________]


SCHEDULE G — RECOVERY, RETURN, AND DESTRUCTION PLAN

Backup Scope and Frequency: [________________________________]

RTO / RPO: [________________________________]

Restore and Continuity Testing: [________________________________]

Customer Export: [________________________________]

Primary and Backup Deletion: [________________________________]

Destruction Standard, Version, and Media Scope: [_____________________]

Subprocessor Deletion and Evidence: [________________________________]


SCHEDULE H — SECURITY RISK, INSURANCE, AND DISPUTE SCHEDULE

Regulated-Use Mapping: [________________________________]

Insurance: [________________________________]

Indemnity: [________________________________]

Liability Limit and Damage Categories: [______________________________]

Suspension and Termination: [________________________________]

Security-Specific Governing / Forum Override: [_______________________]

Jury Waiver or Arbitration Addendum: [________________________________]

Fees and Costs: [________________________________]


End of template.

Insert Image

Insert Table

Watch Ezel in action (sample case)Choose a plan

All changes saved
Save
Export
Export as DOCX
Export as PDF
Generating PDF...
security_addendum_enterprise_ak.pdf
Ready to export as PDF or Word
AI is editing...
Chat
Review

Draft it in the editor

The AI drafts each section from your answers and you review every word. Drafting from scratch takes hours; finish yours for $99 one time.

  • Built on this template
    Uses the Alaska version and the statutes it cites.
  • Formatted like the template
    Captions, numbering and layout stay intact.
  • AI editing
    Rewrite any section from your own notes.
  • Export as PDF and Word
    Yours to review, sign, or file.
Secure checkout via Stripe
Need to customize this document?

About this template

Last updated
August 20, 2026
Citations checked
August 20, 2026
Jurisdiction
Alaska
Category
Contracts & Agreements

A contract is a written record of what two or more parties agreed to and what happens if someone does not follow through. Clear language, defined terms, and clean signature blocks keep disputes small and enforceable. The most common mistakes in contracts come from vague promises, missing details about timing or payment, and skipping standard protective clauses like governing law and dispute resolution.

Not legal advice

This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.

Checked against the law it cites

A reviewer verified this template's legal citations against the official source on August 20, 2026.

Draft your Security Addendum (Enterprise SaaS) in the editor

Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.