Security Addendum (Enterprise SaaS)
ENTERPRISE SAAS SECURITY ADDENDUM
ALASKA
Use gate. Complete the Data and Service Inventory, Shared Responsibility
Matrix, Security Control Profile, and Incident Schedule before Provider receives
production access or Customer Data. Use a tailored agreement for health,
financial, payment-card, biometric, children's, government, education, defense,
criminal-justice, export-controlled, safety-critical, or other regulated data or
systems.
1. PARTIES AND MASTER AGREEMENT
Addendum Effective Date: [__/__/____]
Master Agreement: [________________________________]
Order Form or Services: [________________________________]
Customer
Legal Name: [________________________________]
Security Contact: [________________________________]
Privacy Contact: [________________________________]
Incident Contact: [________________________________]
Provider
Legal Name: [________________________________]
Security Contact: [________________________________]
Privacy Contact: [________________________________]
24-Hour Incident Contact: [________________________________]
Each is a "Party"; together, the "Parties."
2. DOCUMENTS AND PRECEDENCE
This Addendum includes each checked schedule:
☐ Schedule A — Data and Service Inventory
☐ Schedule B — Shared Responsibility Matrix
☐ Schedule C — Security Control Profile
☐ Schedule D — Security Evidence and Testing Plan
☐ Schedule E — Subprocessor and Location Register
☐ Schedule F — Incident, Notification, and Cooperation Plan
☐ Schedule G — Recovery, Return, and Destruction Plan
☐ Schedule H — Security Risk, Insurance, and Dispute Schedule
For security, incident, data-protection, and continuity subjects, this Addendum
controls over inconsistent general terms in the Master Agreement. A signed
regulated-data or sector addendum controls for its narrower subject. If two
security documents conflict without a clear precedence rule, the Parties shall
resolve the conflict in writing; phrases such as "more protective" do not by
themselves identify which operational requirement controls.
No changing web page, framework label, questionnaire answer, report, policy,
certification, or third-party term becomes a contractual control unless the
Parties identify its version, scope, and status in a signed schedule.
3. DEFINITIONS
"Customer Data" means the data, content, files, prompts, records,
credentials, and other information identified in Schedule A that Customer or
its users submit to, make available to, or authorize Provider to access through
the Services.
"Customer Environment" means systems, networks, identities, devices, and
configurations Customer controls and identifies in Schedule B.
"Provider Environment" means systems, networks, identities, devices,
facilities, applications, and configurations Provider controls and uses to
deliver the Services or process Customer Data.
"Security Incident" means the event and threshold defined in Schedule F.
"Security Evidence" means the reports, certifications, summaries,
attestations, test results, diagrams, inventories, and records identified in
Schedule D.
"Subprocessor" means a third party Provider authorizes to process Customer
Data for the Services, as identified in Schedule E.
"Vulnerability" means a weakness in an in-scope system, component,
configuration, process, or control that could be used to affect confidentiality,
integrity, or availability, classified through the method in Schedule C.
4. DATA AND SERVICE SCOPE
Schedule A shall identify for each service and data set:
- Service, feature, environment, owner, and business purpose
- Data categories, sources, individuals, sensitivity, and classification
- Customer, Provider, and third-party roles
- Collection, access, use, disclosure, storage, and output
- Hosting and support locations
- Retention, backup, archive, return, and deletion
- Approved users, administrators, and service accounts
- Integrations, APIs, subprocessors, and material dependencies
- Production, test, support, analytics, telemetry, and AI use
Provider shall process Customer Data only for the purposes, Services, and
instructions in Schedule A. Provider may not use Customer Data for advertising,
profiling, model training, product development, benchmarking, or another purpose
unless the schedule expressly permits that use and states the conditions.
Out-of-scope systems and data: [________________________________]
Prohibited data: [________________________________]
Approved temporary support access: [________________________________]
5. SHARED RESPONSIBILITY
Schedule B shall assign ownership for each control and dependency, including:
- Identity source, user provisioning, authentication, and access review
- Customer configuration and secure defaults
- Network connection, endpoint, browser, and device controls
- Data classification, minimization, input quality, and lawful instructions
- Encryption, keys, certificates, secrets, and credential rotation
- Logging, alerting, monitoring, and response
- Application, infrastructure, platform, and third-party patching
- Backup, export, recovery, continuity, and testing
- Integration, API, webhook, and file-transfer security
- Vulnerability disclosure, remediation, and exception approval
- Subprocessor, location, and cross-border controls
- Incident decisions, individual or regulator notice, and communications
An unassigned row is not presumed to belong to Provider. The Parties shall
resolve every material unassigned responsibility before production use.
Each Party shall promptly notify the other when a dependency it controls is
missing, misconfigured, compromised, or likely to prevent the other Party's
performance.
6. SECURITY GOVERNANCE AND CONTROL PROFILE
6.1 Security Program
Provider shall maintain a documented security program appropriate to the
Services, Customer Data, threat model, and controls selected in Schedule C.
Security executive: [________________________________]
Control framework, version, and scope: [________________________________]
Risk-assessment method and cadence: [________________________________]
Policy review cadence: [________________________________]
Exception approval and expiration: [________________________________]
6.2 Control Status
Each Schedule C control shall be marked:
☐ Required and implemented
☐ Required by agreed date [__/__/____]
☐ Customer responsibility
☐ Shared responsibility
☐ Compensating control approved
☐ Not applicable with rationale
Provider shall not represent that a framework, certification, or report covers a
service, location, period, system, or control outside its documented scope.
6.3 Material Change
Provider shall give the notice in Schedule C before a material change to the
security architecture, control ownership, hosting location, identity model,
encryption, key custody, logging, recovery, material component, or subprocessor
that could materially change Customer's risk.
Emergency-change notice: [________________________________]
Customer objection and resolution: [________________________________]
7. IDENTITY AND ACCESS MANAGEMENT
Schedule C shall state requirements for:
☐ Unique user and administrator identities
☐ Multi-factor authentication by access type
☐ Least privilege and role-based access
☐ Separate privileged and ordinary accounts
☐ Privileged-access approval, recording, and time limits
☐ Service-account inventory and ownership
☐ Joiner, mover, and leaver timing
☐ Periodic access certification
☐ Session, lockout, and reauthentication controls
☐ Emergency and break-glass access
☐ Customer federation or single sign-on
Administrative-access method: [________________________________]
Support-access approval and monitoring: [________________________________]
Access-review frequency and evidence: [________________________________]
Password length, rotation, complexity, and lockout settings shall follow the
selected authentication design and current threat assessment in Schedule C;
this form does not impose one static rule on every identity type.
8. CRYPTOGRAPHY, KEYS, AND SECRETS
Schedule C shall identify:
- Data and connections requiring encryption
- Protocols, algorithms, modes, and minimum strengths
- Certificate issuance, inventory, expiration, and revocation
- Key generation, storage, access, rotation, backup, recovery, and destruction
- Provider-managed, Customer-managed, and third-party key custody
- Secrets storage, scanning, access, and rotation
- Separation of encrypted data from keys and recovery material
Data in transit profile: [________________________________]
Data at rest profile: [________________________________]
Key-management service and custodian: [________________________________]
Customer-held key or bring-your-own-key terms: [_______________________]
Provider shall notify Customer of a known compromise of an in-scope key,
certificate, secret, or recovery mechanism under Schedule F.
9. INFRASTRUCTURE, NETWORK, AND CLOUD SECURITY
Schedule C shall state applicable controls for:
☐ Asset and cloud-resource inventory
☐ Secure configuration baseline and drift detection
☐ Network segmentation and tenant isolation
☐ Firewall, security-group, and access-list governance
☐ Administrative network and remote access
☐ Endpoint protection and device management
☐ Malware and ransomware protections
☐ Denial-of-service protections
☐ Cloud control-plane monitoring
☐ Container, orchestration, and image security
☐ Infrastructure-as-code review and scanning
☐ Production and nonproduction separation
Hosting architecture reference: [________________________________]
Tenant-isolation evidence: [________________________________]
Customer connectivity dependencies: [________________________________]
10. SECURE DEVELOPMENT AND CHANGE MANAGEMENT
For software used to deliver the Services, Schedule C shall address:
☐ Documented development lifecycle
☐ Security requirements and threat modeling
☐ Peer review and protected branches
☐ Static, dynamic, dependency, and secret scanning
☐ Build-pipeline and artifact integrity
☐ Test-data controls
☐ Release approval and rollback
☐ Dependency inventory and update process
☐ Third-party and open-source component review
☐ Vulnerability disclosure and intake
☐ Emergency change process
Production change notice: [________________________________]
Material feature removal or degradation: [____________________________]
Software component inventory or equivalent evidence: [________________]
11. VULNERABILITY MANAGEMENT
11.1 Discovery
Scanning scope and cadence: [________________________________]
Penetration-testing scope and cadence: [________________________________]
External reports or disclosure channel: [________________________________]
11.2 Classification
Vulnerabilities shall be prioritized using the method in Schedule C, which may
consider technical severity, exploitability, exposure, data sensitivity,
service criticality, active exploitation, reachability, compensating controls,
and business impact.
11.3 Remediation Targets
| Priority | Target | Start Event | Exception Approver | Customer Notice |
|---|---|---|---|---|
| Critical | [____] | [____] | [____] | [____] |
| High | [____] | [____] | [____] | [____] |
| Medium | [____] | [____] | [____] | [____] |
| Low | [____] | [____] | [____] | [____] |
An exception shall state scope, rationale, compensating control, owner,
expiration, and review date. Provider shall notify Customer of an overdue
material Vulnerability affecting the Services under the threshold in Schedule C.
12. LOGGING, MONITORING, AND DETECTION
Schedule C shall identify:
- Logged systems, events, identities, administrative actions, and data access
- Log contents, time synchronization, integrity, access, and retention
- Alert sources, thresholds, triage, escalation, and coverage hours
- Security operations responsibilities and contact paths
- Customer access to logs, events, reports, or integrations
- Detection testing and tuning cadence
Security-log retention: [________________________________]
Administrative-action logging: [________________________________]
Customer event feed or export: [________________________________]
Monitoring coverage: [________________________________]
Provider shall not include sensitive content in logs beyond the documented need
and shall protect logs according to their data classification.
13. DATA HANDLING AND LIFECYCLE
Schedule A and C shall identify controls for:
☐ Data minimization and purpose limitation
☐ Production-data restrictions in test and development
☐ Upload, download, export, and bulk-access controls
☐ Data segregation and tenant separation
☐ Backup and archive handling
☐ Removable media and printing
☐ Data loss prevention
☐ Retention and legal-hold interaction
☐ Return, deletion, and destruction verification
Primary retention: [________________________________]
Backup retention: [________________________________]
Support copy and diagnostic data: [________________________________]
Deletion method and evidence: [________________________________]
The selected destruction standard shall be identified by name, version, media
type, and verification method in Schedule G; a superseded version is not
incorporated merely because it appeared in a prior template.
14. BACKUP, RECOVERY, AND CONTINUITY
Schedule G shall identify:
☐ Backup frequency and protected scope
☐ Backup encryption and access
☐ Geographic or logical separation
☐ Restore testing and evidence
☐ Recovery time objective
☐ Recovery point objective
☐ High availability and failover
☐ Disaster declaration and communications
☐ Dependency and concentration risks
☐ Business continuity exercises
| Service | RTO | RPO | Test Frequency | Last Evidence Date |
|---|---|---|---|---|
| [________________] | [____] | [____] | [____] | [__/__/____] |
Provider shall report a failed recovery test that materially affects the agreed
targets, together with remediation and retest timing.
15. PERSONNEL AND PHYSICAL SECURITY
Schedule C shall identify applicable controls for:
☐ Confidentiality commitments
☐ Role-appropriate security training
☐ Specialized administrator, developer, and incident training
☐ Background screening by role and location after legal review
☐ Disciplinary and termination procedures
☐ Remote-work controls
☐ Facility access approval and review
☐ Visitor management
☐ Environmental and power protections
☐ Media storage and disposal
Provider shall not promise a fixed type or lookback period of personnel screening
without confirming that it is appropriate and permitted for each role and work
location.
16. SUBPROCESSORS AND LOCATIONS
Schedule E shall list each Subprocessor's legal name, service, data, purpose,
hosting and support locations, access type, contract status, and material
dependency.
16.1 Existing Subprocessors
Customer approves only the entities listed in the signed Schedule E.
16.2 Change Procedure
Prior notice: [____] days
Emergency notice: [________________________________]
Customer objection grounds and period: [________________________________]
Resolution and termination option: [________________________________]
16.3 Flow-Down and Oversight
Provider shall impose written obligations appropriate to the Subprocessor's
service, data, access, and risk, and shall maintain the assessment and monitoring
evidence selected in Schedule D. Provider's responsibility for a Subprocessor is
stated in Schedule H.
Provider shall not move Customer Data or material support access to a location
outside Schedule E without following the change procedure.
17. SECURITY EVIDENCE, ASSESSMENT, AND AUDIT
17.1 Routine Evidence
Schedule D shall select and scope the evidence Provider supplies:
☐ Independent controls report
☐ Security certification
☐ Penetration-test executive summary
☐ Vulnerability-management summary
☐ Business-continuity and restore-test summary
☐ Security questionnaire
☐ Architecture or data-flow diagram
☐ Insurance evidence
☐ Remediation status
For each item, state period, system and service scope, confidentiality, reliance,
redactions, frequency, and delivery date.
17.2 Customer Assessment
Customer may conduct the assessment selected in Schedule D subject to notice,
frequency, scope, confidentiality, safety, third-party restrictions, tenant
protection, cost, and noninterference conditions.
Ordinary frequency: [________________________________]
Additional assessment triggers: [________________________________]
On-site or technical testing permission: [________________________________]
No penetration test, scan, exploit attempt, social engineering, or facility
access is authorized without separate written rules of engagement.
17.3 Findings
Provider shall respond to an in-scope material finding with owner, severity,
remediation, compensating control, target date, and evidence. Disputed findings
follow the escalation in Schedule H.
18. SECURITY INCIDENT MANAGEMENT
18.1 Incident Definition and Levels
Schedule F shall distinguish:
- Security event not requiring Customer notice
- Suspected Security Incident requiring investigation notice
- Confirmed Security Incident affecting Customer Data or Services
- Material availability or integrity event
- Event requiring transaction-specific legal notification analysis
18.2 Provider Notice
Knowledge threshold: [________________________________]
Initial notice period: [________________________________]
Notice method and 24-hour recipient: [________________________________]
Update cadence: [________________________________]
Provider's notice shall include facts then known, affected services, systems and
data, detection and occurrence dates if known, containment, evidence status,
contact, and next update. Provider shall not delay the initial notice solely
because investigation is incomplete.
18.3 Response and Cooperation
Schedule F shall assign:
- Incident command and technical containment
- Forensic investigator selection and privilege decisions
- Evidence preservation and chain of custody
- Scope, affected-individual, and harm analysis
- Restoration and secure reactivation
- Insurer, law enforcement, regulator, and third-party contact
- Individual, customer, partner, or public notice decisions
- Notice drafting, translation, mailing, call center, and monitoring services
- Cost allocation and reimbursement procedure
- Root-cause report, remediation, and lessons learned
No fixed statutory notice deadline, content, recipient, or threshold is imported
into every incident. Counsel shall determine applicable duties from the actual
data, roles, individuals, locations, contracts, and event facts.
18.4 Communications
Neither Party may identify the other in public incident communications without
approval, except when legally required. The Parties shall coordinate accurate,
timely statements without obstructing a required notice or urgent safety step.
19. RETURN, DELETION, AND EXIT
Schedule G shall state:
Customer export format: [________________________________]
Export availability and timing: [________________________________]
Transition access: [________________________________]
Primary-system deletion deadline: [________________________________]
Backup expiration or deletion: [________________________________]
Subprocessor deletion: [________________________________]
Legal retention exceptions: [________________________________]
Deletion or destruction evidence: [________________________________]
Retained data remains subject to the applicable controls and may be used only
for the documented retention purpose. Provider shall delete it when the approved
retention condition ends.
20. REGULATED USE AND COMPLIANCE MAPPING
Schedule H shall identify transaction-specific privacy, breach, security,
records, sector, export, sanctions, accessibility, public-sector, employment,
and other requirements and map each obligation to a Party, data set, system,
location, control, and evidence source.
Regulated data or use: [________________________________]
Applicable addenda: [________________________________]
Customer legal instructions: [________________________________]
Provider compliance evidence: [________________________________]
A contractual term such as "Personal Information," "Confidential," or
"High-Risk" does not by itself establish a statutory category or assign a legal
role. The legal mapping must be completed separately.
21. AI, AUTOMATION, AND MATERIAL TECHNOLOGY CHANGE
If the Services include AI or automated decision functionality, Schedule A or a
separate AI addendum shall identify models and providers, versions, inputs,
outputs, approved uses, affected persons, decision role, human oversight, data
and training use, evaluation, limitations, monitoring, incidents, changes, and
disable controls.
Provider shall notify Customer before enabling a material AI function that uses
Customer Data or changes an approved decision role, unless the signed schedule
already authorizes that change.
AI features approved: [________________________________]
Customer Data permitted for model improvement: [_______________________]
Material technology change procedure: [________________________________]
22. INSURANCE, INDEMNITY, AND LIABILITY
22.1 Insurance
Schedule H shall select coverage, limits, retention, period, insurer standards,
evidence, notice, additional-insured treatment, and tail requirements based on
the Services and risk.
| Coverage | Limit | Retention | Period | Evidence |
|---|---|---|---|---|
| Cyber / privacy | $[____] | $[____] | [____] | [____] |
| Technology errors and omissions | $[____] | $[____] | [____] | [____] |
| Commercial general liability | $[____] | $[____] | [____] | [____] |
| Crime / fidelity | $[____] | $[____] | [____] | [____] |
Insurance does not expand or reduce contractual liability unless Schedule H
expressly says so.
22.2 Security Indemnity
☐ No separate security indemnity
☐ Provider security indemnity in Schedule H
☐ Mutual data/security indemnities in Schedule H
Any indemnity must identify covered third-party claims, required connection to
conduct, exclusions, defense control, counsel, notice, cooperation, settlement,
cost categories, and relationship to liability limits.
22.3 Liability Allocation
☐ Master Agreement limits apply unchanged
☐ Security sublimit or supercap: [________________________________]
☐ Defined claims outside limits: [________________________________]
☐ Defined excluded damage categories and exceptions: [___________________]
The Parties shall address foreseeable security losses, including investigation,
restoration, notification, call center, monitoring, regulator response,
substitute service, data reconstruction, and customer credits.
23. TERM, SUSPENSION, AND SURVIVAL
This Addendum begins on the Addendum Effective Date and continues while Provider
processes Customer Data or has an uncompleted security, incident, return,
deletion, or remediation obligation.
Provider may suspend Services for a security reason only under the grounds,
scope, notice, emergency, restoration, and data-access rules in Schedule H.
Suspension shall be limited to the affected access where reasonably practicable.
Data use restrictions, confidentiality, incident cooperation, return, deletion,
evidence protection, liability allocation, dispute provisions, and terms
intended by their nature to continue survive to the extent stated.
24. DISPUTES AND GENERAL TERMS
24.1 Governing Terms
The Master Agreement's governing-law, forum, notice, assignment, amendment,
waiver, severability, counterpart, and dispute provisions apply unless Schedule
H expressly states an approved security-specific override.
24.2 Time-Sensitive Relief
A Party may request time-sensitive relief subject to the law, procedure,
jurisdiction, security, and bond or undertaking rules that actually apply. This
Addendum does not promise automatic injunctive relief or waive a required bond.
24.3 Jury Waiver and Arbitration
☐ Master Agreement applies unchanged
☐ No contractual jury waiver or arbitration for this Addendum
☐ Separate counsel-approved security dispute addendum attached
24.4 Fees and Costs
☐ Master Agreement applies unchanged
☐ Each Party bears its own fees and costs except as otherwise required
☐ Defined prevailing-party provision in Schedule H
24.5 Electronic Execution
The Parties may sign this Addendum using the method selected below after
transaction-specific execution review:
☐ Wet ink
☐ Approved electronic-signature platform: [________________________________]
☐ Other authenticated method: [________________________________]
25. SIGNATURES
Each signatory represents that the signatory is authorized to sign for the
identified Party.
Customer
Legal Name: [________________________________]
By: [________________________________]
Printed Name: [________________________________]
Title: [________________________________]
Date: [__/__/____]
Provider
Legal Name: [________________________________]
By: [________________________________]
Printed Name: [________________________________]
Title: [________________________________]
Date: [__/__/____]
SCHEDULE A — DATA AND SERVICE INVENTORY
| Service / Feature | Environment | Data | Purpose | Roles | Locations | Retention |
|---|---|---|---|---|---|---|
| [____] | [____] | [____] | [____] | [____] | [____] | [____] |
Support and Administrative Access: [________________________________]
Telemetry, Analytics, and AI Use: [________________________________]
Prohibited Data and Uses: [________________________________]
SCHEDULE B — SHARED RESPONSIBILITY MATRIX
| Control / Dependency | Customer | Provider | Shared Steps | Evidence |
|---|---|---|---|---|
| Identity source | ☐ | ☐ | [____] | [____] |
| User provisioning | ☐ | ☐ | [____] | [____] |
| Authentication | ☐ | ☐ | [____] | [____] |
| Customer configuration | ☐ | ☐ | [____] | [____] |
| Encryption and keys | ☐ | ☐ | [____] | [____] |
| Logging and alerting | ☐ | ☐ | [____] | [____] |
| Vulnerability remediation | ☐ | ☐ | [____] | [____] |
| Backup and recovery | ☐ | ☐ | [____] | [____] |
| Incident response | ☐ | ☐ | [____] | [____] |
| Notice decisions | ☐ | ☐ | [____] | [____] |
SCHEDULE C — SECURITY CONTROL PROFILE
Framework, Version, and Scope: [________________________________]
Control Baseline and Exceptions: [________________________________]
Identity and Access: [________________________________]
Cryptography and Keys: [________________________________]
Infrastructure and Network: [________________________________]
Secure Development: [________________________________]
Vulnerability Targets: [________________________________]
Logging and Detection: [________________________________]
Data Handling: [________________________________]
Personnel and Physical Security: [________________________________]
Material Change Notice: [________________________________]
SCHEDULE D — SECURITY EVIDENCE AND TESTING PLAN
| Evidence | Scope / Period | Delivery | Confidentiality / Reliance |
|---|---|---|---|
| [____] | [____] | [____] | [____] |
Customer Assessment: [________________________________]
Additional Assessment Triggers: [________________________________]
Finding and Remediation Process: [________________________________]
Technical Testing Rules of Engagement: [______________________________]
SCHEDULE E — SUBPROCESSOR AND LOCATION REGISTER
| Legal Name | Service | Data / Access | Hosting | Support | Contract Status |
|---|---|---|---|---|---|
| [____] | [____] | [____] | [____] | [____] | [____] |
Change Notice: [________________________________]
Objection and Resolution: [________________________________]
Assessment and Flow-Down Evidence: [________________________________]
SCHEDULE F — INCIDENT, NOTIFICATION, AND COOPERATION PLAN
Security Incident Definition: [________________________________]
Knowledge Threshold and Initial Notice: [____________________________]
24-Hour Contacts and Method: [________________________________]
Update Cadence: [________________________________]
Incident Command and Forensics: [________________________________]
Notice Decision and Communications: [________________________________]
Cost Allocation: [________________________________]
Root Cause, Remediation, and Final Report: [___________________________]
SCHEDULE G — RECOVERY, RETURN, AND DESTRUCTION PLAN
Backup Scope and Frequency: [________________________________]
RTO / RPO: [________________________________]
Restore and Continuity Testing: [________________________________]
Customer Export: [________________________________]
Primary and Backup Deletion: [________________________________]
Destruction Standard, Version, and Media Scope: [_____________________]
Subprocessor Deletion and Evidence: [________________________________]
SCHEDULE H — SECURITY RISK, INSURANCE, AND DISPUTE SCHEDULE
Regulated-Use Mapping: [________________________________]
Insurance: [________________________________]
Indemnity: [________________________________]
Liability Limit and Damage Categories: [______________________________]
Suspension and Termination: [________________________________]
Security-Specific Governing / Forum Override: [_______________________]
Jury Waiver or Arbitration Addendum: [________________________________]
Fees and Costs: [________________________________]
End of template.
About this template
- Last updated
- August 20, 2026
- Citations checked
- August 20, 2026
- Jurisdiction
- Alaska
- Category
- Contracts & Agreements
A contract is a written record of what two or more parties agreed to and what happens if someone does not follow through. Clear language, defined terms, and clean signature blocks keep disputes small and enforceable. The most common mistakes in contracts come from vague promises, missing details about timing or payment, and skipping standard protective clauses like governing law and dispute resolution.
Not legal advice
This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Checked against the law it cites
A reviewer verified this template's legal citations against the official source on August 20, 2026.
Draft your Security Addendum (Enterprise SaaS) in the editor
Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.