Security Addendum (Enterprise SaaS)
SECURITY ADDENDUM (ENTERPRISE SAAS)
Alabama Jurisdictional Version
TABLE OF CONTENTS
- Scope and Order of Precedence
- Security Program
- Access Controls and Authentication
- Encryption
- Network and Infrastructure Security
- Application Security and SDLC
- Vulnerability Management
- Logging and Monitoring
- Business Continuity and Disaster Recovery
- Data Segregation and Residency
- Penetration Testing and Assessments
- Incident Response and Notification
- Audit and Compliance Reports
- Third-Party Subprocessors
- Physical Security
- Personnel Security and Training
- Data Return and Deletion
- Changes to Security Controls
- Alabama-Specific Data Protection Requirements
- Governing Law and Dispute Resolution
1. SCOPE AND ORDER OF PRECEDENCE
- Applies to the Services under the [SaaS Agreement name/date].
- If conflict with the SaaS Agreement/DPA on security matters, this Addendum governs; otherwise, SaaS Agreement controls.
2. SECURITY PROGRAM
- Provider maintains a written information security program with administrative, technical, and physical safeguards appropriate to risk, aligned to [ISO 27001/SOC 2/other].
- To the extent Provider is a covered entity or third-party agent handling sensitive personally identifying information as those terms are defined by Ala. Code § 8-38-2, Provider shall implement and maintain the reasonable security measures required by § 8-38-3.
- Contractual safeguards for Customer Data that falls outside the Act's definition remain governed by this Addendum and other applicable law.
3. ACCESS CONTROLS AND AUTHENTICATION
- Role-based access; least privilege; MFA for administrative access; strong password/secret policies; session management; timely deprovisioning.
4. ENCRYPTION
- In transit: TLS [1.2/1.3] or better; at rest: industry-standard encryption for Customer Data stores.
- Key management: [KMS/HSM], separation of duties, rotation policies.
5. NETWORK AND INFRASTRUCTURE SECURITY
- Segmentation of environments (prod/non-prod); firewalls/security groups; DDoS protections; hardened images; configuration management and baselines.
6. APPLICATION SECURITY AND SDLC
- Secure development lifecycle with code review, dependency scanning, SAST/DAST for relevant components; change management with approvals and rollback plans.
7. VULNERABILITY MANAGEMENT
- Regular scanning; prioritization/remediation targets:
- Critical: [X] hours/days; High: [Y] days; Medium: [Z] days; Low: [define].
- Patch management process; emergency patching for exploited vulnerabilities.
8. LOGGING AND MONITORING
- Centralized logging for auth, access, admin actions, and security events; time-synchronized; retention [X] days/months; alerting for anomalous events.
9. BUSINESS CONTINUITY AND DISASTER RECOVERY
- Documented BC/DR plan; tested [annually/semi-annually]; RPO [X hours], RTO [Y hours]; backups encrypted and tested for restoration.
10. DATA SEGREGATION AND RESIDENCY
- Logical/tenant isolation; data residency options [Regions] if offered; no relocation without notice and updated transfer mechanisms.
11. PENETRATION TESTING AND ASSESSMENTS
- Independent penetration tests [annually/semi-annually]; summary reports available under NDA; remediation tracked to closure.
- Customer-sourced testing requires prior written approval and coordinated scope.
12. INCIDENT RESPONSE AND NOTIFICATION
- Incident response plan with roles, runbooks, and communications.
- Notification to Customer without undue delay and within [X] hours of confirming a Security Incident affecting Customer Data; include nature, scope, mitigations, and recommended actions.
- Alabama role gate: If Provider is a third-party agent under Ala. Code § 8-38-2(7), Provider shall notify the applicable covered entity as expeditiously as possible and without unreasonable delay, but no later than 10 days after determining that the breach occurred or having reason to believe it occurred, and shall provide the information and cooperation required by § 8-38-8.
- If Provider is the covered entity responsible for statutory notice, Provider shall conduct the investigation required by § 8-38-4 and, when § 8-38-5's acquisition and substantial-harm conditions are met, provide individual notice as expeditiously as possible and without unreasonable delay and within the statute's 45-day outside period. Attorney General notice under § 8-38-6 applies when the number of individuals Provider is required to notify exceeds 1,000.
- The parties shall identify in the incident register which party owns or licenses each affected data set, which party is the covered entity, and which party is a third-party agent. A contractual Customer-notice deadline does not transfer statutory responsibility by label alone.
- Post-incident report for material incidents within [Y] business days.
13. AUDIT AND COMPLIANCE REPORTS
- Provide current SOC 2 / ISO 27001 certificate and summary upon request; significant exceptions disclosed with remediation plans.
- Onsite/customer audits: [once per year] with reasonable notice; subject to confidentiality and limited to security controls; time/materials fees if onsite.
14. THIRD-PARTY SUBPROCESSORS
- Subprocessors must meet equivalent security standards; list available at [URL/Annex]; notice of new subprocessors with [X] days to object on reasonable grounds; Provider remains liable.
- Each subprocessor that is a third-party agent handling sensitive personally identifying information shall be contractually required to maintain appropriate safeguards and to provide the role-specific notice and cooperation required by Ala. Code §§ 8-38-3 and 8-38-8.
15. PHYSICAL SECURITY
- Data centers with industry-standard controls: access badges/biometrics, CCTV, visitor logging, environmental controls, and redundant power/cooling.
16. PERSONNEL SECURITY AND TRAINING
- Background checks where lawful for personnel with Customer Data access; confidentiality agreements; security and privacy training at onboarding and [annual] refreshers.
17. DATA RETURN AND DELETION
- Upon termination/expiry, Customer Data returned or deleted per Agreement/DPA within [X] days; secure deletion methods; backups aged out on standard cycles unless legal hold applies.
- Data destruction shall include notification upon completion and reasonable documentation of destruction method used.
18. CHANGES TO SECURITY CONTROLS
- Material reductions not permitted without Customer consent; non-material updates allowed to improve or maintain security posture.
- Notice of material changes to contact [security contact].
19. ALABAMA-SPECIFIC DATA PROTECTION REQUIREMENTS
19.1 Alabama Data Breach Notification Act Compliance
- The parties shall apply the Alabama Data Breach Notification Act according to each party's actual statutory role and the data involved, including:
- Implementing and maintaining reasonable security measures for sensitive personally identifying information under § 8-38-3;
- Conducting the good-faith, prompt investigation required of a covered entity by § 8-38-4;
- Requiring a third-party agent to notify the covered entity within § 8-38-8's 10-day outside period and to cooperate with statutory notices;
- Requiring a covered entity to provide individual notice only when § 8-38-5's acquisition and substantial-harm conditions are met, within the applicable 45-day outside period; and
- Notifying the Alabama Attorney General under § 8-38-6 when the number of individuals the covered entity is required to notify exceeds 1,000.
19.2 Sensitive Personally Identifying Information Definition
- "Sensitive personally identifying information" under Alabama law includes an Alabama resident's first name or first initial and last name, in combination with one or more of the following:
- Non-truncated Social Security number or tax identification number;
- Non-truncated driver's license number, state-issued ID number, passport number, military ID number, or other unique ID number issued on a government document used to verify identity;
- Financial account number, including bank account number, credit card number, or debit card number, combined with any security code, access code, password, expiration date, or PIN needed to access the account or conduct a transaction;
- Medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional;
- Health insurance policy number or subscriber identification number combined with unique identifier used by insurer;
- User name or email address combined with password or security question and answer permitting access to an online account.
19.3 Alabama Trade Secret Protection
- Provider acknowledges that Customer's Confidential Information may include trade secrets as defined under the Alabama Trade Secrets Act (Ala. Code Section 8-27-1 et seq.) and the federal Defend Trade Secrets Act (18 U.S.C. section 1836 et seq.), and shall protect such information accordingly.
19.4 Alabama E-Signatures
- Electronic signatures under this Addendum shall be valid and enforceable pursuant to the Alabama Uniform Electronic Transactions Act (Ala. Code Section 8-1A-1 et seq.) and the federal Electronic Signatures in Global and National Commerce Act (E-SIGN Act).
20. GOVERNING LAW AND DISPUTE RESOLUTION
20.1 Governing Law
This Addendum and any dispute arising out of or relating hereto shall be governed by and construed in accordance with the laws of the State of Alabama, without regard to its conflict of laws rules.
20.2 Forum Selection
Subject to any arbitration provisions in the Master Agreement, the Parties consent to the exclusive jurisdiction of the state and federal courts located in Montgomery County / Jefferson County, Alabama, for any litigation arising out of or relating to this Addendum, and waive any objection to venue or forum non conveniens.
20.3 Jury Trial Waiver
EACH PARTY HEREBY KNOWINGLY, VOLUNTARILY, AND IRREVOCABLY WAIVES ITS RIGHT TO A TRIAL BY JURY IN ANY ACTION OR PROCEEDING ARISING OUT OF OR RELATING TO THIS ADDENDUM, TO THE EXTENT SUCH WAIVER IS ENFORCEABLE UNDER ALABAMA LAW.
20.4 Injunctive Relief
Each Party acknowledges that a breach of the security obligations herein would cause irreparable harm for which monetary damages are an inadequate remedy. Accordingly, in the event of any such breach, the non-breaching Party may seek injunctive relief in addition to any other remedy available at law or equity, without posting bond or other security.
20.5 Late Payment Interest
Late payments under this Addendum shall accrue interest at the written annual rate specified in the Master Agreement, not exceeding the maximum permitted for the transaction under applicable law. If no rate is specified, Ala. Code § 8-8-1 generally supplies a 6% annual rate; the same section generally caps a written rate at 8%, except as otherwise provided by law.
CHECKLIST FOR EXECUTION
☐ All [PLACEHOLDER] values have been completed
☐ Master SaaS Agreement referenced in Section 1
☐ Security program framework identified (Section 2)
☐ Incident notification timeline specified (Section 12)
☐ Data residency requirements confirmed (Section 10)
☐ Document reviewed by Alabama-licensed legal counsel
☐ Both Parties have signed and dated
Sources and References
About this template
- Last updated
- August 2, 2026
- Jurisdiction
- Alabama
- Category
- Contracts & Agreements
Legal authority
- Ala. Code §§ 8-38-2 through 8-38-10 (defined data, reasonable security, investigation, role-specific notice, enforcement, and disposal)
- Ala. Code § 8-8-1 (general maximum interest rates)
A contract is a written record of what two or more parties agreed to and what happens if someone does not follow through. Clear language, defined terms, and clean signature blocks keep disputes small and enforceable. The most common mistakes in contracts come from vague promises, missing details about timing or payment, and skipping standard protective clauses like governing law and dispute resolution.
Not legal advice
This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Checked against the law it cites
The statutes this template relies on are listed under Legal authority.
Draft your Security Addendum (Enterprise SaaS) in the editor
Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.