8 questions from the RFI stage, free
These come from the module as sold. The workbook adds follow-ups, a response format, a weight and a score column to each.
1. Describe how your standard agreement allocates ownership of customer-provided input data, including any licenses you require to that data and the scope and duration of those licenses.
Why it matters. Customer input data (prompts, documents, embeddings) can be the buyer's confidential or copyrighted material. Vendor licenses that are broader than necessary, perpetual, or sublicensable create unacceptable IP and confidentiality exposure. This question surfaces the baseline allocation before negotiation.
- Customer retains ownership of all input data.
- Vendor license is limited to providing the service and is narrowly scoped.
- License terminates upon contract expiration, with clear data deletion commitments.
- Vendor claims broad or perpetual rights to customer input data.
- License survives contract termination without a compelling justification.
- Sublicensable to unnamed or a broad category of third parties.
2. Describe the scope of your general third-party IP infringement indemnification, including covered IP types (e.g., patent, copyright, trademark, trade secret) and any geographic limitations.
Why it matters. General IP indemnification is the buyer's primary protection against third-party infringement claims arising from use of the vendor's service. Gaps in covered IP types or geographic scope can leave the buyer exposed to litigation in jurisdictions where they operate.
- Indemnity covers patent, copyright, trademark, and trade secret claims.
- Coverage is worldwide or at least covers all jurisdictions where the customer operates.
- Indemnity explicitly covers costs of defense, settlement, and final judgments.
- Excludes patent infringement claims.
- Limited to the vendor's home jurisdiction only.
- Requires the customer to indemnify the vendor for the customer's ordinary use of the service.
3. State whether customer prompts, inputs, outputs, or any derived data are used to train or improve any model (your own, an upstream provider's, or a third party's) and identify the default setting for enterprise contracts.
Why it matters. Use of customer data for model training is a major confidentiality and IP risk. Buyers must know if their confidential data could be incorporated into model weights, and what the vendor's default posture is. 'Opt-out by default' is materially different and far riskier than a 'never used by default' commitment for enterprise customers.
- Confirms customer data is never used for training by default for enterprise customers.
- The no-training default applies to the vendor, all upstream providers, and any other third parties.
- The commitment is documented in the MSA, not a less-binding privacy policy or ToS.
- Training on customer data is opt-out only, especially with a high-friction process.
- The no-training setting can be changed unilaterally by the vendor.
- Makes a semantic distinction between 'training' and 'improving' or 'fine-tuning' to obscure data use.
4. State the governing law and exclusive venue proposed in your standard agreement, and confirm whether you will negotiate these terms for enterprise customers.
Why it matters. Governing law and venue determine the practical cost and feasibility of enforcing contractual rights. A unilateral choice of the vendor's home jurisdiction can make disputes economically impractical for the buyer to pursue.
- Confirms willingness to negotiate governing law and venue for enterprise contracts.
- Proposes a recognized neutral jurisdiction (e.g., New York, England & Wales).
- Supports floating jurisdiction based on the customer's location.
- Governing law and venue are non-negotiable.
- Proposes a foreign domicile with a less-established or less-predictable rule of law.
- Exclusive venue clause has no exception for seeking injunctive relief in other jurisdictions.
5. State who owns the output generated by your service in response to customer inputs, including any retained rights or licenses the vendor or upstream model providers claim in that output.
Why it matters. Default SaaS templates can leave output rights ambiguous, and upstream model providers may impose their own terms that flow down. Buyers need absolute clarity on whether they can use, modify, and commercialize outputs without restriction.
- Customer is assigned full ownership of or granted an unrestricted, worldwide, perpetual license to outputs.
- Explicitly states which upstream model provider terms flow through to the customer.
- Vendor retains no rights to output content beyond transient use for service delivery.
- Output ownership is assigned to the vendor by default.
- Ambiguity or silence on the flow-down terms from upstream model providers.
- Vendor retains rights to use customer outputs for marketing, benchmarking, or any other purpose.
6. State whether your IP indemnification expressly covers third-party claims that AI-generated outputs infringe copyright, including claims based on the provenance of training data.
Why it matters. Generic SaaS IP indemnities can carve out user-generated content, which vendors may argue includes AI outputs. This leaves buyers exposed to lawsuits over reproduced training data. Several major providers offer specific AI-output indemnities (e.g., Microsoft's Customer Copyright Commitment, Google Cloud's generative AI indemnification, OpenAI's Copyright Shield).
- Explicitly confirms that outputs are covered by the IP indemnity.
- No carve-out for claims based on training data provenance.
- Coverage applies when the customer uses the service and its outputs as delivered, without material modification.
- AI-generated outputs are explicitly excluded from IP indemnity.
- Silence on output coverage, treating it as 'customer content' for which the customer is responsible.
- Coverage is conditioned on undefined 'appropriate use' policies.
7. Describe any non-training secondary uses of customer data (e.g., abuse detection, safety classifier training, evaluation, benchmarking, debugging), including the retention periods and access controls for each use.
Why it matters. Vendors may disclaim data use for 'training' while retaining broad rights for 'safety,' 'evaluation,' or 'product improvement' that amount to similar data exposure. Buyers must understand the full set of secondary uses to evaluate the true confidentiality risk.
- Provides an itemized list of all secondary uses with specific, narrow purposes.
- Specifies bounded data retention periods for each secondary use.
- Human-review access is minimized, logged, and subject to strict controls.
- Uses a broad, catch-all 'to improve our services' clause.
- Unbounded retention periods for data flagged for safety or abuse review.
- Human review of customer data occurs without disclosure or meaningful controls.
8. Describe your dispute resolution mechanism, including any required pre-litigation steps, mandatory arbitration provisions, and the seat and rules of any arbitration.
Why it matters. The dispute resolution process shapes both the expected cost of a dispute and the realistic ceiling of recovery. Mandatory arbitration with restrictive rules or an inconvenient seat can effectively waive material remedies or make them prohibitively expensive to pursue.
- A tiered escalation process (e.g., executive review before formal proceedings).
- A choice between arbitration and court litigation, or arbitration is optional.
- Arbitration is administered by a recognized body (e.g., ICC, AAA, JAMS, LCIA) under standard rules.
- Mandatory, binding arbitration in a vendor-controlled or inconvenient forum.
- A class-action waiver is coupled with a low individual liability cap.
- Arbitration is required to be confidential, preventing discovery of patterns of misconduct.
What the audit changed
A language model drafted these questions and a second model critiqued them. Three audit passes followed and made 142 changes. Three examples:
Wrong or outdated citation
Draft: Exclusions are narrow, specific, and standard (e.g., based on the Berne Convention).
Now: Exclusions are narrow and specific, and each one is listed.
The Berne Convention is a copyright treaty between states. It says nothing about contractual indemnity exclusions.
Wrong or outdated citation
Draft: The cap on customer indemnity is at parity with (or greater than) the vendor's general liability cap.
Now: The cap on customer indemnity is no greater than the vendor's corresponding cap.
The signal was inverted: a customer indemnity cap greater than the vendor's favors the vendor, not the buyer.
Wrong or outdated citation
Draft: Claims the customer can be an additional insured on a professional liability or E&O policy without an endorsement to show it.
Now: Claims the customer can be an additional insured on a professional liability, E&O or cyber policy without an endorsement to show it.
Cyber policies added; see the why_it_matters edit (https://especialty.com/industry-insights/non-affiliated-additional-insureds-not-recommended/).