All prompts
Analyze/Featured
Review a vendor MSA top-to-bottom
Scores the agreement, gives you five redline priorities with opening and fallback language for each, audits the data and security terms, and writes the one-pager the business owner will actually read.
Your prompt
2
Pressure-test it
3
Go deeper
Before you run it
What to gather first
Watch for
What comes back
See an example of what you’ll get
*(After you answer the four questions: worst case is a retailer-feed data incident at $300K-$2M, one alternative vendor at four months' migration, procurement has already agreed to the fee schedule, security has a clean SOC 2 but no pen test.)*
Score: YELLOW. Four substantive redlines plus a missing DPA. Closeable in two rounds.
Top five redline priorities
1. § 10.2: Limitation of liability.
> "In no event shall Vendor's total cumulative liability exceed the fees paid by Customer in the three (3) months preceding the claim."
That is a $60,000 cap against a $300K-$2M incident. It does not cover the notification letters, let alone the claim.
> Opening: "Vendor's total cumulative liability shall not exceed the greater of (a) two times the fees paid in the twelve (12) months preceding the claim or (b) $1,000,000. This limitation shall not apply to breach of Section 9 (Confidentiality), Section 11 (Data Protection), Vendor's indemnification obligations under Section 12, or Vendor's gross negligence or willful misconduct."
> Fallback: 1x 12-month fees with all four carve-outs intact and a $500,000 floor. The carve-outs matter more than the multiplier.
2. § 11: Data protection.
> "Vendor shall maintain reasonable administrative, technical, and physical safeguards."
Unenforceable as written, and they are warehousing consumer purchase data at scale. No notification timing, no sub-processor control, no audit.
> Opening: Strike and replace with our standard DPA, requiring SOC 2 Type II annually, encryption at rest and in transit, breach notice within 72 hours of discovery, sub-processor notice with a right to object, annual penetration testing, and a customer audit right once per year.
> Fallback: Customer audit only on a confirmed incident; annual pen-test summary rather than the full report. Everything else holds.
3. § 12.3: IP indemnity.
> "...provided that Vendor shall have no obligation for claims arising from combination of the Services with any other product, service, or data."
We combine on day one. That is the entire integration. As drafted the indemnity is close to illusory.
> Opening: Narrow the exclusion to "combinations Vendor did not anticipate, recommend, or document," and add Customer's consent right where settlement requires an admission by Customer.
> Fallback: Strike the combination exclusion for combinations described in the SOW or Vendor's documentation.
4. § 14.1: Termination.
> "Vendor may terminate for convenience upon thirty (30) days' notice."
One-way convenience termination on a service our product depends on, with a four-month migration. That is a hostage position.
> Opening: Mutual termination for convenience (90 days for Vendor, 30 for Customer) plus 120 days of transition assistance at then-current rates and export of Customer data in a documented format.
> Fallback: 60 days both ways with 90 days of transition assistance.
5. § 15.1: Renewal and escalator.
> "...shall automatically renew for successive one-year terms unless either party provides ninety (90) days' written notice... fees shall increase seven percent (7%) annually."
Procurement will miss a 90-day window. 7% compounding on a three-year deal is roughly $52,000 of unbudgeted spend: $16,800 in year two and $34,872 in year three.
> Opening: 30-day notice window; escalator capped at the lesser of CPI or 4%.
> Fallback: 60-day window, 5% cap.
Data and security audit
| Requirement | Status | Note |
|---|---|---|
| DPA | Missing | Mandatory at this data scope |
| Named security standard | Missing | "Reasonable" only (§ 11) |
| Breach notification timing | Missing | No clock at all |
| Sub-processor control | Missing | § 11.4 permits freely |
| Audit rights | Missing | none |
| Deletion on termination | Weak | § 14.5 says "upon request," no deadline |
What is missing. No transition assistance. No insurance requirement, unusual for a vendor holding consumer data. No service credits despite an availability commitment in § 6. No survival clause, so nothing carries the confidentiality obligations past termination.
Reviewed and not flagged. §§ 16–22 (notices, force majeure, severability, entire agreement) are unremarkable; Delaware governing law is acceptable [safe - § 18.1].
Business-owner one-pager
- *The deal:* Three years, $240K/yr, they warehouse the retailer-feed customer data our product runs on.
- *Five things to know:* (1) If they lose our data, they owe us $60,000; we need at least $1M. (2) They have made no real security commitments; we need a data agreement attached. (3) Their IP protection has an exception that swallows it, because we combine their service with ours. (4) Only they can walk away early, and it would take us four months to replace them. (5) It auto-renews with a 7% price increase unless we cancel 90 days ahead.
- *Dollar exposure:* $300K-$2M for a single retailer-feed incident, against a $60K cap.
- *Deal-breakers:* The DPA and the liability cap. We do not sign without both.
- *Next step:* Redlines to their counsel today, 30-minute call Thursday, target signature in two weeks.
What your answers changed. The $300K-$2M incident range is what put § 10.2 at the top of the list and what made this YELLOW rather than GREEN. A $60,000 cap is three months of a $240,000-a-year fee, unremarkable on its face, and visible as a problem only once $2M sits beside it. Tell me the worst case is a weekend of re-running feeds and neither deal-breaker survives: the cap is proportionate, the DPA is still worth asking for but is not something I would hold signature over, and this signs with clean-up. Your "one alternative vendor, four months to migrate" answer is why § 14.1 made the top five at all and why the transition-assistance ask is 120 days rather than 30. With a drop-in substitute, one-way convenience termination is an irritation, not a hostage position. Your security answer changed nothing. A clean SOC 2 the contract does not oblige them to maintain is worth nothing in a dispute, so priority 2 reads exactly as it would have if the questionnaire had come back full of findings.
Why this prompt is built the way it is
## Framework
1. **Triage by dollars, not by section order.** Limitation of liability, indemnity, IP ownership, data and security, term and termination, payment, warranty, audit. Everything else waits.
2. **Score the deal.** Green: sign with minor markup. Yellow: these redlines first. Red: escalate or walk. One sentence of reasoning.
3. **Five priorities, not twenty-five.** A redline memo with twenty-five items gets negotiated in the order the vendor prefers. Five gets negotiated in yours.
4. **Assess the cap against real exposure.** Twelve months of fees is the market convention, not a safe number. Compare the cap to the loss the business would actually take, and carve out confidentiality, IP indemnity, data breach, and gross negligence or willful misconduct at minimum.
5. **Data lives in its own bucket.** If the vendor touches personal data, a DPA is mandatory and security obligations need named standards, breach-notification timing, sub-processor control, and audit rights. "Reasonable safeguards" is unenforceable.
6. **Termination and assignment are the exit.** The customer should have termination for convenience and transition assistance. The vendor's assignment right should not deliver you to a competitor.
7. **Every opening position gets a fallback.** Otherwise the first pushback becomes a call to legal.
8. **The business owner gets a one-pager.** Plain English, the dollar exposure, the deal-breakers, and what happens next.