All prompts

Analyze/Featured

Review a vendor MSA top-to-bottom

Scores the agreement, gives you five redline priorities with opening and fallback language for each, audits the data and security terms, and writes the one-pager the business owner will actually read.

About 25 minintermediateIn-house, Transactional

Your prompt5,392 characters

Still to fill in: MSA text, Deal summary, Governing law and forum

RoleYou are a senior in-house counsel who has reviewed hundreds of vendor MSAs and whose job is to ship deals, not to bury them. You triage by dollars at risk rather than by clause order, you give procurement a fallback with every opening position so the negotiation has somewhere to go, and you refuse to send a business owner anything they cannot act on in two minutes.What I needReview the MSA below as Customer: we are buying. The deal: Deal summary. Data scope: No personal data. Governing law: Governing law and forum. Hold me to our playbook where it applies: Our standard positions.InputsMSA: MSA text Deal: Deal summary Which side we are on: Customer: we are buying Data scope: No personal data Governing law and forum: Governing law and forum Our standard positions: Our standard positionsHow to work this1. Read for failure first: limitation of liability, indemnity, IP ownership, data and security, term and termination, payment, warranty, audit. Rank by dollars at risk, not by section number. 2. Convert the liability cap into a dollar figure using the contract value I gave you, then set it against the worst-case loss. Put both numbers in one sentence. 3. Pick exactly five redline priorities. For each: section number, the clause quoted, the problem in one business sentence, paste-ready opening language, and the fallback you would accept. 4. Run the data and security audit against No personal data: DPA present and adequate, named security standard, breach-notification timing, sub-processor control, audit rights, deletion on termination. Mark each present, weak, or missing. 5. Name what is absent: no transition assistance, no insurance requirement, no source-code escrow, no service credits, no survival clause. Absent terms are risk. 6. List the clauses you reviewed and deliberately did not flag, one line, so I know the rest was read. 7. Where Governing law and forum changes the answer: enforceability of the cap, consequential-damages waivers, arbitration of data claims. Say so, and say if you are unsure. 8. Write the business-owner one-pager last: the deal in one sentence, the five things to know in plain English, the dollar exposure, the deal-breakers, and the ask.Ask me firstBefore you produce anything, ask me these questions, then stop and wait: 1. If this vendor fails badly (an outage, a breach, corrupted data), what does the business actually lose in dollars? The cap cannot be assessed against anything but a number. 2. Can we leave? Is there a credible substitute and how long would migration take? That answer sets our real leverage on termination, price escalators, and transition assistance. 3. What has the business or procurement already agreed to, in an order form, a quote, or a meeting, that I should not waste a redline on? 4. What has security already reviewed (a SOC 2 Type II, a penetration test summary, a completed questionnaire) and did anything come back open? Do not begin the review until I answer. If I tell you to proceed anyway, state each assumption at the top of your output and mark it [ASSUMPTION - verify].Output formatScore: green / yellow / red, one-sentence rationale. Top five redline priorities, each with section, quoted clause, the problem, opening redline, fallback. Data and security audit as a table marking each requirement present, weak, or missing. What is missing. Reviewed and not flagged, one line. Business-owner one-pager: the deal in a sentence, five plain-English points, dollar exposure, deal-breakers, next step. End with one line naming the two of my answers that most changed this review: say which of the five priorities would not have made the list without them, and what the score would have been. If an answer changed nothing, say so; it means I should not have been asked.Never do this- If this review would fit any vendor agreement at any company, it is too generic. Every priority has to trace to this deal's numbers and this data scope. - No hedging filler. Cut "arguably," "it should be noted," and "this clause is market" used in place of analysis. Do not tell me to consult an attorney. I am the attorney who signs off on this. - Every statute, regulation, or enforceability claim must come from my inputs or carry [UNVERIFIED - confirm before relying]. Never invent a citation, a regulatory deadline, or a certification standard. - Where you do not know how Governing law and forum treats a liability cap, a consequential-damages waiver, or an indemnity, say you do not know. Do not smooth over the gap with fluent prose in a document procurement will forward to the vendor. - Do not pad. Five priorities means five. Length is not value, and a twenty-item memo gets negotiated in the vendor's order.Before you answer- Did I state the cap as a dollar figure next to the worst-case loss, rather than describing it as "low"? - Does every priority carry both an opening position and a fallback I could actually accept? - Is every redline paste-ready contract language, not a description of what to ask for? - Did I check what the agreement leaves out, not only what it says? - Could a non-lawyer read the one-pager and decide? Would it be useless for a different vendor? It should be.

Adds driver's-seat tunes: options instead of answers, questions before work, every citation flagged. Your values come with it.

2

Pressure-test it

Makes the AI switch hats and attack its own answer.

You wrote this paper, and your sales team has a quarter-end date. As the vendor's general counsel: which three redlines do you push back on hardest, and what business reason do you give? Which one is genuinely off-market for a deal this size, so that insisting on it makes us look like we have never bought software before? Rewrite those three as the compromise language you would sign this week, and tell me what each compromise costs us.
3

Go deeper

Pushes the work further once the basics are right.

Their counsel reads the cover email before anyone opens the redline. Draft the redline send-back to the vendor: a short email to their counsel and our procurement lead that opens with what we accept, groups the five priorities into the two that are conditions of signature and the three that are asks, gives a business reason for each rather than a legal one, and proposes a thirty-minute call with a target signature date. Under 300 words.

Before you run it

What to gather first

  • Annual contract value, term length, and what renewal looks like
  • Realistic worst-case loss if the vendor fails or is breached
  • Whether a substitute vendor exists and how long migration would take
  • What the security team has already reviewed: SOC 2, pen test, questionnaire
  • Your company's standard cap, carve-outs, and approved fallback positions

Watch for

  • The model reads only what you paste. Order forms, SLAs, security exhibits, and incorporated policies carry the real obligations, and the teeth are usually in the exhibit.
  • Liability carve-outs interact with your insurance. Confirm that cyber and E&O coverage actually reaches the exposure you are agreeing to accept.
  • If the vendor processes EU, UK, or California personal data, a DPA is not optional and transfer mechanisms may be required. Treat any DPA analysis here as a starting point, not a compliance conclusion.
  • Auto-renewal and price-escalator clauses become someone else's problem in eighteen months. Calendar the notice window before you sign, not after.
  • State-specific regimes (Illinois BIPA, Washington My Health My Data, New York SHIELD) will not surface unless you name them. Add them to the inputs yourself.

What comes back

A green/yellow/red score with a one-sentence rationale; five redline priorities, each with section number, quoted clause, the business problem, paste-ready opening language, and a fallback; a data and security audit table marking each requirement present, weak, or missing; a list of what the agreement leaves out; a one-line note on what was reviewed and not flagged; and a business-owner one-pager with the dollar exposure and the deal-breakers.

See an example of what you’ll get
*(After you answer the four questions: worst case is a retailer-feed data incident at $300K-$2M, one alternative vendor at four months' migration, procurement has already agreed to the fee schedule, security has a clean SOC 2 but no pen test.)* Score: YELLOW. Four substantive redlines plus a missing DPA. Closeable in two rounds. Top five redline priorities 1. § 10.2: Limitation of liability. > "In no event shall Vendor's total cumulative liability exceed the fees paid by Customer in the three (3) months preceding the claim." That is a $60,000 cap against a $300K-$2M incident. It does not cover the notification letters, let alone the claim. > Opening: "Vendor's total cumulative liability shall not exceed the greater of (a) two times the fees paid in the twelve (12) months preceding the claim or (b) $1,000,000. This limitation shall not apply to breach of Section 9 (Confidentiality), Section 11 (Data Protection), Vendor's indemnification obligations under Section 12, or Vendor's gross negligence or willful misconduct." > Fallback: 1x 12-month fees with all four carve-outs intact and a $500,000 floor. The carve-outs matter more than the multiplier. 2. § 11: Data protection. > "Vendor shall maintain reasonable administrative, technical, and physical safeguards." Unenforceable as written, and they are warehousing consumer purchase data at scale. No notification timing, no sub-processor control, no audit. > Opening: Strike and replace with our standard DPA, requiring SOC 2 Type II annually, encryption at rest and in transit, breach notice within 72 hours of discovery, sub-processor notice with a right to object, annual penetration testing, and a customer audit right once per year. > Fallback: Customer audit only on a confirmed incident; annual pen-test summary rather than the full report. Everything else holds. 3. § 12.3: IP indemnity. > "...provided that Vendor shall have no obligation for claims arising from combination of the Services with any other product, service, or data." We combine on day one. That is the entire integration. As drafted the indemnity is close to illusory. > Opening: Narrow the exclusion to "combinations Vendor did not anticipate, recommend, or document," and add Customer's consent right where settlement requires an admission by Customer. > Fallback: Strike the combination exclusion for combinations described in the SOW or Vendor's documentation. 4. § 14.1: Termination. > "Vendor may terminate for convenience upon thirty (30) days' notice." One-way convenience termination on a service our product depends on, with a four-month migration. That is a hostage position. > Opening: Mutual termination for convenience (90 days for Vendor, 30 for Customer) plus 120 days of transition assistance at then-current rates and export of Customer data in a documented format. > Fallback: 60 days both ways with 90 days of transition assistance. 5. § 15.1: Renewal and escalator. > "...shall automatically renew for successive one-year terms unless either party provides ninety (90) days' written notice... fees shall increase seven percent (7%) annually." Procurement will miss a 90-day window. 7% compounding on a three-year deal is roughly $52,000 of unbudgeted spend: $16,800 in year two and $34,872 in year three. > Opening: 30-day notice window; escalator capped at the lesser of CPI or 4%. > Fallback: 60-day window, 5% cap. Data and security audit | Requirement | Status | Note | |---|---|---| | DPA | Missing | Mandatory at this data scope | | Named security standard | Missing | "Reasonable" only (§ 11) | | Breach notification timing | Missing | No clock at all | | Sub-processor control | Missing | § 11.4 permits freely | | Audit rights | Missing | none | | Deletion on termination | Weak | § 14.5 says "upon request," no deadline | What is missing. No transition assistance. No insurance requirement, unusual for a vendor holding consumer data. No service credits despite an availability commitment in § 6. No survival clause, so nothing carries the confidentiality obligations past termination. Reviewed and not flagged. §§ 16–22 (notices, force majeure, severability, entire agreement) are unremarkable; Delaware governing law is acceptable [safe - § 18.1]. Business-owner one-pager - *The deal:* Three years, $240K/yr, they warehouse the retailer-feed customer data our product runs on. - *Five things to know:* (1) If they lose our data, they owe us $60,000; we need at least $1M. (2) They have made no real security commitments; we need a data agreement attached. (3) Their IP protection has an exception that swallows it, because we combine their service with ours. (4) Only they can walk away early, and it would take us four months to replace them. (5) It auto-renews with a 7% price increase unless we cancel 90 days ahead. - *Dollar exposure:* $300K-$2M for a single retailer-feed incident, against a $60K cap. - *Deal-breakers:* The DPA and the liability cap. We do not sign without both. - *Next step:* Redlines to their counsel today, 30-minute call Thursday, target signature in two weeks. What your answers changed. The $300K-$2M incident range is what put § 10.2 at the top of the list and what made this YELLOW rather than GREEN. A $60,000 cap is three months of a $240,000-a-year fee, unremarkable on its face, and visible as a problem only once $2M sits beside it. Tell me the worst case is a weekend of re-running feeds and neither deal-breaker survives: the cap is proportionate, the DPA is still worth asking for but is not something I would hold signature over, and this signs with clean-up. Your "one alternative vendor, four months to migrate" answer is why § 14.1 made the top five at all and why the transition-assistance ask is 120 days rather than 30. With a drop-in substitute, one-way convenience termination is an irritation, not a hostage position. Your security answer changed nothing. A clean SOC 2 the contract does not oblige them to maintain is worth nothing in a dispute, so priority 2 reads exactly as it would have if the questionnaire had come back full of findings.
Why this prompt is built the way it is
## Framework 1. **Triage by dollars, not by section order.** Limitation of liability, indemnity, IP ownership, data and security, term and termination, payment, warranty, audit. Everything else waits. 2. **Score the deal.** Green: sign with minor markup. Yellow: these redlines first. Red: escalate or walk. One sentence of reasoning. 3. **Five priorities, not twenty-five.** A redline memo with twenty-five items gets negotiated in the order the vendor prefers. Five gets negotiated in yours. 4. **Assess the cap against real exposure.** Twelve months of fees is the market convention, not a safe number. Compare the cap to the loss the business would actually take, and carve out confidentiality, IP indemnity, data breach, and gross negligence or willful misconduct at minimum. 5. **Data lives in its own bucket.** If the vendor touches personal data, a DPA is mandatory and security obligations need named standards, breach-notification timing, sub-processor control, and audit rights. "Reasonable safeguards" is unenforceable. 6. **Termination and assignment are the exit.** The customer should have termination for convenience and transition assistance. The vendor's assignment right should not deliver you to a competitor. 7. **Every opening position gets a fallback.** Otherwise the first pushback becomes a call to legal. 8. **The business owner gets a one-pager.** Plain English, the dollar exposure, the deal-breakers, and what happens next.