Argos OS Intelligent Automation, LLC
v2 · native switcher argos.intelamation.net
Account
Log in · Log out
Intelligent Automation ArgosCOUNSEL Argos Service
← All templates

Master Sub-Service Agreement (MSP-of-MSP)

mssa · v2 · partner-agreement · NJ
Edit (new version) Use this template
Attorney review required. Agreements drafted from this template enter attorney_review automatically and cannot be sent to a counterparty until an authorised attorney approves them.

Persona prompts

The system prompts used by the Legal / CISO / CEO personas when drafting and reviewing this template. Inherited from the Intelligent Automation MSP-attorney baseline.

Legal persona
You are an expert MSP (Managed Service Provider) contract attorney specialising in IT services agreements. You help Intelligent Automation, LLC — a Managed Cybersecurity Service Provider (MCSP) based in Fairfield, NJ — draft professional, legally sound contract language. Write in formal, B2B contract English. Be specific to the service type (cybersecurity, cloud, vCISO, etc). Include concrete metrics, timeframes, and obligations where appropriate. Reference NIST CSF 2.0, CIS Controls v8, MITRE ATT&CK, SOC 2 Type 2 where applicable. Output ONLY the revised clause text, no preamble or explanation. Return a JSON object with keys "body_md" (string, full revised section text), "redline_summary_md" (short bullet list of what you changed and why) and "confidence" (float 0.0–1.0 reflecting your certainty the language is legally sound for IA's NJ jurisdiction).
CISO persona
You are the CISO of Intelligent Automation, LLC, reviewing a draft MSP/MSSP contract for security, compliance, and data-handling adequacy. Verify breach-notification windows, sub-processor obligations, encryption requirements, audit-rights, BAA/HIPAA alignment, SOC 2 evidence requirements, incident-response timing. Flag sections that weaken IA's security posture or compliance position with customers in healthcare, finance, or CMMC-regulated industries. Output ONLY a JSON object with keys "body_md" (your security-revised version of the section), "redline_summary_md" (bullet list of security/compliance changes with rationale), "confidence" (float 0.0–1.0).
CEO persona
You are the CEO of Intelligent Automation, LLC reviewing a draft MSP contract for commercial reasonableness from the MSP's perspective. Verify pricing/payment terms, term length, auto-renewal clauses, termination-for-convenience, liability caps, indemnification scope, limitation-of-liability, IP ownership. Flag terms that give away too much margin, accept unreasonable risk, or create operational drag. Output ONLY a JSON object with keys "body_md" (your commercial-revised version), "redline_summary_md" (bullet list of commercial changes with rationale), "confidence" (float 0.0–1.0).

Merge fields

Filled in by the "New agreement" form before the AI personas draft.

effective_datetenant_namecustomer_namescope_of_servicesmonthly_recurring_feeterm_monthsGoverningClause

Body preview

> ⚠️ **Drafted with AI assistance via Argos Counsel.** This document reflects standard commercial terms but may not address jurisdiction-specific requirements or the unique facts of your transaction. Both parties should obtain independent legal review before signing.

# Master Security Services Agreement

This **Master Security Services Agreement** (this "MSSA") is entered into as of **{{.effective_date}}** by and between **{{.tenant_name}}** ("Provider") and **{{.customer_name}}** ("Customer"), and extends the Master Services Agreement between the Parties for managed security services. Where this MSSA and the underlying MSA conflict on a security matter, this MSSA controls.

## 1. Security Services Scope

Provider shall deliver the managed security services described in the applicable SOW, which may include managed detection and response (MDR), security operations centre (SOC) monitoring, vulnerability management, incident response, security awareness training, and related capabilities. Specific scope: **{{.scope_of_services}}**. The monthly recurring fee for the in-scope security services is **${{.monthly_recurring_fee}}** unless otherwise specified in an SOW.

## 2. Term

The Initial Term is **{{.term_months}} months** from the Effective Date, with automatic twelve (12)-month renewals unless either Party gives ninety (90) days' notice of non-renewal.

## 3. Incident Response Service Levels

Provider commits to the following severity-tiered response times, measured from the time of incident classification by Provider's SOC:

| Severity | Examples | Acknowledgement | Initial Triage | Containment Action |
|----------|----------|-----------------|----------------|--------------------|
| **Critical (P1)** | Confirmed compromise of production system; active data exfiltration; ransomware encryption in progress | 15 minutes | 30 minutes | 1 hour |
| **High (P2)** | High-confidence indicator of compromise; privileged credential abuse; multi-host malware | 30 minutes | 1 hour | 4 hours |
| **Medium (P3)** | Single-host malware; suspicious authentication; policy violation | 2 hours | 4 hours | Next business day |
| **Low (P4)** | Informational; tuning candidate | Next business day | 3 business days | As prioritised |

## 4. Data Handling

Provider processes Customer security telemetry (log data, EDR events, network metadata, identity events) solely to deliver the Services. Personal data and personal health information (where present) are processed under the Master Services Agreement and any executed Business Associate Agreement. Provider stores Customer telemetry in U.S.-based facilities with encryption in transit (TLS 1.2+) and at rest (AES-256), and retains it for the period specified in the SOW (default: thirteen (13) months rolling).

## 5. Right to Audit

Customer may, no more than once per calendar year, request Provider's then-current SOC 2 Type 2 report, ISO 27001 certificate (if held), and a summary of penetration test findings for the Services. Customer shall hold all such materials as Provider Confidential Information. On-site audits are not permitted absent a confirmed security incident affecting Customer.

## 6. Breach Notification

Provider shall notify Customer of any confirmed Security Incident affecting Customer data without undue delay and in no event later than **seventy-two (72) hours** after confirmation. Such notice shall describe, to the extent then known, the nature of the incident, affected data categories, and Provider's response activities. Provider shall provide updates as additional information becomes available and shall cooperate reasonably in Customer's investigation and notification obligations to third parties or regulators.

## 7. Customer Security Obligations

Customer shall (i) maintain accurate asset and user inventories shared with Provider, (ii) promptly action containment instructions from Provider during active incidents, (iii) not disable, modify, or interfere with Provider's monitoring agents or sensors without prior coordination, (iv) ensure all personnel with administrative access complete annual security awareness training, and (v) promptly disclose to Provider any change in business that materially alters the threat profile or compliance posture.

## 8. Tooling Stack and Vendor Substitution

Provider may, at its discretion, substitute the underlying tools, vendors, or technologies used to deliver the Services, provided that any substitution shall not materially degrade the service level commitments in Section 3. Provider shall give Customer thirty (30) days' prior written notice of any change that requires Customer-side action (e.g., agent reinstall, allow-list update).

## 9. Vulnerability Disclosure

Provider operates a coordinated vulnerability disclosure program and shall communicate critical vulnerabilities affecting Provider's service or any Customer-deployed component within seventy-two (72) hours of confirmed reproduction, together with mitigation guidance.

## 10. Subprocessors

Provider engages subprocessors to deliver the Services and maintains a current list available on request. Provider remains liable for subprocessor acts and omissions as if its own. Provider shall give thirty (30) days' notice of new subprocessors who will materially process Customer data; Customer may terminate the affected SOW for cause if it reasonably objects.

## 11. Termination for Material Security Breach

In addition to any general termination rights under the MSA, Customer may terminate this MSSA and any related SOW immediately on written notice if Provider materially breaches its security or data-handling obligations and fails to cure within fifteen (15) days of written notice.

## 12. Governing Law

{{.GoverningClause}}

## 13. Incorporation

All other terms of the underlying Master Services Agreement remain in full force and apply to the Services under this MSSA.

**{{.tenant_name}}**: By ____________________  Name ____________________  Title ____________________

**{{.customer_name}}**: By ____________________  Name ____________________  Title ____________________