SaaS agreements differ significantly from penetration testing contracts, relying instead on standardized terms of service and service level agreements that define uptime guarantees, security responsibilities, and user obligations. Understanding these documents is essential for ensuring a SaaS provider meets organizational security and operational standards.
SaaS Agreements & Security
The type of agreements that we have with a pentester look much different than the type of agreements we have with something like a software company, or a software as a service company, where there's usually some sort of licensing or terms of service. So let's take a look at a SaaS company and what some of them are.
When we're doing everything ourselves, we're responsible for security. But when we're working with a cloud provider, then we're going to rely on them for certain aspects when it comes to security. A SaaS company is an extreme of that, where they are managing all of the backend systems, and all we're doing is working from the user interface and inputting data into the system and then managing our data through that — that essentially is what we're doing. So as software as a service, they're handling all of that and they're responsible for security. We better make sure that they're doing security right, and hold them to certain standards.
One of those standards we want to look at is a service level agreement. What level of service are they guaranteeing that they're going to deliver to us?
Here's a service level agreement, an SLA, for Meo. Meo is a software as a service company and it's one I've used in the past, so I thought I'd look it up. As you can see, there are certain guarantees that they're going to have certain service levels. This particular one right here is saying how much uptime they'll have, and what they say they're going to have is a 99.5% or greater uptime. So that's what we can rely on them for, and if they dip below that then we get a service credit — they'll credit our account back depending on how low they dip below this 99.5%.
But an SLA doesn't give you all of the details, just what service levels they're guaranteeing you. So what you also want to do is make sure that you check out whatever licensing agreement or terms of service that you're agreeing to.
Usually companies like meuro don't have individual contracts with every single customer that's really customized. What they have is they just have a terms of service. They set up the terms of what you are agreeing to if you're using their service, and that's the little check box that you check that you are agreeing to their terms of service, or their licensing, or however they put it. There are several different names for it, but essentially when you sign up for the service you're agreeing to those terms.
Here's that miros site again, and I've gone to the terms of service page. If you look over it, it looks very similar to a contract, and sometimes they read like a contract as well. So you better believe that this terms of service is going to protect the company. What you need to do is read through it and make sure it's going to protect you as a user of the software as well, and make sure that it falls in line with what your company policies and your organization's policies have already set out.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →