MCM-57 — Legal & Compliance Readiness for Customer Deployment
Overview of the legal and compliance deliverables that must be in place before MCM is deployed into a customer's environment.
MCM-57 — Legal & Compliance Readiness for Customer Deployment
MCM is a multi-cloud governance, security, and cost management platform that requires cross-account access into a customer's cloud environment, processes their discovery, security, and cost data, and increasingly uses an AI assistant to draft policies and suggest actions. Deploying it into a customer's environment carries legal and compliance obligations well beyond typical SaaS onboarding — data processing terms, access-scope commitments, licensing, open-source obligations, security certifications, incident response commitments, liability, audit rights, and export control all need to be resolved before the first production deployment.
Each user story below is a self-contained deliverable with its own acceptance criteria, a short technical note on how it ties back to the platform, and — where relevant — a diagram of the review or approval flow. This page holds only what's shared across all of them.
Personas
| Persona | Role | Primary concern |
|---|---|---|
| Legal Counsel | Drafts and negotiates contracts, DPAs, and compliance terms for MCM | Enforceable, risk-appropriate legal terms in place before any customer deployment |
| Compliance & Security Lead | Owns certification, vulnerability management, and audit/pen-test readiness | Passing customer security reviews and keeping certifications and processes current |
| Enterprise Sales / Deal Desk | Runs the commercial deal and contracting process with prospective customers | Closing deals without legal terms blocking or delaying signature |
| Engineering Lead | Owns the dependency inventory, SBOM output, and export classification inputs | Producing accurate, current compliance artifacts on demand |
System Context
User Stories
| Story | Summary |
|---|---|
| MCM-58 — Data Processing Agreement & Controller/Processor Clarity | A standard DPA and a documented controller/processor determination per deployment model. |
| MCM-59 — Cross-Account Access & Least-Privilege Commitments | Documented, contractually-committed least-privilege scopes for every cross-account role MCM requests. |
| MCM-60 — AI Assistant Data Handling & Human-in-the-Loop Governance | No-training terms, disclosure, and a mandatory human approval step for every AI-suggested action. |
| MCM-61 — Licensing Model & Contract Templates | Finalized on-prem/hosted licensing models with approved EULA/MSA templates. |
| MCM-62 — Open Source License Compliance & SBOM Deliverable | A current SBOM and a clean open-source license audit for every release. |
| MCM-63 — Security Compliance Certifications | SOC 2 Type II, ISO 27001/27017/27018, and PCI DSS scoping where applicable. |
| MCM-64 — Vulnerability Management & Incident/Breach Notification SLA | Documented severity SLAs and a contractual breach-notification window. |
| MCM-65 — Liability Caps, Indemnification & Insurance | Bounded, insured financial exposure, including security-tool-specific liability language. |
| MCM-66 — Customer Audit & Penetration Testing Rights | Controlled audit and pen-test rights a customer's security team can exercise before deployment. |
| MCM-67 — Export Control Classification Review | ECCN (or equivalent) classification covering cryptographic and AI components, reviewed per release. |
Cross-Cutting Non-Functional Requirements
| ID | Requirement |
|---|---|
| NFR-01 | Every deliverable in this module must be complete for a given deployment model before the first customer's cross-account access is granted in production under that model. |
| NFR-02 | Customer-facing compliance artifacts (DPA, SBOM, certification reports, insurance certificates) are kept current and reissued at every major release or annually, whichever comes first. |
| NFR-03 | Any new module or materially new capability (e.g., a new AI-driven action, new cryptographic functionality) triggers a review of every story in this module for continued accuracy — none of these are one-time determinations. |
Out of Scope
- Negotiating terms for any single specific customer deal — this module defines the standard templates and processes; per-deal negotiation is handled by Legal Counsel and Deal Desk against that baseline.
- Country-specific data residency requirements beyond a GDPR/CCPA-equivalent baseline — handled case-by-case if a specific customer requires it.
- Physical security or facility compliance for MCM's own corporate offices — this module covers the platform and its deployment into customer environments only.