Activities: Gather business goals, data sources, integration points, required dashboards/alerts, and user roles.
Deliverables: Statement of work (SOW) or requirements document, high-level architecture diagram, success criteria.
Architecture & design
Activities: Define data pipelines (where data comes from, data models), deployment topology, security requirements, and integration with existing systems (SIEM, ticketing, BI tools).
Deliverables: Data model, integration specs, security & access control plan.
Data preparation & onboarding
Activities: Connect data sources, establish ETL/ELT or streaming pipelines, define normalization/transformation routines, data quality checks.
Deliverables: Data mappings, data quality rules, sample datasets.
Implementation & configuration
Activities: Install or provision the software, configure rules/algorithms (e.g., threat detection, anomaly scoring, or business metric calculations), set up dashboards and reports.
Deliverables: Configured instance, user roles/permissions, sample dashboards.
Testing & validation
Activities: Functional testing, performance/load testing, security validation, UAT with key business users.
Deliverables: Test cases, acceptance sign-off, issue log.
Customisation
Data source/connectors: Adding new data sources, supported via connectors or APIs.
Data model customization: Extensible schemas, fields, and metadata to align with business taxonomy.
Rule/algorithm customization: Tuning detection rules, thresholds, scoring models, or ML components.
Dashboards and reports: Custom layouts, new visualizations, branding, and export formats.
Alerts & workflows: Custom alert criteria, routing to incident management tools, and escalation policies.
Security & access: Role-based access control (RBAC), data masking, and multi-tenant isolation.
Automation & integrations: API access for external automation, webhook triggers, and integration with ticketing, IAM, or SIEM tools.
Performance tuning: Scaling configurations, indexing strategies, and caching options.
Additional Costs
License or subscription fees: Per-user, per-seat, per-node, or per data volume/tier.
Implementation/setup fees: One-time professional services for deployment, data integration, and customization.
Professional services: Custom development, advanced integrations, rule/algorithm tuning, and onboarding/training.
Maintenance & support: Ongoing support contracts (SLA levels, response times), software updates, and access to new features.
Training: Initial and ongoing user/admin training, either as part of services or separate licenses.
Data storage & egress: Costs related to data ingested, retained, and processed (especially for cloud deployments).
Add-ons & modules: Any optional features (e.g., advanced analytics, AI/ML modules, premium connectors).
Security/compliance: Additional costs for certifications, audit readiness, or dedicated security controls (if applicable).
Training
Initial onboarding/training
Administrative users: typically receive hands-on admin/ops training covering deployment, user management, data connections, and monitoring.
End users: role-based training focusing on day-to-day use, dashboards, procedures for creating reports, and understanding alerts.
Delivery formats: live instructor-led sessions, recorded videos, interactive labs, and self-paced online courses.
Training content typically includes
System architecture and data model overview
Data source onboarding and ETL/ELT/log streaming setup
Rule/algorithm configuration and dashboard customization
Alerting, incident workflows, and integration with ticketing/PI systems
Pre- and post-upgrade testing: access to test environments or PoCs for new releases
Data Ownership and Portability
Data ownership
The offering should clearly state that you (the customer) own the data you ingest into Hitprobe.
The contract should specify that data remains the property of the customer, with Hitprobe acting as a data processor or service provider.
Ensure terms clarify ownership of any derived analytics, dashboards, or models created by Hitprobe using your data (typically you own outputs you generate, unless otherwise stated).
Data access and export rights
Customers should have the right to access, download, and export their data in common formats (e.g., CSV, JSON, Parquet) on demand.
Specify the frequency and format of data exports, as well as any costs or limits (e.g., monthly export limits, egress fees for cloud deployments).
Data retention and deletion
Define retention periods for raw data, transformed data, and backups after contract termination.
Include a clean-up window and process for secure data deletion (e.g., verifiable deletion reports, cryptographic erasure for storage volumes).
Data portability at end of contract
Provide a documented data migration path to another system, including:
The exact data schemas and mappings.
Availability of export formats and tooling.
Timelines for data provisioning and deletion post-migration.
Scaling Up / Down
Elasticity and scaling options
Define whether scaling is handled automatically by the platform or requires managerial actions (e.g., increasing seats, data volume, or compute resources).
Clarify minimum and maximum limits for scaling, and any constraints (certificates, regions, performance tiers).
Pricing impact of scaling
Provide tiered or usage-based pricing details for:
Additional users/seats or roles
Increased data ingestion/storage volumes
Higher throughput/compute requirements
Include any step-change pricing or cap on price increases for a given period.
Upgrade/downgrade process
Document the process, lead times, and any required approvals to scale up or down.
Specify whether downgrades are allowed mid-cycle and how proration is handled.
Mention any penalties or retroactive charges if scaling occurs outside agreed terms.
Migration impact
Address how scaling changes affect SLAs, support levels, and maintenance windows.
If downgrading, ensure a graceful migration path to a lower tier without data loss or feature crippling.
Termination of excess capacity
Provide a policy for canceling unused licenses, storage, or compute capacity without punitive fees.
The terms & conditions for contract renewal and cancellation
Renewal mechanics
Automatically renewing vs. opt-in renewal.
Renewal notice period (e.g., 60–90 days before term end).
Price renewal guidelines (fixed, capped, or subject to annual increases with a maximum cap).
Pricing at renewal
Whether price changes at renewal are tied to an explicit CPI or vendor-specific escalation cap.
Availability of grandfathering or renewal discounts for multi-year commitments.
Termination rights
Termination for convenience vs. for cause.
Notice period required to terminate (e.g., 30–90 days).
Any early termination penalties or fees, and how prepaid amounts are treated.
Data return/deletion obligations upon termination and the timeline.
Data handling at termination
Final data export window and method (direct download, secure transfer).
Post-termination data deletion window and confirmation (sanitization of backups, if any).
Transition assistance post-termination
Exit support: assistance with data migration to another platform, knowledge transfer, and handover documentation.
Availability of ongoing support for a limited period after termination (e.g., sunset support).
SLA continuity
Whether support SLAs continue through the termination notice period and any cessation of services after termination.
Contractual protections
Service credits for material breaches of renewal terms or persistent performance issues.
Compliance
SOC 2 Type II (Security, Availability, Confidentiality)
ISO 27001 (Information Security Management)
GDPR and data residency compliance
HIPAA (if handling protected health information)
PCI-DSS (if processing payment data)
ISO 27701 (Privacy Information Management)
CSA STAR (for cloud security)
PCI if cloud service touches cardholder data, depending on use case.