I have spent more time reading MSA than kubernetes docs this year and I am not happier for it. The "aggregated" loophole is everywhere. I started adding "aggregate means data from minimum 50 customers combined" to my redlines. 3 vendors accepted, 2 refused, 1 ghosted me. Ghosted one was the cheapest. Still use them. I am part of the problem.
DDoS mitigation vendor leaked my attack data in a sales deck
Self-custody means I run my own DDoS mitigation with community rulesets. Not for everyone. But nobody sells my attack data in a deck because nobody has it. Cost is my time and some false positives. Tradeoff.
This thread is why I only use vendors who let me audit their SOC2 Type II. Not perfect but marketing decks are outside scope of most audits, so maybe useless.
SOC2 Type II does not cover this. Marketing materials are not in the CC6.1 controls. You need custom audit or specific contract language.
Update: counsel reviewed. They recommend two paths: contract amendment with specific "no use of attack metadata for commercial purposes" language, or GDPR Article 82 damages claim if EU jurisdiction applies. My contract is under English law, so GDPR path is uncertain. They also want to see if the webinar was recorded and distributed, which affects damages calculation. I will know more next week.