The buyer said yes, and now it is going to legal and security. What actually happens next?
Two parallel reviews start, and neither of them is your buyer. Legal sends redlines on your MSA (usually liability caps, indemnity, data processing terms and governing law), and the security team sends a questionnaire plus a request for your SOC 2 or equivalent. Both take weeks, not days, and both stall silently if you have no prepared answers. The fix is to have a contract playbook written before you need it (your default position, your fallback, and who signs off on each clause) and a folder with your security answers, subprocessor list and DPA ready to send in one email. Ask your champion for the names of the legal and security reviewers and email them directly rather than waiting for the deal to bounce back through your buyer.
Go deeper
4 resources, 1 India-specific, 4 link-checked.
📄 Article
✓ Link checkedFreeIntermediate
It walks through the eight clauses that redlines actually land on (liability, indemnity, DPA, payment terms, auto renewal, SLAs) and gives you a default position, a fallback and an approver for each. That is exactly the document you wish you had the first time a deal went to legal.
The generic contract advice online assumes US paper. This is the Indian version: the Indian Contract Act, the DPDP Act, GST and TDS on invoices, and FEMA when the deal is cross border. Read it before an Indian enterprise buyer sends you their procurement pack.
An MSA plus order form should carry scope, term, usage limits, payment, confidentiality, warranties, liability cap, indemnity, suspension, termination and governing law.
Cap liability at fees paid over a defined period, and carve out higher caps only for confidentiality and data incidents, not all claims.
The IP line is simple: the startup owns the platform, the customer owns its data, and roadmap improvements stay yours.
For Indian startups the base is the Indian Contract Act 1872, IT Act 2000 and the DPDP Act 2023, with a DPA covering subprocessors and breach notice.
Sets your expectations honestly for the first security review you ever face: the certificate does not make the questions go away, it changes who asks and what they ask about. Useful for knowing what to prepare rather than what to hope for.
Girish Redekar started Sprinto after watching security reviews stall his own deals, so he explains what the buyer's security team is really checking and what to have ready before they ask for it. It turns the scariest part of this stage into a list you can prepare in advance.