Glossary
Plain-English terms from Cubbie’s software marketplace, procurement, subscriptions, rewards, partner, vendor, API, and trust workflows. 43 entries.
Topics covered
A
A document specifying what users may and may not do on a software service, attached to the master agreement.
- ACHFinance
Automated Clearing House, the U.S. electronic network for bank-to-bank payments.
A vendor metric for the annualized value of all active subscription contracts, normalized to a single year.
- Auto-RenewalContracts
A contract clause that renews the agreement automatically if neither party gives notice within a specified window.
C
- CCPAPrivacy
The California Consumer Privacy Act (as amended by CPRA), giving California residents rights over their personal information.
- ChurnMetrics
The rate at which customers cancel or downgrade, expressed as a percentage of revenue or customers per period.
- Commit PricingPricing
A contract structure where the buyer commits to a minimum spend in exchange for a discounted rate.
A vendor metric for the all-in cost to acquire one new customer, including sales, marketing, and onboarding.
A vendor metric for the total gross profit a vendor expects to earn from one customer over the relationship.
D
- DPAPrivacy
Data Processing Agreement — required by GDPR and similar regimes, defines how a vendor processes the buyer's personal data.
E
- Enterprise License Agreement (ELA)Contracts
A multi-year, multi-product, all-you-can-eat contract sold to enterprise customers, typically priced as a flat annual commit.
F
- Feature GatingPricing
The practice of restricting features to higher pricing tiers, often unrelated to underlying cost.
G
- GDPRPrivacy
The European Union's General Data Protection Regulation, governing personal data of EU residents.
H
- HIPAASecurity
A U.S. law governing the privacy and security of protected health information, with corresponding obligations on covered entities and business associates.
I
- IndemnificationLegal
A contract clause where one party agrees to cover specified damages or claims brought against the other.
- ISO 27001Security
An international standard for information security management systems (ISMS), audited and certified by accredited bodies.
L
A contract clause that caps the maximum dollar amount each party can be liable for under the agreement.
M
A vendor metric for the monthly recurring value of all active subscriptions.
- MSALegal
Master Services Agreement — the umbrella legal contract between a buyer and a software vendor.
A login flow that requires two or more independent factors (something you know, have, or are).
N
- Net Revenue Retention (NRR)Metrics
A vendor metric showing the year-over-year change in revenue from existing customers, including expansion and churn.
- Net-30Finance
Payment terms — invoice due 30 days from receipt.
A contract where one or both parties agree to keep specified information confidential.
- Notice PeriodContracts
The number of days before contract end during which a party must declare intent to renew, terminate, or renegotiate.
O
- OpenID Connect (OIDC)Identity
A modern, JSON-based protocol for identity and authentication, layered on OAuth 2.0.
P
- PCI DSSSecurity
The Payment Card Industry Data Security Standard, which governs the handling of credit card data.
- Penetration Test (Pen Test)Security
An authorized simulated attack on a system to find vulnerabilities before real attackers do.
- Purchase Order (PO)Finance
A buyer-issued document that authorizes a vendor to deliver specified goods or services at agreed prices.
R
- Request for Information (RFI)Procurement
An exploratory document asking vendors to describe their capabilities, used early in evaluation to narrow a long list.
- Request for Proposal (RFP)Procurement
A formal procurement document inviting vendors to bid on a defined scope of work, with structured evaluation criteria.
- Request for Quote (RFQ)Procurement
A short-form procurement document asking vendors to quote price for a clearly defined product or service, typically without proposing alternatives.
- Role-Based Access Control (RBAC)Identity
A model for granting permissions based on a user's role rather than assigning individual permissions per user.
S
- SaaS ProcurementProcurement
The end-to-end process of evaluating, buying, deploying, and managing third-party software at a company.
- SAMLIdentity
An XML-based protocol for federated single sign-on, widely used in enterprise SaaS.
- SCIMIdentity
System for Cross-domain Identity Management — an open standard for automating user provisioning and deprovisioning between identity providers and SaaS apps.
- Seat-Based PricingPricing
A pricing model where the buyer pays per active user account.
- Single Sign-On (SSO)Identity
A way for users to sign in to multiple applications with one set of credentials, typically managed by an identity provider.
- SOC 2Security
Service Organization Control 2 — an audit framework for security, availability, processing integrity, confidentiality, and privacy controls.
- Statement of Work (SOW)Contracts
A scoped document attached to a master agreement that specifies deliverables, timeline, and price for a specific engagement.
T
- Tiered PricingPricing
A pricing model where features and limits are bundled into named tiers (Starter, Pro, Business, Enterprise).
The full multi-year cost of a software purchase, including license fees, implementation, integration, training, and switching costs.
U
- Usage-Based PricingPricing
A pricing model where the buyer pays based on consumption (events, API calls, gigabytes, transactions).
V
- Vendor OnboardingProcurement
The structured process of moving a new software vendor from contract signature to active deployment.