skip to content

Product wants an 80% per-call price cut on your model API — what does that hand a cloner?

level: principalimportance: nice to knowfreq 26%

answer

  1. you publish one column of their ledger
  2. cutting price divides only one side
  3. price moves resale and nothing else
  4. the loss is margin, not a breach
  5. supply a number and a trigger, not a veto

basics

~10 s

It divides one side of a copier's build-or-steal ledger by five while leaving their honest alternative untouched, so an endpoint nobody would copy at the old price can start paying for itself.

solid answer

~50 s

A per-call price is one of only two numbers in an adversary's build-or-steal ledger, and it is the one you control and publish. Cutting it by 80% divides the steal column by five and moves nothing on the honest-build side, so an endpoint that was safely uneconomic to copy can cross into paying for itself. What you owe the decision is a re-run of the sum at the new price, stated per motive and with units: which motive newly crosses, roughly how long a reseller would take to recoup, and what the loss actually looks like — margin surrendered to a competitor, not a breach. Be equally clear about what price does not touch: an adversary who wants a stand-in to attack you with, or answers about the data, is already funded at almost any price. And say plainly that you are not vetoing a pricing decision. Security supplies the number and the trigger; the business chooses.

go deeper

for a junior

Understand that the price you charge per call is what an outsider multiplies by their call count. Lowering it lowers their bill without changing what it would cost them to build honestly.

for a middle

Explain why a cut moves only one column of the comparison, and why the attractiveness of an endpoint is the gap between the two columns rather than the level of the price.

for a senior

Bring a re-run ledger to the discussion: query spend at a named fidelity, the honest-build column with its label line, and whether the ordering flips. A qualitative worry with no units will be ignored.

for a principal

Own the split between advising and vetoing. Supply the number, the motive it moves, the loss in commercial terms and a review trigger, and be willing to say a cut is fine when the honest-build column is already small.

## Why this lands on your desk at all An adversary deciding whether to copy your model by querying it runs a two-column comparison: total query spend for the fidelity they need, against acquiring and labelling a comparable corpus plus a training run. **You set and publish one of those two numbers.** That is the only sense in which price per call is a security parameter, and it is a real one: an 80% cut divides the steal column by five and leaves the honest-build column exactly where it was. A competitor's analyst is running this arithmetic off your public price list right now. Your pricing page is the published half of somebody else's ledger. ## What you owe the decision Four things, and they are all numbers or triggers, not objections. **1. The crossing, re-priced.** Re-run the sum at the new price. State the query spend at a *named* fidelity target — the level a reseller in your segment actually needs, which is normally well below matching you — and put it beside the honest-build column with its label line broken out. Say whether the ordering flips. **2. The motive it flips, and the two it does not.** Price moves the resale motive, because that is the only one where both routes end in the same deliverable and money decides. It does not move an adversary who wants a rough stand-in to craft inputs against your production model: that copy is cheap at any price and pays off in effect, not margin. It does not move an adversary using the endpoint as an oracle about the data behind it. Saying "the price cut increases extraction risk" without that split is the sloppy version of this answer. **3. The loss, described honestly.** If a reseller does cross, the outcome is a competitor selling comparable capability at a lower price, trailing your quality and your data refresh. That is margin erosion with a rough time-to-recoup, and it belongs in the same currency as the revenue the price cut is meant to win. It is not a breach, no records leave, and calling it one destroys your credibility in the room where the decision is actually made. **4. A trigger.** The crossing point depends on two prices: yours, and the going rate for the labour that produced your corpus. Say when the estimate gets re-run. ## What you do not get to do Veto. A price is a business instrument and security does not own it. The failure mode here is a qualitative worry — "this makes us easier to steal" — offered with no ledger, which is unanswerable and therefore ignored, and which spends credibility you will want later. The other failure mode is arguing that the price must stay high *as a control*. Holding a price above the market to deter copying is a permanent revenue cost paid to address one motive, and the market will eventually take the decision away from you anyway. If the crossing genuinely matters, the interesting responses are structural rather than a price floor: whether the capability should be sold per call at that price at all, or whether the durable moat is the continuously refreshed corpus and the service around it rather than a snapshot of weights that can be approximated. What specific controls actually bind a determined copier, as against merely raising their bill, is a separate discussion with its own answer. ## When you should not object Be willing to say the cut is fine, and mean it. Two cases: - **The honest-build column is already small.** A commodity task with good public labelled corpora means nobody saves anything by copying you. Price can go to almost nothing without creating a resale motive that was not already there. - **The product is not the weights.** If what customers buy is a service that keeps improving on data that keeps arriving, a snapshot copy trails from the day it is taken and degrades. The clone's ceiling is your behaviour at query time, mistakes included, on the distribution they paid to cover. An analyst who objects to every price cut is not doing threat modelling, they are performing caution. ## What defending the number looks like Expect pushback from both directions, and prepare for both. Engineering will say the model is too good to be approximated from labels; the answer is that the copier does not need to match you, only to clear their own customers' bar on a narrow slice. Finance will say nobody would spend that much on queries; the answer is the ratio between the columns and the payback period, in their units. If you cannot state the sum in currency, with the fidelity assumption written down, you do not have a finding — you have a feeling.

  • If the crossing point does move, who decides what happens?
    The business does. Security owns the ledger and the consequence statement; pricing is a commercial instrument. Frame the finding as expected margin loss with a rough payback period so it competes on equal terms with the revenue the cut is meant to win, rather than as a security objection that has to be argued down.
  • What would make you raise no objection to the cut at all?
    An honest-build column that is already small, because good public corpora exist for the task and copying saves nobody anything. Or a product whose value is a continuously refreshed service rather than a frozen set of weights, so a snapshot copy trails from day one. In both cases price barely moves the ordering.
  • How do you answer an engineer who insists the model is too good to approximate from labels?
    By pointing out that the copier is not trying to match you. They buy the cheap early stretch of the fidelity curve on the narrow slice they intend to sell, and stop where their own customers stop complaining. Your tail quality is exactly the part they decline to pay for.
  • Should you argue for keeping the price high as a control?
    Rarely. A price floor held for security is a permanent revenue cost aimed at one motive, and competitive pressure will remove it eventually anyway. If the crossing truly matters, the structural questions are better: whether to sell this capability per call at all, and whether the moat should be the refreshed corpus and service rather than a copyable snapshot.

saying these in an interview costs you the question

  • Vetoes a pricing decision on security grounds alone
  • Calls a resale clone a breach or a data leak
  • Assumes price movement affects every attacker motive
  • Brings a qualitative worry with no ledger or units
  • Forgets the adversary reads the same public price list
  • Proposes a permanent price floor as the control

context