Legal & ComplianceAI & Agent WorkflowsOpen accessPublished 3 Oct 2026
Grade an AI vendor's completed security questionnaire, trust center, DPA, or security whitepaper against the ethics-opinion duties and the provider-layer facts, and produce a findings table with severity, a traffic-light score per domain, a list of contract fixes, and a go / go-with-terms / no-go recommendation. Catches "not by default" training language, zero-data-retention claims with unlisted exceptions, SOC 2 or ISO 42001 scope that doesn't cover the product, model providers missing from the sub-processor list, and silence on subpoenas and litigation holds. Use this whenever someone has a vendor's answers back, pastes a trust center or security page, asks "is this ven…