Tool Gate · How it works
How the AI Vendor Security Posture Scrutiny Kit gate works
How the AI Vendor Security Posture Scrutiny Kit scores a vendor's 6 security controls to 100: a disqualifier gate forces RED FLAG when the vendor won't commit in writing to not training on your data — which is how a vendor scoring 80, reading SOLID, still reads RED FLAG.
How the gate works
This tool grades an AI vendor's security posture against six controls before you sign. Each control is marked from your own evidence and weighted into a 0–100 score — and then the score is run past a gate that can only make the verdict worse.
The 6 weighted controls
| Signal | Weight |
|---|---|
| Independent audit evidence (SOC 2 / ISO 27001) | 20 |
| Encryption & least-privilege access | 16 |
| Won't train on your data (written opt-out) | 20 |
| Breach-notification SLA in the contract | 16 |
| Subprocessor & LLM-chain transparency | 12 |
| Deletion & exit (erasure + data return) | 16 |
| Total | 100 |
The verdict bands
Two controls are disqualifiers, not just weighted inputs: a written won't-train-on-your-data commitment and a working deletion-and-exit clause. Either one scoring 0 (Absent) forces RED FLAG regardless of the weighted score - get it in writing to release the gate.
In the worked sample it scores 80 out of 100 and still reads RED FLAG — Six controls score 80/100 - SOLID on the weighted math, with a current SOC 2, encryption, a breach SLA, subprocessor transparency, and a working exit clause. But the vendor has no written commitment to not train on your data - that control scored 0 (Absent). The disqualifier gate forces RED FLAG regardless of the 80 score; a vendor that trains on your data is a different risk than one that is merely thin on paperwork. The one thing to fix first: Get a written won't-train-on-your-data commitment before you sign - it is the one Absent answer forcing RED FLAG, and no other control can offset it..
Common questions
Can something score well on the How the AI Vendor Security Posture Scrutiny gate works and still fail?
Yes. The weighted score is run past a worsen-only gate — the Disqualifier gate — that can only make the verdict worse. In the worked sample it scores 80 out of 100 and still reads RED FLAG, because six controls score 80/100 - SOLID on the weighted math, with a current SOC 2, encryption, a breach SLA, subprocessor transparency, and a working exit clause. But the vendor has no written commitment to not train on your data - that control scored 0 (Absent). The disqualifier gate forces RED FLAG regardless of the 80 score; a vendor that trains on your data is a different risk than one that is merely thin on paperwork.
What is a worsen-only gate?
A dispositive rule that can only lower a verdict, never raise it. One fatal flaw overrides an otherwise-good score, because a single disqualifying gap shouldn't hide behind a high average. The tool also names the one thing to fix first — here, "Get a written won't-train-on-your-data commitment before you sign - it is the one Absent answer forcing RED FLAG, and no other control can offset it.".
Scores the vendor evidence you enter, offline. Not a security audit, legal review, or a substitute for your own contract counsel.
Embed this diagram
Free to share and embed with attribution (CC BY 4.0) — keep the link to redhub.ai.
Interactive — renders the live diagram
<iframe src="https://redhub.ai/visuals/tool/ai-vendor-security-posture-scrutiny-kit.html" title="How the AI Vendor Security Posture Scrutiny Kit gate works — RedHub AI" width="760" height="1726" loading="lazy" style="border:0;width:100%;max-width:760px"></iframe>
<p style="font:14px/1.5 system-ui,sans-serif"><a href="https://redhub.ai/visuals/tool/ai-vendor-security-posture-scrutiny-kit">How the AI Vendor Security Posture Scrutiny Kit gate works</a> — by <a href="https://redhub.ai">RedHub AI</a>, the AI that tells you when to doubt it.</p>Image + link — a static picture for any blog
<a href="https://redhub.ai/visuals/tool/ai-vendor-security-posture-scrutiny-kit"><img src="https://redhub.ai/visuals/tool/ai-vendor-security-posture-scrutiny-kit-share.png" alt="Diagram of the AI Vendor Security Posture Scrutiny Kit: six security controls scoring 80 and a disqualifier gate forcing RED FLAG on a vendor that won't opt out of training on your data." width="760" loading="lazy" style="max-width:100%;height:auto;border-radius:16px"></a>
<p style="font:14px/1.5 system-ui,sans-serif"><a href="https://redhub.ai">RedHub AI</a> — the AI that tells you when to doubt it.</p>This is how AI Vendor Security Posture Scrutiny Kit works. More diagrams in the Visual Field Guide.