RedHub AIRedHub AI
Tool Gate · How it works

How the gate works

How the AI Vendor Security Posture Scrutiny gate works

This tool grades an AI vendor's security posture against six controls before you sign. It scores 6 weighted controls into a 0–100 number — then a gate that can only make the verdict worse.

The 6 weighted controls

01Independent audit evidence (SOC 2 / ISO 27001)wt 20
02Encryption & least-privilege accesswt 16
03Won't train on your data (written opt-out)gate - disqualifierwt 20
04Breach-notification SLA in the contractwt 16
05Subprocessor & LLM-chain transparencywt 12
06Deletion & exit (erasure + data return)wt 16
SOLID
score 75+
PRESS FOR PROOF
score 50+
RED FLAG
below floor
Disqualifier gate · worsen-only

Two controls are disqualifiers, not just weighted inputs: a written won't-train-on-your-data commitment and a working deletion-and-exit clause. Either one scoring 0 (Absent) forces RED FLAG regardless of the weighted score - get it in writing to release the gate.

80/100
RED FLAG

Why: Six controls score 80/100 - SOLID on the weighted math, with a current SOC 2, encryption, a breach SLA, subprocessor transparency, and a working exit clause. But the vendor has no written commitment to not train on your data - that control scored 0 (Absent). The disqualifier gate forces RED FLAG regardless of the 80 score; a vendor that trains on your data is a different risk than one that is merely thin on paperwork.

Fix firstGet a written won't-train-on-your-data commitment before you sign - it is the one Absent answer forcing RED FLAG, and no other control can offset it.

A high score didn’t save it. The score is context; the gate is the answer — and it names the one thing to fix first. Scores the vendor evidence you enter, offline. Not a security audit, legal review, or a substitute for your own contract counsel.