Buzzfeed
buzzfeed.com
Detected Vendor Stack
Our Apps for Your Stack
Ticket sidebar app for scanning support replies, security responses, macros, and AI claims.
CRM card and workflow webhook for scanning sales/security claims and customer-facing AI language.
Google Chat app for scanning pasted messages and AI/security claims from Google Workspace conversations.
Google Apps Script add-on for scanning email drafts, threads, and pasted text for AI security and trust language risks.
Google Apps Script add-on for scanning Docs content, selected text, and pasted policy or vendor language for trust risks.
Google Apps Script add-on for bulk-scanning cell content, vendor responses, AI audit worksheets, and questionnaire answers.
Jira-targeted SecEng program blueprint exporter with native issue types, epics, components, and story templates.
Enterprise Onboarding
SSO / Identity Provider
Authentication features(7 available)TOTP / Authenticator AppPasskeys (WebAuthn)Magic Link / PasswordlessEncrypted Backup Codes+3 more
GitHub Signals
CI security tooling
Codebase
AI Attack Surface
api.buzzfeed.com → 172.22.80.170 (+2)
copilot.buzzfeed.com → 34.231.174.40 (+2)
lab.buzzfeed.com → 74.125.29.121
Job Posting Intelligence
Trust Scanner
0
Public Surface
0
AI Language
0
Legal Clarity
0
Security Trust
83
Consistency
100
Remediation Opportunity
Trust Scanner · ATG Scorecard
Buzzfeed · public trust surface
Public trust surface scored 13 with 33 positive detectors out of 74 across 7 pages. Higher remediation scores mean more visible work remains.
13
weak
Public Surface
Whether trust, legal, security, AI, methodology, and contact surfaces are discoverable and coherent.
0% signal
AI Language
Whether AI claims are specific, bounded, and tied to engineering evidence rather than generic positioning.
0% signal
Legal Clarity
Whether privacy, terms, contract, data-processing, and customer-facing boundaries are clear enough to review.
0% signal
Security Trust
Whether public trust artifacts explain controls, evidence, limitations, and escalation paths without oversharing.
0% signal
Consistency
Whether public claims, caveats, service language, and trust artifacts agree across the site.
83% signal
Remediation Opportunity
Whether the public surface makes the next improvement work obvious, scoped, and evidence-backed.
100% signal
Public-signal caveat
Based on public website signals and observed artifacts, not proof of any organization's internal security maturity.
Observed artifacts · 34 of 34
Top finding
highMissing Incident Communication
Document how customers are notified and where public incident updates live.
24 more findings
Missing Privacy Policy
Clarify what personal data you collect, process, retain, and disclose.
Missing Data Breach Notice
Explain how breach notification works and who is notified.
Missing Data Processing Addendum
Make the DPA request path easy to find for customers and partners.
Missing Subprocessors List
Publish a current subprocessor or vendor list with update cadence.
Missing Customer Data Training Policy
Clarify whether customer prompts, files, and outputs can train or improve models.
Missing Model Provider Disclosure
State which model or provider services are used and where customer data may flow.
Missing Model Card or System Card
Publish a model or system card if the site makes substantial AI claims.
Missing AI Evaluation or Safety Report
Provide a public evaluation or safety summary when AI claims are central.
Missing Transparency Report
Publish a public transparency report when the product makes AI capability claims.
Missing Model Limitations
Describe where the model or AI system fails, degrades, or needs human review.
Missing Feedback and Training Policy
Explain whether feedback data is reused for training or product improvement.
Trust center missing privacy policy
Link the privacy policy directly from the trust center and footer.
Missing Contact Paths
Surface public trust and support contact paths in a discoverable place.
Missing Footer Cross-links
Add footer links that make trust artifacts easy to reach.
Missing Cookie Policy
Publish cookie and tracking language with a clear consent path.
Missing Data Retention Policy
State how long data is kept and what triggers deletion or archival.
Missing Data Sharing Notice
Clarify which parties receive data and why.
Missing Cross-Border Transfers
Explain transfer mechanisms, safeguards, and processor relationships.
Missing Data Residency Policy
State where data is stored and whether region selection is supported.
Missing Acceptable Use Policy
Clarify prohibited and abusive use patterns in public-facing terms.
Missing Human Review Policy
Explain what is reviewed by humans and what remains automated.
Missing Evals and Red Teaming
Describe testing and evaluation practices that back AI claims.
Missing Prohibited Uses
State the use cases you will not support and where enforcement lives.
Missing Output Moderation Policy
Explain how outputs are filtered, blocked, or escalated.
Dimension maturity
Scanned 2026-06-24 · rules vtrust-scanner-rules.v1 · 7 artifacts probed