PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

AI Product Security Baseline

A free AI security scorecard for controls, ownership, and evidence

Assess your AI security program across 14 domains, identify gaps, assign ownership, and generate a practical roadmap.

WHERE DOES YOUR PROGRAM STAND?

14-domain program scoring

Score your AI security program across 14 AIPSA domains with weighted program levels.

Gap identification and roadmap

Identify control and evidence gaps and generate a structured remediation roadmap.

Evidence pack generation

Generate exportable evidence packs from assessment results for buyer, audit, and board reporting.

AIPSA framework coverage

Assessment domains span the full AI Product Security Assessment framework across all 14 domains.

AI Security Program Scorecard — 14-domain scoring dashboard with maturity levels and evidence pack generation

Why run the scorecard

Baseline the program before customers, auditors, or regulators ask.

The scorecard turns AI security into a repeatable assessment, a practical reporting system, and an evidence plan.

Create a program baseline before launch, audit, customer review, or red-team work

Identify control and evidence gaps with per-domain scoring, not a single theatrical number

Track program level over time with repeatable assessments

Generate a roadmap and evidence-pack skeleton for deeper Map, Attack, Defend, and Evidence work

Program levels

Five program levels from Ad Hoc to Adaptive.

The levels help teams explain where the program stands, what changed, and what to do next. Do not present scorecard levels as certification or proof that a product is secure.

01

Ad Hoc

0.01.5

02

Repeatable

1.52.5

03

Managed

2.53.5

badge eligible

04

Measured

3.54.5

badge eligible

05

Adaptive

4.55.0

badge eligible

Assessment packages

Choose the depth that matches the decision.

Lite for a fast signal, Standard for most teams, Deep for workshops and paid engagements. Every package runs the same scoring engine and produces the same evidence shape.

Lite

36 questions

A fast executive scan for first-pass discovery, internal alignment, or a quick posture conversation.

~12 minWebsite baseline, first call preparation, event follow-up, or initial consulting triage.

Standard

72 questions

A serious company baseline for product, security, governance, and engineering leaders deciding what to fix, fund, or formalize next.

~35 minConsulting intake, security architecture review prep, product security baseline, AI launch readiness, or customer assurance preparation.

Deep

132 questions

A comprehensive evidence-oriented baseline for workshops, paid engagements, launch readiness, audit preparation, and AI product security program design.

~75 minAI product security challenge, red-team preparation, audit-readiness engineering, maturity roadmap, and security leadership planning.

Assessment domains

Six domain groups cover the 14 underlying control areas.

The grouping is designed for readability and reporting. The underlying domains remain visible so the scorecard is easy to audit and explain.

Inventory & Architecture

3 domains

What AI systems exist, how they're connected, who controls them, and where the trust boundaries are.

InventoryArchitecture & Trust BoundariesModel & Provider Risk

Adversarial Testing

3 domains

Whether adversarial inputs, manipulation, and prompt injection are modeled, tested, and measured over time.

Threat ModelingPrompt InjectionEvaluation & Regression Testing

RAG & Data Authorization

3 domains

Whether retrieval systems enforce proper authorization, and whether data exposure is controlled end to end.

RAG AuthorizationData Exposure & PrivacyAI Supply Chain

Agentic Permissions

3 domains

Whether agentic systems are constrained to the actions they need, with proper guardrails on tool use.

Agentic PermissionsTool AuthorizationWorkflow Boundaries

Detection & Incident Response

3 domains

Whether AI systems produce actionable telemetry, and whether teams can detect and respond to AI-specific incidents.

Logging & TelemetryDetection EngineeringIncident Response

Governance Evidence

3 domains

Whether AI security is documented, auditable, and integrated into delivery — not just asserted.

Governance EvidenceCustomer TrustSecure AI SDLC

Next step

Run the scorecard and turn the results into evidence.

Free. No account required. Under 30 minutes. Results available immediately.

Need an expert-reviewed baseline?

The public scorecard gives you the signal. The AI Security Program Baseline turns that signal into reviewed gaps, ownership decisions, evidence requirements, and a prioritized 30/60/90 execution roadmap.

AIPSA verification records confirm completion of a scoped assessment, lab path, or evidence review where issued. They do not certify that any product, organization, or system is free of vulnerabilities.

Delivery & licensing

Available through the model that fits the product outcome.

Expert-led engagement

We run the AI Security Program Baseline directly, with reviewed gaps and a prioritized roadmap.

Bounded partner pilot

One organization's 14-domain baseline is scored and returned as a representative report.

OEM or licensed capability

The domain-scoring methodology and roadmap logic can operate behind a partner's own GRC, platform, or benchmarking product.

Accepts

Domain-level self-assessment responses across the 14 AIPSA domains.

Returns

Per-domain maturity scores, an evidence-pack skeleton, and a roadmap.

Current maturity

Fixture-tested

Explore Partner Interoperability

AI SECURITY WORKBENCH

Ready to put AI Security Program Scorecard to work?

Start with one bounded application, workflow, tool set, or security decision. Use the relevant Workbench experience to produce connected context, reviewable findings, assigned controls, and explicit next steps.