AI Product Security Baseline
A free AI security scorecard for controls, ownership, and evidence
Assess your AI security program across 14 domains, identify gaps, assign ownership, and generate a practical roadmap.
14-domain program scoring
Score your AI security program across 14 AIPSA domains with weighted program levels.
Gap identification and roadmap
Identify control and evidence gaps and generate a structured remediation roadmap.
Evidence pack generation
Generate exportable evidence packs from assessment results for buyer, audit, and board reporting.
AIPSA framework coverage
Assessment domains span the full AI Product Security Assessment framework across all 14 domains.
Why run the scorecard
Baseline the program before customers, auditors, or regulators ask.
The scorecard turns AI security into a repeatable assessment, a practical reporting system, and an evidence plan.
Create a program baseline before launch, audit, customer review, or red-team work
Identify control and evidence gaps with per-domain scoring, not a single theatrical number
Track program level over time with repeatable assessments
Generate a roadmap and evidence-pack skeleton for deeper Map, Attack, Defend, and Evidence work
Program levels
Five program levels from Ad Hoc to Adaptive.
The levels help teams explain where the program stands, what changed, and what to do next. Do not present scorecard levels as certification or proof that a product is secure.
01
Ad Hoc
0.0–1.5
02
Repeatable
1.5–2.5
03
Managed
2.5–3.5
badge eligible04
Measured
3.5–4.5
badge eligible05
Adaptive
4.5–5.0
badge eligibleAssessment packages
Choose the depth that matches the decision.
Lite for a fast signal, Standard for most teams, Deep for workshops and paid engagements. Every package runs the same scoring engine and produces the same evidence shape.
Lite
36 questionsA fast executive scan for first-pass discovery, internal alignment, or a quick posture conversation.
Standard
72 questionsA serious company baseline for product, security, governance, and engineering leaders deciding what to fix, fund, or formalize next.
Deep
132 questionsA comprehensive evidence-oriented baseline for workshops, paid engagements, launch readiness, audit preparation, and AI product security program design.
Assessment domains
Six domain groups cover the 14 underlying control areas.
The grouping is designed for readability and reporting. The underlying domains remain visible so the scorecard is easy to audit and explain.
Inventory & Architecture
3 domains
What AI systems exist, how they're connected, who controls them, and where the trust boundaries are.
Adversarial Testing
3 domains
Whether adversarial inputs, manipulation, and prompt injection are modeled, tested, and measured over time.
RAG & Data Authorization
3 domains
Whether retrieval systems enforce proper authorization, and whether data exposure is controlled end to end.
Agentic Permissions
3 domains
Whether agentic systems are constrained to the actions they need, with proper guardrails on tool use.
Detection & Incident Response
3 domains
Whether AI systems produce actionable telemetry, and whether teams can detect and respond to AI-specific incidents.
Governance Evidence
3 domains
Whether AI security is documented, auditable, and integrated into delivery — not just asserted.
Next step
Run the scorecard and turn the results into evidence.
Free. No account required. Under 30 minutes. Results available immediately.
Need an expert-reviewed baseline?
The public scorecard gives you the signal. The AI Security Program Baseline turns that signal into reviewed gaps, ownership decisions, evidence requirements, and a prioritized 30/60/90 execution roadmap.
AIPSA verification records confirm completion of a scoped assessment, lab path, or evidence review where issued. They do not certify that any product, organization, or system is free of vulnerabilities.
Delivery & licensing
Available through the model that fits the product outcome.
Expert-led engagement
We run the AI Security Program Baseline directly, with reviewed gaps and a prioritized roadmap.
Bounded partner pilot
One organization's 14-domain baseline is scored and returned as a representative report.
OEM or licensed capability
The domain-scoring methodology and roadmap logic can operate behind a partner's own GRC, platform, or benchmarking product.
Accepts
Domain-level self-assessment responses across the 14 AIPSA domains.
Returns
Per-domain maturity scores, an evidence-pack skeleton, and a roadmap.
Current maturity
Fixture-tested
AI SECURITY WORKBENCH
Ready to put AI Security Program Scorecard to work?
Start with one bounded application, workflow, tool set, or security decision. Use the relevant Workbench experience to produce connected context, reviewable findings, assigned controls, and explicit next steps.
Continue through the Workbench
Previous MADE stage
Runtime Trace
Capture and reconstruction of prompts, retrieval, model calls, identities, approvals, tools, outputs, and side effects.
Related experience
Eval Coverage Auditor
Measure whether AI security evaluations adequately cover prompt injection, tool abuse, RAG, memory, and other critical attack classes.
OEM & partner
OEM Engine
Embed selected Workbench capabilities through bounded APIs, SDKs, and lifecycle contracts.