AI Product Security Baseline
A free AI security scorecard for controls, ownership, and evidence
Assess your AI security program across 14 domains, identify gaps, assign ownership, and generate a practical roadmap.
14-domain program scoring
Score your AI security program across 14 AIPSA domains with weighted program levels.
Gap identification and roadmap
Identify control and evidence gaps and generate a structured remediation roadmap.
Evidence pack generation
Generate exportable evidence packs from assessment results for buyer, audit, and board reporting.
AIPSA framework coverage
Assessment domains span the full AI Product Security Assessment framework across all 14 domains.
Why run the scorecard
Baseline the program before customers, auditors, or regulators ask.
The scorecard turns AI security into a repeatable assessment, a practical reporting system, and an evidence plan.
Create a program baseline before launch, audit, customer review, or red-team work
Identify control and evidence gaps with per-domain scoring, not a single theatrical number
Track program level over time with repeatable assessments
Generate a roadmap and evidence-pack skeleton for deeper Map, Attack, Defend, and Evidence work
Program levels
Five program levels from Ad Hoc to Adaptive.
The levels help teams explain where the program stands, what changed, and what to do next. Do not present scorecard levels as certification or proof that a product is secure.
01
Ad Hoc
0.0–1.5
02
Repeatable
1.5–2.5
03
Managed
2.5–3.5
badge eligible04
Measured
3.5–4.5
badge eligible05
Adaptive
4.5–5.0
badge eligibleAssessment packages
Choose the depth that matches the decision.
Lite for a fast signal, Standard for most teams, Deep for workshops and paid engagements. Every package runs the same scoring engine and produces the same evidence shape.
Lite
36 questionsA fast executive scan for first-pass discovery, internal alignment, or a quick posture conversation.
Standard
72 questionsA serious company baseline for product, security, governance, and engineering leaders deciding what to fix, fund, or formalize next.
Deep
132 questionsA comprehensive evidence-oriented baseline for workshops, paid engagements, launch readiness, audit preparation, and AI product security program design.
Assessment domains
Six domain groups cover the 14 underlying control areas.
The grouping is designed for readability and reporting. The underlying domains remain visible so the scorecard is easy to audit and explain.
Inventory & Architecture
3 domains
What AI systems exist, how they're connected, who controls them, and where the trust boundaries are.
Adversarial Testing
3 domains
Whether adversarial inputs, manipulation, and prompt injection are modeled, tested, and measured over time.
RAG & Data Authorization
3 domains
Whether retrieval systems enforce proper authorization, and whether data exposure is controlled end to end.
Agentic Permissions
3 domains
Whether agentic systems are constrained to the actions they need, with proper guardrails on tool use.
Detection & Incident Response
3 domains
Whether AI systems produce actionable telemetry, and whether teams can detect and respond to AI-specific incidents.
Governance Evidence
3 domains
Whether AI security is documented, auditable, and integrated into delivery — not just asserted.
Next step
Run the scorecard and turn the results into evidence.
Free. No account required. Under 30 minutes. Results available immediately.
AIPSA verification records confirm completion of a scoped assessment, lab path, or evidence review where issued. They do not certify that any product, organization, or system is free of vulnerabilities.
SECENG WORKBENCH
Ready to put AI Security Program Scorecard to work?
Scope a Workbench-backed review — we'll map the AI surfaces, identify the highest-priority gaps, and give you clear findings before any larger commitment.
Also in the Workbench
WHAT AI DO WE HAVE?
SecEng Surface Scanner
Browser, repo & IDE discovery for AI assets, vendors, and risky patterns.
WHERE CAN AI CODE BECOME AN ATTACK PATH?
SecEng Code Scanner
AI-native SAST and marketplace readiness for AI-enabled apps, agents, integrations, and managed packages.
WHAT DID IT ACTUALLY DO?
SecEng Runtime Proxy
MITM capture, replay & runtime evidence reconstruction.
HOW CAN IT FAIL UNDER ATTACK?
SecEng Adversarial Range
Scenario-driven AI red-team testing for prompts, agents, tools, RAG, and multimodal systems.
WHAT CAN AGENTS ACTUALLY DO?
SecEng Authority Graph
Agent authority, tool permissions, approval paths & delegated-action risk.
WAS RETRIEVAL AUTHORIZED?
SecEng RAG Test Harness
Test retrieval security & context authorization.
WHERE ARE THE TRUST BOUNDARIES?
SecEng Threat Canvas
Structured AI threat modeling, trust-boundary mapping, and abuse-path planning.
WHAT DO OUR PUBLIC AI CLAIMS REVEAL?
SecEng Trust Scanner
Public trust surface scoring across six AI governance dimensions.
WHERE DO TRUST BOUNDARIES LIVE IN JIRA?
Atlassian Threat Canvas
AI threat models that ship to Jira and Confluence.
DO YOUR AGENTS HAVE TOO MUCH PERMISSION?
SecEng Agent Permission Analyzer
Deterministic permission security analysis for AI agent tool configs.
WHAT'S INSIDE YOUR AI ARTIFACTS?
SecEng Artifact Analyzer
Static artifact intelligence for AI security and evidence packaging.
HOW RESILIENT IS YOUR SYSTEM TO INJECTION?
SecEng Injection Harness
Structured prompt injection probes with evidence session export.
ARE YOUR PROMPTS SECURE?
SecEng Prompt Reviewer
Deterministic rule-based scanner for system prompts and RAG corpus documents.
WHO CONTROLS WHAT MODELS CAN DO?
SecEng Model Gateway
Governed AI routing, policy enforcement, and spend control.
WHAT DOES YOUR AI SECURITY PROGRAM LOOK LIKE?
SecEng Program Blueprint Kit
Complete AI security program structure for Jira, Confluence, and Linear.
IS YOUR MODEL OUTPUT SAFE TO RENDER?
SecEng Output Safety Tester
Deterministic AI output safety analysis across 8 sink types.
WHAT CAN YOUR AI TOOLS REALLY DO?
SecEng Tool Capsule Analyzer
Analyze MCP servers, OpenAPI specifications, and AI tool definitions to understand capabilities, permissions, and attack surface.
WHERE ARE YOUR PRODUCTION PROMPTS?
SecEng Prompt Asset Scanner
Inventory and review system prompts, developer prompts, agent instructions, and prompt templates for security risks.
WHAT CAN YOUR AGENTS ACTUALLY DO?
SecEng Agent Authority Diff
Compare declared permissions with observed capabilities to identify excessive agent privileges and unsafe tool access.
WHICH AI DEPENDENCIES CHANGE RELEASE RISK?
SecEng Supply Chain Scanner
Identify AI-specific dependency, model loader, framework, and supply-chain security risks.
CAN YOU PROVE WHAT YOUR EVALS COVER?
SecEng Eval Coverage Auditor
Measure whether AI security evaluations adequately cover prompt injection, tool abuse, RAG, memory, and other critical attack classes.
ARE YOUR AI CONFIGS SAFE TO DEPLOY?
SecEng AI Config Linter
Identify AI-specific dependency, model loader, framework, and supply-chain security risks.
CAN YOU PROVE WHAT YOU'VE DONE?
SecEng Evidence Packs
Buyer-ready evidence artifacts from AI security assessment and testing.