ConsultingWorkbench-backed AI security engagements — map, attack, defend, and prove your AI systems.
Scope a Review
← AttestationsIssuedATT-AISC-2025-0488

aisecurity.llc

AI SECURITY · PRIVACY · TRUST

SECURITY REVIEW ATTESTATION

Independent Assessment · Evidence-Based · Public-Safe

A

ACME Corp

acmecorp.io

ACME Corp engaged aisecurity.llc to conduct a security review of the systems, processes, and public trust surfaces described below.

🛡️

Trust Surface Scan

End-to-end audit of public-facing trust artifacts, security disclosures, and buyer-facing evidence.

📋

AI Usage Disclosure Review

Review of AI feature disclosures, model usage statements, and customer-facing AI transparency claims.

⚖️

Privacy & Legal Document Review

Privacy policy, terms of service, data processing addendum, and cookie policy against current practice.

📎

Buyer Evidence Readiness Assessment

Security questionnaire readiness, vendor risk artifacts, and SOC 2 / ISO 27001 evidence mapping.

Systems / Features in ScopeACME Corp public trust center (acmecorp.io/security), all public legal documents, AI feature documentation, help center security disclosures, and externally referenced compliance artifacts.
Review TypeDocument review, public-surface analysis, disclosure accuracy assessment, and evidence-readiness evaluation against common enterprise security questionnaire frameworks.
Engagement IDAISC-2025-0488
Engagement PeriodApril 22, 2025May 2, 2025
Report DeliveredMay 6, 2025
86/ 100

Strong

ACME Corp's public trust surface is well-structured and demonstrates strong alignment between disclosed practices and observable artifacts. Three medium findings were identified relating to AI disclosure gaps and an outdated sub-processor reference. No high-severity gaps were found in core legal documents or security disclosures.

3Medium findings
6Low findings
9Informational

Public Trust Surface

Trust center structure, disclosure completeness, and buyer-facing evidence.

AI Transparency & Disclosure

AI usage language, model disclosure, and feature-level AI notices.

Privacy & Legal

Privacy policy, ToS, DPA, cookies, and sub-processor list.

Data Security Claims

Accuracy of encryption, retention, and access-control disclosures.

Access Control Disclosures

Disclosed access controls, SSO, MFA availability, and role descriptions.

Vendor & Sub-processor Disclosure

Sub-processor list accuracy, data flow disclosures, and DPA coverage.

Incident Response Disclosure

Breach notification language, SLA commitments, and contact paths.

Security Monitoring Claims

Logging, detection, and audit trail disclosures.