Home
AI Vendor Risk Assessment
Implementation Note
Signals
About
Home
AI Vendor Risk Assessment
Implementation Note
Signals
About
Subscribe
Sign in
AI Vendor Risk Assessment
Prompt Retention Is a Control, Not a Preference
AI vendor prompt-retention claims are not evidence-complete without data-type coverage, storage layers, deletion timing, exceptions, admin controls, and…
Jul 16
•
CodeYourCompliance
Subprocessor Lists Do Not Show the Actual AI Data Path
A subprocessor list shows who may process data. It does not show which subprocessors touch which data, feature, region, workflow, or support path.
Jul 10
•
CodeYourCompliance
1
Human Review Is a Data Exposure Path Unless It Is Bounded
Human review may support safety and support workflows, but buyers still need evidence for scope, trigger, access roles, retention, opt-out, and contract…
Jul 3
•
CodeYourCompliance
Why SOC 2 Does Not Prove the AI Vendor Data Path Is Covered
SOC 2 is useful evidence, but AI vendor risk assessment still needs product, model path, retention, support access, and use-case scope mapping.
Jun 30
•
CodeYourCompliance
Introducing the Trust Signal Directory
A public evidence directory tracking trust, security, privacy, compliance, AI governance, and enterprise-readiness signals across SaaS and AI vendors.
Jun 27
•
CodeYourCompliance
A Trust Center Is Not an AI Vendor Risk Assessment
Trust centers are useful source material, but AI vendor risk assessment still requires claim-to-evidence mapping, scope checks, buyer questions, and…
Jun 26
•
CodeYourCompliance
Vendor Says It Does Not Train on Your Data. What Evidence Should You Ask For?
A no-training claim may be true and useful, but it is not evidence-complete. AI vendor review still needs evidence on retention, logging, support…
Jun 4
•
CodeYourCompliance
AI Vendor Risk Is Not a Questionnaire Problem
A vendor can answer every question and still leave the buyer without usable evidence.
Jun 1
•
CodeYourCompliance
AI Vendor Risk Assessment: Vendor Claim Is Not Evidence
Vendor claim is not evidence. A practical AI vendor risk assessment guide for turning vendor statements into evidence requests, buyer questions, and…
May 12
•
CodeYourCompliance
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts