Start AI Cincy Home

Free · 5 minutes · no email gate

How ready is your AI product for a buyer security review?

Check 14 evidence signals across seven domains. You’ll get an immediate readiness score and the three gaps most likely to slow a buyer review.

Answers stay in this browserNot a certificationBuilt for small AI vendors

Your evidence inventory

Choose the answer you could defend today.

“Documented” means the claim is current and you can point a buyer to supporting evidence.

0 of 14 checked
01Scope and ownershipWe document intended uses, prohibited uses, users, and the decisions our AI must not make.
02Scope and ownershipNamed people own product, security, privacy, and AI-risk decisions with a clear escalation path.
03Customer dataWe can trace customer data through our app, model providers, logs, support tools, and subprocessors.
04Customer dataRetention, deletion, and model-training practices are documented by data type and provider.
05Models and providersA current register lists each production model, provider, purpose, owner, and customer-facing feature.
06Models and providersModel and provider changes follow review, regression testing, rollback, and customer-notice rules.
07Access and actionsAccess to prompts, outputs, logs, and configuration is role-limited, logged, and reviewed.
08Access and actionsAI tools and actions have explicit permissions, validation, limits, and human confirmation where needed.
09Testing and oversightPre-release tests cover representative tasks, failure cases, prompt injection, and acceptance thresholds.
10Testing and oversightWe define when a person must review, approve, correct, or reverse an AI-assisted outcome.
11Monitoring and incidentsProduction monitoring covers security events, misuse, quality drift, tool failures, and customer reports.
12Monitoring and incidentsOur incident plan includes AI-specific triage, containment, evidence preservation, and notification.
13Evidence and claimsImportant security and AI claims link to dated policies, configurations, tests, contracts, or records.
14Evidence and claimsKnown gaps are labeled planned, unknown, or not applicable with an owner and target date.

No answers are uploaded or saved by Start AI Cincy.

What the score means

Evidence readiness is not the same as security assurance.

This self-assessment does not test your controls, certify compliance, or predict a buyer’s decision. It helps expose where your current claims are undocumented, incomplete, or difficult to reuse.

Need the questions behind the score? Use the 25-question AI vendor security guide and its editable CSV template.