Vendor risk assessment
Auto-filled from the current AI Solutions Exchange implementation. Answers marked Partial or No reflect controls that are not yet built — we do not auto-fill Yes for anything we cannot demonstrate. Adjust to match your evidence requirements; the score updates instantly. This is not an independent audit.
Data protection
Is data encrypted in transit (TLS)?
Is data encrypted at rest via the managed database provider?
Is application-level authenticated encryption implemented for protected solution content?
Planned. Infrastructure-level encryption at rest applies today.
Access control
Is row-level security enabled on user-scoped tables?
Is protected content stored in a deny-by-default table with no buyer-facing policies?
Are roles stored separately and checked through a security-definer helper?
Is MFA available for accounts?
Available through the managed auth provider; org-level enforcement is planned.
Is SAML SSO available for enterprise workspaces?
Planned.
Logging
Are privileged actions written to an append-only audit log?
Can organization admins export their audit log?
Partial today; SIEM integrations planned.
API
Are API keys stored only as hashes and revocable?
Does the public manifest exclude protected implementation content?
Does protected wizard submission avoid returning raw prompt?
Assurance
Has an independent penetration test been completed?
Not commissioned yet.
SOC 2 Type II completed?
Not initiated.
ISO 27001 certified?
Not initiated.
AI risk
Are solutions analyzed for capabilities and risk before listing?
Can organizations define policies against declared solution capabilities?
Policy records and evaluation exist; enforcement across all deployment paths is partial.
Incident response
Is there a security contact for vulnerability reports?
security@aisolutions.exchange
Privacy
Are per-organization retention controls configurable?
Partial today.