Westbroek IT Security
Westbroek IT Security · AI risk assessment

AI Security Approval Advisor

Assess the security risks of AI tools and integrations in your organization.

Answer a short set of guided questions about the AI solution and how it will be deployed. Receive a clear, evidence-based security recommendation, including risks and recommended controls.

Estimated completion time: 5–8 minutes

Most assessments take approximately 5–8 minutes. More complex AI solutions may require additional security questions or verification. This excludes time spent gathering missing evidence outside the wizard. There is no time limit — take the time you need.

  • 9 security risk dimensions
  • Adaptive follow-up questions
  • No account required to start
How Does It Work?
  • Nine security risk dimensions

    From data protection to vendor risk and human oversight.

  • Practical examples and guided questions

    Realistic situations with Copilot, ChatGPT, Notion AI and AI agents.

  • Clear, explainable recommendations

    Every outcome lists its reasons, required controls and evidence gaps.

Privacy: Your assessment answers are not stored. Only a sanitized recommendation can be saved with your permission.

How it works

Four steps to a security recommendation

Key question: can this AI solution be used securely, given what it can actually do, the information it can reach and the safeguards in place?

  1. 01
    Describe the AI solution

    Seven quick questions on what the tool can technically do, which data it can reach and who uses it.

  2. 02
    See the real deployment scope

    We assess everything users can technically do — not only the intended purpose.

  3. 03
    Answer a short questionnaire

    One question per security area, with follow-ups only when needed — usually 9 to 18 questions.

  4. 04
    Get your recommendation

    9 minimum requirements are checked automatically; you get a transparent, explained result.

Results are security recommendations, not binding organizational approvals. Refreshing or closing the page erases your answers.

Glossary of AI security terms
SSO
Single sign-on: people sign in with their company account instead of a separate password.
MFA
Multi-factor authentication: a second check (app, key or code) in addition to a password.
DLP
Data loss prevention: tools that detect or block sensitive data from leaving where it should be.
DPA
Data Processing Agreement: the contract that binds a vendor to protect personal data it handles for you.
DPIA
Data Protection Impact Assessment: a formal privacy risk review required for high-risk processing.
GDPR
General Data Protection Regulation: the EU's main privacy law.
SCIM
A standard that automatically creates and removes user accounts based on your company directory.
SCCs
Standard Contractual Clauses: EU-approved contract terms that make international data transfers lawful.
OAuth
A standard that lets an app access another service on your behalf with specific, limited permissions (scopes).
TLS
Transport Layer Security: encryption that protects data while it travels over a network.
SIEM
Security information and event management: the central platform where security logs are collected and analyzed.
API
Application programming interface: how software systems talk to each other.
RBAC
Role-based access control: permissions are given to roles, and people get roles.
embeddings
Number-based representations of text that AI search uses to find similar content. They can still reveal the original information.
vector database
A database that stores embeddings for AI search.
prompt injection
Hidden or malicious instructions in content (emails, documents, web pages) that try to make the AI do something unintended.
poisoning
Deliberately adding false or malicious data to the sources an AI learns from or retrieves.
subprocessor
Another company your vendor uses to deliver the service, such as a cloud or model provider.
tenant
Your organization's isolated space inside a shared cloud service.
least privilege
Giving people and systems only the access they actually need.
SOC 2
An independent audit report on a service provider's security controls.
RAG
Retrieval-augmented generation: the AI looks up relevant documents and uses them to answer.
kill switch
A way to stop an AI system immediately.