AI Security Approval Advisor
Assess the security risks of AI tools and integrations in your organization.
Answer a short set of guided questions about the AI solution and how it will be deployed. Receive a clear, evidence-based security recommendation, including risks and recommended controls.
Estimated completion time: 5–8 minutes
Most assessments take approximately 5–8 minutes. More complex AI solutions may require additional security questions or verification. This excludes time spent gathering missing evidence outside the wizard. There is no time limit — take the time you need.
- 9 security risk dimensions
- Adaptive follow-up questions
- No account required to start
- Nine security risk dimensions
From data protection to vendor risk and human oversight.
- Practical examples and guided questions
Realistic situations with Copilot, ChatGPT, Notion AI and AI agents.
- Clear, explainable recommendations
Every outcome lists its reasons, required controls and evidence gaps.
Privacy: Your assessment answers are not stored. Only a sanitized recommendation can be saved with your permission.
Four steps to a security recommendation
Key question: can this AI solution be used securely, given what it can actually do, the information it can reach and the safeguards in place?
- 01Describe the AI solution
Seven quick questions on what the tool can technically do, which data it can reach and who uses it.
- 02See the real deployment scope
We assess everything users can technically do — not only the intended purpose.
- 03Answer a short questionnaire
One question per security area, with follow-ups only when needed — usually 9 to 18 questions.
- 04Get your recommendation
9 minimum requirements are checked automatically; you get a transparent, explained result.
Results are security recommendations, not binding organizational approvals. Refreshing or closing the page erases your answers.
Glossary of AI security terms
- SSO
- Single sign-on: people sign in with their company account instead of a separate password.
- MFA
- Multi-factor authentication: a second check (app, key or code) in addition to a password.
- DLP
- Data loss prevention: tools that detect or block sensitive data from leaving where it should be.
- DPA
- Data Processing Agreement: the contract that binds a vendor to protect personal data it handles for you.
- DPIA
- Data Protection Impact Assessment: a formal privacy risk review required for high-risk processing.
- GDPR
- General Data Protection Regulation: the EU's main privacy law.
- SCIM
- A standard that automatically creates and removes user accounts based on your company directory.
- SCCs
- Standard Contractual Clauses: EU-approved contract terms that make international data transfers lawful.
- OAuth
- A standard that lets an app access another service on your behalf with specific, limited permissions (scopes).
- TLS
- Transport Layer Security: encryption that protects data while it travels over a network.
- SIEM
- Security information and event management: the central platform where security logs are collected and analyzed.
- API
- Application programming interface: how software systems talk to each other.
- RBAC
- Role-based access control: permissions are given to roles, and people get roles.
- embeddings
- Number-based representations of text that AI search uses to find similar content. They can still reveal the original information.
- vector database
- A database that stores embeddings for AI search.
- prompt injection
- Hidden or malicious instructions in content (emails, documents, web pages) that try to make the AI do something unintended.
- poisoning
- Deliberately adding false or malicious data to the sources an AI learns from or retrieves.
- subprocessor
- Another company your vendor uses to deliver the service, such as a cloud or model provider.
- tenant
- Your organization's isolated space inside a shared cloud service.
- least privilege
- Giving people and systems only the access they actually need.
- SOC 2
- An independent audit report on a service provider's security controls.
- RAG
- Retrieval-augmented generation: the AI looks up relevant documents and uses them to answer.
- kill switch
- A way to stop an AI system immediately.
