SAIS
SecureAIScore™
Assess. Download. Improve.
HomeAssessBenchmarkMethodologyPricingResources
Assess
AssessmentReportsAssessment Methodology
Intelligence
BenchmarkVendorsAI HubRadar
Methodology
MethodologyRoadmapRegulationsKnowledge GraphArchitecture Designer
Company
CompanyAboutMissionVisionWhy SecureAIScore™ContactFAQPrivacy PolicyTerms of ServiceCookie PolicyResources
Resources
ResearchDocumentationRelease NotesBlogRoadmap
LoginGet My SecureAIScore™
SAIS
SecureAIScore™
Assess. Download. Improve.

Executive-ready AI Security Assessment for teams that need clear scores, trustworthy reports, and a clean path from insight to action.

Release 18.7
Product
  • Assessment
  • Benchmark
  • Methodology
  • Pricing
  • Workspace
Company
  • Company
  • About
  • Contact
  • FAQ
  • Roadmap
Legal
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Release Notes
  • Documentation
For Yourself. For Your Team. For Your Enterprise.
© 2026 SecureAIScore™. All rights reserved.
SecureAIScore™ Methodology

The structured methodology behind every assessment

SecureAIScore measures domains, capabilities, controls, question evidence, scoring rules, and recommendation mappings in a versioned framework. The platform does not treat assessments as a simple list of questions.

v1.0Assess. Download. Improve.Versioned and maintainable content engine
Open Question Library
Domains
26

Weighted domain catalog with owners, versions, mappings, and recommendation groups.

Capabilities
26

Capabilities define what each domain is expected to do operationally.

Controls
26

Controls are measurable implementation and assurance checkpoints.

Questions
31

Questions are versioned evidence prompts linked to controls and recommendations.

Profiles
5

Profiles enable and disable domains for Personal, Team, Enterprise, Holding, and sector-specific use.

How It Works

SecureAIScore evaluates domains, then capabilities within those domains, then measurable controls, then question evidence tied to each control. Scoring rules are maintained independently from question content so weights, mappings, and dependencies can change without rewriting the application.

Recommendations are linked by control and recommendation group. Framework mapping is stored on domains, controls, and questions without reproducing proprietary framework text. Methodology versions are recorded on every completed assessment snapshot so historical comparisons can detect incompatible scoring versions.

Conditional logic is supported through question dependencies. Agent Security, MCP Security, RAG Security, and Cloud AI control questions only appear when the relevant architecture or operating model is in use.

Validation Report
Generated at Jul 25, 2026, 3:51 PM
Warnings
0
Errors
0
No methodology integrity issues were detected for this version.
Question Bank Checks
7/7 passed
Domain Catalog

AI Strategy

Weight 5

Business strategy, sponsorship, and alignment for AI security.

Owner: Executive Risk
Version: v1.0
Question count: 1
NIST AI RMFISO/IEC 42001

AI Governance

Weight 8

Policy, oversight, accountability, and exception handling for AI.

Owner: Governance Office
Version: v1.0
Question count: 2
NIST AI RMFISO/IEC 42001EU AI Act

AI Inventory

Weight 5

Discovery and inventory of AI services, models, assistants, and workflows.

Owner: Enterprise Architecture
Version: v1.0
Question count: 1
NIST AI RMFISO 27001

Shadow AI

Weight 4

Unmanaged or unsanctioned AI usage and bypassed controls.

Owner: Security Operations
Version: v1.0
Question count: 1
NIST AI RMFOWASP LLM Top 10

Identity

Weight 8

Identity governance, privileged access, and machine identity for AI systems.

Owner: IAM Team
Version: v1.0
Question count: 1
ISO 27001NIST AI RMF

Access Management

Weight 6

Role design, segregation, and access review for AI systems.

Owner: IAM Team
Version: v1.0
Question count: 1
ISO 27001NIST AI RMF

Secrets

Weight 6

Secrets storage, token handling, and key rotation for AI integrations.

Owner: Platform Security
Version: v1.0
Question count: 1
ISO 27001CSA AI Controls

Prompt Security

Weight 7

Guardrails, logging, filtering, and prompt hygiene.

Owner: AI Platform Security
Version: v1.0
Question count: 1
OWASP LLM Top 10MITRE ATLAS

Prompt Injection

Weight 7

Protection against prompt injection and instruction override attacks.

Owner: AI Platform Security
Version: v1.0
Question count: 1
OWASP LLM Top 10MITRE ATLAS

LLM Security

Weight 7

Model evaluation, release gating, and unsafe output control.

Owner: AI Engineering
Version: v1.0
Question count: 1
OWASP LLM Top 10MITRE ATLAS

RAG Security

Weight 6

Retrieval boundaries, source trust, and vector protection.

Owner: AI Engineering
Version: v1.0
Question count: 2
OWASP LLM Top 10CSA AI Controls

Model Security

Weight 7

Model provenance, integrity, drift, and artifact assurance.

Owner: ML Platform
Version: v1.0
Question count: 1
MITRE ATLASCSA AI Controls

Agent Security

Weight 6

Autonomous agent permissions, tool controls, and runtime guardrails.

Owner: AI Platform Security
Version: v1.0
Question count: 2
OWASP LLM Top 10MITRE ATLAS

MCP Security

Weight 5

Connector governance, session traceability, and Model Context Protocol controls.

Owner: Platform Engineering
Version: v1.0
Question count: 2
NIST AI RMFISO 27001

Data Protection

Weight 8

Data classification, redaction, leakage prevention, and retention for AI.

Owner: Data Security
Version: v1.0
Question count: 1
ISO 27001EU AI ActCSA AI Controls

Privacy

Weight 5

Privacy handling, lawful processing, and user transparency for AI use.

Owner: Privacy Office
Version: v1.0
Question count: 1
EU AI ActISO/IEC 42001

Cloud AI

Weight 4

Cloud deployment, isolation, and policy enforcement for AI services.

Owner: Cloud Security
Version: v1.0
Question count: 2
CSA AI ControlsISO 27001

Infrastructure

Weight 4

Runtime and platform infrastructure supporting AI workloads.

Owner: Infrastructure Security
Version: v1.0
Question count: 1
CSA AI ControlsISO 27001

Logging

Weight 5

Event logging and trace retention for AI workflows.

Owner: Security Operations
Version: v1.0
Question count: 1
NIST AI RMFISO 27001

Monitoring

Weight 6

Continuous monitoring, alerting, and coverage for AI systems.

Owner: Security Operations
Version: v1.0
Question count: 1
NIST AI RMFMITRE ATLASISO 27001

Incident Response

Weight 4

AI-specific incident readiness, containment, and recovery.

Owner: Security Operations
Version: v1.0
Question count: 1
NIST AI RMFMITRE ATLASISO 27001

Compliance

Weight 3

Framework readiness, evidence, and regulatory obligations.

Owner: Compliance Office
Version: v1.0
Question count: 1
NIST AI RMFISO/IEC 42001ISO 27001EU AI Act

Third-Party AI

Weight 4

Third-party diligence, contract review, and service assurance.

Owner: Procurement Security
Version: v1.0
Question count: 1
ISO/IEC 42001CSA AI ControlsEU AI Act

Supply Chain

Weight 4

Model, package, and dependency assurance across the AI supply chain.

Owner: Product Security
Version: v1.0
Question count: 1
MITRE ATLASCSA AI ControlsISO 27001

Human Risk

Weight 3

Awareness, human misuse, and unsafe AI operating behavior.

Owner: Security Awareness
Version: v1.0
Question count: 1
NIST AI RMFISO/IEC 42001

Business Continuity

Weight 3

Resilience, fallback paths, and continuity planning for AI-supported operations.

Owner: Business Resilience
Version: v1.0
Question count: 1
ISO 27001NIST AI RMF
Capability Model
Operating Model
Executive ownership, planning, and AI security sponsorship.
Policy Governance
Policies, exception handling, and review cadence.
Asset Discovery
Discovery and inventory coverage for AI usage.
Shadow AI Detection
Policy enforcement and detection of unsanctioned use.
Identity Governance
Identity controls for human and non-human AI access.
Access Review
Role design and periodic access review.
Secret Lifecycle
Storage, rotation, and brokered secret use.
Prompt Validation
Input, output, and guardrail control for prompts.
Prompt Firewall
Prompt injection prevention and response validation.
LLM Evaluation
Behavioral testing, gating, and content safety.
Retrieval Boundary
Source trust and retrieval segmentation.
Model Assurance
Model integrity and release control.
Agent Governance
Action limits and runtime enforcement for agents.
Connector Governance
Connector approval, allow lists, and session traceability.
Control Model
Executive sponsorship established
AI security strategy has an accountable executive sponsor.
Recommendation groups: AI Strategy, AI Governance
Policy review and exception process
AI policy, exceptions, and review cadence are documented.
Recommendation groups: AI Governance, Compliance
AI asset inventory coverage
AI services and workflows are inventoried and reviewed.
Recommendation groups: AI Inventory
Shadow AI policy enforcement
Unsanctioned AI usage is detected and remediated.
Recommendation groups: Training & Awareness, AI Governance
Identity governance for AI systems
Human and machine identities are governed for AI use.
Recommendation groups: Identity & Access Management
Access review and least privilege
Access to AI systems is reviewed and limited by role.
Recommendation groups: Identity & Access Management
Secrets lifecycle management
Secrets for AI integrations are stored, rotated, and monitored.
Recommendation groups: Secrets Management, AI Gateway
Prompt guardrails and logging
Prompt inputs and outputs are filtered, reviewed, and logged.
Recommendation groups: Prompt Security
Prompt injection prevention
Prompt injection attacks are prevented, detected, and triaged.
Recommendation groups: Prompt Injection Protection
LLM evaluation and safety gating
Models are evaluated and gated before production release.
Recommendation groups: LLM Security, Content Safety
RAG trust boundary control
Retrieved context is segmented, validated, and monitored.
Recommendation groups: RAG Security
Model integrity and provenance assurance
Models, artifacts, and updates are verified and monitored.
Recommendation groups: LLM Security, Supply Chain Security
Agent runtime action governance
Agent permissions, approval steps, and runtime actions are constrained.
Recommendation groups: Agent Security, AI Gateway
Connector and session governance
MCP connectors are approved, traced, and policy-controlled.
Recommendation groups: MCP Security, Logging & Monitoring