Weighted domain catalog with owners, versions, mappings, and recommendation groups.
SecureAIScore measures domains, capabilities, controls, question evidence, scoring rules, and recommendation mappings in a versioned framework. The platform does not treat assessments as a simple list of questions.
Weighted domain catalog with owners, versions, mappings, and recommendation groups.
Capabilities define what each domain is expected to do operationally.
Controls are measurable implementation and assurance checkpoints.
Questions are versioned evidence prompts linked to controls and recommendations.
Profiles enable and disable domains for Personal, Team, Enterprise, Holding, and sector-specific use.
SecureAIScore evaluates domains, then capabilities within those domains, then measurable controls, then question evidence tied to each control. Scoring rules are maintained independently from question content so weights, mappings, and dependencies can change without rewriting the application.
Recommendations are linked by control and recommendation group. Framework mapping is stored on domains, controls, and questions without reproducing proprietary framework text. Methodology versions are recorded on every completed assessment snapshot so historical comparisons can detect incompatible scoring versions.
Conditional logic is supported through question dependencies. Agent Security, MCP Security, RAG Security, and Cloud AI control questions only appear when the relevant architecture or operating model is in use.
Business strategy, sponsorship, and alignment for AI security.
Policy, oversight, accountability, and exception handling for AI.
Discovery and inventory of AI services, models, assistants, and workflows.
Unmanaged or unsanctioned AI usage and bypassed controls.
Identity governance, privileged access, and machine identity for AI systems.
Role design, segregation, and access review for AI systems.
Secrets storage, token handling, and key rotation for AI integrations.
Guardrails, logging, filtering, and prompt hygiene.
Protection against prompt injection and instruction override attacks.
Model evaluation, release gating, and unsafe output control.
Retrieval boundaries, source trust, and vector protection.
Model provenance, integrity, drift, and artifact assurance.
Autonomous agent permissions, tool controls, and runtime guardrails.
Connector governance, session traceability, and Model Context Protocol controls.
Data classification, redaction, leakage prevention, and retention for AI.
Privacy handling, lawful processing, and user transparency for AI use.
Cloud deployment, isolation, and policy enforcement for AI services.
Runtime and platform infrastructure supporting AI workloads.
Event logging and trace retention for AI workflows.
Continuous monitoring, alerting, and coverage for AI systems.
AI-specific incident readiness, containment, and recovery.
Framework readiness, evidence, and regulatory obligations.
Third-party diligence, contract review, and service assurance.
Model, package, and dependency assurance across the AI supply chain.
Awareness, human misuse, and unsafe AI operating behavior.
Resilience, fallback paths, and continuity planning for AI-supported operations.