Vendor Security Eval

Standardized security / risk evaluation of a dev or AI vendor against org policy — data flow diagram, SIG (Standardized Information Gathering) Lite/Full responses, SOC 2 Type 2 review, ISO 27001 review, model training opt-out terms, breach history (public + private disclosure), TPRM-file readiness scorecard. Produces a structured pre-procurement evaluation note the TPRM team can use as input to their formal process. Composes with ai-coding-tools-compare (broad comparison) and compliance-framework-lookup (specific control questions). Use before any new dev/AI vendor moves to formal TPRM intake.

themarmack ee73dc7 6.2 KB Updated

File contents

themarmack/research-bot/tree/main/.claude/skills/vendor-security-eval commit ee73dc7b8a

Frequently asked questions

npx skillmds@latest add themarmack/vendor-security-eval