To assess an AI vendor, trace what happens to your data in the exact service and configuration you plan to use, verify the relevant security evidence, and make key promises enforceable in the contract. A certification or framework alignment can help organize the review, but neither proves how every product handles your data.
Start with the use case, not the vendor logo
Write down what the AI service will do, who could be affected, which data classes it will handle, and the consequences of exposure, misuse, or an outage. Identify whether the company you are evaluating is the application provider, model provider, integration layer, or a subprocessor. One product may involve several of these roles.
This supply-chain view is consistent with NIST’s supplier due-diligence guidance for information and communications technology (ICT) suppliers. NIST describes due diligence as “the investigative process of researching all available, pertinent information about a given supplier or product so that informed decisions can be made on new acquisitions or existing systems.” Its guidance includes provenance, resilience, foundational cybersecurity practices, supply-chain tiers, and foreign ownership, control, or influence where relevant. NIST SP 1326
NIST’s Generative AI Profile adds AI-specific concerns, including intellectual property, privacy, security, embedded AI dependencies, ongoing monitoring, and checking incident or vulnerability information. These are voluntary risk-management resources, not a certification that a supplier is safe for every purpose. NIST Generative AI Profile
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
- A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
- FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
- Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
- Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
- Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.
Map every path your data can take
Ask the vendor for a current data-flow diagram for the service and deployment you are considering. It should cover prompts, uploaded files, generated outputs, logs, telemetry, support access, backups, and any feedback or fine-tuning process. Include the model services and subprocessors downstream of the vendor.
For each category of information, get specific answers to these questions:
- What is collected, and for what stated purpose?
- Where is it processed and stored, and which staff or service providers can access it?
- How long is it retained? Does the period differ for logs, backups, or support records?
- Is it used for model training, evaluation, product improvement, or any other secondary purpose?
- What does deletion cover, when does it happen, and what happens to backups or derived artifacts?
- Which subprocessors or embedded model providers receive it, and how will you learn about changes?
Do not treat “we do not train on your data” as a complete answer until the vendor defines “your data,” the services and data types covered, the relevant account settings, and any exceptions. The same care applies to “deleted”: establish what is deleted, on what schedule, and whether copies in backups or derived materials are included.
Check whether the security evidence covers this service
Request current security and privacy materials that match the specific product, deployment, account tier, and processing involved. Depending on what the vendor has, this may include independent audit reports or certifications, scope statements, architecture and data-protection descriptions, access-control practices, vulnerability management, incident response commitments, retention and deletion controls, and subprocessor disclosures.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Rank #2
- Hardware-Rooted Security with PUF Technology – PUFido Drive Clife Key uses Physical Unclonable Function technology to generate a unique, hardware-based identity that cannot be duplicated, delivering stronger resistance against tampering and cyber attacks than conventional security keys.
- FIDO2 Certified Phishing-Resistant Protection – Fully compliant with FIDO2/U2F standards, enabling secure passwordless login and two-factor authentication to help protect accounts from phishing and credential theft.
- Security Key + Flash Drive in One Device – Combines a FIDO security key with a built-in USB flash drive, allowing you to carry files and a hardware authentication key together in a single compact device.
- Easy to Use & Portable – Compact USB-C design fits easily on a keychain or in a pocket. Simply plug in the Drive Clife Key to authenticate or access stored files with no extra software required.
- Universal Compatibility – Works with hundreds of FIDO2/U2F compatible services and supports Windows, macOS, Linux, iOS, Android, and other major platforms.
Read the scope and boundaries, not just the report name. Check the reporting period, exceptions, systems included, and whether the AI service and data processing you plan to use are actually covered. A report about a vendor’s corporate environment may not establish that a particular model service, integration, or configuration is in scope.
A SOC 2 report, certification, or framework mapping can provide useful evidence about specified controls within a defined scope. It does not by itself answer whether your prompts are retained or used for training, whether privacy obligations are met, or how the model behaves. Ask for separate, direct evidence on those questions. NIST’s GAI Profile also recommends assessing suppliers against incident and vulnerability information and continuing to monitor third-party risks. NIST Generative AI Profile
Examine dependencies, provenance, and resilience
Ask who owns or controls the supplier when that is material to your risk assessment, what major models and components the service depends on, and how the vendor tracks changes to them. Find out what happens if a model or cloud provider becomes unavailable, changes its terms, or discontinues service. Ask whether there is a tested fallback and what it would mean for your data and users.
NIST’s supplier guidance identifies provenance, resilience, foundational cyber practices, and supply-chain tiers as due-diligence considerations; its GAI guidance also points to over-reliance on third-party data and the need to document fallbacks. These questions matter most when the service is central to an operation, handles sensitive information, or has few practical substitutes. NIST SP 1326 NIST Generative AI Profile
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesRank #3
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Put data promises into the contract
Translate broad statements such as “no training” or “we delete your data” into terms that identify covered services, data, and purposes. NIST recommends that contracts and service-level agreements (SLAs) address content ownership, usage rights, quality standards, security requirements, and provenance expectations, and allow evaluation of third-party GAI processes and standards. NIST AI RMF Playbook
Depending on your use case and applicable law, negotiate clear terms for:
- Permitted uses of prompts, files, outputs, logs, and feedback, including training, evaluation, and product improvement.
- Retention periods and deletion timing and scope, including how backups and derived artifacts are handled.
- Subprocessor obligations, disclosure, and notice or approval when material providers or processing arrangements change.
- Security requirements, incident notification and cooperation, and access to relevant assurance evidence.
- Evaluation or audit rights, and what evidence the vendor will provide to demonstrate compliance.
- Export, transition, and termination mechanics, including how your data is returned or deleted.
Review standard terms for secondary-use rights, broad exceptions, unexpected liability effects, and restrictions that could make a promised audit or exit right unusable. NIST’s GAI Profile flags risks from non-standard contract terms and unauthorized secondary use of data, and recommends contingency and incident-response planning for third-party systems. NIST Generative AI Profile Have qualified counsel review obligations that depend on your jurisdiction, industry, data, or intended use.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Compare vendors on evidence, not slogans
Use the same questions for each candidate and score answers against your use case. A simple comparison can make gaps visible; “not stated” means the vendor has not provided a comparable answer, not that the control is absent.
Rank #4
- Dual USB-A and USB-C Security Key – Features both USB-A and USB-C connectors for seamless compatibility across desktops, laptops, and tablets. Supports plug-and-stay use or keychain carry.
- NFC-Enabled for Mobile Access – Built-in NFC allows fast, wireless authentication with Android and iPhone devices. Ideal for mobile logins and on-the-go security.
- FIDO Certified for Strong Authentication – [CHECK COMPATIBILITY before purchase] Fully compliant with FIDO2 and FIDO U2F standards. Works with major platforms like Google, Microsoft, GitHub, and Dropbox.
- Passwordless Login with PinPlex – Supports secure passkey login via WebAuthn and CTAP2 with added protection from PinPlex, a complex PIN system that enhances physical security.
- Multi-Layer Authentication Support – Includes PIV certificates and supports both TOTP and HOTP for strong 2FA/MFA coverage across enterprise and consumer apps.
| Assessment area | What to compare |
|---|---|
| Data use | Minimization, permitted purposes, training and other secondary use |
| Retention and location | Retention by data type, deletion scope and timing, processing and storage locations |
| Dependencies | Visibility into subprocessors, embedded models, and change notices |
| Assurance evidence | Recency, report period, exceptions, and whether the specific service is in scope |
| Security operations | Access controls, encryption descriptions, vulnerability management, incident practices |
| Contract rights | Audit or evaluation access, notification, cooperation, export, and termination terms |
| Resilience and fit | Fallback options and whether the service’s risks suit the intended use |
Do not assume every category deserves equal weight. NIST’s AI Risk Management Framework is voluntary, and NIST says it is being revised; check its current status before relying on it operationally. NIST also cautions that trustworthiness characteristics need to be balanced in context. NIST AI Risk Management Framework NIST AI RMF 1.0: Trustworthy and Responsible AI As NIST puts it, “The decision to commission or deploy an AI system should be based on a contextual assessment of trustworthiness characteristics and the relative risks, impacts, costs, and benefits, and informed by a broad set of interested parties.” NIST AI RMF 1.0: Trustworthy and Responsible AI
Keep reviewing after launch
Supplier due diligence is not a one-time procurement exercise. Keep an inventory of third parties with access to organizational content and set a review cadence based on the service’s risk. Reassess when a material change could alter the original decision, such as:
- A new model provider, subprocessor, or data category.
- A change to retention, training, or other data-use policy.
- A security incident, relevant vulnerability, or material audit exception.
- An acquisition, ownership change, or significant change in the intended use.
- A change in the importance of the service or the consequences of its failure.
Maintain an incident-response plan for the service, document third-party AI incidents, and test fallback arrangements rather than assuming they will work. NIST’s GAI Profile recommends continuous monitoring and contingency planning for third-party GAI systems. NIST Generative AI Profile
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

