You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Assessors Studio operationalizes CycloneDX Attestations (CDXA): perform assessments, collect evidence, make claims, and issue machine-readable CycloneDX attestations, optionally legally binding for B2B and B2G use cases.
A complete third-party vendor security risk-assessment framework — questionnaire, live scoring engine, and worked vendor assessments with approve/conditions/reject recommendations. Two-axis inherent×control residual-risk model mapped to NIST 800-161, ISO 27001 & SOC 2.
AI Governance portfolio case study assessing a high-risk automated loan underwriting system using VerifyWise, EU AI Act, NIST AI RMF, and ISO/IEC 42001 concepts.
Turn a vendor security questionnaire spreadsheet into a first-pass draft, citing your own security docs for every answer and never inventing a control you do not have.
AI Governance portfolio case study assessing a high-risk automated loan underwriting system using VerifyWise, EU AI Act, NIST AI RMF, and ISO/IEC 42001 concepts.
Turns vendor security documentation into a preliminary third-party AI risk assessment — cited evidence, deterministic risk scoring, and NIST AI RMF mapping, with prompt-injection screening on untrusted vendor PDFs.
Five Claude Skills for SaaS compliance workflows: security questionnaires, SOC 2 readiness, vendor risk, audit evidence, and trust page audits. Contract-validated in CI.
Standardized diligence for third-party AI systems: vendor intake, test battery (red-team + fairness + lineage), risk score, and go/no-go written into the model governance registry
Seven GRC artifacts — risk register, SOC 2 readiness walkthrough, vendor risk assessment, NIST CSF 2.0 ↔ ISO 27001 ↔ SOC 2 crosswalk, policy set, and a program self-assessment report — built against a real client engagement, with 94 citations checked against primary sources.
Three-part AI vendor governance pack: due diligence questionnaire, SOW/operational requirements, and contract clause checklist — covers NIST AI RMF, ISO 42001, cybersecurity, forensics, and agentic AI controls