AI agent security posture check
Ten questions covering what enterprise security teams actually ask AI agent vendors — data handling, tool access, logging, human oversight, adversarial testing. Instant score, instant gap list, and a report you can share with your team. Nothing stored, no email required.
1.Do you run adversarial tests (prompt injection, jailbreaks) against your agent before releases?
2.Do you filter agent outputs for secrets, credentials, and system-prompt content?
3.Are your agent's tools scoped to least privilege with an explicit allowlist?
4.Do you have a written AI incident response plan?
5.Are users clearly told they're interacting with an AI?
6.Could you reconstruct exactly what the agent did in any past incident from your logs?
7.Do you disclose whether customer data is used for model training — and honor opt-outs?
8.Is there a working path for the agent to hand off to a human?
9.Do you monitor production agent behavior with alerting on anomalies?
10.Do you have SOC 2 (any type)?
Not part of AIUC-1 — but procurement treats it as the floor.
Early warning: test a real questionnaire
Paste a few questions from a past (or upcoming) security review. See instantly which ones map to a structured control — and which would send you scrambling. Runs entirely in your browser; nothing is sent anywhere.