All tools › Operate

Vendor Intake

Read an AI vendor's paperwork before you sign, not after.

Review an AI vendor's SOC report, privacy policy and terms before signing. It flags training use of your data, unknown subprocessors, missing residency and deletion commitments, and marketing claims presented as assurance.

Using Vendor Intake needs a RiskWoven account: sign in with your email and a one-time code.

What you get

A structured review of a third party's security documents, with every concern tied to where it was found.

Concern — Subprocessor disclosure · Level: review
   "The DPA permits onward transfer to subprocessors without prior notice."
   Found at: Data Processing Agreement, clause 8.2

Documents not provided: penetration test report, business continuity plan,
insurance certificate.
   Not provided is not the same as not addressed — these were not supplied,
   so nothing about them has been assessed either way.

Illustrative extract showing the shape and depth of the output. Not captured customer work, and not a template you receive — your document is written from your own answers.

What is checked, and what is not

Checked automatically

  • Every finding must state where in the document it was found; one that cannot is kept but marked unverifiable.
  • An unrecognised concern level fails towards review, never towards none.
  • The not-provided list is built by the system. The model can add to it and can never shorten it.

Not checked: your responsibility

  • Whether the vendor does what its documents claim. This reviews what they wrote, not what they do.
  • Documents they did not send. Silence from a vendor is not evidence of good practice.
  • Whether the contract terms are acceptable to you commercially or legally.

Who it is for

Anyone signing an AI vendor contract.

Paid

  • Included with the AI Agent Governance Pack and with the Readiness Bundle + agents.

Prices in US dollars, one-time, exclusive of tax. Full detail on pricing.

Related tools

See all tools