Evidence before reassurance.
Our method is built around a simple rule: a material claim is only procurement-ready when its scope is clear, the supporting evidence is identifiable, and the likely buyer follow-up has a defensible answer.
Claim → Evidence → Test → Result → Buyer question → Fix
We do not score companies by marketing maturity. We trace specific representations through documents, controls and observable behavior, then record where the chain is strong, incomplete or contradictory.
- Claim
- Exact representation being assessed.
- Evidence
- Source and material that support the claim.
- Test
- Documentary or technical check actually performed.
- Result
- What the evidence demonstrates—and what it does not.
- Action
- Specific remediation or answer path.
Six stages, one audit trail.
Scope the product and deal context
We establish the product, deployment pattern, customer data involved, target buyer and what evidence is in scope.
Build the claims inventory
We collect material representations from public pages and supplied internal/client-facing documents.
Construct the evidence graph
Each claim is mapped to documents, policies, controls, owners, providers and observable product behavior.
Challenge the chain
We look for scope mismatch, missing provenance, contradictions, unowned answers and claims that outrun their evidence.
Forecast buyer escalation
We translate gaps into the next questions a procurement, security, privacy or governance reviewer is likely to ask.
Prioritize remediation
Actions are ranked by practical deal friction and dependency, not by an invented universal compliance score.
We use recognized references without pretending they are certifications.
Depending on scope, we may use established frameworks to structure questions and test coverage. Their use does not mean UniToolx certifies conformity to them.
NIST AI RMF / GAI Profile
Useful for risk-management structure, governance, measurement and generative-AI risk considerations.
Official NIST publication →OWASP GenAI / LLM risks
Useful when testing or questioning AI-application attack surfaces such as prompt injection, information disclosure and supply chain.
Official OWASP resource →EU AI Act guidance
Relevant where product role, market scope or downstream documentation creates buyer questions. Legal applicability remains a matter for qualified counsel.
European Commission →We separate “not found” from “does not exist.”
That distinction matters. A public scan can only conclude that evidence was not located in the reviewed sources. A private assessment can go further when the client supplies records, access and accountable owners.
Typical result labels
- Supported: evidence matches claim and scope.
- Partially supported: evidence covers only part of the representation.
- Unverified: evidence was not available within scope.
- Inconsistent: sources make materially conflicting representations.
- Test-dependent: documentary evidence is insufficient without authorized testing.
See the method applied to a fictional AI vendor.
The sample report shows the level of traceability and the difference between a vague concern and a procurement-ready finding.