Skip to content
Methodology

Evidence before reassurance.

Our method is built around a simple rule: a material claim is only procurement-ready when its scope is clear, the supporting evidence is identifiable, and the likely buyer follow-up has a defensible answer.

Core model

Claim → Evidence → Test → Result → Buyer question → Fix

We do not score companies by marketing maturity. We trace specific representations through documents, controls and observable behavior, then record where the chain is strong, incomplete or contradictory.

Finding anatomyUTX-EV/1.0
Claim
Exact representation being assessed.
Evidence
Source and material that support the claim.
Test
Documentary or technical check actually performed.
Result
What the evidence demonstrates—and what it does not.
Action
Specific remediation or answer path.
Workflow

Six stages, one audit trail.

Scope the product and deal context

We establish the product, deployment pattern, customer data involved, target buyer and what evidence is in scope.

Build the claims inventory

We collect material representations from public pages and supplied internal/client-facing documents.

Construct the evidence graph

Each claim is mapped to documents, policies, controls, owners, providers and observable product behavior.

Challenge the chain

We look for scope mismatch, missing provenance, contradictions, unowned answers and claims that outrun their evidence.

Forecast buyer escalation

We translate gaps into the next questions a procurement, security, privacy or governance reviewer is likely to ask.

Prioritize remediation

Actions are ranked by practical deal friction and dependency, not by an invented universal compliance score.

Reference frameworks

We use recognized references without pretending they are certifications.

Depending on scope, we may use established frameworks to structure questions and test coverage. Their use does not mean UniToolx certifies conformity to them.

NIST AI RMF / GAI Profile

Useful for risk-management structure, governance, measurement and generative-AI risk considerations.

Official NIST publication →

OWASP GenAI / LLM risks

Useful when testing or questioning AI-application attack surfaces such as prompt injection, information disclosure and supply chain.

Official OWASP resource →

EU AI Act guidance

Relevant where product role, market scope or downstream documentation creates buyer questions. Legal applicability remains a matter for qualified counsel.

European Commission →
Evidence states

We separate “not found” from “does not exist.”

That distinction matters. A public scan can only conclude that evidence was not located in the reviewed sources. A private assessment can go further when the client supplies records, access and accountable owners.

Typical result labels

  • Supported: evidence matches claim and scope.
  • Partially supported: evidence covers only part of the representation.
  • Unverified: evidence was not available within scope.
  • Inconsistent: sources make materially conflicting representations.
  • Test-dependent: documentary evidence is insufficient without authorized testing.

See the method applied to a fictional AI vendor.

The sample report shows the level of traceability and the difference between a vague concern and a procurement-ready finding.

Open the sample