Skip to content
Fictional sample

See exactly what a UniToolx finding looks like.

This sample uses a fictional company and fictional evidence. It demonstrates structure, reasoning and deliverable quality only; it is not an assessment of any real vendor.

Fictional example: “Northstar AI” does not represent a real company. All product behavior, policies, contracts and findings below were invented to demonstrate the UniToolx methodology.
Scenario

Northstar AI: enterprise knowledge assistant

A hypothetical B2B RAG product connects to customer documents and uses third-party model providers. The vendor is preparing for enterprise security and procurement review.

  • Public website and security page
  • Privacy policy and fictional DPA
  • Subprocessor list
  • Admin documentation
  • Fictional test environment
Sample executive view

4 material findings

1 likely blocker · 2 escalations · 1 hygiene issue

Highest-friction issue: the public “never used for training” claim is broader than the contractual and subprocessor evidence supports.

The labels describe likely review friction in the fictional scenario; they are not legal or certification determinations.

Sample finding 01

Training-use claim outruns documented scope.

Buyer-facing riskA buyer can reasonably ask whether the “never” commitment covers optional telemetry, every model-provider route and every product tier.
Claim“Your data is never used to train AI models.”
Evidence checkedPrivacy policy, fictional DPA §4.2, subprocessor list, admin docs, model-provider terms supplied by the client.
ResultPartially supported. The DPA prohibits vendor training on customer content, but supplied evidence does not establish the same scope for one optional analytics path.
Likely follow-up“Does this statement apply to every provider and telemetry path, and can you point us to the binding commitment?”
Recommended actionNarrow the public claim to the evidenced scope or extend contractual/technical controls so the broader statement is accurate.
Finding 02

Retention ambiguity

Documentation says “deleted on request” but does not distinguish primary stores, logs and embeddings.

Finding 03

Model-change evidence

The vendor names its model provider but cannot show a repeatable customer-impact review before model-version changes.

Finding 04

Testing claim scope

“Red-teamed” appears in sales material, but the supplied test report covers generic web security and not the AI interaction layer.

What the client gets next

A remediation path, not just criticism.

Each finding ends with the smallest concrete change that improves answerability: wording, evidence, ownership, testing, contract language or product control.

Example 14-day remediation sequence

  1. Normalize training-use language across website, DPA and security FAQ.
  2. Document retention by data class and storage path.
  3. Assign an owner and evidence record for model-provider changes.
  4. Separate web-security testing from AI-layer testing claims.
  5. Assemble the buyer evidence index and response owners.

Want this applied to your actual product?

A public-evidence scan can start from your website alone. Private assessments can include the documents you already send to buyers.

Request an assessment