See exactly what a UniToolx finding looks like.
This sample uses a fictional company and fictional evidence. It demonstrates structure, reasoning and deliverable quality only; it is not an assessment of any real vendor.
Northstar AI: enterprise knowledge assistant
A hypothetical B2B RAG product connects to customer documents and uses third-party model providers. The vendor is preparing for enterprise security and procurement review.
- Public website and security page
- Privacy policy and fictional DPA
- Subprocessor list
- Admin documentation
- Fictional test environment
4 material findings
1 likely blocker · 2 escalations · 1 hygiene issue
Highest-friction issue: the public “never used for training” claim is broader than the contractual and subprocessor evidence supports.
The labels describe likely review friction in the fictional scenario; they are not legal or certification determinations.
Training-use claim outruns documented scope.
| Claim | “Your data is never used to train AI models.” |
|---|---|
| Evidence checked | Privacy policy, fictional DPA §4.2, subprocessor list, admin docs, model-provider terms supplied by the client. |
| Result | Partially supported. The DPA prohibits vendor training on customer content, but supplied evidence does not establish the same scope for one optional analytics path. |
| Likely follow-up | “Does this statement apply to every provider and telemetry path, and can you point us to the binding commitment?” |
| Recommended action | Narrow the public claim to the evidenced scope or extend contractual/technical controls so the broader statement is accurate. |
Retention ambiguity
Documentation says “deleted on request” but does not distinguish primary stores, logs and embeddings.
Model-change evidence
The vendor names its model provider but cannot show a repeatable customer-impact review before model-version changes.
Testing claim scope
“Red-teamed” appears in sales material, but the supplied test report covers generic web security and not the AI interaction layer.
A remediation path, not just criticism.
Each finding ends with the smallest concrete change that improves answerability: wording, evidence, ownership, testing, contract language or product control.
Example 14-day remediation sequence
- Normalize training-use language across website, DPA and security FAQ.
- Document retention by data class and storage path.
- Assign an owner and evidence record for model-provider changes.
- Separate web-security testing from AI-layer testing claims.
- Assemble the buyer evidence index and response owners.
Want this applied to your actual product?
A public-evidence scan can start from your website alone. Private assessments can include the documents you already send to buyers.