Intelligence that protects your business

Assess AI vendor risk. With confidence.

Certifications checked at the source, security and governance measured, risks quantified and a client-ready report.

NovaMente Tecnologia · Customer service assistant
ISO/IEC 27001✓ IAF CertSearch
Environment security58 / 100
AI governance71 / 100
Risk criticality44 · 2 high
VerdictApproved with conditions
Alignment
NIST AI RMF 1.0Govern · Map · Measure · Manage
SOC 2AICPA Trust Services Criteria
BacenRes. CMN 4.893 · Res. BCB 85
OWASP Top 10 for LLMPrompt injection, disclosure, excessive agency
The numbers

One yardstick, grounded in international standards

47+controls across 12 domains
14quantified AI risks
13frameworks, standards and laws
What you receive

Reports ready to present

Scorecard

NovaMente · Customer service assistant

58Environment security
71AI governance
44Risk criticality
ISO/IEC 27001✓ IAF CertSearch
VerdictApproved with conditions
Scorecard1 page · to share with customers
Due diligence report

AI customer service assistant

NovaMente Tecnologia · 2026
Score per domain
Governance63
Access83
Data58
App and model38
Infra75
Risk matrix
4 critical
1 high
9 moderate
Due diligence report15 to 20 pages · scores, risks and findings
Action plan

Prioritized findings

P1Mandatory MFA on privileged access30 days
P1Prompt injection defenses30 days
P2Model card and change control90 days
P3Bias testing per group180 days
Action planP1 to P3 priorities with deadlines
ScorecardDue diligence reportHighlightsBenchmarkRating details
Who it is for

Buy with confidence or prove your maturity.

Buyers

Mitigate AI vendor risk

  • The same yardstick for every vendor
  • A verdict ready for risk, legal and privacy
  • Contracts conditional on the action plan
Book a demo
Vendors

Get assessed once

  • One scorecard for all customers
  • Gaps before the customer finds them
  • Progress tracked at every reassessment
Request an assessment
Methodology

Based on international frameworks

Standards

  • ISO/IEC 27001:2022
  • ISO/IEC 42001:2023
  • ISO/IEC 23894
  • ISO/IEC 27701

Frameworks

  • NIST AI RMF 1.0
  • NIST CSF 2.0
  • SOC 2 (AICPA TSC)
  • OWASP Top 10 for LLM
  • MITRE ATLAS

Regulation

  • EU AI Act
  • LGPD
  • GDPR
  • Brazilian Bill 2338/2023
  • Central Bank of Brazil: Res. CMN 4,893 and BCB 85
NIST AI RMF 1.0ISO/IEC 27001 + 42001IAF CertSearch
Book a demo

See SoAITrust assess a real vendor

30 minutes, with a sample AI system.

Book a demo