Procurement infrastructure for third-party AI
An independent record of what an AI vendor actually does.
Verdict runs adversarial security assessments of AI vendors on behalf of the enterprises evaluating them — not the vendors themselves. Findings are written for procurement, CISOs, and AI governance teams making a go/no-go call.
No vendor funding. No pay-to-play tiers. No findings softened for accounts under review.
The spine of the practice
Independence is structural, not promised.
Every AI vendor claims to be secure. Few procurement teams have the standing to test that claim without a stake in the answer. Verdict does not sell to model vendors, does not accept fees contingent on outcome, and does not license findings back to the vendor under review. The distance is built into how the practice is funded, staffed, and governed — not asserted in a sales deck.
Funding
Revenue comes from the enterprises commissioning an assessment — never from the vendors being assessed, directly or through referral arrangements.
Staffing
Assessors hold no equity, advisory seat, or paid consulting relationship with any vendor currently or previously under review.
Governance
A completed verdict is not shared with the vendor for approval or softening before it reaches the commissioning organization.
How an assessment is built
Five stages, the same order, every time.
Consistency of process is what makes one assessment comparable to the next. Nothing in the sequence below is negotiated per engagement.
-
01
Scope definition
The model, deployment surface, integration points, and data paths under review are fixed at the outset, set by the commissioning organization's own risk profile — not by what the vendor prefers to show.
-
02
Adversarial testing
Structured red-teaming against the model and its integration surface: prompt injection, jailbreak resistance, data exfiltration paths, and resistance to abuse under sustained, deliberate pressure.
-
03
Documentation & control review
The vendor's stated data handling, retention, sub-processor, and access-control practices are checked against what testing actually observed — not against the vendor's own description of itself.
-
04
Independent verdict
Findings are compiled into a plain verdict: what was tested, what held, and what did not. Written without vendor input, and without adjusting tone for the size of the account.
-
05
Ledger entry
The assessment is recorded to the audit ledger — dated, scoped, and retained for the life of the vendor relationship so it can be re-checked against a later re-assessment.
Where an assessment lands
The audit ledger.
Every completed assessment closes with a ledger entry — an engraved record, not a marketing artifact. The format is fixed so two entries, from two different vendors, can be compared on the same terms.
A ledger entry is not a badge or a score. It is a dated statement of what was in scope, how long testing ran, that no financial relationship existed with the vendor under review, and where the verdict currently stands.
The entry is retained by Verdict and made available to the commissioning organization's procurement and governance counsel for as long as the vendor relationship continues — so the record can be checked again at renewal, not just at signing.
Right: specimen — ledger entry format, not a completed assessment
Ledger Entry
Specimen format
- Scope
- Model, API surface, and named sub-processors as defined at engagement start.
- Window
- Fixed testing period, dated on open and on close.
- Attestation
- Signed statement of no financial relationship with the vendor under review.
- Status
- Recorded to ledger; available to the commissioning organization and its governance counsel.
Scope of review
What gets assessed.
An assessment is scoped to the deployment in front of the commissioning organization, not to a generic checklist. These are the domains most engagements draw from.
01 • Behavior
Model behavior & alignment
Whether the model behaves as documented under adversarial and edge-case prompting, not just under demo conditions.
02 • Resistance
Prompt injection & jailbreak resistance
Resistance to instruction override via direct prompting and indirect injection through retrieved content.
03 • Data
Data handling & retention
What is retained, for how long, under whose jurisdiction, and whether that matches what the vendor discloses.
04 • Supply chain
Sub-processor disclosure
Which downstream model and infrastructure providers actually touch the data, beyond the primary vendor's name.
05 • Access
Access control & key management
How credentials, API keys, and administrative access are scoped, rotated, and revoked.
06 • Response
Incident response posture
What happens, and who is notified, when something goes wrong — tested against the vendor's own stated process.
Bring verdict into procurement
An assessment is built to sit inside the process you already run.
Use it as a required artifact before a contract is signed, or as a periodic re-assessment once a vendor is in production. Governance, CISO, and procurement teams can request an assessment directly.