Free resource · 4-page PDF
12 questions to ask before any vendor touches your findings.
Every AI security vendor will tell you they don’t train on your data, that the model is “proprietary,” and that pricing is “simple.” None of those claims can be checked in a demo. These twelve questions can.
Trace one finding end to end. Which network hops sit outside my perimeter?
What in your architecture — not your contract — prevents you from training on my findings?
Which telemetry, prompt logs, or traces leave my environment, and who at your company can read them?
Is the model yours, or a call to someone else's API with your interface on top?
Does the model improve on my findings over time, and does that improvement stay on my hardware?
If your upstream model provider changes price, policy, or availability, what happens to my deployment?
Which tools come off my invoice on day one, and which are you only sitting on top of?
Do the pentest, the SOC alert, and the threat model share one context, or three databases behind one login?
Show me one unedited report the platform produced for a customer my size.
What is my total annual cost at 1 user and at 200 users — every module, every token?
What does the next module or feature cost after I sign?
If I stop paying, what do I keep: my data, my reports, the model weights, the hardware?
How to score it
CyberAGI’s on-prem AI security platform answers every question on this list. If you want that proven live on your own findings, we’ll walk through every one.