Five minutes. A real answer on your AI security posture.
Answer 12 questions about your environment. Get a scored readiness report mapped to BOD 26-04's four-variable model and the AI Defense Matrix's 8 AI-specific asset classes — from agent identities to training data to the AI-generated code already in your repos. No email required to see your score. No vendor sponsorship influences results.
What this assessment covers.
Four questions mapped to the four variables of CISA BOD 26-04's prioritization model: KEV Status (how you monitor the Known Exploited Vulnerabilities catalog), Asset Exposure (per-asset internet exposure), Exploit Automation (whether a flaw can be exploited at machine speed), and Technical Impact (forensic triage before patching). Also referenced: FedRAMP VDR/VER, CISA Vulnrichment, and FIRST's EPSS.
Eight questions, one per asset class of the AI Defense Matrix, each scored as its own category bar in your results:
Each asset class is cross-mapped to NIST CSF 2.0, the NIST AI Risk Management Framework, MITRE ATLAS, and the OWASP LLM and Agentic Security Top 10s.
A 0–100 score with a maturity label, a per-domain and per-asset-class breakdown, and your three weakest answers written up as gaps with the framework requirement each one maps to. A full PDF report covering all twelve findings is available afterward, and partner matching is optional.
One question at a time. Your score at the end.
You can move backward and forward freely. "Don't know" is a valid answer — it scores as zero and surfaces as a gap, which is more useful than a guess.
Download your PDF report.
Every finding across all twelve questions, scored and mapped to the frameworks above. It downloads straight to this device — we don't email it, and nothing else is sent.
Want hands-on help closing these gaps?
Tell us which areas matter most — we've pre-selected your weakest domains — and we'll introduce you to a vetted partner. No cost, no obligation.
How scoring works — and who doesn't influence it.
Scoring is published openly: 12 questions, each scored 0–3, normalized to 0–100. Each of the 12 questions carries equal weight toward your overall score. Because Security for AI spans eight distinct asset classes against four for Vulnerability Response Readiness, it also carries more weight in your total — reflecting how much of the AI-era threat surface these questions actually cover. Vendors cannot pay to alter the logic, the questions, or the gap-to-category mappings.
Built on public frameworks — CISA BOD 26-04, FedRAMP VDR/VER, MITRE ATLAS — and the AI Defense Matrix's 8 asset classes, each cross-mapped to NIST CSF 2.0, MITRE ATLAS, and the OWASP LLM and Agentic Security Top 10s.