---
title: "How to Do a Vendor Security Review Faster with AI (2026 Checklist)"
url: https://stormap.ai/post/vendor-security-review-with-ai-checklist
category: "AI Tools"
tags: ["security review", "vendor risk", "SOC 2", "AI policy", "MCP"]
published: 2026-10-10
updated: 2026-10-10
description: "What to check in a vendor security review (SOC 2, ISO 27001, AI training on your data, subprocessors, DPA) and how to let an AI agent do the first pass."
source: Stormap (https://stormap.ai)
---

# How to Do a Vendor Security Review Faster with AI (2026 Checklist)

Every new software tool your company adopts needs a security review. Someone has to answer the same questions every time: Is the vendor SOC 2 certified? Where is our data stored? Who else touches it? And, more and more often, **will they train AI models on our data?**

Most of those answers are already published on the vendor's own website, scattered across a trust center, a privacy policy, a subprocessor list and a data processing agreement. This guide shows what to check, where to find it, and how to let an AI agent do the first pass in seconds.

## What a first-pass vendor review covers

| Question | Where vendors usually publish the answer |
|---|---|
| Which security certifications do they hold? | Trust center or `/security` page |
| Will they train AI on our data? | AI policy, trust center or privacy policy |
| Who are their subprocessors? | `/subprocessors` or `/legal/subprocessors` |
| Is there a data processing agreement (DPA)? | `/dpa` or the legal section |
| Where is data stored? | Trust center, DPA or data residency page |
| How do we report a security issue? | `/.well-known/security.txt` |
| Do they publish uptime and incidents? | `status.vendor.com` |

## The certifications that matter

- **SOC 2 Type II**: an independent auditor tested the vendor's security controls over a period of time, usually 6 to 12 months. This is the most common requirement for US software vendors. **SOC 2 Type I** only checks that controls existed on one day, so it's weaker.
- **ISO/IEC 27001**: the international standard for an information security management system. **27017** and **27018** add cloud security and cloud privacy, **27701** adds privacy management, and **42001** covers AI management systems.
- **HIPAA, PCI DSS, FedRAMP**: only relevant if you handle health data, card payments or US government data.
- **GDPR and CCPA**: privacy laws, not certifications. Vendors mention them to say they comply.

A logo on a website is a claim, not proof. For anything important, ask the vendor for the actual SOC 2 report (usually shared under NDA) or the ISO certificate.

## The AI training question

This is the newest and most common question in 2026 reviews. Read the exact wording, because vendors often draw lines like these:

- **"We do not train on customer data"**: the clearest answer.
- **Business vs. consumer plans**: many vendors don't train on business or enterprise data but may use data from free or consumer plans.
- **Opt-out**: "we may use your content to improve our models unless you opt out" means training is on by default.
- **Subprocessors**: a good policy also says the AI providers it uses (for example a model provider) are contractually barred from training on your data.

When statements conflict between pages, trust the more specific one (an AI policy or DPA) and confirm in writing.

## Subprocessors and the DPA

A **subprocessor** is any company the vendor uses that can touch your data: cloud hosting, email delivery, support tools, AI model providers. GDPR requires vendors to list them and tell you when the list changes. Check whether any subprocessor is a dealbreaker for your company, for example a provider in a country you can't send data to.

The **DPA** is the contract that covers how the vendor processes personal data on your behalf. Most B2B vendors publish a standard DPA you can sign.

## Let an AI agent do the first pass

Clicking through five pages for every vendor is slow. Stormap's free MCP server has a `vendor_trust_profile` tool that reads a vendor's public pages and returns a structured summary:

- certifications the vendor claims, with the page each claim came from
- the AI-training statement, quoted, with a link
- the subprocessor list, DPA link and data residency regions
- security features (SSO/SAML, SCIM, MFA, encryption, pen tests, bug bounty)
- `security.txt` contact, status page, and a 0–100 transparency score

Connect it to Claude Code with:

```bash
claude mcp add --transport http stormap https://stormap.ai/mcp
```

Then ask: *"Do a first-pass security review of these five vendors and flag any that might train AI on our data."* In Claude (web or desktop), add `https://stormap.ai/mcp` as a custom connector. Setup for other apps is on the [developers page](/developers).

To keep an eye on vendors after you sign, the `company_changes` tool tracks their pricing, terms, privacy and subprocessor pages and reports what changed and when.

## What an automated first pass can't do

- **It can't verify certifications.** It reports what the vendor claims. Request the audit report for anything critical.
- **It only sees public pages.** Some trust centers load with JavaScript or sit behind a login; the summary will say when it couldn't read a page.
- **It doesn't replace your questionnaire.** Use it to skip the obvious questions and focus your review on the gaps.

## Quick checklist

1. Run the first pass (by hand or with an agent).
2. Confirm SOC 2 Type II or ISO 27001 for anything that stores sensitive data.
3. Read the AI-training statement word for word, for your plan type.
4. Check the subprocessor list for dealbreakers.
5. Sign the DPA.
6. Request the SOC 2 report or certificate if the data is sensitive.
7. Watch for changes to terms, privacy policy and subprocessors after you sign.
