Vendor Risk & Agreements
Vendor Scorecard
After evaluating a vendor, assign one of three ratings in each domain:
RED ZONE – Unacceptable / Ethical Violation Risk:
- Vendor serves adversarial parties (police/prosecution) in the same jurisdiction or provides technology that creates a structural Rule 1.7 conflict.
- Vendor reuses client data to 'improve products.'
- No guaranteed, rapid breach notice timeline or forensic cooperation.
- No guaranteed right to full data export or destruction.
- Vendor refuses to contractually agree to resist or appeal compelled disclosure.
YELLOW ZONE – Borderline / Needs Mitigation:
- Vendor claims to protect data but allows some ambiguous 'service improvement' use of uploads.
- Vendor uses third-party AI without clearly banning training on privileged defense content.
- Vendor provides security controls but not clear audit log access or subpoena notice.
- You can proceed only if you negotiate protective contract language.
GREEN ZONE – Meets Duties with Documented Safeguards:
- Vendor explicitly bars training AI on your data without written opt-in.
- Vendor contractually segregates defender data from law enforcement.
- Vendor commits to timely breach notice with detail and cooperation (24-48 hours maximum).
- Vendor gives you audit logs, subprocessor transparency, export rights, and certified deletion.
- Vendor commits to resisting compelled disclosure on your behalf.
Suggested Procurement Rule
- A single RED in any domain, especially Rule 1.7 Conflict/Alignment, blocks purchase or forces immediate rejection/withdrawal.
- Three or more YELLOWs require a written mitigation plan and leadership sign-off.
- GREEN across all domains indicates the vendor is structured to satisfy confidentiality, loyalty, supervision, and breach duties.