24 categories. 76 items. The whole evaluation, instead of the spreadsheet.
The canonical framework buyers check vendors against on the Trooth Network. Every item explains why buyers look for it. 11 items are gated Under NDA, evidence is request-only, never stored by Trooth.
24
Categories
76
Items evaluated
65
Public items
11
Under NDA
Maintained in code as the single source of truth.
01
Data Governance & Privacy
5 itemsBuyer question
What happens to my data?
Training-data prohibition
PublicWritten guarantee that customer data, prompts, and outputs are never used to train or fine-tune the vendor's models.
Data residency & localization
PublicData stays stored and processed in the jurisdictions the buyer requires (e.g. EU-only for GDPR).
Retention schedules & purging
PublicConfigurable retention with automated deletion of logs, transcripts, and temporary data.
Tenant data isolation
PublicTechnical guarantees that one customer's data can never leak into another's.
Data portability & exit rights
PublicThe right and the mechanism to export everything in standard formats when the contract ends.
02
Security & Cryptographic Standards
4 items · 1 under NDABuyer question
Is my data actually protected?
Encryption architecture
PublicAES-256 at rest and TLS 1.2/1.3 in transit with enforced cipher suites.
Customer-managed keys (CMEK)
PublicThe buyer holds the encryption keys, so ultimate data access stays with them.
Vulnerability & threat management
Under NDAIndependent penetration tests, remediation schedules, and a public bug-bounty route.
Endpoint & token security
PublicSecrets vaulted and rotated automatically so credentials never leak into code or logs.
03
Compliance, Attestations & Regulatory Frameworks
4 items · 2 under NDABuyer question
Can they prove it to my auditors?
Security certifications
Under NDASOC 2 Type II reports, ISO 27001 certification, and continuous-monitoring evidence.
Regulatory agreements (DPA)
PublicPre-signed DPAs covering GDPR, CCPA, and industry-specific regulation.
Specialized compliance
PublicBAAs for HIPAA, FINRA/SEC alignment, FedRAMP-class frameworks for public sector.
Vendor risk questionnaires
Under NDASIG and CAIQ completed promptly instead of stalling procurement for weeks.
04
Identity, Access Management & Governance
4 itemsBuyer question
Who can touch what, and how is that controlled?
Enterprise SSO on the standard plan
PublicSAML 2.0 / OIDC without forcing a plan upgrade for basic security.
Granular RBAC
PublicPermissions scoped per user, role, data source, team, or agent to shrink blast radius.
Automated user lifecycle (SCIM)
PublicJoiners and leavers provisioned and de-provisioned in real time.
Shadow AI discovery
PublicDashboards that surface unmanaged or rogue AI tools employees adopted quietly.
05
Auditability, Observability & Logging
3 itemsBuyer question
If something happens, can we reconstruct it?
Comprehensive immutable audit trails
PublicLogins, exports, admin changes, and data access, recorded and tamper-evident.
Log export APIs (SIEM)
PublicStreams into Splunk, Datadog, and the buyer's existing security tooling.
Workflow observability
PublicFull execution traces, inputs, tool calls, latency, failures, not just final outputs.
06
Infrastructure, Reliability & Performance
3 items · 1 under NDABuyer question
Will it stay up when we depend on it?
Uptime SLAs with credits
Public99.9%+ availability contractually backed by financial service credits.
Performance standards
PublicLatency thresholds and concurrency floors with remedies when degradation occurs.
Disaster recovery & redundancy
Under NDADocumented failover, geographic redundancy, high-availability architecture.
07
Integration Depth & Ecosystem Compatibility
3 itemsBuyer question
Does it fit the stack we already run?
Native connectors
PublicWorking integrations with the buyer's CRM, ERP, databases, and collaboration suite, not just an 'API available' claim.
Orchestration control
PublicDeterministic human-in-the-loop checkpoints and hard guardrails instead of purely autonomous routing.
Extensibility
PublicDocumented webhooks, REST APIs, and SDKs for the buyer's own builders.
08
Model Flexibility & Vendor Stability
3 itemsBuyer question
Are we locked in, and will this still exist next year?
Model agnosticism
PublicUnderlying models can be swapped; no lock-in to a single foundation provider.
Model deprecation policy
PublicContractual notice (90+ days) before models, versions, or APIs are retired.
Vendor viability
PublicFinancial health, capitalization transparency, and continuity planning.
09
Intellectual Property & Licensing Rights
2 itemsBuyer question
Who owns what we make with it?
IP ownership
PublicThe buyer retains ownership of fine-tuned weights, derivatives, and generated content.
IP indemnification
PublicVendor-backed protection against third-party copyright and patent claims.
10
Financial Predictability, Support & Onboarding
3 itemsBuyer question
What does it really cost, and who helps us?
Transparent pricing
PublicPredictable subscriptions or clear usage metrics with no hidden spike risk.
Layered support & success
PublicCSMs, TAMs, and committed response times for critical outages.
Structured implementation
PublicGuided onboarding and self-service resources built for immediate time-to-value.
11
AI Safety, Content Guardrails & Red Teaming
4 items · 1 under NDABuyer question
Can the AI be hijacked, and what stops bad outputs?
Prompt-injection defenses
PublicProtections that stop malicious inputs from hijacking behavior or extracting context.
Content moderation & output filtering
PublicReal-time filters for toxicity, PII leakage, and severe hallucinations.
Continuous automated red teaming
Under NDAOngoing testing against OWASP LLM Top 10 and MITRE ATLAS, not a one-off pentest.
Verifiable grounding
PublicOutputs checked against authorized sources to minimize fabrication.
12
Agentic Workflows, Tool-Use Controls & Shadow-AI Governance
4 itemsBuyer question
What are the agents allowed to do, and who approved it?
Agent discovery & registry
PublicEvery autonomous agent tracked with owner, purpose, and environment.
Granular tool-use allowlists
PublicHard limits on which tools, APIs, and actions an agent may call, with parameter bounds.
Human-in-the-loop authorization
PublicHigh-stakes operations require explicit human approval before they execute.
Identity preservation & token vaulting
PublicCredentials vaulted, never leaked into logs, with a verifiable human-to-agent link.
13
Sub-processor & Fourth-Party Risk
2 itemsBuyer question
Who ELSE touches my data underneath this vendor?
Sub-processor transparency
PublicEvery third-party vendor, cloud, and foundation-model builder disclosed with change notice.
Upstream dependency controls
PublicDefined behavior when upstream APIs go down, deprecate, or change terms.
14
Operational Resilience & Continuity Metrics
3 items · 1 under NDABuyer question
How much downtime and data loss is actually possible?
Committed RTO & RPO
PublicQuantified, contractual maximums for downtime and data loss.
DR testing frequency
Under NDAProof of how often failover is actually exercised under stress.
Infrastructure redundancy
PublicMulti-region, multi-AZ deployments with no single point of failure.
15
Financial Stability, Insurance & Corporate Risk
3 items · 3 under NDABuyer question
If they fail, or get breached, who absorbs it?
Cyber liability & E&O insurance
Under NDAConfirmed coverage for breaches, disruption, and IP claims.
Financial health & runway
Under NDAFunding status and solvency transparency to reduce disruption risk.
Customer concentration risk
Under NDAWhether revenue depends dangerously on a handful of clients.
16
Legal Remedies, Breach Notification & Audit Rights
3 items · 1 under NDABuyer question
When something goes wrong, what are we owed?
Breach notification timelines
PublicContractual obligation to notify within a fixed window (e.g. 24-48 hours).
Right-to-audit clauses
PublicThe buyer (or an independent party) may review controls and data handling.
Liability caps & indemnity scope
Under NDAClear limits and indemnification for confidentiality, data loss, and IP.
17
Accessibility, Usability & Regulatory Inclusion
3 itemsBuyer question
Can everyone on my team actually use it?
WCAG 2.1/2.2 AA compliance
PublicUsable for people with visual, auditory, motor, or cognitive disabilities.
Section 508 / public-sector mandates
PublicRequired for selling into government and education.
Assistive-technology compatibility
PublicWorks with screen readers, keyboard-only navigation, and high contrast.
18
Software Bill of Materials & Open-Source Governance
3 items · 1 under NDABuyer question
What is actually inside the software?
Machine-readable SBOMs
Under NDACycloneDX/SPDX inventories of every package and dependency, shared automatically.
License compliance auditing
PublicNo copyleft surprises (e.g. AGPL) contaminating the buyer's proprietary code.
Third-party vulnerability tracking
PublicContinuous CVE scanning of dependencies with a defined patch SLA.
19
Localization, Internationalization & Global Scale
3 itemsBuyer question
Does it work where my company works?
Multi-language & regional support
PublicLocalized UI, RTL formatting, regional dates, currencies, and numbers.
Cross-border regulatory alignment
PublicAPPI, PIPL, LGPD, PIPEDA and beyond, not just GDPR/CCPA.
Multi-currency & regional billing
PublicLocal tax, multi-currency invoicing, and compliant payment processing.
20
Environmental, Social & Governance (ESG)
3 itemsBuyer question
Does buying this align with our commitments?
Carbon footprint tracking
PublicTransparency into the energy cost of hosting and AI inference.
Data-center energy sourcing
PublicRenewable-energy commitments for the underlying infrastructure.
Corporate social responsibility
PublicLabor practices, diversity initiatives, and supply-chain sustainability disclosures.
21
Consumption Metering, Token Tracking & Billing Auditability
3 itemsBuyer question
Is the bill provably correct?
Transparent metering accuracy
PublicVerifiable token/usage tracking, no phantom inflation.
Real-time usage dashboards & caps
PublicLive consumption velocity, hard spending caps, budget alerts.
Billing dispute resolution
PublicDefined processes and credits when invoices and reality disagree.
22
Professional Services, Customization & Exit Support
3 itemsBuyer question
Who does the work, and what happens when we leave?
Implementation consulting
PublicScoped services, timelines, and dedicated solution architects.
Customization limits & guardrails
PublicClear line between configurable and custom-development territory.
Managed exit & migration support
PublicContractual transition help and data extraction when the contract ends.
23
Commercial Contracting, Payments & Supplier Onboarding
3 itemsBuyer question
Can our procurement machine actually buy this?
Procurement portal integration
PublicWorks with Coupa, SAP Ariba, Jaggaer, POs, e-invoicing, vendor master data.
Commercial payment terms
PublicNet-30/60/90, multi-year commitments, volume breaks, scheduled increments.
Supplier diversity & tax compliance
PublicMWVBE certifications and clean W-9/W-8BEN/VAT handling.
24
License Optimization, Adoption Analytics & Change Management
2 itemsBuyer question
Will the seats we buy actually get used?
Seat utilization & waste analytics
PublicDormant-account detection and automated license reclamation against shelf-ware.
Change management & enablement
PublicRollout playbooks, in-app training, and success touchpoints that drive adoption.
If you have already answered MVSP
A mapping means an MVSP answer gives you a documented starting point for a Standard item. It does not mean the item is satisfied, and Trooth marks nothing as met on the strength of it: every row says what the Standard asks for beyond the MVSP control, and the Standard items no MVSP control reaches are listed at the end rather than left out.
Mapped against MVSP v3.0-20231109. The checklist is published by The MVSP Working Group. MVSP is published by the MVSP Working Group under CC0 1.0. Control numbers and short names below are theirs; the summaries and the mapping are Trooth's, and Trooth is not part of the working group and does not speak for it.
MVSP 1.1External vulnerability reportsBusiness controls
Publish a vulnerability disclosure policy with scope, a safe harbour and a contact route.
- Security & Cryptographic Standards - Vulnerability & threat managementThe Standard also asks for independent penetration tests, a remediation schedule, and a bug-bounty route.
MVSP 1.4External testingBusiness controls
Have an external vendor penetration test the product at least annually.
- Security & Cryptographic Standards - Vulnerability & threat managementThe Standard also asks for the remediation schedule and the disclosure route, not only that a test happens.
MVSP 1.6ComplianceBusiness controls
Comply with the industry security standards relevant to the business.
- Compliance, Attestations & Regulatory Frameworks - Security certificationsThe Standard asks for the report or certificate itself and its continuous-monitoring evidence, not a statement of compliance.
MVSP 1.7Incident handlingBusiness controls
Notify relevant parties of a breach affecting sensitive information within 72 hours of discovery.
- Legal Remedies, Breach Notification & Audit Rights - Breach notification timelinesMVSP sets 72 hours from discovery; the Standard asks what the CONTRACT commits to, which is often shorter and is the enforceable one.
MVSP 1.8Data handlingBusiness controls
Sanitise media following NIST SP 800-88 or an equivalent.
- Data Governance & Privacy - Retention schedules & purgingThe Standard also asks for configurable retention and automated deletion of logs and transcripts while the service is live, not only sanitisation at end of life.
MVSP 2.1Single Sign-OnApplication design controls
Offer single sign-on over a modern standard protocol to every customer at no extra cost.
- Identity, Access Management & Governance - Enterprise SSO on the standard planMVSP already says at no additional cost, which is the whole of this item; the Standard also asks which protocols and on which plan.
MVSP 2.3Security HeadersApplication design controls
Set the security headers that reduce attack surface and limit post-exploitation.
- Security & Cryptographic Standards - Encryption architectureHeaders are one surface. The Standard asks about the encryption architecture itself: algorithms at rest, TLS versions and enforced cipher suites.
MVSP 2.6Dependency PatchingApplication design controls
Keep third-party dependencies current, prioritising security updates of medium severity and above.
- Software Bill of Materials & Open-Source Governance - Machine-readable SBOMsThe Standard asks for a machine-readable inventory a buyer can ingest, not only that dependencies are kept current.
MVSP 2.7LoggingApplication design controls
Log authentication, create/read/update/delete, configuration change and staff access to customer data, retained at least 30 days at no extra cost.
- Auditability, Observability & Logging - Comprehensive immutable audit trailsThe Standard also asks for immutability and tamper evidence, and MVSP's 30-day floor is usually far below what an audit needs.
- Auditability, Observability & Logging - Log export APIs (SIEM)MVSP asks that logs be kept. The Standard asks that the buyer can get them out, into their own SIEM.
MVSP 2.8EncryptionApplication design controls
Encrypt sensitive data in transit between systems using maintained, standard means.
- Security & Cryptographic Standards - Encryption architectureMVSP covers data in transit between systems. The Standard also asks about encryption at rest and the cipher suites enforced.
MVSP 3.1List of dataApplication implementation controls
Keep a list of the sensitive data types the application is expected to process.
- Data Governance & Privacy - Training-data prohibitionKnowing which data types are processed is the input. The Standard asks for the written guarantee that they are never used for training.
MVSP 3.2Data flow diagramApplication implementation controls
Keep a current diagram of how sensitive data reaches the systems and where it is stored.
- Data Governance & Privacy - Data residency & localizationA data flow diagram shows where data goes. The Standard asks whether the buyer can require it to stay in a named jurisdiction.
MVSP 3.3Vulnerability preventionApplication implementation controls
Train developers and hold guidelines against the named vulnerability classes, including handling untrusted data.
- AI Safety, Content Guardrails & Red Teaming - Prompt-injection defensesMVSP's untrusted-data guidance is the general form. The Standard asks specifically about prompt injection reaching model context and tool calls.
MVSP 3.4Time to fix vulnerabilitiesApplication implementation controls
Ship fixes for application vulnerabilities that materially affect security within 90 days of discovery.
- Security & Cryptographic Standards - Vulnerability & threat managementMVSP sets 90 days for material vulnerabilities. The Standard asks for the whole remediation schedule by severity.
MVSP 3.5Build and release processApplication implementation controls
Use version control and a consistent build that produces provenance describing how the artifact was built.
- Software Bill of Materials & Open-Source Governance - Machine-readable SBOMsBuild provenance is upstream of the bill of materials. The Standard asks for the inventory itself, in CycloneDX or SPDX.
MVSP 4.2Logical accessOperational controls
Limit sensitive data access to a legitimate need, authorised by the data owner.
- Identity, Access Management & Governance - Granular RBACMVSP asks that access be limited and authorised. The Standard asks how finely it can be scoped: per user, role, data source, team or agent.
- Auditability, Observability & Logging - Comprehensive immutable audit trailsThe Standard asks that staff access to customer data be recorded and tamper-evident, not only authorised.
MVSP 4.3Sub-processorsOperational controls
Keep a list of third parties with access to customer data and make it available on request.
- Sub-processor & Fourth-Party Risk - Sub-processor transparencyMVSP asks for a list on request. The Standard asks for it published, with notice before it changes.
MVSP 4.4Backup and Disaster recoveryOperational controls
Back up all data securely to a location other than where the application runs.
- Operational Resilience & Continuity Metrics - Committed RTO & RPOA backup in another location is the mechanism. The Standard asks for the committed recovery time and recovery point, which is a contractual number.
- Infrastructure, Reliability & Performance - Disaster recovery & redundancyThe Standard also asks for documented failover, geographic redundancy and a high-availability architecture.
What an MVSP answer set does not reach
60 of the Standard’s 76 items have no MVSP control against them, and 7 MVSP controls have nothing in the Standard against them. Answering MVSP is a head start on 16 of them; it is not a substitute for the rest, and Trooth does not treat it as one.
Run your next evaluation against the Standard.
Watchlists, comparison, and shortlists, free in the buyer dashboard. The method is public →