AI Tool Security & Privacy Checklist Pack
Don't let another tl;dv-style breach catch you off guard. Four practical checklists — pre-purchase, implementation, quarterly monitoring, and incident response — to keep your AI tools locked down.
What's inside
- Pre-Purchase Security Checklist — 15 items to vet any AI vendor before you sign up (data residency, SOC 2, audit logs, training-data opt-out, subprocessor transparency).
- Implementation Security Checklist — 10 items to lock down within 48 hours (API key rotation, MFA, SSO, zero-retention mode, tenant isolation).
- Quarterly Monitoring Checklist — 10 items to run every 90 days (key audit, access review, vendor health, compliance updates, cost anomalies).
- Incident Response Template — step-by-step playbook for the first 4 weeks after a breach or suspected data leak.
- Vendor Risk Scorecard — 10-criterion 1–5 scoring matrix to rate any AI tool as Low / Medium / High risk.
Who this is for
Solo operators, small teams, and IT admins who use AI tools in their workflow and want a repeatable process for evaluating security. Especially relevant if you handle client data, work in regulated industries, or have been bitten by a tool that "just worked" until it didn't.
Why we built this
The tl;dv breach (181K meetings exposed for 6 months due to a Firestore tenant-isolation flaw) showed that even popular, well-funded AI tools can have critical security gaps. Most teams don't have a repeatable process for evaluating AI vendor security before signing up, and most post-breach responses are ad-hoc. This pack gives you a structured, repeatable framework — the same one we use internally before recommending any tool on StigStack.