Which compliance frameworks does the scanner cover?
The scanner evaluates a vendor across seven frameworks: SOC 2 (Trust Services Criteria), HIPAA Security Rule, NIST CSF, ISO 27001 Annex A, PCI-DSS v4, CMMC 2.0, and GDPR Article 32 security obligations. Each framework is scored separately so you can see exactly where a vendor passes and where they fall short.
How long does a vendor scan take?
Most scans complete in about 90 seconds once you submit a vendor domain. The full PDF report is generated and emailed to your inbox within a few minutes after that, so you can review findings the same day rather than waiting on a slow questionnaire cycle.
What does the $19 report contain?
You receive a PDF with a 0–100 risk score, per-framework pass/fail breakdown, the specific controls the vendor appears to meet or miss, and the highest-leverage remediation questions to send the vendor next. The report is yours to keep and is suitable for vendor review files, internal risk registers, and procurement sign-off packets.
Who is the $19 vendor scanner for?
It is built for security and compliance leads at startups and mid-market companies who need to triage vendors quickly without spinning up an account or paying enterprise platform fees. Typical buyers run it before signing a new SaaS contract, during annual vendor reviews, and as a first pass on vendors flagged by procurement.
How does AIComplianceNav compare to Vanta or Drata?
Vanta and Drata are continuous compliance platforms designed for companies getting their own SOC 2 — great when you need an in-house control program, but they cost hundreds to thousands per month and require onboarding your stack. AIComplianceNav is the opposite trade-off: one $19 scan per vendor, no platform to deploy, and the report is delivered in minutes. Use us when you need to assess a third party, not certify your own house.
Do I need an account or login to run a scan?
No account is required. You enter the vendor domain and a work email for the report delivery, pay $19 through Stripe checkout, and the report lands in your inbox. We do not require you to sign up, install software, or share internal credentials.
What input does the scanner need and how is the vendor assessed?
The only input is the vendor's public domain. Our AI engine reviews the vendor's external security signals — public documentation, trust pages, security disclosures, certifications claimed, breach disclosures, and observed posture — then evaluates those signals against the controls in each covered framework. No questionnaires are sent to the vendor and no internal access is required.
How is the AI vendor risk score calculated?
The score is a weighted blend of three factors: whether the vendor publishes evidence for the relevant framework controls, whether the controls align with the vendor's actual data handling, and whether there are public signals of gaps or incidents. The output is a 0–100 score plus a per-framework breakdown so you can see exactly which controls drove the rating.
Does the report replace a formal SOC 2 or HIPAA audit?
No. The scanner gives you a fast, evidence-based triage of the vendor's controls based on public signals. It is intended as pre-screening and procurement-grade due diligence, not a substitute for a full SOC 2 Type II audit, a HIPAA Security Rule risk analysis performed by the covered entity, or a formal attestation. Use it to decide whether deeper diligence is warranted.
Is the scanner suitable for GDPR and ISO 27001 vendor reviews too?
Yes. GDPR Article 32 requires controllers and processors to verify that vendor safeguards are appropriate, and ISO 27001 Annex A.15 covers supplier relationships. The scanner maps its findings to both frameworks so you have the language to cite either standard when documenting a vendor review.