AI security self-assessment in five questions.
Free, from CWS. See where your organization stands, Crawl to Sprint, and the one move that takes you forward.
What an AI security self-assessment measures
An AI security self-assessment reads your organization's AI security across six dimensions: governance, data, prompt, model, runtime, and vendor. Each dimension maps to a named framework, so every gap traces back to a source, not a private scoring model.
Governance
AI policy, accountable owner, inventory, framework alignment.
Explore GovernanceData
Classification, controls, logging, vendor data terms, subject rights.
Explore DataPrompt
Injection testing, input validation, output filtering, OWASP LLM mapping, red-teaming.
Explore PromptModel
Selection, version control, hallucination testing, retirement, theft prevention.
Explore ModelRuntime
Rate limiting, monitoring, isolation, incident response, audit logging.
Explore RuntimeVendor
Due diligence, contracts, attestations, onboarding, continuous monitoring.
Explore VendorThe governance dimension also asks what AI coding agents and assistants are running on staff machines, what files, applications, and credentials they can reach, and how MCP servers and Skills are vetted before install. In this market, governance means agent permissions and blast radius as much as it means policy.
The four AI security maturity stages
These are maturity stages, not a compliance checklist. The Cloud Security Alliance's AI Security Maturity Model, OWASP's AI Maturity Assessment, and the SANS AI security self-assessment go deeper into each one. The Posture Check is the three minute placement that tells you which of them to pick up next.
Crawl
No sanctioned AI and no policy.
Walk
Policy and owner first, controls uneven.
Run
Controls running ahead of the program.
Sprint
Program and controls in place and audited.
You choose how your stage arrives.
Both paths give you the same result: your stage, the move to the next one, and the framework citations behind it.
By email
Your stage, from Crawl to Sprint, the one move that takes you to the next stage, and the framework citation behind every question you answered, written so you can forward it to your board.
In a live conversation
Twenty minutes with a CWS engineer who closes these gaps for a living, free. They walk through your stage, answer the question it raises, and tell you plainly whether a paid audit is worth booking yet.
Guides for the AI systems you already run
Most AI security gaps are specific to the system running them. These guides cover the systems we see most, the vendors worth shortlisting, and the industries where the stakes are highest, all mapped to the same six dimensions.
Vendor security guides
Directory
AI security vendor directory
60 vendors in 11 categories, from runtime guardrails to AI red teaming, organized so you can shortlist by what you actually need.
Compare vendors
Lakera vs Protect AI
Runtime guardrails or full-lifecycle MLSecOps: the choice depends on whether your AI is already in production.
HiddenLayer vs Robust Intelligence
Adversarial ML detection, standalone or folded into Cisco.
Microsoft Purview AI vs Prisma AIRS
Compliance-layer AI governance or network-layer AI traffic control: pick by the platform you already run.
By industry
Banking and finance
Model risk management now has an AI-shaped edge case, and OSFI and the OCC are already asking about it.
Healthcare
PHI plus AI plus regulator scrutiny. Get the controls right before HHS or your provincial commissioner asks.
Government
NIST AI RMF and Canada's Directive on Automated Decision-Making turn AI governance into a compliance deadline.
Education
Student data privacy, AI, and academic integrity are converging into one policy problem.
Legal
Privilege does not survive the prompt, and a hallucinated citation is now a sanctionable event.
The frameworks behind every question
OWASP LLM Top 10
The defining LLM-application security risk catalog. The AI Posture Check questions on prompt and runtime dimensions map directly.
Read the guideNIST AI RMF
AI Risk Management Framework. Govern, Map, Measure, Manage. Increasingly cited in US regulator guidance.
Read the guideISO 42001
International standard for AI management systems. Certifiable. Enterprise buyers increasingly ask for it.
Read the guideEU AI Act
Tiered risk obligations including high-risk system requirements. Phased enforcement through 2027.
Read the guideMITRE ATLAS
Adversary tactics and techniques against AI systems. Adversarial machine learning threat catalog.
Read the guideHow the AI Posture Check works
Answer up to five questions
Each question is chosen from what you answered before. Pick the answer closest to your reality and don't overthink it. The check only works if you answer with what is true today.
Watch your position move
Each answer moves a dot on the Posture Quadrant: program across, controls up. Hover an answer before you pick it to see where it lands.
Choose how your stage is delivered
Your stage, where you are and what moves you to the next stage, is sent to your work email or talked through live with a CWS engineer. The stage itself never shows on screen.
When you have a specific AI deployment to secure.
Beyond a self-reported stage, the Standard AI Posture Audit goes further: a senior CWS engineer reviews your named AI deployments, including prompt-injection and jailbreak testing against OWASP LLM Top 10 cases, as a scoped engagement for a fixed fee agreed on a call.
Senior-engineer paid review of your specific AI deployments.
Fixed-fee, scoped on call. When you have specific AI deployments live and need to demonstrate diligence to your board, regulator, or customers.
Share the Posture Check as a conversation starter.
If you are a reseller, distributor, or technology vendor, share the AI Posture Check with your clients as an AI readiness and governance conversation starter. CWS delivers under its own name through your relationship as the partner of record, credited to you as the referring partner throughout.
Frequently asked questions.
What is the AI Posture Check?
A free adaptive self-assessment of up to five questions that reads your AI security across six dimensions: governance, data, prompt, model, runtime, and vendor. You get your stage (Crawl, Walk, Run or Sprint), what moves you to the next one, and the framework behind each answer, delivered by email or in a live conversation with a CWS engineer.
Is the AI Posture Check a maturity model?
It is a placement on four maturity stages, not a full maturity model. Deeper instruments exist: the Cloud Security Alliance's AI Security Maturity Model, OWASP's AI Maturity Assessment, and the SANS AI security self-assessment. The Posture Check tells you which of those is worth picking up next.
How long does the Posture Check take?
A few minutes for most people. Faster if you know your environment well.
Does it ask about AI coding agents?
Yes. The governance dimension asks what AI coding agents and assistants are running on staff machines, what files, applications, and credentials they can reach, and how MCP servers and Skills are vetted before install.
What happens after I finish the assessment?
You choose how your stage is delivered: emailed to you with what moves you to the next stage, or talked through live with a CWS engineer. The stage is not shown on screen. CWS does not contact you beyond the delivery you chose.
How is the Posture Check different from a paid audit?
The free check is self-reported. A paid Standard Audit is delivered by a senior CWS engineer reviewing your actual AI deployments, including adversarial testing. The free check is calibration; the paid audit is verification.
Which frameworks does the Posture Check map to?
OWASP LLM Top 10, NIST AI RMF, ISO 42001, EU AI Act, and MITRE ATLAS. Each question you're asked cites the framework it maps to, so you can trace every gap back to its source.
Ready to find out where you stand?
Free, a few minutes, and your stage arrives the way you choose: by email, or live with a CWS engineer.