Review 01
System and data scope
Identify the AI-STORMS applications, integrations, data categories, user roles, and deployment paths in the proposed use case.
Security review
Security answers must match the application, data flow, providers, and controls actually in scope. This page is a procurement starting point—not a certification, audit report, or substitute for a deployment-specific review.
AI-STORMS includes a public marketing site and separate operational applications and integrations. A control observed in one service must not be assumed to cover every other service. Security evidence is therefore evaluated against a named system, environment, data flow, and review date.
We will not use planned controls, provider defaults, or marketing copy as proof. Material requirements should be captured in the applicable agreement after technical and operational validation.
These are review domains, not claims that every listed control is already implemented in every environment.
Review 01
Identify the AI-STORMS applications, integrations, data categories, user roles, and deployment paths in the proposed use case.
Review 02
Review how authentication, authorization, administrative access, and tenant separation are enforced in the systems that will hold customer data.
Review 03
Document collection, processing, export, retention, deletion, and provider handoffs for the exact channels and features being activated.
Review 04
Confirm current monitoring, backup, restoration, incident handling, and recovery commitments before placing contractual reliance on them.
Review 05
Identify the providers enabled for the customer deployment and review their current terms, security documentation, and data-processing roles.
Review 06
Validate consent evidence, suppression handling, sender configuration, escalation, and channel-specific approvals as separate compliance controls.
Send the systems, integrations, data types, user roles, and contractual requirements you need reviewed. Responses should be treated as point-in-time and limited to the documented scope.
hello@ai-storms.comReport suspected vulnerabilities without accessing another person's data, disrupting service, or retaining sensitive data. Include the affected URL, reproduction steps, and observed impact.
Submit a security report