SecEng Workbench · Map
Trust Scanner — Live Demo
ATG public scorecard · rendered from fixture data
The panel below is the same output the Trust Scanner produces in the Chrome extension, the web app, and in-app mini-apps — six dimension scores, artifact checklist, top finding, and improvement guidance.
95
Public Surface
93
AI Language
91
Legal Clarity
87
Security Trust
89
Consistency
82
Remediation Opportunity
Trust Scanner · ATG Scorecard
aisecurity.llc · public trust surface
The public trust surface is now comprehensive. Legal, AI-governance, security, SDLC, and contract surfaces are all discoverable, linked, and specifically documented. The remaining gap is a formal third-party security certification or attestation.
91
advanced
Public Surface
Whether trust, legal, security, AI, methodology, and contact surfaces are discoverable and coherent.
95% signal
AI Language
Whether AI claims are specific, bounded, and tied to engineering evidence rather than generic positioning.
93% signal
Legal Clarity
Whether privacy, terms, contract, data-processing, and customer-facing boundaries are clear enough to review.
91% signal
Security Trust
Whether public trust artifacts explain controls, evidence, limitations, and escalation paths without oversharing.
87% signal
Consistency
Whether public claims, caveats, service language, and trust artifacts agree across the site.
89% signal
Remediation Opportunity
Whether the public surface makes the next improvement work obvious, scoped, and evidence-backed.
82% signal
Public-signal caveat
Based on public website signals and observed artifacts, not proof of any organization's internal security maturity.
Chrome + VS Code surface
Trust Scanner in the extension
The same ATG scorecard language runs inside the Chrome side panel and the VS Code extension — scan any public page in one click and get the full 6-dimension scorecard in-context.
Observed artifacts · 19 of 21
Top finding
infoFull legal suite is enterprise-reviewable
Keep each document directly linkable from the trust center and contract hub. Enterprise buyers often paste URLs into procurement systems rather than reading inline.
Improvement guidance
Pursue a scoped third-party security attestation
A SOC 2 Type I or equivalent readiness assessment would provide independently verified evidence for the controls already disclosed on the security practices and SDLC pages. Even a scoped readiness letter closes the gap between self-disclosed and verified.
Important caveat
Based on public website signals and observed artifacts, not proof of any organization's internal security maturity.
Run this against your own trust surface.
A private scan produces a full scorecard plus a remediation backlog — not just a public signal.