Free checklist · No form, no email
AI Vendor Runtime Evidence Checklist.
Twelve evidence questions to adapt for higher-consequence healthcare and PHI workflows. Move from assurances to inspectable operational records, testing, and coverage evidence.
How to use
01
Attach it to the questionnaire.
Add this checklist to the security questionnaire your team already sends AI vendors. It stands alone: no tooling, no account, and no Glacis relationship required.
02
Require the artifacts before contract.
An acceptable answer is an evidence set your reviewer can inspect: signed records, published keys, tests, and coverage analysis. A signed record checks integrity and signer attribution for covered fields; it does not alone establish source truth, control effectiveness, or complete capture.
03
Verify one receipt yourself.
Verification runs in your browser at glacis.io/verify. It takes about a minute, needs nothing from the vendor, and shows your reviewers what a passing receipt looks like.
Runtime evidence
The vendor produces independently checkable records for the workflows in scope. If contemporaneity matters, require separate trusted-time and deployment evidence rather than inferring timing from the record alone.
Require the vendor to identify who signs each receipt. Portal receipts may carry a Glacis service-operated witness countersignature and inclusion proof; SDK or self-hosted receipts may be operator-signed only. A second signature does not by itself establish organizational independence.
A reviewer can detect modification within a sequence they already possess. Detecting omitted events or suffix truncation also requires an externally held checkpoint, expected sequence count, or other reference outside the vendor-controlled history.
The record identifies the configured path’s claim about PHI and sensitive-data control invocation and outcome. Corroborate execution and boundary coverage separately.
Verification
Receipts verify offline or in-browser, with no vendor software, vendor account, or vendor assistance in the loop.
The trust material needed to verify records is published and versioned, with safe rotation and enough history to check records across the life of the contract.
The vendor provides a sample receipt during review, and your reviewer checks it independently. You can Verify a record to see what passing looks like.
Boundary & egress
Producing evidence should not create an unnecessary copy of protected content. Ask which payloads remain local, which hashes, outcomes, signatures, or metadata travel, and how that boundary is tested.
The vendor states in writing which traffic and action classes are in scope for evidence and which are excluded, so your review covers what the receipts cover.
Review artifacts
Receipts are assembled into an evidence pack your security and compliance teams can review without specialist tooling.
Records can support reconstruction of covered events. Completeness and any PHI disclosure depend on the retained fields, coverage, and investigation procedure.
The vendor states how long receipts are retained, where they live, and what survives contract termination.