Skip to content

ScopeMantle is SOC 2 Type II in progress, read our trust commitments →

← Platform overview

Platform capability

Vendor Risk & Privacy Posture Scoring

Every vendor gets an automatic risk score from LLM analysis of privacy policies, security pages, sub-processors, and breach history — re-scored monthly.

Start a 30-day trial

02 · RISK SCORING

Vendor Risk & Privacy Posture Scoring

Every vendor in your inventory — including the long tail of small AI SaaS tools that manual vendor databases never cover — gets an automatic risk score within minutes of discovery. ScopeMantle's LLM analysis engine reads each vendor's privacy policy, security page, sub-processor list, and known breach history, and produces a confidence-scored posture assessment broken into four axes: Security, Privacy, Scope Sanity, and Breach History.

This is not a static database. Every score re-evaluates monthly, and a change in policy or a new breach disclosure pushes an alert into your event stream, Slack, or SIEM the same day.

  • SOC 2 / ISO 27001 / HIPAA presence detection per vendor
  • Scope-sanity red-flagging (the Context.ai signal)
  • AI-training-on-customer-data clause detection
  • Sub-processor graph per vendor
  • Correlation with HIBP, CISA, and public breach sources
  • Monthly re-score with change alerts
  • Source-cited — every score links to the policy passages that produced it
Talk to an engineer
scopemantle.app/vendors/context-ai
ScopeMantlePrivacy IntelligenceNotion
Claude Opus 4

Notion · privacy posture

notion.so/privacy
Last refreshed: 18 Apr 2026Doc revision: 2025-11-04Source pages parsed: 7
Data categories collected
94%

Identity · Communications · File contents · Behavioral telemetry

Sub-processors disclosed
97%

AWS (us-east-1, eu-west-1) · Stripe · Datadog · Twilio · Snowflake

Cross-border transfers
88%

EU → US under SCCs (2021/914) · UK IDTA · No data transferred to China

Retention windows
79%

Account data: 30d post-cancellation · Logs: 12 months · Backups: 35 days

Notification SLA (incident)
91%

72 hours from confirmed breach (Article 33-aligned)

Extracted facts are evidence-linked back to the source URL · re-runs monthly or on policy change detection

Frequently asked

Platform — common questions

Find the Context.ai in your org before the attacker does.

15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.

Book a demo to see the inventory on your own tenant.