FDE ACADEMY · MODULE 04 · LESSON 03
Vendor assessment: published, promised, verified
Three different things that get written down as one. How to read a vendor’s documents for what they commit to, and how to record what you could not establish.
- Effort
- Two hours per vendor the first time; forty minutes once you have the question set.
- Skills
- compliance-governance · api-integration
Free and self-paced. No certification is offered.
01The distinction this whole site is built on
That a vendor publishes a data-processing agreement, a subprocessor list, a security page or a supported-countries page at a given URL is checkable: you fetch it, hash it, date it. What the page says — that customer data is not used for training, that a region is offered, that logs are retained for thirty days — is a claim about content, and reproducing it as your own fact means adopting a statement you did not verify.
This site keeps the two apart and shows the state plainly: documents retrieved, claim pending review, verified. Copy that into your own assessments. The value you add is knowing which of your statements is which.
02What actually binds
A marketing page is not a commitment. A data-processing agreement, the terms in force for the plan the customer is on, and the documents those incorporate are what bind. Plan matters: the same vendor commonly offers materially different terms on a consumer tier and an enterprise agreement, and a deployment scoped against the wrong one is scoped against nothing.
When this site assesses a hosted assistant it does so against a written agreement, documented residency, a written no-training term, a retention and deletion path, and audit logging with single sign-on. Those five are a serviceable checklist for any vendor.
- Which legal entity contracts with the customer, and under which jurisdiction’s law.
- Which subprocessors exist, and how changes to that list are notified.
- What is retained, for how long, and what deletion actually removes.
- Whether the terms differ by plan, and which plan the customer will really be on.
- What audit and access evidence the customer can obtain without asking.
03Recording an unknown as an unknown
Half of a good assessment is the list of things you could not establish. A row that says “not stated in any published document; asked on 3 March; no answer yet” is more useful than a confident guess, and it is the row that gets the vendor to respond.
Never write zero, “none” or “not applicable” where you mean unknown. This site refuses to print a price it has not read for the same reason: an invented number is indistinguishable from a real one once it is in a document.
04Do this
PRACTICAL TASK
Assess one vendor and write down what you could not establish
Produce a one-page assessment of a hosted tool for a specific customer, separating what is published, what is claimed, what you verified, and what remains unknown.
What you need
- One vendor your customer is actually considering
- The customer’s jurisdiction and the plan they would be on
Steps
- 01
Open the tool page and read the vendor documents section: which documents this site watches, and when each was last fetched.
- 02
Read the verified facts section and note which claims carry evidence and which are still pending review.
- 03
Read the same vendor against your customer’s jurisdiction and list every issue the assessment raises.
- 04
Now go to the vendor’s own documents. For each of the five checklist items, quote the sentence that supports it, or write “not found”.
- 05
Compare with the self-hosted alternative for the same use case, so the recommendation has something to be a recommendation against.
You are done when
- Every statement in your page is marked published, claimed, verified or unknown.
- Each verified statement quotes a sentence from a document you fetched, with the date.
- Your unknown list is not empty, and each entry says what you asked and when.
05Where these facts live
This lesson does not restate anything that is already recorded with its evidence elsewhere on the site. These are the pages it leans on.
- Tool index
Every tool here separates what its vendor publishes from what has been verified about the contents.
- How we research
The source tiers, the freshness windows and the rule against reproducing another directory’s scores.
- Questions to ask before adopting an AI vendor
The list, with what a good answer looks like and what a published page does not settle.
Ticks are stored in your browser only. They are not sent anywhere, they are not attached to an account, and clearing your browser data removes them.