Techtonic TrustVendorGuard · AI & SaaS tool approval record
Approval record
Generated 30 Jun 2026
Record ID: VG-SAMPLE-0042
Northwind Notetaker AI
AI meeting assistant · transcription & summarisation · reviewed against AI & vendor security controls
Assessment overview
Northwind Notetaker AI
AI meeting assistant (SaaS)
AI Tool Security Review
Operations Manager
Up to Confidential
Decision recorded
Overall posture
● Conditional · Proceed with conditions
1 Red · material gap2 Amber · condition required2 Grey · insufficient evidence
The tool is usable for its stated purpose, but vendor disclosure is incomplete. Approval is conditional on closing
the data-training, residency, access-control and contract gaps below before customer conversations are processed.
AI tool profile
AI use case
Real-time meeting transcription and summary generation
RedCustomer data may be used for model training with no opt-out
The vendor could not confirm whether prompts, transcripts or outputs are used to train or improve models. For a tool processing customer conversations, this is a material gap until contractually excluded.
Evidence: vendor statement only · not contractually confirmed
AmberAustralian data residency not confirmed
Storage and processing locations were not disclosed. Acceptable to proceed only with written confirmation, or with data limited to a lower classification.
Evidence: not provided
AmberAccess controls not evidenced (RBAC / MFA)
No confirmation of role-based access, least privilege, or MFA for privileged accounts. Condition: vendor to provide access-control documentation before rollout.
Evidence: vendor statement only
GreyInteraction logging and retention unconfirmed
It is unknown whether prompts/outputs are logged, how long they are retained, or whether logs are protected from tampering. Insufficient evidence to assess.
Evidence: none; clarification requested
GreyOutput safety controls not specified
No detail on controls against inaccurate or harmful output. Mitigated in practice by the human-validation step, but the vendor control itself is unevidenced.
Evidence: none
Evidence basis
Each finding records how strong its evidence is, so a vendor statement never looks like independent proof.
1StatementVendor's word
2DocumentPolicy / screenshot
3ContractClause / DPA
4AssuranceSOC 2 / ISO / test
5VerifiedConfirmed in context
Decision
Approved with conditions
Limited rollout permitted for internal meetings up to Confidential, subject to the following conditions being met before wider use.
Complete a Privacy Impact Assessment before processing customer conversations.
Obtain written confirmation of Australian data residency and processing locations.
Add a contractual restriction preventing customer inputs from being used to train or improve the model.
Vendor to provide and enforce role-based access control (RBAC) and least-privilege access.
Retain human validation of AI-generated summaries before they are relied upon.
Include AI-specific contract clauses covering liability, transparency and audit rights.
Approve with conditions
Head of Operations
Security Reviewer
30 Jun 2026
31 Dec 2026
6 tracked
This is an illustrative sample using fictional data to show the structure of a VendorGuard approval record.
It is not a real assessment of any vendor and does not constitute legal, security or compliance advice.