Skip to main content
In development — partly built. There is no hosted service to sign up for yet. Some of what follows runs today; the rest is designed and not yet built.Individual pages repeat this where it matters.
The AI Vendor Trust Exchange (ATX) is a public, web-first platform for technology and security due diligence on AI vendors. A buyer looks up an AI tool and gets a source-cited, always-current read on how it handles data, what it is built on, and whether it is safe to adopt or renew.

The question it answers

Every AI purchase eventually reaches one reviewer asking one thing: is it safe to adopt this vendor? Answering it means knowing which foundation models sit underneath, who the sub-processors are, whether the vendor trains on your data, which certifications actually hold, and what has gone wrong before. Today that answer is produced by a bespoke questionnaire, takes weeks, and is stale the day it is delivered. AI vendors ship changes weekly; a posture assessment written last quarter describes a product that no longer exists.

Why nothing existing covers it

AI-governance platforms

Have the risk taxonomy, but are buyer-private. Nothing is shared, nothing is public.

Vendor-trust exchanges

Proved the shared-assessment model works, but are security-only — not AI-specific.

AI directories

Have reach and traffic, but no real trust layer underneath the listings.
Nobody offers a public, browsable, continuously re-verified trust directory for AI vendors. That gap is what ATX is built for.

The forcing function

EU AI Act Article 26 places due-diligence obligations on deployers — the buyers — of high-risk AI, enforceable from 2 August 2026. Every organisation adopting AI is about to be compelled to produce exactly the vendor-trust evidence this exchange aggregates. That matters for more than urgency. It means contribution is a byproduct of work buyers must do anyway, which is what makes a shared exchange viable rather than charitable.

The two sides

Both feed one shared dataset. See The assessment exchange.

Three properties that define it

1

Freshness is the product

Every field carries a last_verified_at date that advances only on re-confirmation — a rule the code enforces, down to silence is not confirmation. The automation now exercises it: sources are re-crawled on their cadence, posture changes are diffed into typed events on a public change log, and anything past its window is flagged. See Trust profiles.
2

Provenance is first-class

Every published field is tagged verified, vendor_claimed, or crowd, and links to its source. A field with no provenance does not ship.
3

Independence is structural

Money can buy presence and support. It can never buy a rating input, a ranking position, or an answer. This is enforced by separate services and isolation tests, not by policy alone. See Independence.

What it is not

  • Not a GRC workflow tool. It is a public intelligence layer, not an internal control plane. It does not run your approval process.
  • Not a compliance certification. ATX publishes source-cited findings; it does not audit or certify anyone.
  • Not an outside-in security scanner. Ratings are analyst-assessed and attested against public evidence. Continuous scanning is not part of the design as it stands.
  • Not real-time. Re-verification runs on a cadence tied to risk tier, and the profile says when each field was last confirmed.

Where to go next

Trust profiles

The two field blocks, provenance tags, side-by-side comparison, and how freshness and change tracking work.

Ask ATX

The natural-language front door — how a plain question becomes a cited shortlist.

The assessment exchange

Give-to-get, contribution normalization, and the four trust boundaries.

Independence

The firewall between vendor money and any verdict, and why it is load-bearing.

Pricing and support

Open source and free to run, with custom support available on request.