SecurityScorecard's LLMs in Titan AI use proprietary logic and run inside the SecurityScorecard environment. The underlying language models come from Amazon Bedrock, an AWS-managed service, using approved Anthropic foundation models. These features work only with data already in the platform and visible to you under your existing role-based permissions.
AI appears in five areas of Titan AI today, and each one only runs when someone clicks something. No AI feature reads, scores, or submits anything on its own.
Understand Titan's AI safeguards
The following protections apply to all features that use AI:
- No training. Your data doesn't train any model, whether run by SecurityScorecard or by a provider.
- No sharing with the model provider. Amazon Bedrock hosts models in AWS-controlled accounts that the provider can't access. Bedrock doesn't store prompts and outputs in standard operation, and they don't leave the AWS network.
- Guardrails. Amazon Bedrock Guardrails protect production AI invocations, including content filters and prompt-attack detection.
- Human review. A human reviews AI output by default, using several tracing and benchmark techniques to measure quality and performance.
- The same controls as the rest of the platform. AI features sit inside the access controls, logging, incident response, and data retention commitments covered by our SOC 2 Type II report (unqualified, with no exceptions). This report is available under NDA through our Trust Center.
A person stays in the loop for every feature. Every suggestion is saved as a draft, and nothing is submitted, published, or scored until someone accepts it. Each feature above also requires a specific action to start, such as opening a dialog, clicking a button, or opening an assistant panel, rather than running in the background unprompted.
The AI features below are currently part of the standard Titan AI experience and aren't turned on or off per tenant or role.
Find AI features in Titan Assess
Most customers first encounter AI while filling out or reviewing a security questionnaire, since that work involves a lot of repetition. These features cut down on retyping.
- Autofill. You start it. Autofill suggests answers to questionnaire questions by drawing on answers your organization submitted before. It runs only when someone opens the autofill dialog for a questionnaire or a batch of questionnaires. Each suggestion is saved as a draft that a person can accept, edit, or reject before submitting.
- Answer refinement. You start it. This feature tightens the wording of an answer you already wrote, keeping the same meaning with cleaner phrasing. A button next to the answer field triggers it, and nothing changes until you press that button.
- Import assistant. You start it. The import assistant reads a spreadsheet or Word document you upload and maps its contents into the right questionnaire fields, so you don't have to copy and paste row by row. It opens in its own panel when you choose to import a file this way.
- Template assistant. You start it. This assistant helps you draft or adjust questionnaire templates in conversation, such as adding a section, rephrasing a question, or restructuring scoring, while you edit a template. It lives in a side panel that you open on demand.
Find AI features on the Trust Page
The Trust Page assistant helps you write or restructure the content on your public Trust Page, such as summarizing a security posture or drafting a new section. You start it from a side panel that you open while editing. Publishing the page remains a separate, deliberate step.
Find AI features in vendor onboarding
The setup assistant walks you through initial account setup conversationally instead of through a long static form. It's available on the pilot onboarding flow, and only for accounts where it's been turned on.
Find AI features in Workflow Builder
If you build automations in Workflow Builder, you can add pre-built AI agents as blocks. Each agent handles one narrow task with its own model and guardrails, rather than acting as a general-purpose chatbot. An agent runs only when it's wired into a workflow someone built and triggered; none run on their own.
- Access Vendor Relationship. Assesses whether a Tier-2 vendor's breach warrants outreach, based on SecurityScorecard's relationship with that vendor.
- Continuous Monitoring summary. Produces a weekly plain-language summary of a vendor's Continuous Monitoring activity.
- Generate micro-summary. Produces a strict two-sentence, fact-grounded summary of vendor outreach activity tied to a security event.
Review what each feature reads and produces
| Feature | What it produces | What it reads | Do you type or upload anything into it? |
| Autofill | Draft answers to questionnaire questions | Your organization's previously submitted questionnaire answers | No. A button triggers it; you don't type or upload anything. |
| Answer refinement | A reworded version of an answer, with the same meaning | The answer text already in that field | Yes. The free text you already wrote in that answer. |
| Import assistant | Mapped questionnaire field values | The spreadsheet or Word document you upload | Yes. You upload a spreadsheet or .docx file. |
| Template assistant | Draft edits to a questionnaire template | The current template content, plus your messages to the assistant | Yes. You type free text in the assistant panel. |
| Access Vendor Relationship (Workflow Builder) | A recommendation on whether a vendor breach warrants outreach | Vendor tier and relationship data already in the platform | No. It runs automatically inside a workflow you built; you don't type or upload anything at runtime. |
| Continuous Monitoring summary (Workflow Builder) | A weekly plain-language summary of vendor monitoring activity | Vendor Continuous Monitoring data already in the platform | No. |
| Generate Micro Summary (Workflow Builder) | A two-sentence summary of vendor outreach activity | The outreach activity log tied to that security event | No. |
| Security event status report (Workflow Builder) | An executive situation report for a security event | Triage data supplied by the workflow itself | No. |