The TRACE Score: A Five-Dimension Framework for AI Tool Risk
Why "is this tool safe?" is the wrong question
The question I get asked most often by IT and security leaders is some version of "is [specific tool] safe to use?" I understand why — they want a yes or no so they can update the approved software list and move on.
The honest answer is that safety is not a binary property. It is a function of five verifiable characteristics, and without a consistent framework the gaps get missed. Most enterprise AI tools pass some dimensions while failing others. That specific combination determines your actual exposure.
The five dimensions
Does the tool train its models on your company's content?
This is the highest-impact question in the framework. Some tools are explicit about it in their terms of service. Others are ambiguous by design. Some are opt-out by default — training is enabled unless someone actively turns it off, which most employees never do because they do not know to look.
When a tool trains on your data, internal communications, client documents, and strategic plans become part of that vendor's training dataset permanently. There is no recall mechanism, and no version of DPDPA compliance accounts for data already incorporated into model weights. If this is true of a tool, it escalates the risk profile regardless of everything else.
Where does your data actually go?
An AI tool built in the US, marketed globally, hosted on infrastructure in Europe, and processed by subcontractors in Southeast Asia is not an unusual configuration. Under DPDPA your organisation is accountable for where personal data flows.
"We accepted the vendor's privacy policy" is not an adequate defence, and "cloud-based" is not a data residency answer.
Does the vendor hold SOC 2 certification?
SOC 2 is not a perfect standard, but it is the baseline proof that an independent auditor verified the vendor's security controls exist and operate as described. Without it you are relying on the vendor's own account of its security posture. For any tool processing company content, the absence of SOC 2 should require a specific documented justification — not a default approval.
Does the vendor hold ISO 27001?
Where SOC 2 is a point-in-time audit against a control framework, ISO 27001 requires a vendor to build and maintain an ongoing information security management system. It is the marker of a vendor who has operationalised security rather than passed a test — and it is the benchmark a regulator is likely to reference when assessing whether you exercised adequate care under DPDPA Section 8(5).
Does the vendor provide a signed Data Processing Agreement?
Under DPDPA, where a third party processes personal data on your behalf you need a contract specifying purpose, data categories, retention period, security obligations, and breach notification. An AI vendor who does not offer a DPA is either unaware of that requirement or has made a deliberate choice not to be bound by it. Engaging one without a signed DPA means you may be processing personal data unlawfully before any breach occurs.
Higher risk vs lower risk, at a glance
| Dimension | Higher risk | Lower risk |
|---|---|---|
| T — Trains on your data | Yes, or undisclosed | No, contractually excluded |
| R — Data residency | Unknown or "cloud-based" | Declared in writing |
| A — SOC 2 | Not certified | Certified |
| C — ISO 27001 | Not certified | Certified |
| E — DPA | Not offered | Signed |
What TRACE is, and what it isn't
TRACE is not a final verdict. It is a structured, documented starting point — one that produces a defensible record of due diligence if the Data Protection Board ever asks what your organisation knew and when. A tool failing all five dimensions is categorically different from one passing all five, and most enterprise AI tools sit somewhere in the middle. That is precisely why the specific combination matters more than an overall impression.
The practical test: which of the five dimensions does your current vendor review process actually capture in writing? Anything you cannot produce on paper is, for compliance purposes, an assumption.
Score the AI tools already running in your tenant.
Pyroniq discovers every OAuth-consented AI tool and scores it against these dimensions automatically.
This article is for awareness only and does not constitute legal advice. DPDPA obligations depend on your organisation's specific circumstances — confirm them with qualified counsel.