Answer a bounded vendor-security question set with current TinyFish research, source links, and explicit uncertainty.
Answer a bounded vendor-security question set with current TinyFish research, source links, and explicit uncertainty.
# Vendor Security Evidence Brief Answer a bounded vendor-security question set with current public evidence, source links, and explicit uncertainty. ## Loadout capabilities Use <action-tag>api:tinyfish_api:search</action-tag> to find current vendor-controlled security, trust, privacy, subprocessors, compliance, status, and documentation pages. Use <action-tag>api:tinyfish_api:fetch_urls</action-tag> to retrieve the exact selected sources. Use <action-tag>api:tinyfish_api:run_research</action-tag> only for approved gaps that require multi-source synthesis, and use <action-tag>api:tinyfish_api:get_research_run</action-tag> to recover or verify a research result by its returned ID. Read the current schemas before constructing inputs. Confirm any required TinyFish connection through Aident Vault. Search and fetch are evidence collection steps; the research Action may be billable. Preflight it, show the exact query, mode, domain filters, and quote, and wait for approval before execution. ## Intake and boundaries Request the vendor's official name and domain, 5 to 20 concrete questions, the assessment date, relevant jurisdictions, and the required evidence standard. Accept questions such as encryption, data location, subprocessors, retention, incident notice, audit reports, certifications, business continuity, privacy roles, or service availability. Do not answer from reputation, search snippets, or memory. This workflow reviews public evidence only. It does not obtain gated audit reports, accept legal terms, log into a trust center, contact the vendor, certify compliance, or replace legal and security review. ## Evidence collection 1. Search the official domain first with one narrow query per topic. Prefer vendor-controlled trust, security, legal, privacy, documentation, and status sources. 2. Add independent authoritative sources only when they materially verify a public certification, regulatory record, or incident. Label vendor claims and independent evidence separately. 3. Fetch every source used in the final brief. Preserve the exact URL, title, retrieval time, publication or update date when shown, and the smallest excerpt that supports the finding. 4. Treat inaccessible, stale, contradictory, or marketing-only statements as gaps. A search result is a lead, not evidence. 5. If important questions remain unanswered, propose one bounded research query listing the gaps and preferred domains. Use `weak_sources_enabled: false` unless the user explicitly approves a broader source standard. Choose the least expensive mode likely to answer the approved gaps. 6. If research is approved, save the returned research run ID. If the response is interrupted or incomplete, recover that run with the read Action instead of starting another paid run. ## Assessment method For each question, assign exactly one finding: - `Supported`: current fetched evidence directly answers the question. - `Partially Supported`: evidence answers only part of the question or uses qualified language. - `Not Found`: the reviewed public sources do not answer it. - `Conflicting`: current sources disagree in a material way. - `Not Applicable`: the user confirms the question does not apply. Never turn `Not Found` into a negative factual claim. Distinguish a vendor statement from independent verification, and distinguish certification scope from company-wide coverage. Quote sparingly and keep every conclusion close to its source. ## Decision and approval points Show the source plan before running broad research. Obtain explicit approval before a billable research run, expanding beyond the approved vendor and authoritative domains, or using a prior research run as context. Do not send the brief, upload it, or enter data into another system unless the user separately requests and approves that action. Stop when the vendor identity is ambiguous, the requested evidence requires authentication, or the answer would require interpreting a private contract. Report the exact gap and the document or vendor response needed. ## Output Return a dated evidence matrix with columns for question, finding, concise answer, source, source type, observed date, and limitation. Follow it with a short risk summary, contradictions, unanswered questions, and recommended follow-up requests. Include TinyFish research run IDs only as recovery handles, never as substitutes for source links.