Most enterprise AI systems are built almost entirely from components you don't control — foundation models, vector databases, MCP servers, plugins, and open-source packages. Each one is a potential attack vector. This dashboard maps the full dependency chain and scores exactly where your unreviewed exposure sits.
Enter your AI dependencies across 5 categories. Get a risk score, dependency map, unreviewed surface area, and board-ready PDF export.
Few organisations build their own foundation models. Most deploy AI through a supply chain of third-party models, inference APIs, vector databases, orchestration frameworks, MCP connectors, and open-source dependencies. Each one is an external dependency with its own security posture, data handling terms, and vulnerability exposure — yet most enterprise AI vendor assessments evaluate SLAs, pricing, and general data handling, not model security, inference-time attack resilience, or supply chain transparency.
The result is a structural blind spot: the component making the most consequential decisions in your AI system — the foundation model itself — often receives the least security scrutiny in procurement. The AI Supply Chain Risk Dashboard™ exists to surface that blind spot before an incident does.
OpenAI, Anthropic, Google, and open-weight models you've deployed — each with distinct data handling terms and training data governance
Pinecone, Weaviate, pgvector, and other retrieval infrastructure storing your embedded enterprise knowledge
Model Context Protocol connectors giving AI systems tool access — one of the fastest-growing and least-reviewed dependency categories
Third-party services your AI systems call directly — each call is a potential data exposure or manipulation point
Integrations extending your AI applications' capabilities, each with its own permission scope and security posture
The dependency tree beneath your AI pipeline — orchestration frameworks, tokenizers, and supporting libraries, often numbering in the hundreds
The dashboard's scoring methodology is transparent by design — every score is traceable to a specific calculation, which is what makes the output defensible in a board or procurement conversation rather than a black-box number.
| Factor | Method | What It Captures |
|---|---|---|
| Vendor Scoring | Weighted criteria | Data residency, SLA terms, audit transparency, incident history, certifications |
| Open-Source Scaling | log2(n+1) × 8, capped at 60 | Risk grows with package count but logarithmically — the 50th package matters less than the 5th |
| Dependency Multiplier | score × (1 + active × 0.05) | Each additional active third-party connection compounds total exposure |
| Supply Chain Depth | 1 + (depth × 0.03) | Multi-tier dependencies (a vendor's vendor) increase risk further |
| Industry Multiplier | Finance 1.1× · Healthcare 1.2× · Tech 1.0× | Regulatory and data sensitivity context scales the base score |
Beyond the headline risk score, the dashboard visualises your full dependency map — every foundation model, vector database, MCP server, API, plugin, and package category represented as a node, sized by criticality. The "unreviewed surface" metric specifically flags dependencies that have never been through a formal security or vendor risk assessment — typically the highest-leverage finding in the entire dashboard, since it identifies exactly where your blind spots are without requiring you to manually audit every vendor relationship first.
Model Context Protocol servers are singled out in the dependency categories because they represent a newer and structurally different risk than traditional API dependencies. An MCP server doesn't just exchange data with your AI system — it can grant the AI system tool access, meaning a compromised or malicious MCP connector can translate directly into unauthorised actions, not just data exposure. Most organisations are adopting MCP servers faster than they're developing MCP-specific vendor review criteria, which is precisely the kind of growing-adoption-outpacing-governance pattern the broader AI Security Benchmark 2026 report identifies as the defining risk dynamic of the year.
Get a single defensible risk score for the entire AI vendor ecosystem, with the underlying methodology fully transparent for board questions
Identify which AI vendor relationships need security review before renewal, and which new vendor evaluations need AI-specific criteria added
Build the AI vendor inventory required by NIST AI RMF and EU AI Act risk management obligations, with risk scoring already attached
Receive a board-ready PDF translating dependency sprawl into a single comparable risk metric, trackable quarter over quarter
Supply chain is one of six domains in the full Coverage & Maturity Dashboard. Benchmark your complete AI security posture against industry peers.