The Vendor Check · Free Evaluation Kit

Trust is earned in writing.

AI is not software you use. It is intelligence you delegate. Most AI buying mistakes do not show up at the booth. They show up six to twelve months later, in your data, your contract, and your bill. This kit is how you catch them at the booth: every question worth asking, the rubrics for the answers, the red flags, the vocabulary, and an auditor you run yourself.

Before Anything Else

The one question that matters.

What work will this AI own inside my dealership? If the rep cannot answer in one sentence, stop. Everything below assumes they passed.

Set One · Business & Data Rights

Ten questions that separate real AI from demos.

The deal side: what the AI owns, who owns the data, what leaving costs, what growth costs, who pays when it is wrong. Use them exactly as written. The press line is what to say when the answer goes soft.

The second set, twelve security and compliance questions with full answer rubrics, is in the questionnaire below. Certifications, controls, data handling, incident readiness, continuity. Pick your sets, pick your vendor categories, print the sheet.

The Questionnaire

Build it. Print it. Send it.

A dealership is a data business that sells cars. Credit applications, government IDs, and bank details sit in systems your vendors operate. The FTC Safeguards Rule requires dealers that arrange financing to oversee those service providers, in writing, in contracts. A generated questionnaire, sent and filed with the answers, is that oversight on paper.

Question sets to include
Your store (optional, appears on the printout)
Vendor this is for (optional)
Which vendor categories apply
Does the vendor say AI touches customer data
Runs entirely in your browser. Nothing is sent anywhere.
The Line We Hold

This tool never evaluates, scores, or renders a verdict on any named vendor. It fetches nothing about any company. It generates the questions and describes what strong, weak, and red-flag answers look like. You do the asking. You do the judging.

The Tells

Booth phrases that should end the meeting.

These phrases sell booths. They do not run dealerships. Each one has a strong version. The gap between the two is the tell.

"End-to-end AI"
Strong vendors name the exact steps the AI owns and the exact steps a human owns.
"Works out of the box"
Strong vendors tell you which data feeds it needs on day one, and what breaks without them.
"We never train on your data"
Strong vendors put that in an enforceable clause with definitions, not a settings toggle that can change.
"You own your data"
Strong vendors specify export format, completeness, timing, and what happens to derivative data. Ownership without export is a slogan.
"We're SOC 2 compliant"
Strong vendors hand you the Type II report and let you read the date, the scope, and the legal entity it actually covers.
"Our AI replaces your team"
Strong vendors describe how it changes your team's day, and who overrides it.
"Unlimited usage"
Strong vendors define fair use in numbers and give up the right to redefine it mid-term.
"The AI keeps getting smarter"
Strong vendors tell you what feedback actually changes the system, and whether your store's learning stays yours.
The Auditor

Run the audit yourself.

This site never judges a vendor. You do. The Auditor is a full set of due-diligence instructions, refined in production at a real dealership. Copy it into your own AI, point it at a vendor's website and documents, and get a procurement-ready report with testable proof questions and a scored claim inventory.

  1. Enter the vendor's website below, and your use case if you have one in mind.
  2. Copy the generated instructions into a fresh chat in Claude, ChatGPT, or Gemini. Attach any PDFs you have: trust center exports, SOC 2 reports, DPAs, SOWs, proposals.
  3. Read the report. Take the Top Questions into the meeting. Ask for the artifacts it lists.
Vendor website (optional)
Your use case (optional)

    
The Vocabulary

Terms to understand before you sign.

Plain English, no vendor spin. If a rep cannot explain these clearly, that is your answer.

SOC 2, Type I vs Type II
An independent audit of a company's security controls. Type I is a snapshot of design on one day. Type II tests whether the controls actually operated over a period, usually six to twelve months. Type II is the one that means something. Always read the date, the scope, and the legal entity covered.
Ask: Send the Type II report. What period, what scope, which entity?
Subprocessor
A company your vendor uses that touches your data: model providers, cloud hosts, analytics tools. Your data's real exposure is the whole chain, not just the logo on the contract.
Ask: Name every subprocessor that touches my customer data, and notify me when the list changes.
LLM (Large Language Model)
The engine that generates answers. It does not know your dealership by default.
Ask: Is the model trained on my data, or just accessing it?
RAG (Retrieval-Augmented Generation)
The AI looks up your data when answering. It does not mean the AI is learning your dealership. RAG improves answers, not intelligence.
Ask: What data is retrieved, and how fresh is it?
Fine-tuning vs retrieval
Fine-tuning changes how the AI behaves based on your data. Retrieval looks things up without changing how it thinks. Fine-tuning is what builds institutional intelligence.
Ask: Is your AI fine-tuned on my outcomes, and is that model isolated to my store?
Derivative data
Data created from your data: scores, predictions, segments, risk flags, embeddings. Vendors increasingly grant you ownership of inputs and outputs, then keep broad rights to derivatives. That is where value compounds, so the definition belongs in the contract, narrowed.
Ask: Define derivative data in my contract. Who owns it, and can it be reused for anyone else?
Model deprecation
The vendor's underlying model will change. When it does, your product's behavior changes with it, sometimes overnight. Version pinning and rollback rights are what protect you.
Ask: When you swap or retire a model, how much notice do I get, and can I roll back?
Black box vs explainable
A black box gives answers with no reasoning. Explainable AI shows inputs or signals your managers can challenge. No explanation means no trust, and no trust means no adoption.
Ask: Can my managers see why the AI decided what it decided?
Feedback loop
Vendors say their AI improves over time. Software updates are not learning. Only specific feedback that changes the system is.
Ask: What feedback from my store actually changes the system?
Inference cost
Every AI response costs the vendor money. That cost is in your price somewhere, and it scales with usage. Some cheap AI gets very expensive.
Ask: Show me the bill at five and ten times my pilot usage, and show me the clause that lets you change the rates.
Agentic AI
AI that takes action, not just recommends. Agents without scoped access and accountability are operational risk, not innovation.
Ask: What actions can it take, what can it reach, and who is accountable when it acts?
Prompt injection
A crafted message that steers an AI into leaking data or taking actions it should not. Any AI that reads what customers type is exposed to it.
Ask: How do you test for this, and will you share the latest results?
SBOM (Software Bill of Materials)
The ingredient list of a product's code: every component and dependency. It is how a vendor proves they know what is inside their own software, including the parts an AI wrote or fetched.
Ask: Provide an SBOM, and explain how a package is verified before it enters your build.
The Tool Family

Three tools, one discipline.

GEO scores your site. Safeguards scores your store. This one arms you for everyone you plug into them.