How to read an AI Trust Scan report
A grade is easy to glance at and easy to misread. Here is how to read one properly — the dimensions behind it, the evidence classes under each claim, and what the report is careful not to say.
An AI Trust Scan gives you a grade and a TRUSTYCYBER Score. Both are useful at a glance, and both are easy to misuse if you stop there. The value of the report is in the layers beneath the number. Here is how to read them.
Start with the dimensions, not the score
The score is a summary of eight weighted dimensions — governance, model and provider transparency, independent assurance evidence, and others — graded with fixed weights for the scope profile (vendor, product or organisation). Because the weights are fixed, the same subject is measured the same way every time, and two vendors can be compared without one being flattered by a better story.
Read the dimensions before the headline. A solid overall score can still hide a weak spot on the one dimension that matters most for your use. A middling score might be entirely acceptable if the strength sits exactly where you need it.
Check the evidence class on each claim
Every claim in the report is labelled with how strong its source is. From strongest to weakest, the ones you will see most often:
- Registry-verified — confirmed against an official third-party register, such as an accredited certification body's public registry. This is the firmest ground.
- Externally corroborated — stated by a source independent of the vendor, not merely repeated across the vendor's own pages.
- Vendor-published — stated by the vendor on a domain it controls, with no independent corroboration found. Not worthless, but not confirmed.
- Media-reported — reported by an analyst, journalist or reviewer without independent verification of the underlying fact.
- Inferred — not directly stated, but reasonably drawn from stated facts. Always flagged as inference, never presented as a claim.
The label is the point. A registry-verified certification and a vendor-published assertion of the same thing are not equivalent, and a good report never lets them blur together.
Notice what the report says is missing
Two markers do quiet, important work.
Verified absence means a topic was actively searched for and no statement was found. It is never used for topics that simply were not examined — only for genuine gaps. It is not an accusation; it is a prompt for the question you should ask next.
Conflicting claims means two or more sources say things that cannot both be straightforwardly true. Rather than pick a winner, the report shows both and notes the conflict, so you can judge it yourself.
How certifications are handled
Certification claims get particular care, because they carry weight. A claim is walked up a verification ladder — claimed by the vendor, then evidenced in a document, then corroborated on the issuing body's public registry. Where a claim reaches the top of that ladder, you can rely on it. Where it stops partway, the report tells you exactly how far it got.
Then follow the links
Every figure links back to the evidence behind it, and every published scan resolves to a full report in the Trust Directory that anyone can open and check. If a conclusion matters to a decision you are making, do not take it on trust — follow it to its source. That the report invites you to is the whole idea.
Every report can be checked. Run a free AI Trust Scan and read one end to end, or browse the Trust Directory to see published reports.
