▸case-01 We are preparing to close our first mid-market healthcare customer (around 1,500 employees, US-based). Here is our posture: AWS-hosted web app, Google Workspace authentication (SAML SSO not implemented yet), SOC 2 Type II attestation currently in progress, processing employee PII, 12-person team, basic privacy policy and terms on hand, no custom DPA or BAA ready. We have no formal disaster recovery drill documented.
Please simulate an enterprise procurement evaluation for us. We need:
1. A findings evaluation table organized across security, legal, compliance, and vendor continuity desks, showing grades and how each finding impacts the deal outcome.
2. A procurement stall forecast estimating how long review will take in weeks based on identified blockers.
3. A debrief action plan listing the artifacts we need to build, ordered by overall impact per effort, plus an honest sales positioning statement for our reps when asked about current gaps. | fail→pass | 30,068 | 28,609 | -5% | 1 | 1 | 0% | 4,005 | 4,746 | +19% | 0 | 0 | — |
▸case-02 Our dev-tools startup is target-pitching a 500-employee fintech in Europe. Our posture: single-tenant AWS setup, password and TOTP auth without SAML, handling developer credentials and repository metadata, SOC 2 Type 1 completed, third-party penetration test done 4 months ago, basic DPA and security summary available, $1M cyber insurance policy, team of 15. Gaps: no automated data deletion endpoint, missing formal business continuity plan.
I want a complete vendor risk assessment simulation. Please deliver:
- A structured table of findings grouped into security, legal, regulatory compliance, and vendor viability categories, detailing deal consequences and evaluation grades.
- A timeline forecast of potential procurement delays measured in weeks.
- A debrief matrix prioritizing missing artifacts by deal unblocking value relative to effort, along with clear sales copy guidelines on how to discuss our posture transparently. | fail→pass | 36,491 | 30,623 | -16% | 1 | 1 | 0% | 4,498 | 5,216 | +16% | 0 | 0 | — |
▸case-03 We are an AI workflow automation company pitching a US regional bank with 5,000 employees. Our current state: Azure cloud infrastructure, Okta SAML SSO supported, AES-256 and TLS encryption, SOC 2 Type 2 report available, handling customer service logs containing PII. Paper ready: standard MSA, privacy policy, subprocessor list. Gaps: no software escrow, limited disaster recovery testing history, liability limits capped at 1x contract value.
Please run a mock vendor risk review from their perspective. Provide:
1. A categorized findings matrix covering security, legal, compliance, and vendor operational risk desks, grading each issue and explaining its deal-level impact.
2. An estimated procurement completion timeline highlighting the main schedule drivers.
3. An out-of-character debrief recommending which compliance/security documents to build first (sorted by effort-adjusted deal enablement) and a survivable positioning line for sales reps. | fail→fail | 56,733 | 27,126 | -52% | 1 | 1 | 0% | 6,477 | 4,768 | -26% | 0 | 0 | — |
▸case-04 Draft a master services agreement (MSA) contract template for our B2B SaaS platform, including standard clauses for intellectual property ownership, 30-day payment terms, limitation of liability, and mutual confidentiality. | pass→fail | 29,218 | 42,562 | +46% | 1 | 1 | 0% | 4,520 | 6,310 | +40% | 0 | 0 | — |
▸case-05 We are setting up pricing tiers for our B2B SaaS startup targeting mid-market and enterprise accounts. Help us design a pricing model with seat-based tiers, feature gating for SSO, and enterprise volume discounts. | pass→fail | 25,701 | 36,743 | +43% | 1 | 1 | 0% | 3,421 | 5,032 | +47% | 0 | 0 | — |
▸case-06 Provide a step-by-step engineering guide for implementing SAML 2.0 single sign-on authentication using Passport.js and Okta in a Node.js Express backend application. | pass→pass | 31,310 | 22,744 | -27% | 1 | 1 | 0% | 5,800 | 5,183 | -11% | 0 | 0 | — |
▸case-07 Run a vendor review simulation for an e-commerce analytics SaaS pitching a 10,000-person retail chain in North America. Posture: GCP multi-tenant, Auth0 SAML support, SOC 2 Type 2 complete, handling anonymized transaction logs, team of 40. Gaps: subprocessor list is outdated by 6 months, no annual third-party pen test report available. | fail→fail | 23,626 | 29,479 | +25% | 1 | 1 | 0% | 3,600 | 3,738 | +4% | 0 | 0 | — |
▸case-08 Simulate procurement review for a recruitment software vendor selling to a 2,000-employee European enterprise. Posture: AWS Frankfurt region, email/password login only (no SAML), processing candidate CVs and email addresses, ISO 27001 certified, team of 25. Gaps: no formal DPA with standard contractual clauses, EU data subject request process is manual. | pass→fail | 25,247 | 23,074 | -9% | 1 | 1 | 0% | 3,154 | 3,395 | +8% | 0 | 0 | — |
▸case-09 Conduct a vendor evaluation simulation for a log analysis tool pitching a US defense contractor with 8,000 employees. Posture: self-hosted Docker container, local active directory auth, handling internal network metadata, no cloud storage, team of 8. Gaps: company is 6 months old, $500k ARR, no SOC 2, basic $1M general liability insurance. | pass→pass | 38,940 | 26,564 | -32% | 1 | 1 | 0% | 4,369 | 4,243 | -3% | 0 | 0 | — |
▸case-10 Simulate an enterprise procurement review for a student testing application pitching a school district with 40,000 students. Posture: AWS US-East, Google Single Sign-On supported, handling student grades and parent contacts, no SOC 2 report, team of 10. Gaps: no FERPA compliance whitepaper, data retention policy does not specify automated deletion upon contract termination. | fail→pass | 28,419 | 27,083 | -5% | 1 | 1 | 0% | 3,125 | 3,965 | +27% | 0 | 0 | — |
▸case-11 Simulate a vendor review for a email marketing platform selling to a 3,000-employee global hotel brand. Posture: AWS infrastructure, SAML SSO supported, handling customer email lists and first names, ISO 27001 audit scheduled in 3 months, team of 50. Gaps: indemnity clause in terms limits liability to 6 months of fees, subprocessor list missing cloud provider regions. | fail→pass | 26,651 | 34,397 | +29% | 1 | 1 | 0% | 2,904 | 3,295 | +13% | 0 | 0 | — |
▸case-12 Simulate procurement for an API middleware provider pitching a 3,000-employee credit union. Posture: multi-cloud AWS/Azure, SAML/OIDC ready, SOC 2 Type 2 completed, handling financial transactions, team of 80. Gaps: disaster recovery RTO is 24 hours, liability cap is set to $100k, no business continuity drill performed in past 18 months. | fail→fail | 30,222 | 23,729 | -21% | 1 | 1 | 0% | 3,825 | 3,966 | +4% | 0 | 0 | — |
▸case-13 Run an enterprise vendor assessment simulation for a static code analysis startup pitching a 4,000-developer tech company. Posture: SaaS offering, GitHub OAuth login only (no SAML), access to proprietary source code, SOC 2 Type 1 completed, team of 6. Gaps: no SOC 2 Type 2 report, no escrow agreement for code models. | fail→pass | 39,404 | 24,571 | -38% | 1 | 1 | 0% | 4,353 | 3,553 | -18% | 0 | 0 | — |
▸case-14 Evaluate our telehealth video API startup pitching a 2,500-employee hospital network. Posture: WebRTC architecture, AWS infrastructure, HIPAA compliant infrastructure with signed AWS BAA, SOC 2 Type 2 complete, SAML SSO available, team of 30. Gaps: standard DPA excludes customized BAA indemnification, no cyber insurance policy on file. | pass→fail | 22,790 | 22,261 | -2% | 1 | 1 | 0% | 2,839 | 3,572 | +26% | 0 | 0 | — |
▸case-15 Simulate procurement evaluation for an IoT logistics tracker selling to a global shipping company (20,000 employees). Posture: AWS IoT Core, SAML SSO enabled, SOC 2 Type 2 active, handling GPS location logs and cargo manifests, team of 60. Gaps: no automated data purge on account closure, third-party penetration test is 14 months old. | pass→pass | 23,904 | 22,963 | -4% | 1 | 1 | 0% | 3,094 | 3,603 | +16% | 0 | 0 | — |
▸case-16 Perform a procurement gauntlet evaluation for an AI contract reviewer pitching a 500-attorney law firm. Posture: Azure OpenAI integration, SSO via Azure AD, SOC 2 Type 2 ready, handling confidential legal contracts, team of 18. Gaps: privacy policy permits using customer queries for aggregate model tuning, no liability coverage for professional negligence. | fail→pass | 26,469 | 23,994 | -9% | 1 | 1 | 0% | 4,150 | 4,078 | -2% | 0 | 0 | — |
▸case-23 Simulate a procurement gauntlet evaluation for a vendor onboarding workflow app selling to a 10,000-employee enterprise conglomerate. Posture: AWS US-West, SAML SSO active, SOC 2 Type 2 available, handling vendor financial records, team of 50. Gaps: company is 2 years old with 10 employees, $1M ARR, no disaster recovery failover region configured. | pass→pass | 25,851 | 33,378 | +29% | 1 | 1 | 0% | 3,469 | 4,890 | +41% | 0 | 0 | — |
▸case-17 Simulate enterprise procurement review for a claims processing engine targeting a top-10 insurance carrier (15,000 employees). Posture: AWS US regions, SAML SSO, SOC 2 Type 2, handling claimant PII and medical billing codes, team of 45. Gaps: disaster recovery RPO is 12 hours, subprocessor list missing secondary hosting providers, MSA lacks audit rights clause. | pass→fail | 22,210 | 23,677 | +7% | 1 | 1 | 0% | 4,097 | 3,640 | -11% | 0 | 0 | — |
▸case-18 Evaluate our customer support AI plugin pitching a mid-market e-commerce company (800 employees). Posture: Cloudflare Workers architecture, SAML supported, handling customer chat histories, SOC 2 Type 1 completed 2 months ago, team of 10. Gaps: no formal incident response plan document, basic terms of service with no uptime SLA. | pass→pass | 27,998 | 27,895 | -0% | 1 | 1 | 0% | 3,168 | 4,022 | +27% | 0 | 0 | — |
▸case-19 Simulate a vendor risk evaluation for a sales video recording app pitching a 3,000-person enterprise software company. Posture: AWS S3 video storage, Google Workspace auth, SOC 2 Type 2 in progress (audit period ending in 2 months), handling recorded sales calls, team of 14. Gaps: no SAML SSO support, standard contract has unlimited customer indemnification. | fail→pass | 27,856 | 24,487 | -12% | 1 | 1 | 0% | 3,133 | 3,982 | +27% | 0 | 0 | — |
▸case-20 Run a simulated procurement review for an automated expense reporting tool pitching a 5,000-employee consulting firm. Posture: AWS infrastructure, SAML SSO ready, SOC 2 Type 2 complete, handling employee credit card transactions and receipts, team of 70. Gaps: subprocessor list hosted on an unlinked Google Doc, no software escrow, insurance certificates expired last month. | pass→pass | 26,188 | 20,411 | -22% | 1 | 1 | 0% | 3,252 | 4,025 | +24% | 0 | 0 | — |
▸case-21 Simulate an enterprise procurement review for a data observability tool pitching a 2,000-person fintech startup. Posture: AWS read-only IAM roles, SAML SSO supported, SOC 2 Type 2 active, handling database metadata and query performance logs, team of 35. Gaps: breach notification period in terms is 72 hours (buyer requires 24 hours), no disaster recovery drill documentation. | fail→pass | 26,228 | 22,402 | -15% | 1 | 1 | 0% | 3,215 | 3,529 | +10% | 0 | 0 | — |
▸case-22 Conduct a vendor risk assessment simulation for a lab sample tracking software selling to a 1,000-employee pharmaceutical firm. Posture: Azure hosted, SAML SSO ready, handling proprietary chemical formulas and test results, SOC 2 Type 1 complete, team of 20. Gaps: no formal data backup testing records, terms missing intellectual property indemnity for third-party claims. | fail→pass | 24,337 | 24,687 | +1% | 1 | 1 | 0% | 3,211 | 3,489 | +9% | 0 | 0 | — |
▸case-24 Run a procurement evaluation simulation for an access governance tool pitching a 6,000-employee insurance provider. Posture: AWS cloud, SAML SSO supported, SOC 2 Type 2 complete, handling active directory user roles, team of 40. Gaps: subprocessor inventory missing security certs, terms restrict customer audit rights to once every 3 years. | fail→pass | 23,618 | 19,003 | -20% | 1 | 1 | 0% | 3,367 | 3,134 | -7% | 0 | 0 | — |
▸case-25 Simulate procurement review for a cloud bill management SaaS targeting a 3,000-employee media company. Posture: GCP, SAML SSO ready, SOC 2 Type 2 report available, handling cloud billing data and resource tags, team of 22. Gaps: breach notification clause specifies best efforts without fixed hours, no formal security whitepaper available. | fail→pass | 24,779 | 20,043 | -19% | 1 | 1 | 0% | 2,842 | 3,302 | +16% | 0 | 0 | — |