For CIOs and security leaders
Five questions to ask before an AI agent relies on security reference data
Your people may already ask assistants about CVEs. Here is what to ask about the source behind the answer, and how Lattice answers each one.
6 minute read
The assistant is already in the room
In many firms analysts, engineers and the person who runs IT on the side are asking AI assistants what a vulnerability means and what to do about it. The answer arrives fluent and unsourced. Nobody decided that this is how security reference knowledge reaches your decisions; it just became how.
You do not have to ban it. You can ask five questions of whatever it relies on. They apply to any vendor, including us.
The five questions, and how Lattice answers them
| Ask | Why it matters | Lattice |
|---|---|---|
| Where does each fact come from? | An unsourced fact cannot be checked or defended. | Every link names its source, and every answer lists the licence notices that apply. |
| Does it separate what a source stated from what the system guessed? | A guess that reads as a fact travels into a report. | Yes. Each link is declared or inferred, and inferred links carry a confidence figure. Missing data is reported as missing. |
| What leaves our network? | Prompts leak. Assume everything you send is stored. | Only public identifiers such as a CVE number or an ATT&CK technique id. The interface rejects free text, so there is nowhere to put your data. |
| Who can see what was asked, and for how long? | You need to be able to answer this for your own customers. | We log the tool, the identifiers asked about, timing, the client name and version, and a salted one-way hash of the address. Not the raw address, and never the key. The beta terms say we may keep the logs after the beta. |
| What happens when it is wrong, or gone? | The honest answer decides how much weight it can bear. | It comes as is: no warranty, no service level, no promise it continues. It is a beta. Treat it as a lead generator, not a system of record. |
What to do this quarter, with or without us
- Ask the five questions of every AI tool your team uses for security work, and write the answers down.
- Require that an agent reports sources and uncertainty, not only conclusions. This is a prompt and a review habit before it is a tool.
- Decide what must never be pasted into an assistant (customer data, secrets, internal hostnames) and say so in writing.
- Check how your own estate looks, so the reference material has something real to be read against.
Where this lands on a questionnaire
Some enterprise security questionnaires now ask how AI tools are used and what data they see. Questions three and four above are most of the answer.
What we will not tell you
- That it keeps you safe. It looks at nothing of yours.
- That it is a replacement for an analyst, or for a person who knows your estate.
- That it will be there, or free, after the beta.
Where to go next
- The IT check — Reference material tells you what is known. The check tells you where your own estate stands.
- IT and security for small firms — The service behind the reference layer: someone who looks after your own estate.
- Surviving the enterprise security questionnaire — AI use can be a line on those questionnaires. This is how to answer the rest.
- Get a Lattice trial key — read the beta terms first.