Home / Methodology
PUBLIC PRODUCT METHODOLOGY

How ProcureDeal Decides What an Answer Can Safely Claim

ProcureDeal is designed around a simple rule: if the supplied evidence cannot support a material claim, the system should not quietly turn that uncertainty into a confident answer.

Published by ProcureDeal Updated 15 September 2026 · Editorial policy · AI-use disclosure

1. Evidence boundary

For questionnaire analysis, the drafting workflow is instructed to use only the evidence supplied for that analysis. It should not infer that a certification, security control, privacy practice, retention rule, training exclusion, legal compliance position or human-oversight process exists unless the supplied evidence supports it.

2. Response states

SUPPORTED

Evidence clearly supports the answer

The source directly supports the material statement being drafted.

PARTIAL

Evidence supports only part of the claim

The answer is narrowed and remaining uncertainty is surfaced.

GAP

Evidence is missing or insufficient

The question should be confirmed by the accountable human owner.

3. Confidence scoring

Confidence is intended to reflect the strength and directness of the supplied evidence, not the probability that the organization is compliant and not a guarantee that the generated answer is correct. A high score is still a draft that requires human review.

4. Human accountability

Security, privacy, legal, product and governance owners remain responsible for final approval. ProcureDeal is a research and drafting workflow, not a compliance certification service or legal adviser.

5. Source hierarchy

Stronger evidence is usually a current policy, contractual document, product architecture record, approved technical documentation or current owner-confirmed position. Previously answered questionnaires can be useful retrieval sources, but they should be revalidated when the underlying product, providers or policies change.

Framework references

When discussing AI governance concepts, ProcureDeal links to primary framework sources such as NIST AI RMF and Cloud Security Alliance AI-CAIQ/AICM materials.