AI Risk Library

How risky is your team's AI?

A reference library of 500+ AI tools, reviewed across 9 attributes that matter to security and procurement teams.
500+ AI tools · 9 risk attributes · Free, no signup required

Explore up to 5 AI tools, then book a meeting for the full industry analysis.

How the Risk Library works

9 attributes that matter to security and procurement teams.

Each tool in the library is reviewed against nine attributes using publicly available evidence: vendor documentation, terms of service, privacy policies, and regulatory disclosures. The Risk Library is a high-level screening aid, not a security audit.
01

Audit log / trail

Whether the tool produces an audit log of user activity, what's captured, and whether logs are exportable.
02

Geographic data centers

Where the tool processes and stores data. Critical for data residency requirements in regulated industries.
03

Intellectual Property

Whether the tool's terms of service preserve customer IP ownership of inputs and outputs, or claim license over them.
04

Prompt injection

Whether the tool has known vulnerabilities to prompt injection attacks, and what mitigations are in place.
05

SOC 2 / ISO 27001

Compliance certifications the tool holds. Required for many enterprise procurement processes.
06

Supply chain vulnerabilities

Disclosed CVEs, security incidents, and breach history affecting the tool or its dependencies.
07

Third-party AI risks

Which third-party AI models or services the tool depends on, and what data flows to those parties.
08

Training on data

Whether the tool trains its models on customer prompts and outputs by default, and whether opt-out is available.
09

Zero data retention

Whether the tool offers a zero-data-retention mode where inputs and outputs are not stored after processing.
The bigger picture

This library tells you about a tool.
Risk Monitoring tells you what your team is actually using.

Looking up one tool is a start. Knowing what your employees use, who's using it, and with what data, is the real question.
01

What this library does

Helps you assess a specific AI tool before deciding whether to allow it. One tool at a time, in any browser.
02

What this library can't tell you

Which AI tools your employees are using right now. Whether they're sharing sensitive data. Which department is using what. What's been growing in usage over the last 30 days.
03

What Risk Monitoring does

Continuous, on-device visibility into every AI tool, account, and prompt across your organization. Same 9-attribute risk model, applied to your real environment.
Trusted by

Trusted by security teams evaluating real AI risk.

We want to give our employees these tools, but we need to do it in a safe & responsible way. We really think MagicMirror can be the avenue for that.”
— Brian
Head of IT & Corporate Security, Hover
We had written our AI policy and outlined best practices, but we needed to have confidence that they were being followed."
—  Bill Coapman
I.T. Manager
The user experience has been a great enabler for our employees. With MagicMirror enforcing policies & maintaining privacy standards for us, IT has become less of a “no” organization & more of a “yes” when it comes to AI.”
— Brian
Head of IT & Corporate Security, Hover
I don’t want to just block tools—we need to know how they’re being used so we can help our attorneys work smarter,”
—  Bill Coapman
I.T. Manager
It’s changing how we think about endpoint security.”
— David Baker
Former CSO at, Okta
MagicMirror doesn’t feel like a hammer—it’s a toolbox. It provides us with visibility, protection, and the ability to shape AI usage based on real-world data. We’re not guessing anymore.”
—  Bill Coapman
I.T. Manager
Customers & Partners

Stop assessing one tool at a time.

Get started

See every AI tool, account, and prompt across your organization in real time. Continuous visibility into your real environment.