An open standard for trustworthy self-hosted AI.
Most "AI for business" products are marketing claims dressed as technology. "Secure" means they encrypt the connection. "Private" means they won't sell your data — probably. SHAITS answers what those claims don't: where your data sits, who can see it, what happens when the vendor disappears, and whether it works offline. 125-point score across 5 categories. Cloud products cannot qualify.
Five questions SOC 2 won't answer.
Compliance frameworks tell you who's compliant. They don't tell you whether your AI vendor's architecture actually matches what they're selling. SHAITS puts specific, reproducible answers on the record.
- Where does my data physically sit?
- Who else can see it?
- What happens when the vendor disappears?
- Can I export everything and leave?
- Does it work if my internet dies?
125 points, 18 criteria, 5 lenses.
Each criterion has a testable spec with point tiers (10/5/0 or 8/4/0). Every test has a defined automation method — anyone can reproduce any score.
Four outcomes. No middle ground.
Three paths to certification.
Self-audit for free. Get an independent review when you're ready to ship a badge. Continuous monitoring for enterprise compliance.
audit_runner.py against your repo. Produces JSON report per criterion. Shareable badge. Open source, reproducible.- ChatGPT Teams / Enterprise — fails A1 (cloud-only)
- Microsoft Copilot — fails A1, A3
- Google Gemini for Business — fails A1
- Claude Teams — fails A1
Cloud products may have excellent security, privacy policies, and SOC 2 certifications. They may be the right choice for many customers. But they do not meet the definition of "actually self-hosted," and SHAITS exists to make that distinction precise. By our criteria, the big AI players don't even qualify.