Vendor Claims Fact-Check Dossier
Use Perplexity to build a citation-backed procurement dossier that tests AI, SaaS, software, agency, or service-provider claims, grades evidence, records unresolved risks, and prepares precise vendor questions without representing research as approval or completed due diligence.
Create a procurement-focused fact-check dossier for the following inputs. Vendor and product: [Vendor and product] Claims and sales materials: [Claims and sales materials] Procurement context: [Procurement context] Evidence standard: [Evidence standard] Security, privacy, compliance, and AI requirements: [Security, privacy, compliance, and AI requirements] Commercial, contract, and customer claims: [Commercial, contract, and customer claims] Competitors: [Competitors] Provided public or sanitized sources and research cutoff date: [Provided public or sanitized sources and research cutoff date] INPUT CONTROL 1. Treat the supplied text and links as assertions or leads, not proof. Do not infer that a sales statement, logo, testimonial, comparison table, trust badge, questionnaire answer, or contract draft is accurate or current. 2. The minimum inputs needed to begin claim-level research are an identifiable vendor or product, at least one claim, the procurement decision being supported, and an evidence cutoff date. If any are missing, stop and request them. If optional inputs are absent, continue only where useful and list the omission without filling it by assumption. 3. If a claim is broad, split it into testable units. For example, separate a compliance claim into certification type, covered legal entity, product or service scope, audit period, status, and availability of supporting documentation. 4. If inputs conflict, preserve both versions, identify their sources, and ask which governs. Do not silently reconcile different product editions, legal entities, regions, dates, plan names, security scopes, prices, or contract terms. 5. Do not expose confidential sales materials, personal data, credentials, non-public security artifacts, or contract terms beyond what the user has supplied and is authorized to review. Recommend an approved private review channel when sensitive evidence cannot safely be assessed here. PERPLEXITY RESEARCH BOUNDARY Use Perplexity to locate and summarize publicly accessible sources and to attach citations to factual findings. Research requested in this prompt is not necessarily research executed: report only searches and source inspections actually reflected in the response. Never imply access to a private trust center, data room, paid report, customer reference call, internal system, signed agreement, audit report, or blocked page unless its contents were supplied or genuinely accessible in the current session. For every inaccessible, paywalled, login-gated, missing, or technically unreadable source, mark it Unavailable and state the limitation. If Perplexity returns a citation whose page does not support the stated proposition, mark the proposition Unverified rather than relying on the search summary. Never claim that evidence was verified merely because a citation was generated. Distinguish work state explicitly: - Requested: research or confirmation the buyer asked for. - Executed: a search or source inspection actually performed and evidenced by a citation or supplied material. - Proposed: a future review, vendor request, legal check, test, reference call, or negotiation step. - Unavailable: evidence could not be accessed or was not supplied. - Unverified: available material was insufficient to establish the claim. Do not say a claim, control, price, certification, customer relationship, test result, contract term, approval, message, or remediation was confirmed, tested, approved, sent, completed, or implemented without direct evidence for that exact statement. The dossier is decision support, not legal advice, a security assessment, an audit, a penetration test, a financial approval, or procurement authorization. CLAIM AND EVIDENCE METHOD 1. Build a complete inventory of material claims from the supplied inputs before searching. Record each atomic claim once and assign a stable identifier such as C-01. 2. Classify each claim as security, compliance, privacy, AI or data use, performance, pricing, contract, customer proof, integration, support, implementation, or competitive positioning. 3. Define the evidence needed before evaluating the claim. Apply [Evidence standard]; if it is unclear, ask for clarification when it would change the decision. Otherwise use a conservative standard and label it as an assumption. 4. Prefer evidence tied to the correct vendor legal entity, product, plan, region, and time period. Suitable primary evidence may include current official documentation, pricing and policy pages, contract language supplied by the buyer, certification registry records, regulator or standards-body records, official security advisories, and detailed customer case studies. 5. Seek independent corroboration where material, including regulator records, certification registries, public incident reports, procurement records, reputable technical evaluations, customer-authored statements, and dated marketplace records. Label vendor-authored and independent evidence separately; independence does not automatically make a source reliable. 6. For each source, record title, publisher, source category, URL or citation, publication or effective date when available, access date when available, relevant claim identifiers, exact proposition supported, and limitations. Never invent missing metadata. 7. Grade evidence as Strong, Moderate, Weak, or Insufficient, with a claim-specific reason. Marketing copy, unsourced comparison charts, sales decks, generic testimonials, and customer logos alone are Weak or Insufficient. 8. Assign exactly one verdict to each atomic claim: - Confirmed — current evidence meeting [Evidence standard] directly supports the complete atomic claim for the relevant legal entity, product, plan, region, period, and scope. - Partially confirmed — evidence supports only part of the claim or supports it only for a narrower entity, product, plan, region, period, condition, or scope. - Unsupported — no adequate supporting evidence was found or supplied within the stated research scope. Unsupported does not by itself mean that the claim is false. - Ambiguous — the wording, terminology, measurement, scope, ownership, timeframe, or intended interpretation is too unclear to assess reliably. - Contradicted — credible, relevant evidence directly conflicts with the atomic claim. Preserve the conflicting evidence and do not infer the cause without support. - Outdated — supporting evidence exists but is too old, superseded, or temporally mismatched for the current procurement decision. - Not enough evidence — access, source coverage, evidence quality, or the available research scope is insufficient to reach another verdict. A vendor-authored assertion alone may confirm only the narrower proposition that the vendor currently publishes or represents that statement. It does not independently confirm the underlying control, performance result, customer relationship, compliance status, or contractual commitment. Do not treat failure to find public evidence as proof that a claim is false. Record the search and access limitations and use Unsupported or Not enough evidence according to the distinction above. 9. Record conflicting evidence side by side. Explain differences in scope, date, entity, plan, geography, methodology, or terminology when supported; otherwise leave the cause unresolved. 10. Convert every decision-relevant evidence gap into a precise vendor question identifying the artifact, scope, date, or contractual commitment needed. DOMAIN-SPECIFIC CHECKS - Security and compliance: distinguish claimed, documented, certified, independently assessed, and contractually enforceable controls. Verify the standard, auditor or registry where public, audit period, report type, covered entity, product scope, exceptions, and document freshness. Do not equate a framework-aligned statement with certification. - Privacy and AI: distinguish model or subprocessors, customer-data use, training or improvement use, retention, deletion commitments, residency, cross-border transfers, human access, opt-out scope, logging, and contractual enforceability. Do not infer no-training or zero-retention commitments from general privacy language. - Performance: require a defined metric, test population, baseline, methodology, date, conditions, sample size when available, and independent reproducibility. Treat undefined accuracy, productivity, reliability, or best-in-class language as unsupported. - Pricing and contracts: identify currency, region, billing interval, plan, included usage, overages, minimum commitments, add-ons, implementation fees, renewal mechanics, cancellation terms, discounts, and source date. Published pricing is not proof of a buyer-specific final price; only supplied current contractual terms can evidence that price. - Customer proof: distinguish a vendor-displayed logo from a customer-authored confirmation. Check whether the relationship appears current, concerns the evaluated product, and supports the claimed use case or outcome. Do not contact customers or represent that a reference call occurred. - Competitors: compare only equivalent products, plans, regions, dates, and claim areas supported by evidence. Label missing or non-comparable data instead of ranking by assumption. REQUIRED DOSSIER Produce concise markdown with these sections: Keep the dossier concise and proportional to the number, materiality, and complexity of the claims and to the evidence actually available. Do not repeat the same claim, source description, evidence gap, or limitation across multiple sections unnecessarily. Use claim IDs and evidence IDs to cross-reference earlier records. Include only applicable domain-specific subsections. Where a subsection is genuinely outside scope or cannot be assessed, retain its heading when needed for decision clarity, state Not assessable, and explain briefly why. Never omit: - decision scope and research status; - claim inventory and verdict register; - evidence ledger; - decision-critical findings; - prioritized evidence requests; - research-informed decision posture; - verification and reconciliation record; - human review gates. Do not fill unsupported sections with generic procurement advice merely to complete the format. 1. Decision scope and research status State the vendor and product, decision, buyer context, cutoff date, required evidence level, material exclusions, missing or conflicting inputs, and a count of Requested, Executed, Proposed, Unavailable, and Unverified research items. State that no procurement approval has been granted by this dossier. 2. Claim inventory and verdict register Provide a table with: Claim ID; atomic claim; category; source of the claim; why it matters; required evidence; verdict; evidence strength; procurement reliance risk; and short rationale. Use these qualitative procurement-reliance risk labels: - High — accepting the claim without stronger evidence could materially change the buying decision or create substantial security, privacy, legal, financial, contractual, operational, customer, or reputational exposure. - Medium — the evidence gap is decision-relevant and should become a condition, vendor request, contractual requirement, or assigned follow-up, but it does not independently establish an immediate blocker. - Low — the claim is adequately supported for the stated evidence standard or the remaining uncertainty has limited consequence for the current decision. - Unknown — the available evidence, scope, or authority is insufficient to classify the reliance risk defensibly. Base each label on the importance of the claim, the evidence gap, the decision context, and the consequence of relying on it incorrectly. Do not infer likelihood or severity merely from generic industry experience. Do not convert the labels into a numerical score or present them as a comprehensive vendor-risk rating. 3. Evidence ledger Separate Vendor-authored, Independent, Buyer-supplied, and Unavailable evidence. For each accessible source provide: Evidence ID; title and publisher; source category; citation or URL; relevant date; claim IDs; exact support; strength; limitations; and access status. Do not list a source as independent if the vendor sponsored, republished, or supplied it unless that relationship is disclosed. 4. Material findings by claim For each High-risk or decision-critical claim, provide the verdict, supporting and conflicting evidence IDs, scope and freshness assessment, remaining uncertainty, buyer implication, and a proposed next step. Clearly label future steps as Proposed. 5. Security, privacy, AI, commercial, and customer-proof checks Include only applicable subsections. Map each supplied requirement or claim to evidence, unresolved gaps, and the artifact or contract language needed. If a subsection is not assessable, say why rather than producing a generic assessment. 6. Competitor evidence comparison If competitors were supplied, provide: claim area; vendor evidence; competitor evidence; comparability limits; and buyer implication. Omit unsupported rankings. 7. Prioritized vendor evidence requests Group precise questions by security and compliance, privacy and AI data use, pricing and contract, customer references, implementation, and support. Give each question a priority, linked claim ID, required response artifact, and acceptance condition. Do not state that questions were sent. 8. Decision posture Choose one: Choose one research-informed posture: - Proceed to approval review - Proceed to approval review with conditions - Delay approval review pending evidence - Do not proceed to approval review - Not enough evidence to form a posture. Tie the posture to specific claim IDs, conditions, unresolved evidence, residual reliance risks, and required human approvals. The posture indicates what the evidence supports as the next procurement step. It is not procurement approval, contract authorization, legal clearance, security acceptance, budget approval, or permission to onboard the vendor. 9. Verification and reconciliation record Report each check below as Pass, Fail, or Not assessable, with concrete evidence or an explanation: - Claim reconciliation: every material input claim appears once in the inventory or is identified as out of scope; provide input count, atomic claim count, and omitted-item count. - Verdict traceability: every verdict cites at least one evidence ID or explicitly states that no supporting evidence was found. - Citation entailment: each cited page supports the exact proposition attributed to it; identify citations that were not inspectable or did not support the proposition. - Scope match: security, compliance, privacy, pricing, performance, and customer evidence matches the relevant entity, product, plan, region, and period, or the mismatch is disclosed. - Freshness: source dates are recorded where available and evidence predating the stated cutoff or decision need is flagged with its resulting risk. - Source separation: vendor-authored, independent, buyer-supplied, and unavailable materials are not conflated. - Conflict handling: contradictory sources are retained and unresolved conflicts affect the verdict and risk. - Commercial reconciliation: quoted prices and terms identify currency, plan, region, billing basis, effective date, and contractual status where available. - Customer-proof threshold: no logo or vendor testimonial is reported as an independently confirmed current relationship without corroboration. - Completion integrity: every statement suggesting research, verification, contact, approval, testing, or completion is supported by evidence; otherwise it is relabeled Requested, Proposed, Unavailable, or Unverified. Acceptance requires all material claims to be reconciled, all verdicts to be traceable, all inaccessible evidence to be disclosed, and all decision-critical conflicts or gaps to appear in the vendor requests and decision posture. If any requirement fails, label the dossier Incomplete for procurement reliance and list the exact remediation needed. 10. Human review gates Identify the authorized functions that still need to review applicable legal terms, privacy obligations, security evidence, financial exposure, regulatory fit, and final procurement approval. Recommend escalation proportionate to risk, but do not assign approval that has not occurred.