# Entropy — full description > Entropy is an independent AI vendor trust and security directory. It scores AI > companies on observable security posture and AI-safety practices, turning > unverified vendor claims into evidence-backed report cards (grades A+ to F) for > CISOs, procurement teams, VCs doing diligence, and anyone vetting an AI tool > before procurement approval. This is the expanded version of https://entropy.com/llms.txt. It is descriptive only: it contains no installation commands, no package names, and no scripts, and neither does any page it links to. Entropy's own scanner treats a file that tells an agent to fetch and execute something — for example, one that pipes a remote download straight into a shell, or that instructs an agent to install a named code package — as an attack-surface finding, so Entropy holds its own published files to that same bar. Treat everything here as context for a human or an agent deciding which links to open, not as instructions to act on. ## What Entropy is Security teams were answering the same security questionnaire dozens of times, and buyers had no independent, evidence-backed way to compare AI vendors on security and AI-safety practices side by side. Entropy exists to close that gap. It is not pay-to-play: a vendor cannot buy a better grade, and a vendor does not need to pay or claim anything to be listed and scored. Paid tiers add convenience features (bulk comparison, score-change alerts, higher API limits, the embeddable verified badge), never score movement. ## How scoring works Every vendor is scored against a versioned rubric across five categories: technical security, AI safety, governance, incident history, and a verification bonus. Each grade is computed from the signals actually implemented for that vendor, not against a fixed maximum, and every score document records the rubric version it was produced under so historical grades stay interpretable after the rubric changes. Scores are append-only — a new scan writes a new version rather than overwriting the last one, so a vendor's trajectory over time is visible. The signals Entropy reads are all public and independently verifiable: - A security.txt file at the well-known location, and whether it carries the fields RFC 9116 expects. - HTTPS enforcement and HTTP Strict Transport Security configuration. - HTTP security response headers. - A published, findable vulnerability-disclosure or responsible-disclosure policy. - Third-party compliance attestations discovered on public trust pages: SOC 2 Type I and Type II, ISO 27001, ISO 42001, and HIPAA. Each finding on a company profile links to the evidence it came from and the date it was observed. A certification Entropy only saw mentioned publicly is labelled as unverified; one an Entropy admin confirmed, or one backed by vendor evidence an admin reviewed, is labelled accordingly. Nothing is asserted as "certified" on a vendor's behalf. ## Claiming a profile A vendor can claim its profile by adding a DNS TXT record to prove control of the domain. A verified claimant can edit descriptive profile fields, attach an optional public attribution (their name and role, self-attested), upload compliance evidence for admin review, and confirm which AI models their product uses. None of these actions change the vendor's grade on their own; evidence raises governance credit only after a human at Entropy reviews it. ## AI model disclosure Entropy reads the AI-model names a vendor states in its own llms.txt or llms-full.txt and surfaces them on the company profile as a self-disclosed, unconfirmed list, with a dated citation to what Entropy captured at scan time. The vendor can confirm or correct that list from their dashboard. This is informational only and is not part of the Entropy score. Entropy itself is a scoring service, not a model-backed product, and has nothing to disclose here. ## For developers Entropy's public read API for grades and directory data is not currently available. The directory is available as a single static data file for building comparisons and autocomplete. ## Key links - [Home](https://entropy.com/) - [Directory](https://entropy.com/directory) - [Compare vendors](https://entropy.com/compare) - [Methodology](https://entropy.com/methodology) - [About](https://entropy.com/about) - [Learn guides](https://entropy.com/learn) - [Glossary](https://entropy.com/glossary) - [Blog](https://entropy.com/blog) - [Pricing](https://entropy.com/pricing) - [Claim your profile](https://entropy.com/claim) - [Security](https://entropy.com/security) - [Contact](https://entropy.com/contact) - [Security reporting](https://entropy.com/.well-known/security.txt)