Evidence-aware product decisions

Supply chain assurance

AIM evaluates whether the evidence behind software, hardware, cloud, SaaS, AI, and managed-service products is sufficient for an organization's intended use and risk tolerance.

Freedom AIM eagle and gear mark

The principle

AIM continuously evaluates products using versioned criteria and traceable evidence, clearly distinguishes verified findings from supplier assertions and unknowns, and applies each organization's risk tolerance to determine whether the available assurance is sufficient for the intended use.

Unknown is not low risk, and missing evidence is never converted into a neutral score.

Why supply-chain risk belongs in modernization

A product can meet functional and security requirements while still introducing unacceptable risk through opaque dependencies, weak update controls, concentrated suppliers, unsupported components, compromised delivery paths, or an impractical exit strategy. Those risks affect governments, hospitals, regulated businesses, critical infrastructure, and commercial enterprises differently.

AIM therefore treats product assurance as a distinct decision dimension. It does not replace cybersecurity, compliance, or vendor-lock-in analysis; it works with those engines to show whether a product is both capable and sufficiently supportable for the proposed mission.

What AIM evaluates

The versioned SCRM rubric contains 13 weighted criteria across these assurance areas:

Supplier governance & ownership

Who controls the product, how accountability is assigned, and whether material ownership changes are visible.

Secure development

Documented secure-development practices, artifact integrity, signing, and release controls.

Component transparency

Product-specific SBOM, VEX, dependency, and fourth-party visibility.

Vulnerability response

Known exploitation, remediation performance, disclosure practices, and incident notification.

Resilience & lifecycle

Operational resilience, supported lifecycle, update continuity, and recovery readiness.

Provenance & chain of custody

The traceability and integrity of software, hardware, firmware, models, and delivery paths.

Exit continuity

Portability, customer-controlled data or keys, transition support, and the ability to leave safely.

How the assurance flow works

  1. 1

    Capture organizational tolerance

    The assessment records supply-chain risk tolerance, workload criticality, minimum evidence expectations, concentration tolerance, acceptable disruption duration, and mandatory controls.

  2. 2

    Resolve the exact product

    AIM links evidence only after the product, offering, version, CPE, PURL, or supplier document identity is sufficiently specific. Ambiguous matches are quarantined for review.

  3. 3

    Collect traceable evidence

    Source-specific collectors preserve evidence from authoritative registries, vulnerability sources, supplier advisories, and reviewed documentation with freshness and provenance.

  4. 4

    Separate fact from assertion

    Independent or authoritative findings, supplier assertions, disputed facts, expired evidence, and unknowns remain visibly distinct.

  5. 5

    Calculate a versioned standing

    A deterministic rubric produces assurance, confidence, coverage, known adverse risk, conservative bounds, failed gates, and missing evidence—not one unexplained number.

  6. 6

    Apply intended-use context

    AIM evaluates whether the available assurance is sufficient for this organization and workload. Critical gates can disqualify a product even when its aggregate score appears strong.

  7. 7

    Monitor for material change

    Time-sensitive events can trigger early review. High-impact, stale, or unassessed products are scheduled for monthly review; stable ordinary products are reassessed at least quarterly.

The assessment inputs that change the answer

  • Supply-chain risk tolerance
  • Workload criticality
  • Minimum supplier transparency
  • Supplier concentration tolerance
  • Acceptable disruption duration
  • Required SBOM or VEX
  • Signing and provenance requirements
  • Incident-notification and remediation thresholds
  • Exit plans and customer-controlled keys
  • Documented exception rationale

The same product can be acceptable for a low-impact internal workload and unacceptable for a mission-critical or patient-care workload. AIM preserves the policy context used for each decision so the result can be reproduced later.

A seventh RAO dimension—only when defensible

AIM's six core RAO dimensions remain available for every recommendation. Supply Chain Assurance becomes a seventh dimension only when the assessment contains an explicit, non-unknown supply-chain tolerance and the exact product has a current evidence-backed score.

When either condition is absent, AIM does not invent a middle score. It keeps the six-dimensional ranking compatible, identifies the assurance gap, and allows the missing evidence to be addressed through review.

Current capability status

AIM's versioned rubric, assessment fields, conditional RAO integration, evidence ledger, identity matching, review workflow, score history, and scheduled collection foundation are implemented. The catalog has product-level applicability dispositions and is being expanded through reviewed CPE, PURL, registry, and supplier-advisory mappings.

Coverage is not represented as universal. A catalog product without sufficient product-specific evidence remains unassessed or insufficiently evidenced until its identity and findings are reviewed. External pilot validation and broader supplier coverage remain required before AIM claims catalog-wide assurance.

Continue exploring

Supply Chain Assurance | AIM | Freedom AIM