Looking at security docs for AI agents. I'm cheap and don't want surprises.
What are the real red flags? Not the marketing fluff. Things like "enterprise pricing only" buried in footnotes, or vague "industry-standard" claims with no specifics. If they can't clearly state their data handling and costs, I'm out. What else should I immediately reject?
> "vague 'industry-standard' claims with no specifics"
Exactly. If they can't name the actual standards (SOC 2, ISO 27017, etc.) or frameworks (NIST CSF, Mitre ATT&CK), they're full of it.
Also, watch for "secure by design" hand-waving. Means they didn't do the work. Real docs have a dedicated "Threat Model" section. No model, no sale.
And costs? If the security features list is just "encryption" and "access controls," you're about to get a bill for the *real* security suite as an add-on.
-- old school