Chrysalis
Free self-assessment Start the scorecard
Free self-assessment

The AI You Can Defend Scorecard

Fifteen questions, about five minutes, two scores. Who in your service currently has nobody to ask? And if something answered them, could you show a regulator, an auditor or a client what it was told and what it said?

15 questions· About five minutes· Score shown instantly· No sign-up to see it
Start the scorecard

Your score appears before we ask you for anything. Answer honestly. Nobody is watching, and a flattering score tells you nothing.

Two scores, not one grade

You get two scores because they answer two different questions, and they move independently. Strong on one says nothing about the other.

Opportunity

Who in your service currently has nobody to ask. A social worker whose week overruns, a carer with a question at nine on a Sunday night, a young person who wants to read what has been written about them. And what the record you keep now will be worth to that child later.

Defensibility

If AI did that work, could you say where your information went, who processed it, in which country, under whose law? And could you show exactly what the tool was told and what it answered? That is what a regulator, auditor or client would ask for.

Your two scores place you in one of four positions. Each one has a clear next step.

Question {{ qNumber }} of 15 · {{ qAxis }} {{ qGroup }}

{{ qText }}

Back Next
Your result
Opportunity · who has nobody to ask
{{ oppPct }}/100
Defensibility · could you prove it?
{{ defPct }}/100
Your position
{{ quadName }}
Proof without reach Ready to move Standing start Reach without a record
← Opportunity → ↑ Defensibility

{{ quadName }}

{{ quadBlurb }}

The detail behind your scores
{{ row.label }} {{ row.band }}

Two last questions, then the full read-out

Neither of these changes your score. They decide which half of the read-out is worth your time.

{{ qb.text }}
{{ qb.note }}
{{ err.msg }}
Show my full read-out Nothing has reached us yet
Your read-out

{{ sentHeading }}

Inside: your three next actions in order, a score for where your information goes, the eight questions a regulator would ask you, and an honest note on what this scorecard cannot tell you.

{{ confirmNote }}

Opportunity {{ oppPct }} · Defensibility {{ defPct }} · Data control {{ dcPct }} · {{ quadName }}

Download your read-out (PDF) Print this page Start again

What you get at the end

Immediately, before we ask for anything
Your opportunity and defensibility scores, out of 100
Your position plotted on the grid, with the quadrant named and explained
The detail behind the scores: five bars showing exactly where you are strong and where you are exposed
In the full read-out
Your three next actions, in order, specific to where you landed
Where your information goes, scored on its own. For most organisations this is the number that stings
The eight questions a regulator, auditor, insurer or client will eventually ask you, so you can rehearse the answers before anyone asks for real
An honest note on what this scorecard cannot tell you

Written so you could put it in front of a board or a management meeting without translating it first.

Where organisations land

↑ Higher defensibility Higher opportunity →
Proof without reach

You built the controls, and nobody is better served than they were. The social worker, the carer and the child are where they started. The hard half is already done.

Ready to move
Rarest

People who would be better served, and the records to prove what happened. The strongest position and the rarest one. Your question is how fast to scale, not whether you are allowed.

Standing start

Not much AI happening, not much exposure. Comfortable, and easy to stay in too long. The moment people start using AI, the record needs to already be there.

Reach without a record
Most common

People across your service need answers, and there is no record of what AI is already telling them. They reach for it anyway, in browser tabs, unrecorded. The most common position, and the most expensive one to ignore.

The kind of thing it asks

Answer these two in your head and you will know whether the other thirteen are worth five minutes.

From the defensibility side

Where does the processing physically happen when your people use AI, and under whose law?

We have never established that
Somewhere overseas, we think
Named in the terms, mostly outside the UK
On infrastructure we or a named UK supplier control, under UK law
From the opportunity side

How long does it take someone to find the answer to a policy or case question that is already somewhere in your own documents?

Seconds, our search is genuinely good
A few minutes
Long enough that people ask a colleague instead
Long enough that people guess

No trick questions and no points for optimism. The uncomfortable answers are the useful ones.

What this scorecard does not do

Every vendor assessment has limits. Most bury them. Here are ours, before you start rather than after.

It does not audit you. Fifteen self-reported answers reflect what you believe about your organisation. That is useful, and it is not evidence.
It does not assess your suppliers. A tool that produces a strong record still needs its own review, and its terms still need reading.
It is not a DPIA and it is not legal advice.
It cannot see use you do not know about. Nothing self-reported can. If the last question gives you pause, that pause is worth more than the score.

What happens to your answers

Scored in your browser Nothing sent until you ask One click unsubscribes

We sell control over information, so here is how this page handles yours, plainly.

Your answers stay in your browser while you take the scorecard. The score is worked out on your device. If you close the tab before asking for the read-out, nothing has reached us at all.

When you ask for the full read-out, we receive your answers along with the name, work email and organisation you give us. Your read-out downloads straight away. We also email that address a link to confirm it is yours; only if you click it do we email your read-out and, if you ticked the box, add you to occasional updates. If you never confirm, we keep nothing. One click unsubscribes. We do not sell or pass your details to anyone, and we do not enrich them from third party data.

If we ever publish anything from the results, it will be aggregate only, with the sample size stated, and never attributed to an organisation. Read the privacy notice.

Full details, including your rights, are in the privacy notice.

Who this is for

Anyone accountable for how information is handled in a regulated organisation. It was written first for social care, where the material is about children and vulnerable adults and the recording burden is heaviest, and it applies without translation to legal, healthcare, education and professional services.

It is aimed at the person who would have to answer if somebody asked. A director or a registered manager. A DPO or information governance lead. A COO or an operations director. A partner or a practice manager. If AI use in your organisation would land on your desk when it went wrong, this is written for you.

Not for

Anyone comfortable with cloud AI inside their existing boundary who needs no evidence of how it was used. That is a legitimate position and it does not need a scorecard.

Where Chrysalis fits

We built this because we kept having the same conversation.

Somebody describes what AI could do for the people they are responsible for, and then somebody else in the room asks whether they could show what it did. The pause that follows is the whole problem. Chrysalis is a dedicated AI appliance, on your premises or in UK-owned, UK-jurisdiction infrastructure. Mothy, the AI Secretary that runs on it, works across your own documents: finding the answer, drafting the routine document, and keeping the record of both.

On control

Your information stays on hardware dedicated to your organisation alone, in the UK, under UK law. Exactly one named UK company processes it: us, under a contract. No AI company ever sees it, and nothing is trained on it. Because nothing leaves, sensitive documents can be used whole: no blacking out names before anyone dares type.

On evidence

Every interaction is written to a log that cannot be quietly edited. “What was it told, what did it answer, who signed it off” becomes a record you hold, not a claim you make.

The boundary, stated plainly

Chrysalis produces the evidence; your auditor checks it. It governs what happens inside Mothy. It does not police other tools, it removes the reason to reach for them.

Private AI with verifiable governance.

Talk to us

Thirty minutes, no deck. If your read-out was uncomfortable in the places you expected, a conversation is usually more useful than another framework.

Questions people ask

How long does it really take?+

About five minutes. Fifteen questions, one screen each, four options each. There are two more at the end that do not affect your score and take a few seconds.

Do I have to give you my email to see my score?+

No. Your scores, your position and the five detail bars all appear before any form. The email is only for the full read-out: the actions, the eight questions, and the score for where your information goes.

Is this going to tell me to buy something?+

The read-out ends with a page about Chrysalis, because we made it and we are not pretending otherwise. Everything before that is written to be useful whether or not you ever speak to us. Two of the four positions have next steps that involve no supplier at all.

We already have Copilot inside Microsoft 365. Is this relevant?+

Yes. The questions are about how AI processes your information and what record survives, and that applies inside Microsoft 365 just as much as anywhere else.

Can I take it on behalf of a team rather than a whole organisation?+

Yes. Answer for whatever unit you can honestly answer for, and say so when we speak. A directorate and a whole council will produce very different scores, and both are worth having.

Can I share the result with my board?+

That is what it is for. The read-out prints cleanly, and you can save it as a PDF from your browser.

What if my score is bad?+

Most are, on the defensibility side. It is a new category and almost nobody has this straight yet. The scorecard is more useful as a map of what to fix in what order than as a grade.

Start the scorecard