FAQ
Questions Buyers Ask About AI Security Consulting
- What does an engagement cost?
- Fixed-scope engagements run from $3,500 (AI Risk & Security Review, Core tier) to $24,000 (Certification-Ready compliance work). Every price is published on the services page before you ever get on a call. The 15-minute fit call is free.
- How long does an engagement take?
- The shortest engagement is 5 days (Risk & Security Review, Core). The longest fixed scope is 6–8 weeks (Certification-Ready). Most work lands between one and four weeks; every scope includes two revisions.
- Do you work remotely or on-site?
- Engagements are delivered remotely, for clients in the US, EU, Canada, and Australia. The work runs on your admin exports, working sessions, and readout calls — not site visits.
- What industries do you serve?
- Current work includes AI agent platforms in battery storage, manufacturing, and healthcare. The primary buyer is any company shipping AI without a security team; the method doesn't depend on the vertical.
- What makes AI security different from traditional cybersecurity?
- Traditional cybersecurity protects systems that answer questions. AI agents take actions — through tools, permissions, and data your company is accountable for — so the exposure includes prompt injection, data exfiltration through model inputs, and agents nobody inventoried. A firewall review doesn't see any of that.
- Do I need this if we already have SOC 2?
- SOC 2 attests your general controls; it does not inventory your AI tools, map what data flows into them, or assess what your agents can do. The AI-specific artifacts — risk register, data-flow map, agent action-paths — are a separate layer, and they're what customers and insurers now ask about.
- What is Defensible Agentic AI?
- It's the name of the practice: agentic systems you can defend to your board, your employees, and a courtroom if necessary. The output is controls and audit records wired into the systems, so the proof exists when the questionnaire, the auditor, or the discovery request arrives.
- Do you do hourly or retained work?
- Hourly work exists only as scoped advisory after a fit call. No engagement ends in an open-ended hourly arrangement — you get a fixed price with a defined scope in writing, or a pointer to someone better suited.
- Will an assessment guarantee we're secure or compliant?
- No. Findings are time-boxed and sampling-based — no assessment guarantees the absence of vulnerabilities, and readiness work guarantees no regulatory outcome; the accredited certification body decides that. What you get is a defensible, documented position.
- Do you write our policies?
- Policy artifacts are drafted in the Compliance Readiness engagement — up to 10 policy documents on the Certification-Ready path. Counsel review stays with your lawyers.
- What's the first step?
- A 15-minute fit call. If the work fits a fixed scope, you'll get the price and timeline on the call. If it doesn't — or it isn't mine to do — you'll hear that too, with a pointer to who's better suited.