AI Security Assessment
What does an AI security assessment include?
An AI security assessment inventories every AI tool your company uses — paid, shadow, and embedded — maps what data flows into each one, scores the risks, and ranks them by what an incident would actually cost you. It ends with an action plan written for whoever has to execute it.
If you run AI agents, the assessment extends to what those agents can do: which actions, through which permissions, with what blast radius. A red team tests one application. This maps the estate.
Who this is for
Companies using or shipping AI without a security team — from teams on ChatGPT and embedded copilots up to companies running production agents and MCP servers.
What the engagement delivers
- Inventory of paid, shadow, and embedded AI
- Data-flow map — what goes in, where it lives, whether it trains
- Scored risk register (the artifact a board, insurer, or courtroom recognizes)
- For agents: action-path maps, prompt-injection and data-exfiltration exposure, and guardrail architecture your developers can implement in days
How the process works
- A 15-minute fit call sizes the engagement — seats, touchpoints, and whether agents are in scope.
- Inventory from your admin exports, not a guess: every tool, agent, and MCP server, including shadow deployments.
- Mapping and scoring: data flows, permissions, and exposures, ranked by cost of incident.
- Readout: the risk register, the action plan, and a working session with whoever executes it.
AI Risk & Security Review — $3,500 / $5,500 / $8,500 by company size, 5–10 days. AI Agent Security Assessment — from $5,000 per agent or MCP server. Full scope and limits on the services page.