AI Security and Governance Services

Three fixed-scope engagements with published prices, and four practice areas behind them: AI governance, AI security assessment, data privacy, and cybersecurity assessment.

AI Risk & Security Review

Every AI tool you use — mapped, scored, and ranked by what an incident would actually cost you.

  • Inventory of paid, shadow, and embedded AI
  • Data-flow map — what goes in, where it lives, whether it trains
  • Scored risk register (the artifact a board, insurer, or courtroom recognizes)
  • Action plan written for whoever has to execute it
Three tiers · up to 50 seats · 5 / 7 / 10 days · two revisions
$3,500Core
≤10 seats, ≤15 AI touchpoints, 5 days
$5,500Plus
11–25 seats, ≤30 touchpoints, 7 days
$8,500Pro
26–50 seats, ≤50 touchpoints, 10 days · board one-pager and MSP handoff memo

Pro finds what you have. Compliance Readiness proves what you owe. Same price, different job.

Seat count comes from the admin export, not a guess. Whichever cap is exceeded sets the tier. First 5 touchpoints over the cap are free; beyond that the work is re-scoped before it continues. Three or more production agents belong on the Agent Security Assessment, not Pro. Findings are time-boxed and sampling-based — no assessment guarantees the absence of vulnerabilities.
Book the fit call

AI Agent Security Assessment

Your agents can take actions. This shows which actions, through which permissions, with what blast radius.

  • Agent and MCP-server inventory, including shadow deployments
  • Action-path map per agent: tool → permission → data → blast radius
  • Prompt-injection and data-exfiltration exposure
  • Guardrail architecture your developers can implement in days
Per agent or MCP server · 1–2 weeks (one agent) / 3–4 weeks (two or more) · re-map $2,000/agent within 6 months · two revisions
From $5,000
$5,000 per agent or MCP server. One agent is a complete engagement. Agents 11+ are $3,500 each.

A red team tests one application. This maps the estate.

Not included: network penetration testing, source-code audit of the surrounding stack, continuous monitoring, or remediation. Retesting covers confirmed critical and high findings within 30 days of the report. Agents discovered during the assessment are invoiced at half rate — finding them is the point; you elect per discovery, in writing, before any charge.
Book the fit call

AI Compliance Readiness

Which rules apply to you, where you stand, and what you show the customer, the insurer, or the auditor.

  • AI system inventory with regulatory classification (ISO 42001 / NIST AI RMF / EU AI Act)
  • Gap assessment ranked by what hits first — procurement questionnaires and insurer renewals
  • Risk register mapped to those obligations
  • Questionnaire-ready evidence pack
Two paths · Gap & Readiness 2–3 weeks · Certification-Ready 6–8 weeks (readiness work first) · two revisions · certification-body fees pass through at cost
$8,500Gap & Readiness
$24,000Certification-Ready
Typical all-in first year, including the certification body and the compliance platform, runs $46–73K. Stated up front. Policies are drafted here; counsel review stays with your lawyers.

Readiness proves what you owe. The Risk & Security Review Pro finds what you have. Same $8,500, different job.

Tier 1 covers up to 25 AI systems across the three frameworks. Tier 2 requires Tier 1 (or an equivalent register), covers up to 10 policy documents, one platform deployment, and one internal-audit dry-run, with two working sessions a week. Readiness is not certification and guarantees no regulatory outcome — the accredited body decides that. Live obligations lead: questionnaires and insurer renewals. Article 50 transparency, NYC LL144, and Colorado's 2027 notice rules are covered in the evidence pack when they apply.
Book the fit call

Fixed scope. Defined deliverables. Defined price. Every engagement starts with a 15-minute fit call. If your situation does not fit a fixed scope, you will hear that on the call.

When your situation doesn't fit a fixed scope

Most work fits the scopes above. When yours doesn't — more systems, more agents, remediation, a second framework, a retained advisor — the fit call ends one of two ways: a fixed price with a defined scope in writing, or an honest "this isn't mine to do" and a pointer to someone better suited. What it never ends with is an open-ended hourly arrangement. Hourly work exists only as scoped advisory after a fit call.

ENGAGEMENTPRICEHARD LIMITSDURATIONREVISIONS
Risk & Security Review$3,500 / $5,500 / $8,500Core ≤10/15 · Plus 11–25/30 · Pro 26–50/50 · 3+ agents → Agent Assessment5 / 7 / 10 days2
Agent Security Assessment$5,000/agent · from $5,0001 agent = full engagement · 11+ at $3,500 · shadow at 50% · re-map $2,000 ≤6 mo1–2 wks / 3–4 wks2
Compliance Gap & Readiness$8,500≤25 systems · 3 frameworks2–3 weeks2
Certification-Ready$24,000 (all-in yr-1 $46–73K)Tier 1 first · ≤10 policies · 1 platform · 1 dry-run6–8 weeks2

Advisory and ongoing work: hourly, scoped after a fit call.