AI Security and Governance Services
Three fixed-scope engagements with published prices, and four practice areas behind them: AI governance, AI security assessment, data privacy, and cybersecurity assessment.
AI Risk & Security Review
Every AI tool you use — mapped, scored, and ranked by what an incident would actually cost you.
- Inventory of paid, shadow, and embedded AI
- Data-flow map — what goes in, where it lives, whether it trains
- Scored risk register (the artifact a board, insurer, or courtroom recognizes)
- Action plan written for whoever has to execute it
Pro finds what you have. Compliance Readiness proves what you owe. Same price, different job.
AI Agent Security Assessment
Your agents can take actions. This shows which actions, through which permissions, with what blast radius.
- Agent and MCP-server inventory, including shadow deployments
- Action-path map per agent: tool → permission → data → blast radius
- Prompt-injection and data-exfiltration exposure
- Guardrail architecture your developers can implement in days
A red team tests one application. This maps the estate.
AI Compliance Readiness
Which rules apply to you, where you stand, and what you show the customer, the insurer, or the auditor.
- AI system inventory with regulatory classification (ISO 42001 / NIST AI RMF / EU AI Act)
- Gap assessment ranked by what hits first — procurement questionnaires and insurer renewals
- Risk register mapped to those obligations
- Questionnaire-ready evidence pack
Readiness proves what you owe. The Risk & Security Review Pro finds what you have. Same $8,500, different job.
Fixed scope. Defined deliverables. Defined price. Every engagement starts with a 15-minute fit call. If your situation does not fit a fixed scope, you will hear that on the call.
Most work fits the scopes above. When yours doesn't — more systems, more agents, remediation, a second framework, a retained advisor — the fit call ends one of two ways: a fixed price with a defined scope in writing, or an honest "this isn't mine to do" and a pointer to someone better suited. What it never ends with is an open-ended hourly arrangement. Hourly work exists only as scoped advisory after a fit call.
| ENGAGEMENT | PRICE | HARD LIMITS | DURATION | REVISIONS |
|---|---|---|---|---|
| Risk & Security Review | $3,500 / $5,500 / $8,500 | Core ≤10/15 · Plus 11–25/30 · Pro 26–50/50 · 3+ agents → Agent Assessment | 5 / 7 / 10 days | 2 |
| Agent Security Assessment | $5,000/agent · from $5,000 | 1 agent = full engagement · 11+ at $3,500 · shadow at 50% · re-map $2,000 ≤6 mo | 1–2 wks / 3–4 wks | 2 |
| Compliance Gap & Readiness | $8,500 | ≤25 systems · 3 frameworks | 2–3 weeks | 2 |
| Certification-Ready | $24,000 (all-in yr-1 $46–73K) | Tier 1 first · ≤10 policies · 1 platform · 1 dry-run | 6–8 weeks | 2 |
Advisory and ongoing work: hourly, scoped after a fit call.