$2,750 · first engagement
AI security review: what your AI can reach, what it can change, and what it can do with nobody watching.
$2,750 for the first engagement. It ends in a written capability map and a live walkthrough where you watch your own AI act, yours to keep whether or not you ever work with us again.
What can your AI do with nobody watching?
Building with AI got easy. Knowing what you built can do got hard. A system assembled in an afternoon can read a database, call an API, send an email, and move money, and the person who assembled it usually cannot list those permissions on request. Most teams answer the first question below and stall on the third.
- Reach. Which data, services, and accounts it can see.
- Change. What it is able to write, alter, send, or delete.
- Unattended. Which of those it can do with no person approving.
What you get
The review has two parts: a written capability map of everything your AI can reach, and a live walkthrough where you watch your own AI act. Here is exactly what is in the map, and what happens in the room.
- Every finding in plain language, with what it means for your business rather than a scanner dump.
- A ranked list of what to fix first, because a flat list of forty items is the same as no list.
- Anything that could not be checked, marked not measured. Never a pass, never a zero. A check that did not run is reported as a check that did not run.
- A live walkthrough. We point your AI at what the map flags and you watch it act, in the room, instead of taking a document's word for it.
- Yours to keep and act on, with your own team or anyone else's.
How the review runs
- Scope it. A short call establishes what to point the review at. Read access only.
- Five checks run automatically: static analysis of your own code, a dependency vulnerability scan of the outside packages it depends on, injection scanning of the instruction files that steer your AI, secret scanning for credentials sitting where they should not be, and a visibility audit of what your system exposes publicly.
- A person reads the output. Roughly eight hours of it. Scanners produce noise, and deciding which findings actually matter for your system is the part a machine cannot do yet.
- The capability map gets written. Findings, ranking, and the not-measured rows.
- We walk you through it, live. We point your AI at what the map flags and you watch it act, in the room, so you can decide on the spot instead of taking a document's word for it.
Five checks automatic, about eight hours of human reading, one live walkthrough.
Why take our word for it
The team that builds your AI cannot be the one who says it is safe. That is the whole reason this review exists as its own engagement instead of a line item inside a build. We will not pretend to a track record we do not have either. No client of ours has paid for this yet. So here is what we can actually show you.
- These checks run on us first. The same automated gates clear every code change, every release, and every outbound message at this company, and have for months. The review is that layer pointed at you instead of at us.
- The not-measured rule is the tell. A report that grades everything green is a report where something did not run. Ours says so.
- We carry $2M of professional liability on the opinion, through CFC at Lloyd's, active to May 2027, written to cover artificial intelligence software specifically. If we tell you a system is fine and it is not, that is our exposure. Most people who will look at your AI carry no such thing.
What it costs
$2,750 for the first engagement. The price is published rather than quoted, because a review priced by negotiation is a review whose scope moves.
- Included: the scoping call, the five automated checks, the human read, the written capability map, and the live walkthrough.
- Not included: fixing what we find. That is a separate engagement, scoped and quoted per client after you have read the report rather than before, because no two systems are broken the same way. Keeping the gates running once it is fixed is a separate subscription.
The report is built to be worth the price on its own. If you read it and take it to your own developer, that is a fine outcome and we will say so on the call.
Who this is for
Any company running something built with AI that touches real money, other people's data, the public, or an action nobody can undo. Company size is not the test. What the system can reach is the test. We do this for five-person companies and for large enterprises, and the review itself is the same work either way. What changes afterwards is how much of the fixing can run automatically and how much needs hands on it.
AI security review, answered
What is an AI security and governance review?
An AI security and governance review is a fixed-scope examination of what an AI system can already do without a person approving each action: what data and services it can reach, what it is able to change, and which of those actions it can take unattended. It produces a written capability map listing what was found, what could not be checked, and what to fix first, plus a live walkthrough where you watch your own AI act. It is a read of the current state rather than a change to it.
What does the review cover?
Five checks run automatically over the system you point us at: static analysis of the code you wrote, a dependency vulnerability scan of the outside packages it depends on, injection scanning of the instruction files that steer your AI, secret scanning for credentials sitting where they should not be, and a visibility audit of what your system exposes publicly. A person reads the combined output and writes the capability map. Then comes a live walkthrough: we point your AI at what the map flags and you watch it act, in the room.
What do I get at the end?
The review has two parts: a written capability map you can act on, and a live walkthrough where you watch your own AI act. The map lists each finding in plain language, ranks what to fix first, and marks anything that could not be checked as not measured rather than passing it. You keep both whether or not you ever work with us again.
How do I find out what my AI agent can access on its own?
Start with the three questions: what can it reach, what can it change, and what can it do with nobody watching. Most teams can answer the first and stall on the third, because permissions pile up quietly: a key here, a connected account there, a tool switched on during a build and never switched off. The review answers all three in writing, and the live walkthrough answers the third one in front of you.
What does an AI security review cost?
$2,750 for the first engagement. The price is published rather than quoted. Fixing what the review finds is a separate engagement, quoted after you have seen the report rather than before. Keeping the gates running once you have fixed what we found is a separate subscription.
Do you only work with small companies?
No. The review is the same work for a five-person company and a large enterprise. What changes is how much of the fixing runs automatically afterwards and how much needs hands on it. Small companies are where the automated path gets proven first.
Will the review make my AI safe?
No, and any review that says otherwise is overselling. The review shows you what is unsafe and what to fix first. Fixing it is separate work. We are direct about this because the difference between showing and fixing is the difference between a report you can trust and a report written to sell you something.
Find out what yours can do
A free 30-minute call establishes whether the review is worth running on your system. If it is not, we will tell you that on the call.