Not a scan, not a maturity score with no consequences. A structured read on where you stand, what it exposes you to, and what to do about it in what order, with what each move costs.
Where AI is already in use and by whom. What data it touches. What your customer and vendor contracts already commit you to. Which use cases are worth doing, which are not, and what has to be true before you start.
Exposure in plain terms. Controls coverage measured against real threat patterns rather than a generic checklist. Incident readiness. Third-party and vendor risk. What your insurer and your largest customers will ask next.
Companies often run one, act on it, and run the other a quarter later. They are deliberately separable.
Documents, contracts, policies, and a structured questionnaire. We read what you already have before asking you for anything new.
Short sessions with the people who actually know: IT, finance, operations, whoever is closest to the work. Usually four to six conversations.
A written assessment, a ranked set of decisions with likely costs, and a working session to walk your leadership team through it.
No credentials, no agents, no scanners. Nothing we do can interrupt anything you run. That is a deliberate constraint, and it is also why we can start next week rather than after a security review.
Fees are fixed and quoted before we begin, scaled to company size and complexity. Ask and we will tell you the number in the first conversation.
Neither. A pen test finds technical holes and an audit checks you against a standard. This asks a different question: given what you face and what you can afford, what should you do next. If you need a pen test we will tell you and help you scope it.
Often the opposite. Smaller companies carry the same customer and contractual obligations with far less specialist attention. The assessment is scaled to the company; the questions do not change.
No. We have nothing to sell you. If work is needed we help you scope it and evaluate whoever does it.