Secure

AI Security & Governance

Find out where AI already touches your data, what could go wrong, and which controls close the gaps. We inventory the AI tools and integrations in use, review data flows and vendor terms, threat-model agents for prompt injection and tool misuse, and design identity and authorization for agent actions. You get a prioritized remediation backlog and policy templates. Available standalone or attached to any build. We do not issue certifications, perform penetration tests, or give legal advice; where needed, we partner with specialist firms.

Scope

What you get

  • Inventory of AI tools, models, and integrations in use
  • Architecture and data-flow review
  • Threat model for agents: prompt injection and tool misuse
  • Model and vendor risk review, including retention and training-use terms
  • Identity and authorization design for agents and service accounts
  • Control roadmap and AI acceptable-use policy templates

Fixed scope

Packages

PackageDurationDeliverables
AI Security Review1–3 weeksArchitecture and data-flow review · AI threat model · Control gaps · Prioritized remediation backlog

Security by default

Built into every engagement

All 12 baseline controls
  1. 01Data classification and data-flow mapping first
  2. 02Model and vendor terms reviewed for retention
  3. 03Least-privilege access for tools and agents
  4. 04Identity-aware access for staff, customers, admins
  5. 05Secrets managed — never in code or prompts
  6. 06Separate dev, test, and production

Next step

Book an AI Systems Readiness Call

Tell us about the workflow. We will tell you whether AI Security Review is the right first step, and what it would take.