Skip to content

AI Audit

A Read-Only AI Audit

We review your systems before anyone proposes changing them. Written findings within 48 hours of access being granted, view access only, no fee, and conducted under mutual NDA. The roadmap is yours whether or not you engage us further.

Why There Is No Fee

Accurate Scoping Requires Reading The Systems

A retainer quoted before anyone has reviewed your systems is an estimate without evidence. This diagnostic would be the first step of any engagement, so we carry it out before there is a contract and let the findings determine whether further work is warranted.

Where the findings show limited exposure, we will say so and recommend no further engagement.

The written roadmap is yours either way, with no obligation attached and nothing withheld.

The Checks

Six Passes, In This Order

The inventory comes first because every later check depends on knowing what exists. An audit limited to the systems identified at the outset can miss the one that holds the most privileged credentials.

01

What is actually running

A census of every AI system in use and who owns each one - the ones on the roadmap, and the ones that arrived through a SaaS feature switched on by default, a copilot nobody registered, or an internal script that was never registered. The first honest inventory routinely finds production systems the people accountable for AI had not been told about.

02

Blast radius

For each system, what it is technically able to reach: which tools and APIs it can call, what those credentials are scoped to, which of those actions are irreversible, and whether anything stands between the model deciding to act and the action happening. This check most often produces the highest-priority findings.

03

Untrusted input paths

Where text an outsider controls enters a context window - tickets, uploads, fetched pages, retrieval indexes, database rows - and what an instruction hidden in that text could reach once it is there. We trace the path from untrusted input to privileged action rather than testing whether a jailbreak string gets past a system prompt.

04

Data exposure and retention

What goes into context and what leaves: which personal or confidential data reaches a provider, under which contract, whether training use is switched off, what is logged, where those logs live, and how long any of it is kept. Also who inside the organisation can read a conversation after the fact.

05

Whether accuracy is measured at all

Whether an eval set exists, whether it runs on changes, whether anyone knows the current error rate, and whether grounding is checked separately from fluency. In most first audits the answer is that nothing is measured and the team's confidence rests on a demo, which is a finding worth writing down plainly.

06

Whether actions are recorded

Take one real interaction from last week and try to reconstruct it: the input, the prompt version, the retrieved documents, the tool calls, the authorising identity, the outcome. If that cannot be assembled, the system cannot be audited, debugged after an incident, or defended to a customer - and we will tell you which of those three you should care about first.

What We Need

View Access. Never Passwords.

All of it is delegated through your own identity and permission systems, granted to named accounts, visible to you, and revocable by you at any time without rotating a single secret. The audit reads; it changes nothing.

Code

Read access to the repositories where prompts, tool definitions and agent code live. Granted to named accounts, revocable by you, no credentials handed over.

Provider consoles

Viewer access to your model providers, so retention settings, training opt-outs and actual spend can be read rather than assumed.

Observability

Viewer access to whatever logging or tracing exists today. Often the shortest check in the audit, because the answer is that none exists.

Cloud IAM

Read-only on the roles and service accounts your agents run as. This is where blast radius is actually established.

The product itself

No access needed - we use the AI features the way a customer does, from outside.

What You Get

A Document, Not a Deck

Written findings you can read without us in the room, and hand to an engineer who then knows what to change. If it only makes sense as an argument for a retainer, it was a pitch wearing a diagnostic costume.

  • Every AI system we found, what it can reach, and who owns it
  • Findings ordered by the blast radius we could actually demonstrate, not by a severity label
  • Fixes that can be made this week - usually permission scoping and a gate on the irreversible actions
  • A roadmap for what to build after that, with the reasoning attached so you can argue with it

Turnaround

48 Hours From Access · Not From Enquiry

Request It

Request an Audit

No call needed to start one. Tell us what you have in production and we reply with the exact read-only access to grant - the clock starts when it lands, not when you fill this in.

Turnaround

48 Hours From Access

No Fee · Under Mutual NDA · View Access Only

By submitting this form, you agree to be contacted regarding your request. Submitted information may be processed for operational and communication purposes in accordance with our Privacy Policy.

Audit Questions

What does the initial AI audit include?

A read-only review of six things: every AI system in use and who owns it, what each system can technically reach, where untrusted input can reach a privileged action, what data leaves and under which terms, whether accuracy is measured at all, and whether a past interaction can be reconstructed. It ends in a written roadmap ordered by risk.

Is there a fee for the initial audit?

No. It is provided at no cost, under mutual NDA, and you keep the written roadmap whether or not you engage us further. Scoping this work accurately requires reviewing the systems first, so the diagnostic is work that would be needed at the start of any engagement.

What access do you need to run the audit?

Read-only access, and never passwords or production secrets - viewer-level on the repositories where prompts and agent code live, the model provider consoles, whatever tracing exists, and the IAM roles your agents run as. Nothing is edited, access goes to named accounts, and you can revoke it at any time without rotating a secret.

How long does the audit take?

Within 48 hours of access being granted. The analysis itself takes a day; the wait is usually the access grants, which have to come from whoever owns each system.

Send Us The Systems

Book 20 minutes or write to us. Access takes ten minutes to grant and the read comes back inside two days.

Book a Call