Questions
Straight Answers
Access, pricing, timelines, the limits of what we guarantee, and how an engagement ends - answered in full, in writing.
What does an AI assurance engagement actually cover?
Five lines of work: security and red-teaming, accuracy and evaluation, governance and policy, monitoring and incident response, and efficiency and cost control. In practice an engagement starts with the audit, and the audit tells you which of the five has the most upside on your systems - which is frequently not the one you came in asking about.
What is included in the initial AI audit?
A read-only look at what you are running now. We inventory every AI system in use, map what each one can reach, trace where untrusted input can get to a privileged action, check what data leaves and under which terms, and establish whether accuracy is measured or actions are recorded at all. It ends in a written roadmap, ordered by risk, and you keep that roadmap whether or not you work with us.
Is this about the model, or about the system around it?
The system around it, almost entirely. Model choice matters less than most teams expect, and permissions, retrieval quality, tool scoping, approval gates and instrumentation matter more. A capable model wired into an unscoped set of credentials is a worse position than a weaker one that cannot do damage.
Can you guarantee our AI will not hallucinate or be jailbroken?
No. Neither problem is solved at the current state of the art, and no responsible provider can guarantee otherwise. What we commit to is what we control: measuring the real error rate on your data, bounding what a compromised system can reach, and making sure that when something does go wrong it is visible and reconstructable rather than silent.
How do you price engagements?
Retainer by default, scoped after the audit rather than quoted blind, because scoping this work without reading the systems first would be guesswork. Model and infrastructure spend is always separate and paid by you directly to your providers - our fee is never a cut of it.
What access do you need, and do you take our credentials?
Read-only access, and we never take passwords or production secrets. In practice that is viewer-level access to the repositories, the provider consoles, the observability stack and the relevant configuration - granted to named accounts, visible to you, and revocable by you at any time without rotating anything. The audit itself changes nothing; where later work needs write access, it is scoped to a specific system and agreed in advance.
Do you certify us for the EU AI Act or ISO/IEC 42001?
No. We are not an accredited auditor or certification body, and keeping preparation separate from certification avoids a conflict of interest. What we do is get the inventory, the controls and the evidence into the shape those frameworks ask for, so that a real audit becomes a matter of producing records that already exist.
Do you build AI systems, or only assess them?
Both, in that order. The audit is read-only and diagnostic. The work that follows is implementation - eval harnesses, tracing, approval gates, permission scoping, routing - built inside your own stack and repositories. We are not a firm that delivers a findings deck and leaves the hard half to you.
Which providers, models and frameworks do you work with?
We are vendor-neutral and intend to stay that way, because the moment we resell something our advice on it stops being worth anything. The work is provider-agnostic by construction - it sits at the boundaries around the model rather than inside any one vendor's stack - and it is built on open standards like OpenTelemetry, into the tools you already run. Everything we build lives in your repositories and is yours.
Is our data or our prompts used to train anything?
Not by us. Anything we hold outside your environment is deleted within 30 days of the engagement ending, we do not train on it, and we do not carry examples from one client into another. Checking whether that is also true of your existing providers - whether training use is switched off, what is retained, and under which contract - is one of the six things the audit looks at, because it is frequently not what teams assume.
How long before we see results?
Honestly: it depends on what is broken. Permission scoping and approval gates on irreversible actions can be in place within days, because they are configuration rather than construction. Tracing takes a couple of weeks to be genuinely useful, since it needs real traffic flowing through it. An eval set worth trusting is the slowest - it needs enough real cases and known-correct answers to mean something, which is weeks, not days, and we would rather say that than promise a number by Friday.
What size of company is this for?
Organisations that already have AI in production, or are about to put it there, and have started to notice that nobody can say what it is allowed to do. If you are running one chat feature with no tool access and no customer data anywhere near it, the audit will be short and we will say so rather than sell you a retainer.
Do you work with companies outside India?
We are based in India and most of our work is with Indian organisations. This work is not geographically constrained the way physical audit work is, and we take engagements from outside India where the fit is right. Where a jurisdiction's obligations are the point of the engagement rather than context for it, we would scope that honestly with local counsel rather than claim expertise we do not have.
Will you guarantee our systems are secure?
No. No provider can give that guarantee responsibly. Red-teaming establishes that specific attacks work or do not work today, against the systems as they are configured today - it is evidence, not proof of a negative. What we commit to is the turnaround on findings, the blast radius stated honestly for each one, and telling you when something is not worth fixing rather than padding a report.
What happens if we want to stop?
You keep everything, because it was built in your accounts and your repositories from the start - the eval sets, the tracing, the policies, the approval gates, the inventory and the roadmap. There is no platform of ours to migrate off and no data of yours held anywhere we control. Removing us is revoking read access.
Still Something Unanswered?
Ask on a 20-minute call or in writing. Where a question falls outside what we do, we will say so.