Services

Pick what fits your timeline and budget

From a focused security assessment to full ongoing protection—we scale to what you actually need.

Flexible engagement
  • One-time assessment or ongoing monitoring.
  • Testing only, or testing plus remediation help.
  • Start small, expand if needed.
Service tiers

Three ways to work with us

Quick start

Security assessment

2-4 week focused test of your AI system. You get a findings report with severity ratings and remediation guidance. Good for: pre-launch validation or answering a specific customer concern.

Most popular

Full engagement

8-16 week program covering assessment, control implementation, and documentation. You get tested, fixed, and a shareable report. Good for: enterprise sales readiness.

Ongoing

Continuous protection

Monthly retesting as you ship updates, plus on-call support for new features. Good for: fast-moving teams where the AI system changes frequently.

What's included

Every engagement includes

Prompt injection testing

Direct attacks, jailbreak attempts, and indirect injection through retrieval content.

Data leakage testing

Cross-tenant retrieval, context extraction, and PII disclosure attempts.

Output safety testing

Policy bypass attempts, harmful content generation, unsafe tool execution.

Detailed findings report

Each vulnerability documented with severity, reproduction steps, and fix guidance.

Executive summary

Non-technical overview suitable for sharing with customers and leadership.

Remediation consultation

Call time to walk through findings and answer implementation questions.

Add-ons

Optional extras for full engagements

  • Control implementation: We build the guardrails, not just report the gaps.
  • Policy drafting: AI governance docs ready for customer review.
  • Vendor risk review: Assessment of your LLM provider agreements.
  • Incident response planning: What to do when your AI misbehaves.

What you get

  • Technical findings report (for your team)
  • Executive summary (for customers)
  • Control mapping spreadsheet
  • Remediation priority list
  • Re-test after fixes (full engagement only)
FAQ

Common questions

Is this like a penetration test?

Similar philosophy, but specialized for AI systems. We test for AI-specific vulnerabilities like prompt injection, data leakage, and output safety—things traditional pentesters don't cover.

Do you need access to our source code?

Not required. We test through your product interface like a real attacker would. Code review is optional and helps us test more thoroughly.

Is this a SOC 2 audit?

No. We do security testing. The report can support your SOC 2 or help answer customer security questionnaires, but we don't issue SOC 2 attestations.

What if you find something critical?

We notify you immediately for critical findings—we don't wait for the final report. You can start fixing while we continue testing.

Can you help us fix what you find?

Yes. Full engagements include remediation support. For assessment-only, you can add consulting hours.

How is this priced?

Based on scope and complexity. Assessment starts around $8K. Full engagements typically $25-50K. Ongoing monitoring from $2K/month.

Not sure which tier?

Tell us about your AI system and timeline. We'll recommend the right scope and give you a quote.

Get a quote