Services · How it worksFILE NO. 015 / EU · ISO · NIST · OWASP

One audit.
Then continuous
assurance.

Independent adversarial testing that gives your security team the evidence and your board the confidence. 800+ tests span 25 categories across the OWASP LLM and Agentic Top 10, each run enough times to tell you how often it actually fails.

Start an auditFixed price · no subscription · free scoping call first, no commitment.See a sample report
ScopeBlack-box · endpoint only
Coverage800+ tests · 25 categories
RigourEvery test run multiple times
FrameworksEU · ISO · NIST · OWASP
01 / The auditThe entry point

There is one audit. It runs everything.

No lite tier, no scoped-down sweep. Every engagement runs the full 25-category catalog at full multi-trial and adaptive depth: standalone, fixed price, no lock-in, no subscription.

◗ Founding cohort · 5 slots · through Dec 31, 2026AI Security Audit

AI Security Audit

Full 25-category coverage at full depth, every time. This is the audit, not a starter version of a bigger one.
12,000 USD/ endpoint · standard rate
6,500 USD/ endpoint
Founding rate for the first five audits, in exchange for a reference.
Report in 10 business days · one endpoint
  • Full 25-category catalog at full depth, capability-aware, N/A never padded
  • Verbatim evidence per finding: frequency, confidence interval, trial count, prioritized remediation
  • Three compliance dossiers: Article 15, ISO 42001, NIST AI RMF
  • Board-ready executive summary your CISO can forward to the CEO
  • One re-test within 30 days, same version, failed tests only, included
Start an audit
02 / The destination · Flagship

Continuous Assurance

A point-in-time audit describes a system that has already changed: a new prompt, a new model version, a new tool. It decays in weeks. We keep you tested every time you ship.

  • Four quarterly full audits: the same full 25-category audit, on a quarterly cadence
  • Regression re-testing on material change: new model version, new prompt, new tool
  • Dossiers and board summary kept current between audits
  • Multi-endpoint pricing available
Founding cohort · year one
30,000 USD/ endpoint / year · standard rate
18,000 USD/ endpoint / year

Founding cohort rate, locked for year one, converting to standard at renewal.

03 / GovernanceIncluded, not sold separately

Governance is included. Not a tier.

Every audit includes the three compliance dossiers (EU AI Act Article 15 · ISO/IEC 42001 · NIST AI RMF) and the board-ready executive summary. There is no separate governance tier to buy.

Add-ons, not a tier
  • Additional endpoint in the same engagement 7,000 USD 5,000 USD
  • Extra re-test beyond the included one 2,500 USD 2,000 USD
  • Rush turnaround +30%
04 / ScopingWhat counts as one endpoint

How we define an endpoint.

One endpoint = one deployed AI application reachable at a distinct URL / auth boundary, running one system prompt and one model configuration.

Same endpoint

Same app at staging and production = one endpoint (tested at one).

Separate endpoints

Different system prompt or different model = separate endpoints.

Language variants

Language variants of one system prompt = one endpoint, unless guardrails differ.

05 / FAQDirect answers

The plain version.

Plain answers, written for the people who'll actually read the report: security leads, compliance officers, and the engineers on the receiving end of the remediation.

Q · 01
What exactly do we get?
A Technical Assessment Report, a board-ready executive summary, and a full evidence package: every finding carries its observed frequency, confidence interval, and trial count, plus representative evidence. Add the three compliance dossiers, prioritized per-finding remediation, and one bounded re-test within 30 days. Delivered as a PDF. HTML, JSON, and Markdown are available on request.
Q · 02
Is there a lighter, scoped-down option?
No. There is one audit, and it always runs the full 25-category catalog at full multi-trial and adaptive depth. A partial sweep can't tell you what it didn't test, so we don't sell one.
Q · 03
How is this different from a one-off pentest?
LLM endpoints are non-deterministic: the same input produces different outputs, even at temperature 0. A single-run test proves very little. We run every attack multiple times and report how often it actually succeeds, with a confidence interval attached to the clean results too.
Q · 04
What happens after the first audit?
Most teams move to Continuous Assurance. A point-in-time audit describes a system that has already changed: a new prompt, a new model version, a new tool. It decays in weeks. Continuous Assurance keeps you tested every time you ship.
Q · 05
What if we run more than one endpoint?
Each endpoint is scoped and priced on its own. An additional endpoint in the same engagement is 5,000 USD during the founding window, 7,000 USD standard. If you're not sure how many endpoints you have, the scoping call is free and we'll work it out together.
Q · 06
How does this map to compliance frameworks?
Every audit includes assessment evidence mapped to EU AI Act Article 15, ISO/IEC 42001, and NIST AI RMF by default. There is no separate governance tier to buy. We are not a certification body; the dossiers are evidence for your filing, not a certificate.
Q · 07
Can I see a sample report?
Yes, see a sample report. The OWASP LLM tests are also available on GitHub (Community Edition).
Q · 08
Do you sign NDAs and support enterprise procurement?
Yes. NDA or MSA is standard. We handle security questionnaires, vendor onboarding, and provide evidence for procurement teams.

⚖ Legal note: Technical Assessment Reports document testing against industry frameworks. They are not legal certification or regulatory approval. Consult qualified legal counsel for your compliance obligations.

An audit before the next board review

An audit before the next
board review.

Tell us the endpoint and your use case. You get a scoped statement of work (fixed price, fixed timeline) in your inbox the same day.

Start an auditSee a sample reportFixed price · no subscription · free scoping call first, no commitment.