One audit.
Then continuous
assurance.
Independent adversarial testing that gives your security team the evidence and your board the confidence. 800+ tests span 25 categories across the OWASP LLM and Agentic Top 10, each run enough times to tell you how often it actually fails.
There is one audit. It runs everything.
No lite tier, no scoped-down sweep. Every engagement runs the full 25-category catalog at full multi-trial and adaptive depth: standalone, fixed price, no lock-in, no subscription.
AI Security Audit
- Full 25-category catalog at full depth, capability-aware, N/A never padded
- Verbatim evidence per finding: frequency, confidence interval, trial count, prioritized remediation
- Three compliance dossiers: Article 15, ISO 42001, NIST AI RMF
- Board-ready executive summary your CISO can forward to the CEO
- One re-test within 30 days, same version, failed tests only, included
Continuous Assurance
A point-in-time audit describes a system that has already changed: a new prompt, a new model version, a new tool. It decays in weeks. We keep you tested every time you ship.
- Four quarterly full audits: the same full 25-category audit, on a quarterly cadence
- Regression re-testing on material change: new model version, new prompt, new tool
- Dossiers and board summary kept current between audits
- Multi-endpoint pricing available
Founding cohort rate, locked for year one, converting to standard at renewal.
Governance is included. Not a tier.
Every audit includes the three compliance dossiers (EU AI Act Article 15 · ISO/IEC 42001 · NIST AI RMF) and the board-ready executive summary. There is no separate governance tier to buy.
- Additional endpoint in the same engagement 7,000 USD 5,000 USD
- Extra re-test beyond the included one 2,500 USD 2,000 USD
- Rush turnaround +30%
How we define an endpoint.
One endpoint = one deployed AI application reachable at a distinct URL / auth boundary, running one system prompt and one model configuration.
Same app at staging and production = one endpoint (tested at one).
Different system prompt or different model = separate endpoints.
Language variants of one system prompt = one endpoint, unless guardrails differ.
The plain version.
Plain answers, written for the people who'll actually read the report: security leads, compliance officers, and the engineers on the receiving end of the remediation.
Q · 01What exactly do we get?
Q · 02Is there a lighter, scoped-down option?
Q · 03How is this different from a one-off pentest?
Q · 04What happens after the first audit?
Q · 05What if we run more than one endpoint?
Q · 06How does this map to compliance frameworks?
Q · 07Can I see a sample report?
Q · 08Do you sign NDAs and support enterprise procurement?
⚖ Legal note: Technical Assessment Reports document testing against industry frameworks. They are not legal certification or regulatory approval. Consult qualified legal counsel for your compliance obligations.
An audit before the next
board review.
Tell us the endpoint and your use case. You get a scoped statement of work (fixed price, fixed timeline) in your inbox the same day.