LLM and vendor risk
Who owns each vendor, where data is processed, whether your inputs train their models, and what their security posture actually is.
A fixed-scope project that answers three questions: which AI tools your company actually uses, what data flows into them, and which of those flows put you at risk. In two to four weeks you get a full inventory, risk-ranked findings, an acceptable use policy, and a 90-day remediation plan.
Every company has two AI footprints: the one IT approved, and the bigger one employees built themselves.
Discovery pairs log analysis with staff interviews: personal ChatGPT accounts doing client work, free tools with training rights over your data, AI features switched on inside software you already own. For a preview, read our guide to shadow AI and what to do about it.
Who owns each vendor, where data is processed, whether your inputs train their models, and what their security posture actually is.
We map what leaves your boundary and where it lands: prompts, uploads, connected drives, and integrations, ranked by sensitivity.
If chatbots or copilots touch your data, we test how they handle hostile input designed to hijack them.
We review or write your policy: approved tools, prohibited data, and consequences, in language staff will read.
Your governance mapped against NIST AI RMF, the standard insurers, auditors, and enterprise customers increasingly ask about.
Who can connect AI tools to company data, and with what permissions. Overshared drives turn one careless prompt into a company-wide exposure.
Every tool, account, and integration in use, with a map of what sensitive data goes where. This becomes your ongoing register.
Each finding scored by likelihood and impact, in plain language for executives with technical detail attached. No padding, no scare graphics.
An acceptable use policy ready to adopt, plus a remediation plan with owners and sequence, presented in a working session.
Attackers use the same models your employees experiment with to write flawless phishing, clone executive voices, and stage deepfake video calls that approve wire transfers.
We test how your payment approvals, identity verification, and executive communications hold up against AI-assisted fraud, and we run deepfake tabletop exercises through our cybersecurity consulting practice.
Two to four weeks for most companies with 25 to 1,000 employees. Week one is discovery, weeks two and three are analysis and testing, and you get the written report and remediation plan in a working session, not an inbox drop.
That is the exact profile that needs it. The risk is rarely the sanctioned tool; it is the personal accounts, free tools with training rights over your data, and AI features quietly switched on inside software you already own.
Five deliverables: an inventory of every AI tool in use, a data exposure map, a risk-ranked findings report, an acceptable use policy ready to adopt, and a 90-day remediation plan with owners.
No. Bans push AI use onto personal devices where you have no visibility. We pair controls with a sanctioned path: an approved tool, clear rules for what data can go into it, and training so people use it well.
Start with the free ten-minute readiness assessment. It scores your AI use and data controls and shows you where a full assessment would dig in first.
Take the free AI Assessment