AI Security Review · New
Everyone is adopting AI. Almost nobody can prove theirs is safe. We answer two questions from real configuration rather than a questionnaire: is your Microsoft 365 tenant safe to turn Copilot on — access hygiene, oversharing containment, auditability — and are the AI services already running in your cloud actually governed. You get a scored report, evidence on every line, and a prioritised list of what to fix first.
SCANNED measured directly from configuration · ATTESTED reviewed and evidenced by a senior engineer
10 areas · 6 measured, 4 attested · no Copilot licence required
The outcome: a defensible answer to "can we safely switch Copilot on?", with the specific settings to change first — assessed from your current tenant, whether or not Copilot is licensed.
7 control areas on AWS · Bedrock & SageMaker
Scope, honestly. This review covers Microsoft 365 and AWS. AWS is graded requirement-by-requirement across Bedrock and SageMaker against the AWS AI Security Framework; Copilot readiness is graded from your Microsoft 365 tenant. Azure and Google Cloud are not in scope — our coverage there is one control apiece, and charging the same price for it would imply a parity that does not exist. If your AI estate is Azure- or GCP-heavy, tell us and we will scope it as engineering work instead.
Every control scored and graded to a published framework, with a verdict and evidence on each line. This is a representative preview, not real client data.
You grant read-only credentials. No agents installed; credentials never stored in our portal.
Configuration-level evidence collected across M365 and your AI estates.
A senior engineer reviews what scanners can't see, such as labels, DLP and governance, with evidence notes.
Scored, prioritised and senior-reviewed. We walk it through with you, then it is yours to keep.
Scope, honestly. This is an AI security review: how your AI services and Copilot rollout are actually configured, evidenced control by control. It is not an AI governance certification — if you need ISO 42001 or the NIST AI RMF attested as policy and process, that is a different discipline and we will point you to it rather than pretend a scan covers it.
or +$2,500 attached to a Security Controls Assessment. The credentialed scan is already running, so you pay only for the AI-specific analysis.
Read-only access · no agents · client credentials never touch our portal · project-based, no lock-in