RG Labs ← All services

AI Security Review · New

Your AI adoption, security-reviewed with evidence.

Everyone is adopting AI. Almost nobody can prove theirs is safe. We answer two questions from real configuration rather than a questionnaire: is your Microsoft 365 tenant safe to turn Copilot on — access hygiene, oversharing containment, auditability — and are the AI services already running in your cloud actually governed. You get a scored report, evidence on every line, and a prioritised list of what to fix first.

You don't need to own Copilot yet Readiness is measured from your existing Microsoft 365 configuration. The most useful time to run this is before you enable Copilot — when the findings are still cheap to fix.
Copilot inherits every permission It answers with whatever the signed-in user can already open, so years of oversharing surfaces in seconds.
GenAI ships ungoverned by default Bedrock and SageMaker run without guardrails, invocation logging or network isolation unless someone configures them.
The board is already asking "Is our AI safe?" deserves evidence: a grade against a published framework, not a shrug or a slide.

What we review

SCANNED  measured directly from configuration  ·  ATTESTED  reviewed and evidenced by a senior engineer

Microsoft 365 Copilot Readiness

10 areas · 6 measured, 4 attested · no Copilot licence required

  • SCANNEDIdentity & access hygiene — MFA, Conditional Access, device-code flow
  • SCANNEDGuest & external identity containment
  • SCANNEDSharePoint, OneDrive & Teams oversharing
  • SCANNEDAuditability — unified audit log, mailbox auditing, no bypass
  • SCANNEDInsider-risk sign-in containment
  • ATTESTEDSensitivity labelling & DLP for AI
  • ATTESTEDRollout governance & oversharing review

The outcome: a defensible answer to "can we safely switch Copilot on?", with the specific settings to change first — assessed from your current tenant, whether or not Copilot is licensed.

Cloud AI Posture

7 control areas on AWS · Bedrock & SageMaker

  • SCANNEDAI governance & model management
  • SCANNEDGenAI guardrails — prompt-attack & sensitive-data filters
  • SCANNEDInvocation logging & model monitoring
  • SCANNEDLeast-privilege access & network isolation
  • SCANNEDData & artifact encryption
  • SCANNEDLLM-jacking detection — hijacked model usage and spend spikes

Scope, honestly. This review covers Microsoft 365 and AWS. AWS is graded requirement-by-requirement across Bedrock and SageMaker against the AWS AI Security Framework; Copilot readiness is graded from your Microsoft 365 tenant. Azure and Google Cloud are not in scope — our coverage there is one control apiece, and charging the same price for it would imply a parity that does not exist. If your AI estate is Azure- or GCP-heavy, tell us and we will scope it as engineering work instead.

What the report looks like

Every control scored and graded to a published framework, with a verdict and evidence on each line. This is a representative preview, not real client data.

AI Security Review AWS AI SECURITY FRAMEWORK
Needs work
14 of 16 controls assessed · 4 gaps · 1 critical
Identity & accessMET
Data oversharing containmentGAP · HIGH
GenAI guardrailsPARTIAL
Logging & monitoringMET
Network isolationATTESTED

Each line expands to the requirement, its verdict, the evidence, and step-by-step remediation in the full report.

How it works

01

Connect

You grant read-only credentials. No agents installed; credentials never stored in our portal.

02

Scan

Configuration-level evidence collected across M365 and your AI estates.

03

Attest

A senior engineer reviews what scanners can't see, such as labels, DLP and governance, with evidence notes.

04

Report

Scored, prioritised and senior-reviewed. We walk it through with you, then it is yours to keep.

What you receive

Scope, honestly. This is an AI security review: how your AI services and Copilot rollout are actually configured, evidenced control by control. It is not an AI governance certification — if you need ISO 42001 or the NIST AI RMF attested as policy and process, that is a different discipline and we will point you to it rather than pretend a scan covers it.

$5,000 ex-GST · standalone · typical 1–2 weeks

or +$2,500 attached to a Security Controls Assessment. The credentialed scan is already running, so you pay only for the AI-specific analysis.

Read-only access · no agents · client credentials never touch our portal · project-based, no lock-in