RG Labs ← All services

AI Security Review · New

Your AI adoption, security-reviewed with evidence.

Everyone is adopting AI. Almost nobody can prove theirs is safe. We review your implementation across Microsoft 365 Copilot, AWS Bedrock and Google Gemini, from real configuration rather than a questionnaire, and hand you a scored report your board can read.

Copilot inherits every permission It answers with whatever the signed-in user can already open, so years of oversharing surfaces in seconds.
GenAI ships ungoverned by default Bedrock & Gemini run without guardrails, invocation logging or network isolation unless someone configures them.
The board is already asking "Is our AI safe?" deserves evidence: a grade against a published framework, not a shrug or a slide.

What we review

SCANNED  measured directly from configuration  ·  ATTESTED  reviewed and evidenced by a senior engineer

Microsoft 365 Copilot Readiness

10 checks · before or after rollout

  • SCANNEDIdentity & access hygiene
  • SCANNEDData oversharing & containment
  • SCANNEDAuditability & insider-risk monitoring
  • ATTESTEDSensitivity labelling & DLP for AI
  • ATTESTEDRollout governance

AWS & GCP AI Posture

6 control areas · Bedrock, SageMaker & Gemini

  • SCANNEDAI governance & model management
  • SCANNEDGenAI guardrails
  • SCANNEDLogging & monitoring
  • SCANNEDLeast-privilege access & network isolation
  • SCANNEDData & artifact encryption

Graded to the AWS AI Security Framework requirement-by-requirement, plus Gemini exposure on Google Cloud. The full checklist and per-requirement detail are in your report.

What the report looks like

Every control scored and graded to a published framework, with a verdict and evidence on each line. This is a representative preview, not real client data.

AI Security Review AWS AI SECURITY FRAMEWORK
Needs work
14 of 16 controls assessed · 4 gaps · 1 critical
Identity & accessMET
Data oversharing containmentGAP · HIGH
GenAI guardrailsPARTIAL
Logging & monitoringMET
Network isolationATTESTED

Each line expands to the requirement, its verdict, the evidence, and step-by-step remediation in the full report.

How it works

01

Connect

You grant read-only credentials. No agents installed; credentials never stored in our portal.

02

Scan

Configuration-level evidence collected across M365 and your AI estates.

03

Attest

A senior engineer reviews what scanners can't see, such as labels, DLP and governance, with evidence notes.

04

Report

Scored, prioritised and senior-reviewed. We walk it through with you, then it is yours to keep.

What you receive

$5,000 ex-GST · standalone · typical 1–2 weeks

or +$2,500 attached to a Standard or Complete Posture Report. The credentialed scan is already running, so you pay only for the AI-specific analysis.

Read-only access · no agents · client credentials never touch our portal · project-based, no lock-in