Continuous AI Assurance
Between assessments, models change, tools are added, system prompts are rewritten and retrieval corpora grow. Each change is reasonable on its own, and each one moves the ground under the previous assessment. Continuous AI Assurance re-tests what was verified at the last assessment and reports what has changed.
What is included
Scheduled regression evaluations
The evaluation suite built during your assessment, re-run on a schedule, so we catch a regressed fix before a customer does.
Prompt-injection regression tests
Every injection that worked against you, plus new public attack classes as they emerge, re-tested against the current system.
Model and provider change analysis
When you change model, version or provider, we measure the behavioural and security differences in your system specifically.
Newly introduced tool review
Every new tool, integration or MCP server an agent gains is a new permission. Each one is reviewed while it is still new.
RAG quality and boundary testing
Retrieval authorization, tenant separation and citation accuracy re-checked as the corpus grows and the ingestion pipeline changes.
Permission and privilege review
What the system can reach this month against what it could reach last month. Permissions accumulate quietly, so we track the delta.
Drift monitoring
Shifts in refusal behaviour, instruction following and output characteristics that arrive without a deployment to explain them.
Security control regression
The controls that closed previous findings, verified as still present and still effective.
Governance review
Model inventory, ownership, intended-use documentation and change management, kept current month by month so an auditor finds them ready.
Remediation tracking
Every open finding, its age, its status and what is blocking it, carried forward month to month until it closes.
How a month runs
Scheduled runDI-DS
The evaluation suite runs against your current system, inside the same authorization that governs the engagement. Widening that scope requires your sign-off.
Expert reviewDI-DS
Results pass through human review before they reach you. Automated tooling produces candidates. A person decides which are findings, which are noise, and which represent a genuine change in behavior.
Critical findings escalated immediatelyDI-DS
Anything critical and exploitable reaches you the day we confirm it, with enough detail to act on immediately.
Monthly report deliveredDI-DS
What changed, what regressed, what is newly at risk, and what closed since last month, delivered through authenticated portal access.
You decide what to act onYou
Take the remediation guidance to your own engineers, or hand the work to us as a separate scope. Open findings stay on the tracker until they close.
Questions
What does $1,000 a month actually get us?
The baseline covers one production AI application: a monthly regression run of your evaluation suite, prompt-injection retesting, model-change analysis, permission review and a monthly report. Larger estates, faster cycles and agentic systems with many tools price above that, quoted from scope and fixed thereafter.
Do we need an assessment first?
In practice, yes. Continuous Assurance re-runs and extends the evaluation suite built during an Assurance Audit or Red-Team, and that baseline is what makes a regression visible. Most customers start with the audit and add monitoring once they see how quickly the system moves.
Are there meetings?
Only if you want them. The default is a monthly report in the portal and a notification when something needs attention. Teams who prefer a standing call are welcome to one.
What happens when you find something?
Critical findings go out the day we confirm them. Everything else appears in the monthly report with severity, evidence and remediation guidance, and stays on the tracker until it closes.
Can we cancel?
Month to month, with 30 days' notice and no annual lock-in. If your system settles down enough that monitoring stops earning its keep, pause it and come back when it moves again.
Is this just running the same tests forever?
The suite grows every month: new attack classes as they are published, a new test for each finding we confirm, and fresh coverage as your system gains tools and surfaces.
Keep the answer current
Most organizations add Continuous Assurance after a first assessment, having seen how much the system changed during the weeks the assessment took to complete.