Engagement process

How an Assessment Works

Meetings are optional for standard assessments. A complete engagement, from purchase through agreement, authorization, intake, assessment, reporting and remediation plan, runs asynchronously. A form collects what a kickoff meeting collects, and collects it more accurately. A written report delivers what a readout meeting delivers, and it can be forwarded to the people who need it.

Every engagement includes a findings call at no extra cost, available whenever it helps.

01

Select your assessmentYou

Choose the AI Assurance Audit, or start scoping a Red-Team engagement. Describe the system and we will tell you which one fits, including when the cheaper option covers it.

02

Execute the agreement and authorizationBoth

Two documents, signed electronically: a standard engagement agreement, and a Security Testing Authorization naming the exact systems, environments, permitted and prohibited methods, testing window and an emergency stop contact. Active testing begins once both are complete.

03

Complete the secure technical intakeYou

A form that adapts to your answers, so retrieval questions appear for systems that retrieve and agent questions appear for systems that act. Every question offers "I don't know", and that answer tells us something worth knowing.

04

Provide access and documentationYou

Test accounts at two privilege levels, a staging environment where possible, an architecture description in whatever form already exists, and any prior evaluations. Everything uploads through authenticated portal access.

05

We assess the systemDI-DS

Automated evaluation across the assessment areas, followed by manual testing that pursues whatever the automated pass surfaces. This is where most of the time goes, and where the character of your system decides what we chase.

06

Every finding passes expert reviewDI-DS

Automated tooling proposes candidate findings. A person then confirms each one, clears the noise, assigns severity and confidence, and writes the remediation guidance. Everything you read has been through that gate.

07

Reports delivered to the portalDI-DS

An executive report and a technical findings report, both typeset as PDFs and delivered through authenticated portal access.

08

Optional findings callOptional

Walk through the technical report with the person who wrote it, at no extra cost. The reports are written to stand alone, so the call is there when it adds something.

09

Remediation or monitoring, if you want itOptional

Take the remediation plan to your own engineers, have us implement the fixes as a separate fixed-price scope, or move to Continuous Assurance where the system changes often. You choose.

What we ask of you, in total

Across an entire standard assessment, this is the complete list of things that require your time.

That is the whole obligation. Your engineers stay on their roadmap while the assessment runs.

How your data is handled

Documents and credentials

Documents and credentials are uploaded through authenticated portal access and encrypted in transit and at rest. Customers are asked to keep test credentials short-lived and scoped to the engagement, and DI-DS flags any credential that carries more privilege than the work requires.

Findings and reports

Because a system's architecture and its weaknesses are sensitive, reports remain behind authenticated portal access, and that access is revoked on request. At the end of the testing window DI-DS reminds the customer to revoke the test credentials.

Testing is bounded by written authorization

Active testing runs only against systems and scopes the customer has authorized in writing, within a defined window, using permitted methods. Where findings suggest the scope should be wider, DI-DS returns to the customer for approval.

Start when you are ready

Scope and price are confirmed before anything is charged, and before any testing begins.

Start an Assessment See a sample report