Free AI Risk Snapshot
The AI Risk Snapshot is a short report on what an organization's public material reveals about its AI system: the functionality it implies, the trust boundaries it suggests, the controls already documented, and the questions a security reviewer would ask next.
Every observation comes from information you have already published.
What a Snapshot contains
Company AI profile
What your organization appears to be doing with AI, assembled from your own public material: product pages, documentation, engineering posts and job listings.
Observed AI functionality
The AI capabilities we can actually see: what the product appears to do, whether it retrieves, whether it acts, and where a user's input reaches a model.
Likely trust boundaries
Where untrusted input plausibly enters, and where the system crosses from your control into a model provider's or a customer's. Every inference is labelled as an inference.
Publicly visible controls
What you already document: a trust centre, a security page, a subprocessor list, a model policy. Often the most useful section, because it shows exactly what a prospect's security reviewer will find.
Potential risk areas worth validating
Areas where the architecture your public material implies raises a question worth answering. Each one is phrased as a question.
Questions management should be able to answer
Roughly ten questions a board member, enterprise customer or insurer might reasonably ask. If you can answer all of them, you are in better shape than most.
Recommended next step
Sometimes an assessment. Sometimes 'publish a model policy, you are most of the way there already.' We say which one applies.
What we do and do not do
This distinction matters more than anything else on this page, so here it is in full.
Sources we use
- Your public website and product pages
- Public technical and API documentation
- Trust centres, security pages and subprocessor lists
- Privacy policies and terms of service
- Public model and AI-use documentation
- Job postings describing your AI stack
- Public engineering talks, posts and architecture discussions
- Press releases and public product demos
What we never do
- Penetration testing of any kind
- Prompt injection against your applications
- Credential testing or authentication bypass attempts
- Port scanning or vulnerability scanning
- Exploitation of anything we observe
- Destructive or state-changing actions
- Aggressive or automated probing of your systems
- Accessing anything that requires authentication
A Snapshot is not a security assessment, and we will not pretend otherwise
Public information shows what a product does and what its vendor says about securing it, and no more. Whether retrieval is scoped correctly, whether approval gates hold under pressure, and whether one tenant's data can reach another are questions that require authorized testing. The Snapshot identifies which of those questions apply to the system in question.
How we write findings
A Snapshot involves no testing, so every statement in it is scoped to what public evidence supports. The wording is deliberate.
| We write | We never write | Why |
|---|---|---|
| "Worth validating" | "You are vulnerable to…" | Claims stay inside what the evidence supports. |
| "Potential exposure" | "Your data is exposed" | Public material implies an architecture. Proving a failure in it takes testing. |
| "Cannot be confirmed from public information" | Silence | Naming the limits of the method tells you how much weight to put on the rest. |
| "Area worth reviewing" | "Critical finding" | Severity requires evidence, and evidence requires authorized testing. |
Questions
What is the catch?
It takes us a couple of hours and it is how we introduce ourselves. A few recipients become customers and the rest keep a useful document. Follow-up runs to two messages, with an opt-out in each.
Will you test our systems?
A Snapshot is assembled entirely from information you have already made public. Your application receives zero requests from us. Active testing happens only under a signed authorization, which a Snapshot never involves.
Then how accurate can it be?
Accurate about what it can see, and explicit about the rest. Public information shows what your product does and what you say about securing it. How retrieval is scoped and whether your approval gates hold stay invisible from outside. The report separates what we observed from what we inferred, and every claim carries its evidence.
Will it say we have vulnerabilities?
It raises questions and marks them as questions. The language stays deliberate: "worth validating", "potential exposure", "cannot be confirmed from public information". Treat any report that claims confirmed vulnerabilities without testing anything as a warning about its author.
We already received one. What now?
Keep it and use whatever was useful. Where a question in it is one you would rather answer with confidence, the AI Assurance Audit answers it with evidence.
Can you remove us from your list?
Yes, immediately and permanently. Every message carries an opt-out, and using it suppresses you across everything we send.
Request a full AI Assurance Audit
Where the Snapshot raises a question the organization would prefer to answer with evidence, the AI Assurance Audit answers it: a fixed price of $7,500 for one application, purchased online.