Review Intake
Pilot-readyCapture buyer deadline, questionnaire source, AI workflow scope, account value, and decision owner before any custom work starts.
Local pilot demo
A focused workspace for turning one active AI or MCP security review into buyer-ready evidence, reusable questionnaire answers, and a clear gap list.
This is a sales/demo surface only. It should not be treated as a proven SaaS product until paid pilots validate the workflow.
MVP workflow
The first version exists to close and deliver paid pilots, not to automate every security workflow. Each module answers a buyer-money question.
Capture buyer deadline, questionnaire source, AI workflow scope, account value, and decision owner before any custom work starts.
Collect policies, trust-center pages, model/provider settings, data flow notes, logging screenshots, and approval rules.
Map each model, tool, permission, customer-data path, prompt-injection control, human approval gate, and audit trail.
Produce reusable answers, evidence links, unsupported-claim warnings, and a prioritized gap list for the buyer review.
Evidence vault
| Evidence item | Owner | Status | Buyer-ready note |
|---|---|---|---|
| AI provider and region | Security | Ready | Model route, region, retention, and training-use position. |
| Customer-data classes | Product | Review | Data classes listed; admin retention screenshot still needed. |
| Agent tool permissions | Engineering | Ready | Read/write actions and approval gates are mapped. |
| Prompt-injection testing | Engineering | Gap | Direct tests exist; indirect email and HTML payload tests are missing. |
| Audit reconstruction | Security | Gap | Internal logs exist; customer-facing export is not ready. |
Questionnaire engine
Map data classes, source systems, masking, retention, and model-provider path.
Separate read, draft, internal write, and external action permissions with approval rules.
Answer only from approved provider contract, DPA, and subprocessor documentation.
Show log sources, event ids, actor, tool call, prompt context, and approval trail.
Output
The paid pilot output is a buyer-facing packet: executive summary, AI workflow inventory, control matrix, answer bank, evidence index, unsupported claims, and remediation plan.
High enough to unblock a review conversation, not high enough to claim certification.
Buyer wants reconstructable logs for tool calls and approvals.
Move forward only when a live review or procurement need exists.
Revenue validation
Buyer has an active AI security review in the next 30-60 days
Buyer confirms paid scope or asks for procurement/order form
Pilot produces reusable evidence for more than one future deal
Maintenance plan is justified by recurring reviews or regulated customers