Assessments
Know exactly where you stand before you spend a dollar on the fix.
Three assessments, one rule: every score line maps to a check that was actually run, the fixes are written for your site or system, and the report is yours whether or not you go further. Start with the one that matches how your business depends on the internet.
At a glance
Which one, for whom, for how much
| Assessment | For a business that | You receive | Price · turnaround |
|---|---|---|---|
| AI Security & Risk Audit | already runs agents, copilots or automations and needs to know who can do what, and where it can be abused | a 25-control NIST AI RMF scorecard, every finding owned and dated, the fix for each | $1,500–$3,000 · once |
| Digital Intelligence Assessment | wants the whole picture: operations, visibility, the web and app layer, and security, and where automation pays first | a scoped review across all four pillars with a prioritised plan and the price of each step | scoped · priced before work starts |
Assessment 1
AI Security & Risk Audit
For a business that already runs agents, copilots or automations. We score the operation against the NIST AI Risk Management Framework: who can do what, where approval gates sit, how secrets and inbound content can be abused, what is logged, and what would stop a bad instruction before it acts. We run the same scorecard on ourselves every week and publish the result, so you can see what the report looks like before you buy it.
- price
- $1,500–$3,000, once
- framework
- NIST AI RMF 1.0, 25 controls
- output
- scorecard + owned, dated fixes
- what it is not
- a certification
Assessment 2
Digital Intelligence Assessment
The wide view. How the business runs day to day and what a person still does by hand; where it is invisible to AI search; what the website, apps and workflows cost in time and money; and where the security exposure sits. It ends in a prioritised plan with the price of each step, so the first thing you fund is the thing that pays back first.
- scope
- all four pillars
- starts with
- a three-line intake
- price
- quoted before any work starts
- output
- scored review + prioritised plan
Straight answers
Which assessment should I start with?
If you already run agents, copilots or automations, start with the AI Security & Risk Audit — it scores what is live today. If you want the whole operation looked at before deciding where a structural system would pay back first, request scoping for the Digital Intelligence Assessment.
What do I actually receive?
A scored report: every check that was run and what it found, the fixes ranked by impact and written for your site or system, and a methodology section that says what was automated and what could not be assessed. Nothing is invented to fill a gap.
After the assessment
Do assessments lock me into anything?
No. Each one is priced once and the report is yours. The sprints and partner engagements are the next step only if the numbers say so.
Is the security audit a certification?
No. It scores your AI operation against the NIST AI Risk Management Framework and hands you owned, dated fixes. It is evidence for your own governance, not a certificate, and it does not guarantee that nothing can go wrong.
Request an assessment
Three lines is enough to scope one.
Leave your company, your market, and what you already run — agents, copilots, automations, or nothing yet. You get a written reply naming which assessment fits, what it would cover, and the price, before any work starts.