Assessments

Know exactly where you stand before you spend a dollar on the fix.

Three assessments, one rule: every score line maps to a check that was actually run, the fixes are written for your site or system, and the report is yours whether or not you go further. Start with the one that matches how your business depends on the internet.

At a glance

Which one, for whom, for how much

AssessmentFor a business thatYou receivePrice · turnaround
AI Security & Risk Audit already runs agents, copilots or automations and needs to know who can do what, and where it can be abused a 25-control NIST AI RMF scorecard, every finding owned and dated, the fix for each $1,500–$3,000 · once
Digital Intelligence Assessment wants the whole picture: operations, visibility, the web and app layer, and security, and where automation pays first a scoped review across all four pillars with a prioritised plan and the price of each step scoped · priced before work starts
SteelWorks scored against the NIST AI RMF, drawn from the live scorecard
Our own operation, scored against the NIST AI RMF and re-measured weekly.

Assessment 1

AI Security & Risk Audit

For a business that already runs agents, copilots or automations. We score the operation against the NIST AI Risk Management Framework: who can do what, where approval gates sit, how secrets and inbound content can be abused, what is logged, and what would stop a bad instruction before it acts. We run the same scorecard on ourselves every week and publish the result, so you can see what the report looks like before you buy it.

price
$1,500–$3,000, once
framework
NIST AI RMF 1.0, 25 controls
output
scorecard + owned, dated fixes
what it is not
a certification

See the audit and our own scorecard

Assessment 2

Digital Intelligence Assessment

The wide view. How the business runs day to day and what a person still does by hand; where it is invisible to AI search; what the website, apps and workflows cost in time and money; and where the security exposure sits. It ends in a prioritised plan with the price of each step, so the first thing you fund is the thing that pays back first.

scope
all four pillars
starts with
a three-line intake
price
quoted before any work starts
output
scored review + prioritised plan

Request scoping

The SteelWorks fleet: every unit and its agent count, drawn from the org record
The operating system the assessment measures you against, drawn from our own org record.

Straight answers

Which assessment should I start with?

If you already run agents, copilots or automations, start with the AI Security & Risk Audit — it scores what is live today. If you want the whole operation looked at before deciding where a structural system would pay back first, request scoping for the Digital Intelligence Assessment.

What do I actually receive?

A scored report: every check that was run and what it found, the fixes ranked by impact and written for your site or system, and a methodology section that says what was automated and what could not be assessed. Nothing is invented to fill a gap.

After the assessment

Do assessments lock me into anything?

No. Each one is priced once and the report is yours. The sprints and partner engagements are the next step only if the numbers say so.

Is the security audit a certification?

No. It scores your AI operation against the NIST AI Risk Management Framework and hands you owned, dated fixes. It is evidence for your own governance, not a certificate, and it does not guarantee that nothing can go wrong.


Request an assessment

Three lines is enough to scope one.

Leave your company, your market, and what you already run — agents, copilots, automations, or nothing yet. You get a written reply naming which assessment fits, what it would cover, and the price, before any work starts.