Light consulting offer
AI Security Setup Review
A practical review for small teams that already use AI tools and need a clear operating baseline for approved tools, sensitive data, admin controls, and near-term fixes.
Scope
What is included
This is a focused setup review, not a full audit. The goal is to help a founder, operator, or technical lead decide which AI risks need action this month and which controls can wait.
Tool inventory review
Review up to 8 AI tools, including chat tools, meeting bots, coding assistants, browser extensions, and AI agents.
Data rule review
Identify where customer data, source code, credentials, transcripts, or confidential files need clearer rules.
Admin control check
Check managed accounts, MFA, sharing, connectors, retention settings, offboarding, and approval records.
Priority action plan
Deliver a short ranked list of fixes with owners, urgency, and a simple 30-day rollout sequence.
Deliverables
- One-page AI tool risk summary.
- Approved, restricted, and needs-review tool list.
- Data handling recommendations for common AI use cases.
- Admin control and connector checklist.
- 30-day action plan with practical next steps.
Not included
- No legal, compliance, certification, or security assurance opinion.
- No penetration test, SOC 2 readiness review, or vendor due diligence report.
- No custom policy drafting beyond short practical recommendations.
- No handling of passwords, API keys, customer exports, or regulated personal data.
Intake
Questions to answer before booking
The review works best when the team can share non-sensitive answers and links to public vendor docs. Do not send secrets, customer records, source code, or private contracts.
- Which AI tools do employees already use for work?
- Which systems are connected to AI tools, such as email, Drive, Slack, GitHub, CRM, helpdesk, calendar, or meeting platforms?
- What data types might employees paste, upload, transcribe, or sync?
- Which tools are managed company workspaces versus personal accounts?
- Who owns approval, offboarding, and incident decisions today?
- What is the most urgent decision: approve, restrict, remove, or write policy?