Commercial portal · Private offers
Private offers for bounded technical and partner decisions.
A private offer defines one commercial relationship: the selected outcome, scope, inputs, outputs, deployment or delivery model, evidence boundary, responsibilities, support, timing, and commercial terms. Choose the relevant path first; the packet, intake, contracts, and proposal then adapt to that path.
Private offers may support direct SOW, invoice, enterprise procurement, or other approved buying paths. AWS-compatible deployment or procurement support may be discussed where relevant; this does not imply an AWS Marketplace listing unless one exists.
How the buying motion works
Get to yes without waiting on every process sequentially
We help product, security, legal, and finance get to yes quickly with a scoped plan, approval packet, and evidence-ready deliverables. Pre-Engagement Scoping confirms the decision, scope, information boundary, authorization requirements, procurement path, and appropriate commercial instrument before paid work begins — it is not free consulting.
AI Security Academy → AI Security Academy
- 01
Choose the relationship
Select the engagement, product, pilot, Academy, workforce, or partner motion.
- 02
Define the bounded scope
Confirm the system, workflow, capability, learners, partner object, or business decision in scope.
- 03
Confirm the information boundary
Identify what can safely be supplied during qualification and what requires NDA, DPA, ROE, or secure exchange.
- 04
Assemble the applicable packet
Generate only the technical, legal, procurement, evidence, and commercial material required for that relationship.
- 05
Review the offer
Confirm scope, deliverables, responsibilities, timing, support, price, and applicable agreements.
- 06
Approve and activate
Begin only after the required commercial and authorization conditions are satisfied.
AI Security Academy Onboarding Kit
Artifacts your champion can forward internally — AI Security Academy
The first deliverable is a decision package, not just a report. Each asset is track-aware — copy or forward it.
AI Security Academy One-PagerForwardable summary of the offer, timeline, and positioning.Show copy-ready content ↓
AI SECURITY ACADEMY — ONE-PAGER Build role-aligned AI security capability through structured learning and practice. Track: AI Security Academy → AI Security Academy AI Security Academy packages structured courses, Q&A checks, workshops, and LMS-ready content into an enterprise training program your teams can start in days, not months. Timeline: Team access live within 1–3 business days. LMS package delivery: 2–4 weeks. Private cohort: scheduled by agreement. We help product, security, legal, and finance get to yes quickly with a scoped plan, approval packet, and evidence-ready deliverables.
Internal Approval MemoMemo focused on enterprise AI security training: course selection, seat count, delivery mode (hosted/LMS/cohort), and required training evidence.Show copy-ready content ↓
INTERNAL APPROVAL MEMO — AI Security Academy Why now: New AI products launching internally, compliance or audit requirement for AI security training, enterprise customer requiring evidence of team training, scaling a red team or AppSec program, onboarding an AI security hire. Business pressure: We need structured AI security training for our teams but have no budget for a custom curriculum build, and off-the-shelf compliance training doesn't cover LLMs, agents, RAG, or AI product security. Focus: This engagement is about enterprise AI security training: course selection, seat count, delivery mode (hosted/LMS/cohort), and required training evidence. What we are buying: AI Security Academy. Timeline: Team access live within 1–3 business days. LMS package delivery: 2–4 weeks. Private cohort: scheduled by agreement. Budget category: L&D / security training / compliance / security program. Note: This is a scoped, bounded engagement, not a platform migration or open-ended program build. Expected deliverables: • Course access for selected seat count • Team training plan and recommended learning paths • Q&A credential checks per course • Manager completion and readiness summary • SCORM 1.2 preview package (available by scope) • LMS deployment guide • Enterprise training terms • Private cohort kickoff (if selected) Who needs to approve: • L&D / training lead • Security / CISO • Finance (fixed-fee or annual) • Legal (enterprise training terms + DPA if learner data processed) Risk if delayed: Build role-aligned AI security capability through structured learning and practice. Decision needed: Approve Pre-Engagement Scoping (NDA + information boundary + draft plan) so legal, finance, and technical can move in parallel, then a fixed-fee SOW / private offer once scope is clear. Scope guardrails: • Not a rubber stamp. • Not a certification claim. • Not an open-ended governance program. • Not a platform migration. • Not production testing without explicit authorization.
Information Boundary ChecklistWhat's needed to scope this engagement.Show copy-ready content ↓
INFORMATION BOUNDARY CHECKLIST — AI Security Academy To scope this engagement, please prepare: • Context needed to produce: Course access for selected seat count • Context needed to produce: Team training plan and recommended learning paths • Context needed to produce: Q&A credential checks per course • Context needed to produce: Manager completion and readiness summary • Context needed to produce: SCORM 1.2 preview package (available by scope) • Context needed to produce: LMS deployment guide Do not submit passwords, API keys, tokens, private keys, production credentials, regulated data, unredacted customer records, exploit payloads, or proprietary source code at this stage. Secure exchange methods are established after qualification and, where required, the applicable NDA, DPA, or agreement.
Legal + Procurement PacketVendor, payment, and buying-motion details for finance.Show copy-ready content ↓
VENDOR / PROCUREMENT PACKET — AI Security LLC Engagement: AI Security Academy Budget category: L&D / security training / compliance / security program. Vendor profile: AI Security LLC — graph-backed AI application and agent security engineering. Payment: fixed-fee or licensed where applicable; invoice terms available; private offer / SOW path. Security/assurance: trust-center materials and references available on request. Onboarding: we can complete standard vendor onboarding and security questionnaires. Buying motion: 1. Choose the relationship and define the bounded scope. 2. Pre-Engagement Scoping confirms the information boundary and authorization requirements — no committed budget to start. 3. Private offer / SOW once scope is clear. Timeline: Team access live within 1–3 business days. LMS package delivery: 2–4 weeks. Private cohort: scheduled by agreement. Pre-Engagement Scoping does not mean free consulting. It means confidentiality, access boundaries, and review planning before paid work begins.
Draft Engagement PlanMADE-aligned plan, timeline, and deliverables.Show copy-ready content ↓
DRAFT PLAN — AI Security Academy MADE translation: • Map the system, workflow, or capability in scope. • Attack or test what matters for this engagement. • Defend by addressing what must change. • Evidence what supports the decision. Timeline: Team access live within 1–3 business days. LMS package delivery: 2–4 weeks. Private cohort: scheduled by agreement. Deliverables: • Course access for selected seat count • Team training plan and recommended learning paths • Q&A credential checks per course • Manager completion and readiness summary • SCORM 1.2 preview package (available by scope) • LMS deployment guide • Enterprise training terms • Private cohort kickoff (if selected) The first deliverable is a decision package, not just a report.
Onboarding
Move four tracks in parallel
We put legal, finance, procurement, and technical scoping on parallel rails so the work can start without waiting on every internal process sequentially.
Technical / Program Definition
Output: Draft Engagement Plan
- system or capability in scope
- workflow and integration points
- access or environment needs
- authorization and boundaries
Legal
Output: NDA + Scoping Authorization
- mutual NDA
- data handling
- authorized use boundaries
- confidentiality
- work-product terms
Finance / Procurement
Output: Procurement Packet
- vendor profile
- tax/payment details
- budget category
- fixed-fee quote path
- invoice terms
- onboarding answers
Internal Approval
Output: Approval Memo
- why now
- business pressure
- risk if delayed
- expected deliverables
- timeline
- decision needed
Readiness packet
Bundle a scoped pentest or red team engagement
A private offer can include scoped penetration testing, cloud review, or adversarial red teaming. Build the readiness packet first — targets, authorization, ROE, access, evidence handling, and deliverables — so the offer and SOW come together cleanly.
Readiness Packet
Prepare the test before selecting the tester.
Cobalt-style onboarding for scoped security testing, adversarial review, cloud assessment, and AI/agentic red teaming.
- Scope Brief & Target Inventory
- Rules of Engagement & Authorization
- Access Plan & Evidence Handling
- Required contracts + Draft SOW inputs
Testing only proceeds against targets your organization owns, controls, or is explicitly authorized to assess.
Enterprise training
Request an Academy enterprise training packet
Team Pack, Enterprise LMS Package, Private Cohort, Workforce Platform Partner Add-On, and Academy Content Licensing options are available. Covers seat access, supported LMS delivery, facilitator guides, Q&A checkpoint keys, manager reports, and enterprise training terms. SCORM 1.2 preview available; full package by implementation scope.
From packet to offer
Private offers are generated from readiness packets
A private offer should be generated from a clear packet, not a vague intake thread. Complete the readiness packet for your engagement, then we turn it into a fixed-fee offer.
- 1Choose your buyer pressure
- 2Complete the readiness packet
- 3Confirm NDA / legal path
- 4Generate draft SOW inputs
- 5Request a fixed-fee private offer
- 6Kickoff after approval
Readiness packets
Pick the packet to turn into an offer
Each packet captures scope, authorization, access, evidence, and contracts — everything finance and legal need to approve a fixed-fee engagement.
Launch Review Packet
We are launching an AI feature, copilot, RAG system, agent, or workflow soon and need launch-risk clarity fast.
Required to assemble
Target AI feature or workflow · Lifecycle stage · Release pressure · Architecture overview · Evidence available · NDA/SOW path
Likely blockers
Missing staging/demo access · Unclear system prompt / RAG / tool boundaries · No launch owner · No buyer/security evidence owner
Routes to:
Product Security Packet
We need a full architecture, data-flow, trust-boundary, model/provider, RAG, and tenant-isolation review beyond an urgent launch gate.
Buyer Evidence Packet
Enterprise buyers are asking AI security questions we cannot answer cleanly, and the deal/security review is slowing down.
Required to assemble
The buyer questions / questionnaire · Claims needing support · Existing evidence · Trust-center / audience
Likely blockers
No evidence owner · Claims lack scope / date · Unclear what is public-safe
Routes to:
Agent Authority Packet
Agents, tools, credentials, workflows, approvals, and actions have unclear blast radius.
Required to assemble
Agent / tool inventory · Permissions & credentials model · Approval & rollback paths · Logs / audit coverage
Likely blockers
Unclear tool / action blast radius · No rollback path · Missing audit logs
Routes to:
Pentest Readiness Packet
We need a pentest or adversarial test, but scope, authorization, ROE, access, window, evidence, and procurement are not ready.
Required to assemble
Target inventory · Ownership / authorization · ROE · Testing window · Emergency contact · Access plan · Evidence rules
Likely blockers
Third-party target authorization · No testing window · Missing stop contact · Production constraints unresolved
Routes to:
AI Red Team Packet
We need adversarial validation of prompt injection, RAG exposure, tool abuse, tenant leakage, and unsafe autonomy.
Required to assemble
Model / provider / app surface · Prompt / RAG / tool boundaries · Allowed adversarial methods · Prohibited methods · Evidence handling · Human approval points
Likely blockers
Unclear tenant / data boundaries · No safe test data · Tool / action blast radius unclear
Routes to:
RAG Boundary Packet
RAG retrieval, embeddings, ingestion, and tenant boundaries may leak customer or cross-tenant data.
Required to assemble
Source systems · Corpus sensitivity · Tenant boundaries · Retrieval access rules · Eval / logging coverage
Likely blockers
Unclear source ownership · Production customer data present · No retrieval logs / evals
Routes to:
Connector Security Packet
OAuth apps, SaaS connectors, scopes, webhooks, token storage, and connected actions need a least-privilege review.
Required to assemble
Connected apps · OAuth scopes · Read/write actions · Webhook / callback handling · Token storage assumptions · Revocation path
Likely blockers
Excessive OAuth scopes · Unclear admin ownership · Missing revocation process
Routes to:
Enterprise Onboarding Packet
Enterprise SSO/SCIM, RBAC, provisioning, deprovisioning, and auditability are becoming a deal blocker.
Required to assemble
IdP · SSO protocol · SCIM / provisioning · Role / group mapping · Deprovisioning · Audit / logging needs
Likely blockers
No IdP owner · Unclear role model · No test users / groups
Routes to:
Program Build Packet
AI security is scattered policy with no operating model, ownership, controls, evidence, or cadence.
Maturity Scorecard
We do not yet know our AI security gaps or where to invest first.
Secure AI SDLC Packet
AI security is not operationalized in engineering: CI/CD, design review, code review, evals, logging, and release gates.
Required to assemble
Current SDLC / CI-CD · Release process · Eval / test coverage · Design / code review practice
Likely blockers
No release-gate owner · Eval coverage gaps · No logging baseline
Routes to:
Guardrails & Evals Packet
Our guardrails, evals, refusal behavior, and release criteria have unknown coverage and failure modes.
Provider Risk Packet
We need clarity on model/provider data flows, retention, training terms, residency, logging, and fallback risk.
Required to assemble
Providers in use · Data sent to each · Logging approach · Residency requirements
Likely blockers
No DPA from provider · Unclear retention / training terms · No fallback design
Routes to:
Claim-Readiness Packet
We need to control what we can safely say publicly or to buyers after assessment work.
Required to assemble
Intended claim · Audience · Evidence source · Scope / date / limitations · Approval owner · Public-safe summary needs
Likely blockers
Draft evidence treated as final · Claim lacks scope / date · No approval owner
Routes to:
Custom Support Packet
We have a specialized AI security need that does not fit a standard service.
Engagement readiness
Ready to scope is not the same as authorized to test.
Testing starts only after the required SOW, ROE, target list, access path, and testing window are approved.
Technical Scope
Needs inputTechnical owner or security owner
Inputs: Target systems, lifecycle stage, architecture overview, boundaries
Next: Define the in-scope systems and surfaces
Build a packetLegal / NDA / DPA / SOW
Needs inputLegal owner
Inputs: Mutual NDA, DPA if personal/customer data, SOW or no-cost scoping
Next: Start the no-cost scoping / NDA path
Contract packetAccess & Credentials
Needs inputTechnical owner or IT/admin owner
Inputs: Access model, test accounts, secure credential-delivery channel
Next: Plan secure access — never via public forms
Evidence Handling
Needs inputSecurity owner
Inputs: Storage location, redaction, retention, deletion
Next: Confirm evidence storage + retention rules
Evidence Handling PolicyScheduling & Stop Contacts
Needs inputTechnical owner and emergency contact
Inputs: Testing window, blackout dates, stop-testing/emergency contact
Next: Set the window and a reachable stop contact
Procurement / Payment / Private Offer
Needs inputFinance / procurement owner
Inputs: Vendor packet, budget category, PO/payment path, private offer
Next: Request a fixed-fee private offer once scope is clear
Private offersDo not submit secrets, production credentials, access tokens, regulated data, or unredacted customer records through public forms. Credential exchange happens only after NDA/SOW/DPA/ROE through an approved secure channel.
What you can bundle
One scoped engagement, many components
Products + onboarding
AI Security Workbench tools and platforms with implementation and onboarding included.
Services + retests
Assessments, red teaming, and hardening with scheduled retests.
Academy at scale
Team training, SCORM/LMS packages, and certification seats.
Evidence + reporting
Evidence packs, control mappings, and executive reporting cadence.
Enterprise packages
Common starting points
AI Security Workbench
AI security program, trust evidence, and remediation workbench
Code Scanner Team License
Recurring AI code and configuration review for product security, AppSec, and developer teams
Trust Scanner
AI and security claim scanner for customer-facing trust language
Adversarial Range
Deployable AI security lab for RAG, agents, telemetry, and evidence validation
AIPSA SCORM Training Package
LMS-compatible AI product security training with a supported SCORM 1.2 preview and additional delivery formats by validated implementation scope
Workforce Platform Partner Add-On
The role-readiness layer for cybersecurity training platforms, cyber ranges, and enterprise security teams. Role taxonomy, Q&A bank, job-market signals, hiring calibration, and workforce reporting — under your brand.
Scanner Provider OEM Pilot
A bounded OEM pilot that preserves the scanner's finding identity and workflow while adding selected AI-specific findings, connected context, evidence, and optional Attack Path Analysis.
AI Launch Security Review
Pre-launch AI security review for product teams shipping LLM features, RAG systems, copilots, agents, or AI workflows.
Pen Test & Red Team Readiness Packet
Structured readiness assessment for teams scoping an external pen test or red team engagement — scope, authorization, ROE, evidence handling, and vendor criteria.
AI Security Academy
Structured AI security training for security, engineering, product, governance, and trust teams — courses, Q&A checks, LMS delivery, and private cohorts.
Academy Content Licensing
Partner-ready AI security training content — courses, Q&A bank, LMS packages, and workforce readiness modules for training platforms, cyber ranges, and enterprise L&D delivery.
Request a private offer
Tell us what to scope
Do not submit passwords, API keys, OAuth or access tokens, private keys, production credentials, regulated data, unredacted customer records, exploit payloads, or proprietary source code through this public form. Describe the boundary at a high level. Secure exchange methods are established after qualification and, where required, the applicable NDA, DPA, SOW, or rules of engagement.
AI Security Academy uses a dedicated request flow, not this general intake form.
AI Security Academy packages structured courses, Q&A checks, workshops, and LMS-ready content into an enterprise training program your teams can start in days, not months.
Private-offer packet
The default enterprise packet is ready to assemble.
This packet is designed for quote-first and invoice-first motion with legal, procurement, data handling, and evidence language attached to the same opportunity.
Statement of Work Template
Mission-specific scope, deliverables, timeline, access, assumptions, and acceptance criteria for scoped AI security engagements.
Mutual NDA
Mutual confidentiality protections for pre-sales, delivery, and research collaboration contexts.
Used for NDA baseline
Assessment Terms Addendum
Scope, authorization, evidence use, testing boundaries, safe harbor, retesting, reporting limitations, and reliance limits for AI product security assessments.
Used for Assessment and quote-first services
Data Processing Addendum
Controller/processor allocation, data protection obligations, subprocessing, security measures, AI provider boundaries, and customer-data handling for scoped services.
Used for Data handling and public-safe claims
Commercial Services Addendum
Converts the services framework into scoped paid work with rate card, invoicing, and activation terms.
Used for Retainer and advisory billing
Publication & Claim-Readiness Policy
Claim-readiness criteria for public research, trust pages, scorecards, attestations, sponsor materials, security review outputs, and buyer-facing evidence.
Used for Data handling and public-safe claims · Sponsored research and launch
Payment terms
Net 30, prepaid invoice, or custom procurement terms.
Acceptance terms
Accepted when the agreed deliverables are delivered and the buyer has had a factual review window.
Fulfillment workflow
scope -> packet -> quote / invoice -> acceptance -> launch room
Prefer to browse first? Back to the Marketplace