PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

AI Security Pricing

Start with a bounded decision, not an open-ended transformation.

Pricing follows the defined scope, systems, workflows, evidence requirements, delivery model, and decision the work must support. Start with one bounded review or pilot and expand only when the next phase has a clear owner and value.

NDA, DPA, SOW, rules of engagement, evidence handling, and subprocessors available through the Trust Center.

AI Launch Security Review

Scoped after triage

5-10 business days

Product teams shipping an AI feature, copilot, RAG system, agent, or workflow in the next 30–60 days. First findings in 5 business days. Typical budget: launch, AppSec, product security, red team, customer assurance, or security review.

Primary services

AI Launch Security Review

Common deliverables

Launch Risk Memo, Graph-Backed Abuse Paths, Release Gate Checklist, Defense Breakpoint Fix Backlog

Scope This Review

Expert-Led AI Security Program Baseline

Scoped after discovery

1-3 weeks

Teams that need a fast baseline before assessment, red-team, hardening, governance, or buyer review work.

Primary services

Expert-Led AI Security Program Baseline

Common deliverables

Analyst-Reviewed Program Baseline, AI surface inventory, Control Coverage Snapshot, Evidence-gap register

Establish the program baseline

AI Product Security Assessment

Scoped after discovery

2-4 weeks

A deeper follow-on assessment for broader architecture, trust-boundary, RAG, agent, tenant-isolation, product-security, and evidence coverage after launch triage or when the product surface is already larger than a focused launch review.

Primary services

AI Product Security Assessment, AI Guardrails & Evals Review, AI Security Sales Enablement

Common deliverables

AI system inventory, Architecture and trust-boundary review, Abuse-path review, Control gap assessment

Scope a Product Assessment

Adversarial Testing & Hardening

Scoped after discovery

3-6 weeks

Teams that need reproducible abuse validation, RAG/XPIA testing, agent action testing, guardrail/eval validation, retesting, or post-assessment hardening.

Primary services

AI Red Team & Adversarial Testing, RAG & XPIA Security Review, Agentic Workflow Security & Hardening, AI Guardrails & Evals Review

Common deliverables

Red-team scope and test plan, Findings register with reproduction evidence, Agent permission matrix, RAG authorization review

Scope an AI Red Team

Program, Governance & Evidence

Scoped after discovery

4-10 weeks or retainer

Teams that need an AI security operating model, release gates, control ownership, evidence cadence, trust-center support, or a follow-on program build after the baseline.

Primary services

Expert-Led AI Security Program Baseline, AI Security Sales Enablement, AI Product Security Assessment

Common deliverables

AI governance operating model, Control ownership matrix, Evidence pack, Control crosswalk

Start with the Program Baseline

Flexible Expert Support

Flexible expert support for scoped AI security work.

Time banks are prepaid AI security engineering hours for advisory, review, remediation planning, evidence review, red-team support, governance support, and follow-up after an assessment. They are not a substitute for a scoped assessment when rules of engagement, testing depth, or formal deliverables are required.

Most popular

TIME BANK · Team

25hours

$4,975

$199/hr

  • No expiry
  • Any service
  • Priority scheduling
  • Monthly summary
Buy Team time bank

TIME BANK · Program

50hours

$8,950

$179/hr

  • No expiry
  • Any service
  • Dedicated architect
  • Quarterly review
Buy Program time bank

Hours never expire. Transferable within your org. Hours are tracked per session with a running balance in your client portal. Explore engagement options

Academy training

Practical AI product security training built around MADE.

Academy plans provide access to field-guide lessons, labs, study cards, skill checks, and role-based training paths for teams learning how to map, test, harden, and evidence AI systems. Or purchase individual labs and domain packages at /pricing/academy-lab-access.

AI SECURITY ACADEMY · ACCESS

Weekly

$9/week

  • Full academy access — all 14 labs
  • Reference desk + study cards
  • Skill-check progress
  • Lab summaries

Auto-renews weekly · Single seat

View plan

Most popular

AI SECURITY ACADEMY · ACCESS

Monthly

$25/month

  • Full academy access — all 14 labs
  • Reference desk + study cards
  • Skill-check progress
  • Lab summaries
  • Cancel anytime

Auto-renews monthly · Single seat

View plan

AI SECURITY ACADEMY · ACCESS

Annual

$150/year

  • Full academy access — all 14 labs
  • Priority scheduling
  • Reference desk + study cards
  • Skill-check progress
  • Lab summaries

Equivalent to $12.50/mo · Auto-renews annually · Single seat

View plan

Academy training does not certify an organization’s AI system as secure and does not replace assessment, red-team testing, or audit work. Team plans (10 seats) from $499/month or $4,990/year. Enterprise (50 seats) at $19,900/year. View all plans

Enterprise course

Role-based enterprise courses

Private-offer courses for the people who build, test, sell, govern, and operate AI products. Each includes a public-safe manuscript, print edition, and enterprise delivery path.

Defendintermediate6h

Academy Course

Secure Coding with GenAI

Private offer

Build, review, test, and ship AI-assisted code safely.

  • Public-safe MDX manuscript and print edition
  • LMS / SCORM add-on compatible
  • Slack / Teams challenge add-on compatible
  • Enterprise delivery and direct SOW scoping
Evidenceintroductory5h

Academy Course

AI Security for Sales Engineers

Private offer

Speak clearly about AI risk, controls, and buyer trust.

  • Public-safe MDX manuscript and print edition
  • LMS / SCORM add-on compatible
  • Slack / Teams challenge add-on compatible
  • Enterprise delivery and direct SOW scoping
Attackintermediate6h

Academy Course

AI Red Teaming for Product Teams

Private offer

Test LLM, RAG, and agentic systems before users and attackers do.

  • Public-safe MDX manuscript and print edition
  • LMS / SCORM add-on compatible
  • Slack / Teams challenge add-on compatible
  • Enterprise delivery and direct SOW scoping
Mapintroductory5h

Academy Course

AI Product Management for Secure AI Features

Private offer

Define, scope, and ship AI products buyers can trust.

  • Public-safe MDX manuscript and print edition
  • LMS / SCORM add-on compatible
  • Slack / Teams challenge add-on compatible
  • Enterprise delivery and direct SOW scoping
Defendintermediate6h

Academy Course

AI Model Gateways and Secure Platforms

Private offer

Build the approved path for safe AI adoption.

  • Public-safe MDX manuscript and print edition
  • LMS / SCORM add-on compatible
  • Slack / Teams challenge add-on compatible
  • Enterprise delivery and direct SOW scoping
Talent AIIntroductory5h

Academy Course

Hiring AI-Savvy Talent Without Unicorn Hunting

Private offer

Build better reqs, sharper scorecards, and roles the market can fill.

  • Public-safe MDX manuscript and print edition
  • LMS / SCORM add-on compatible
  • Slack / Teams challenge add-on compatible
  • Enterprise delivery and direct SOW scoping

MADE Domain Packages

Focused training packages for Map, Attack, Defend, and Evidence.

Each package includes modules, guided labs, study cards, skill checks, and evidence-writing prompts where implemented. $399 per package — or get all four in Academy Complete at $1,199.

Map Pillar

Map Domain Package

$399

Inventory your AI surface before it becomes an incident.

  • 3 training modules
  • AI asset inventory + provider risk + trust boundary labs
  • Flashcards
  • Skill check
  • Evidence-writing prompts
Buy package

Attack Pillar

Attack Domain Package

$399

Train teams to find AI failures before they reach production.

  • 3 training modules
  • Prompt injection + RAG leak + red team labs
  • Attack scenario cards
  • Flashcards
  • Red-team evidence-writing prompts
Buy package

Defend Pillar

Defend Domain Package

$399

Turn AI security findings into deployable controls.

  • 4 training modules
  • Agent permissions + supply chain + MLOps + data exposure labs
  • Control design exercises
  • Defense evidence-writing prompts
Buy package

Evidence Pillar

Evidence Domain Package

$399

Package AI security work so auditors and governance teams can act on it.

  • 4 training modules
  • Secure SDLC + IR tabletop + governance + boundary review labs
  • Evidence writing exercises
  • Review-safe evidence prompts
Buy package

Academy Complete — $1,199 · All four domain packages. Modules, labs, skill checks, flashcards, and evidence-writing prompts across Map, Attack, Defend, and Evidence.

Buy complete

Delivery Add-Ons

Deploy training where your team actually works.

Add LMS/SCORM setup, Slack or Teams rollout, enterprise onboarding, or evidence review to any Academy or domain package purchase.

LMS / SCORM Setup

$1,500

SCORM/Moodle-ready delivery setup, import guidance, and LMS administrator onboarding.

Inquire

Slack / Teams Rollout

$2,500

Slack or Teams delivery install, pilot workflow, and onboarding contact coordination.

Inquire

Enterprise Onboarding

$5,000

White-glove rollout planning with IT/security contact routing and first cohort support.

Inquire

Evidence Review

$1,500

Validate and polish Academy lab outputs into review-ready AI security evidence summaries.

Inquire

Software & tooling licenses

Use Code Scanner as licensed tooling, or add expert review through Workbench-backed assessments.

AI Security Workbench instruments support assessments, red-team work, hardening, and evidence production. Some tools can be licensed separately; others remain engagement-backed unless scoped as a private deployment.

Direct Product

Scoped after discovery

Use Code Scanner directly inside an AI Security LLC engagement or direct product workflow. Headless execution and machine-readable outputs are supported in the scoped deployment mode.

OEM / White-Label

From $50k

Embed Code Scanner behind your existing scanner, AppSec platform, MSSP workflow, or security product through the OEM Engine. 30-day pilot pilot; partner-controlled UX and reporting; JSON and SARIF outputs.

Enterprise OEM

Custom

Deep white-label licensing, custom naming, report language, packaging, and partner-owned presentation where strategic deployment needs more control than a pilot.

Caveat: Tooling licenses do not include public vulnerability disclosure, CVE assignment, live exploit validation, official marketplace certification, or unlimited consulting support unless separately scoped.

AI Code Mini-Scan

Scoped after discovery

Find the highest-priority code-risk paths in one private repo. Attack Path Analysis summary, SARIF, Markdown, and validation plan. Delivered within 5 business days where scope is complete.

AI Product Security Review Sprint

Scoped after discovery

1 app/package, Code Scanner run, product-readiness report, top blockers, remediation checklist, and one review call.

AI Code Attack Path Analysis

Scoped after discovery

1-2 repos, manual triage, Attack Path Analysis Record, validation plan, candidate disclosure register where applicable, Jira backlog, review-ready evidence package, and readout workshop.

How to choose

What is happening right now?

We do not know where to start

AI Security Program Baseline - Scoped after discovery

We need to map our AI system

AI Product Security Assessment - Scoped after discovery

We are launching an AI feature

AI Launch Security Review - Scoped after triage

We need deeper coverage after launch triage

AI Product Security Assessment - Scoped after discovery

We need abuse validation

AI Red Team & Adversarial Testing - Scoped after discovery

Our agent can take actions

Agentic Workflow Security & Hardening - Scoped after discovery

RAG or tenant data could leak

AI Red Team & Adversarial Testing - Scoped after discovery

Enterprise buyers are blocking deals

AI Security Sales Enablement - Scoped after discovery

Governance is policy, not operations

AI Governance & Security Program Build - Scoped after discovery

We need ongoing support

Time bank, retainer, or phased program - Scoped after discovery

What changes the price?

  • Number of applications or workflows
  • Repository and language breadth
  • Retrieval and data boundaries
  • Agent, tool, identity, and permission complexity
  • Authorized adversarial depth
  • Runtime evidence requirements
  • Partner contract and projection work
  • Remediation and retest support
  • Evidence and audience requirements
  • Deployment or data-boundary requirements

What is included?

  • scoped kickoff
  • evidence request list
  • architecture and product context review
  • system or workflow mapping where relevant
  • findings or gap analysis
  • prioritized recommendations
  • deliverable artifacts
  • readout session
  • follow-up clarification window
  • optional SOW for the next phase

Not included by default

  • certification or audit opinion
  • guarantee that the system is secure
  • full source-code audit
  • production penetration test
  • cloud account hardening across the entire AWS estate
  • formal compliance audit or legal certification
  • SOC 2 / ISO certification
  • official marketplace certification
  • public vulnerability disclosure
  • CVE assignment
  • live exploit validation
  • unlimited retesting
  • unlimited repository scanning
  • production CI deployment
  • remediation implementation
  • incident response
  • managed detection or 24/7 support
  • ongoing vCISO cadence
  • public claim approval by legal counsel
  • production data handling outside the agreed evidence policy

What teams actually scope

Five common engagement patterns with typical price bands.

AI Feature Launch Review

Customer-facing LLM feature: architecture review, trust-boundary map, abuse-path review, control gap assessment, remediation roadmap.

Scoped after triage

RAG & XPIA Security Review

Knowledge workflow: document ingestion and retrieval review, tenant/permission testing, external-content prompt injection testing, RAG authorization review.

Scoped after discovery

Agentic Workflow Security & Hardening

Agent workflow: tool inventory, permission matrix, approval bypass testing, logging/rollback review, hardening backlog.

Scoped after discovery

Enterprise Security Review Evidence Pack

Questionnaire answer bank, model/provider boundary statement, trust-center AI security notes, evidence references, deal-blocker priorities.

Scoped after discovery

AI Security Program Baseline

Inventory model, control ownership, framework crosswalk, evidence lifecycle, release gate, executive roadmap.

Scoped after discovery

AWS-compatible scope

Cloud architecture review, not AWS resale.

Common AWS-compatible surfaces we can review include Amazon Bedrock, Bedrock Agents, Bedrock Knowledge Bases, Bedrock Guardrails, SageMaker, Lambda, API Gateway, S3, KMS, Secrets Manager, IAM, CloudTrail, CloudWatch, OpenSearch, Step Functions, EventBridge, Security Hub, GuardDuty, AWS Config, WAF, DynamoDB, RDS/Aurora, SQS/SNS, and CI/CD integrations where relevant.

Current commercial motion is direct consulting/SOW. Marketplace and private-offer packaging can be scoped when relevant.

Workbench-backed delivery

Instruments support the engagement.

Pricing includes use of Workbench instruments where relevant: Threat Canvas, Application Surface Discovery, Code Scanner, Runtime Trace, Adversarial Range, Authority Graph, RAG Security Testing, AI Control Crosswalk, and Evidence System.

Code Scanner is also available as a separate tooling license for teams that need repeatable, graph-backed code-risk analysis, developer exports, and review-ready evidence. Other Workbench instruments remain engagement-backed unless separately scoped.

Add-ons

Common scope extensions.

Retest package
Buyer questionnaire response support
Trust-center AI security copy
Additional system or workflow review
Additional red-team scenario pack
AWS-compatible architecture deep dive
Agent permission hardening workshop
RAG authorization test extension
Framework mapping add-on: OWASP, NIST AI RMF, MITRE ATLAS, ISO 42001, SOC 2, EU AI Act
Executive or board briefing
Remediation planning workshop
Monthly advisory cadence

FAQ

Commercial questions.

No. The ranges are public so buyers can budget early. The SOW is fixed after scoping the system, evidence needs, testing depth, and delivery timeline.

Yes. The AI Security Scorecard is the no-cost evaluation entry point. The AI Security Program Baseline is the smallest paid entry path and routes into the right next engagement.

The first fit/scoping conversation is free. Paid work starts when there is a scoped benchmark, assessment, sprint, or program SOW.

No. The scorecard is the evaluation step; the paid offer is the AI Security Program Baseline.

Sometimes. If the larger engagement begins immediately and reuses the same evidence request and scope, we can structure the SOW that way.

Yes. Mutual NDA, SOW, DPA when needed, assessment terms, evidence handling, and red-team rules of engagement can be provided.

Yes, as AWS-compatible architecture review and procurement support where relevant.

No. We provide evidence, mappings, findings, and readiness artifacts. Formal certification or audit opinions require the appropriate auditor or legal authority.

Yes. That is part of AI Security Sales Enablement when scoped.

Yes. Retesting can be included or added as a separate package.

Implementation support is not included by default. It can be scoped as hardening, release-gate, or advisory support.

Both. Direct product use can be scoped for direct workflows, and OEM / white-label licensing is available for partner products through the OEM Engine. Workbench-backed assessments and review sprints add expert review, triage, and reporting. Separate private repo delivery, CI integration, and enterprise deployment can be scoped.

No. It helps teams prepare evidence, identify blockers, and remediate AI-native security risks before official marketplace, enterprise buyer, or partner security review.

No. It ranks CVE candidates and can generate disclosure-ready evidence when appropriate, but CVE assignment depends on affected products, validation, vendor coordination, public references, and the appropriate CNA or advisory process.

Start with the smallest defensible scope.

Bring the AI product, workflow, buyer blocker, launch risk, or governance gap. The first scoping step determines which MADE path and pricing lane fits.

Pricing packet

Pricing is now tied to the same commercial packet library.

Self-serve checkout, quote-first services, and invoice-first retainers all attach the relevant contract docs and fulfillment metadata.

Stripe-optimized packet

Payment terms

Prepaid for self-serve items, quote-first for services, and invoice-first for retainers.

Acceptance terms

Accepted on delivery or milestone completion depending on the path.

Fulfillment workflow

pricing -> packet -> checkout or quote -> webhook -> launch room