NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

AI Security Pricing

Pricing ranges for AI security reviews, testing, and hardening

Use these published ranges to estimate scope before formal scoping. Final pricing depends on system complexity, access level, testing depth, timeline, and evidence needs.

NDA, DPA, SOW, rules of engagement, evidence handling, and subprocessors available through the Trust Center.

AI Launch Security Review

Scoped after triage · fixed-fee where possible

5–10 business days

Product teams shipping an AI feature, copilot, RAG system, agent, or workflow in the next 30–60 days. First findings in 5 business days. Typical budget: launch, AppSec, product security, red team, customer assurance, or security review.

Primary services

AI Launch Security Review

Common deliverables

Launch Risk Memo, Graph-Backed Abuse Paths, Release Gate Checklist, Defense Breakpoint Fix Backlog

Scope a Launch Review

Diagnostic / MAP Entry

$5k-$15k

1-2 weeks

Teams that need a fast baseline before assessment, red-team, hardening, governance, or buyer review work.

Primary services

AI Security Program Scorecard

Common deliverables

AI Security Maturity Scorecard, AI surface inventory, Control Coverage Snapshot, Evidence-gap register

Open the AI Security Program Scorecard

AI Product Security Assessment

$15k-$35k

2-4 weeks

A deeper follow-on assessment for broader architecture, trust-boundary, RAG, agent, tenant-isolation, product-security, and evidence coverage after launch triage or when the product surface is already larger than a focused launch review.

Primary services

AI Product Security Assessment, AI Guardrails & Evals Review, AI Security Sales Enablement

Common deliverables

AI system inventory, Architecture and trust-boundary review, Abuse-path review, Control gap assessment

Start focused assessment

Adversarial Testing & Hardening

$30k-$75k

3-6 weeks

Teams that need reproducible abuse validation, RAG/XPIA testing, agent action testing, guardrail/eval validation, retesting, or post-assessment hardening.

Primary services

AI Red Teaming, RAG & XPIA Security Review, Agentic Workflow Hardening, AI Guardrails & Evals Review

Common deliverables

Red-team scope and test plan, Findings register with reproduction evidence, Agent permission matrix, RAG authorization review

Request adversarial testing

Program, Governance & Evidence

$50k-$150k+

4-12 weeks or retained

Teams that need an AI security operating model, release gates, control ownership, evidence cadence, trust-center support, or a follow-on Program Buildout module after the scorecard.

Primary services

AI Security Program Scorecard, AI Security Sales Enablement, AI Product Security Assessment

Common deliverables

AI governance operating model, Control ownership matrix, Evidence pack, Control crosswalk

Build governance and evidence program

Flexible Expert Support

Flexible expert support for scoped AI security work.

Time banks are prepaid AI security engineering hours for advisory, review, remediation planning, evidence review, red-team support, governance support, and follow-up after an assessment. They are not a substitute for a scoped assessment when rules of engagement, testing depth, or formal deliverables are required.

Most popular

TIME BANK · Team

25hours

$4,975

$199/hr

  • No expiry
  • Any service
  • Priority scheduling
  • Monthly summary
Buy Team time bank

TIME BANK · Program

50hours

$8,950

$179/hr

  • No expiry
  • Any service
  • Dedicated architect
  • Quarterly review
Buy Program time bank

Hours never expire. Transferable within your org. Hours are tracked per session with a running balance in your client portal. Explore engagement options

Academy training

Practical AI product security training built around MADE.

Academy plans provide access to field-guide lessons, labs, study cards, skill checks, and role-based training paths for teams learning how to map, test, harden, and evidence AI systems. Or purchase individual labs and domain packages at /pricing/academy-lab-access.

AI SECURITY ACADEMY · ACCESS

Weekly

$9/week

  • Full academy access — all 14 labs
  • Reference desk + study cards
  • Skill-check progress
  • Lab summaries

Auto-renews weekly · Single seat

View plan

Most popular

AI SECURITY ACADEMY · ACCESS

Monthly

$25/month

  • Full academy access — all 14 labs
  • Reference desk + study cards
  • Skill-check progress
  • Lab summaries
  • Cancel anytime

Auto-renews monthly · Single seat

View plan

AI SECURITY ACADEMY · ACCESS

Annual

$150/year

  • Full academy access — all 14 labs
  • Priority scheduling
  • Reference desk + study cards
  • Skill-check progress
  • Lab summaries

Equivalent to $12.50/mo · Auto-renews annually · Single seat

View plan

Academy training does not certify an organization’s AI system as secure and does not replace assessment, red-team testing, or audit work. Team plans (10 seats) from $499/month or $4,990/year. Enterprise (50 seats) at $19,900/year. View all plans

Enterprise course

Role-based enterprise courses

Private-offer courses for the people who build, test, sell, govern, and operate AI products. Each includes a public-safe manuscript, print edition, and enterprise delivery path.

Defendintermediate6h

Academy Course

Secure Coding with GenAI

Private offer

Build, review, test, and ship AI-assisted code safely.

  • Public-safe MDX manuscript and print edition
  • LMS / SCORM add-on compatible
  • Slack / Teams challenge add-on compatible
  • Enterprise delivery and direct SOW scoping
Evidenceintroductory5h

Academy Course

AI Security for Sales Engineers

Private offer

Speak clearly about AI risk, controls, and buyer trust.

  • Public-safe MDX manuscript and print edition
  • LMS / SCORM add-on compatible
  • Slack / Teams challenge add-on compatible
  • Enterprise delivery and direct SOW scoping
Attackintermediate6h

Academy Course

AI Red Teaming for Product Teams

Private offer

Test LLM, RAG, and agentic systems before users and attackers do.

  • Public-safe MDX manuscript and print edition
  • LMS / SCORM add-on compatible
  • Slack / Teams challenge add-on compatible
  • Enterprise delivery and direct SOW scoping
Mapintroductory5h

Academy Course

AI Product Management for Secure AI Features

Private offer

Define, scope, and ship AI products buyers can trust.

  • Public-safe MDX manuscript and print edition
  • LMS / SCORM add-on compatible
  • Slack / Teams challenge add-on compatible
  • Enterprise delivery and direct SOW scoping
Defendintermediate6h

Academy Course

AI Model Gateways and Secure Platforms

Private offer

Build the approved path for safe AI adoption.

  • Public-safe MDX manuscript and print edition
  • LMS / SCORM add-on compatible
  • Slack / Teams challenge add-on compatible
  • Enterprise delivery and direct SOW scoping
Talent AIIntroductory5h

Academy Course

Hiring AI-Savvy Talent Without Unicorn Hunting

Private offer

Build better reqs, sharper scorecards, and roles the market can fill.

  • Public-safe MDX manuscript and print edition
  • LMS / SCORM add-on compatible
  • Slack / Teams challenge add-on compatible
  • Enterprise delivery and direct SOW scoping

MADE Domain Packages

Focused training packages for Map, Attack, Defend, and Evidence.

Each package includes modules, guided labs, study cards, skill checks, and evidence-writing prompts where implemented. $399 per package — or get all four in Academy Complete at $1,199.

Map Pillar

Map Domain Package

$399

Inventory your AI surface before it becomes an incident.

  • 3 training modules
  • AI asset inventory + provider risk + trust boundary labs
  • Flashcards
  • Skill check
  • Evidence-writing prompts
Buy package

Attack Pillar

Attack Domain Package

$399

Train teams to find AI failures before they reach production.

  • 3 training modules
  • Prompt injection + RAG leak + red team labs
  • Attack scenario cards
  • Flashcards
  • Red-team evidence-writing prompts
Buy package

Defend Pillar

Defend Domain Package

$399

Turn AI security findings into deployable controls.

  • 4 training modules
  • Agent permissions + supply chain + MLOps + data exposure labs
  • Control design exercises
  • Defense evidence-writing prompts
Buy package

Evidence Pillar

Evidence Domain Package

$399

Package AI security work so auditors and governance teams can act on it.

  • 4 training modules
  • Secure SDLC + IR tabletop + governance + boundary review labs
  • Evidence writing exercises
  • Review-safe evidence prompts
Buy package

Academy Complete — $1,199 · All four domain packages. Modules, labs, skill checks, flashcards, and evidence-writing prompts across Map, Attack, Defend, and Evidence.

Buy complete

Delivery Add-Ons

Deploy training where your team actually works.

Add LMS/SCORM setup, Slack or Teams rollout, enterprise onboarding, or evidence review to any Academy or domain package purchase.

LMS / SCORM Setup

$1,500

SCORM/Moodle-ready delivery setup, import guidance, and LMS administrator onboarding.

Inquire

Slack / Teams Rollout

$2,500

Slack or Teams delivery install, pilot workflow, and onboarding contact coordination.

Inquire

Enterprise Onboarding

$5,000

White-glove rollout planning with IT/security contact routing and first cohort support.

Inquire

Evidence Review

$1,500

Validate and polish Academy lab outputs into review-ready AI security evidence summaries.

Inquire

Software & tooling licenses

Use SecEng Code Scanner as licensed tooling, or add expert review through Workbench-backed assessments.

SecEng Workbench instruments support assessments, red-team work, hardening, and evidence production. Some tools can be licensed separately; others remain engagement-backed unless scoped as a private deployment.

Starter

$199/mo

1 private repo, up to 250k LOC, monthly scans, AI attack-path report, MCP/RAG/tool/browser-agent rulepacks, SARIF and Markdown exports.

Team

$599/mo

3 private repos, up to 1M LOC, weekly scans, SARIF + VS Code diagnostics, Jira ticket JSON, developer export, control matrix, safe validation plans, baseline/suppression.

Product / Partner Review

$1,299/mo

5 private apps/repos/packages, product-readiness reports, partner and security review evidence mapping, submission blocker report, white-labeled evidence package, Jira backlog, candidate disclosure triage, variant and patch-diff checks.

Agency / White Label

$2,999/mo

15 apps/repos/packages, white-label client reports, custom branding, validation templates, multi-client workspace assumptions, priority support, redistribution rights inside client engagements.

Enterprise

From $12k/year

Private repo/license delivery, local/on-prem execution, CI integration, custom rules, custom policy packs, support, and private deployment options.

Caveat: Tooling licenses do not include public vulnerability disclosure, CVE assignment, live exploit validation, official marketplace certification, or unlimited consulting support unless separately scoped.

AI Code Mini-Scan

$499 one-time

Find the top AI attack paths in one private repo. Attack-path report, SARIF, Markdown, and validation plan. Delivered within 5 business days where scope is complete.

AI Product Security Review Sprint

$5k fixed

1 app/package, Code Scanner run, product-readiness report, top blockers, remediation checklist, and one review call.

AI Code Attack-Path Assessment

$10k-$25k

1-2 repos, manual triage, attack-path report, validation plan, candidate disclosure register where applicable, Jira backlog, review-ready evidence package, and readout workshop.

How to choose

What is happening right now?

We do not know where to start

AI Security Program Scorecard - $5k-$15k

We need to map our AI system

MAP Review / Product Security Assessment - Scoped

We are launching an AI feature

AI Launch Security Review - $8k-$15k

We need deeper coverage after launch triage

AI Product Security Assessment - $15k-$35k

We need abuse validation

Adversarial Testing & Hardening - $30k-$75k

Our agent can take actions

Agentic Workflow Hardening - $20k-$75k

RAG or tenant data could leak

RAG & XPIA Security Review - $20k-$45k

Enterprise buyers are blocking deals

AI Security Sales Enablement - $15k-$50k

Governance is policy, not operations

Program Buildout follow-on - $50k-$150k+

We need ongoing support

Time bank, retainer, or phased program - Scoped after benchmark or assessment

What changes the price?

  • number of AI systems, workflows, agents, RAG paths, model gateways, or repositories in scope
  • number of tenants, data classes, identities, tools, and external integrations reviewed
  • depth of source-code, architecture, runtime, log, and evidence access
  • testing depth, adversarial scenarios, retesting, and rules of engagement
  • whether remediation planning or implementation support is included
  • evidence requirements for buyers, auditors, governance, executives, or legal
  • framework mapping requirements: OWASP LLM Top 10, NIST AI RMF, MITRE ATLAS, ISO 42001/AIMS, SOC 2, EU AI Act, or internal policy
  • delivery urgency, stakeholder count, workshops, and procurement/legal needs
  • private tooling, CI, SARIF, VS Code, Jira, Confluence, or local/on-prem deployment needs
  • disclosure, CVE candidate, or public advisory support if explicitly scoped

What is included?

  • scoped kickoff
  • evidence request list
  • architecture and product context review
  • system or workflow mapping where relevant
  • findings or gap analysis
  • prioritized recommendations
  • deliverable artifacts
  • readout session
  • follow-up clarification window
  • optional SOW for the next phase

Not included by default

  • certification or audit opinion
  • guarantee that the system is secure
  • full source-code audit
  • production penetration test
  • cloud account hardening across the entire AWS estate
  • formal compliance audit or legal certification
  • SOC 2 / ISO certification
  • official marketplace certification
  • public vulnerability disclosure
  • CVE assignment
  • live exploit validation
  • unlimited retesting
  • unlimited repository scanning
  • production CI deployment
  • remediation implementation
  • incident response
  • managed detection or 24/7 support
  • ongoing vCISO cadence
  • public claim approval by legal counsel
  • production data handling outside the agreed evidence policy

What teams actually scope

Five common engagement patterns with typical price bands.

AI Feature Launch Review

Customer-facing LLM feature: architecture review, trust-boundary map, abuse-path review, control gap assessment, remediation roadmap.

$8k-$15k

RAG & XPIA Security Review

Knowledge workflow: document ingestion and retrieval review, tenant/permission testing, external-content prompt injection testing, RAG authorization review.

$10k-$25k

Agentic Workflow Hardening

Agent workflow: tool inventory, permission matrix, approval bypass testing, logging/rollback review, hardening backlog.

$15k-$40k

Enterprise Security Review Evidence Pack

Questionnaire answer bank, model/provider boundary statement, trust-center AI security notes, evidence references, deal-blocker priorities.

$10k-$22k

AI Security Program Scorecard

Inventory model, control ownership, framework crosswalk, evidence lifecycle, release gate, executive roadmap.

$25k-$75k+

AWS-compatible scope

Cloud architecture review, not AWS resale.

Common AWS-compatible surfaces we can review include Amazon Bedrock, Bedrock Agents, Bedrock Knowledge Bases, Bedrock Guardrails, SageMaker, Lambda, API Gateway, S3, KMS, Secrets Manager, IAM, CloudTrail, CloudWatch, OpenSearch, Step Functions, EventBridge, Security Hub, GuardDuty, AWS Config, WAF, DynamoDB, RDS/Aurora, SQS/SNS, and CI/CD integrations where relevant.

Current commercial motion is direct consulting/SOW. Marketplace and private-offer packaging can be scoped when relevant.

Workbench-backed delivery

Instruments support the engagement.

Pricing includes use of Workbench instruments where relevant: SecEng Threat Canvas, SecEng Surface Scanner, SecEng Code Scanner, SecEng Runtime Proxy, SecEng Adversarial Range, SecEng Authority Graph, SecEng RAG Test Harness, AI Control Crosswalk, and Evidence Library.

SecEng Code Scanner is also available as a separate tooling license for teams that need repeatable graph-backed AI SAST, developer exports, and review-ready evidence. Other Workbench instruments remain engagement-backed unless separately scoped.

Add-ons

Common scope extensions.

Retest package
Buyer questionnaire response support
Trust-center AI security copy
Additional system or workflow review
Additional red-team scenario pack
AWS-compatible architecture deep dive
Agent permission hardening workshop
RAG authorization test extension
Framework mapping add-on: OWASP, NIST AI RMF, MITRE ATLAS, ISO 42001, SOC 2, EU AI Act
Executive or board briefing
Remediation planning workshop
Monthly advisory cadence

FAQ

Commercial questions.

No. The ranges are public so buyers can budget early. The SOW is fixed after scoping the system, evidence needs, testing depth, and delivery timeline.

Yes. The AI Security Program Scorecard is the smallest paid entry path and is designed to route into the right next engagement.

The first fit/scoping conversation is free. Paid work starts when there is a scoped benchmark, assessment, sprint, or program SOW.

Yes. The scorecard is a paid artifact, not a generic sales call.

Sometimes. If the larger engagement begins immediately and reuses the same evidence request and scope, we can structure the SOW that way.

Yes. Mutual NDA, SOW, DPA when needed, assessment terms, evidence handling, and red-team rules of engagement can be provided.

Yes, as AWS-compatible architecture review and procurement support where relevant.

No. We provide evidence, mappings, findings, and readiness artifacts. Formal certification or audit opinions require the appropriate auditor or legal authority.

Yes. That is part of AI Security Sales Enablement when scoped.

Yes. Retesting can be included or added as a separate package.

Implementation support is not included by default. It can be scoped as hardening, release-gate, or advisory support.

Both. Starter, Team, Product/Partner Review, Agency, and Enterprise are tooling licenses. Workbench-backed assessments and review sprints add expert review, triage, and reporting. Separate private repo delivery, CI integration, and enterprise deployment can be scoped.

No. It helps teams prepare evidence, identify blockers, and remediate AI-native security risks before official marketplace, enterprise buyer, or partner security review.

No. It ranks CVE candidates and can generate disclosure-ready evidence when appropriate, but CVE assignment depends on affected products, validation, vendor coordination, public references, and the appropriate CNA or advisory process.

Start with the smallest defensible scope.

Bring the AI product, workflow, buyer blocker, launch risk, or governance gap. The first scoping step determines which MADE path and pricing lane fits.

Pricing packet

Pricing is now tied to the same commercial packet library.

Self-serve checkout, quote-first services, and invoice-first retainers all attach the relevant contract docs and fulfillment metadata.

Stripe-optimized packet

Payment terms

Prepaid for self-serve items, quote-first for services, and invoice-first for retainers.

Acceptance terms

Accepted on delivery or milestone completion depending on the path.

Fulfillment workflow

pricing -> packet -> checkout or quote -> webhook -> launch room