Start with the buyer pressure.
Choose the path that matches the decision.
Pick the path that matches the decision in front of you: launch, scanner coverage, program baseline, enterprise security review, team training, or AI security hiring.
AI Launch Security Review
We are launching an AI feature, copilot, RAG system, agent, or workflow soon and need launch-risk clarity fast.
- For:
- Founder, CTO, VP Product, Head of Engineering, Product Security, AppSec owner
- Result:
- First findings in 5 business days. Launch-ready review in 5–10 business days.
- You'll get:
- You'll get a Launch Risk Memo and a go/no-go release gate.
AI Security Sales Enablement
Enterprise buyers are asking AI security questions we cannot answer cleanly, and the deal/security review is slowing down.
- For:
- Founder, CEO, Sales Engineer, Head of Sales, Customer Trust, Security Assurance, GRC
- Result:
- First evidence-gap readout in 5 business days. Buyer-ready pack in 5–10 business days where scope allows.
- You'll get:
- You'll get a buyer-ready evidence summary and an answer bank.
Agentic Workflow Security & Hardening
Agents, tools, credentials, workflows, approvals, and actions have unclear blast radius.
- For:
- AI platform lead, engineering manager, security engineer, automation owner, product owner
- Result:
- First authority map and abuse-path readout in 5 business days. Hardened review plan in 5–10 business days.
- You'll get:
- You'll get a tool permission matrix and an agent authority graph.
No-Cost Scoping Retainer
We may want to move, but vendor onboarding, NDA, finance, SOW, procurement, security review, and internal justification can stall everything.
- For:
- Champion who needs legal, finance, procurement, security, and product aligned before paid work can start.
- Result:
- No-cost scoping packet immediately. Draft review plan after intake. Paid SOW/private offer after scope is clear.
- You'll get:
- You'll get an NDA, a procurement packet, and an internal approval memo.
SecEng Code Scanner OEM Pilot
Your scanner covers web, APIs, and infrastructure. It doesn't cover AI-generated code, LLM apps, or agentic workflows — and customers are starting to ask.
- For:
- Scanner vendor founder, product owner, CTO, head of AppSec product, commercial/partnerships lead
- Result:
- Feasibility Sprint: 2 weeks. 30-Day OEM Pilot: 30 days. White-Label Productization: 8–12 weeks.
- You'll get:
- You'll get a working invocation plan, JSON/SARIF/Markdown output examples, AppCheck-style report mapping, and annual license terms.
Role Readiness / Platform Partner Add-On
Training platforms prove skills but can't answer 'which AI security role is this person ready for' or 'how should our enterprise customers hire for AI security' — leaving practitioners without career direction and corporate buyers without workforce evidence.
- For:
- VP Product, BD lead, or partnerships director at a cybersecurity training platform, cyber range, certification provider, or enterprise L&D company
- Result:
- Pilot validation: 2 weeks. Platform Integration: 4–8 weeks. Strategic License: by negotiation.
- You'll get:
- You'll get a role taxonomy sample, Q&A bank preview, integration architecture spec, and commercial terms.
Pen Test & Red Team Readiness Packet
We want to commission a pen test or red team but don't have the scope definition, authorization documents, ROE, evidence handling plan, or vendor criteria in place yet.
- For:
- Offensive security lead, red team coordinator, AppSec manager, CISO office scoping an external pen test or red team engagement
- Result:
- Readiness packet delivery: 5–10 business days. Engagement-ready authorization: after your legal and technical owners sign off.
- You'll get:
- You'll get a scoped ROE, authorization pack, evidence handling policy, and vendor selection criteria.
AI Security Academy
We need structured AI security training for our teams but have no budget for a custom curriculum build, and off-the-shelf compliance training doesn't cover LLMs, agents, RAG, or AI product security.
- For:
- L&D lead, CISO, security training program manager, HR/enablement director, or team lead at an organization with 50+ security, engineering, product, or governance staff
- Result:
- Team access live within 1–3 business days. LMS package delivery: 2–4 weeks. Private cohort: scheduled by agreement.
- You'll get:
- You'll get course access, a team training plan, manager reports, and an LMS package (by scope).
Readiness packets
Every engagement is a readiness packet
Every serious security engagement starts with the same problem: scope, authorization, access, evidence, and approval. Pick the one closest to your need.
Launch Review Packet
We are launching an AI feature, copilot, RAG system, agent, or workflow soon and need launch-risk clarity fast.
Required to assemble
Target AI feature or workflow · Lifecycle stage · Release pressure · Architecture overview · Evidence available · NDA/SOW path
Likely blockers
Missing staging/demo access · Unclear system prompt / RAG / tool boundaries · No launch owner · No buyer/security evidence owner
Routes to:
Product Security Packet
We need a full architecture, data-flow, trust-boundary, model/provider, RAG, and tenant-isolation review beyond an urgent launch gate.
Buyer Evidence Packet
Enterprise buyers are asking AI security questions we cannot answer cleanly, and the deal/security review is slowing down.
Required to assemble
The buyer questions / questionnaire · Claims needing support · Existing evidence · Trust-center / audience
Likely blockers
No evidence owner · Claims lack scope / date · Unclear what is public-safe
Routes to:
Agent Authority Packet
Agents, tools, credentials, workflows, approvals, and actions have unclear blast radius.
Required to assemble
Agent / tool inventory · Permissions & credentials model · Approval & rollback paths · Logs / audit coverage
Likely blockers
Unclear tool / action blast radius · No rollback path · Missing audit logs
Routes to:
Pentest Readiness Packet
We need a pentest or adversarial test, but scope, authorization, ROE, access, window, evidence, and procurement are not ready.
Required to assemble
Target inventory · Ownership / authorization · ROE · Testing window · Emergency contact · Access plan · Evidence rules
Likely blockers
Third-party target authorization · No testing window · Missing stop contact · Production constraints unresolved
Routes to:
AI Red Team Packet
We need adversarial validation of prompt injection, RAG exposure, tool abuse, tenant leakage, and unsafe autonomy.
Required to assemble
Model / provider / app surface · Prompt / RAG / tool boundaries · Allowed adversarial methods · Prohibited methods · Evidence handling · Human approval points
Likely blockers
Unclear tenant / data boundaries · No safe test data · Tool / action blast radius unclear
Routes to:
RAG Boundary Packet
RAG retrieval, embeddings, ingestion, and tenant boundaries may leak customer or cross-tenant data.
Required to assemble
Source systems · Corpus sensitivity · Tenant boundaries · Retrieval access rules · Eval / logging coverage
Likely blockers
Unclear source ownership · Production customer data present · No retrieval logs / evals
Routes to:
Connector Security Packet
OAuth apps, SaaS connectors, scopes, webhooks, token storage, and connected actions need a least-privilege review.
Required to assemble
Connected apps · OAuth scopes · Read/write actions · Webhook / callback handling · Token storage assumptions · Revocation path
Likely blockers
Excessive OAuth scopes · Unclear admin ownership · Missing revocation process
Routes to:
Enterprise Onboarding Packet
Enterprise SSO/SCIM, RBAC, provisioning, deprovisioning, and auditability are becoming a deal blocker.
Required to assemble
IdP · SSO protocol · SCIM / provisioning · Role / group mapping · Deprovisioning · Audit / logging needs
Likely blockers
No IdP owner · Unclear role model · No test users / groups
Routes to:
Program Build Packet
AI security is scattered policy with no operating model, ownership, controls, evidence, or cadence.
Maturity Scorecard
We do not yet know our AI security gaps or where to invest first.
Secure AI SDLC Packet
AI security is not operationalized in engineering: CI/CD, design review, code review, evals, logging, and release gates.
Required to assemble
Current SDLC / CI-CD · Release process · Eval / test coverage · Design / code review practice
Likely blockers
No release-gate owner · Eval coverage gaps · No logging baseline
Routes to:
Guardrails & Evals Packet
Our guardrails, evals, refusal behavior, and release criteria have unknown coverage and failure modes.
Provider Risk Packet
We need clarity on model/provider data flows, retention, training terms, residency, logging, and fallback risk.
Required to assemble
Providers in use · Data sent to each · Logging approach · Residency requirements
Likely blockers
No DPA from provider · Unclear retention / training terms · No fallback design
Routes to:
Claim-Readiness Packet
We need to control what we can safely say publicly or to buyers after assessment work.
Required to assemble
Intended claim · Audience · Evidence source · Scope / date / limitations · Approval owner · Public-safe summary needs
Likely blockers
Draft evidence treated as final · Claim lacks scope / date · No approval owner
Routes to:
Custom Support Packet
We have a specialized AI security need that does not fit a standard service.
Engagement readiness
Ready to scope is not the same as authorized to test.
Testing starts only after the required SOW, ROE, target list, access path, and testing window are approved.
Technical Scope
Needs inputTechnical owner or security owner
Inputs: Target systems, lifecycle stage, architecture overview, boundaries
Next: Define the in-scope systems and surfaces
Build a packetLegal / NDA / DPA / SOW
Needs inputLegal owner
Inputs: Mutual NDA, DPA if personal/customer data, SOW or no-cost scoping
Next: Start the no-cost scoping / NDA path
Contract packetAccess & Credentials
Needs inputTechnical owner or IT/admin owner
Inputs: Access model, test accounts, secure credential-delivery channel
Next: Plan secure access — never via public forms
Evidence Handling
Needs inputSecurity owner
Inputs: Storage location, redaction, retention, deletion
Next: Confirm evidence storage + retention rules
Evidence Handling PolicyScheduling & Stop Contacts
Needs inputTechnical owner and emergency contact
Inputs: Testing window, blackout dates, stop-testing/emergency contact
Next: Set the window and a reachable stop contact
Procurement / Payment / Private Offer
Needs inputFinance / procurement owner
Inputs: Vendor packet, budget category, PO/payment path, private offer
Next: Request a fixed-fee private offer once scope is clear
Private offersDo not submit secrets, production credentials, access tokens, regulated data, or unredacted customer records through public forms. Credential exchange happens only after NDA/SOW/DPA/ROE through an approved secure channel.
SCOPE planner
Loading the interactive planner.
The planner hydrates in a separate client island so the page can paint faster. If you need to start now, jump to the lighter routing options while the form loads.
Onboarding
Move four tracks in parallel
We put legal, finance, procurement, and technical scoping on parallel rails so the work can start without waiting on every internal process sequentially.
Technical Scoping
Output: Draft Launch Review Plan
- architecture
- demo/staging
- prompts
- RAG
- agents/tools
- authz
- logs/evals
- test boundaries
Legal
Output: NDA + Scoping Authorization
- mutual NDA
- data handling
- authorized testing boundaries
- confidentiality
- work-product terms
Finance / Procurement
Output: Procurement Packet
- vendor profile
- tax/payment details
- budget category
- fixed-fee quote path
- invoice terms
- onboarding answers
Internal Approval
Output: Approval Memo
- why now
- business pressure
- risk if delayed
- expected deliverables
- timeline
- decision needed
Output
Your output: a clear, measurable prescription.
SCOPE delivers a one-page engagement plan you can share and act on immediately.
- Situation & core problem
- Desired outcome & success criteria
- Key risks & assumptions
- Recommended path(s)
- Effort, timing & impact
- Open questions & next step
SCOPE Prescription
Situation
Criteria
Recommended path
Next step
Export as markdown ↗