Service · LAUNCH
AI Launch Security Review
Know what must be fixed, accepted, or evidenced before launch.
Decision answered
What must be fixed, accepted, or evidenced before this AI feature ships?
Duration
Typical duration: 5–10 business days; first findings targeted within 5 business days.
Primary output
AI Launch Risk Memo and release-condition checklist
Best for
Teams preparing a selected AI feature, system, workflow, or release boundary for launch.
Engagement type
Bounded pre-release review
What is in scope
- Selected AI feature or release boundary
- Material architecture and data flows
- Relevant retrieval, agent, tool, and permission paths
- Launch-impacting controls
- Release decision and evidence needs
Inputs needed
- Defined release boundary
- Architecture and change context
- Authorized test access and representative fixtures
- Current controls and known issues
What the work actually does
- Launch risk report
- Prioritized fix list
- Release decision pack
- Buyer-ready evidence
What the work delivers
- System Boundary Record
- AI Launch Risk Memo
- Launch-impacting Finding and Observation Set
- Prioritized fix and acceptance list
- Release-condition checklist
Evidence produced
- Bounded system observations
- Reproduced launch-impacting behavior
- Release decisions and owners
- Retest conditions
Boundary
What this engagement does not establish
- A certification
- A universal security assessment
- A guarantee of absence of vulnerabilities
- A substitute for ongoing product-security ownership
After the engagement
Fix, accept, or evidence the launch-impacting items; retest changed conditions; and expand into a deeper AI Product Security Assessment where the release boundary warrants it.
Optional deliverables: Retest Record, Buyer evidence summary. Selected according to engagement scope.
Supporting Workbench capabilities
Selected according to scope.
The engagement outcome and evidence are the deliverable. These AI Security Workbench capabilities support the work where they add value; their presence here does not mean every engagement uses all of them.
Threat Canvas
Frame the selected release boundary and material abuse hypotheses.
Application Surface Discovery
Identify relevant AI components and integrations within the bounded release.
Code Scanner
Produce code-derived observations where source is authorized and in scope.
Evidence System
Preserve findings, release decisions, remediation, and retest state.
Relevant research
Delivery / subject-matter leads
Delivery leads are confirmed during scoping.
Adjacent services
Choose by the decision you need to make.
ASSESS
AI Product Security Assessment
What are the material security paths, control gaps, and remediation priorities across this AI product?
BASELINE
Expert-Led AI Security Program Baseline
Where should the AI security program start, and which ownership, control, and evidence gaps need priority work?
SELL
AI Security Sales Enablement
What AI security claims can the company safely make, and what evidence can support buyer review?