Every engagement uses the same passive methodology. What changes is the framework the findings map to, and the audience the report is written for.
Passive only — no systems, networks or accounts are accessed at any point.
Assessments are organised by the obligation you carry rather than by technology. If more than one applies, they combine into a single engagement and a single report.
Packages and pricing are set out on the assessment packages page. To scope an engagement against your specific obligations, book a short call.
Every engagement is the same passive methodology. What changes is the framework the findings are mapped to, and the audience the report is written for.
Find the AI you are running, not the AI you declared — exposed model endpoints, MCP servers and shadow deployments, mapped to ISO/IEC 42001.
Independent external exposure evidence mapped clause by clause to the APRA prudential standard — for your Board and internal audit function.
Externally verified evidence against the mitigation strategies that can honestly be assessed from outside — and an explicit statement of those that cannot.
What your organisation exposes, mapped to the Australian Privacy Principles — including tracking, consent sequencing and overseas disclosure.
What your suppliers actually expose, observed from outside without their cooperation. Evidence rather than questionnaires.
For law firms, accountants, conveyancers and agencies now holding seven years of client identity documents under obligations that commenced 1 July 2026.
Every assessment begins from the same place: an independent, evidenced view of what your organisation presents to the outside world. Passive only. Nothing accessed.
Request an Assessment →