Binary Rogue

AI exposure assessment

Your insurer is asking which AI tools your staff use.
We produce the answer.

Binary Rogue finds the AI your employees connected to your company without anyone approving it, tests the AI systems you built yourself, and hands you an evidence pack you can forward to an underwriter or a customer's procurement team. Fixed price. Fixed scope. Two weeks.

Fixed price from $2,500 Read-only access NIST AI RMF & OWASP LLM Top 10

Why now

Three people started asking questions you cannot currently answer.

None of them are asking whether you have been breached. They are asking whether you know what is happening — which is a much harder question, and it now has a deadline attached.

01 / THE UNDERWRITER

Your cyber renewal

AI governance questions have moved onto renewal applications, and the answers now affect terms. Carriers have begun attaching AI-specific sublimits and asking for documented risk assessments. A vague answer is the expensive one — it gets priced as unknown risk.

02 / THE CUSTOMER

The security questionnaire

Your biggest prospect's procurement team sent a questionnaire with a new section in it. The deal is now waiting on your answers about AI tool inventory, model governance, and whether staff paste customer data into chatbots.

03 / YOUR BOARD

The question in the meeting

Someone asked what AI the company uses. The honest answer was a list of the tools you pay for — which is not the same list as the tools in use, and everyone in the room knew it.

The technical part

Your firewall did not catch it, and it was never going to.

Most companies assume network monitoring would have found unsanctioned AI use. It does not. An employee using a browser-based AI tool generates ordinary HTTPS traffic to a known SaaS domain — indistinguishable from any other web app your staff are entitled to use. DNS and firewall logs see a domain, not a decision.

The signal that matters is at the identity layer. When someone connects an AI tool to their work account, they generate an OAuth consent event: a durable, timestamped record naming the application, the permissions it was granted, and the person who granted them. Almost nobody looks at it.

What that record often shows

A tool nobody evaluated holding standing read access to a mailbox or a file store, granted in two clicks eighteen months ago by an employee who no longer works there — and still connected today.

How the assessment works

Signals we pull

  • OAuth and enterprise app grants — every third-party application authorized against your identity provider, with the permissions and the person who consented
  • Consent and sign-in audit events — what was authorized, by whom, and when
  • Browser extension inventory — the AI extensions with permission to read every page a user opens, including systems that have no AI in them
  • AI subscription spend — the tools that leave no identity trace because someone expensed them personally
  • Sanctioned AI configuration — what your licensed assistant can actually reach, which is usually more than intended
  • Staff survey — the tools no log will ever show you

Services

Three tiers. Fixed price, fixed scope, stated exclusions.

Hourly billing punishes you for our getting faster. Every engagement is quoted from a scope worksheet before it starts, and the price does not move unless the scope does.

Tier 1

Rogue Scan

Discovery and evidence. Find out what is actually connected.

$2,500
5 business days
  • Full OAuth and enterprise app grant inventory
  • Consent and audit log analysis
  • Browser extension and AI spend review
  • AI Inventory Register — every tool, who authorized it, what it can reach
  • Insurance Evidence Pack
  • No adversarial testing at this tier
What is included
Tier 3

Rogue Watch

Ongoing monitoring, and evidence refreshed before your renewal date.

$750/month
12-month term
  • Quarterly re-scan of grants and audit logs
  • Alerts when a new AI application appears in your tenant
  • Annual re-test of your AI surfaces
  • Evidence pack refreshed 45 days before renewal, unprompted
  • Named contact for AI security questions
What is included

The deliverable

Nobody buys a PDF. They buy the ability to answer the question.

AI Inventory Register

One row per tool: what it is, who authorized it, when, what data it can reach, sanctioned or not, and a risk tier. This is the artifact your underwriter means when they ask whether you maintain an AI inventory.

Insurance & questionnaire evidence pack

The standard AI questions from cyber renewal applications and customer security questionnaires, answered, each with a reference to the evidence behind it. Built to be forwarded without editing.

30/60/90 remediation roadmap

Sequenced by effort against impact, not severity alone. The one-hour configuration change that closes an entire class of exposure comes before the three-month project, every time.

What this is not

Binary Rogue is not a law firm and does not issue compliance opinions or certifications. An assessment is point-in-time, performed within an agreed scope under written authorization, and is never represented as comprehensive. What was not tested is stated explicitly in every report — which is precisely what makes the rest of it credible to a third party.

Fit

Who this is for

  • 25–500 employees, running Microsoft 365 or Google Workspace
  • Carrying cyber insurance — which means you have a renewal date and a broker
  • Selling to enterprise customers, or operating in a regulated vertical
  • Healthcare, financial services, legal, professional services — where confidentiality is contractual and the documentation habit already exists

Fit

Who this is not for

  • Companies wanting a certification. ISO 42001 is a different engagement with a different timeline; we will refer you.
  • Companies wanting someone to implement AI. We assess and test. We do not build.
  • Companies wanting a legal opinion on regulatory compliance. We flag exposure and recommend counsel.
  • Companies wanting a clean bill of health more than they want the findings.

Start here

Find out where you stand in three minutes.

Twelve questions, no email required to see your result. You get an exposure score, a breakdown across the four areas an assessment covers, and a plain view of how you would currently answer the questions your underwriter is going to ask.