Services
Fixed price. Fixed scope.
The exclusions in writing.
Three tiers, designed to be walked in order. A Scan tells you what is there. An Audit tests it and tells you what to do. Watch keeps the answer true after we leave.
Rogue Scan
Discovery and evidence. No adversarial testing.
- Full OAuth and enterprise application grant inventory across Microsoft Entra ID and Google Workspace
- Audit log analysis for AI tool authentication and consent events
- Browser extension inventory via your existing RMM or endpoint management
- Egress log review where a secure web gateway exists
- AI-related subscription spend review
- Sanctioned AI configuration check — Copilot or Gemini data boundary settings
- AI Inventory Register — every tool found, who authorized it, when, what data it can reach, sanctioned or not, risk tier
- Insurance Evidence Pack — the standard underwriter AI questions, answered, with evidence references
- 30-minute findings walkthrough
- Excluded: adversarial testing, policy drafting, remediation work, governance framework mapping
Rogue Audit
Discovery, adversarial testing, governance analysis, roadmap.
- Everything in Rogue Scan
- Adversarial testing of AI systems you operate — direct and indirect prompt injection, system prompt extraction, data leakage and cross-user boundary testing, RAG authorization boundaries, guardrail bypass, and tool-calling abuse where agentic capability exists
- Findings mapped to the OWASP Top 10 for LLM Applications
- Governance gap analysis against the NIST AI Risk Management Framework — Govern, Map, Measure, Manage
- AI acceptable use policy reviewed, or a starter policy written where none exists
- AI vendor and subprocessor review — data processing terms, training on customer data, retention
- Identity and consent controls review — who in your tenant can authorize a new AI application
- Prioritized 30/60/90 remediation roadmap with effort and owner per item
- Full evidence pack for insurance and procurement
- 60–90 minute live readout for your stakeholders
Rogue Watch
Ongoing monitoring, maintenance, and renewal-time evidence.
- Quarterly re-scan of OAuth grants and audit logs
- New AI tool alerts — notification when a previously unseen AI application appears in your tenant
- Annual re-test of AI surfaces for Audit clients
- AI policy maintenance as your tooling changes
- Refreshed evidence pack delivered 45 days before your insurance renewal, without you asking
- Quarterly 30-minute check-in
- A named contact for AI security questions as they come up
Pricing
What moves the price, and what does not.
Three variables matter: how many people you have, how many identity platforms you run, and how many AI systems you operate yourself. Everything else is noise, and we do not price on it.
| Condition | Adjustment to Rogue Audit |
|---|---|
| Under 50 employees, single identity platform, no AI systems of your own | −$1,500 |
| Two or more identity platforms — Microsoft 365 and Google, or post-acquisition | +$1,000 |
| Each AI system you operate beyond the first | +$1,000–2,000 |
| An agentic system with tool-calling or write access to business systems | +$2,000 minimum |
| 250+ employees | +$2,000 |
| Regulated vertical requiring specific framework mapping | +$1,000 |
Then there is nothing for the adversarial phase to test, and what you actually need is a governance audit — which we price at $4,000–4,500, not $6,500. We would rather tell you that on the first call than sell you a tier and quietly deliver a smaller one.
Terms
Payment
50% on signature, 50% on delivery of the report. Rogue Watch is billed monthly in advance.
Before work starts
A signed authorization letter and rules of engagement, and the deposit cleared. Both, every time, without exception.
The clock
The delivery timeline starts when read-only access is confirmed working — not at signature. Access is the most common cause of a slipped date and it sits on your side.
Not sure which tier you need?
The self-check takes three minutes and tells you honestly. If a Scan is enough, we will say so.