The audit we run
before anything ships.

The message came in on a live chatbot — a working site, real customer data behind it. Someone was probing it with injection attempts, trying to make it execute code and leak what it knew.
It refused, logged the attempt, and flagged it. Every check it hit was designed months earlier, before launch, when the system was still a diagram.
We didn't get lucky. We'd assumed someone would try — that assumption is what we sell.
The rules landed on 2 August 2026.
The EU AI Act's high-risk obligations are in force: risk management, data governance, logging, human oversight, post-deployment monitoring.
Most small B2B teams aren't high-risk. Proving which side you're on takes thirty minutes, and it's the first thing we do.
What we check.
Data exposure
What it sees that you didn't intend.
Prompt injection
Can it be talked into ignoring you.
Human oversight gaps
Decisions with nobody's name on them.
Failure modes
What it does on its worst day.
Logging and audit trail
Can you reconstruct what happened.
Data consent
Are you allowed to feed it that.
Compliance
Can you prove it to an auditor.
Model selection
Is your model defensible.
A demo and a production system are not the same thing.
A demo
In production
Works on the path someone planned.
Handles the inputs nobody thought of.
Fails quietly.
Fails loudly, with an alert attached.
Impressive in a meeting.
Boring on purpose.
What you get.
Risk assessment report
Remediation roadmap
Governance framework
Two weeks, fixed scope, priced as a project.
How we build everything.
Data flows are mapped before anything is connected.
Sign-off on anything high-stakes stays with your team.
If we find something uncomfortable, it goes in the report anyway.