Audit
  • Free
  • 5-day turnaround
  • No software installed
  • No engineering time

Your teams are already running AI.
Can you prove what it touched?

Shadow tools and autonomous agents are moving company data across your business right now, often with no logging, no oversight, and no audit trail. The AI Exposure Audit shows you exactly what is running, what it can reach, and where the record stops.

Built for teams whose security review is the hard part.

Confidential. No obligation. The report is yours to keep either way.

Exposure

Most organisations cannot answer three questions
about their own AI.

87%

of the 100+ companies we surveyed had no formal AI governance procedure: no approved tool list, no owner, and no audit trail of what their own teams were doing with company data.

Aisty Shadow AI survey, 2026
  1. 01

    What AI tools are our people actually using?

    Sanctioned platforms are only half the picture. The other half is shadow usage nobody approved and nobody is tracking.

  2. 02

    What can those tools reach?

    Every tool connected to a mailbox, a repo, or a ledger is a path your data can travel. Most teams have never mapped it.

  3. 03

    If something went wrong, could we show what the AI did?

    A chat history is not an audit trail. When a regulator, a board, or an incident review asks you to prove it, most organisations cannot.

Every prompt sent to a shared model may train its next version. Every ungoverned agent is a data exfiltration path waiting for a prompt-injection attack. And none of it shows up until it is a problem you are explaining after the fact.

Deliverable

A written report you can put in front of your security team, your board, or your regulator.

At the end of the audit you receive the AI Exposure Report: a clear, vendor-neutral picture of your organisation's AI footprint and where it is exposed.

  1. 01

    AI Inventory

    Every AI tool and agent in use across the organisation, sanctioned and shadow.

  2. 02

    Data Access Map

    What each tool can reach: mailboxes, repositories, CRM, ledgers, customer data.

  3. 03

    Audit Gap Analysis

    Where AI is acting with no retrievable record of what it did.

  4. 04

    Risk Findings

    Prioritised: data leaving to public models, prompt-injection exposure, and compliance exposure against the EU AI Act, ISO 27001, and your sector’s own requirements.

  5. 05

    Remediation Priorities

    What to fix first, ranked by risk. Written to be actionable whether or not you ever work with us.

Process

Three steps. Around five days.
About two hours of your team's time.

  1. Step 01

    Scoping call

    30 minutes

    You tell us your stack, your concerns, and who to talk to. We agree scope and sign an NDA before anything begins.

  2. Step 02

    The review

    2 to 3 days

    Short sessions with your IT and engineering leads, plus a review of the tools in use. We install nothing and touch none of your production systems. This is an assessment, not a deployment.

  3. Step 03

    The report

    Walkthrough and written deliverable

    We walk you and your team through the findings, then hand over the written Exposure Report. Yours to keep and share internally, with no obligation to go further.

Terms

No install. No obligation.
No exposure created by the audit itself.

  • Free. No cost, no card, no catch.
  • Nothing installed. We do not connect to your systems or touch production. The audit creates no new risk.
  • Around two hours. Two hours of your team’s time in total. Not a project, and not a rollout.
  • Confidential. NDA up front. Findings are shared only with you.
  • No obligation. The report is yours whether or not we ever speak again.
Who it is for

The Exposure Audit is designed for regulated and security-first organisations: teams where AI adoption has outrun oversight and the security review is the hard part. Financial services, healthcare, legal, and any organisation accountable for where its data goes. If your AI usage would struggle to survive a regulator asking you to prove it, this is for you.

Request

Find out what your AI is doing before someone else asks you to prove it.

One screen, under a minute. Your answers scope the audit, so the report speaks to your stack rather than a generic one.

Company size
Industry
Your role
Timeline

We reply within one business day to book your 30-minute scoping call. Confidential, and no obligation.

Questions

Before you ask

Request your Exposure Audit

Free. Five-day turnaround. Confidential. No obligation.