One-page posture report
The five basics plus AI data flows, each rated with the evidence beside it. Written to answer the insurer's questionnaire line by line.
Is MFA on everywhere. Is there a password manager. Are devices protected. Does your email prove it's you. Has the team been trained. Then the sixth question nobody's insurer asks yet: which AI tools can see your data, and under what terms. Two weeks, evidence-backed, and a report you can hand to the insurer and the board.
CAD 3,500, fixed.
Credited against Protected Workplace or the retainer if you go ahead within 60 days.
Two weeks. Read-only. Nothing is changed
until you say so.
Each lens is scored with the evidence beside it. Nothing in the report is an opinion without a screenshot, an export or an interview behind it.
MFA coverage by account, shared passwords, who still has access that shouldn't, admin sprawl.
Every laptop and phone that touches organization data: known or unknown, encrypted or not, wipeable or not.
SPF, DKIM and DMARC as they actually are, who can send as you, and what a spoof would look like.
Which AI tools your people use, personal and approved, what gets pasted where, and what the vendor terms say about training and residency.
Whether a separate copy exists, how long it's kept, and whether anyone has ever restored from it.
Phishing exposure tested with your real scenarios, and who reports versus who clicks.
Delivered in a 60-minute walkthrough with the owner, then yours to keep.
The five basics plus AI data flows, each rated with the evidence beside it. Written to answer the insurer's questionnaire line by line.
Every AI tool in use, approved or not, what data it can see, and what the terms allow. Usually the page that changes the meeting.
What to switch on this week with licences you already own, what needs a decision, and what can wait. Most of it maps to Protected Workplace and Backups.
You can stop after the report and keep everything. Most organizations don't, because the fix list is already written.
Read-only access to your tenant, a device inventory, a phishing simulation with your scenarios, and the AI-tool survey. Nothing is changed.
Posture report, AI exposure map and the ranked fix list. A 60-minute walkthrough with the owner, and the insurer version if you want it.
Protected Workplace and Backups for the basics; AI, Switched On Properly for the AI side. Or your own IT team, with the list.
Credited against Protected Workplace or the retainer if you go ahead within 60 days.
Book the assessmentThe things owners ask us on the first call.
Because you signed a questionnaire. If a claim is investigated and a 'yes' wasn't true, it can be denied. This produces the evidence behind each yes, dated.
Most security reviews stop at devices and passwords. This one maps which AI tools your people actually use, what data they paste in, and what the vendor terms permit. In most organizations it's the biggest exposure nobody has written down.
No. Access is read-only, the device inventory is passive, and the phishing test is a few emails. Two weeks, mostly invisible.
No. The fix list is written so any competent IT provider can run it. If you do go ahead with us within 60 days, the fee is credited.
Book the assessment. Two weeks, read-only, a report you can hand to the insurer and the board.
Book a 30-minute callA conversation about your organization.
Not a demo of software.