Assessment
How ready is your AI estate, actually?
24 questions against the eight domains and four exit gates of the AI Security Control Model. About four minutes. Your results appear on screen — nothing is gated behind an email.
AI Asset & Posture Management
Plan & Discover · Gate ACan you produce a current list of every model, agent and MCP server running in production, each with a named owner?
Is that inventory generated from your cloud and code, rather than maintained by hand in a spreadsheet?
Would you detect an AI system that reached production without going through your approval process?
Identity & Access for Agents
Plan & Discover · Gate ADo agents authenticate with short-lived workload identity rather than static keys or long-lived tokens?
Is each agent's tool access scoped to a named least-privilege set, rather than inherited from a shared service account?
Can you answer “what could this agent reach if it were fully compromised?” for any agent in production?
Development Security & AI App Testing
Build & Develop · Gate BDoes a pull request that adds an AI tool or MCP server get a security check before it can merge?
Do you test AI applications against prompt injection and tool poisoning before release?
Do those tests run against a versioned corpus of attack payloads, with a measured detection rate?
Runtime Protection & Interaction Security
Build & Develop · Gate BIs there a control point that every agent tool call passes through?
Can you block an agent action at runtime based on policy, not just observe it afterwards?
Are high-risk or irreversible agent actions gated on human approval?
Data Security for AI
Deploy & Operate · Gate CIs data classified before it reaches a model, rather than after an incident?
Could you determine whether regulated data has passed through a given model or agent?
Are retrieval corpora access-controlled per end user, rather than per application?
Model Security & Supply Chain
Deploy & Operate · Gate CDo you verify the provenance of models, adapters and third-party tools before they are used?
Do you hold a bill of materials for each deployed AI system — base model, datasets, prompts, tools?
Would you detect a third-party tool changing its behaviour after you approved it?
Confidential AI & Infrastructure
Govern & Assure · Gate DAre AI workloads isolated from other workloads at the infrastructure layer, not only by application logic?
Where the data warrants it, is it protected in use as well as at rest and in transit?
Do you control which regions AI workloads and their data run in, and can you evidence it?
Governance, Risk & Compliance
Govern & Assure · Gate DAre your AI controls mapped to a framework you already report against — NIST AI RMF, ISO/IEC 42001, the EU AI Act?
Is evidence for those controls collected automatically, rather than assembled by hand before an audit?
Is accepted AI risk recorded against a named owner with a time-bound expiry?
Answer all 24 to see your gate results. Roughly four minutes. Nothing is submitted until you choose to.