AI Audits

Independent audits for private AI

We assess your agents, data boundaries, and controls inside your own network — verifying that prompts, embeddings, and customer data never cross your perimeter, and that every action is governed and traceable.

  • Runs entirely inside your perimeter
  • Mapped to SOC 2, ISO, NIST AI RMF
  • Data-boundary & egress verification
  • Prioritized remediation roadmap
0
bytes of your data leave the perimeter
5
control domains assessed end to end
100%
of agent tool calls reviewed for least privilege
2 wks
typical turnaround to a findings report
// what we inspect

Five control domains

An AI audit is not a pen test. We assess the places where models, data, and autonomy create new exposure.

// the engagement

How an audit runs

Read-only by default, inside your network, with no surprises.

01

Scope

We agree on systems, data classifications, and frameworks in scope, then provision read-only access within your perimeter.

02

Assess

We inspect configs, logs, prompts, tool definitions, and egress paths in place — and run approved tests in a staging copy.

03

Report

You receive prioritized findings with evidence and severity, mapped to a control matrix for your frameworks.

04

Re-audit

After remediation we re-test the closed findings and issue a confirmation your auditors can rely on.

// the perimeter is the point

Your data never leaves your network

Most AI security reviews quietly ship your logs and sample data to a vendor's cloud to be analyzed. That defeats the purpose. Our audit runs where your data already lives — on-prem, in your VPC, or fully air-gapped — and inspects everything in place.

We verify the boundary empirically: tracing egress from every model host and agent, confirming proxy and DNS controls, and proving that no prompt, embedding, or document silently crosses a trust boundary. Findings are written only to a location you own.

  • No data copied to our systems
  • Egress traced from every model host
  • Findings stored in your environment
  • Air-gap and VPC isolation verified

Generic security scan vs. AI audit

Why model- and agent-specific exposure needs its own assessment.

A generic scanAn Automatic.co AI audit
Where it runsVendor cloud, data exportedInside your perimeter, in place
FocusCVEs and open portsData boundary, agent actions, lineage
Agent autonomyNot assessedTool scope & approval gates reviewed
Retrieval leakageInvisible to itVector-store permissions tested
OutputA vulnerability listFindings mapped to SOC 2 / ISO / NIST

Frequently asked questions

Does our data leave our environment during an audit?

No. The audit runs inside your perimeter — on-prem, in your VPC, or air-gapped. We inspect configs, logs, and code in place; nothing is copied to our systems, and findings are written to a location you control.

What standards do you map findings to?

We map controls to SOC 2, ISO 27001/42001, the NIST AI RMF, HIPAA, and GDPR as relevant. The report cross-references each finding to the frameworks your auditors and customers already ask about.

Will the audit disrupt our running agents?

No. The assessment is read-only by default — we observe traffic, prompts, tool calls, and access policies without changing them. Any active probing (e.g., prompt-injection tests) happens in a staging copy you approve first.

What do we get at the end?

A prioritized findings report with severity, evidence, and a remediation path, a control matrix mapped to your frameworks, and a working session to walk your team through fixes. Re-audits confirm closure.

Audit your AI before someone else does.

A scoped session to map your AI attack surface and the controls an external assessor will expect — all inside your own network.