Home  /  Services

Services

Four services that take a business from "we have no idea what our people are doing with AI" to "we know, it's governed, and it's making us money."

Service 01

AI Readiness Assessment

Everything starts here. Over roughly two weeks we build an honest picture of how AI is already moving through your business — the sanctioned tools, the ones on personal accounts, the data flowing to each — and turn it into a plan your leadership team can actually act on.

You keep the deliverables whether or not you engage us for the work that follows. Several clients have taken the roadmap to their in-house team and run it themselves. That's a fine outcome.

Time from you: about three hours total — a kickoff, a few short interviews, and a one-hour readout.

deliverables
  • AI tool inventoryEvery AI service touching your environment, with owner and spend.
  • Data exposure mapWhat categories of data are leaving, through which tool, under what terms.
  • NIST AI RMF risk registerScored, prioritized, and written so a non-technical board can read it.
  • Top three use casesSized by effort, cost, and realistic hours returned per week.
  • Draft AI acceptable-use policyOne page, plain English, ready to adopt.
  • 90-day roadmapSequenced, costed, and yours to keep.
Service 02

AI Governance & Policy

A policy nobody reads protects nobody. We write AI governance the way it has to work in a real small business: short enough that people finish it, specific enough that they know what to do on Tuesday morning.

Then we make it real — the approved-tool list gets configured, the data line gets enforced technically rather than hopefully, and everyone gets thirty minutes of training that uses examples from your actual business.

Increasingly not optional. Cyber insurance renewals, client security questionnaires, and SOC 2 / HIPAA reviews have all started asking how AI is governed. Having a documented answer is now part of doing business.

What you get

  • AI acceptable-use policy, written for your industry and headcount
  • Data classification: what may be shared with a model, what never can
  • Approved-tool list with named owners and review dates
  • Vendor review of AI terms — training use, retention, sub-processors, region
  • Role-based staff training with your own examples
  • Incident playbook for when something is pasted where it shouldn't be
  • Board- and insurer-ready summary of controls in place
Service 03

Secure AI Integration

This is the part that returns money. We deploy the tools your teams will use every day — and we configure the security posture before the first user logs in, not after an incident.

Copilot inheriting over-permissive SharePoint access is the single most common self-inflicted wound we see. Getting permissions right first is unglamorous work. It's also the difference between a rollout that helps and one that quietly surfaces the salary spreadsheet to the whole company.

Productivity AI

Microsoft 365 Copilot, Google Gemini for Workspace, and Claude or ChatGPT enterprise tiers — with tenant controls, DLP, and retention set correctly.

Private assistants on your data

A retrieval assistant over your own SOPs, contracts, or knowledge base — scoped to existing permissions so it can never answer beyond what the asker may already see.

Workflow automation

Document intake, quoting, ticket triage, meeting notes into your PSA or CRM — automation with a human checkpoint wherever a mistake would cost real money.

Identity & access first

SSO, conditional access, least-privilege review, and permission remediation on the data sources AI will read. The boring layer that makes everything else safe.

Service 04

Ongoing Monitoring & Review

AI is not a project you finish. New tools ship weekly, vendors quietly change their terms, and staff turn over. A policy written in March is out of date by August unless someone owns it.

We own it. Continuous visibility into what AI is being used, alerting when something new shows up or sensitive data heads somewhere it shouldn't, and a quarterly review you can hand straight to your board, auditor, or insurer.

What ongoing looks like

  • Continuous discovery of new AI tools appearing in your environment
  • Alerting on sensitive-data movement toward unapproved services
  • Vendor term-change watch on the tools you depend on
  • Quarterly control review against the NIST AI RMF
  • Refreshed use-case backlog as new capabilities become viable
  • Written quarterly report for leadership, auditors, and insurers
  • A named engineer who knows your environment — not a ticket queue
Who this is for

Built for businesses without a compliance department

Roughly 20 to 500 people, no dedicated AI staff, and a real obligation to protect somebody's sensitive information.

Healthcare & dental

PHI never reaches a consumer chatbot. HIPAA-aligned controls and BAAs reviewed before any tool goes live.

Financial & legal

Client confidentiality, privilege, and retention obligations mapped to concrete AI controls.

Construction & manufacturing

Bid documents, drawings, and supplier pricing kept out of public models while estimating gets faster.

Professional services

Client contracts and deliverables governed, so an AI question on an RFP is a strength, not a scramble.

Not sure which one you need?

Almost everyone starts with the assessment — it's designed to answer exactly that question in two weeks.