AI Security

Odds are, someone at your company uploaded a customer file to ChatGPT this week.

On a personal account. You can’t see it, you can’t delete it, and when that employee leaves, it goes with them.

Can you prove it didn’t happen?

No sales pressure. Just a candid conversation about your risks.

It isn’t just ChatGPT

AI Is Already Inside Your Business

AI notetakers

They join customer and staff calls, record them, and store the transcript on someone else’s servers.

Browser extensions

AI “assistants” that can read every page an employee opens, including the systems that hold your data.

Free document tools

Upload a contract or a spreadsheet, get a “summary.” The file now lives with a company you’ve never vetted.

Coding assistants

Source code, credentials and configuration files pasted in to get an answer faster.

We look for 260 AI services across 12 categories.

The Numbers Behind It

80%

of AI users at small and mid-sized companies bring their own AI tools to work.

Microsoft & LinkedIn, 2024 Work Trend Index

43%

of security incidents in the 2026 study involved shadow AI. That is more than double the prior year’s 20%.

IBM, Cost of a Data Breach Report 2026

68%

of breached organizations lacked AI governance to manage AI or detect shadow AI.

IBM, Cost of a Data Breach Report 2026

The Threat, Defined

Shadow AI is staff using AI tools the business never approved, on accounts the business doesn’t own. It is rarely malicious: it’s someone saving an hour on a deadline. The exposure is what happens next.

Data leaves without a record

Contracts, HR files, financials and customer data get pasted or uploaded into AI tools. No log, no alert, no record of what went where.

It can’t be recovered

A personal account has no admin, no deletion, no legal hold and no offboarding. When the employee leaves, the data goes too.

Nobody can answer the question

Insurers, auditors, regulators and major customers now ask what AI you use. Without evidence, the answer is a guess.

The AI Discovery Assessment

What You Get

A detailed AI inventory

Every AI service we observe, checked against 260 services in 12 categories: chatbots, notetakers, browser extensions, document tools, coding assistants and more.

Who is using it where your logs allow

Usage by person and device, so the fix lands on a name, not on a policy memo nobody reads.

What is leaving where your logs allow

The names of files uploaded to AI services, and where they came from: shared drives, HR folders, finance, legal.

Who owns the accounts

Whether staff use a company workspace you control, or personal accounts you can’t reach, delete from or revoke. This is usually the finding that changes the conversation.

Every finding reviewed by an analyst

Each finding is tied to the evidence behind it, plus a written statement of what our sources could and could not see.

A 30/60/90-day roadmap

Sequenced and owner-assigned, so the first thirty days establish the facts before anything irreversible happens.

How It Works

1

Authorize

You sign a scope. We agree the networks, the data sources and the collection window in writing. Nothing starts before that.

2

Observe

We ship a pre-configured sensor you plug in, or review logs you already keep. Days for a snapshot, weeks for the full picture, or months of history from existing logs.

3

Report

An analyst reviews every finding against the evidence. You get the inventory, the roadmap and a briefing in plain English.

What we need from you: a network port and a signature. No software on your endpoints, no agents, and nothing tested or changed without written authorization. Your IT team spends under an hour on it.

Built for Organizations That Answer to Someone

Defense contractors

If CUI goes into a consumer AI tool, it has left your CMMC boundary. Find out before your assessor does.

Credit unions & financial institutions

NCUA has no AI-specific rules. Existing regulations apply to AI use. You can’t oversee a tool you don’t know is in use.

Healthcare & regulated businesses

Patient, client and employee data in an AI tool nobody approved is a compliance problem waiting for an audit.

Frequently Asked Questions

Will this slow down our network or break anything?

No. The assessment is passive. We observe a copy of your traffic or read logs you already have. Nothing is installed on your computers and nothing on your network is changed.

Do you read what employees type into AI tools?

No. We see which AI services are used and by whom. Where your logs record it, we also see the names of files uploaded. We never see the contents of a file or a prompt.

How long does it take?

That’s your call. A few days gives a fast snapshot; a few weeks gives a fuller picture. If you already keep the right logs, we can review months of history right away.

We already block ChatGPT. Do we still need this?

ChatGPT is one of 260 AI services we look for. Blocks also tend to push activity to personal phones and other tools. The assessment shows whether your controls are actually holding.

Will you find every AI tool?

We’ll find the AI services our sources can see, and we’ll tell you in writing what they can’t, such as AI built into software you already use. An honest boundary is what makes the findings defensible.

What happens after the assessment?

You get a 30/60/90-day roadmap your IT team or provider can act on. If you want ongoing executive ownership of AI risk, our Fractional CISO service can lead it.

Find Out What Your Organization Is Actually Sending to AI

No sales pressure. Just a candid conversation about your risks.

Sources: Microsoft & LinkedIn, 2024 Work Trend Index (31,000 knowledge workers, 31 markets); IBM & Ponemon Institute, Cost of a Data Breach Report 2026 (602 organizations); NCUA, Artificial Intelligence (AI) compliance resources (updated April 28, 2026). Passive observation shows that a file was sent, not its contents. Independent assessment within an authorized scope; not legal or regulatory advice and not a guarantee against incidents.

To top