Scope, evidence, independence, and what you actually receive.
The assessment is deliberately clear about what it does and does not do. These answers cover the questions that usually matter before contracting.
Agentic Assurance Snapshot; Agent Authority and Blast-Radius Review; AI Architecture and Control Assurance; and Enterprise Independent Validation. The route follows the system’s authority, architecture, evidence condition, and business trigger. A routing recommendation does not create an engagement or authorize testing.
Scope, fee, evidence requirements, and schedule are confirmed after an initial consultation and written scoping. The decision reflects the system’s authority, integrations, evidence, permitted testing boundaries, and business timeline.
Many focused assessments can be completed in roughly ten business days once the scope, evidence, handling terms, and responsible owners are ready. Larger, unusually privileged, or poorly documented systems receive a schedule matched to the actual work.
LeftOut Security will decline, pause, or explain what kind of provider is better suited to the request. A materially different engagement exists only through a separate written scope accepted by both sides.
No. It is an independent, point-in-time security and governance assessment. It is not a certification, attestation, legal opinion, security guarantee, exhaustive source-code audit, or formal compliance audit. Any technical validation requires explicit written authorization and boundaries.
Mutually accepted written terms can be completed before confidential evidence is exchanged. Customer paper, data-protection obligations, liability terms, and security schedules are reviewed during scoping. Submitting a form, email, or purchase order does not create an engagement.
Ask during the consultation. Current, accurate documentation is provided only when available and applicable. Any insurance limit, questionnaire, audit, or vendor-onboarding requirement that cannot be met will be surfaced before scope is accepted.
Yes, when the process fits the engagement. A purchase order does not replace the accepted scope, authorization, handling terms, or required payment. The delivery schedule begins when the agreed commercial and evidence prerequisites are complete.
Known conflicts that could impair independent judgment are disclosed and resolved before acceptance. LeftOut Security does not turn findings into implementation revenue. If independence cannot be preserved, the engagement is declined.
Not by default. The assessment begins with architecture, identities, permissions, tool boundaries, configurations, policies, logs, evaluations, interviews, and guided walkthroughs. Read-only repository or environment evidence is considered only when it materially affects the decision and is explicitly authorized.
The evidence list is tailored to the system but commonly covers architecture, identities, data flows, retrieval and memory, tool definitions, permissions, approval controls, logs, evaluations, retention, incident paths, and relevant customer claims.
The channel is selected during contracting based on client requirements and the evidence involved. It may be a client-controlled workspace or another approved, access-controlled channel. The public form and ordinary inquiry email are never evidence channels.
AI may assist with evidence organization, inconsistency detection, analysis, and document production under controlled workflows; it does not issue the assessment. Written handling terms identify approved systems and material subprocessors where applicable. Client evidence is not placed into an AI service unless permitted in writing.
Retention, return, deletion, backups, and required residual records are defined in the written engagement terms. The agreed rule is applied to the approved channel and engagement records, subject to applicable legal, accounting, security, or dispute-preservation requirements.
Do not submit passwords, keys, tokens, production credentials, source code, customer data, logs, confidential architecture, regulated data, payment data, or repository and cloud-console invitations. The public request is for high-level fit information only.
Plan for an accountable sponsor, a system owner, and the relevant security or engineering owners. The engagement normally uses a kickoff, focused evidence walkthroughs or interviews, a factual-correction window, and an executive readout. The exact meeting plan is set during scoping.
Typical outputs include an execution graph, blast-radius scorecard, evidence-backed risk register, abuse paths, trust brief and evidence index, prioritized roadmap, and executive readout. Controlled PDF and agreed tabular formats are confirmed in the written scope.
The trust brief and evidence index can support authorized external conversations. The full report may contain sensitive system information. Permitted recipients, redistribution, reliance, and confidentiality are governed by the written engagement terms; no third party should treat the output as a certificate or guarantee.
Yes. The process includes one coordinated factual-correction window. New evidence or a demonstrated factual error can change a finding; preference alone cannot. Independent judgment, severity, and the final decision are not negotiated.
Yes. A focused buyer-security call can be included in the written scope to explain the assessment, trust brief, and evidence index. It does not include open-ended questionnaire completion, representation as the client, a new assessment scope, or attestation.
When included in scope, a focused follow-up can review agreed updated evidence and record whether decision conditions changed. It is not implementation, continuous monitoring, a full retest, or certification. A materially changed system requires a new scope.
No. The finding is not a sales lead. Your team or selected implementation partner owns remediation. LeftOut Security can review agreed updated evidence without selling the implementation.