AI assurance engagements

Four routes. One evidence-led decision boundary.

LeftOut Security finds the authority paths, control dependencies, and evidence gaps other reviews left out—then routes the defined AI system to the engagement that fits its architecture and business trigger.

Scope and fee after consultationConfirmed in writing for the actual system
Focused deliverySchedule matched to the actual system
Founder-signedTom Schreier, CISSP reviews every conclusion
IndependentNo implementation upsell
Approved public routing

The route follows the decision—not a public price tier.

A routing recommendation is not an engagement, audit result, or authorization to test. The accepted written scope controls the system boundary, evidence, permitted activities, fee, and schedule.

01

Agentic Assurance Snapshot

For an early, constrained, or advisory-stage system that needs a bounded baseline of reported evidence readiness and the next control questions to resolve.

02

Agent Authority and Blast-Radius Review

For meaningful write access, privileged integrations, external action, persistent memory, cross-system reach, or weak containment.

03

AI Architecture and Control Assurance

For multiple trust boundaries, models, RAG, MCP servers, APIs, identities, data stores, or complex control dependencies.

04

Enterprise Independent Validation

For enterprise review, procurement, diligence, regulated requirements, or leadership decisions that require independent inspection and validation.

How scope is set

The boundary follows authority—not a generic package.

Every engagement is scoped around the system’s authority, integrations, evidence, and decision timeline—including the identities, tools, and dependencies other reviews left out. After an initial consultation, LeftOut Security provides a written scope, professional fee, and delivery schedule.

  • The production or customer-pilot system that matters to the decision.
  • The agent workflows with meaningful access or external action.
  • The tools, APIs, data stores, identities, and dependencies that shape blast radius.
  • The business trigger, accountable sponsor, and decision deadline.
  • An agreed evidence set and focused walkthroughs with the relevant owners.
  • A delivery plan sized to the system rather than an arbitrary page count.
What is reviewed

The complete path from instruction to consequence.

Coverage follows what the system can see, call, change, store, expose, and trigger—not only the model provider or application boundary.

Identity and delegated authorityHuman, service, agent, and workload identities; credential inheritance; approval enforcement.
Data and retrieval reachCustomer data, internal knowledge, RAG, vector stores, memory, and cross-tenant exposure.
Input-to-action influencePrompts, documents, retrieved content, remote instructions, and indirect injection paths.
Tools and integrationsMCP servers, APIs, OAuth scopes, webhooks, automations, and downstream actions.
Containment and interruptionHuman approval, transaction boundaries, kill paths, rate limits, and recovery controls.
Evidence and accountabilityLogging, attribution, traceability, evaluations, retention, and reconstruction.
Secrets and session trustKeys, tokens, sessions, browser boundaries, and server-side enforcement.
Business claimsPrivacy, security, autonomy, oversight, and customer-facing claims versus actual behavior.
Blast radiusCredible chains from one bad input, identity, tool call, or control failure to business impact.
Deliverables

Built for the decision room and the engineering backlog.

01

System understanding

Agent execution graph, trust-boundary map, and reach and blast-radius scorecard.

02

Evidence-backed risk

Risk register with confidence states, highest-impact abuse paths, and control decisions.

03

Actionable decision package

Trust brief, evidence index, prioritized roadmap, executive readout, and any agreed buyer-support or follow-up review.

Decision states: Proceed, proceed with conditions, or pause. The assessment explains the evidence behind the decision and what must change for the state to move.
Follow-through

Updated evidence can be reviewed without selling the fix.

When useful, the written scope can include a focused review of updated evidence after remediation. This records whether agreed decision conditions changed; it is not implementation, continuous monitoring, or a new certification.

Explicit exclusions

No hidden expansion.

  • No certification, attestation, legal opinion, or security guarantee.
  • No full penetration test or exhaustive source-code audit unless separately authorized and scoped.
  • No remediation implementation, managed service, incident response, or 24/7 support.
  • No access or testing without accepted written scope and authorization.
When it is not a fit

We will say so before turning it into a sales process.

If the system, decision, or evidence does not fit a focused independent assessment, LeftOut Security will decline, pause, or recommend a different type of provider. A materially different engagement exists only through a new written scope accepted by both sides.

Start with a conversation

Do not commit to an assessment until the system and decision are clear.

Send a short, non-sensitive overview. Qualified requests move to a focused consultation, followed by a written scope, fee, evidence requirements, and schedule.

Start the Readiness Screen Request a Consultation