Services · Go deeper

Which records did the model read?
Most teams cannot answer that.

Answering a subject access request, a breach notification, or an AI Act record-keeping question all require the same thing: proof of which records a given AI system read, and when. This assessment establishes real exposure across the estate using automated data classification, then tells you plainly whether your current logging could produce that proof.

Estate
Wide, not sampled
20+
Classification categories
Verdict
On audit trail readiness
24h
Quote turnaround
Deliverables

What you get, in writing

Every deliverable below is named in the statement of work. Nothing here is aspirational.

Estate-wide exposure map

Every data store an AI system can reach, with the sensitive data each one holds — classified automatically across 20+ categories including PII, PHI, and cardholder data.

Per-system exposure scoring

Each AI system scored by the volume and sensitivity of what it can reach, so remediation starts with the system holding the most consequential access.

AI audit trail readiness verdict

A direct answer on whether you could today prove which records a given AI system read: what is captured, what is missing, and what it takes to close the gap.

Containment recommendations

Scoping, masking, and view-level controls that reduce exposure without breaking the AI use cases the business actually wants.

How It Works

A defined path, with a defined end

1

Classify

Automated discovery and classification runs across the in-scope estate to establish what sensitive data exists and where.

2

Map exposure

AI system access is resolved against the classified data to establish real, not theoretical, exposure.

3

Test provability

We attempt to reconstruct which records a chosen AI system read, and document what the current logging can and cannot show.

4

Report

You receive the exposure map, the readiness verdict, and prioritized containment recommendations.

Good Fit

This is for you if

  • AI systems have broad read access and nobody has quantified it
  • You need to answer subject access or breach questions covering AI systems
  • EU AI Act record-keeping applies and you are unsure you can satisfy it
  • A RAG pipeline was pointed at production and the blast radius is unknown

Not sure it fits? Ask anyway — if it isn't a fit, we'll say so on the scope call.

Pricing

Priced up front, quoted in 24 hours

Fixed fee banded by estate size and the number of AI systems assessed. Runs on the platform, so the classification work carries forward if you license it.

Get an Exposure Quote

Get a fixed-scope quote in 24 hours

Enter your business email. We'll come back within 24 hours with a written quote for AI Data Exposure Assessment — scope, price, and end date included.