AI Security Engagement
This page describes how the free AI security curriculum on this site connects to a professional assessment engagement with 365 Architect — scope, methodology, delivery, and contact.
From Curriculum to Readiness
The AI security documentation here is free and public by design. Our reasoning is open — see Open Validation — so you can evaluate our methodology before any commercial conversation.
What Comes Next
1. Free AI Security Sample Assessment
Request one and 365 Architect will run a scoped, time-boxed assessment of one AI system — models, pipelines, data, and deployment — under NDA. It is hard-capped at three working days. You receive:
| Deliverable | Description |
|---|---|
| AI Asset Inventory | Discovered models, datasets, endpoints, agents, and dependencies |
| Threat Model | ATLAS/OWASP-mapped attack surface with likelihood/impact |
| One-Page Control Gap Read | NIST AI RMF / EU AI Act / ISO 42001 control coverage with residual risk |
No charge. No obligation. The sample assessment is our way of demonstrating methodology before you commit. It is deliberately capped — the remediation roadmap is what the AI Sovereignty Diagnostic sells.
2. AI Sovereignty Diagnostic
A fixed 2-week engagement — diagnosis and architecture, no hands-on red-teaming. The fastest way to know exactly where your IP is leaking and what a private architecture looks like:
| Deliverable | Description |
|---|---|
| Threat Matrix Report | Shadow-AI footprint, prompt-layer exfiltration paths, and GDPR / EU AI Act compliance gaps |
| Zero-Knowledge Architecture Blueprint | A roadmap to local / private LLM orchestration and prompt-level redaction so IP never leaves your infrastructure |
| Executive Briefing | A direct debrief with technical leadership to move from diagnosis to decision |
Full scope on the AI Sovereignty Diagnostic page. Many clients start here, then graduate to the full Baseline Audit below.
3. Full AI Security Baseline Audit
A fixed-scope engagement, tiered by system type:
| Tier | Scope | Duration |
|---|---|---|
| B3-S · Single-system | One LLM application — a chatbot or single assistant on a third-party model API, with limited integration and no autonomous tool use | 4 weeks |
| B3-M · Multi-agent / regulated | Multi-agent or agentic systems, RAG + retrieval layers, proprietary or fine-tuned models, autonomous tool use, or regulated data (GDPR / EU AI Act high-risk / HIPAA) | 6 weeks |
Both tiers include everything in the AI Sovereignty Diagnostic (B2) plus adversarial testing, control testing against NIST AI RMF / EU AI Act / ISO 42001, a full risk register, an executive summary with technical findings, a remediation roadmap, and 90-day advisory access.
Phase plan:
| Phase | B3-S | B3-M | Activities |
|---|---|---|---|
| 1. Discovery | Week 1 | Weeks 1–2 | Inventory (models, data, pipelines, agents), stakeholder interviews, regulatory context mapping |
| 2. Threat Modelling | Week 2 | Week 3 | ATLAS/OWASP attack trees per system; risk register creation |
| 3. Control Assessment | Weeks 3–4 | Weeks 4–5 | NIST AI RMF, EU AI Act, ISO 42001 control testing; adversarial testing; red-team |
| 4. Reporting | Week 4 | Week 6 | Executive summary, technical findings, risk register, remediation roadmap |
| 5. Delivery | Week 4 | Week 6 | Walkthrough, Q&A, handover via NestVault365 |
How the tier is chosen. The tier-qualifying questions asked in the scope call:
- What can the system access? (databases, files, APIs, production data)
- What tools can it call? (function calling, external services)
- What does it retrieve? (RAG sources, retrieval layers)
- Can it trigger downstream actions? (writes, deployments, financial operations)
- Is the data regulated? (GDPR, EU AI Act high-risk, HIPAA)
The B3-S tier is justified by the three-framework control testing (NIST AI RMF / EU AI Act / ISO 42001, tested and evidenced) that lighter assessments do not include — not by the attack tooling.
Fixed scope, fixed timeline. Both tiers include all deliverables and 90-day advisory access. Pricing is published on the Full AI Security Baseline Audit page.
4. Continuous AI Security Programme
Ongoing subscription for organisations with evolving AI estates:
| Tier | Cadence | Includes |
|---|---|---|
| Monitor | Monthly | Drift alerts, threat intel briefs, control effectiveness dashboards |
| Assure | Quarterly | Adversarial re-test, drift validation, regulatory change impact |
| Govern | Continuous | Board-ready reporting, audit evidence packages, incident response retainer |
Pricing on request — tailored to AI estate size and regulatory exposure.
Delivery via NestVault365
All findings, blueprints, audit artefacts, and communications are delivered exclusively through NestVault365, our proprietary end-to-end encrypted data room:
- Zero-knowledge encryption — we cannot read your data
- Granular access control — per-artefact, per-role, time-limited
- Audit trail — every view, download, and share logged
- Regulatory readiness — evidence packages structured for EU AI Act Art. 11/17/72, ISO 42001 Annex A
- No email transmission — nothing sensitive leaves the vault
See a sample of the output format before you engage.
How to Start
- Review the curriculum — Start with Standards & Frameworks and Threat Taxonomy
- Request a sample assessment — Use the form below or email
info@365architect.com - Scope call — 30 minutes to align on sample scope, timeline, and NDA
- Execute sample — hard-capped at three working days; you receive the deliverables above
- Decide — Continue to full audit, continuous programme, or stop with no obligation
Contact
Request an AI Security Sample Assessment →
Or email: info@365architect.com