AI & SaaS Risk Audits
End-to-end review of model usage, data flows, vendor terms, disclosures, and automated decision risk across your product surface.
- Model & data flow mapping
- Training-data and vendor terms
- Disclosure gap analysis
Services
Seven review domains, one methodology, one report. Run the full audit or start with a focused review.
End-to-end review of model usage, data flows, vendor terms, disclosures, and automated decision risk across your product surface.
Tag, tracker, and consent-banner analysis mapped to GDPR, CPRA, and state privacy expectations — with evidence you can hand to counsel.
Forms, SMS flows, call scripts, and lead-gen paths reviewed for express written consent, revocation, and record-keeping defects.
WCAG 2.2 AA testing combining automated scans with manual keyboard, screen-reader, and contrast validation on real user journeys.
Externally observable security posture: headers, exposure, authentication surfaces, and disclosure readiness — no intrusive testing.
Engineers who ship the fix: consent plumbing, accessibility refactors, policy generators, and CI guardrails in your codebase.
Continuous checks that catch regressions before they become claims — with quarterly executive reporting for your board.
In practice
Every domain produces reproducible artifacts your engineers can act on the same day.

Consent & privacy
We replay your banner against real tag firing order, revocation, and record retention.

Accessibility
Keyboard, screen reader, and contrast passes on the journeys that actually convert.

Public security
Externally observable posture — headers, TLS, exposure — with zero intrusive testing.