SteadySec Your retained security partner

Retainer capacity is full until mid-2027.Fixed-scope projects available on request.

Tell us what your AI does.

Send the answers and we bring a price to the call.

  • 10 questions
  • About 3 minutes
  • Free, no sign-up
AI application scoping 0 of 8 answered
1. Can your AI do anything other than produce text?

This one answer decides most of the price. An assistant that answers questions has a small attack surface; one that can call a tool, change a record or reach an API has a large one.

2. How many tools, functions or MCP servers can it call?

Count each distinct action it can take. If it calls one API with six endpoints, that is six.

3. Does it read documents or data belonging to your customers?

A retrieval pipeline over per-customer data is where cross-customer exposure lives, and testing it needs an account in each of two tenants.

4. Who can talk to it?

An assistant reachable by anyone outside your company has a larger population of potential attackers than one behind a staff login.

5. Is there a test environment we can work against?

Testing in production is workable and it narrows what we are allowed to do. A staging instance with dummy data lets us prove more.

6. When do you need the result?

Booking three weeks or more ahead is reflected in the quote. Short notice carries a premium because it displaces scheduled work.

7. Who reads the report?

A report going to a customer, an auditor or a certification body is written differently from one that stays with your engineers.

8. Anything that would get in the way of testing?

Pick every one that applies. None of these stops the work; each one changes how it is planned.

9. Anything else we should know?

What the assistant is for, what worries you about it, a deadline you are working to, or a question you want answered on the call.

10. Who is asking?

Optional. Filling these in means the reply can carry a price.

Nothing leaves your browser until you send it.

Still deciding? What the assessment covers →