Mon–Fri, 9:00 AM – 5:00 PM PST

Compliance · AI governance

Your staff already use AI. Governance decides whether that's an asset or a breach

AI Governance & AI Compliance

Nobody approved it, but somebody already pasted a patient list, a client tax return or a signed contract into a chatbot. AI governance is the boring work that makes that stop: an inventory of what's actually in use, a policy people can follow, technical controls that block the dangerous paths, and a log you can hand an auditor. We build it around the rules you already answer to — HIPAA, FINRA, PCI, SOX, FDA and federal contracts — and against the AI frameworks regulators are now citing.

The question is no longer whether your team uses AI. It's whether you can prove what it was allowed to see.

What's included

  • Shadow-AI discovery: every AI tool and browser extension in use
  • Written AI acceptable-use policy, in English and Spanish
  • NIST AI RMF and ISO/IEC 42001 aligned control set
  • Data-leakage controls: DLP rules, tenant restrictions, blocked consumer endpoints
  • Approved-tool catalog with vendor and model risk review
  • Prompt and output audit logging with retention
  • Human-review requirements for regulated decisions
  • Staff training on what may and may not go into a model

What changes for your business

  • Stop the quiet data leak

    Consumer AI accounts train on what you paste. We move the work to tenant-bound tools where your data stays yours, and block the rest at the edge.

  • An answer when the auditor asks

    "Do you use AI, and how do you control it?" is now a standard question on HIPAA, FINRA and vendor security questionnaires. You'll have the policy, the inventory and the logs.

  • Say yes instead of no

    Blanket bans just push AI onto personal phones. A governed catalog lets the team use the productivity gain out in the open, where it can be supported.

How we deliver it

What actually happens

No vague promises — these are the concrete pieces of work included in the engagement.

  1. AI use inventory

    We scan network and endpoint telemetry, SaaS sign-ins and browser extensions to produce a real list of the AI in your business — including the tools nobody told you about.

  2. Risk classification by data type

    PHI, cardholder data, client financials, federal contract information and trade secrets each get an explicit rule: allowed, allowed with redaction, or prohibited.

  3. Policy, training and attestation

    A short policy people actually read, a training session, and a signed attestation per employee retained as evidence.

  4. Technical enforcement

    Tenant restrictions, conditional access, DLP policies and DNS filtering configured so the policy is enforced by the system, not by hope.

  5. Ongoing monitoring

    New AI tools appear weekly. The automated check flags newly seen AI services on your network the week they show up, and the 90-day review re-scores the approved catalog.

AI frameworks

What we build your AI program against

There is no single AI law covering a San Diego business yet. There is a stack of frameworks regulators, insurers and your clients' security teams already cite — so we build to those.

  • NIST AI RMF 1.0

    NIST AI Risk Management Framework

    The Govern / Map / Measure / Manage structure we use to organize your AI controls. Voluntary, but it's the vocabulary auditors and insurers speak.

    Applies to everyone — this is the backbone of the program.

  • ISO/IEC 42001

    AI management system standard

    The certifiable management-system standard for AI. We build your documentation to its shape so certification is a step, not a rebuild.

    Matters most if enterprise customers audit your vendors.

  • EU AI Act

    EU AI Act obligations

    Risk-tier classification, transparency notices and human-oversight duties, mapped only to the use cases that actually put you in scope.

    Only if you sell into, or process data from, the EU.

  • Sector rules

    Your existing regulator, applied to AI

    HIPAA on PHI in prompts, FINRA on AI-generated communications, PCI on cardholder data, FDA Part 11 on records, FAR on federal contract information.

    This is where the real enforcement risk lives today.

What it costs

The line items behind this service

Straight from the rate card we quote from. Add them to a full estimate in the calculator.

Build a full estimate
Compliance
Service List price
AI Governance & Compliance $9/user* /month
Assigned Compliance Specialist $295/contract* /month
LionGuard $75/site /month
Security
Service List price
Endpoint Security $5/user /month

Estimated price. Confirmed in writing before anything is signed.

Informational use only — this is not a quote The numbers on this page are for informational use only and are not a factual quote. Pricing depends on what we find in your environment. For an actual quote, please contact us.

Frequently asked questions

Which AI frameworks do you align to?

The NIST AI Risk Management Framework and ISO/IEC 42001 for the control structure, plus the AI-specific expectations layered onto HIPAA, FINRA, PCI, SOX, FDA Part 11 and federal contracting. If you sell into the EU, we map the EU AI Act obligations that apply to your use case.

Do we have to stop using ChatGPT?

Usually not — you have to stop using the consumer version for regulated data. Business and enterprise tiers with no-training terms and tenant isolation are generally approvable; we document why, and configure the guardrails.

We build AI into our own product. Can you help?

Yes, on the governance side: model and vendor due diligence, data flow documentation, logging, human-in-the-loop requirements and the security questionnaire answers your customers will demand. We are not your development team, and we'll say so plainly.

How fast can this be in place?

Discovery and the technical guardrails typically land inside two to three weeks. Policy, training and attestations follow in the same quarter, then it joins the weekly automated and 90-day manual cycle.

Compliance

Back to overview

Let's take IT off your plate.

A free onsite consultation: we assess your network and security, flag the risks we find, and show you exactly what it costs to fix them.