Security leadership, on retainer
vCISO for AI companies
For AI-native products selling into enterprise. SOC 2, ISO 42001, EU AI Act obligations, and the AI governance section of the security questionnaire that is currently holding up your deal.
Built around how your product actually handles data, which models it calls, and who sits downstream of you.
Trusted for
SCOPE FOR AI Companies
SOC 2 no longer answers the question
Enterprise buyers now treat SOC 2 as the baseline. What they added on top is an AI section: which models you call, whether customer data trains them, what your subprocessor chain looks like below the foundation model, how outputs are monitored, and who is accountable when the system gets something wrong.
Those questions are now built into the standard templates. The Cloud Security Alliance released an AI extension to its CAIQ questionnaire, and the widely used SIG questionnaires added AI modules, so buyers no longer have to write the questions themselves. Most AI companies cannot answer them, because the answers are not documents. They are facts about your architecture that nobody has written down: which provider terms govern retention, whether tenants share model API keys, what happens to prompts in your logs.
We work these out with your engineers and turn them into answers your buyer's security team will accept.

WHAT WE DO
What we do for AI companies specifically
01
The AI section of the security questionnaire
Training use, retention, subprocessor chain, tenant isolation, prompt and output logging, human review, model change management, exit and deletion. We write the answers, back them with evidence, and defend them on the call with the buyer's security team.
02
AI data flow mapping
Where customer data enters, which model providers receive it, what is retained and for how long, what lands in logs and telemetry, and which subprocessors sit below your foundation model provider. This is the artefact buyers, auditors, and your own incident response all need, and almost nobody has it.
03
ISO 42001 preparation
The certifiable AI management standard, and increasingly the thing enterprise and regulated buyers name directly. If you already hold ISO 27001, the additional effort is materially smaller because the management system structure is shared.
04
Model and vendor risk
Your model providers are your subprocessors, and their terms differ on retention and training. We inventory them, check the contract terms actually say what your questionnaire answers claim, and set up a process for adding new ones.
05
EU AI Act positioning
Whether you are a provider or a deployer, which obligations already apply to you, and what the deferred high-risk deadlines mean for your roadmap. Transparency obligations are in force now; the heavier high-risk regime is not.
06
Incident response for AI systems
Prompt injection, data leakage through outputs, model behaviour changing after a provider update. We write the playbook, run the tabletop, and lead the response.
Ready to move faster?
Too much to do,
too important to ignore.
Start with a 30-minute discovery call. If we're not the right fit, we'll tell you and point you in the right direction. If we are, we'll leave the call with a clear plan to get you up and running.
TIMING
When to engage
A questionnaire came back with an AI section you cannot answer.
Your SOC 2 report does not cover training use, model provenance, or subprocessor chains, and the buyer has noticed.
A buyer or investor named ISO 42001.
Certification takes months, so the moment it appears in your pipeline the clock has already started.
You sell into the EU, or your customers do.
Transparency obligations are already live. Your buyers also carry deployer obligations, which is why their questions got harder.
You are moving from pilots to production contracts.
A proof of concept gets waved through. A production contract goes through the full review, and that is where deals stall for a quarter.
FRAMEWORKS
Frameworks we run for healthcare
SOC 2 Type I and Type II
The baseline enterprise buyers assume you have
ISO 42001
The certifiable AI management system standard. What buyers in regulated sectors increasingly ask for by name.
HIPAA
If your product touches patient data.
HOW WE WORK
How we work together
01
Discovery call (30min)
What the buyer asked for, what your product does with their data, and the real deadline.
02
Scoped proposal
Fixed scope, timeline, and price within a few days. No open-ended hours.
03
Kickoff
We map what actually happens to customer data before anything else. Every questionnaire answer depends on getting this right, and it is usually where the surprises are.
04
Delivery
We write the documentation, answer the diligence, and work alongside your engineers on technical fixes. You approve decisions.
05
Ongoing
Model providers change, subprocessors get added, and Type II runs continuously. We stay on or hand over documented processes.
The questions that come up on every first call.
-
Is SOC 2 still enough?
It is necessary and no longer sufficient. Buyers assume it and then ask AI-specific questions a SOC 2 report was never designed to answer, including whether customer data trains your models and who sits in your subprocessor chain.
-
What is ISO 42001 and do we need it?
It is the first international certifiable standard for AI management systems — governance over how AI is built, deployed, and monitored, rather than how data is secured. It is voluntary, but enterprise and regulated buyers increasingly require it contractually. The honest answer on timing: pursue it when a buyer names it, an investor asks for it, or the question keeps recurring across deals. Certifying before anyone asks spends real money on a document nobody is checking yet.
-
How long does ISO 42001 take?
Roughly six to twelve months from a standing start. If you already hold ISO 27001, expect that to drop by around a third to a half, because the management system structure and risk methodology are shared.
-
Does the EU AI Act apply to us?
Probably in some form if your output reaches the EU. The transparency obligations under Article 50 — telling people they are interacting with an AI system, labelling AI-generated content — took effect on 2 August 2026 and are live now. The heavier high-risk regime was deferred by the Digital Omnibus: December 2027 for standalone Annex III systems and August 2028 for AI embedded in already-regulated products. The deferral covers the high-risk obligations, not everything, and penalties reach €35 million or 7% of global turnover.
-
Our model provider is compliant. Does that cover us?
No. Their terms govern what they do with data you send them. Your buyer is asking what you do, which provider terms you have actually selected, and whether tenants are isolated from each other. That is your programme to document.
Book a discovery call
Thirty minutes on what is blocking the deal, what you have in place, and when you need it. You leave with a recommended engagement level.