DOC AI-READINESS-ASSESSMENT / PRICE $950 / DELIVERY 5 BUSINESS DAYS / MODE ASYNC — NO CALLS
Governance assessment · engineering teams · self-serve

Your engineers adopted AI coding tools.
Your governance didn't.

97% of software teams now use AI coding assistants. Fewer than 1 in 3 govern how. The governed third ships faster and safer — the rest are accumulating risk at AI speed.

Full refund within 7 days if no actionable finding Nothing retained beyond delivery No call, no meeting, no scoping
97% of engineering teams now use AI coding assistants
30% have a fully governed approach to that usage
65% of organizations say AI assistants increase risk
Self-diagnosis · 60 seconds

Does any of this look familiar?

[!]

CI failures get re-run until they go green.

[!]

AI attribution lives in PR comments — if anywhere.

[!]

Any PR can edit your CI config, including AI-generated ones.

[!]

Nobody has re-checked test coverage since AI tools arrived.

[!]

Your AI acceptable-use policy exists in heads, not writing.

[!]

PRs got bigger and review time didn't.

Two or more true? Your team is operating at higher AI autonomy than its validation quality has earned — the gap where incidents live. That gap is exactly what the assessment measures.

What you get

One fixed price. Three artifacts. Nothing left implicit.

Delivered in 5 business days from a structured intake — no discovery call, no scoping meeting.

01

Readiness Assessment Report

Your CI/CD configs, workflow files, and a structured questionnaire, analyzed against validation coverage, review-gate integrity, autonomy readiness, and guardrail gaps. Every finding follows a fixed contract — observation, organizational risk, steps to validate it yourself, remediation, and references to recognized authority — plus a verified-in-place section documenting the controls you already have right. No finding asks for your trust.

A finding without references is opinion — we don't ship opinion
02

Tailored Adoption Playbook

An autonomy-laddering plan for your team specifically: which work AI agents should own now, what objective validation must exist before you extend that further, and the review-gate policy that keeps velocity without the incidents.

03

Guardrail Config Templates

Protected-path rules, agent-permission boundaries, and CI validation gates, ready to adapt directly into your repos. Implementation stays yours — you get the map and the tools, your team keeps control.

How a finding actually reads

Not a checklist. A claim you can check.

One real finding from the sample report, in full — this is the format every finding in your report follows.

F-07 — Validation pipeline modifiable by the code it validates SEVERITY: CRITICAL
Observation

No protected paths exist. .github/workflows/, CI config, and deployment files are editable by any PR — including AI-generated ones. No CODEOWNERS files present.

Risk to the organization

The validator is not independent of the validated. A single careless or compromised PR can weaken the checks that gate it — your tests are only as trustworthy as the least-reviewed PR that could touch them.

Steps to validate
  1. Open a test PR editing your CI config to skip the test job — observe nothing distinguishes it from a normal PR (revert immediately).
  2. Confirm the absence of CODEOWNERS entries for .github/ and infra paths.
Remediation

CODEOWNERS on workflow and infra paths, owned by platform leads; branch protection requiring code-owner review on those paths.

References

OWASP Top 10 CI/CD Security Risks — CICD-SEC-4: Poisoned Pipeline Execution · SLSA v1.0 — build integrity · NIST SP 800-204D

Every finding in your report — all of them, not a sample — is structured exactly this way.

Grounded in recognized standards

Findings and recommendations are assessed against leading industry frameworks — cited per finding, so your team can go to the source.

NIST SSDF (SP 800-218) OWASP CI/CD Top 10 OWASP LLM Top 10 SLSA Supply-Chain Levels ISO/IEC 42001 Peer-reviewed research
Process

How it works

1

Buy

Fixed price, standard terms, no custom paperwork.

2

Intake

15-minute structured questionnaire. Repo access optional, never required.

3

Analysis

Configs assessed against the governance rubric — no meeting needed.

4

Delivery

Report, playbook, and templates in your inbox within 5 business days.

This assessment is executed by an AI agent pipeline with structured validation gates, adversarial review, and expert human sign-off before release.

That's not incidental — it's the same architecture the playbook teaches you to build. The delivery mechanism is the demonstration. Full methodology is documented in the sample report. Analysis is confined to the materials you provide, and nothing is retained beyond delivery.

Who it's for: engineering leaders at 10–100-engineer software companies where AI coding tools arrived faster than the policy for them.

If your AI-generated code is flagged by hand in PR comments — or not flagged at all — this is for you.

FAQ

Before you buy

Do I have to give you repo access?

No. The questionnaire tier requires only the CI/workflow configs you paste or upload. Read-only access deepens the findings but is entirely optional.

Is there a call?

No. Async by design — purchase, intake, delivery, and follow-up questions all run without a meeting. Questions are answered by email within one business day.

What are the terms?

Standard terms at checkout. We don't execute custom NDAs at this price point — the questionnaire input tier exists specifically so you never have to share anything sensitive to get value from the assessment.

What if the report doesn't help?

If it contains no finding you consider actionable, say so within 7 days for a full refund.

Know where you stand before it costs you.

$950 — less than a single consultant day, for a complete governance readout your team can verify finding-by-finding. 5 business days. No calls.

Full refund within 7 days if no actionable finding Nothing retained beyond delivery