The free read-out and the Forensic Triage work at the machine level. A Forensic Audit is the same kind of examination at organizational scope — collection under a written scope, and a chain of custody that holds up if the findings are ever challenged. From $5,000, scoped. Available after a Forensic Triage.
| Free read-out | Forensic Triage | Forensic Audit | |
|---|---|---|---|
| Price | Free, one laptop | $2,500 (first three clients $1,500) | From $5,000, scoped |
| Covers | One laptop | Up to 5 laptops | Scoped in writing |
| Who collects | You, with our open-source scanner | You, with a collection script we send you | Collection under a written scope |
| What we receive | The scanner's output (folder names and dates) | The files the script collects, after you preview and remove anything you choose | Artifacts defined in writing beforehand |
| What it answers | Which AI tools are present, when each was last active, what evidence expires and when | When AI was used, which documents were open at the time, what the vendor's terms said that day, graded 1 to 5 with limitations first | The same, across more machines, with chain of custody |
| Delivery | Within 2 working days | 5 working days after we receive the file | Agreed in the scope |
| We access your machines | Never | Never | Only within written scope |
| Your data | Stays with you except the output you send | Encrypted transfer, analysed on an offline machine, deleted within 30 days with a certificate | Same |
For IT providers: you can resell the Forensic Triage at your own price. Ask us for the terms.
Chrome and Edge keep browsing history (about 90 days) and one storage folder per website. Together they show which AI services were reached, and when.
Windows records which files were recently opened. Matched against AI visits, this is how we assess whether a business document was likely involved.
Locally installed AI applications write files recording installation and use. What each one keeps varies by product and version, so we establish it per engagement rather than assuming it.
We report what the evidence supports, and nothing beyond it. We do not reconstruct what anyone typed. Every finding carries a 1 to 5 confidence grade, and its limitations come before its conclusion.
Scope is agreed in writing before collection begins, and nothing outside it is examined.
A triage narrows the question from every laptop, every file and every month to the specific people, documents and hours that matter, and tells you what to do about each.
| Grade | What we found | What you do next |
|---|---|---|
| 1. Present | An AI tool is on the machine, with no dated use | Nothing urgent. Cover it in your AI policy |
| 2. Used | The dates and times the tool was used | Check whether that use was allowed under your policy |
| 3. Overlap | A business document was open within 15 minutes of AI use | Review that document's sensitivity |
| 4. Close match | The document was opened within 5 minutes before AI use, confirmed by two independent records | With your counsel's guidance, ask that person for their own data export from the AI vendor. We analyse it and confirm or rule out the finding |
| 5. Confirmed | The export shows what was submitted | Your counsel has the record needed to decide what comes next |
We grade strictly. A grade rises only when an independent record confirms it, and anything that contradicts a finding is reported with it. If chats were deleted before the export, they won't appear in it, and we say so.
Every artifact is logged from the moment it's collected — what it is, where it came from, who handled it, and when — following SWGDE and NIST documentation standards. If a finding is ever challenged, the custody record is what makes it defensible.
Collected artifacts are destroyed 30 days after final delivery unless you request otherwise in writing. You receive a certificate of destruction confirming it happened — your sensitive forensic data doesn't sit on our systems indefinitely by default.
2–4 pages written for non-technical readers. Findings, risk level, regulatory exposure, and recommended immediate actions.
Complete documentation of every finding with evidence citations, artifact source, timestamp, a 1-to-5 grading, and its stated limitations. Written for General Counsel and CISO review. Structured for attorney work product delivery on request.
A visual map of AI exposure by department and tool. Communicates where risk is concentrated and which teams need policy attention.
Finding-by-finding mapping to HIPAA, SOX, GDPR, and EU AI Act obligations. Where a gap is present, we document the specific provision, the finding that triggers it, and the disclosure risk.
Prioritised list of recommended actions ranked by risk severity and implementation complexity, with 30/60/90-day suggested milestones.
The collection method, the custody log, and the destruction certificate once evidence is destroyed. Required for any subsequent regulatory filing or litigation use of the findings.
It requires collection under a written scope, and we think that should be earned rather than sold. If you haven't run the free read-out or a Forensic Triage yet, that's where to start.