COMPARE

Know where your AI system stands and what to fix first.

Get a reviewed AI Security Readiness Assessment for one defined system, with prioritised findings, control and evidence gaps, and a remediation backlog your team can work through.

A$3,500One defined AI system · Five business days from payment

Free. No account or sales call is required to receive the fit result.

What the report looks like

The executive summary page from a fictional example, so you can see the output without a customer result being shown. Its decision reads “Not recommended for production in its current state”, followed by the three risks that drive it and the three actions that would change it.

Executive summary: decision and prioritiesFictional example
Executive summary page from a synthetic trusec.ai AI security assessment, showing the assessment decision, classification and priority actions.
Finding

Risk 1, “Overscoped connected content”, names the weakness in one line: connector permissions may expose records beyond the intended audience. It sits first because it drives the decision.

Supporting evidence

The decision box says what must be demonstrated before progression: connector scope, data permissions and audit evidence. Risk 2 is that gap stated plainly: prompt, retrieval and connector events not yet shown as reviewable evidence.

Recommended action

Priority action 1, “Prove least-privilege connector scope”, carries its owner (the M365 platform team) and the evidence that closes it (an access review and test results). The full backlog continues in the report.

The report overview lists what every section contains.

What you use it for

An enterprise customer's security review is asking about your AI feature.

Use reviewed findings, with the supporting facts and assumptions made clear, to support your responses to an enterprise customer's AI security review.

You are about to put an agent with tools and permissions into production.

See the control gaps and the abuse paths in the architecture, and get the fixes ordered by decision impact before launch.

A board or committee wants to know whether one system is under control.

Give them a readiness decision, the material risks and the conditions on one page.

You are deciding whether, and where, to spend on testing or certification.

Use the findings to scope a red team to the paths that matter, or to see what to fix before an auditor arrives. This is one use of the report, not a requirement.

Who reviews it, and the scope

An authorised trusec.ai reviewer approves every report before it is released and is accountable for that release. The review checks that each finding rests on the facts you confirmed, that assumptions are labelled as assumptions, that the evidence still needed is named, and that the actions are ordered by decision impact. The technical controls behind that gate, including reviewer authentication and package integrity, are on the security page.

Your remedies are written down before you pay. For a change of mind, you may request a full refund before submitting your intake. After submission, full or partial refunds are discretionary based on work completed and the circumstances. If trusec.ai cannot deliver, we refund the unperformed portion, or the full payment if no useful service was supplied. Refunds return to the original payment method. Your Australian Consumer Law rights are unaffected. Contact support@trusec.ai. The full assessment terms apply.

Scope in one statement. One defined AI system at one point in time, assessed from the facts you confirm in a structured intake and documents you provide for extraction, with no secrets, credentials or production access. Penetration testing, code review, runtime monitoring, certification and assurance sign-off are not included. A changed system or a second system needs a separate assessment.

How it compares with the other ways to get AI security evidence

Six routes answer different questions and are often used together. Each card shows the short version; open it for what you receive, what it needs, its limits and the published price bands. Ranges observed 16 September 2026; third-party figures are in their authors' own currencies and are not quotes.

Self-assessment questionnaire
For example Vanta's AI Security Assessment template download
When you need it
Starting an inventory, no budget yet
Indicative price
No price stated (download)
Time
Hours
What you receive, what it needs, limits and price bands
What you receive:
Your own answers to a standard question set, mapped to frameworks.
What it needs from you:
Your time.
Limits:
Nobody reviews your answers; it says nothing about your specific architecture.
Published pricing:
The cited page offers a form download and states no price.
AI Security Readiness Assessment
trusec.ai · one defined system at one point in time
When you need it
A decision on one system is due
Indicative price
A$3,500
Time
Five business days from payment
What you receive, what it needs, limits and price bands
What you receive:
A reviewed report: readiness status, prioritised findings, threat model summary, control and evidence gaps, remediation backlog, walkthrough, up to three written questions.
What it needs from you:
A structured intake of facts you confirm plus documents for extraction; no secrets, credentials or live access.
Limits:
No penetration testing, code review, runtime monitoring, certification or assurance sign-off. See the scope statement above.
Published pricing:
Fixed price, published on the pricing page.
AI security assessment from a platform vendor's services team
For example CrowdStrike's AI Systems Security Assessment or Palo Alto Networks' Unit 42 AI Security Assessment
When you need it
A vendor-led engagement, from discovering AI use across the environment to application-level review
Indicative price
Contact sales; no price published
Time
Not published
What you receive, what it needs, limits and price bands
What you receive:
CrowdStrike: discovery of AI use, including shadow AI, through its platform telemetry; expert evaluation of architecture, data access, configurations and user controls; a summary report with technical findings, strategic recommendations and prioritised actions; stakeholder workshops. Unit 42: plan, explore, evaluate and activate, ending in a threat-informed report and a risk-prioritised roadmap.
What it needs from you:
A consulting engagement scoped with the vendor. CrowdStrike's discovery uses its platform telemetry; Unit 42's steps include workshops with your team.
Limits:
Neither page publishes a price or a duration. Scope is agreed in the engagement; the pages describe discovery, architecture and configuration review, application threat modelling and governance.
Published pricing:
Neither CrowdStrike nor Palo Alto Networks publishes a price or a duration for the service; both pages end in a contact request.
Automated adversarial scan
Automated red-teaming tools and services
When you need it
Testing evidence for one application, quickly
Indicative price
From about US$5,000
Time
Days to two weeks
What you receive, what it needs, limits and price bands
What you receive:
Results from adversarial probes against the live application; the cited tiers list compliance-mapped, audit-ready findings with human oversight from the standard tier.
What it needs from you:
API or interface access to the running system.
Limits:
Scope and exclusions vary by package; check the quote for what is reviewed beyond the probes.
Published pricing:
AI Vyuh publishes US$5,000–10,000 (quick scan), US$10,000–20,000 (standard) and US$20,000–25,000 (deep dive with retest).
Human-led AI red team or penetration test
Security consultancies and specialist AI testing firms
When you need it
Deep technical assurance before a high-risk release
Indicative price
From about US$8,000 (survey)
Time
One to eight weeks
What you receive, what it needs, limits and price bands
What you receive:
Findings with reproducible payloads and remediation guidance; a retest where the engagement includes one.
What it needs from you:
Scoped access and time from your engineers.
Limits:
Tests what is in scope on the day; no management-system view.
Published pricing:
A published survey citing Mindgard data: simple chatbot US$8,000–15,000; RAG US$15,000–35,000; tool-using agent US$25,000–60,000; multi-agent US$50,000–150,000 and above; MCP-connected agent ecosystem from US$60,000. Rate cards: Pentest Testing Corp from US$9,500; DSE from US$18,000 with a US$12,000–18,000 fee band on the same page.
Certification
ISO/IEC 42001, or AIUC-1 for AI agents
When you need it
A contract, customer or market requires a certificate
Indicative price
US$15,000–40,000 first year (ISO 42001, small organisation)
Time
Months
What you receive, what it needs, limits and price bands
What you receive:
An audited AI management system, or a certified agent, from an accredited auditor.
What it needs from you:
Implementation, documentation and audit time across the organisation.
Limits:
The scope is the organisation or the agent programme, not a quick answer for one system.
Published pricing:
Compyl: outsourced gap assessment US$5,000–20,000 (small US$0–8,000, mid-size US$5,000–15,000, enterprise US$10,000–25,000); typical first-year total US$15,000–40,000 for a small organisation with one or two AI systems in scope. AIUC-1 publishes no price on its site.

Questions buyers ask

Is this a penetration test?

No. The assessment reviews one defined system from the facts you confirm and the architecture you describe. It does not test the running system, review code or monitor it in production, and the report says so. If your requirement is testing evidence, budget for testing as well.

Why is it A$3,500 when testing engagements start near US$8,000?

Because the scope is different, not discounted: one system, a structured intake, no testing, five business days, a reviewed report. If your requirement is adversarial testing, this is not it, and the free fit check exists so you find that out before paying.

Does it replace ISO 42001, SOC 2 or a certificate a customer asked for?

No. Certification audits a management system across an organisation and only an accredited auditor can issue it. The assessment tells you where one system stands and what to fix first.

Will an enterprise customer's reviewer accept it?

That is their decision. The report states its scope, the facts it relies on, the assumptions it makes and what was not examined, so a reviewer can judge what it covers. If you are unsure, ask them what evidence they accept before you buy.

Start with the free fit check to confirm your system is within scope; no account or sales call is required to receive the result. Check assessment fit · See the full inclusions

Sources for the published ranges