Capabilities

Four engagements. Nothing open-ended.

Every engagement is fixed in scope and price, begins with a one-page proposal, and delivers something usable inside the first ten days. Pricing is published because you should be able to decide whether this is worth a conversation before you have one — and because a fixed price is a commitment: the number in the proposal is the number on the invoice.

Flagship engagement

AI Security Readiness Assessment

A defensible answer to the question your board has already asked — delivered in three weeks, in language your auditors and insurers recognise.

  • AI usage inventory — every tool in use, sanctioned or shadow, and the data each one touches
  • Threat model of your highest-stakes deployments: prompt injection, data disclosure, excessive agency
  • NIST AI RMF gap assessment — scored across Govern, Map, Measure, and Manage
  • Governance policy pack — acceptable use, vendor review, agent deployment standards, incident response
  • Prioritised roadmap plus an executive readout and a board one-pager
For CISOs, CTOs, and heads of engineering at organisations of 200–2,000 people deploying copilots or shipping AI features.
Retained leadership

Fractional Security Leadership

The security function without the headcount — a senior leader accountable for the roadmap, the audit, and the answers your customers demand.

  • Roadmap ownership and quarterly priorities, reported at board level
  • SOC 2 and ISO 27001 stewardship — policy programme, evidence cadence, auditor management
  • Customer security questionnaires answered quickly, so enterprise deals stop stalling
  • Vendor and architecture decisions from someone who has operated these platforms at scale
  • An escalation point when something breaks, and a monthly report leadership actually reads
For venture-backed companies without a security hire, organisations between security leaders, and managed service providers needing CISO-tier depth for their clients.
Diagnostic

Third-Party Access Audit

Know precisely what has access to your data — and what to revoke first. A bounded, self-contained review with a fixed fee and no commitment beyond it.

  • Complete inventory of applications holding OAuth access — publisher, scopes, users, last activity
  • Risk classification of every application, with the reasoning stated in plain language
  • A revoke-first list your administrator can execute in an afternoon
  • Control mapping to SOC 2 and HIPAA — the evidence page your auditor asks for
  • A 60-minute findings session with your team
For any organisation on Google Workspace or Microsoft 365 — most valuable ahead of a SOC 2 audit or following a period of turnover.
Continuous assurance

Roust — Continuous Access Assurance

A point-in-time audit begins ageing the day it is delivered. Roust keeps the answer current, and keeps the evidence filed.

  • Scheduled scanning of your tenant for newly granted third-party access
  • Alerts on unverified publishers, excessive scopes, and departed-employee authorisations
  • An audit-ready monthly record — including the quiet months, because documented absence of risk is the point
  • Offboarding verification on demand
Delivered by Axiomeer — our own service, not a third-party licence resold at a margin. Read-only scopes · encrypted at rest · 90-day retention · revocation entirely in your control. Explore Roust
A note on scope

What we deliberately do not do.

Axiomeer does not perform penetration testing, operate a security operations centre, or resell tooling. Those are excellent services — they are simply not ours, and a firm that claims all of them delivers none of them well. Where you need them, we will point you to people we would use ourselves.

The prices above describe the engagements as scoped. Regulated environments, multi-entity groups, and organisations above roughly two thousand people are quoted individually — the method is the same, the scope is not.

See anonymised excerpts from these deliverables →

Not sure which fits

Start with the question, not the engagement.

Tell us what is driving this — a board question, an audit date, a customer demand — and we will point you to the right engagement, or tell you plainly if there isn't one.