Find out how well your organisation is defending the AI it already uses, and where to act first.
A free 28-question self-assessment for the person who owns AI security — often alongside every other job. It scores eight areas, from shadow AI to board reporting, and returns a maturity band with priority actions. With it comes a working toolkit: registers, policy templates, vendor checks, incident runbooks, and board packs. The assessment runs in your browser. Your answers never leave your device.
Two free ways to see if the toolkit fits.
1. Take the free assessment
28 questions across eight areas: AI inventory and shadow AI, vendor and model supply chain, prompt injection, data protection, access control, monitoring, incident readiness, and governance. About 12 minutes. You get a maturity band and priority actions. Runs in your browser. No email required; nothing is sent anywhere.
Take the free assessment →2. Read the free guide
"The First 5 AI Security Fixes" walks through the five actions that close the most common AI security gaps, in the order worth doing them, with time estimates. Plain English, and yours to keep.
Read the free guide →This is for securing the AI your organisation already uses.
It scores how you govern AI (from shadow AI to board reporting), not your general IT security or your patching programme. If what you really need is a plain-English security baseline, start with the SMB Security Assessment; if your focus is scanning, triage, and patching, that's Vulnerability Management.
Three tiers: one for a single owner, one for the first AI security lead, one for programmes at scale.
- The 28-question assessment with per-area scoring and a printable report
- AI Tool Inventory Starter Register, with a filled-in worked example
- AI Acceptable-Use Policy template — the one-page version staff will actually read
- Shadow-AI Discovery Checklist — where unsanctioned AI hides, and a four-week plan to surface it
- Small-Team AI Vendor Check — the ten questions worth asking an AI vendor
- What's Safe to Paste? — the AI data-handling quick guide staff actually ask for
- Staff AI Onboarding Briefing Card — the one-page AI ground rules for every new joiner
Enough if AI security is one of many hats and you just need to see and contain the risk.
Buy Solo — $49- AI Vendor Due-Diligence Questionnaire with a scoring rubric and decision thresholds
- AI Incident Response Runbook Pack — three working runbooks, from prompt-injection exploitation to vendor model failure
- AI Asset Register and model-risk classification worksheet
- Prompt-Injection Defence Checklist — eight layered defences, with an honest note on what each can and cannot do
- AI Output Validation & Guardrail Checklist — the controls between a model's answer and anything that acts on it
- Everything in Solo
Choose this once a policy isn’t enough: you need a governed, repeatable programme.
Buy Team — $99- Ten-dimension AI security maturity rubric — the deep version of the free assessment
- AI governance and board reporting pack
- Tabletop exercise kit — three facilitator-scripted scenarios with role cards
- Model-risk audit checklist and a plain-English regulatory readiness map
- Secure AI Development Lifecycle Checklist — security gates from data sourcing to monitoring
- LLM Application Logging & Monitoring Checklist — what to log around a model, and which signals matter
- Everything in Solo and Team
- Single-organisation licence
Step up here when a board and regulators need evidence on a cadence, not just controls.
Buy Enterprise — $299Every tier is a one-time purchase with a 30-day money-back guarantee, no questions asked, and free updates while the toolkit is in our catalogue.
How access works: the documents in every tier are downloads you keep, and the assessment app unlocks in your browser with the licence key from your purchase receipt — no account, no sign-in. The key activates on up to 3 devices on the solo tier, 7 on the middle tier, and 13 on the top tier.
The companion books: the field guide and the workbook behind this toolkit.
The books teach the discipline; the toolkit does the work with you. The AI Security Field Guide covers the judgement; the Operator's Workbook carries the templates.
If this is your situation, one of these usually is too
Vulnerability Management
AI tools are one slice of your estate. The Vulnerability Management toolkit covers the rest — scanning, triage, patching, and reporting.
SMB Security Assessment
If your organisation also needs the everyday security baseline — access, backups, patching — the SMB Security Assessment covers the controls cyber insurers ask about.
The situation this toolkit is built for, written up.
Before your team pastes customer data into a chatbot — ~9 min read.