Your staff already use AI.
We settle the control question first.
We set up Copilot in the Microsoft 365 your firm already pays for. Before anyone uses it, we fix who can open which files. You get a dated record of every safeguard.
Who we work with
Firms that hold information other people trusted them with. The controls are the same in every one. The rules differ, and each engagement is mapped to the ones that apply.
The Safeguards Rule also reaches collection agencies, finance companies, credit counselors and dealerships that arrange financing. The same engagement applies.
How each engagement is mapped →The chain we work along
Every engagement follows the same sequential order.
The rule that binds the firm, read against its primary source.
The single "you must" inside it, in plain English, with the threshold that switches it on or off.
What the firm actually does about it, delivered inside the Microsoft 365 tenant it already pays for.
The artifact that proves the control ran, with the date it was observed and the window before it goes stale.
What a partner hands to the person asking. Never a certificate. A dated record of what was in force.
What a deployment leaves behind
Two agents every firm gets, and one built for the work your practice does. Each hands back a draft for a person to check. None of them sends anything.
Firm Assistant
Morning Brief
Return Reviewer
Review Prep
Matter Brief
File Checker
Practice Desk
Clean Room
Advisory, oversight and compliance
Three ways we work. Every one priced in writing before it starts.
Secure AI Integration
Copilot set up in the Microsoft 365 you already pay for, with file access fixed first.
- File access review
- Data loss warnings for staff
- Two firm-wide agents and one practice agent
- Staff training
- Usage logging and an AI statement for your clients
- A dated handover report
A few weeks, done remotely
Fixed fee
AI Oversight and vCISO
A named advisor who answers for your security settings in writing and keeps the AI environment growing. You keep your IT provider.
- New agents reach your tenant in the quarter they ship
- New gallery prompts and notes on what Microsoft changed, as they are written
- Sign-in and access controls, and device and update checks
- Client and insurer questionnaires answered, with the evidence
- A quarterly review with your leadership
Compliance Documentation
The written security program a regulator expects, written for your firm, with the gaps named.
- Written Information Security Program
- Incident response plan and a practice run
- Vendor register
- AI use policy
- Staff training with completion records
Three weeks
Fixed fee
Not sure where to start? Begin with the Baseline Security Assessment: two weeks, read-only, nothing changed. You get a written list of gaps, each with a recommended owner and a target date. The fee is credited in full against the engagement that follows, if it starts within 90 days.
