Measure AI risk before it reaches production
We assess each AI use case against security, privacy and regulatory risks, then give you a ranked list of what to fix, what to accept and what to stop.
What we see in most companies
These are the gaps we find most often when we start. Each one is fixable with the right owner and a plan.
- Sensitive or personal data flowing into model prompts and logs
- Agents with more permissions than their task needs
- Model and dataset supply-chain tampering
- Customer and regulator questions you can't answer yet
How TokenAegis delivers AI Risk Assessment
Threat modelling
Map data flows, trust boundaries and tool calls for each AI system, using MITRE ATLAS techniques.
Privacy impact
Check personal-data handling against PDPA obligations and your customers' contract terms.
Control gap analysis
Compare current controls with ISO/IEC 42001, NIST AI RMF and OWASP LLM Top 10.
Risk register
Rate each finding by likelihood and impact, with an owner and a target date.
What you receive
Everything is written for your business, in plain language, and yours to keep.
- AI risk assessment report with an executive summary
- Threat model diagram for each system in scope
- Prioritised remediation plan (30 / 60 / 90 days)
- Board-ready one-page risk summary
From first call to handover
- Discovery call30 minutes to understand your business, systems and deadlines.
- ScopingA fixed-fee proposal with clear deliverables, usually within 3 business days.
- DeliveryHands-on work with your team, with weekly check-ins.
- HandoverReports, evidence and a plan your team can keep running.
Other AI Security services
Talk to a CISO this week
Tell us where you are with security and AI. In 30 minutes we'll show you what we'd fix first, and what it would cost.