Black Bay Security

AI Security Assessment

Know where your AI is actually exposed

Structured assessment across five pillars, scored against a versioned rubric and cited to recognized standards. Every finding gets an owner and a tracked remediation task, so the second review can be measured against the first.

5
Assessment pillars
10
Standards referenced
100%
Findings with an owner

Every question cited to a recognized standard

  • CSA AICM
  • NIST AI RMF
  • MITRE ATLAS
  • OWASP LLM TOP 10
  • ISO 27001
  • NIST CSF 2.0
  • EU AI ACT

The gap

Why conventional security reviews miss AI

Existing frameworks were written for systems that do not improvise. The controls still matter, but on their own they do not describe how an organization builds, buys and operates AI.

[01]

AI is not on the asset register

Models, APIs and agentic systems get stood up outside the change process. A control framework that never enumerated them cannot tell you what they touch or who owns them.

[02]

Agents hold authority nobody scoped

Delegated tool access grows quietly. Permission boundaries go untested, kill switches go unexercised, and the blast radius is discovered during the incident rather than before it.

[03]

The review is not repeatable

A point-in-time report ages out within a quarter and the next one uses a different rubric. Nothing can be compared, so nothing can be shown to have improved.

The Deepwater framework

Five pillars, one score you can compare

What we are securing

AI Landscape

Inventory of every model, API and agentic system, with sensitivity classified, provenance documented and a named business owner.

Where you stand today

Readiness

Governance and risk ownership, identity and access, vendor risk, and whether AI risk reaches the enterprise register in business terms.

Protecting the asset

Model Security

Model scanning, runtime protection, lifecycle traceability and red teaming, with secure development practices applied to AI specifically.

Security in practice

Operations

AI-aware detection and response, output monitoring for drift and manipulation, and incident playbooks distinct from conventional IR.

Building to last

Resilience

Data protection, infrastructure security and recovery planning, so the AI estate withstands disruption and continuity holds.

Each pillar scores independently and rolls into a single index. Engagements lock to a versioned question set, so a score from a year ago still means the same thing.

Read the framework →

How it runs

A review you can run twice

Most AI security reviews end in a document. This one ends in a score, an owner for every finding, and a plan you can measure against next time.

How it works
  1. [01]

    Scope

    A pre-flight establishes data sensitivity, system connections and agency, external providers and deployment architecture. It sets the depth of everything after it.

  2. [02]

    Assess

    The Deepwater catalog across five pillars. Every question cites a standard; every answer carries a status, an owner and evidence.

  3. [03]

    Score

    Deterministic scoring per pillar and overall, locked to a versioned question set so the number does not drift when the catalog changes.

  4. [04]

    Remediate

    Findings become owned tasks on the Deepcurrent platform, so progress is visible between assessments rather than rediscovered at the next one.

Questions

What people ask first

It depends on what the pre-flight surfaces. A focused estate with a handful of models is a very different engagement from an organization running agentic systems across several business units, and we scope it before quoting rather than after.

Find out what your AI risk actually looks like

A short call is enough to scope an assessment and tell you whether we are the right fit. If we are not, we will say so.