[01]
AI is not on the asset register
Models, APIs and agentic systems get stood up outside the change process. A control framework that never enumerated them cannot tell you what they touch or who owns them.

AI Security Assessment
Structured assessment across five pillars, scored against a versioned rubric and cited to recognized standards. Every finding gets an owner and a tracked remediation task, so the second review can be measured against the first.
Every question cited to a recognized standard
The gap
Existing frameworks were written for systems that do not improvise. The controls still matter, but on their own they do not describe how an organization builds, buys and operates AI.
[01]
Models, APIs and agentic systems get stood up outside the change process. A control framework that never enumerated them cannot tell you what they touch or who owns them.
[02]
Delegated tool access grows quietly. Permission boundaries go untested, kill switches go unexercised, and the blast radius is discovered during the incident rather than before it.
[03]
A point-in-time report ages out within a quarter and the next one uses a different rubric. Nothing can be compared, so nothing can be shown to have improved.
The Deepwater framework
What we are securing
Inventory of every model, API and agentic system, with sensitivity classified, provenance documented and a named business owner.
Where you stand today
Governance and risk ownership, identity and access, vendor risk, and whether AI risk reaches the enterprise register in business terms.
Protecting the asset
Model scanning, runtime protection, lifecycle traceability and red teaming, with secure development practices applied to AI specifically.
Security in practice
AI-aware detection and response, output monitoring for drift and manipulation, and incident playbooks distinct from conventional IR.
Building to last
Data protection, infrastructure security and recovery planning, so the AI estate withstands disruption and continuity holds.
Each pillar scores independently and rolls into a single index. Engagements lock to a versioned question set, so a score from a year ago still means the same thing.
Read the framework →How it runs
Most AI security reviews end in a document. This one ends in a score, an owner for every finding, and a plan you can measure against next time.
How it worksA pre-flight establishes data sensitivity, system connections and agency, external providers and deployment architecture. It sets the depth of everything after it.
The Deepwater catalog across five pillars. Every question cites a standard; every answer carries a status, an owner and evidence.
Deterministic scoring per pillar and overall, locked to a versioned question set so the number does not drift when the catalog changes.
Findings become owned tasks on the Deepcurrent platform, so progress is visible between assessments rather than rediscovered at the next one.
Questions
It depends on what the pre-flight surfaces. A focused estate with a handful of models is a very different engagement from an organization running agentic systems across several business units, and we scope it before quoting rather than after.
A short call is enough to scope an assessment and tell you whether we are the right fit. If we are not, we will say so.