Black Bay Security

The Deepwater framework

Five pillars, one score you can compare.

Deepwater is our assessment model for AI risk. Every question maps to a pillar and cites a recognized standard, so a finding is never just an opinion, and a second assessment can be measured against the first.

  1. What we are securing

    AI Landscape

    Inventory of every model, API and agentic system, with data sensitivity classified and a named business owner. Model provenance, agentic permission boundaries and tested kill switches.

  2. Where you stand today

    Readiness

    Governance and risk ownership, identity and access, third-party and vendor risk, and how AI risk is expressed in business terms on the enterprise risk register.

  3. Protecting the asset and the methodology

    Model Security

    Model scanning, runtime protection, lifecycle traceability and red teaming. Secure development lifecycle practices applied specifically to AI, not inherited from general application security.

  4. Putting security into practice

    Operations

    AI-aware detection and response, output monitoring for drift and adversarial manipulation, and incident playbooks distinct from conventional IR.

  5. Building to last

    Resilience

    Data protection, infrastructure security and recovery planning, so the AI estate withstands disruption and business continuity holds.

Anchored to standards, not to us

Every question in the catalog carries a citation. When a finding says your agentic systems lack tested permission boundaries, it points at the control that says so.

  • CSA AICM
  • NIST AI RMF
  • MITRE ATLAS
  • MITRE ATT&CK
  • OWASP LLM Top 10
  • ISO 27001 / 27002
  • NIST CSF 2.0
  • CIS Controls v8.1
  • NIST SSDF
  • EU AI Act

Scored so it is repeatable

Each pillar scores independently and rolls into a single index. Because engagements are locked to a versioned question set, scores do not move when the catalog changes. A year later, the comparison still means something.

Talk through an assessment