Shadow AI usage
Employees are using AI tools that IT and security never approved. Customer data, source code, and internal documents are being entered into platforms with no oversight.
Cyberneza translates requirements into security architecture, control designs, remediation plans, implementation procedures, configuration guidance, and validation criteria. Your technical teams execute approved changes through your organization’s established change-management process, preserving internal ownership and production-change authority.
ChatGPT, Copilot, Claude, Gemini — your team is already using these tools. Customer data, source code, and internal documents are being entered into platforms you may not control. We find the exposure, assess the risk, and tell you exactly what to do about it.
CISSP · CRISC · CCSK · CCZT | 29+ years in cybersecurity | Fixed-fee | Veteran-owned
Most SaaS teams adopted AI tools before security had a chance to evaluate them. That gap is now a real business risk.
Employees are using AI tools that IT and security never approved. Customer data, source code, and internal documents are being entered into platforms with no oversight.
A developer pastes an API key into Copilot. A sales rep enters a customer list into ChatGPT. A support agent feeds ticket data into a summarizer. That data may be logged, retained indefinitely, or used to train the next version of the model — and you have no record it happened.
Most companies have no written policy for AI usage. No guidelines on what data can be entered, which tools are approved, or who is responsible for oversight.
Most AI vendors retain input data for some period. Some use it to train future models. Few companies have reviewed the actual terms. If your data enters a platform that trains on inputs, you may have lost control of that data permanently — and triggered contractual or regulatory obligations you didn't plan for.
We look at how your company is actually using AI — then give you a clear picture of the risk and a prioritized plan to address it.
We identify which AI tools are being used across your organization, by whom, and for what purposes. This includes sanctioned tools, shadow usage, and browser-based AI platforms.
We map what types of data are being entered into AI tools — customer records, source code, financial data, internal documents — and assess the risk of each data flow.
We review AI vendor terms of service, data retention policies, and model training practices to determine whether your data is being used in ways you haven't agreed to.
We evaluate whether your existing policies, controls, and processes adequately address AI usage. We identify what's missing and what needs to be created or updated.
Every engagement produces specific, actionable artifacts:
After the engagement, you have:
Identify exactly which sensitive data — customer records, source code, financial information — is entering AI platforms, and close those specific exposure paths.
Understand which AI vendors retain your data, which may use it for model training, and whether your contracts actually protect you.
Move from "we think people use ChatGPT" to a documented inventory with approved tools, prohibited data types, and clear employee guidelines.
When your SOC 2 auditor or enterprise customer asks "how do you manage AI risk?" — hand them a documented assessment, not a verbal answer.
Auditors are asking about AI. SOC 2 trust services criteria (especially confidentiality and security) now require companies to demonstrate they understand and control how data flows through AI tools. ISO 27001 Annex A controls around information classification and supplier relationships apply directly.
This assessment produces evidence and documentation that directly supports your audit readiness — whether you're starting compliance work or maintaining an existing certification.
Enterprise buyers are adding AI governance questions to security questionnaires. They want to know: what AI tools do you use? How do you control data flowing into them? What policies do you have?
The deliverables from this engagement give you documented answers to those questions — backed by a real assessment, not guesswork.
ISO/IEC 42001 gives organizations a management-system structure for governing AI. Cyberneza helps define AI governance roles, risk processes, policies, controls, and evidence workflows so teams can prepare for customer AI reviews, internal governance requirements, and future certification conversations. For organizations already familiar with ISO 27001, ISO 42001 can extend existing management-system practices into AI governance.
Cyberneza provides ISO/IEC 42001 readiness, implementation, advisory, and coordination support. Certification audits and certification decisions are performed by independent accredited certification bodies.
AIUC-1 is a certification standard built specifically for AI agents, covering security, safety, reliability, privacy, and accountability controls. Where ISO/IEC 42001 governs AI across the organization, AIUC-1 focuses on the agent itself — the questions enterprise buyers now ask when an AI agent touches their data or acts on their behalf. Cyberneza provides control-gap assessment against the AIUC-1 criteria, remediation planning, documentation, and evidence preparation.
Cyberneza provides AIUC-1 readiness and advisory support and coordinates with the accredited auditor you select. Certification involves an independent audit by an accredited AIUC-1 auditor and technical evaluation by AIUC, which issues the certificate. Cyberneza is not an accredited AIUC-1 auditor, does not perform AIUC-1 audits or AIUC technical evaluations, does not issue certificates, and does not guarantee certification outcomes. See AIUC-1 readiness →
Readiness work for ISO/IEC 42001 is done by security and compliance consultancies, not by the certification body itself — a body that audits you for certification cannot also prepare you for it, so the two are always separate firms. That splits the market into three groups: the large audit and advisory practices, the GRC platform vendors and their partner networks, and independent consultancies like Cyberneza.
What separates them is less the standard than the AI part. ISO 42001 is a management system standard — the clause structure will look familiar to anyone who has done ISO 27001 — but the controls in Annex A are about model provenance, data used for training and inference, human oversight, and impact assessment. A provider who can run an ISO management system but cannot tell you where your models get their data will produce a binder, not a program. Ask any candidate to describe how they would inventory the AI already in use across your company, including the tools nobody registered.
Cyberneza is an independent practice run by a cybersecurity architect holding CISSP, CRISC, CCSK v5 and CCZT, and a Cyber AB CMMC Registered Practitioner. We start with shadow-AI discovery and data-exposure analysis rather than with the clause list, because the gap between the AI you have documented and the AI your staff are actually using is where every real 42001 finding comes from.
SaaS companies with 20–300 employees where teams are using AI tools in their daily work. If you have employees using ChatGPT, Copilot, or similar tools — and you don't have visibility into what data is being entered — this assessment is for you.
Smaller teams often have the highest risk because there are fewer controls in place. The assessment is sized to your environment. If you have 30 employees using AI tools with no policy, that's a real exposure — regardless of company size.
A penetration test looks for technical vulnerabilities in your systems. This assessment looks at how your people are using AI tools and where your data is going. These are business process and governance risks — not infrastructure vulnerabilities.
You don't need to be working toward SOC 2 or ISO 27001 to benefit from this. The assessment stands on its own as a practical security exercise. If you pursue compliance later, the findings and documentation carry forward.
Most assessments are completed in 2–3 weeks. We work efficiently and deliver a clear report — not a months-long consulting engagement.
Engagements are scoped to your situation, with pricing agreed up front — fixed-fee wherever the scope allows. We'll discuss your environment on an initial call and provide a clear quote before any work begins. No hourly billing, no open-ended retainers.
Start with a free 30-minute call. We'll discuss your current AI usage, identify likely risk areas, and recommend a clear next step.
Tell us the requirement you are facing, your deadline, and what is blocking you. We will come back with where to start, the likely sequence of work, and whether you actually need outside help.
Personal reply within one business day.