🔍 Shadow AI Discovery Assessment

Find every AI agent, risk & compliance gap — in weeks.

A fixed-scope, read-only engagement that inventories every AI agent, shadow-AI app, MCP tool, and non-human identity across your estate, ranks them by risk, maps PII & data exposure, and delivers a board-ready findings report plus a governance roadmap. Your paid fee is 100% creditable against your Year-1 RuntimeAI subscription.

10
Discovery Modules
Read-Only
Non-Intrusive
80+
Compliance Frameworks
100%
Creditable

The 10 Discovery Modules

Full-estate coverage — cloud, endpoint, network, identity, and data.

01
Cloud AI Resource Scan
Enumerate AI/ML services, model endpoints, and agent workloads across your cloud accounts.
02
IDE & Endpoint Discovery
Detect AI coding assistants, local agents, and shadow-AI tools on developer machines.
03
DNS & Network Analysis
Surface calls to LLM and AI-SaaS endpoints leaving your network — sanctioned or not.
04
OAuth & SaaS Grant Review
Map AI-app OAuth grants and the data scopes they hold across your SaaS estate.
05
Container & CI/CD Scan
Find AI dependencies, model artifacts, and agent runtimes in images and pipelines.
06
Local LLM & MCP Inventory
Inventory self-hosted models and every MCP tool/server agents can reach.
07
Risk-Ranked AI Inventory
Consolidate every discovered agent and identity into a single risk-ranked register.
08
Data-Access & PII Exposure
Map which agents touch which data — and where PII is exposed to AI systems.
09
Executive Findings Report
A board-ready report of risks, blast radius, and prioritized recommendations.
10
Governance Roadmap
A recommended, phased roadmap to bring your AI estate under continuous governance.

What You Receive

Concrete, board-ready deliverables — under NDA.

Risk-ranked AI & non-human-identity inventory
Data-access & PII exposure map
Board-ready executive findings report
Phased governance roadmap
(Compliance Sprint) chosen-framework readiness gap analysis
(Compliance Sprint) compliance-evidence pack + prioritized remediation plan

Packages & Pricing

Every paid fee is 100% creditable against your Year-1 subscription if executed within 90 days of delivery.

Free Scan
$0
One endpoint scanner — self-serve shadow-AI discovery on a single machine.
  • Single-endpoint scanner
  • Self-serve, no NDA
  • Instant shadow-AI snapshot
Start Free →
Rapid Scan
$10,000
Modules 1, 7 & 9 across a single cloud environment. ~1 week.
  • Cloud AI + risk-ranked inventory
  • Executive summary
  • Single cloud env · ~1 week
  • 100% creditable
Request →
Enterprise Assessment
$25,000
Full scope, multi-BU / multi-cloud, larger estate. 3–4 weeks.
  • All 10 modules at scale
  • Multi-BU / multi-cloud
  • Board-ready findings
  • 100% creditable
Request →
Compliance Sprint
$40,000
Enterprise Assessment + gap analysis & evidence mapping for one chosen framework. 4–6 weeks.
  • Everything in Enterprise
  • One chosen framework (top-10)
  • Evidence pack + remediation plan
  • 100% creditable
Request →

Compliance Sprint frameworks: EU AI Act · NIST AI RMF · ISO/IEC 42001 · SOC 2 · HIPAA · GDPR · PCI DSS 4.0 · ISO/IEC 27001 · NIST CSF · CCPA. RuntimeAI's compliance catalog covers 80+ frameworks.

Request Your Assessment

Tell us about your estate — we'll scope and respond within one business day.

FAQ

Is the paid fee really creditable?
Yes — the full paid fee is 100% creditable against your Year-1 RuntimeAI subscription if executed within 90 days of assessment delivery.
Is the assessment intrusive?
No. Every engagement is read-only and non-intrusive. We inventory and analyze — we do not modify your systems.
How are results handled?
All results are delivered under NDA. Findings are yours; nothing is shared externally.
Does this include remediation?
The assessment identifies and prioritizes risks. Remediation implementation is a separate SOW.

Know your AI estate.

Every agent, every shadow-AI app, every non-human identity — ranked by risk, mapped to exposure. Start with a free scan or request a full assessment.