Answers to what compliance leads, CISOs, and legal teams ask before booking a briefing.
It depends on the engagement tier. The Browser Log Light Scan uses a read-only PowerShell script your IT team can review line-by-line before running — no installation, no persistent agent. Full forensic audit engagements use industry-standard forensic imaging tools, deployed with your IT team present. We never operate unilaterally on your infrastructure.
Only the examiner assigned to your engagement. All data is processed under a signed NDA and our standard confidentiality agreement, executed before any engagement begins. Findings are delivered in an encrypted report. We do not retain client data beyond the engagement period — documented in our evidence destruction certificate, issued at close.
Browser Log Light Scan: 2–3 business days from export receipt to report. AI Vendor Risk Assessment: 48 hours from intake completion. Full AI Exposure Audit: 7–14 business days depending on scope and number of endpoints. Timeline is confirmed at engagement kickoff — we don't start the clock until scope is agreed.
That outcome exists and we'll tell you clearly when it does. A clean finding is a defensible finding — documented evidence that your organization examined its AI exposure and found it within acceptable parameters. That documentation has real value in a regulatory inquiry or litigation context. We don't inflate findings to justify our fee.
DLP and SIEM monitor traffic and flag policy violations in real time. They don't examine what's already on the endpoint — cached browser artifacts, local storage, downloaded conversation exports, browser extension permissions. We examine what your existing tools never saw. In most engagements, the meaningful findings come from artifacts that predate our involvement by weeks or months.
Yes. Where legally appropriate, engagements can be scoped and delivered under attorney-client privilege — typically by routing the engagement through outside counsel. We work with your legal team to structure this at kickoff. Not every organization requires this, but regulated industries facing active regulatory scrutiny or pending litigation often do.
Always. Our standard NDA is executed before we receive any organizational information. For enterprise engagements, we'll work with your legal team's preferred form. If you'd like to review our standard NDA before booking a briefing, email adil@shadowaiforensics.com.
The frameworks are ready to deploy for most organizations — drafted with regulatory specificity for your industry and mapped to current HIPAA, SOX, FINRA, and ABA requirements. Organizations with complex multi-jurisdiction exposure or active regulatory matters should have outside counsel review before finalization. For most, the Foundation Pack is sufficient without that step.