Frequently asked questions

Direct answers for assessment buyers and reviewers.

Clear scope, careful claims, and no mystery about what the engagement can—and cannot—produce.

01What do we receive from an assessment?

The engagement can produce a signed assessment with an executive summary, scoped AI inventory, data-flow documentation, evidence-backed findings, risk prioritization, framework references, limitations, and remediation recommendations. Exact contents depend on the agreed scope.

02Can we use the assessment during a customer, regulator, or partner security review?

You may provide the assessment as evidence during relevant security, vendor-risk, procurement, regulatory, or partner diligence. Each reviewer decides what evidence it requires, who may rely on the report, and whether the assessment is sufficient.

03What procedures can be included?

A scope may include document review, stakeholder interviews, configuration inspection, observation, demonstrations, and sampling. The written scope states which procedures were performed and which were not.

04Does the assessment include technical testing?

Not automatically. Penetration testing, source-code review, model-performance evaluation, AI red-teaming, and continuous monitoring are excluded unless separately scoped and documented.

05How is missing or conflicting evidence handled?

The report identifies unavailable, stale, conflicting, client-represented, and not-tested evidence. Conclusions are qualified when evidence quality or coverage limits confidence.

06How current is the assessment?

The report is point-in-time. It states its assessment date or period, evidence cutoff, scope, and change-after-assessment boundary. Material changes may require an update or new assessment.

07Can Ayliea receive sensitive or regulated data?

Do not send regulated records, personal data, credentials, questionnaires, or assessment evidence through the booking page or initial email. Ayliea avoids receiving unnecessary sensitive data, including PHI, and establishes engagement-specific transfer arrangements in writing.

08What does independent mean?

Ayliea is an external, paid assessor rather than the organization being assessed or its regulator. Independence does not imply governmental authority. Potential conflicts are addressed during scoping, and commercial outcomes are not guaranteed.

09How are corrections handled?

Factual errors and evidence references can be corrected through a documented review process. A request to change a commercial outcome does not require the assessor to change a supported professional conclusion.

10How long does an engagement take?

Timing depends on the agreed scope, system count, entities, procedures, evidence readiness, and stakeholder availability. The written scope sets the expected assessment period and delivery plan before work begins.

11How much does an engagement cost?

AI Security Reviews start at $3,500; AI Security Assessments start at $7,500; Comprehensive AI Security Assessments start at $15,000; Enterprise / Complex Scope engagements are custom-scoped. Final pricing is confirmed in a written scope before work begins.

12Do you certify HIPAA compliance?

No. Ayliea does not provide a government-backed HIPAA certification, certify that an organization is HIPAA compliant, or guarantee compliance. Relevant findings may be mapped to applicable HIPAA Security Rule safeguards.

13What security frameworks do you assess against?

Ayliea maps and aligns relevant findings to established AI security frameworks: NIST AI RMF 1.0, ISO/IEC 42001:2023, HIPAA Security Rule, OWASP LLM Top 10, MITRE ATLAS. These references frame the findings so a receiving reviewer can place them in a familiar context. Mapping and alignment are not certification or endorsement—Ayliea is not a certification body—and professional judgments and evidence-quality decisions remain explained and attributable to the assessor.

Next step

Need a clearer record of your AI security risk?

Use a 20-minute scoping call to clarify what the reviewer is asking for, what belongs in scope, and whether an independent Ayliea assessment is a fit.

  • Clarify the review request
  • Identify systems and evidence
  • Define a defensible scope