STALWART GOVERNEDAI & Security Governance · vCISO
The work

Three engagements. The Audit, the Sprint and the Retainer.

AI is already in use somewhere in the office. What’s usually missing are the written rules and expectations: who may use which tools, for what work, with what data. The work below comes in three parts. The Audit examines the business before any further AI integration is built on it. The Sprint closes the gaps and sets up the first governed workflow. The Retainer keeps the record current as the business changes. They run in that order, and the business can stop after any one.

01 · Map it

The AI & Security Audit

The business as it is, and the baseline in writing.

Every engagement starts with the Audit. It gives the owner a record to hand the insurance broker when the renewal asks how staff use AI and handle client data. We look at the business directly. There is no questionnaire.

The AI. Which AI tools are in use at the business, what data they touch, on what terms, and who is allowed to use what.

The security it stands on. Backups and tested restores, endpoint protection, patching, who still has access, and how its email is authenticated.

The work. How each job gets done, where it slows down, and where a decision needs a person. We ask the people who do the work.

The report is the baseline for all the work after it. It says what is there, what to change and why, in order.

  • Starts at $2,500

    If the business signs the Sprint within 60 days of the Audit report, the Audit fee is credited toward it.

  • Examined directly

    The walkthrough happens where the work is done. We look at the tools, accounts and data flows directly, with the people who use them.

  • A report that can be checked and shared

    Every finding cites the evidence it rests on and the rule it comes from, as each applies: NIST, the FTC Safeguards Rule, HIPAA, the IRS’s rules on tax return information, the bar’s confidentiality rules, and Illinois and Wisconsin privacy and AI law. The report belongs to the business. It is the business’s to share, with its insurer, advisors and counsel, or anyone it chooses. Each issued document is registered. Anyone the business shares it with can confirm on the Verify page that the copy in hand is the one we issued, unchanged.

02 · Build it

The AI & Security Sprint

The gaps closed and the first workflow set up.

The Sprint is a working engagement with a fixed scope. It closes the gaps the Audit found, both kinds: the ones that expose the business and the ones that cost its people time. We build the first governed workflow around how the office already works. Plain code does what a computer already does well. Wherever the work varies too much for code, AI gets one narrow, defined job, and a workflow can have dozens of them. Each is bounded and checkable, every answer is cited to its source, and a gate checks it before the next step uses it. The Sprint ends when every item is closed or has a date the business set.

  • In severity order

    The most consequential exposures close first. The order is printed before the work starts.

  • Rules written with the owner

    The rules become the business’s AI use policy: plain statements it can hand to new staff on their first day.

  • Alongside the IT provider

    We make the fixes with the IT provider the business already has. We set what has to change and confirm it is done. The IT provider keeps running the systems.

  • Closure verified

    After each fix, we examine the item again and record it closed. That way the Audit and the Sprint reconcile.

03 · Run it

The AI & Security Retainer

The record kept current, and the next improvement built.

With the Retainer, we serve as the business’s vCISO, its named security lead, working inside the business month after month. Tools, terms and staff change. The Retainer updates the written record as they do, so it stays clean and current. It also holds the vendors to the rules.

  • The next workflow, measured

    We build the next AI workflow when the business is ready. We measure the time it saves and report it.

  • Fee set by size

    A flat monthly fee, set by the size of the business, fixed in writing after the Audit.

  • At least one visit and one check-in a month

    On a schedule set with the owner at the start, and written into the engagement letter. We visit anywhere in the Stateline area.

  • Change on the record

    New tools, new terms of service and new staff are written into the baseline as they arrive. The written information security program (the WISP), vendor risk and vendor contracts are kept current. New vendor and partner negotiations are checked for security and data terms.

  • The incident plan

    A one-page plan for the day something goes wrong, written for the business. It says who to call and in what order, what not to touch, the notice window in the cyber policy, and what to ask the responders. We practice it together once a year and keep it current as the business changes, so the owner can run it. If something happens, we respond the same day, have the business’s current record ready for the responders, and check in each day while the incident is active. The investigation and the repairs stay with the response firm and the IT provider. The legal calls stay with counsel.

  • An attestation on request

    A current attestation of the record, whenever the business needs one for a vendor, an insurer or a partner. It is our own account of our own work, limited to what we observed. It names the records that hold the evidence. It is not an independent audit.

  • The named role

    Some rules require a named person to be responsible for security. We can serve in that role, named in writing. We handle the work that comes with it. The responsibility, by rule, stays with the business.

The method
1 of 3

Evidence

Evidence quoted word for word, cited and fingerprinted.

Every finding says how it was seen: a screen, a contract, a console export, a grant, a vendor’s own terms. Something the owner or staff tell us is a lead. It is never a finding on its own. The report says which is which before it says anything else.

2 of 3

Severity

Graded in the open.

Each grade has two inputs. One is how sensitive the data is. The other is how far it went outside the control of the business. Both inputs are printed beside every grade, so anyone can see how it was figured, and question it.

3 of 3

Coverage

What passed and what did not, both listed.

What we checked and found in good order is listed as carefully as what needs work. Anything we couldn’t see well enough to judge is listed separately, with what it would take to check it.

Businesses like yours

For firms and businesses that hold regulated and confidential information

We focus on owner-run offices where the law sets duties for the data they hold. Any business that wants its AI use governed is welcome too.

CPA & accounting firms

Client books and tax records pass through every tool the office uses. The IRS wrote in its June 2026 guidance on AI in tax practice: “Practitioners must strictly handle all client data using only secure, enterprise-approved AI.”

Law offices

Privileged client files. The duty of confidentiality holds whether a person or an AI tool works on them.

Medical & dental practices

Patient records with rules already attached to them.

Insurance agencies

Applications and claims full of personal detail, quoted and re-keyed daily.

Auto dealerships

Buyer financing files the Safeguards Rule already governs.

Manufacturers & job shops

Customer drawings and quotes. They are other firms’ property, held in trust.

Not on the list? We say at the first meeting whether it’s a fit.

An engagement begins with a meeting and a written scope.

The engagement letter sets a fixed fee before any work starts.

Request a consultation