Discovery Phase

AI Risk Assessment
At The Endpoint Level
Proof, Not Posture.™

Before you can write an AI acceptable-use policy, you need to know what your staff are actually running. Our agentless, read-only scanner inventories AI usage across your computers in minutes — giving you the evidence you need to secure your data and satisfy underwriters.

Point-in-Time Shadow AI Scan

Here is what a typical run looks like when inspecting a single endpoint. Nothing is installed, and the scanner reports findings in a clean JSON format.

Scan-AIUsage.ps1 AUTHORIZATION: SOW-2026-08
$ .\Scan-AIUsage.ps1 -ClientName "Practice-Alpha" -AuthorizationRef "SOW-2026-08"
[i] Initializing LockDown AI Discovery Collector v1.1.0...
[i] Mode: Pseudonymised (Salting identifiers: Hostname/Username)
[✓] Scanning installed applications...
[!] FOUND: 1 unauthorized local AI interface (Ollama running on port 11434)
[✓] Scanning browser extensions...
[!] FOUND: 2 browser extensions matching AI catalog (Chrome Web Store IDs verified)
[✓] Scanning browser histories (capped at 96MB)...
[!] ALERT: 147 hits on GenAI chat hostnames (chatgpt.com, claude.ai) in last 30 days
[✓] Scanning local model weights >50MB...
[!] FOUND: llama3.1-8b.gguf (4.7 GB) in per-user cache directory
[✓] Scanning shell histories and environment variables...
[!] ALERT: Found API key variables defined: OPENAI_API_KEY (Value not read)
[i] Redacting local paths to preserve privacy (%LOCALAPPDATA% / C:\Users\<user>)
[i] Exporting evidence to results\aiscan-DEV-3d657a18aa15.json
[✓] SCAN COMPLETE — Findings detected (Exit code 2)
EXECUTION TIME: 11.4 seconds

Privacy-First Architecture

Employee monitoring is a data protection concern. Our discovery tool is designed strictly as a risk validator. We verify the presence of tool usage without ever inspecting the contents of the work.

What the Scanner Inventories

We look for twelve independent evidence classes to verify the existence and frequency of AI interactions:

  • Installed Apps: Registry uninstall entries and folder catalogs.
  • Browser Extensions: Manifest matching across Chrome, Edge, Brave, Arc, Firefox.
  • DNS Cache: Recent name resolutions for AI hostnames.
  • Local Model Weights: Manifests and .gguf files over 50MB.
  • Listening Ports: Interfaces for Ollama, LM Studio, ComfyUI, etc.
  • Browser History: AI hostnames and hit counts (redacted to domain root).
  • IDE Extensions: VS Code, Cursor, Windsurf plugins (Copilot, Cline, etc.).
  • Shell History: Counts of CLI tool executions (e.g., aider, ollama).
  • API Key Presence: Names of environment variables (values are never read).

What the Scanner Never Reads

Privacy by design ensures we collect only structural meta-data. We strictly exclude and redact the following:

  • No Prompt Text: We do not log what staff are asking AI.
  • No Chat Content: We never capture conversation histories.
  • No Document Data: File contents are never accessed.
  • No Key Values: API key values are completely ignored.
  • No Query Parameters: Full URL queries like chatgpt.com/c/some-id are cut off at the root hostname.
  • No Keystrokes: Active text entry is never logged.
  • No Screen Captures: The scanner runs invisibly in the background.
  • Pseudonymization: Hostnames and usernames are salted-hashed by default.

One-Time Assessment Scope

Designed as a point-in-time diagnostic. We walk you through the entire deployment and present findings directly to your leadership.

1. Guided Deployment

Run from a secure USB key or pushed centrally via Intune, SCCM, GPO, or RMM. The collector is our own read-only script — built and maintained in-house, updated as new AI tools emerge — and completes in under a minute per device. Zero impact on daily operations.

2. Evidence Consolidation

Evidence JSON files are compiled locally. Real identities are salted-hashed by default so the findings focus on structural practice risk, not individuals.

3. Board-Ready Report

A comprehensive risk analysis including illustrative business exposure ranges, compliance alignment reviews, and a prioritized roadmap for governance.

Land-and-Expand Credit: De-risking your governance baseline

A point-in-time scan is an essential diagnostic, but its value decays. To help you establish continuous oversight, 100% of your assessment fee is credited toward your first year of our Continuous AI Governance Subscription if you sign within 60 days. This makes the diagnostic assessment effectively free if you continue the program.

Independent by design

The assessment fee is flat regardless of what we find — there's no incentive to inflate. The report is yours to act on however you choose: with us, with your existing IT provider, or on your own. And when we point to a tool we don't resell, we say so.

Schedule Your Risk Assessment

An authorized pilot (typically 10 to 25 devices) is all it takes to establish your baseline. We coordinate directly with your IT resource.