// AI ASSURANCE
AI Security & Compliance Review
Already using AI? We find every tool, map where your data goes, and give you a report you can show clients and insurers.
Your clients will ask about your AI. Your insurer already is.
AI didn't arrive in your business as one big decision. It crept in tool by tool — a chatbot here, an "AI feature" quietly switched on in software you already pay for, a personal account someone signed up for on a Tuesday. Nobody mapped it.
Now the questions are landing: client security questionnaires with an AI section. Cyber insurance renewals asking about AI controls. The Privacy Act asking whether your privacy policy still tells the truth. And for most businesses, the honest answer is: we don't actually know what our AI does with the data.
We fix that. We audit the AI that's already in your business — every tool, every data flow — and hand you a report you can put in front of anyone.
Not sure where you stand? Run the free 2-minute scan →
The problem, in plain English
Your last security audit checked your firewall, your email, your backups. It almost certainly didn't check what your AI tools do with the data that goes into them — because two years ago, there was nothing to check.
Today there is. Data pasted into chatbots. AI features inside your CRM and accounting software, switched on by default. AI vendors whose terms nobody read, some of whom keep what you send them — a few of whom train on it. It's a new layer of your business that grew without oversight, and it's exactly the layer clients, insurers and regulators have started asking about.
You can't answer their questions — or fix the risks — until someone finds out what's actually there.
What we do — AI Security & Compliance Review
- Find every AI in the building. The sanctioned tools, the personal accounts, and the AI features quietly enabled inside software you already run. You can't secure what you haven't found.
- Map where your data goes. Which vendors receive it, where in the world it's processed, how long they keep it, and whether it's used to train their models. Translated from vendor-speak into plain English.
- Check the paperwork against reality. Your privacy policy, client contracts and vendor terms — do they match what's actually happening? We flag every gap, including Australian Privacy Act obligations around sending data overseas, so you can close them before a client or regulator finds them first.
- Probe the new attack surface. AI features can be tricked into leaking data, and AI tools wired into your systems can be given far too much access. We test for the AI-specific risks a traditional security audit doesn't cover.
- Hand you the fix list — and the proof. A prioritised, plain-English remediation plan. Plus a report you can put in front of a client, an insurer or your board and say: audited, controlled, documented.
Starting fresh with AI instead? That's our Safe AI Adoption service. This one is for the AI that's already in the building.
We audited ourselves first
We're not selling a checklist we've never used. We run our own AI-powered security platform — DMARC Busta — and before we offered this review to anyone, we pointed it at ourselves: traced every byte flowing to our AI vendor, tightened data retention, and rewrote our disclosures to match reality.
That's the standard we hold our own product to. It's the same one we'll hold yours to.
Who this is for
- You're already using AI — officially, unofficially, or "we're honestly not sure."
- A client's security questionnaire just landed with an AI section in it.
- Your cyber insurance renewal is asking about AI controls.
- You're about to buy AI-enabled software and want it vetted before it's in.
Why HCS
We're a security firm first. This is an audit, run by people who audit things for a living — not an AI consultancy that added compliance to the menu.
We build AI, so we know where it leaks. DMARC Busta is ours. We've been through this review from the inside, on our own platform.
28 years. 2,000+ Perth businesses. One phone number. The same team that's kept Perth businesses online since 1998 — finding the thing before it bites.
AI security reviews for Perth businesses
We audit businesses across Perth — Belmont, the CBD, the eastern suburbs, out to Kewdale and Welshpool, and across the metro area. The review is remote-first, with onsite time when staff interviews or a hands-on systems sweep call for it.
Whether it's a one-off review to answer a client questionnaire, a pre-purchase vetting of AI-enabled software, or an annual check as part of a managed IT plan, we scope it to the size of your business and the size of your risk.
// Ready to stop firefighting