AI Security & Compliance Review
Already using AI? We find every tool, map where your data goes, and give you a report you can show clients and insurers. Fixed prices below — no call needed to find out.
Your clients will ask about your AI. Your insurer already is.
AI didn't arrive in your business as one big decision. It crept in tool by tool — a chatbot here, an "AI feature" quietly switched on in software you already pay for, a personal account someone signed up for on a Tuesday. Nobody mapped it.
Now the questions are landing: client security questionnaires with an AI section. Cyber insurance renewals asking about AI controls. The Privacy Act asking whether your privacy policy still tells the truth. And for most businesses, the honest answer is: we don't actually know what our AI does with the data.
We fix that. We audit the AI that's already in your business — every tool, every data flow — and hand you a report you can put in front of anyone.
Not sure where you stand? Run the free 2-minute scan →
The problem, in plain English
Your last security audit checked your firewall, your email, your backups. It almost certainly didn't check what your AI tools do with the data that goes into them — because two years ago, there was nothing to check.
Today there is. Data pasted into chatbots. AI features inside your CRM and accounting software, switched on by default. AI vendors whose terms nobody read, some of whom keep what you send them — a few of whom train on it. It's a new layer of your business that grew without oversight, and it's exactly the layer clients, insurers and regulators have started asking about.
You can't answer their questions — or fix the risks — until someone finds out what's actually there.
What we do — AI Security & Compliance Review
- Find every AI in the building. The sanctioned tools, the personal accounts, and the AI features quietly enabled inside software you already run. You can't secure what you haven't found.
- Map where your data goes. Which vendors receive it, where in the world it's processed, how long they keep it, and whether it's used to train their models. Translated from vendor-speak into plain English.
- Check the paperwork against reality. Your privacy policy, client contracts and vendor terms — do they match what's actually happening? We flag every gap, including Australian Privacy Act obligations around sending data overseas, so you can close them before a client or regulator finds them first.
- Probe the new attack surface. AI features can be tricked into leaking data, and AI tools wired into your systems can be given far too much access. We test for the AI-specific risks a traditional security audit doesn't cover.
- Hand you the fix list — and the proof. A prioritised, plain-English remediation plan. Plus a report you can put in front of a client, an insurer or your board and say: audited, controlled, documented.
Starting fresh with AI instead? That's our Safe AI Adoption service. This one is for the AI that's already in the building.
Pricing — fixed, and on the page
Two sizes, one report. Pick the one that matches your headcount and book it. If you'd rather talk first, the consult is still free.
01
Up to 10 staff
$2,495 +GST, fixed
- Every AI tool found, sanctioned or not
- Where your data goes, vendor by vendor
- Privacy policy and contracts checked against reality
- AI-specific attack surface tested
- Prioritised fix list, and the report to prove it
02
11 to 30 staff
$3,995 +GST, fixed
- Everything in the smaller review
- More staff interviewed, more tools traced
- More data flows mapped, same plain English
- One report covering the whole business
03
30+ staff or multi-entity
Quoted
- Same review, scoped to your structure
- Several entities or sites under one report
- Fixed quote before we start
Add-on
Annual re-review
$1,495 +GST /yr
Tools change, vendors rewrite their terms, and last year's report stops being true. The re-review keeps your insurer and client questionnaire answers current.
- Every tool and data flow re-checked
- Paperwork re-tested against what's actually running
- Updated report, ready to hand over
If the report says the fix is a proper rollout, half your review fee is credited against Safe AI Adoption when you book it within 60 days of the report.
// All prices in AUD, excluding GST. Reviews are one-off. The re-review bills yearly.
We audited ourselves first
We're not selling a checklist we've never used. We run our own AI-powered security platform — DMARC Busta — and before we offered this review to anyone, we pointed it at ourselves: traced every byte flowing to our AI vendor, tightened data retention, and rewrote our disclosures to match reality.
That's the standard we hold our own product to. It's the same one we'll hold yours to.
Who this is for
- You're already using AI — officially, unofficially, or "we're honestly not sure."
- A client's security questionnaire just landed with an AI section in it.
- Your cyber insurance renewal is asking about AI controls.
- You're about to buy AI-enabled software and want it vetted before it's in.
Why HCS
We're a security firm first. This is an audit, run by people who audit things for a living — not an AI consultancy that added compliance to the menu.
We build AI, so we know where it leaks. DMARC Busta is ours. We've been through this review from the inside, on our own platform.
28 years. 2,000+ businesses. One phone number. The same team that's kept Perth businesses online since 1998 — finding the thing before it bites.
FAQ — AI security review
What does it cost? $2,495 +GST for a business with up to 10 staff, or $3,995 +GST for 11 to 30. Both are fixed, and the report is in your hands in 10 or 15 business days. Larger or multi-entity businesses are quoted after the free readiness scan. An annual re-review is $1,495 +GST a year. Half the review fee comes off Safe AI Adoption if you book it within 60 days of your report.
What do we get at the end? A written report: every AI tool found, where your data goes, the gaps between your paperwork and what's actually happening, and a prioritised fix list in plain English. It's written to be handed to a client, an insurer or your board.
Do you need access to our systems? Some. The review is remote-first — we talk to your staff, look at the software you already run, and read the vendor terms nobody else has. Onsite time is for staff interviews or a hands-on systems sweep, when the size of the business calls for it.
We're not sure we're even using AI. Is the review still worth it? Yes — that answer is what the review is for. AI features are switched on by default inside software you already pay for, and personal accounts don't show up on any list. Finding what's there is the first step. The free readiness scan is a fair place to start if you want a rough answer first.
AI security reviews for Perth businesses
We audit businesses across Perth — Belmont, the CBD, the eastern suburbs, out to Kewdale and Welshpool, and across the metro area. The review is remote-first, with onsite time when staff interviews or a hands-on systems sweep call for it.
Whether it's a one-off review to answer a client questionnaire, a pre-purchase vetting of AI-enabled software, or an annual check as part of a managed IT plan, we scope it to the size of your business and the size of your risk.
Ready to stop firefighting