Scope & authorise
We agree the hosts, the window and the rules of engagement, and you sign a short authorisation and indemnity. Nothing runs before that signature is on record.
Validate
The AI operator works through your surface, reasoning about what it finds and confirming each issue instead of dumping a raw scanner list. Anything active pauses for your approval.
Evidence
Every confirmed finding is written up with proof and severity, then mapped to the ISO/IEC 27001 control it breaks — so it lands as audit evidence, not just a ticket.
Report & re-scan
You get a signed report, reviewed by a person before it reaches you. Fix what matters, then we re-scan to confirm the issues are actually closed.