How an assessment runs
A disciplined 15 business days program with explicit phases, human review, and deliverables your team can reuse after the engagement ends.
Timeline
| Timing | Phase | What happens |
|---|---|---|
| Before Day 1 | Scope | Confirm workflow, access model, exclusions, risks, and success criteria |
| Days 1–3 | Intake | Review policies, architecture, examples, and known failures |
| Days 4–6 | Scenario design | Build normal, edge-case, and adversarial evaluations |
| Days 7–9 | Execution | Run scenarios; capture outputs, traces, and tool behavior |
| Days 10–12 | Human adjudication | Review uncertainty, classify severity, consolidate findings |
| Days 13–14 | Reporting | Prepare executive, engineering, and regression deliverables |
| Day 15 | Readout | Present findings, answer technical questions, agree on next actions |
| Optional | Retest | Verify remediation against the same scenario set under separate scope |
Access & data
Supported access methods
- Staging HTTP endpoint or internal API
- Callable function with representative inputs
- Recorded traces replayed in a controlled harness
- VPN or IP-allowlisted sandbox (by agreement)
What we do not require
- Production credentials in the contact form
- Full source-code access (helpful but optional)
- Customer PII in initial intake
- Unlimited scope creep without a change order
Client decisions
- — Severity acceptance and remediation prioritization remain with your team.
- — Scope changes are documented before additional work proceeds.
- — If test access is blocked, timeline shifts to when access is restored.
- — Assessments are advisory; they do not certify safety or compliance.