Services & rates

I make AI systems safe to ship — and able to survive an audit.

Guardrails and hard limits for live LLM apps and agents, tamper-evident audit trails that stand up to a regulator, and the EU AI Act / ISO 42001 controls behind them. I design it, build it, and can run it — backed by seven years architecting a GRC / compliance platform (CISOteria), and this past year an app for the Israel National Cyber Directorate.

Start here — the contained way in

AI Security & Audit-Readiness Teardown

$5,000

One week. I talk to the people who built and run your AI, review the code and the AI/cloud spend (FinOps), and map where you’re exposed — prompt-injection and abuse paths, data leakage, runaway spend — and whether you could produce the evidence an auditor would ask for. You get a written findings report, prioritized by risk, with a concrete fix list. A fixed-price, contained first engagement before anything larger.

You get

  • Written findings, prioritized by risk
  • A concrete fix list, mapped to EU AI Act / ISO 42001 controls
  • A 30-minute walkthrough call

How to hire me

Teardown · $5,000

A one-week, fixed-price assessment. The contained way in.

Fixed-scope project · from $7,500

A named deliverable at a price agreed up front — a review, a build, or an implementation.

Fractional / ongoing · from $6,000/mo

A senior security voice on call, month to month — reviews, guidance, and the hard-to-reverse decisions.

Consulting · $500/hour

Architecture reviews, a second opinion, a sounding board.

AI security & governance — fixed-scope work

  • AI Security & Audit-Readiness Review — from $7,500. The deep version of the teardown: a full threat model of your LLM apps and agents, guardrail and spend-control design, and an audit-readiness gap analysis against the EU AI Act and ISO 42001 — with a prioritized remediation plan you can hand to your team.
  • AI gateway implementation — from $15,000. I put a fail-closed gateway in front of your models: hard spend caps and denial-of-wallet control (my own Guardrail), plus prompt-injection, PII-redaction and output-validation layers integrated from the proven open-source tooling — wired in and enforced, not a policy document that sits in a drawer.
  • Tamper-evident AI audit trail — scoped to your systems. Independently verifiable, tamper-evident logs of what your AI did and why — self-hosted, no third-party dependency — so the record holds up when a regulator, auditor, or board asks.

Tamper-proof infrastructure & private blockchain

The deepest form of the audit-trail work above: immutable, independently verifiable records on self-hosted infrastructure — no third-party dependency. My longest-running specialty, with fixed-scope offerings.

Feasibility Assessment

$5,000

A one-week deep dive into whether tamper-proof infrastructure fits your situation: where your current systems are vulnerable, what the architecture would look like, and a clear go / no-go. Written report, cost estimate and roadmap, and a 30-minute walkthrough.

Proof of Concept

$7,500

In four weeks, a working system you can demo to stakeholders — a 2-node private chain, one smart contract, a basic web UI, and API docs. Source code is yours (MIT), one-command Docker deploy, recorded walkthrough, and a follow-up call.

Full Implementation

$20–50K

Production deployment: a multi-node chain, custom contracts, integrations, and hardening — built on the proof of concept once you’ve seen it work.

Architecture Audit

$15,000

A deep review of an existing blockchain implementation — smart contracts, node and consensus setup, security model, and disaster recovery — with a prioritized report.

Managed infrastructure — $2–5K/month

I run your private chain so your team doesn’t have to: monitoring, security patches, node management, backup verification, and a 24-hour response for critical issues.

Who I work with

  • Companies deploying AI in regulated contexts — fintech, healthcare, legal, government — that need their AI governed and provable.
  • Real estate title companies — wire-fraud prevention and tamper-proof closing documents.
  • Legal firms — chain-of-custody for sensitive documents and transactions.
  • Healthcare organizations — audit trails that can’t be backdated.
  • Government & municipal IT — transparent, accountable records.

If you’re running something where getting it wrong is expensive — an AI system, or the records around it — we should talk. If I’m not the right fit, I’ll say so.

More from me

Controlling the AI you can’t fully trust — its cost, its abuse, and its compliance.

I write near-daily about the practical side — cutting cloud bills and keeping AI spend and abuse under control — at smallestbusiness.com . Get the posts by email, or read them there.

Or read at smallestbusiness.com →