Services & rates
I make AI systems safe to ship — and able to survive an audit.
Guardrails and hard limits for live LLM apps and agents, tamper-evident audit trails that stand up to a regulator, and the EU AI Act / ISO 42001 controls behind them. I design it, build it, and can run it — backed by seven years architecting a GRC / compliance platform (CISOteria), and this past year an app for the Israel National Cyber Directorate.
Start here — the contained way in
AI Security & Audit-Readiness Teardown
$5,000
One week. I talk to the people who built and run your AI, review the code and the AI/cloud spend (FinOps), and map where you’re exposed — prompt-injection and abuse paths, data leakage, runaway spend — and whether you could produce the evidence an auditor would ask for. You get a written findings report, prioritized by risk, with a concrete fix list. A fixed-price, contained first engagement before anything larger.
You get
- Written findings, prioritized by risk
- A concrete fix list, mapped to EU AI Act / ISO 42001 controls
- A 30-minute walkthrough call
How to hire me
Teardown · $5,000
A one-week, fixed-price assessment. The contained way in.
Fixed-scope project · from $7,500
A named deliverable at a price agreed up front — a review, a build, or an implementation.
Fractional / ongoing · from $6,000/mo
A senior security voice on call, month to month — reviews, guidance, and the hard-to-reverse decisions.
Consulting · $500/hour
Architecture reviews, a second opinion, a sounding board.
AI security & governance — fixed-scope work
- AI Security & Audit-Readiness Review — from $7,500. The deep version of the teardown: a full threat model of your LLM apps and agents, guardrail and spend-control design, and an audit-readiness gap analysis against the EU AI Act and ISO 42001 — with a prioritized remediation plan you can hand to your team.
- AI gateway implementation — from $15,000. I put a fail-closed gateway in front of your models: hard spend caps and denial-of-wallet control (my own Guardrail), plus prompt-injection, PII-redaction and output-validation layers integrated from the proven open-source tooling — wired in and enforced, not a policy document that sits in a drawer.
- Tamper-evident AI audit trail — scoped to your systems. Independently verifiable, tamper-evident logs of what your AI did and why — self-hosted, no third-party dependency — so the record holds up when a regulator, auditor, or board asks.
Tamper-proof infrastructure & private blockchain
The deepest form of the audit-trail work above: immutable, independently verifiable records on self-hosted infrastructure — no third-party dependency. My longest-running specialty, with fixed-scope offerings.
Feasibility Assessment
$5,000
A one-week deep dive into whether tamper-proof infrastructure fits your situation: where your current systems are vulnerable, what the architecture would look like, and a clear go / no-go. Written report, cost estimate and roadmap, and a 30-minute walkthrough.
Proof of Concept
$7,500
In four weeks, a working system you can demo to stakeholders — a 2-node private chain, one smart contract, a basic web UI, and API docs. Source code is yours (MIT), one-command Docker deploy, recorded walkthrough, and a follow-up call.
Full Implementation
$20–50K
Production deployment: a multi-node chain, custom contracts, integrations, and hardening — built on the proof of concept once you’ve seen it work.
Architecture Audit
$15,000
A deep review of an existing blockchain implementation — smart contracts, node and consensus setup, security model, and disaster recovery — with a prioritized report.
Managed infrastructure — $2–5K/month
I run your private chain so your team doesn’t have to: monitoring, security patches, node management, backup verification, and a 24-hour response for critical issues.
Who I work with
- Companies deploying AI in regulated contexts — fintech, healthcare, legal, government — that need their AI governed and provable.
- Real estate title companies — wire-fraud prevention and tamper-proof closing documents.
- Legal firms — chain-of-custody for sensitive documents and transactions.
- Healthcare organizations — audit trails that can’t be backdated.
- Government & municipal IT — transparent, accountable records.
If you’re running something where getting it wrong is expensive — an AI system, or the records around it — we should talk. If I’m not the right fit, I’ll say so.