Read access
Repository, deployment configuration, relevant logs, and architecture material.
AP–01 / production readiness
We establish what has been built, what prevents dependable use, what it will cost to resolve, and whether further investment is justified.
The question
A prototype can demonstrate that a model, integration, or workflow is possible. It does not establish that the system is controlled, measurable, supportable, or worth operating.
The assessment closes that evidence gap. It is designed for a decision-maker who needs a technically credible answer without commissioning another vague phase of work.
What you receive
Every material conclusion is tied to observed evidence. Findings are written for both technical owners and the people accountable for the investment.
Assessment frame
The exact findings differ by system. The assessment frame remains consistent enough to make omissions visible.
| Reference | Observed defect | Severity |
|---|---|---|
| A-01 | Identity and access boundaries | Critical |
| A-02 | Data provenance, retention, and exposure | Critical |
| A-03 | Evaluation coverage and release thresholds | Major |
| A-04 | Observability, incident reconstruction, and escalation | Major |
| A-05 | Ownership, runbooks, cost, and operational support | Minor |
What we need
We do not begin with a week of workshops. We ask for the smallest set of access and context needed to test the system against its intended use.
Repository, deployment configuration, relevant logs, and architecture material.
Up to 90 minutes with the person or team that knows the build best.
Representative data and the operational path the system is expected to support.
Questions
No. Security is part of production readiness, but the assessment also covers architecture, AI behaviour, evaluation, operations, cost, maintainability, and delivery viability. Where formal certification or penetration testing is required, we will identify it rather than pretend this assessment replaces it.
No. The report is written to stand on its own. Your team, the original supplier, or another partner can deliver against it.
We explain why, identify anything worth retaining, and set out the least damaging way to close or redirect the initiative. Avoiding the wrong build is a successful outcome.
Yes. We adapt access and evidence collection to minimise operational risk. The report distinguishes immediate containment from longer-term improvement.
Next step
We will confirm whether the assessment is the right starting point and what access it requires.
Start a conversation