The Evidence Pack

You have a document to complete and a date it is due. This engagement gets it answered honestly, with something real behind every answer, and tells you plainly what is still missing.

What happens across a two-week Evidence Pack Five sequential steps down a vertical spine. One: read the document you were sent, line by line. Two: look at what is actually running, not what the policy says. Three: mark each answer as already true, cheaply true, or not true. Four: fix the cheap gaps inside the engagement. Five: hand over the answers, the artifacts, and what is still open. 01 Read the document you were sent, line by line 02 Look at what is actually running, not what the policy says 03 Mark each answer: already true, cheaply true, or not true 04 Fix the cheap gaps inside the engagement 05 Hand over the answers, the artifacts, and what is still open
Two weeks, fixed scope, fixed fee.

The AI section nobody can answer

Questionnaires and insurance applications have grown an AI section over the past two years, and it is usually the part that stalls the return. The questions are not hard, but they are specific: which models do you call, what leaves your systems to reach them, is that covered by your processor terms, how long does the provider keep it, and who reviews an output before it affects someone. They are answered the same way as every other section here — by looking at what the system actually sends, not at what the AI policy says.

What you get

  • Completed response. Your questionnaire or application, worked through line by line, with each answer marked as supported, partially supported, or not yet true.
  • Control-evidence index. Every “yes” mapped to the artifact that backs it — a configuration export, a policy that matches practice, a restore test result, a screenshot with a date on it.
  • Gap list with effort and cost. What is not true yet, what it takes to make it true, and what it would cost. Ordered by what the reader of your document will care about.
  • Quick fixes applied. Gaps I can close inside the engagement, closed — with your approval and your change process, not around it.

How it runs

  1. Scoping call. You send the document. I tell you whether this engagement fits, and quote a fixed fee from the actual document before any work starts.
  2. Week one. Evidence gathering against what is actually running — identity and access, endpoint coverage, backup and restore, logging, vendors, data locations.
  3. Week two. Drafting, quick fixes, and a walkthrough so you can defend every answer yourself when someone follows up.

What this is not

  • Not an audit, an attestation, or a certification. I do not sign your document; you do.
  • Not a SOC 2 report or an ISO/IEC 27001 certificate — those require a licensed CPA firm and an accredited certification body respectively.
  • Not legal advice, and not advice on what your insurance policy will or will not do. The application is a document you sign. What a particular policy does if an answer turns out to be wrong is a question for your broker and your lawyer.
  • Not a guarantee of any outcome decided by a third party — an insurer, a customer's security team, or a public body's privacy office.

Fee

Availability

Ask whether this fits