We don't tell you whether you're “secure.” We tell you what your existing proof actually allows a bank reviewer to verify, before they ask.
The offer
A bank-review proof diagnostic.
A fraction of the cost of a stalled bank deal or weeks of senior engineering time spent reconstructing proof.
Give us the bank's AI and security questionnaire and the engineering artifacts you already have. We map what you can prove, what a reviewer still can't verify, and what to fix first, before the reviewer has to ask.
Scope boundaries
What this is
A narrow, fixed-scope diagnostic designed to establish what your submitted proof actually supports before the review begins.
What this is not
Not a pen test, SOC 2 certification, legal advice, a judgment on whether a control is adequate, or a guarantee of bank approval.
What we return
What you can prove
The claims your existing proof actually substantiates, mapped against the underlying questions in the bank's AI diligence. Each finding carries a proof-status label, so a clean answer stops reading as evasive.
What the bank still can't verify
Gaps, ambiguity, stale artifacts, and unsupported claims, plus the specific claims most likely to draw a follow-up request or a challenge, and why. We assess verification friction, not company risk.
What to do about it
The fixes to make first, prioritized by likely review impact, available proof, and effort. And the Defer List: issues that can wait without becoming the current blocker, so the team doesn't burn cycles on the wrong thing.
Make it actionable
A proof record showing the basis for each finding and the limits of what can be established from the materials reviewed, then a working session to walk it with your team.
How the 10 days work
Intake & NDA
We start with a mutual NDA, then you send your live questionnaire and existing artifacts through your own secure channel. The 10-day clock starts when the materials are in hand.
Review, on our side
The diagnostic work happens with us, not your team. Your engineers stay on the roadmap. We work from what you provided and flag anything we need.
Midpoint check-in
A short progress note by email around the halfway mark, so you always know where the review stands. No meeting required.
Delivery & walkthrough
You receive the proof map, the prioritized remediation plan, and an executive deal-risk brief, followed by one Q&A walkthrough call. Send your questions ahead of time so the call goes straight to answers.
The proof-status scale
Substantiated
The submitted proof supports the claim.
Partially substantiated
Some proof present, gaps remain.
Not substantiated
The claim is stated, the proof isn't there.
Unable to assess
We couldn't evaluate it from the materials provided.
Every finding is labeled by what the submitted proof establishes, never by whether the control is adequate. That keeps the diagnostic inside its lane: a statement about the proof, not a conclusion about your security.
Scope
Findings-or-refund
If we cannot deliver the defined diagnostic outputs from the materials you provide, covering what can be substantiated, what remains unverified, and prioritized review actions, you don't pay.
Founding-cohort terms. Applies to the engagement as scoped in your proposal.
Before you send, have these ready
Takes you to a short, private intake check. It reflects where a reviewer would get stuck, then shows you the sample report and how to begin. Nothing is shared until you decide to proceed, and a mutual NDA comes first.