Aeon AI Risk Management

Use AI without losing control of confidential work.

Know where sensitive information goes, which controls protect it, and what to change. Aeon connects a focused assessment to practical implementation, not another report left on a shelf.

Questions this page answers

Is this a software product or a consulting service?
It is a fixed-scope consulting engagement. Shadow AI List and RiskMemo can support discovery and vendor review, but they do not replace evidence from your environment.
Do we need to stop using cloud AI?
Not necessarily. We assess the specific product, account, data and controls. The outcome may be a better-configured cloud workspace, private processing for selected workflows, or a governed combination.
Can you prove whether a vendor already trained on our files?
Not from an external configuration review alone. We document applicable commitments, settings, available evidence and unresolved questions. We do not promise forensic proof of a provider's historical training pipeline.
Does private AI guarantee that nothing leaves our organization?
No deployment label is a guarantee. Local inference avoids sending prompts to a cloud model on that route, but connectors, fallback models, telemetry, logs, backups and administrator access also need controls. We agree and test those boundaries, then document exceptions and residual risks.
How much does the assessment cost?
Request pricing. We agree a fixed fee after confirming the business unit, tools, workflows, access and deliverables. Larger environments receive a separately scoped proposal.
Must we buy the AI Control and ROI Assessment first?
No. Start here when confidentiality is the defined problem. The AI Control and ROI Assessment is an alternative for organizations deciding which broader AI investment or delivery priority to address first.
Can the work include staff, manager or board training?
Yes, as an agreed workshop or follow-through package. Staff practise safe handling, managers work through exceptions, and executives or boards review responsibility and evidence. Companion books are optional; no prior reading is required.
Should we send confidential files with our enquiry?
No. Describe the tools and workflow at a high level without client data, credentials or unpublished material. Agree authorized access and secure evidence handling before sharing sensitive information.

Tools and accounts

Identify approved and unapproved tools using stakeholder interviews and available administrative, procurement and usage records. Shadow AI List helps classify tools; a registry alone does not establish actual employee usage.

Information routes

Trace selected prompts, files and outputs through models, connectors, logs, sharing, backups and support access. Distinguish observed routes from documented or unverified ones.

Terms and settings

Review the actual product, account tier, training choices, retention, deletion and sharing controls. Separate contractual commitments from configuration evidence and tests.

Business consequences

Rank findings by information sensitivity, plausible business impact and strength of evidence. Record unknowns rather than inventing loss estimates or claiming a complete firm-wide inventory.

A clear exposure map

Selected workflows, information classes, destinations and responsible owners, with evidence dates and visibility gaps.

A decision-ready findings pack

Ranked findings, a vendor-terms summary and an executive or board summary. Evidence can support governance documentation where relevant; this is not certification or an independent assurance opinion.

A practical correction plan

What can remain in approved cloud tools, what needs configuration changes, and what merits private processing. Each action has an owner, priority and verification step.

A route to implementation

Agree a bounded set of low-risk configuration changes within the assessment where authorized. Scope integrations, migrations, private deployments and ongoing support separately, with clear acceptance criteria.

Fixed scope

A starting package covers one business unit, up to five priority AI tools and two sensitive workflows. We agree access, evidence, exclusions and a fixed fee before kickoff. Typically 2-3 weeks after the agreed evidence and access are available; larger environments need a separate scope.

Remote delivery

Available where access and data-handling arrangements permit. Use sanitized examples until secure evidence handling is agreed.

Implementation and training

Configure approved cloud tools, deploy private AI where justified, and train staff, managers, executives and boards. Books are optional companions, not prerequisites.