Sirrapa IT · Security & cloud engineering

Your AI demo works.
Now ship it without regret.

Sirrapa IT runs a structured technical audit on your AI POC and tells you, in 5 to 10 working days, whether it is safe, manageable and production-ready, or what must be fixed first.

Timeline5-10 working days
Starting price€5,000fixed fee
OutputScore · Findings · Roadmap
The record

20+ years of hands-on security engineering, delivered in regulated, audit-heavy environments.

Public sector
Banking
Transport
Aviation
Retail
Professionally insured.
Why this exists

Teams now build AI faster than their governance can keep up. Production is a different game.

01
Is the application safe enough for real users?
02
Where do personal data and customer data actually go?
03
Are permissions, access and tenant isolation in order?
04
Are prompts, outputs and AI tool calls controllable?
05
What happens during abuse, leak or prompt injection?
06
Are logging, monitoring and incident response set up?
07
Will this pass a client review or security questionnaire?
08
Should we harden, or partially rebuild?

These are the questions the POC2Prod Blueprint™ answers, with technical evidence, in 5 to 10 working days.

The five audit dimensions

What we look at

Each engagement covers the same five dimensions. No checklist theatre, a working review by a senior engineer with security, cloud and AI-tooling background.

01

Architecture & production-readiness

Is it manageable, scalable and explainable enough for real production?

architecturedeploymentenvironmentsrollbackbackupsownership
02

Application security

The classic app- and platform-level risks: auth, secrets, dependencies, exposure.

authn / authzsecretsdepsinput validationtenant isolation
03

AI / LLM risk

The risks normal security reviews miss: prompt injection, tool use, agency, output trust.

prompt injectiondata leakageinsecure tool useexcessive agencyAI logging
04

Privacy & data governance

What data is processed, where it goes, what the retention story actually is.

GDPRpersonal dataretentionminimisationDPIA relevance
05

Compliance readiness

Technical input for compliance questions, not legal advice.

GDPREU AI ActNIS2BIO2client questionnaires
What you get

A score, ten ranked risks, and a clear next step.

Within 5-10 working days, you get a compact technical readiness audit, written so a CTO, a Head of Product and a non-technical board member can all act on it.

BLUEPRINT v1.0 · SAMPLEExampleAI B.V. · Support Assistant POC
5-10 day audit
2.6/5READINESS
Hardening required before production

2.6 / 5

Readiness score · 9 domains

Architecture readiness3/5
Application security2/5
AI / LLM risk2/5
Privacy & data governance2/5
Secure SDLC & supply chain3/5
Cloud & deployment3/5
Logging & monitoring2/5
Incident readiness2/5
Documentation & handover3/5
9 domains · 10 ranked findings · backlogNext step: AI Hardening Sprint™ →

Top findings, ranked by severity

Anonymised excerpt. Real reports include 10 ranked findings, detailed evidence and acceptance criteria for each.

P0
AI / LLM RiskApp Security

AI tooling has overly broad data access

Backend retrieves customer context by ticket id without proving the support agent has rights to that specific record.

P0
Privacy / GDPRLogging

Full prompts and outputs are logged

Application logs contain customer questions, names, e-mail addresses and ticket bodies, with no defined retention.

P1
App SecurityAI / LLM Risk

No rate-limiting on AI endpoints

Model-call endpoints have no per-user or per-tenant limits and no cost guardrails.

Read a redacted sample Blueprint →

Process

5 to 10 working days, fixed scope, one fixed fee.

We work to a predictable rhythm. No open-ended consulting, no creeping scope.

Day 0

Qualification & proposal

30-min call, scope confirmed, proposal signed.

Day 1

Intake & access

Intake questionnaire, read access to repo and one environment, kickoff call.

Day 2-4

Audit

Architecture, security, AI risk, privacy and compliance review. Up to three interviews.

Day 5-7

Findings & scoring

Top 10 risks ranked. Scorecard per domain. Remediation backlog with effort estimates.

Day 8-10

Report & readout

Written report, 60-min presentation call, recommended next step.

Self-assessment

Is your POC ready for the Blueprint™?

Six honest questions. Two minutes. We tell you whether an audit is the right next step, or whether you should fix one thing first.

QUESTION · 01/06
Q01

Does your AI feature actually process customer data or personal data?

Including support tickets, CRM records, uploads, account data.

~ 2 MIN · NO SIGNUP
The productladder

POC2Prod Blueprint™ is the entry point. The rest is optional.

POC to Production OS™ is the methodology. The Blueprint™ is the first rung, most clients only need it. The rest are scoped only when the Blueprint says so.

ServiceWhen to useDurationFrom
02AI Hardening Sprint™We fix the P0 and key P1 findings: authz, secrets, privacy-safe logging, AI guardrails, CI/CD checks.Blueprint says: hardening required before production.2-4 weeks€10,000from
03AI Compliance Evidence Pack™Technical evidence map for client, board, auditor or legal counsel, dataflow, AI inventory, control summary.A client questionnaire or board review is incoming.1-2 weeks€5,000to €15,000
04Secure Rebuild™Partial or full rebuild of the components where the POC base is too weak. Only where rebuild is cheaper than hardening.Blueprint says: the base will not survive production.Scoped per engagement€25,000from
05Monthly Assurance Retainer™Periodic review, AI governance, security and compliance support as your system evolves.After going live, when AI risk is now part of operations.Ongoing€2,000/ month
Pricing

Three ways to start. Pick the smallest that fits.

All prices exclude VAT. Larger or more complex systems are scoped and quoted upfront.

Triage

call

Where most teams start
Free  · 30 minutes
No obligation. No sales playbook.
  • Confirm whether the Blueprint™ fits
  • Realistic scope and timeline
  • Likely risk areas, named upfront
  • Output options you actually need
Book a call
Ongoing

Monthly Assurance Retainer™

After production
€2,000  / month
Up to €8,000 / month at higher scopes.
  • Periodic AI risk review
  • Security & privacy backstop
  • Incident-response support
  • Quarterly board-ready summary
Talk to us
Frequently asked

Honest answers, before you book.

Is this legal advice or a compliance guarantee?
No. This is technical security, privacy and production-readiness support. We give you evidence and recommendations a CTO, board or legal counsel can act on, we do not give legal opinions or certify compliance.
Is this a penetration test?
No. A full pentest is a separate engagement. The Blueprint™ covers application-level security in a senior-engineer review, but is not a substitute for a formal pentest where one is required.
How much access do you need?
Read access to one or two repositories and one environment, plus up to three short interviews. We do not need production credentials. We work entirely against staging and code, unless the engagement scope explicitly says otherwise.
Will my code or data leave my environment?
We review code in your environment where possible. We do not store customer data. Notes and findings are kept in our system, encrypted at rest. A short DPA is provided on request.
What if the result is 'rebuild'?
We say so plainly. We only recommend Secure Rebuild™ when hardening is more expensive than rebuild for that specific component. We will never recommend rebuilding the entire system to invent more work.
We are not in the EU. Does this still apply?
Yes. The technical readiness work is jurisdiction-agnostic. Compliance relevance notes are flagged for the frameworks you actually face, GDPR, EU AI Act, NIS2, BIO2, or none of the above.
Can we pilot with a discount?
Our first three pilot engagements can be discounted in exchange for a testimonial or anonymised case study. We are not running a permanent discount programme.
What does a day-rate engagement look like?
For deeper or ongoing work I take fixed-scope blocks at a day rate, one engagement at a time. We agree the scope and the days up front, no open-ended retainer.
Where do you hand off?
I am a senior engineer, not an auditor, lawyer or pentester. For a certification audit, formal legal sign-off or a penetration test, I tell you exactly who to bring in. That clean hand-off is part of the value.
Next step

Bring the audit to your POC, not the other way around.

Thirty minutes is enough to know whether the Blueprint™ fits, what scope is realistic, and what risks are likely already in your system.

Whether you need a Blueprint, senior engineering by the day, or a bounded governance deliverable, the call is where we scope it.

Calendar not loading? Email contact@sirrapa.com