LAYER 01
Network
Which AI services were reached, from which device or identity, how often, and over what period. Including the long tail nobody has on a blocklist yet.

Almost no owner can. That's the problem — not the AI itself. Find out what's actually running inside your business, what it can reach, and whether it puts your compliance obligations at risk.
THE ACTUAL RISK
It’s your best employee trying to move faster. A customer list pasted into a chatbot to clean it up. A contract run through a free assistant to summarise it. A browser extension nobody approved, quietly reading every page it’s opened on. The moment they hit enter, that data is outside your control — often retained by a company you never signed an agreement with.
Think of an AI assistant as an extremely capable, extremely confident intern. Fast, useful, and often right. But you wouldn’t hand a new intern the master password, unsupervised access to the client folder, and permission to take work home on a personal laptop. Right now, in most businesses, that’s exactly the access an ungoverned AI tool already has.
And if you carry compliance obligations — HIPAA, CMMC, NIST 800-171, PCI, or a cyber policy with a controls attestation — the stakes sharpen. “An employee used a tool we didn’t know about” does not satisfy an auditor, and it will not satisfy an underwriter looking for a reason to deny a claim.
STEP ONE · FREE
Ten yes-or-no questions about how AI is actually being used inside your business. Five minutes, scored instantly, and you’ll know where you stand before you talk to anyone. No email required to see your result.
A sample of what it asks
STEP TWO · FIXED FEE
The scorecard tells you what you know. It can't tell you what's actually happening inside your environment. The AI Exposure & Governance Assessment examines three independent layers, so findings are corroborated by evidence rather than inferred.
LAYER 01
Which AI services were reached, from which device or identity, how often, and over what period. Including the long tail nobody has on a blocklist yet.
LAYER 02
Every AI application and browser extension installed across your machines — and precisely what data each one is able to read.
LAYER 03
Third-party applications holding standing permission to your mail, files, and calendars. These survive password changes and persist until an administrator revokes them.
WHAT YOU RECIEVE:
TRANSPARENT PRICING
Priced by size and regulatory burden, not by hours — and the fee doesn't change with how much we find.
Want to see something real before committing to anything
$750
Fixed · 3 business days
Microsoft 365 permission audit
Every app that can read your mail and files
Two-page written finding
Credited in full toward a full assessment
26–75 seats, or multiple locations, or contractual security obligations
$3,500–5,000
Fixed · 3–4 weeks
All three evidence layers
Full deliverable set
Compliance gap mapping
Findings presentation
Credited toward remediation
[MOST COMMON]
76+ seats, or HIPAA, CMMC, NIST 800-171, or NERC CIP in force
$7,500+
Fixed · 4–6 weeks
Everything in Standard
Framework control mapping
Cyber insurance questionnaire review
Audit-ready evidence pack
Up to 25 seats and non-regulated? Essential tier runs $1,500–2,500. Ask.
Fee credited
Engage us for remediation within 60 days and the full assessment fee is credited against that work. You’re not paying twice to find and fix the same problem.
WHO’S DOING THE WORK
In 1994 I sat with CPAs who were nervous about moving off paper ledgers onto a computer. The machine was faster than they were, and that was exactly what scared them. My job was to show them how to trust it — carefully, with guardrails.
Thirty-two years later I’m having the same conversation about AI.
Heath Carlson, Principal · My Computer Pro LLC
Thirty-two years of technology consulting in the Valley. This assessment is delivered personally — not handed to a junior technician and not outsourced to a scanning vendor. The scan takes minutes; the judgement about what it means for your business is the part you’re paying for.
Step three · Free
If you'd rather talk it through than read a page, pick a time that suits you. No form, no phone tag.
WE WILL
WE WON’T
Booking a call doesn’t reserve an assessment slot. Assessments are scheduled separately and capacity is limited — we’re taking six before year end. The call is where we work out whether it’s the right fit and when we could start.
Straight answers
Will this disrupt my team or slow anything down?
No. Collection is read-only and passive. Nothing is installed permanently, no setting is changed, and no one’s work is interrupted. Most staff never know it ran.
Do you see what my employees typed into ChatGPT?
No, and we say so plainly in the report. The assessment establishes which services were reached and what each tool is capable of accessing — not the content of what was sent. Content-level inspection requires different licensing, and if that’s what you need, the report tells you exactly what it would take.
Is this just a sales pitch for something else?
The assessment is the product, and it stands on its own. You get the full written findings whether or not you engage us for anything afterward. If we recommend remediation, the fee credits toward it — and if you’d rather have your existing IT provider do the work, the roadmap is written so they can.
What if you don't find anything?
Then you have documented evidence of that, which is worth having the next time a customer, auditor, or insurer asks. In practice, we have not yet run this in an environment that produced nothing worth acting on — the Microsoft 365 permission layer in particular almost always surfaces something the owner didn’t know about.
If I book a call, how soon could you actually start?
The call is usually within a week. The assessment itself depends on capacity — we run six at a time, and a Standard engagement takes three to four weeks from kickoff to findings presentation. We’ll tell you the real start date on the call rather than after you’ve signed something.
We already have an IT provider.
Most of our assessment clients do. This is a specific, bounded engagement, and a second set of eyes on a risk category that emerged faster than most providers have adapted to. The roadmap is written so your existing provider can execute it.

Take the scorecard. If your number bothers you, we'll talk. If it doesn't, you've spent five minutes and learned something useful either way.