# Platform assurance: keeping AI-built software secure, current and auditable

> **In short:** Platform assurance is a retainer that regularly reviews AI-built applications for security, dependencies, cost and architecture and brings them up to date. It also prepares applications for external penetration tests and audits.

## The problem

AI makes new applications cheap, but each one needs maintenance, patching and review. Without a routine, a landscape of unreviewed tools grows.

## What you get

- Pentest readiness against a catalogue of more than 30 review areas
- Quarterly review report with actions and status
- Updates of framework, dependencies and AI models
- Evidence for data protection, ISO 27001 or NIS2 requirements of your customers

## How it works

1. **Initial review:** Architecture, data access, authentication, headers, dependencies and failure behaviour.
2. **Hardening:** Findings are fixed, every change documented with a test and a rationale.
3. **Routine:** Fixed review cycles, update windows and a channel for urgent security notices.

**Duration:** ongoing, initial review in 1 to 2 weeks  
**Commercial model:** Monthly retainer

## Frequently asked questions

### Do you review applications you did not build?

Yes. Applications that business units built themselves with AI tools benefit most from an independent review.

### Does this replace an external penetration test?

No, it prepares for one. External tests should stay independent. Our experience: well-prepared applications come out of the test without critical or high findings.