AI for trust work
AI governance, privacy, security, risk, and compliance, work delivered by experienced practitioners with a blended agent and human team. Agents do the work, while humans retain judgement and deliver outcomes.
Proposal · Q14
Awaiting reviewIs access to production reviewed on a schedule?
Yes. Access to production is reviewed quarterly and enforced through SSO.
The problem
A single audit request can need a PDF policy, a spreadsheet export, three screenshots, and an email thread. A scan shows how a system is configured. An integration log shows what happened. Someone still has to read both against the control and write down what they prove.
Workspace fragments
6 of 6 linkedProducts
Services
Our solution
Agents draft the work, check claims against your records, and propose the changes. Experienced practitioners keep the judgement, review the result, and deliver the outcome across AI governance, privacy, security, risk, and compliance.
CASK is the workspace that team shares. When you want our practitioners to run an engagement, see services.
See how CASK worksEvidence
Access to production is reviewed quarterly and enforced through SSO and role-based approvals.
Cited
Subprocessor DPA is on file and matches the SOC 2 report.
Agent
Why choose us
CASK keeps your files on your desktop, and you choose what goes to the AI provider.
Work on a privacy assessment from your desktop, with the records and draft in the same workspace.
Sent in this request
The instruction and 2 excerpts
Stays on your desktop
The workspace
Choose an approved provider for a questionnaire task, or use a local model when the work calls for it.
Access reviews are performed annually.
Access reviews run every quarter, owned by the IT Lead.
Access Review Procedure v2
The agent drafts a risk assessment. Your reviewer checks the evidence and decides the rating and treatment.
Do you encrypt customer data at rest?
Yes, in managed storage.
Encryption Standard v2, section 3
Was your continuity plan tested this year?
Not Provided · no record in the workspace
A questionnaire asks about a control with no supporting record. The answer is flagged as Not Provided for review, instead of treating an assumption as evidence.
Services
Outcome as a Service (OaaS) puts our practitioners on one defined project, such as an AI governance plan, a privacy assessment, or audit preparation. Compliance as a Service runs the recurring work, with scheduled reviews, evidence refreshes, and open actions tracked to their owners. On both, CASK writes the first draft from your records, and a practitioner edits it and signs off.
Explore our servicesInventory, risk, policy, and readiness
By hand
AI tools, owners, risks, and policies are collected team by team, then copied into a new sheet for each review.
With us
We inventory the AI you build and buy, assess risk and impact, write the policy, and prepare what an ISO 42001 audit asks for. CASK drafts each file. A practitioner checks it.
Examples of how we work. Scope and timing are agreed for each engagement.
The team
Our founders have more than two decades of combined experience in privacy, compliance, and security engineering. We have used AI agents on this work for several years, and we built CASK around what held up under review.
Read our story
