Services & pricing

Choose the right starting point for your technology exposure.

Every ATLAS engagement is designed to identify hidden technology cost and risk without taking custody of your data. Start with a focused snapshot or go directly to a complete audit.

Engagements

A clear path from first visibility to ongoing governance.

The flagship audit is the center of the model. The other engagements help you start at the right level or act on what the audit finds.

Start here

Exposure Snapshot

01

A fast, low-cost diagnostic that surfaces the headline findings of a full audit — a lightweight executive summary, not the full audit deliverable. The entry point, not a profit center.

$2,500–$5,000, flat fee
3–5 Business Days
Flagship engagementInitial findings within days; signed report and board deck within 1–2 weeks

Full Shadow IT & Shadow AI Audit

The core engagement — full 18-threat-category coverage, with Shadow AI treated as a first-class, mandatory part of the scope.

Tier A (50–150 employees) $25,000 · Tier B (151–500 employees) $65,000 · Tier C (501–1,000+ employees) $120,000–$250,000

What you receive
  • Full SaaS subscription discovery
  • Identity and access audit
  • OAuth token mapping and risk categorization
  • AI model exposure and Shadow AI endpoint analysis across the full 18-category taxonomy
  • Cloud infrastructure waste and sprawl analysis
  • Signed Executive Recommendations Report
  • Board-ready slide deck
  • Prioritized remediation roadmap with dollar values per finding

Self-funding — if the audit does not identify recoverable waste of at least 2× the fee, ATLAS refunds the difference, subject to dispute-resolution terms in the engagement agreement.

Remediation & Implementation Support

03

Execution support for the cost-cutting and security roadmap that follows an Exposure Snapshot or Flagship Audit. Highest liability of any ATLAS service — every change requires explicit client authorization under a defined scope-of-work boundary. No unilateral changes.

Fixed fee, scoped per engagement
Scoped per engagement

Compliance-Triggered Audit Packages

04

The same audit engine as the Flagship Audit, repackaged as three named, dated products tied to specific external regulatory triggers.

Fixed fee, calibrated per package
Narrower and faster than the Flagship Audit

Continuous Monitoring Retainer

05

Shadow IT and Shadow AI grow back. Watches your environment and alerts your CISO when a new unauthorized tool, user, or AI endpoint appears. Cross-sold from the Flagship Audit or any Compliance Package.

$3,000–$15,000/month (Small Enterprise $3,000 · Mid-Market $7,500 · Large Enterprise $15,000+)
Ongoing — real-time detection and monthly reporting
The process

A focused engagement, not another dashboard to manage.

Three steps take you from read-only connection to a signed, executive-ready report.

  1. 01

    Connect

    Authenticate read-only access to the agreed systems. Every connection is documented before work begins, and ATLAS cannot modify connected systems.

  2. 02

    Analyze

    The audit runs through the selected deployment method with automated inventory, AI-assisted analysis, and mandatory human review of every final finding.

  3. 03

    Report

    Receive a signed Executive Recommendations Report, prioritized findings, estimated value, and a practical remediation roadmap.

Client-controlled architecture

Your data stays within the boundary you choose.

ATLAS is designed so engagement data is processed within your environment or agreed cloud perimeter under the selected method, rather than being uploaded into an ATLAS-controlled data store.

Read-only by design

ATLAS cannot write to, modify, or delete anything in a connected system.

Choose the boundary

Use a local edge application, your cloud environment, or a stricter BYOM or air-gapped approach.

Remove the workspace

Temporary processing environments are decommissioned after delivery under the engagement terms.

Technical detail

The depth is here when your security team needs it.

Progressive disclosure keeps the main decision simple while giving technical evaluators a complete view of how the engagement works.

Four ways to run ATLASDeployment methods
A

Local Edge Application

Typical range: $2,500–$65,000

Best for CFOs and IT Directors who want simplicity with no technical complexity — the workhorse method, and the only method used for the Exposure Snapshot.

A lightweight application downloads to your corporate laptop. You authenticate your systems inside the app, click Run, and the entire analysis happens in your computer's active memory. When you close the application, all processing data is permanently wiped. Nothing was uploaded; nothing was saved beyond the finished report. This is the lowest-friction method and where most first engagements close.

B

Client Cloud Container

Typical range: $65,000–$120,000

Best for technology companies and enterprises with an internal DevOps team.

Your IT team deploys ATLAS as a self-contained package inside your own AWS, Azure, or GCP environment. It runs entirely within your existing network perimeter, generates your report, deposits it into your private cloud storage, and permanently deletes itself. A signed digital destruction certificate is generated as compliance documentation. Requires a real DevOps counterpart on the client side — ATLAS will recommend Method A instead if that's not in place.

C

Bring-Your-Own-Model (BYOM)

Add-on to A or B; no standalone price.

Best for regulated industries with strict AI data-handling requirements. Always an add-on to Method A or B, never standalone.

AI reasoning routes through local open-weight models running entirely offline on your hardware, or through your own corporate enterprise API key under your own zero-data-retention agreement. ATLAS never uses its own developer keys when processing your data; PII is stripped before any AI model sees it. Most relevant paired with Method A for healthcare/fintech clients, or Method B for defense-adjacent clients including CMMC 2.0 Readiness Audit engagements.

D

Air-Gapped Physical White-Glove

Typical range: $150,000–$300,000+ (positioning)

Best for regional banks, defense contractors, and organizations that prohibit any internet connectivity during an audit.

We travel to your headquarters with a FIPS 140-3 certified encrypted hardware drive. Everything runs offline inside your facility — no internet, no cloud, no external connection. We print the final report on your physical printer, deliver a live executive briefing, and hand the hardware drive directly to your CISO for physical destruction. Currently positioned as a capability we can credibly propose — including into defense-adjacent accounts, where the founder's active Secret clearance matters — rather than a typical near-term engagement path. The realistic entry point into the defense-adjacent segment is the CMMC 2.0 Readiness Audit, delivered via Method B + Method C through partnerships or prime flow-downs — not a solo Method D engagement. See Industries / Defense-Adjacent for detail.

18-category taxonomyWhat the audit can find
Severity and confidence are labeled in text, not communicated by color alone.
01CRITICAL

Zombie Accounts from Former Employees

Ex-employees still holding active access to corporate SaaS platforms after departure

Detected with high precision
02CRITICAL

OAuth Tokens Granted and Forgotten

Permanent authentication bridges to third-party apps created and never revoked

Detected with high precision
03CRITICAL

Malicious Browser Extensions

Over-permissioned extensions reading sessions and capturing authentication cookies

Detected probabilistically
04CRITICAL

Shadow AI in the Browser

Staff using consumer AI tools in browser tabs invisible to standard security stacks

Detected probabilistically from billing and usage patterns
05HIGH

Hardcoded API Keys in Extensions

Authentication credentials embedded in extension code and publicly extractable

Detected with high precision
06CRITICAL

Abandoned Cloud Databases

Forgotten test environments loaded with live production data sitting unmonitored

Detected with high precision
07HIGH

Data Exported to Personal Devices

Customer records and financial models downloaded to unmanaged employee devices

Requires client logging enabled
08HIGH

Public Document Sharing Links

Never-expiring public links exposing confidential documents to the open internet

Detected with high precision
09HIGH

Citizen-Built No-Code Applications

Employee-built Airtable and Notion systems handling sensitive data without IT oversight

Detected probabilistically
10HIGH

Unauthorized Automation Pipelines

Zapier and Make.com workflows routing sensitive data between systems without approval

Detected probabilistically
11HIGH

Proprietary Code in Public Repositories

Developer source code pushed to personal GitHub accounts and publicly visible

Detected with high precision
12HIGH

Shadow SaaS Subscriptions

Recurring software charges on department cards below the procurement threshold

Detected with high precision
13HIGH

Overprovisioned Licenses

Enterprise contracts with significantly more seats than active users

Detected with high precision
14MEDIUM

Duplicate Tooling

Multiple departments paying separately for functionally identical software

Detected with high precision
15MEDIUM

Orphaned Project Software

Subscriptions auto-renewing years after the project they supported was completed

Detected probabilistically
16CRITICAL

Unrevoked Vendor & Contractor Access

Former agencies and contractors still holding active credentials after engagement ends

Detected with high precision
17HIGH

Shadow Network Complexity

Unmapped subnets and forgotten infrastructure from past migrations creating blind spots

Requires client logging enabled
18CRITICAL

AI Training Data Exposure

Corporate data submitted to AI tools under terms permitting use for model training

Detected probabilistically from ToS analysis
Date-specific readiness workCompliance-triggered packages
A

CMMC 2.0 Readiness Audit

For defense-industrial-base mid-market suppliers facing the CMMC 2.0 Phase 2 deadline.

Final rule effective November 10, 2025; critical compliance deadline November 2026 — TorchSec; Pivot Point Security. This service is readiness and gap-remediation consulting only, not official CMMC certification — official certification requires an accredited C3PAO, which ATLAS is not. Leverages the founder's defense-logistics background and active Secret clearance as a genuine differentiator in trust and subject-matter fluency, not a substitute for accredited certification. Delivered via Method B + Method C, typically through partnership or prime-contractor flow-downs.

Readiness, Not Certification — official CMMC certification requires an accredited C3PAO.

B

SOC 2 AI-Readiness Pre-Audit

For tech and SaaS mid-market companies whose SOC 2 auditors are now formally scoping AI systems, shadow AI tools, and third-party model vendors directly into engagements.

Sources: RhindonCyber; SOC2Auditors.org. Positioned as prep work completed before your actual SOC 2 auditor arrives, reducing the risk of reopened findings.

C

EU AI Act Exposure Check

For any US mid-market company with EU customers or EU-based employees.

High-risk-system enforcement compliance deadline is August 2, 2026 — Holland & Knight. Applies extraterritorially, with fines up to €35M or 7% of global turnover — European Commission.

Separate non-audit offerSaaS Cost-Recovery

SaaS Cost-Recovery is not an audit or attestation. It is a separately contracted cost-optimization engagement paid as a share of documented recurring savings—approximately 15–20% of realized savings. It remains separate from the fixed-fee audit and compliance offers.

Common questions

The details enterprise buyers ask before signing.

How do we know our data truly never leaves our environment?

The architecture is designed to prevent it structurally. Method A blocks all external network connections at the application level. Method B runs entirely within your own VPC with one permitted outbound connection — depositing your finished report into your own storage. We provide full technical documentation for your security team to verify independently before any engagement begins.

We are a HIPAA-covered entity. What protections apply?

ATLAS is building toward the healthcare vertical as a Year 2 engagement, gated on a completed HIPAA Business Associate Agreement workflow, E&O/cyber insurance, and either a completed audit credential or a credentialed partner. We execute a HIPAA BAA before any engagement that will touch PHI, and PHI is never stored in an ATLAS-controlled system under our zero-data architecture. See Industries / Healthcare for current engagement status before booking a healthcare-scope call.

Can your AI models see our sensitive data?

Before any data reaches an AI model, a local privacy-masking process strips personally identifiable information — employee names, Social Security numbers, credit card numbers — replacing them with anonymous placeholders. The AI analyzes patterns, not personal details. Every AI-generated finding also passes through a human-in-the-loop review before it appears in your final report.

How long does an engagement take?

It depends on the service. The Exposure Snapshot is delivered in 3–5 business days. The Full Audit and Compliance Packages are automated in their data-gathering and analysis stages, but the finished, human-reviewed report and board deck is realistically delivered within one to two weeks of full data connection.

What does the guarantee actually cover?

The Full Shadow IT & Shadow AI Audit is a fixed fee, never a percentage of what we find. If the audit doesn't identify recoverable waste worth at least 2× our fee, we refund the difference, subject to a defined dispute-resolution process for what counts as 'recoverable.' A separate, distinctly labeled SaaS Cost-Recovery service (not an audit) is available on a contingency basis — see above for the distinction.

What happens after the initial audit?

Shadow IT and Shadow AI tend to grow back. Our Continuous Monitoring Retainer — $3,000–$15,000/month depending on organization size — keeps ATLAS watching your environment, alerting on new unauthorized tools, and generating monthly automated board summaries.

Are you CMMC certified?

No. The CMMC 2.0 Readiness Audit is explicitly readiness and gap-remediation consulting, not official CMMC certification — official certification requires assessment by an accredited C3PAO, which ATLAS is not and does not claim to be.

Not sure which service is right for you?

Every engagement starts with a 15-minute conversation. We will recommend the right starting point—or tell you plainly if ATLAS is not the right fit.