Where to start

Start with the question you most need answered.

Start with a free one-week proof of concept on 25 to 50 of your devices, with first findings in 24 hours. Together with a licence snapshot, it gives you an indicative risk estimate for your whole estate. Then choose your first question. From there, each engagement is fixed-fee and contracted, with a fixed scope; it runs in your own environment and leaves you with evidence you keep, whether or not you continue.

Illustrative example

What a one-week proof of concept shows

A pilot on 40 devices in a 1,200-person organisation, plus a licence snapshot. Invented figures.

1. Found in the pilot group (40 devices)

62

AI tools, agents and connectors found on the pilot devices

34

graded D or F

9

in use but not approved

6 of 40

pilot users with premium AI features they aren't licensed for

Risk grade across everything found in the pilot

  • A 1
  • B 12
  • C 15
  • D 28
  • F 6
  • 62 in total
Top risks in the pilot, with the action we recommend
FindingGradePilot reachAction
Unvetted MCP server connected to HR records F 3 devices Block, then review
Coding-agent skill reading API keys from config files F 2 devices Remove and rotate keys
Personal AI accounts used with company data D 7 users Move to approved tenant
Browser extension that reads page content D 4 devices Block
Premium Copilot features reaching unlicensed users Licence 6 users Fix before renewal

2. Indicative estimate for the whole estate (1,200 devices)

500 to 850

devices likely to have at least one high-risk (D or F) AI tool

Based on 23 of 40 pilot devices

90 to 270

users likely to have premium AI features they aren't licensed for

Based on 6 of 40 pilot users

High

indicative overall risk, before AI Estate Discovery confirms it

Based on grades, reach and licence exposure combined

Estimates are extrapolated from the pilot and shown as ranges, because a pilot is a sample. AI Estate Discovery and the Cost Review then confirm the real position across every device, user and licence.

Stage 1 focus · 5 to 10 days

AI Estate Discovery

“What AI is running across our estate, what does it commit us to, and could we defend it?”

You receive

  • A map of your AI estate across devices, platforms, business apps, connectors, identity and licences
  • An inventory of AI tools, agents, MCP servers (connectors that give AI access to your systems), browser extensions and personal accounts linked to company systems
  • A licence check before rollout: entitlements, features switched on for everyone, and metered AI already running
  • A risk grade for each, with prioritised actions
  • Your position against the EU AI Act, NIST AI RMF and ISO/IEC 42001
  • A board-ready summary and a recommended route through the journey

Start AI Estate Discovery

Stage 4 focus · 2 to 3 weeks · useful at any point

AI and Technology Cost Review

“Are we getting value from what we pay for, and are we licensed for what we use?”

You receive

  • Overlapping security and AI tools, and unused licences, identified
  • Microsoft and SaaS licence optimisation opportunities
  • Licence compliance exposure, including premium features switched on for unlicensed users
  • Metered AI usage and spending controls reviewed
  • AI subscriptions bought across teams, brought into view
  • Quantified savings, and a plan to capture them

Find the savings

Any stage

Fractional CISO and scoped delivery

Senior ownership of cyber and AI risk without a full-time hire, or delivery against a gap you have already identified. On the same 90-day terms as everything else.

Talk to us about scope

After the first 90 days

Ongoing support follows the journey: each tier covers more of the four stages (Adopt, Operate, Scale, Realise). You choose how far to go, and review it every quarter.

Covers: Adopt

Govern

  • Continuous AI inventory and A–F grading
  • Automatic blocking of high-risk AI
  • Approval desk for new AI tools
  • Licence compliance and AI spend review
  • Monthly summary

Covers: Adopt, Operate, Scale

Protect

  • Everything in Govern
  • Unlimited approval desk
  • Data protection and oversharing control
  • Identity and access governance for AI agents
  • Analyst triage and coding-agent policy
  • Quarterly board report

Covers: all four stages, adding Realise

Monitor

  • Everything in Protect
  • Agent behaviour monitoring with your security operations centre (SOC) or managed detection and response (MDR) provider
  • AI incident response playbooks and exercises
  • ISO/IEC 42001 and EU AI Act support
  • Pre-renewal licence position
  • Fractional CISO time

Technology licences are charged separately at cost or through your existing agreements.

Questions

Common questions

What is AI Estate Discovery?

A fixed-scope review that maps every layer of your AI estate: the AI tools on people's devices, the AI platforms you use, AI built into your business applications, connectors and agents, identity and data, and the licences behind them. It grades the risk, checks licensing before rollout and gives your board a summary and a recommended route. It usually takes 5 to 10 days.

What is the free proof of concept?

One week on a pilot group of 25 to 50 of your devices. Within 24 hours you see the AI tools, agents and connectors in use, each graded for risk. We add a licence snapshot for the pilot users, checking what they use against what they are licensed for, and review which premium AI features are switched on across your Microsoft 365 tenant. We then extrapolate from the pilot to give an indicative risk estimate for your whole estate, shown as ranges. The proof of concept is free; the 90 days that follow are a fixed-fee, contracted engagement.

Do we need to buy new tools?

No. We start with the security, identity and licences you already pay for, whether your estate runs on Microsoft, CrowdStrike, SentinelOne, Google or a mix. Anything new is added only where it is proven, and technology licences are charged at cost or through your existing agreements.

Are you tied to any vendor?

No. Peruze is independent. We don't mark up technology licences or earn more by locking you in, and specialist partners are held to the same 90-day terms as we are.

What happens at day 90?

You decide: continue, change course or stop, with no penalty either way. You keep everything produced, whether or not you continue.

Which frameworks do you align to?

ISO/IEC 42001, the EU AI Act and the NIST AI Risk Management Framework, plus DORA for financial services firms in scope.

Who do you work with?

UK organisations with 500+ employees and £2.5M+ annual IT spend, typically in financial services and insurance, healthcare, business services, manufacturing and retail.

Where are you on the journey?

A 30-minute conversation to find your starting point. No pitch.

Book a discovery call