Vannus Concierge

Know who controls your AI stack — in 14 days.

A founder-led audit that maps every vendor in your stack to who owns its model, which jurisdiction can compel it, and where you’re exposed — board-reportable, fixed price, and quoting each vendor’s own wording wherever they publish it. Not handed to a junior; not a generic checklist.

Two minutes, no email required. Or write to support@vannus.co — we reply personally within one business day.

→ See an example audit (composite, illustrative)  ·  Or try the free Rate-my-stack tool first

$7,500 fixed price 14-day deliverable Founder-led — not handed off
Who it's for

If a customer, an auditor or a regulator asks who controls your AI vendors, and you cannot answer in writing.

AI tools arrive one at a time, each approved by a different team, none of them through a procurement review. The result is a stack nobody can describe: which legal entity you actually contract with, which country’s law can compel it, and what each vendor’s own agreement says about your data. That gap is invisible until something forces you to put it in writing — and then it is urgent. The Concierge audit answers it per vendor, with the vendor’s own wording and the date attached.

Answering a customer’s DPA

An enterprise customer’s data-processing agreement asks you to name your AI sub-processors, their contracting entities and their governing law. You have two weeks, the answer goes in a signed document, and being wrong about a named company is the part that carries.

A security questionnaire or an auditor

Someone is asking, on the record, what your AI vendors do with your data and who can reach it. You need a dated document with the vendor’s own wording quoted, not a summary you wrote from memory.

Inherited a stack

You took over privacy, security or compliance and the AI vendors were chosen before you arrived. You need a baseline you can defend — what is in the stack, who controls each one, and where the exposure actually sits.

Where Vannus fits

A different question from SaaS spend management.

SaaS-management and procurement platforms answer what are we paying for, and can we pay less. They do that well, they integrate with finance systems, and if that is your question you should buy one of them rather than this.

The Concierge audit answers a different question: who controls the AI vendors you have already adopted, which jurisdiction can compel their data, and which of them is a thin layer over someone else’s model. That question does not appear on a spend report, and it is the one that comes up when a customer sends a data-processing agreement, when security reviews a renewal, or when someone asks where the prompts actually go.

It is a fixed-price engagement with no minimum spend, which makes it reachable for a company under 500 people that has accumulated AI tools without a procurement process. Every finding is tied to the vendor’s own published wording, and where a vendor discloses nothing we record that rather than inferring a value — so you can hand the result to somebody who will check it.

How it works

Four steps. Fourteen days.

No long retainer, no kickoff theater, no slide decks pretending to be insight. We take in your stack, run it through our methodology, write up the findings, and walk you through them on a call.

STEP 01

Intake

You share your current tool list, monthly spend per tool, and what each one is supposed to do. ~30 minutes of your time.

STEP 02

Analysis

We score each tool against the Vannus 9-dimension methodology and cross-reference against your team's actual workflow. We do the work; you keep your week back.

STEP 03

Written audit

You receive a written report: who legally controls each vendor, mapped to your own contracts and residency commitments, with every determination cited to the vendor's own documentation or recorded as not disclosed.

STEP 04

Walkthrough call

60-minute call to walk through the findings and the answers you now have to give. 30 days of follow-up email.

What's included

Specifically, you get:

eight concrete deliverables, all yours to keep. Below is the full breakdown of what the $7,500 buys — written so you can hold us to it.

Plus, you keep everything. All written deliverables are yours. We retain a redacted summary only with your explicit permission. No SaaS subscription on the audit itself, no portal lock-in, no ongoing access fees — the audit closes when you say it does.

Pricing

Fixed price. No surprises.

$7,500
USD · one-time · payable by ACH, wire, or card
See if Vannus is a fit → Email our team directly

Two minutes, no email required. Or write to support@vannus.co — we reply personally within one business day.

How we stand behind the work.

1. Pre-screened intake. Every prospective engagement starts with a 20-minute intake call before any contract is signed. If we don't believe we can materially improve your position on who controls your AI vendors, we decline the engagement rather than take the fee. We'll tell you on the intake call — not after you've paid.

2. Outcome-aligned follow-up. If, ninety (90) days after audit delivery, your post-audit review surfaces concerns about the analysis, we provide a follow-up assessment at no additional charge to revisit the recommendations against your real-world implementation experience. If at the 90-day mark you don't believe the audit paid for itself, write to us directly — we'd rather work with you on a follow-up than walk away from the relationship.

The terms of pre-screening and follow-up assessment are documented in your engagement letter and in our Terms of Service, Section 12.6.

FAQ

Common questions

How is this different from the free catalog?
The free catalog records each vendor on its own — the contracting entity, its country, the governing law of its terms. The Concierge audit takes your vendor list and maps each record to your own contracts and data-residency commitments, resolves which of a vendor’s several agreements actually binds you, and delivers it dated and quoted in a form you can hand to an auditor. The catalog answers “who controls this vendor?” The audit answers “what can we say, in writing, about the vendors we already run?”
Will you try to upsell us into other tools or services?
No. Where the audit names another vendor, it is because that vendor’s published terms state something the incumbent’s do not — quoted and dated, never ranked, and never tied to affiliate revenue from your case — the architectural separation is documented at /neutrality and verified by an automated test on every deploy. There is nothing recurring to buy here, and the audit deliverable stands on its own.
How is my data handled? Will you sign an NDA?
Your tool list and spend data are kept confidential and not shared. Intake materials are received via email (Resend) or shared doc and stored in Vannus's operational account — not exposed to any third party; retained per Privacy Policy §7. The audit deliverable is yours. We retain a redacted summary internally for case-study purposes only with your explicit permission. Mutual NDA on request — the Vannus standard NDA is short and one-sided in your favor; we'll counter-sign within one business day of intake if it's a precondition for your team.
What's the largest stack you can audit? What if we have internal/proprietary tools?
The published methodology applies cleanly to stacks up to ~30 AI subscriptions; beyond that, we'll quote a custom timeline rather than the standard 14 days. Internal or proprietary tools (your own AI build, an unreleased vendor product, a niche tool not in our catalog) are evaluated against the same 9-dimension framework — the record is qualitative rather than catalog-scored, but the evidence standard is the same — quoted where the vendor publishes, “not disclosed” where it does not. We've never declined an engagement because a stack had unfamiliar tools; tell us on the intake call and we'll confirm scope.
How fast can you start?
Typically within 5 business days of contract signing and intake. Audit completion is 10-14 days from kickoff.
Who actually does the work?
Every audit is founder-led. It is not handed off to a contractor, analyst, or third-party agency. That's the whole point of "Concierge."
What if my stack is already optimized?
We'll tell you on the intake call — before you sign anything. If we don't believe we can materially improve your position on who controls your AI vendors, we decline the engagement rather than take the fee. The free Vannus surfaces (the catalog, the published methodology, and the free stack check) are likely the right starting point in that case.
Are the audit’s findings guaranteed to stay true?
No, and the deliverable says so on its face: every finding carries the date the document was read. Vendors change their terms, their corporate control, and the model behind a product, usually without notice. If your 90-day post-audit review surfaces concerns, you get a free follow-up assessment.
Fit check

See if Vannus is a fit

Four questions. Two minutes. No email required. We'll tell you within two minutes whether your stack profile fits what we audit, or whether the free Vannus surfaces are the right starting point.

1. How many SaaS or AI tools does your team currently pay for?
2. When was the last time anyone established, in writing, who controls each of these vendors?
3. Which best describes your AI tool adoption?
4. What prompted you to look at this?

Your answers are scored locally for instant feedback. Nothing is sent unless you choose to send your situation to our team using the form that appears after scoring.

Scope. A Concierge audit establishes, from vendors’ own published documents, which legal entity you contract with, that entity’s country, and the governing law of its terms. Those are informational findings quoted to their source. They are not legal advice, not a legal conclusion, and not a representation that any government has taken or will take any action. Vannus is not a law firm and no attorney-client relationship arises from an engagement. It is not a substitute for advice from your own qualified counsel. Vannus is operated by PRAXIS AI LLC.