Know who controls your AI stack — in 14 days.
A founder-led audit that maps every vendor in your stack to who owns its model, which jurisdiction can compel it, and where you’re exposed — board-reportable, fixed price, and quoting each vendor’s own wording wherever they publish it. Not handed to a junior; not a generic checklist.
Two minutes, no email required. Or write to support@vannus.co — we reply personally within one business day.
→ See an example audit (composite, illustrative) · Or try the free Rate-my-stack tool first
If a customer, an auditor or a regulator asks who controls your AI vendors, and you cannot answer in writing.
AI tools arrive one at a time, each approved by a different team, none of them through a procurement review. The result is a stack nobody can describe: which legal entity you actually contract with, which country’s law can compel it, and what each vendor’s own agreement says about your data. That gap is invisible until something forces you to put it in writing — and then it is urgent. The Concierge audit answers it per vendor, with the vendor’s own wording and the date attached.
Answering a customer’s DPA
An enterprise customer’s data-processing agreement asks you to name your AI sub-processors, their contracting entities and their governing law. You have two weeks, the answer goes in a signed document, and being wrong about a named company is the part that carries.
A security questionnaire or an auditor
Someone is asking, on the record, what your AI vendors do with your data and who can reach it. You need a dated document with the vendor’s own wording quoted, not a summary you wrote from memory.
Inherited a stack
You took over privacy, security or compliance and the AI vendors were chosen before you arrived. You need a baseline you can defend — what is in the stack, who controls each one, and where the exposure actually sits.
A different question from SaaS spend management.
SaaS-management and procurement platforms answer what are we paying for, and can we pay less. They do that well, they integrate with finance systems, and if that is your question you should buy one of them rather than this.
The Concierge audit answers a different question: who controls the AI vendors you have already adopted, which jurisdiction can compel their data, and which of them is a thin layer over someone else’s model. That question does not appear on a spend report, and it is the one that comes up when a customer sends a data-processing agreement, when security reviews a renewal, or when someone asks where the prompts actually go.
It is a fixed-price engagement with no minimum spend, which makes it reachable for a company under 500 people that has accumulated AI tools without a procurement process. Every finding is tied to the vendor’s own published wording, and where a vendor discloses nothing we record that rather than inferring a value — so you can hand the result to somebody who will check it.
Four steps. Fourteen days.
No long retainer, no kickoff theater, no slide decks pretending to be insight. We take in your stack, run it through our methodology, write up the findings, and walk you through them on a call.
Intake
You share your current tool list, monthly spend per tool, and what each one is supposed to do. ~30 minutes of your time.
Analysis
We score each tool against the Vannus 9-dimension methodology and cross-reference against your team's actual workflow. We do the work; you keep your week back.
Written audit
You receive a written report: who legally controls each vendor, mapped to your own contracts and residency commitments, with every determination cited to the vendor's own documentation or recorded as not disclosed.
Walkthrough call
60-minute call to walk through the findings and the answers you now have to give. 30 days of follow-up email.
Specifically, you get:
eight concrete deliverables, all yours to keep. Below is the full breakdown of what the $7,500 buys — written so you can hold us to it.
- ✓ 1. Written audit report (PDF, typically 15-25 pages) The core deliverable. Executive summary, stack inventory, 9-dimension scoring per tool, the contracting entity and governing law behind each vendor with the source quoted, a jurisdiction exposure map, and a recommended sequence of changes. Yours to share internally with finance, IT, or your board.
- ✓ 2. Per-tool one-page scorecards For every tool in your stack: a single page showing which legal entity you contract with, which jurisdiction can compel it, what the vendor's own documents say about the models it runs, any caution flags, your team's stated use case, and the verdict. Every line quotes the vendor's own wording with a source and a date, or records that they do not disclose it. Designed to drop into a Slack channel or a procurement ticket without rewriting.
- ✓ 3. Jurisdiction and contracting-entity table The entity you actually contract with for each vendor, its country, and the governing law of its terms — quoted from the vendor's own documents where they publish them, and recorded as not disclosed where they do not, so you can stress-test each determination against the vendor’s own document.
- ✓ 4. Vendors whose published terms meet the bar you set Where a vendor fails a bar you stated, we list vendors in the same category whose published terms state the thing the incumbent’s do not — each quoted and dated, scored under the same published methodology. A document comparison, not a recommendation: we do not rank them, do not estimate what switching would cost or take, and do not tell you which to choose. If no vendor in a category publishes terms that clear your bar, we say so rather than filling the slot.
- ✓ 5. Sovereignty & compliance map of your current stack Where each tool is hosted, who owns the parent company, and which compliance regimes (SOC 2 Type II, ISO/IEC 42001, GDPR, HIPAA, EU AI Act, FedRAMP) it currently satisfies. Surfaces exposure to US CLOUD Act, CFIUS, or jurisdictional concerns before they become procurement blockers. (See the sovereignty grid in the composite example →)
- ✓ 6. Written 30/60/90-day action plan The findings sequenced into an executable plan: what to answer in 30 days, what to put in writing to a vendor in 60, what to re-verify in 90. Each step has an owner placeholder, estimated time investment, and dollar impact attached.
- ✓ 7. 60-minute walkthrough call with the founder Live Q&A, prioritization, and a working session on the first three changes to make. Recorded on request so anyone on your team can rewatch. Our founder delivers this call directly — not handed off to an analyst or contractor.
- ✓ 8. Up to 5 follow-up email exchanges within 30 days Implementation questions answered as you execute — vendor counter-offers, contract terms, comparable-tool questions. Bounded scope so each audit gets real attention.
Plus, you keep everything. All written deliverables are yours. We retain a redacted summary only with your explicit permission. No SaaS subscription on the audit itself, no portal lock-in, no ongoing access fees — the audit closes when you say it does.
Fixed price. No surprises.
Two minutes, no email required. Or write to support@vannus.co — we reply personally within one business day.
How we stand behind the work.
1. Pre-screened intake. Every prospective engagement starts with a 20-minute intake call before any contract is signed. If we don't believe we can materially improve your position on who controls your AI vendors, we decline the engagement rather than take the fee. We'll tell you on the intake call — not after you've paid.
2. Outcome-aligned follow-up. If, ninety (90) days after audit delivery, your post-audit review surfaces concerns about the analysis, we provide a follow-up assessment at no additional charge to revisit the recommendations against your real-world implementation experience. If at the 90-day mark you don't believe the audit paid for itself, write to us directly — we'd rather work with you on a follow-up than walk away from the relationship.
The terms of pre-screening and follow-up assessment are documented in your engagement letter and in our Terms of Service, Section 12.6.
Common questions
See if Vannus is a fit
Four questions. Two minutes. No email required. We'll tell you within two minutes whether your stack profile fits what we audit, or whether the free Vannus surfaces are the right starting point.