AI·IA
Inspect · Analyze · Assure
Your AI rollout has risks nobody on your team has mapped. Find the big ones in three minutes — free.
Agentic-AI risk triage for the systems that run your money. Built by practitioners who pressure-test AI the way attackers and auditors actually think.
Our rule from the field: treat every system like the cameras are on — because now they are.
Just a web page Runs 100% in your browser No logins · no installs · your selections never leave this page
See what one innocent sentence can do Real prompt patterns, rotating — tap a dot to browse.

Illustrative demonstrations of how ordinary requests can produce unintended results — awareness examples, not attack instructions. No working exploit code.

1 · Your organization

Context changes which risks matter.
0 selected

2 · Financial & operational systems

Select everything in production — including the systems around the ERP.
0 selected

3 · AI in the environment

Include pilots and "just a few power users."
0 selected

4 · Access reality

Answer for how things actually are, not policy.
0 selected

5 · Controls in place

Check only what actually exists and is current.
0 selected

Risk triage results

These are the risks visible from a checklist.

The serious ones live in your configuration — permission inheritance, automation identity, injection paths. A structured review maps them against your actual environment under NDA, with findings your auditors and board can use.

This automated triage is informational only and is based solely on the selections you provided. It is not an audit, security assessment, legal advice, or professional opinion, and it does not establish an engagement or duty of care. Findings describe categories of risk commonly associated with the indicated configurations; your actual exposure depends on facts not collected here.

Offerings

Test yourself, test continuously, or have us test you. Either way it's your environment and your data — we never touch either.
Free

Risk Triage

This page. Three minutes of checkboxes, a severity-ranked report with an exposure grade, printable for your next leadership meeting. No account, no install — nothing you select leaves your browser. Free forever.

Subscription

Control Test Packs

The demos above are the illustrative versions. Subscribers license the runnable ones: a library of vetted, safe-to-execute test prompts, each mapped to a named control objective, with sandbox setup guides, pass/fail rubrics, and evidence logs your auditors can file. Updated as agent capabilities change. You run them in your own environment, on your own authorization — your data never touches us.

Coming soon · annual license per company
Consultation

Independent Review

We administer the full test suite and a structured review of your environment under NDA — fixed fee, scoped deliverable, findings written for your auditors and board. Pre-acquisition diligence on deal timelines. Portfolio programs for sponsors who want one standard across every company they hold.

Test packs are licensed for use in your own environment with your organization's written authorization, and are designed as safe checks — probes against sandbox and canary data you control, never live exploits.

Seen something? Tell the story.

Auditors, controllers, admins, consultants — practicing or retired. Field stories are how the detection rules above get built.

We collect real-world accounts of AI, automation, and control failures around financial systems and compile them — anonymized — into our detection ruleset. What happened, which systems were involved, what the control gap was, and how (or whether) it was caught. Contributors of substantive casework may be invited into our contributor program as it develops. Do not include company names, personal names, account data, or documents you are not authorized to share.

Submissions are voluntary and treated as confidential. Stories are delivered through Formspree, a form-processing service — we receive what you write and whatever contact you choose to include; leave the contact field blank to stay anonymous to us. As with any web form, use a personal device and network if discretion matters to you. This is not a legal whistleblower channel: reports to regulators (e.g., the SEC or IRS whistleblower programs) carry their own legal protections and processes, and nothing here substitutes for them or for advice from a lawyer. If you are bound by an NDA or confidentiality obligation, get legal advice before sharing specifics.

About the founder

Engineer by training · systems builder by trade · auditor by instinct.

I'm Shawn Kimble. Over twenty-five years I've administered, automated, migrated, and audited the systems that run companies' money — from Financial Director & CIO of a multi-subsidiary family construction group to global NetSuite OneWorld environments run through M&A, external audits, and IPO readiness. At nearly every stop, I found something someone hoped nobody would look at. AI·IA exists because AI agents are now inside those same systems, acting under trusted identities at machine speed — and almost nobody is testing what they'll actually do.

Read the full story → Schedule a consultation