Family Sentinel
AI security & hardening · for organizations

Your staff are already using AI.
Nobody has checked what it can reach.

Somebody in your organization is pasting documents into a chatbot. Somebody built a form with AI-written code. Somebody connected an assistant to the shared drive. None of that is wrong — but no one has written down which tools exist, what data they can touch, or whether the vendor trains on what you send. We do that, and then we fix what it turns up.

Read-only assessment · Fixed scope · Call or text (940) 281-6672

~1 in 4AI-coded repositories in a 549-project study exposed a secret. Roughly 1 in 3 had a critical or high-severity finding.
Free is not freeSeveral major AI providers state plainly that free-tier prompts may train their models. Most organizations have never checked.
No inventoryAlmost nobody we meet can list which AI tools their staff use, or what those tools can reach.

The numbers, honestly

A July 2026 study scanned 549 public repositories that identified themselves as AI- or "vibe"-coded. Among the 467 substantial ones: 48.8% had injection-category flaws, 30.2% had a critical or high-severity finding, and 23.3% exposed a secret. The most common single issue was unescaped HTML rendering, in 43%.

Two caveats we will give you before you ask, because we would rather you trusted the rest: the study capped findings at 300 per repository, so the worst offenders are under-counted; and the sample includes small demo projects, which flatter the average. The authors' own reading is that real applications score worse. We cite it because it is measured, not because it is scary.

Services

AI Inventory & Exposure Review
from $2,500
  • Which AI tools your staff actually use — not which ones are approved
  • What data each one can reach: mail, drive, CRM, donor and payroll records
  • Does the vendor train on your data? Answered per tool, in writing
  • Every AI agent, integration and API key with access to your systems
  • A one-page acceptable-use policy your staff will actually read
  • Ranked findings, and what to shut off first
Schedule a scoping session
AI-Written Code Review
from $3,500
  • Static review of applications built with AI assistance
  • Exposed secrets, committed .env files, hardcoded credentials
  • Injection and unescaped-output flaws — the two most common classes
  • Wildcard CORS, missing authorization checks, unsafe defaults
  • Each finding demonstrated, not just named — with the fix
  • Re-review after your fixes, included
Start with a scoping session
AI Agent Hardening
from $4,500
  • For organizations running assistants or agents against real systems
  • Least-privilege review: what the agent can reach vs what it needs
  • Prompt-injection exposure where an agent reads untrusted content — email, documents, web pages
  • Human-approval gates on anything that moves money or sends mail
  • Logging you could actually investigate an incident with
  • A written escalation path for when an agent gets something wrong
Start with a scoping session

Why us for this

We run an AI system against other people's email every day. That means we have had to answer, for ourselves and in writing, the exact questions we will ask you: which model provider, does it train on inputs, what does the model see, what does it never see, who approves an action before a human is contacted, and what happens when it is wrong.

Our own answers are on our Trust page and our Privacy policy. We think an AI security assessment from someone who has not had to answer those questions about their own product is worth very little.

The large agent-governance platforms now being funded are real and good — and they are built for enterprises with a SecOps team, an IAM team and a platform team. If you have those, buy one of those. If you do not, the useful thing is a person who inventories what you have, tells you what to turn off, and writes it down. That is this.

Schedule a scoping session.

Thirty minutes, free. We ask what your staff are using and what it can reach, and tell you honestly which of these is worth doing — or that you are already fine.

Schedule a scoping session

Or call the Security Architect directly — (940) 281-6672

security@familysentinel.org