What we solve ·What is unaccounted for, and what am I missing?

Vanguard · Guide

Which AI tools are in use without anyone having approved them?

I know there is AI in use and I do not know which tools or with what information.

What is being used off the record, with what data and with what exposure, and what is best approved, replaced or cut.

Book a call25 minutes. Just one question when you book.

Shadow AI inventorySend this page to whoever decides

This sounds like you if

  • The AI policy was written before there was an inventory of what is already in use.
  • A tool showed up on one area's corporate card.
  • Audit asked for the list of tools in use and today it is not consolidated.
Who delivers
The founder, on every engagement.
How engagements work
Fixed price, with written acceptance criteria before we start.
Timeline and price
Fixed, in writing, after we assess your case in the 25-minute conversation.

Use this today, without hiring anyone

The three discovery routes, in the version you can run alone. None of them finds everything; cross referenced they find almost everything. Separately they already give you the picture.

  1. Minor spend. Review corporate cards and purchases below the approval threshold for the last twelve months, looking for small monthly subscriptions. It is the fastest route and the one that generates the least resistance.
  2. Outbound internet. Ask networking for the most visited destinations over the last thirty days and cross reference against your list of approved tools. What is left over is your shadow inventory.
  3. Amnesty. Declare in writing that there will be no consequences for declaring use, then ask. Without that declaration, half of it does not appear, and the half that hides is the one with sensitive data inside.

Classifying matters more than listing. What data leaves, where it goes and what the terms of service say about how long the vendor keeps it. A free tool that retains your information indefinitely is more serious than a paid one that does not.

How we solve it

The method, not the promise.

  1. The amnesty gets declared in writing before anything is asked. Without it the rest does not work.
  2. Discovery runs through three cross referenced routes: network, minor spend and declared use.
  3. It gets classified by real risk: what data leaves, where it goes, with what vendor retention.
  4. The decisions already being made with those tools without anyone knowing get identified.
  5. A recommendation per tool (approve, replace or cut) gets made with cost and friction, and the one-page minimum rule gets drafted.

What you receive

  • The inventory of undeclared use, by area and by tool.
  • The risk and data exposure classification for each one.
  • The list of decisions already automated off the record.
  • The recommendation with cost and the one page minimum use rule.

The proof that applies here

  • Asset and dependency discovery and inventory over an infrastructure of 60,000 servers.
  • Eight years under regulatory supervision, where the inventory was the reviewer's first question.
  • 250,000 incidents analyzed: the same work of extracting signal from logs at scale.

Before you hire

The inventory is delivered by area and by tool, never as a list of names: it is not material for disciplining anyone, and that condition is not negotiable.

Discovering and inventorying assets nobody registered is infrastructure operations work, not AI consulting. It is what was done for years over sixty thousand servers, and the only new thing here is what you are looking for.

If an auditor asks you today for the list of AI tools in use, what do you hand over?