Engagement

How engagements actually unfold at TaoQ AI. If you are considering booking a discovery call and want to understand what working together looks like in practice, read on.

Before we start

The discovery call is a 30-minute conversation, not a sales call. We use it to understand what you are building, where it is in the lifecycle, what your security and compliance exposures look like, and whether our scope is a good fit for what you need. If it is not, we will tell you directly. If it is, we will scope an engagement and quote on a follow-up call.

Lifecycle entry points

SECURE-BY-DESIGN

AI Threat Model & Security Architecture Review

Who it's for

  • System architecture is committed; code is being written
  • RAG, agentic, or multi-model system with real attack surface
  • Upcoming EU AI Act classification decision or Annex IV scaffolding need
  • Security or compliance concern identified by a CISO, board, or investor

Typical flow

  • Week 1: System walkthrough with the engineering team. Data flow mapping. Threat model (STRIDE for AI, attack trees). Classification under EU AI Act Article 6.
  • Week 2: Deep review of specific subsystems: data pipeline, retrieval, agent tool chain, output handling. Annex IV scaffolding.
  • Weeks 3-N: Remediation. Sitting with engineers on specific findings. Closing vulnerabilities. Writing evidence alongside the code. Duration depends on the number and severity of findings.

Deliverables

  • Threat model document
  • Security architecture review with findings and remediation plan
  • Annex IV scaffold (technical file structure, initial evidence)
  • Closed findings with verifiable code changes

How it ends

  • Handoff to the engineering team with documentation
  • Often extends into pre-launch Risk Baseline when the system nears launch

PRE-LAUNCH

AI Risk Baseline

Who it's for

  • System is about to ship or recently shipped
  • EU AI Act classification needed for a specific deployment
  • Investor or customer asking about AI security posture
  • Board preparing for AI governance disclosure

Typical flow

  • Week 1: System walkthrough, EU AI Act classification, initial agent red-teaming scan with Ziran (live system) or review of design artefacts (not-yet-live system).
  • Week 2: Deep red-teaming pass. Conformity gap analysis. Document drafting.
  • Week 3 (optional): Draft review with client, remediation priorities, final document.

Deliverables

  • Comprehensive, actionable executive document: classification, top risks, conformity gaps, prioritised remediation
  • Raw red-teaming findings (appendix)
  • Remediation roadmap with named owners if requested

How it ends

  • Handoff of the document
  • Often extends into the post-launch AI Security, Compliance & Governance Partner engagement when the roadmap requires ongoing attention

POST-LAUNCH

AI Security, Compliance & Governance Partner

Who it's for

  • System is live and evolving
  • Ongoing EU AI Act obligations (post-market monitoring)
  • Incident response capability needed for AI-specific issues
  • Architecture review required as the system scales

Typical flow

  • Monthly retainer, three tiers quoted against the specific risks surfaced earlier
  • Regular architecture review as systems evolve
  • AI Act evidence maintenance, conformity updates
  • Incident response availability
  • Governance roadmapping with engineering leadership

Deliverables

  • Ongoing threat model updates
  • Maintained Annex IV documentation
  • Incident response reports when applicable
  • Quarterly governance review

How it ends

  • Retainer continues as long as it earns continuation
  • Three-month minimum, no open-ended commitment

ACROSS THE LIFECYCLE

Continuous Security & Governance Partnership

Who it's for

  • Multiple AI systems at different lifecycle stages under one programme
  • Product evolving fast enough that separate Design, Pre-launch, and Post-launch engagements would create coverage gaps
  • Founding-team situation where security is woven in from day one, not bolted on later
  • Compliance obligations that span upstream design decisions and post-market monitoring without a clean launch boundary

Typical flow

  • Discovery call shapes the scope. A rapid diagnostic week covers whichever systems already exist: current-state scan, gap analysis against EU AI Act obligations and security posture.
  • Transitions into embedded support: threat models as new features are designed, red-teaming before releases, Annex IV evidence maintenance, incident response availability, architecture review as systems evolve.
  • Cadence agreed per engagement (weekly, bi-weekly, or monthly) based on the pace of the product.

Deliverables

  • Running threat model library, kept current as systems change
  • Maintained Annex IV documentation across the programme
  • Red-teaming reports on releases as they ship
  • Incident response reports when applicable
  • Quarterly programme review

How it ends

  • Reviewed quarterly against scope and value
  • No fixed endpoint, no open-ended commitment; continues as long as it earns continuation

Signals we are not the right fit

Honest disqualification. If any of these apply, a different partner will serve you better.

  • Your engineering team cannot be in the room during the engagement. The remediation model is collaborative; we sit with engineers and close findings alongside them. If the team is not available, the model breaks.
  • You need penetration testing of non-AI systems such as network, web application, API, or mobile. Different craft. Our specialism is AI-specific: agents, RAG, tool chains, AI Act conformity. Traditional pentesting is better served by a dedicated pentest firm.
  • You need a compliance certificate signed by an accredited body. We prepare the technical file and close the engineering gaps; the formal attestation comes from an accredited auditor.
  • You need pure legal interpretation of the EU AI Act. We translate the regulation into engineering controls; we do not do legal interpretation. Your General Counsel or a law firm is the right partner for that.
  • You want a deliverable handed over at the end with no remediation support. We do not operate that way. A report without closing the findings leaves you with the same risk you started with.