Engagement
How engagements actually unfold at TaoQ AI. If you are considering booking a discovery call and want to understand what working together looks like in practice, read on.
Before we start
The discovery call is a 30-minute conversation, not a sales call. We use it to understand what you are building, where it is in the lifecycle, what your security and compliance exposures look like, and whether our scope is a good fit for what you need. If it is not, we will tell you directly. If it is, we will scope an engagement and quote on a follow-up call.
Lifecycle entry points
SECURE-BY-DESIGN
AI Threat Model & Security Architecture Review
Who it's for
- System architecture is committed; code is being written
- RAG, agentic, or multi-model system with real attack surface
- Upcoming EU AI Act classification decision or Annex IV scaffolding need
- Security or compliance concern identified by a CISO, board, or investor
Typical flow
- Week 1: System walkthrough with the engineering team. Data flow mapping. Threat model (STRIDE for AI, attack trees). Classification under EU AI Act Article 6.
- Week 2: Deep review of specific subsystems: data pipeline, retrieval, agent tool chain, output handling. Annex IV scaffolding.
- Weeks 3-N: Remediation. Sitting with engineers on specific findings. Closing vulnerabilities. Writing evidence alongside the code. Duration depends on the number and severity of findings.
Deliverables
- Threat model document
- Security architecture review with findings and remediation plan
- Annex IV scaffold (technical file structure, initial evidence)
- Closed findings with verifiable code changes
How it ends
- Handoff to the engineering team with documentation
- Often extends into pre-launch Risk Baseline when the system nears launch
PRE-LAUNCH
AI Risk Baseline
Who it's for
- System is about to ship or recently shipped
- EU AI Act classification needed for a specific deployment
- Investor or customer asking about AI security posture
- Board preparing for AI governance disclosure
Typical flow
- Week 1: System walkthrough, EU AI Act classification, initial agent red-teaming scan with Ziran (live system) or review of design artefacts (not-yet-live system).
- Week 2: Deep red-teaming pass. Conformity gap analysis. Document drafting.
- Week 3 (optional): Draft review with client, remediation priorities, final document.
Deliverables
- Comprehensive, actionable executive document: classification, top risks, conformity gaps, prioritised remediation
- Raw red-teaming findings (appendix)
- Remediation roadmap with named owners if requested
How it ends
- Handoff of the document
- Often extends into the post-launch AI Security, Compliance & Governance Partner engagement when the roadmap requires ongoing attention
POST-LAUNCH
AI Security, Compliance & Governance Partner
Who it's for
- System is live and evolving
- Ongoing EU AI Act obligations (post-market monitoring)
- Incident response capability needed for AI-specific issues
- Architecture review required as the system scales
Typical flow
- Monthly retainer, three tiers quoted against the specific risks surfaced earlier
- Regular architecture review as systems evolve
- AI Act evidence maintenance, conformity updates
- Incident response availability
- Governance roadmapping with engineering leadership
Deliverables
- Ongoing threat model updates
- Maintained Annex IV documentation
- Incident response reports when applicable
- Quarterly governance review
How it ends
- Retainer continues as long as it earns continuation
- Three-month minimum, no open-ended commitment
ACROSS THE LIFECYCLE
Continuous Security & Governance Partnership
Who it's for
- Multiple AI systems at different lifecycle stages under one programme
- Product evolving fast enough that separate Design, Pre-launch, and Post-launch engagements would create coverage gaps
- Founding-team situation where security is woven in from day one, not bolted on later
- Compliance obligations that span upstream design decisions and post-market monitoring without a clean launch boundary
Typical flow
- Discovery call shapes the scope. A rapid diagnostic week covers whichever systems already exist: current-state scan, gap analysis against EU AI Act obligations and security posture.
- Transitions into embedded support: threat models as new features are designed, red-teaming before releases, Annex IV evidence maintenance, incident response availability, architecture review as systems evolve.
- Cadence agreed per engagement (weekly, bi-weekly, or monthly) based on the pace of the product.
Deliverables
- Running threat model library, kept current as systems change
- Maintained Annex IV documentation across the programme
- Red-teaming reports on releases as they ship
- Incident response reports when applicable
- Quarterly programme review
How it ends
- Reviewed quarterly against scope and value
- No fixed endpoint, no open-ended commitment; continues as long as it earns continuation
Signals we are not the right fit
Honest disqualification. If any of these apply, a different partner will serve you better.
- Your engineering team cannot be in the room during the engagement. The remediation model is collaborative; we sit with engineers and close findings alongside them. If the team is not available, the model breaks.
- You need penetration testing of non-AI systems such as network, web application, API, or mobile. Different craft. Our specialism is AI-specific: agents, RAG, tool chains, AI Act conformity. Traditional pentesting is better served by a dedicated pentest firm.
- You need a compliance certificate signed by an accredited body. We prepare the technical file and close the engineering gaps; the formal attestation comes from an accredited auditor.
- You need pure legal interpretation of the EU AI Act. We translate the regulation into engineering controls; we do not do legal interpretation. Your General Counsel or a law firm is the right partner for that.
- You want a deliverable handed over at the end with no remediation support. We do not operate that way. A report without closing the findings leaves you with the same risk you started with.