Engagement
How engagements actually unfold at TaoQ AI. If you are considering booking a discovery call and want to understand what working together looks like in practice, read on.
Before you book
The discovery call is a 30-minute conversation, not a sales call. I use it to understand what you are building, where it is in the lifecycle, what your security and compliance exposures look like, and whether my scope is a good fit for what you need. If it is not, I will tell you directly. If it is, I will scope an engagement and quote on a follow-up call.
Lifecycle entry points
SECURE-BY-DESIGN
Threat model and security architecture review
Who it's for
- System architecture is committed; code is being written
- RAG, agentic, or multi-model system with real attack surface
- Upcoming EU AI Act classification decision or Annex IV scaffolding need
- Security or compliance concern identified by a CISO, board, or investor
Typical flow
- Week 1: System walkthrough with the engineering team. Data flow mapping. Threat model (STRIDE for AI, attack trees). Classification under EU AI Act Article 6.
- Week 2: Deep review of specific subsystems: data pipeline, retrieval, agent tool chain, output handling. Annex IV scaffolding.
- Weeks 3-N: Remediation. Sitting with engineers on specific findings. Closing vulnerabilities. Writing evidence alongside the code. Duration depends on the number and severity of findings.
Deliverables
- Threat model document
- Security architecture review with findings and remediation plan
- Annex IV scaffold (technical file structure, initial evidence)
- Closed findings with verifiable code changes
How it ends
- Handoff to the engineering team with documentation
- Often extends into pre-launch Risk Baseline when the system nears launch
PRE-LAUNCH
AI Risk Baseline
Who it's for
- System is about to ship or recently shipped
- EU AI Act classification needed for a specific deployment
- Investor or customer asking about AI security posture
- Board preparing for AI governance disclosure
Typical flow
- Week 1: System walkthrough, EU AI Act classification, initial agent red-teaming scan with Ziran (live system) or review of design artefacts (not-yet-live system).
- Week 2: Deep red-teaming pass. Conformity gap analysis. Document drafting.
- Week 3 (optional): Draft review with client, remediation priorities, final document.
Deliverables
- Comprehensive, actionable executive document: classification, top risks, conformity gaps, prioritised remediation
- Raw red-teaming findings (appendix)
- Remediation roadmap with named owners if requested
How it ends
- Handoff of the document
- Often continues as the ongoing security and compliance partner when the roadmap needs ongoing attention
POST-LAUNCH
Ongoing security and compliance partner
Who it's for
- System is live and evolving
- Ongoing EU AI Act obligations (post-market monitoring)
- Incident response capability needed for AI-specific issues
- Architecture review required as the system scales
Typical flow
- Monthly retainer, three tiers quoted against the specific risks surfaced earlier
- Regular architecture review as systems evolve
- AI Act evidence maintenance, conformity updates
- Incident response availability
- Governance roadmapping with engineering leadership
Deliverables
- Ongoing threat model updates
- Maintained Annex IV documentation
- Incident response reports when applicable
- Quarterly governance review
How it ends
- Retainer continues as long as it earns continuation
- Three-month minimum, no open-ended commitment
DESIGN & DELIVERY
AI architecture and build
Who it's for
- Teams that need a principal architect who ships code with them
- An agentic, RAG, or multi-model system being designed or built now
- Platform and build-vs-buy decisions still open
- Security, governance, and evaluation that need to be engineered in rather than assessed afterwards
What I do
- Target architecture and architecture decision records for the AI system (or the AI platform) being built
- Agentic system design: tool-chain and permission scoping, orchestration pattern, state and memory, human-in-the-loop boundaries
- Retrieval strategy: RAG vs. structured query routing, grounding, evaluation of retrieval quality
- Model serving and MLOps/LLMOps pipeline design across cloud and edge
- Build-vs-buy and platform decisions, with the trade-offs written down
- Hands-on implementation alongside the team, with reviewable commits
- An evaluation harness, so the team can tell whether the system gives the right answers
What you get
- Target architecture document and decision log (C4-level diagrams where useful)
- Working, reviewed code in your repository
- Evaluation harness and baseline results
- Security and governance controls implemented as part of the build, with the evidence trail that the security engagements would otherwise produce afterwards
- Handoff package: documentation, runbooks, and a test plan for the next iteration
Commercial
- Fixed-fee scope where the scope is defined; milestone-based where it isn't yet. Quoted on discovery call.
Signals I am not the right fit
Honest disqualification. If any of these apply, a different partner will serve you better.
- Your engineering team cannot be in the room during the engagement. The remediation model is collaborative; I sit with your engineers and close findings alongside them. If the team is not available, the model breaks.
- You need penetration testing of non-AI systems such as network, web application, API, or mobile. Different craft. My specialism is AI-specific: agents, RAG, tool chains, AI Act conformity. Traditional pentesting is better served by a dedicated pentest firm.
- You need a compliance certificate signed by an accredited body. I prepare the technical file and close the engineering gaps; the formal attestation comes from an accredited auditor.
- You need pure legal interpretation of the EU AI Act. I translate the regulation into engineering controls; I do not do legal interpretation. Your General Counsel or a law firm is the right partner for that.
- You want a deliverable handed over at the end with no remediation support. I do not operate that way. A report without closing the findings leaves you with the same risk you started with.