Security review, drafted

Your enterprise deal is stuck in security review. We draft your way out.

SecurityDraft turns your own docs into the due-diligence pack a stalled B2B AI deal needs — a completed AI security questionnaire, a public trust page, and a mapping to the EU AI Act, ISO 42001 and NIST AI RMF. You review, sign off, and own it.

Fixed price from £900 ex‑VAT · Turnaround in days · No SaaS subscription, no GRC hire

Built on the CSA AI Controls Matrix 18 control domains EU AI Act · ISO 42001 · NIST AI RMF
The problem

You closed them on the product. Then their security team sent a spreadsheet.

200 lines asking which model providers you use, whether their data trains your model, and where your ISO 42001 mapping is — and the deal went quiet.

You don't have a GRC hire. Every day the questionnaire sits idle can slide the deal into next quarter — and a stalled enterprise deal isn't a delay, it's revenue you've already earned, frozen. SecurityDraft turns your existing architecture notes, sub-processor list and DPA into the exact artifacts a security reviewer is waiting for, so you answer once, answer well, and get back to selling.

How it works

Three steps. Days, not weeks.

STEP 01

You send what you already have

Architecture and data-flow notes, your model-provider & sub-processor list, any SOC 2 or ISO evidence, and your DPA. A short email back-and-forth fills any gaps. No new documentation to write.

STEP 02

We draft the pack

We map your material to the CSA AI-CAIQ across all 18 control domains and draft prepared responses to every applicable control — plus your trust page and cross-framework mapping.

STEP 03

You review, sign off & own it

Every answer comes to you to verify and correct. You sign off, and the finished pack is yours to hand your buyer — your representations, in your voice, on your domain.

What's in the pack

Three deliverables an enterprise reviewer actually asks for.

01 · Questionnaire

Completed CSA AI-CAIQ

The emerging canonical AI-specific security questionnaire, drafted from your own docs across all 18 AICM domains — data security, model security, supply chain, governance and the rest. Your finished master for every buyer that follows.

02 · Trust page

Public AI trust page

A clean, self-hostable page on your domain summarising your posture, AI-specific controls, sub-processors, data-handling and model governance. It pre-answers the buyer's first question — and gives sales a link to send.

03 · Mapping

Cross-framework appendix

Your answers indexed to the EU AI Act, ISO/IEC 42001 and NIST AI RMF, so a reviewer working from any of the three finds exactly what they need. Mapping to clauses — not advice on your legal obligations.

Pricing

Fixed price. One-off. You own it.

A fraction of a $9,600/yr trust-center subscription — and a rounding error against the $50K–$500K of deal revenue a stalled review holds up.

Starter
£900 ex-VAT
  • +Completed AI-CAIQ (core control set)
  • +One-page trust summary
  • Full public trust page
  • Cross-framework mapping
Choose Starter
Standard
£1,450 ex-VAT
  • +Full AI-CAIQ / AICM questionnaire
  • +Full public trust page
  • +EU AI Act · ISO 42001 · NIST AI RMF mapping
  • +Turnaround in days
Choose Standard
Plus
£2,000 ex-VAT
  • +Everything in Standard
  • +Buyer-specific / SIG-Lite crosswalk
  • +One revision round after buyer feedback
Choose Plus
Keep it current — re-issue / refresh £350/yr. The frameworks move; we update your pack as your product and the questionnaires evolve.

All prices exclude VAT. SecurityDraft is a trading name of Zebtech Ltd (UK, VAT-registered); VAT is added at checkout where applicable.

In plain terms

What SecurityDraft is — and what it isn't.

This scope line is deliberate. It keeps you in control of every claim made in your name.

What we do

  • Draft prepared responses from the documentation you supply
  • Map your answers to the leading AI frameworks
  • Build your trust page and cross-framework appendix
  • Make you fast and buyer-ready

What we don't

  • Audit, test or inspect your controls
  • Attest that any statement is true
  • Issue certification, assurance or a compliance guarantee
  • Give legal advice on your framework obligations

Every answer is drafted from your material for you to review, verify, correct and sign off. Once you do, the answers are your representations to your buyer, and the finished pack is yours. The truth of each answer is, and remains, yours — that's what keeps you in control.

Questions

Straight answers.

Do you certify, audit or guarantee this is compliant?+
No — and any vendor claiming they can, on a one-off pack built from your docs, is overselling. We draft prepared responses from your own material and map them to the frameworks; you verify and sign off every answer, and they become your representations to your buyer. We don't audit or test your controls and issue no certification. If you need an independent audit or an ISO 42001 certificate, you need an accredited auditor — a different service, and we'll say so plainly.
Is my data safe?+
Yes, and we keep our footprint minimal. We only take the documents needed to draft the pack, we don't want your customers' personal data and ask you not to send it, and we never reuse one client's material in another's. We retain your documents only for delivery plus a short support window, and delete on request. The models and tools we use to draft are disclosed to you on request.
How fast?+
Days, not weeks, once we have your intake and any quick follow-ups by email. The AI-CAIQ is a fixed, structured instrument, so drafting is repeatable and quick — the gating step is your review and sign-off, which is entirely in your hands.
We call OpenAI / Anthropic / Bedrock under the hood — can you still do this?+
Yes. Most of our buyers are application-layer AI vendors calling third-party models. The AICM's supply-chain and model-security domains are built for exactly that — the pack documents your provider chain, your training-data contractual position, and your tenant isolation, which is what reviewers actually probe.
What do you need from me?+
Whatever you already have: architecture and data-flow notes, your model-provider and sub-processor list, any existing SOC 2 or ISO evidence, and your DPA — plus a short email exchange to fill any gaps. You won't be asked to write new documentation. That's the point.
Unstick the deal

Send us your docs today.
Hand your buyer a finished pack this week.

Fixed price from £900 ex-VAT. Turnaround in days. You review, sign off, and own every word.

enquiries@securitydraft.com