{"ok":true,"engine":"aicost.msp-client-ai-exposure-audit","inputs":{"clients_none":20,"clients_soc2":12,"clients_hipaa":8,"clients_export":0,"routed_none":15,"routed_litellm":20,"routed_openrouter":5,"routed_portkey":0,"routed_bedrock":0,"routed_unknown":0,"clients_with_allowlist":12,"hourly_rate":145},"result":{"ok":true,"verdict":"AUDIT FINDING","verdictReason":"6 HIPAA client(s) have no enforced allowlist. An endpoint without a BAA that can receive PHI is an unauthorised disclosure, not a paperwork gap.","decision":"Start with the HIPAA clients. An attested client without an enforced allowlist is a finding, not a backlog item.","decisionDetail":"Start with the 6 hipaa clients. An endpoint without a BAA that can receive PHI is an unauthorised disclosure, not a paperwork gap.","clientsTotal":40,"clientsWithAllowlist":12,"clientsWithGap":28,"gapSharePct":70,"avgReachableEndpoints":88,"weightedExposure":88,"attestedClientsWithGap":14,"remediationHours":36.8,"remediationCostUsd":5329,"headline":"28 of 40 clients have no enforced allowlist, so the reachable endpoint set is the router catalogue, roughly 88 endpoints, rather than the handful in their documented inventory.","workQueue":[{"attestation":"hipaa","clients":8,"clients_with_gap":6,"weight":7,"weighted_exposure":42,"consequence":"An endpoint without a BAA that can receive PHI is an unauthorised disclosure, not a paperwork gap."},{"attestation":"soc2","clients":12,"clients_with_gap":8,"weight":4,"weighted_exposure":32,"consequence":"An undocumented data flow makes the data-processing answer incomplete, which can produce a qualified opinion or a failed audit."},{"attestation":"none","clients":20,"clients_with_gap":14,"weight":1,"weighted_exposure":14,"consequence":"Housekeeping. Worth fixing, not urgent."}],"routerBreakdown":[{"router":"none","clients":15,"reachable_endpoints":1,"note":"Direct vendor SDK. Reaches exactly what the code names."},{"router":"litellm","clients":20,"reachable_endpoints":100,"note":"Broad provider support. Any provider added to the config stays reachable until removed."},{"router":"openrouter","clients":5,"reachable_endpoints":300,"note":"Large default catalogue, and cost-based auto-routing can select an endpoint nobody chose."}],"memo":"28 of 40 clients (70 percent) have no enforced allowlist. Across the book the average reachable endpoint count is 88, so that is the breadth an auditor would ask you to account for. Of those gaps, 14 sit on clients holding an attestation, which is where the exposure actually is. Remediation is estimated at 36.8 hours, about $5,329 at $145 an hour.","questions":["For each attested client, who can name every model endpoint their data can reach today?","When a developer adds a provider SDK, what stops it reaching an endpoint nobody approved?","Is the allowlist enforced at the gateway, or written in a policy document nobody checks?","Which clients changed routing tool in the last quarter without the allowlist being revisited?","If an auditor asked for the reachable endpoint list tomorrow, how long would it take to produce?"],"assumptions":["Reachable endpoint counts per routing tool come from the engine catalogue, not per-client measurement.","Remediation hours are an analyst estimate and scale with client count *","Engineering time valued at $145 an hour *","Attestation weights reflect consequence, not likelihood."],"limitation":"This scores CONFIGURATION REACHABILITY, not traffic. A reachable endpoint with no requests is an audit finding, not a disclosure. Confirm against router usage logs before telling a client data actually went somewhere.","notes":[],"inputs":{"clients_none":20,"clients_soc2":12,"clients_hipaa":8,"clients_export":0,"routed_none":15,"routed_litellm":20,"routed_openrouter":5,"routed_portkey":0,"routed_bedrock":0,"routed_unknown":0,"clients_with_allowlist":12,"hourly_rate":145}}}