aicost.ai
VC/PE Diligence Memo
2026-07-28
Pricing as of 2026-07-20
aicost.msp-client-ai-exposure-audit
Verdict
AUDIT FINDING
6 HIPAA client(s) have no enforced allowlist. An endpoint without a BAA that can receive PHI is an unauthorised disclosure, not a paperwork gap.
Key figures
| Weighted exposure |
88 |
| Clients with no allowlist |
28 |
| Share of book with a gap |
70% |
| Attested clients with a gap |
14 |
| Avg reachable endpoints |
88 |
| Remediation hours |
36.8 |
| Remediation cost |
$5,329 |
| What to do |
Start with the HIPAA clients. An attested client without an enforced allowlist is a finding, not a backlog item. |
Assessment
28 of 40 clients (70 percent) have no enforced allowlist. Across the book the average reachable endpoint count is 88, so that is the breadth an auditor would ask you to account for. Of those gaps, 14 sit on clients holding an attestation, which is where the exposure actually is. Remediation is estimated at 36.8 hours, about $5,329 at $145 an hour.
Questions for the founder
- For each attested client, who can name every model endpoint their data can reach today?
- When a developer adds a provider SDK, what stops it reaching an endpoint nobody approved?
- Is the allowlist enforced at the gateway, or written in a policy document nobody checks?
- Which clients changed routing tool in the last quarter without the allowlist being revisited?
- If an auditor asked for the reachable endpoint list tomorrow, how long would it take to produce?
Assumptions & method
- Reachable endpoint counts per routing tool come from the engine catalogue, not per-client measurement.
- Remediation hours are an analyst estimate and scale with client count *
- Engineering time valued at $145 an hour *
- Attestation weights reflect consequence, not likelihood.