Choose Save as PDF as the destination.
aicost.ai
VC/PE Diligence Memo
2026-07-28
Pricing as of 2026-07-20
aicost.msp-client-ai-exposure-audit

Verdict
AUDIT FINDING

6 HIPAA client(s) have no enforced allowlist. An endpoint without a BAA that can receive PHI is an unauthorised disclosure, not a paperwork gap.

Key figures

Weighted exposure 88
Clients with no allowlist 28
Share of book with a gap 70%
Attested clients with a gap 14
Avg reachable endpoints 88
Remediation hours 36.8
Remediation cost $5,329
What to do Start with the HIPAA clients. An attested client without an enforced allowlist is a finding, not a backlog item.

Assessment

28 of 40 clients (70 percent) have no enforced allowlist. Across the book the average reachable endpoint count is 88, so that is the breadth an auditor would ask you to account for. Of those gaps, 14 sit on clients holding an attestation, which is where the exposure actually is. Remediation is estimated at 36.8 hours, about $5,329 at $145 an hour.

Questions for the founder

  1. For each attested client, who can name every model endpoint their data can reach today?
  2. When a developer adds a provider SDK, what stops it reaching an endpoint nobody approved?
  3. Is the allowlist enforced at the gateway, or written in a policy document nobody checks?
  4. Which clients changed routing tool in the last quarter without the allowlist being revisited?
  5. If an auditor asked for the reachable endpoint list tomorrow, how long would it take to produce?

Assumptions & method

Generated by AICost.ai (aicost.msp-client-ai-exposure-audit), CloudIntelligence.ai LLC. API pricing is sourced vendor-exact from a daily-maintained pricing single source of truth as of 2026-07-20. Values marked with an asterisk are analyst estimates rather than vendor-verified data. This memo is a cost-and-unit-economics analysis prepared for diligence purposes; it is not investment advice, and it does not assess team, market, product or legal risk.