Statement of Work
AI Security Evaluations
Prepared by Starks Enterprise — starksenterprise.com · Irving "Gene" Starks Jr. · [email protected] · (980) 355-9706
Purpose & Overview
Starks Enterprise will evaluate the security posture of Client's AI systems — LLM applications, copilots, and agentic workflows — through structured adversarial testing, model risk assessment, and guardrail validation, producing an executive-ready risk report with prioritized fixes.
Scope of Work
Threat-model AI application architecture (prompts, tools, data flows, model providers)
Automated and manual prompt-injection, jailbreak, and data-exfiltration testing
Evaluation of guardrails, content filters, and tool-permission boundaries
Data-leakage and PII-handling review across prompts, logs, and vector stores
Model-supply-chain review (provider APIs, plugins, retrieval sources)
Findings report with severity ratings, reproduction steps, and remediation guidance
Executive briefing and engineering walkthrough of results
Deliverables
AI threat model and evaluation plan
Adversarial testing findings report with prioritized remediations
Guardrail and permission-boundary configuration recommendations
Executive risk summary and engineering deep-dive session
Timeline
| Phase | Activities | Duration |
|---|---|---|
| Phase 1 | Scoping, threat modeling & evaluation plan | 1 week |
| Phase 2 | Adversarial testing & guardrail assessment | 2-3 weeks |
| Phase 3 | Reporting, briefings & remediation planning | 1 week |
Pricing & Payment Terms
| Item | Timing | Fee |
|---|---|---|
| AI security evaluation (one-time, per application) | Due at kickoff | $12,000 - $25,000 |
| Recurring evaluation cadence (quarterly) | Quarterly, in advance | $4,000 - $8,000/quarter |
| Additional applications (each) | Added to engagement | $6,000 - $12,000 |
Invoices are due net 15. Quarterly evaluations are billed at the start of each quarter.
Client Responsibilities & Assumptions
Client will provide a staging or representative environment and test accounts for each in-scope AI application.
Client will identify the model providers, plugins, and data sources in use.
Client will authorize adversarial testing in writing and confirm blast-radius boundaries.
Out of Scope
Model training or fine-tuning services
Production incident response (available as a separate engagement)
Formal compliance certification (SOC 2, ISO) — advisory only
Acceptance Criteria
Evaluation executed against all in-scope AI applications without production impact
Findings report delivered with reproducible evidence for each finding
Executive briefing completed and remediation roadmap accepted by Client
Term & Termination
This SOW is effective upon signature by both parties and remains in effect through delivery and acceptance of all deliverables, or until terminated by either party with 30 days' written notice. Fees for work performed and expenses incurred prior to termination are non-refundable. This SOW is governed by, and incorporated into, the Master Services Agreement between Starks Enterprise and Client.