The questions engineering leaders raise most often about the sprint, security, pricing, and what happens after. Don't see yours? Ask us directly.
The sprint
No. The sprint is designed to run alongside your existing work. The only standing commitment is a one-hour weekly alignment meeting plus the kick-off and end-of-sprint reviews. Stakeholder interviews are scheduled around your team's availability, and our engineers work in your stack without pulling your people off their own deliverables.
Senior engineers and architects who've worked in regulated healthcare software environments. The people reviewing your system are the same people who would help you build what comes next. There's no junior bench doing the real work behind the scenes.
You own everything: the findings, the fixes in motion, the five-pillar review, and the 90-day build sequence. Many teams continue with us as embedded engineering partners to execute that sequence — but there's no obligation to.
Security & compliance
We scope access to exactly what the review requires and work within your existing controls — your SSO, your repo permissions, your environments. For anything touching PHI, we follow least-privilege access and can work against de-identified or staging data where it's sufficient. We align on specifics during the week-one kick-off before any access is granted.
A concrete, demonstrable risk in how AI is used in your environment — for example, an integration sending PHI to a third-party model without a BAA, prompts or logs persisting sensitive data, or missing governance around what engineers can ship with AI tools. Specific and fixable, not a generic observation.
Yes — behavioral health software is our focus, and compliance pressure is the environment we're built for. We can execute a BAA as part of the engagement and operate within your compliance requirements throughout.
Pricing & commitment
Yes. One fixed scope, one fixed fee, no retainers and no surprise change orders — backed by the Two-Week Test. If we don't find an exposure and get a fix underway in the first two weeks, the engagement ends and you owe nothing.
Our guarantee: in two weeks we find a specific AI security exposure in your environment and get a fix underway. If we don't, you owe us nothing and the engagement ends. We take the risk so the decision to start is easy.
No. The sprint is a complete, standalone six-week engagement with no lock-in. Continuing with embedded engineering afterward is always your choice.
Getting started
Once we align on scope and access in a short scoping call, we can typically begin within a couple of weeks. Week one is access and review — real engineering work, not discovery workshops.
Access to your codebase, infrastructure and data; interviews with your tech team and key stakeholders; a one-hour weekly alignment meeting; and a kick-off plus end-of-sprint review. That's the whole ask.
Still have questions?
Book a short scoping call and we'll answer them directly, no obligation.