Ofreygo
Methodology

The Ofreygo Audit, end to end.

A finite, flat-fee engagement broken into three phases. Each phase has a fixed duration, a defined deliverable, and a direct mapping to the controls your existing compliance program already runs against.

Phase 01 · 48-hour discovery window

Discover

Scoped, read-only access is provisioned by your team. Ofreygo runs ten-plus discovery streams in parallel, working to a fixed discovery checklist. All activity is logged and shared with your security lead in real time.

Deliverables
  • ·Raw inventory across 5 data categories
  • ·Provenance log of every discovery source queried
  • ·Preliminary risk flags surfaced during collection
SSO / IdP logs

Okta, Google Workspace, Entra — signed-in apps

Expense data

Ramp, Brex, QuickBooks — API keys and SaaS on personal cards

Slack / Teams

Scoped queries for shared keys, prompts, custom GPTs

GitHub org scan

MCP servers, agent code, automation scripts, leaked credentials

Drive / Notion

Prompt libraries, SOPs, "system instructions" docs

Stakeholder interviews

Targeted conversations across Eng, Ops, Marketing, Finance

Phase 02 · 5-day synthesis window

Synthesize

Raw inventory is reconciled, de-duplicated, and mapped to owners. Every finding is categorized against SOC 2, ISO 27001, and NIST AI RMF control families so it lands cleanly with your existing governance program.

Deliverables
  • ·AI Landscape Map rendered as a production document
  • ·Risk Register ranked by severity × business-impact × remediation effort
  • ·Spend Analysis with on-ledger vs off-ledger breakdown
  • ·Draft 30/60/90 remediation roadmap
Phase 03 · Executive readout + handoff

Deliver

Sixty-minute leadership presentation covering findings, risks, spend, and the remediation roadmap. Followed by a one-page governance framework starter your team can adopt on day one.

Deliverables
  • ·Executive readout deck (22 slides)
  • ·One-page governance framework starter
  • ·Remediation roadmap hand-off with named owners
  • ·Full raw-data export for internal continuity
Control mappings

Mapped to the frameworks your program already runs against.

Every finding in an Ofreygo Audit is categorized against at least one mapped control, so discovery outputs can be consumed directly by your existing compliance, audit, and risk programs.

SOC 2

Trust Services Criteria
ControlNameHow Ofreygo maps to it
CC6.1Logical access controlsAudit inventories every unmanaged access path to AI systems and assigns an owner.
CC6.6Boundary protectionShadow workflows crossing trust boundaries (personal VPS, shared accounts) are identified and closed.
CC7.2System monitoringDiscovery establishes a baseline inventory monitoring can be operated against.
CC8.1Change managementPrompt libraries and agent configurations are brought under version-controlled change governance.

ISO 27001

Annex A
ControlNameHow Ofreygo maps to it
A.5.9Inventory of information assetsAI tools, agents, keys, and workflows added to the information-asset inventory with assigned owners.
A.8.2Privileged access rightsUnmanaged API keys (personal-card, shared-key) surfaced and scheduled for rotation or revocation.
A.8.16Monitoring activitiesBaseline established for ongoing monitoring of AI consumption and drift.
A.8.28Secure codingAgent code and prompts brought under review processes consistent with existing SDLC.

NIST AI RMF

Core Functions
ControlNameHow Ofreygo maps to it
GOVERNGovernGovernance framework starter surfaces accountability, policy, and roles across AI usage.
MAPMapThe audit itself IS the Map function: establishing context, categorizing AI systems, and mapping risks.
MEASUREMeasureRisk register quantifies severity, business impact, and remediation effort for every finding.
MANAGEManage30/60/90 roadmap operationalizes risk responses with owners and timelines.
Methodology one-pager

Send your team the full methodology PDF

A single PDF covering the three-phase methodology, per-phase deliverables, discovery-source checklist, and control mappings to SOC 2, ISO 27001, and NIST AI RMF. Sent to your work email within one business day.

No marketing. Just the PDF.

Ready to see your AI landscape?

Book a 20-minute call. We’ll walk through your current setup and decide together whether an Ofreygo Audit is a fit.

Where Mission Meets Compliance