Product Readiness Review
Find out what they'll find, before they do.
I trace how data, access and AI actually work across the product, check the evidence behind the claims you make, and turn the material gaps into an ordered 30-day plan.
For teams with a working product and an outside deadline: a customer security review, an investor, a regulated pilot. Most often university spin-outs, healthtech, AI SaaS and AI-built products.
- Price
- €1,200 fixed
- Turnaround
- 5 working days
- Scope
- Up to 3 key flows
- Includes
- Kickoff + readout
Exact scope and boundaries
One product, up to 3 key user or data flows, read access to one repository and its cloud setup, the agreed documentation needed to examine those flows, a 60-minute kickoff and a 60-minute readout call. Anything larger is quoted first. Delivered within 5 working days of receiving access and materials. Engineering-led readiness work; not legal advice, certification or a penetration test.
Already know exactly what must be delivered? You may not need the review. Book a fit call and I can scope the implementation directly.
The output
What you get
The review follows your product’s real data and AI flows, so the findings land where the risk actually is. Areas it commonly covers:
GDPR and data protection
Lawful basis, data minimisation, processor relationships and DPIA-ready documentation.
ePrivacy and cookies
Consent before non-essential cookies, trackers, analytics and marketing tags.
Data mapping
What personal data you hold, where it lives, and which systems and vendors it flows to.
Retention and deletion
How long data is kept, and whether deletion reaches backups, logs, exports and derived data.
Access and tenant separation
Who can see what, role and permission checks, and customer data isolation.
Security basics
Secrets, encryption, logging, backups and the answers a security questionnaire expects.
AI and third-party vendors
What reaches AI providers and other processors, and what they retain.
EU AI Act and AI governance
Risk classification, human oversight, transparency and record-keeping for AI features.
You leave with
- 01
Prioritised risk list
Every finding across data, security and AI, ranked by what blocks your deadline now and what can wait.
- 02
30-day action plan
Ordered, week-by-week work your team can start on immediately, with an owner for each item.
- 03
Documentation for your area
The evidence your situation calls for, such as a data-flow map, retention schedule or DPIA inputs.
- 04
Shareable summary and readout
A written summary for investors, customers or partners, plus a call to walk through the findings.
After the review
Choose who takes the plan forward
You don't have to hire me after. Most teams can run with the plan themselves.
Use the plan
Your team implements it
Take the prioritised 30-day plan, assign the work internally and use the readout to resolve questions before you begin.
No further engagement
Implement
Implementation Projects
Hands-on implementation of the findings: privacy and access controls, DPIA-ready documentation, EU AI Act work and architecture changes.
From €2,500
See implementation projects →Lead
Fractional Technical Leadership
A senior technical owner for the architecture, delivery and diligence work, without a full-time hire.
€2,000 to €6,000/month
See fractional leadership →