Product Readiness Review

Find out what they'll find, before they do.

I trace how data, access and AI actually work across the product, check the evidence behind the claims you make, and turn the material gaps into an ordered 30-day plan.

For teams with a working product and an outside deadline: a customer security review, an investor, a regulated pilot. Most often university spin-outs, healthtech, AI SaaS and AI-built products.

Price
€1,200 fixed
Turnaround
5 working days
Scope
Up to 3 key flows
Includes
Kickoff + readout
Exact scope and boundaries

One product, up to 3 key user or data flows, read access to one repository and its cloud setup, the agreed documentation needed to examine those flows, a 60-minute kickoff and a 60-minute readout call. Anything larger is quoted first. Delivered within 5 working days of receiving access and materials. Engineering-led readiness work; not legal advice, certification or a penetration test.

Already know exactly what must be delivered? You may not need the review. Book a fit call and I can scope the implementation directly.

The output

What you get

The review follows your product’s real data and AI flows, so the findings land where the risk actually is. Areas it commonly covers:

  • GDPR and data protection

    Lawful basis, data minimisation, processor relationships and DPIA-ready documentation.

  • ePrivacy and cookies

    Consent before non-essential cookies, trackers, analytics and marketing tags.

  • Data mapping

    What personal data you hold, where it lives, and which systems and vendors it flows to.

  • Retention and deletion

    How long data is kept, and whether deletion reaches backups, logs, exports and derived data.

  • Access and tenant separation

    Who can see what, role and permission checks, and customer data isolation.

  • Security basics

    Secrets, encryption, logging, backups and the answers a security questionnaire expects.

  • AI and third-party vendors

    What reaches AI providers and other processors, and what they retain.

  • EU AI Act and AI governance

    Risk classification, human oversight, transparency and record-keeping for AI features.

You leave with

  1. 01

    Prioritised risk list

    Every finding across data, security and AI, ranked by what blocks your deadline now and what can wait.

  2. 02

    30-day action plan

    Ordered, week-by-week work your team can start on immediately, with an owner for each item.

  3. 03

    Documentation for your area

    The evidence your situation calls for, such as a data-flow map, retention schedule or DPIA inputs.

  4. 04

    Shareable summary and readout

    A written summary for investors, customers or partners, plus a call to walk through the findings.

After the review

Choose who takes the plan forward

You don't have to hire me after. Most teams can run with the plan themselves.

  • Use the plan

    Your team implements it

    Take the prioritised 30-day plan, assign the work internally and use the readout to resolve questions before you begin.

    No further engagement

  • Implement

    Implementation Projects

    Hands-on implementation of the findings: privacy and access controls, DPIA-ready documentation, EU AI Act work and architecture changes.

  • Lead

    Fractional Technical Leadership

    A senior technical owner for the architecture, delivery and diligence work, without a full-time hire.

    €2,000 to €6,000/month

    See fractional leadership →