engagements
Four stages. Each one is a fixed deliverable at a stated price.
Deployment Audit
£500
Up to 5 working days
Credited in full against the next stage.
Counts against a battery fixed, hashed and dated before it runs: which checks failed, on how many eligible probes, and whether each failure reproduced across passes.
No call included. The credit applies to a Remediation Specification or Build commissioned within 60 days.
- Environment
- Yours.
- What reaches me
- The responses file and the handover record.
Remediation Specification
£2,500–4,000
1–2 weeks
The architecture that fixes what the audit found, written so your engineers can implement it. Each failure mode named with its cause and its mitigation.
The screen-share reads your architecture. Code is written in the Build.
- Environment
- Yours. Screen-share.
- What reaches me
- The audit report, your corpus schema, and a short session with one of your lawyers.
In development
A fact-sheet constructor. It reads your configuration on your side and replaces the screen-share.
Compliance Architecture Build
£15,000–25,000
2–5 weeks
Built into your infrastructure. I write the Infrastructure-as-Code and hand it over; your engineers or your CI/CD deploy it.
Documentation ships with the work: architecture, data flow, deployment procedure, runbook. Your engineers are taken through it.
- Environment
- Mine for development. Yours for the system.
- What reaches me
- The masked corpus and the schema.
Monitoring Retainer
£5,000–8,000/month
Rolling monthly
Continuous evaluation and drift monitoring against public statutory corpora, with the evidence your buyers' risk assessments ask for.
No document content or matter identifiers are logged. A proprietary masking engine runs over the fields emitted. Updates are built against public data and GPG-signed.
- Environment
- Yours.
- What reaches me
- Telemetry carrying no personal data.
Across every stage
- No production credentials are held.
- Production debugging runs through break-glass access under your named approval with session recording, or a screen-share with your engineer at the keyboard.
- Development runs in an isolated environment against a structure-preserving masked corpus.
- Where a specialist is engaged for a narrow task, they work only in that environment against synthetic or masked data, hold no production access, commit under a GPG-signed named identity, and are under NDA and written agreement before starting.
- Your system is built into your cloud tenancy and runs there.
Jurisdiction, insurance, the sub-processor position and the transfer instrument are set out on Trust, with the artefact that verifies each one.
How the £500 audit runs
I write the corpus and the probes. You run them against your system.
I score the responses and write the
report.
What I need
Nothing is required. Each input below widens coverage.
| Input | Without it |
|---|---|
| An endpoint | You produce the responses your own way and send the file |
| Your response shape | You map the responses to the published schema yourself |
| Upload access | The public-law half of the battery runs standalone |
| Written authorisation | Injection, cross-tenant canary and index-freshness checks fall out of scope |
No document, no codebase, no credential, no call, at any point.
Running it
Where you have a public demo or trial, I generate the evidence myself. Otherwise you produce the responses, with your own tooling or with mine.
If you use the harness
The harness is legal-rag-audit, an open-source container. It runs five commands.
| Step | What it does | Runs on |
|---|---|---|
| plant | Generates a corpus with invariants minted per run | Your side |
| hash | Digests corpus, probes and answer key before any answer exists | Your side |
| validate | Three neutral probes. Confirms the response mapping. Scores nothing | Your side |
| generate | Fires the battery and records responses. Reaches your endpoints only | Your side |
| score | Offline. Opens no sockets, and asserts that at startup | Mine |
What the harness returns
Whatever produced the responses, score writes the report.
- Tier 1 · assertion-free
- Exact match against an answer key I authored. No model in the path.
- Tier 2 · instrument-scored
- Sentence-level entailment and retrieval relevance.
Each check gives a count against the probes eligible for it, not against the battery total. Each pass is counted separately: three failures of three is a defect, one of three is non-reproducibility.
The battery over-samples known failure surfaces. Its composition is fixed before the run.
You receive the corpus, the probes and a digest of the answer key before any response exists. The complete answer key ships with the report and hashes to what you were given. The withholding lasts the length of a run.
If the battery comes back clean there is nothing here to remediate, and the report says so. Your own buyer can re-run it. Nobody can re-date it.The harnesses are open source. See what they measure and where they fail
Personal data
| Input | Personal data? |
|---|---|
| An endpoint, or your own output | No |
| Your response shape | No |
| Upload access | No. The planted documents are mine |
| Written authorisation | Not data |
| Statutory corpus | No. Public |
| Corpus schema, from Remediation onward | No. Schema only |
| Domain knowledge, from one of your lawyers | Not data |
| Real production documents | Yes. Not needed |
The planted half of the battery is documents I wrote, so nothing leaves your environment except responses to my own material. The public-law half runs against your real index and its responses may carry your content.
Not in scope
- Health or clinical AI.
- Benchmarks of named commercial products.
- US regulatory advice.
- Regulatory interpretation. The measurements and the technical documentation are mine; whether they satisfy a given obligation is a determination for your counsel.
- Certification.
Start with the audit.
Email what your system does and the practice areas it covers.
contact@memonsystems.com