Kretoss Technology  ·  Web · Mobile · AI Product Engineering Rate card

Turning your governance frameworks into working software.

A technology partnership brief prepared ahead of our call — covering what we understand about your practice, where we think product can carry the load that documents currently carry, and how we would build it with you. Rates and terms are on the rate card page.

Prepared for
Ash Masoha
The AI Integrity Group
Prepared by
Ankur Patel
CEO & Founder, Kretoss
Date
27 July 2026
Status
Discussion draft
for review on call
01Our reading

What we understand about your practice

You help enterprises get ahead of the AI regulatory landscape — risk assessment, controls, monitoring, shadow AI exposure, and readiness for the EU AI Act and the standards moving alongside it.

From your work and the consultant role you are hiring for, the shape of the engagement looks consistent: assess what AI a client actually has, classify it by risk, find the gaps, define the policies and controls, document the evidence, train the teams, and then keep it current as both the models and the rules move.

The last part is the hard part. Assessment is a project. Governance is a permanent operating function — and that is where your own positioning around continuous AI infrastructure points. Continuous is a software word.

02The constraint

Where a consulting practice hits its ceiling

Most governance work still lives in spreadsheets, Word policies, and slide decks. That works for the first engagement and gets expensive by the tenth. Four things break in a predictable order:

  • The inventory goes stale the day it is delivered. New models, new vendors, new prompts in production — the register no longer matches reality.
  • Evidence is scattered. When an auditor or a client's board asks for proof, someone reconstructs it by hand from email threads and folders.
  • Delivery does not compound. Every client gets a fresh build of substantially the same control library and the same reporting.
  • Revenue is capped by consultant hours. There is no asset in between the engagements.
Where we come in

We are not governance advisors — you are. We are the engineering team that takes your framework, your control library, and your judgement, and turns it into a platform your clients log into and your consultants deliver from.

03Proposal

A governance platform, built around your method

The build below is a starting proposal, not a fixed scope. Modules are deliberately separable — we would expect to argue about the order with you on the call.

M-01

AI system register

A living inventory of every model, tool, vendor API, and use case: owner, purpose, data sources, lifecycle stage, deployment status.

M-02

Shadow AI discovery

Connectors and survey workflows that surface unsanctioned AI use — SaaS integrations, browser extensions, expensed subscriptions, self-reported tooling.

M-03

Risk classification

A guided assessment that walks a system to its risk tier with your questions and your logic, and records the reasoning behind the outcome.

M-04

Control library & gap view

Your controls, mapped once and reused across every client. Gap status per system, per control, with owners and target dates.

M-05

Evidence vault

Versioned documentation, model cards, validation results, data lineage and sign-offs — held against the control they satisfy, with a full audit trail.

M-06

Continuous monitoring

Scheduled re-attestation, drift and performance thresholds, incident logging, and alerts when a system's profile changes enough to need re-review.

M-07

Report generator

One click from live data to a board pack, a readiness report, or a client-branded assessment — replacing the manual deck assembly.

M-08

Multi-tenant workspace

One platform, isolated client tenants, role-based access for your consultants and your clients' stakeholders. Your brand throughout.

Risk tiering, made visible

Tiering is the spine of the product. We would render it consistently everywhere it appears — register, dashboard, report — so a client's exposure is legible at a glance rather than buried in a column.

Prohibited  High risk  Limited / transparency  Minimal  General-purpose model

Note

The tiering logic, control wording, and obligation mapping stay yours. We build the engine to execute them and keep them versioned as the regulation moves — we will not put our reading of the law into your product.

04Build

How we would build it

LayerApproach
FrontendReact / Next.js with TypeScript. Dense, table-first interfaces designed for people who work in registers all day, not marketing pages.
BackendNode.js or Python services, PostgreSQL, row-level tenant isolation, append-only audit logging on every state change.
DocumentsTemplated generation to PDF and DOCX from live platform data, so a report is always a view of the record rather than a copy of it.
IntegrationsSSO, cloud and SaaS discovery connectors, model registries, ticketing, and webhook events out to your clients' existing stacks.
HostingEU-region deployment where client data residency requires it, with environment separation and documented access control.
Our own trailChange logs, release notes, and architecture documentation maintained as deliverables — your platform should be able to survive the scrutiny it applies to others.
05Delivery

Milestone plan

We work in fixed, demonstrable milestones. Each one ends in something you can open, use, and sign off — never a status report.

MilestoneOutcomeIndicative
M0 — DiscoveryWorkshops with you to capture the framework, control library, and assessment flow as it exists today. Ends with a clickable prototype and an agreed scope.1–2 weeks
M1 — Register & tieringMulti-tenant foundation, AI system register, guided risk classification, user roles. First client workspace usable.4–5 weeks
M2 — Controls & evidenceControl library, gap assessment views, evidence vault with versioning and audit trail.4 weeks
M3 — ReportingReport generator, dashboards, branded exports for client delivery.3 weeks
M4 — MonitoringRe-attestation cycles, alerting, incident log, shadow AI discovery workflows.4 weeks
M5 — HardeningSecurity review, performance, documentation, deployment, team handover and training.2 weeks

Timelines are indicative and assume a dedicated pod. We would firm these up after M0, and we are comfortable shipping M1 as a standalone pilot before you commit to the rest.

06Engagement

Three ways to work with us

ModelBest whenShape
Fixed-scope buildThe platform scope is settled and you want cost certainty.Milestone-based, fixed price per milestone, defined acceptance criteria.
Dedicated podThe roadmap will keep moving with the regulation.A monthly team — product engineer, frontend, backend, QA — working to your priorities.
Pilot firstYou want proof before a full commitment.M0 + M1 only, delivered as a working pilot you can put in front of one real client.

We work with clients across the USA, UK and EU from Ahmedabad, with a working-hours overlap that covers European mornings and US mornings.

Pricing

Full rates, packaged teams, fixed-price options and engagement terms are on a separate page — open the rate card. Nothing is held back for a call.

07Partner

Why Kretoss

  • We build products, not just websites. Web and mobile application development is our core business, and we run our own SaaS products — so we understand the difference between shipping a feature and running a platform.
  • Multi-tenant B2B is familiar ground. Tenant isolation, role-based access, audit trails and document generation are patterns we have implemented before, not research topics.
  • Direct access to the founder. You deal with me, not an account manager relaying messages to a delivery team.
  • Milestone discipline. Fixed deliverables, demos at every milestone, and no invoice for work you have not seen running.
Also worth raising

We noticed you are hiring an AI Governance Consultant. Those two needs often compete for the same budget — the consultant does the advisory work, and the platform is what stops that work from being rebuilt by hand for every client. If it is useful, we are happy to work alongside whoever you hire rather than instead of them.

08The call

What we would like to cover

  1. 00–05Introductions, and a quick check on whether we have read your practice correctly.
  2. 05–15How an engagement runs today, end to end — where your consultants lose the most hours.
  3. 15–25Walk the proposed modules and cut, add, or reorder them with you.
  4. 25–35Pilot scope: which single client or use case would prove this fastest.
  5. 35–45Data residency, security expectations, timelines, and how you would like to work commercially.

What happens after

Within 24 hours you get a revised scope reflecting the call and a firm milestone plan priced from the rate card. If you would rather test us before committing to anything, the discovery package is the cheapest way to do it — two weeks, a working prototype, and the fee credited back if you continue.