We start with named controls and the behavior they are supposed to enforce: access boundaries, tool permissions, approval requirements, monitoring coverage, alert handling, escalation and remediation. The scope identifies the systems, model and configuration versions, review period and reporting recipients.
We inspect configurations and representative operating records, speak with the people responsible, and observe agreed checks in an authorized environment. A policy document or a vendor statement alone cannot establish that a control works.
The limits are part of the scope.
The accord also addresses model capabilities and alignment, biosecurity and chemical threats. This service focuses on security controls and their oversight. Specialized capability, biological or chemical evaluations require separately agreed work and named, qualified specialists. A cybersecurity review cannot stand in for those assessments.
If operating access or records are unavailable, we can scope a readiness review. Its report identifies preparation gaps; it does not conclude that the controls operate effectively.