B2B AI & agent vendors
A regulated enterprise wants to buy your product. Then procurement sends the AI risk, model lineage and drift-governance questionnaire, and a US$50k–250k contract goes quiet. The contract moves again when their reviewer receives answers they can check for themselves, rather than assurances they have to take on trust.
The forcing function
Healthcare, finance and legal buyers push their own compliance obligations down the vendor chain. Their third-party-risk teams ask how chained models, prompts and API calls are prevented from compounding errors, what your agent can never do and what enforces that, and how you would detect drift before their users do. General assurances about monitoring score poorly on these questionnaires.
The gate is also hardening. ISO 42001 is appearing as a named requirement in enterprise questionnaires in much the way SOC 2 did a decade ago, and since 2 August 2026 the EU AI Act's transparency and general-purpose-AI provisions apply to vendors whose output reaches the EU. Reviewers are rewarded for caution, so incomplete answers tend to default to a no.
Each week the questionnaire sits unanswered, your internal champion loses momentum and competitors with stronger compliance material get the next meeting.
The twenty questions that stall deals
Which models, prompts and parameters produce each output, what changed, when, and under whose sign-off. A versioned, signed release history answers this; a general description of your model provider does not.
How errors compound across model, prompt and API stages, and what bounds them. Reviewers look for an enforcement mechanism here, not a monitoring plan.
What your agent categorically cannot emit or execute, and whether that is enforced below the application or only requested of the model through a system prompt.
How you would know the system's aggregate behaviour has moved, at what threshold, and who is notified, before the customer's own audit finds it.
Why this passes review
A report from an unfamiliar vendor is a career risk for whoever accepts it. Triodian removes the dependence on reputation: every output a governed system emits carries a signed conformance record bound to a versioned rule set, and your buyer's procurement or TPRM reviewer can check that record independently, without dashboard access and without contacting us.
The capabilities behind it are shipped and badged deliverable now on this site: Structured Output Assurance, Bounded Command Governance, the Certifiable Conformance Pack, the Aggregate Drift Service and the Certified Miss-Rate.
Production proof: the governed-reasoning engine and provenance ledger behind these artefacts already run pinpole.cloud, a live commercial platform, at scale.
The first step
A 90-minute structured interview with your risk and engineering leads. The assessment requires no system access, log export or InfoSec review, so nothing about it needs your security team's approval.
Within 7–14 days you receive a Diagnostic Gap Report covering model architecture, data provenance, evaluation pipeline, runtime controls and aggregate-drift exposure, mapped question by question to the questionnaire your buyer sent. It identifies the gaps their reviewer is most likely to raise, so you can close them before the review begins.
| Fee | A$7,500 / US$5,000, fixed |
| Cycle | 7–14 days, interview to report |
| Access | None (interview only) |
| Credit | 50% creditable against the Evidence Pack within 45 days |
The assessment fee is shown in both AUD and USD. Later stages are shown in AUD; US engagements are quoted from the USD price book.
Where it leads
A$2,000/mo · 12-month minimum
A Rules-tier SDK or lightweight proxy your team onboards itself: out-of-set commands become unemittable, and every output ships with a signed conformance record you hand straight to the reviewer. A live control rather than a one-off report, reusable across every deal.
The Certifiable Conformance Pack →A$25,000 single pipeline
For buyers who want a dossier: an audit-grade model risk, lineage and aggregate-drift Evidence Pack addressed to their procurement team, built from historical log exports through an encrypted bucket. No firewall change and no InfoSec review on your side.
The Certified Miss-Rate →