Shadow AI Discovery for Regulated Enterprises — CISO & Privacy Audit
Kriv AI · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
Employees are pasting PHI into personal ChatGPT, NPI into personal Claude.ai, and MNPI into personal Gemini — and CISOs cannot see it. CSA Shadow AI Framework 2024 documents 70–90% of enterprise AI usage is unsanctioned. Netskope Threat Labs (2024–2025) reports 96% of organizations have unsanctioned GenAI. Only Converge holds a shadow-AI-adjacent assessment SKU on AWS Marketplace today. Kriv AI is first with a regulated-industry-anchored Shadow AI Discovery assessment.
CISOs, CCOs, HIPAA Privacy Officers, CROs, CDOs, DPOs, and GCs across healthcare, pharma, and financial service face the same exposure: unauthorized employee use of consumer-grade GenAI toolconsumer GenAI tools (ChatGPT, Claude, Gemini, Perplexity, Copilot, others) is creating massive PHI / NPI / MNPI / trade-secret exposure that does not appear on any IT asset inventory. IBM Cost of a Data Breach Report 2024 shows shadow-AI-related breaches cost $670K+ more than average. HIPAA §164.502(b) minimum-necessary, GLBA §6801, NYDFS Part 500 §500.14 third-party risk, SR 11-7 + OCC 2011-12 model risk, SOC 2 CC6 + CC9, ISO 27001:2022 A.5.19–A.5.23, and EU AI Act Article 26 all extend to shadow AI.
Show the rest of the publisher’s description (3 more lines)
Assessment methodology (3–5 weeks). Week 1 Scope + telemetry baseline (cloud/SaaS tenant scoping — AWS, Azure, GCP, Workspace, M365, Salesforce, ServiceNow, Workday, vertical platforms; CASB / SSE log export — Netskope, Zscaler, Palo Alto Prisma Access, Cisco Umbrella, Microsoft Defender for Cloud Apps; Okta / Entra / Google SSO catalog export; endpoint DLP telemetry — Microsoft Purview, Symantec, Forcepoint, Trellix; browser-extension inventory; mobile MDM inventory — Intune, Jamf, Workspace ONE). Week 2 Network + SaaS + endpoint + browser + mobile scan (network-layer shadow-AI detection via CASB / SSE DNS + TLS-metadata + user-agent signature matching against 500+ GenAI service catalog — ChatGPT variants, Claude.ai, Gemini, Perplexity, Character.ai, Copilot consumer, Poe, You.com + 400+ vertical AI copilots; endpoint scan — installed AI apps, browser extensions, developer-tool AI copilots like Cursor / Windsurf / Continue / Claude Code consumer / GitHub Copilot personal / Cody / Tabnine / Codeium; mobile scan — ChatGPT, Claude, Gemini, Perplexity, Copilot mobile, Grammarly Go, QuillBot, Notion AI personal; browser-extension scan — Sider, Monica, ChatHub, Compose AI). Week 3 Exposure mapping + framework gap analysis (per detected shadow AI — data types likely exposed, user count + frequency, regulatory frameworks affected — HIPAA §164.502(b) + §164.308 + §164.312; GLBA §6801; NYDFS Part 500 §500.14; SR 11-7; SOC 2 CC6.1–CC6.8 + CC9; ISO 27001 A.5.19–A.5.23; EU AI Act Article 26; Colorado SB 24-205; NAIC Model Bulletin; HHS OCR shadow-AI guidance; FINRA 2025–2026 exam priority; residual-risk scoring). Week 4 Standard — Remediation roadmap + CASB/SSE policy authoring (30/60/90-day plan; sanctioned-alternative enablement — Bedrock Claude, Q Business, Copilot enterprise, Claude for Enterprise CPN; CASB / SSE policy authoring; employee AUP updates; HIPAA Privacy Officer disclosure workflow; IR playbook integration pairs with N44). Week 5 Enterprise — Mobile deep-scan + tabletop + executive briefing + board-ready deliverable (pairs with N42).
Three tiers. Foundation $35K (3 weeks; 1 cloud + 1 SaaS + endpoint + browser; up to 2,500 employees; 20 most-used AI services; HIPAA + GLBA OR NYDFS gap analysis; Tier 1 30-day remediation). Standard $65K (4 weeks; 2 clouds + 3 SaaS + endpoint + browser + CASB / SSE policy authoring; up to 10,000 employees; 100 AI services; HIPAA + GLBA + NYDFS + SR 11-7 + SOC 2; full 30/60/90 roadmap). Enterprise $95K (5 weeks; 3 clouds + 5 SaaS + endpoint + browser + mobile + tabletop + executive board briefing; up to 25,000 employees; 500+ AI services; full framework suite incl. ISO 27001 + EU AI Act + Colorado SB 24-205 + NAIC). Additional tenant $15K each. EDP-eligible — assessment fees ($35K–$95K) count toward your AWS Enterprise Discount Program commitment (up to 25%). CISOs structuring this via AWS Marketplace private offer can align procurement with existing EDP/PPA commitments. Contact info@kriv.ai to scope.
Important disclosures. No 100% shadow-AI discovery guarantee (constrained by Customer telemetry — CASB / SSE retention, endpoint DLP coverage, mobile MDM enrollment, BYOD). Does NOT provide incident response (route to N44). Does NOT install / configure / operate CASB / SSE / DLP / MDM. No legal / regulatory / clinical / actuarial opinions. Does NOT replace HHS OCR Risk Analysis, FINRA Rule 3110, NYDFS §500.02, or ISO 27001 certification audit. Does NOT disclose to regulators on Customer's behalf. Personal employee data not collected. No regulator-outcome guarantee. Anthropic CPN membership (April 9, 2026) — CPN partner, not Anthropic-authorized reseller.
Highlights
Highlighted by the publisher on AWS Marketplace.
First regulated-industry Shadow AI Discovery SKU on AWS Marketplace — HIPAA §164.502(b) minimum-necessary + §164.308 + §164.312 + §164.514 + GLBA §6801 + NYDFS Part 500 §500.14 + SR 11-7 + OCC 2011-12 + SOC 2 CC6 + CC9 + ISO 27001:2022 A.5.19–A.5.23 + EU AI Act Article 26 + Colorado SB 24-205 + NAIC Model Bulletin + HHS OCR shadow-AI guidance + FINRA 2025–2026 exam priority. CSA Shadow AI Framework 2024: 70–90% of enterprise AI unsanctioned. Netskope 96%.
Network + SaaS + endpoint + browser + mobile scan across 500+ GenAI services (ChatGPT, Claude.ai, Gemini, Perplexity, Character.ai, Copilot consumer, Cursor, Windsurf, Continue, Claude Code, GitHub Copilot personal, Sider/Monica/ChatHub/Compose AI extensions, Grammarly Go, QuillBot, Notion AI + 400+ vertical AI copilots). Exposure-to-framework mapping across PHI / NPI / MNPI / trade secrets / source / customer lists / PII / legal-privileged.
$35K (3 wks) / $65K (4 wks) / $95K (5 wks) fixed-fee + $15K per additional cloud/SaaS tenant. AWS Select + Anthropic CPN-certified. Prioritized 30/60/90-day remediation roadmap + sanctioned-alternative enablement plan (Bedrock Claude / Q Business / Copilot enterprise / Claude for Enterprise) + CASB/SSE policy authoring + executive briefing + board-ready deliverable + tabletop exercise (Enterprise). Pairs with N44 GenAI IR Playbook as natural N43 → N44 → N2 sequential motion.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

