Pilot Offering

Shadow-mode assessment for AI-agent actions

A controlled GitHub Actions pilot for security and platform teams that want to evaluate recoverability-aware runtime permission scoring before enforcing new controls.

ALLOW THROTTLE FREEZE DENY ESCALATE
CISO review GitHub Actions pilot Review console Live demo

Technical Review

$0-$2,500

Best for teams that want to decide whether SMERC maps to a real workflow before starting a pilot.

  • Repository and CISO packet review
  • GitHub Actions integration walkthrough
  • 30-minute feedback call
  • Fit / no-fit recommendation

90-Day Design Partner

$25,000+

Best for teams ready to evaluate observe, recommend, and enforce-readiness across multiple workflows.

  • Multiple workflow candidates
  • Observe -> recommend -> enforce-readiness
  • Calibration support
  • Executive findings report
  • Design-partner feedback loop

Included

  • GitHub Actions shadow-mode setup guidance
  • Runtime posture reports for selected actions
  • Reason codes and recommended constraints
  • Immutable reviewer annotations and denominator-aware pilot metrics
  • Browser review queue and replay evidence console
  • Recommendation on whether enforcement is justified

Not Included

  • Production enforcement before calibration
  • Compliance certification
  • Replacement of IAM, OPA, branch protection, or code review
  • Handling production secrets or raw customer data
  • Custom enterprise integrations outside the agreed scope

Request Pilot Review

Use this form to request a pilot conversation. The first decision is whether a shadow-mode recoverability signal is worth testing against one real workflow.

Readiness Statement

SMERC is available for controlled pilot validation. It should be introduced in shadow mode first and should not be represented as production-certified enforcement infrastructure until calibrated against real workflows and reviewed by accountable security owners.