aidex@prod:~$ ./aidex.sh --init
Adopt AI without losing track of it.
AIDex runs an AI security assessment and scores readiness against the NIST AI Risk Management Framework. The model's reading and a consultant's review are recorded separately, and where both exist, both stay on the record.
- Where do we stand?
- What are we exposed to?
- What changed since last time?
- Govern
- Map
- Measure
- Manage
The four functions of the NIST AI Risk Management Framework. Readiness scores decompose into them, so a number can always be traced back to what produced it.
Six capabilities that boot organizations into AI readiness
Every capability connects to a measurable outcome. Teams build practical AI skills, assess where they stand, strengthen security posture, and follow adoption plans grounded in how the organization actually operates.
Readiness Assessment
Every engagement starts with learning. Your team works through an assessment authored for the engagement, building a shared understanding of current capabilities, gaps, and growth areas. The score it produces is reported against the four functions of the NIST AI Risk Management Framework, and the assessment teaches as it measures, so your people gain clarity on what AI readiness actually looks like for your organization.
./platform#readiness →Agentic routing
A policy in a document constrains nobody, and the same policy expressed as a rule in the code that decides what an agent may reach and what it may execute constrains everybody, which is the difference between having governance and being governed.
What the agent can reach
Whatever an agent's tools can read, the agent can read, and that access chains further than the tool list suggests.
What it may do versus what it may recommend
An agent that investigates and drafts belongs to a different risk class than one that executes.
Where the human gate sits, and whether it fails closed
A gate holds only when it is a check in ordinary code and a stopped run is the default.
What it costs, and whether the loop is bounded
A single call has a predictable cost, and a loop does not, so the loop needs a ceiling.
What record it leaves
Outputs can be reviewed after the fact, and actions can only be reconstructed from the record.
What happens when the framework changes
Orchestration frameworks lock in harder than model endpoints, so keep your policy in your own code.
The loop
The work runs as a loop, and the last stage feeds back into the first.
MEASURE
The cycle opens with a readiness assessment, scored against the four functions of the NIST AI Risk Management Framework. The result is one figure for the organization that comes apart into govern, map, measure, and manage, each with its own sub-score and a written summary behind it.
SECURE
Alongside it runs a separate AI security assessment, which produces a secure score and a register of the gaps behind that score.
TEACH
Training is one of the categories a roadmap item can carry, alongside security, governance, operations, and technology. Learning paths are generated separately, organized by subject and phase.
PROVE
When leadership asks for evidence, the platform compiles a board report that opens with a risk posture overview and carries the NIST subcategory references beside the gaps it lists.
RE-MEASURE
Later, the assessment is taken again and dated, so the change since the previous one is visible in the result. From there the cycle starts over.
Training
- 01
Aware
Knows which AI tools are in use and what the organization's policy says about them.
- 02
Capable
Uses AI for real work and comes back with a result worth keeping.
- 03
Fluent
Matches the approach to the task, and recognizes the tasks that should not go to a model at all.
- 04
Accountable
Owns the decision, supervises and defends AI output including someone else's, and carries the risk without outside review.
A framework built around practical training, security, and real results
Training drives the velocity
Organizations that invest in AI education early see faster adoption, fewer failed pilots, and stronger ROI across every initiative.
Read in fullCollapse
Our framework weaves structured training into every phase of the adoption journey. Teams learn inference fundamentals, prompting techniques, security best practices, and tool evaluation skills while they work through real projects. That combination of applied learning and forward momentum turns AI curiosity into actual capability.
Operate secure, develop secure, remain secure
Security starts before the first model goes live.
Read in fullCollapse
Our framework applies a shift-left philosophy, embedding guardrails, compliance checks, and governance protocols from day one instead of retrofitting them after something breaks. Business continuity is non-negotiable, so every recommendation accounts for data protection, access control, and regulatory alignment. When teams understand security as part of the workflow rather than an obstacle to it, the entire organization moves faster with less exposure.
From small organizations to the enterprise
AIDex serves public and private organizations of every size, from a small team running its first readiness assessment to a global company tracking them across every business unit.
Read in fullCollapse
Assessments, the gap register, and cost analysis all work against however many departments are in scope, without a drop in rigor. A small organization gets the same method and the same standard of evidence as a global one. Nonprofit organizations and K-12 districts work under tighter constraints and the same obligations, and we do not think a smaller budget should mean weaker guidance.
Build the understanding your teams need to use AI well
Most organizations jumped straight to tools before their teams understood how AI actually works.
Read in fullCollapse
AIDex builds that foundation. People across the organization learn how to write prompts that produce reliable outputs, evaluate what a model gives back, recognize when to trust a result and when to question it, and fold AI into real decisions. That kind of grounded understanding turns tentative experimentation into genuine confidence, and confidence is what makes adoption stick.
“Most AI initiatives don’t fail on technology. They fail on trust.”
How we work
- AI Exposure Review

What is already happening here?
- Readiness Baseline

Where do we actually stand?
- Agentic Routing Policy

What are our agents allowed to do?
- Vendor and Cost Review

What are we paying for, and twice?
- Department Pilot

Can we prove this works in one place first?
- Governance Setup

Who decides, and what happens when something goes wrong?
Durations and prices appear nowhere on this site because each engagement is scoped one to one against the number of departments in scope, the governance that already exists, and the AI that is already running, and those answers move the shape of the work too much for a published figure to mean anything.
See all servicesWho this is for
- The executive who has to answer for it
When the board asks whether the company is exposed on AI, you want an answer you can put in writing and one clear thing to do next.
- The security, IT or compliance lead
Nobody files a ticket before pasting customer data into a chatbot, so you want the real inventory of what is in use and how it maps to NIST AI RMF.
- The department head
Some of your people are far ahead on AI and others have not started, and you need to know which is which before you commit to anything this quarter.