AI TRUST.
IMPLEMENTED FOR SMALL DEFENSE AND FEDERAL CONTRACTORS.
──────────────────────────────────────────────────────────────────────
+AI GOVERNANCE YOU CAN SHOW A PRIME OR A CONTRACTING OFFICER → STARTING WITH WHICH AI TOOLS TOUCH YOUR CUI
+AI TEST AND EVALUATION: MEASURED RESULTS, STATED LIMITS
+FIXED-FEE BASELINE FIRST · YOU SEE THE FINDINGS BEFORE ANY BIGGER COMMITMENT
$frostlabs --trust
Two services for small defense and federal contractors adopting artificial intelligence (AI). Each starts with a fixed-fee baseline. That fee is credited in full toward the same service's implementation package if you sign it within 60 days. Ongoing upkeep is monthly reserved hours, quoted after the build.
AI GOVERNANCE SETUP
booking
FORA defense or federal contractor whose people already use AI: chat assistants, coding assistants, AI features inside software you already pay for. A prime or a customer has started asking how that use is controlled, and a policy nobody has read is not an answer.
For a defense contractor, start with the sharpest question: which AI tools sit inside the boundary around your Controlled Unclassified Information (CUI) and Federal Contract Information (FCI), and what are people sending them? The baseline finds the AI actually in use, including tools nobody approved, and maps where your data goes against the boundary your security plan already defines. Then I build a working program on the National Institute of Standards and Technology (NIST) AI Risk Management Framework (AI RMF): a use policy people can follow, a register of AI systems and tools, a risk method and register, the points where a person must review AI output before it goes out, vendor and data rules that apply the CUI and FCI handling requirements your contracts already set to each AI tool, and an AI incident procedure. If you want ISO/IEC 42001 certification later, I provide implementation support aligned with that standard. Only a certification body can certify you against it.
You get. AI use register · data-flow map against your boundary · AI use policy · risk method and register · human-review gates · vendor and data rules · AI incident procedure · AI RMF to ISO/IEC 42001 crosswalk.
$7,500AI Governance Baseline · up to 10 AI use cases
$18,000 to $30,000AI Governance Implementation · priced by the number of AI use cases; certification audit excluded
AI TEST AND EVALUATION
booking
FORA contractor building or integrating an AI capability (a classifier, an extraction pipeline, a language-model feature, an agent) that a government customer will want evidence on before trusting it.
I measure what the system actually does, on data that looks like its intended use, and write it down so someone else can rerun it. The baseline sets the test and evaluation plan (intended use, metrics, pass thresholds, data needs and the scope of adversarial testing), then runs a first measured evaluation with one adversarial pass. The build puts a versioned evaluation harness in your repository, freezes the protocol before the first run, checks the test data for leakage from any training, tuning and prompt data you hold, and reports results by the conditions that matter, with the limits stated as plainly as the results. Adversarial testing (red-teaming) runs only under rules of engagement you sign.
If the system processes CUI, the harness runs inside your environment on your accounts, and I see only the results you release. Test engineering is where my career started; this is the same discipline applied to models.
You get. System and intended-use profile · test and evaluation plan · frozen evaluation protocol · harness in your repository · data provenance manifest · leakage audit · evaluation report · red-team findings and retest.
$9,500AI Evaluation Baseline · one AI system or use case
$20,000 to $40,000Evaluation Harness and Credibility Evidence Pack · priced by system complexity
$frostlabs --method
How the work gets done. I design and direct AI systems that draft most of the documentation: inventories, policies, control statements, test harnesses, evidence indexes. I run the interviews, look at the evidence, make every finding and recommendation in my deliverables, review every artifact, and sign the deliverable. Each deliverable carries a method statement that says exactly that. It is how one person delivers this work, and it is why the fees are fixed.
Where your data goes. CUI, export-controlled technical data, configuration exports, logs, scan results and credentials stay in your environment and never come to me. If evidence I need contains CUI, I view it on a screen share you run, or in an account you provision inside your boundary. Your CUI never goes into any AI service I run. FCI and the rest of what you send (policies, process descriptions, my interview notes) go only to AI models on hardware I control or under Frost Labs' own paid cloud account, never to a consumer AI subscription. When the work ends, you get the deliverables and I destroy my working copies.
What every finding rests on. Every finding points to the artifact it rests on: a configuration you showed me, a log entry, a test result, a signed policy. Before anything leaves, a script reconciles every count and number in the deliverable and flags any finding with no recorded basis. Where there is no artifact, the deliverable says so.
Who decides. You make every attestation and every change to your systems. Your customer or a certification body makes the final call. I do not promise a certification or a contract.
$frostlabs --background
→ took my own firm through a full NIST Special Publication (SP) 800-171 self-assessment: boundary, system security plan, plan of action and milestones, policies, configuration changes, results posted in the supplier performance risk system
→ federal civilian engineer at hill air force base (air force solar telescope network, 309th software engineering group), then a shorter period there as a contractor (minuteman iii sustainment)
→ test engineering background, starting with mixed-signal characterization at nxp semiconductors
→ ms electrical engineering, arizona state · mba, university of utah · about 10 years as an electrical engineer
→ frost labs llc: utah llc formed 2026 · active in sam.gov, the system for award management · commercial and government entity (cage) code 20NR5
$frostlabs --limits
+I do not do Cybersecurity Maturity Model Certification (CMMC) readiness. CMMC and NIST SP 800-171 readiness is its own job; see the questions below.
+I do not take custody of controlled data. No CUI, no export-controlled technical data, no raw security data, no credentials.
+I do not change your production systems. Your managed service provider does, from work packages I write.
+I do not promise outcomes. No promised certification or contract.
+I do not give legal advice. What a clause requires of your company is a question for your counsel or your contracting officer.
$frostlabs --faq
Do you do CMMC readiness?
No. Readiness for the Cybersecurity Maturity Model Certification (CMMC) and NIST SP 800-171 is a security program built from people, facilities and daily operations as much as from documents, and it is not what I sell. My work covers how AI is used and tested inside your company, including keeping Controlled Unclassified Information (CUI) out of AI tools that should not see it. For the readiness work itself, look for a Registered Practitioner Organization in the Cyber AB Marketplace.
Will you take custody of our CUI?
No. CUI, export-controlled technical data, configuration exports, logs, scan results and credentials stay in your environment and never come to me. If evidence I need contains CUI, I view it on a screen share you run, or in an account you provision inside your boundary. Your CUI never goes into any AI service I run.
Do we still need a compliance platform?
Maybe. A platform tracks evidence and reminds people. It does not find the AI your people actually use, decide which uses are acceptable, or test your model. If you already use one, I work inside it.
Why start with a baseline?
Because the scope of everything after it depends on what it finds. It is a fixed fee, it ends in a written plan you own and can take to anyone, and the fee is credited in full toward the same service's implementation package if you sign it within 60 days.
$frostlabs --contact
FROSTLABS