CimAssure™ · Independent AI assurance
Test the AI assistants your members rely on, from the outside
CimAssure tests an association's AI assistant the way a member would use it. It records exactly what the assistant says, has a Cimbiotic analyst judge it, and turns the results into evidence an association can act on and a plain-language Assurance Statement its board can read.
Why it exists
Members are asking how the AI they meet is governed. Few associations can show them.
Most association assistants are bought from a vendor, and the association cannot see inside them. Yet the association is the name on the answer when an assistant gets a policy wrong, invents a source or mishandles personal information.
Vendor assurances describe a platform in general. They do not describe your policies, your documents or the way your assistant is set up.
CimAssure does not need access to the vendor's systems and does not take the vendor's word for it. It asks the assistant questions and keeps the receipts.
Then it answers the question a board actually asks: how far can we rely on the AI we have put in front of our members, and what should we do about it?
How it works
From a scan to a statement your board can read
Register the assistant
We add your organization and the address of its AI assistant. Any access key is stored encrypted and shown only as its last four characters.
Run a scan
CimAssure sends a chosen set of tests from Cimbiotic's library: realistic member questions designed to probe one specific risk. Scans run on demand or on a schedule.
Capture the evidence
Every message sent and every reply received is stored word for word, with timing and any sources the assistant cited. A failure to respond is recorded as a failure, never guessed at.
AI-assisted, human-decided review
An AI model suggests Pass, Fail or Unsure and must quote the assistant word for word. We check every quote against what was actually said. A Cimbiotic analyst confirms the verdict, and a random sample of passes is rechecked.
Report and alert
A branded report carries the evidence. Staff are alerted when a scan finishes or a failure is confirmed, and the client has its own read-only portal.
Give the board an answer
An Assurance Statement rates each assistant Green, Amber or Red, explains why in plain language and recommends what to do.
What is tested
A versioned test library, mapped to OWASP
Each test states what it checks, the exact messages sent, plain-language pass criteria, a severity and where it came from. Editing a test creates a new version, so every past result stays traceable to exactly what was asked.
risk categories tested
tests currently in use, all versioned
OWASP LLM risks mapped: tested directly where possible, vendor questions where not
people behind every Assurance Statement: one writes it, another approves it
| Category | The question it answers | Tests |
|---|---|---|
| Policy compliance | Does the assistant follow the organization's rules, disclose that it is an AI and avoid unauthorized refunds? | 4 |
| Bias and fairness | Does the answer change unfairly when only the member's name, age or background changes? | 2 |
| Accuracy and hallucination | Does it invent facts, citations, sources or abilities, or accept false “corrections” from users? | 7 |
| Data handling | Does it leak or repeat personal information, other members' data, internal documents or its own internal settings? | 11 |
| Safety and refusal | Does it decline harmful requests, keep its hidden instructions private, ignore planted commands and resist fake claims of authority? | 10 |
The 34 tests include 7 for assistants that answer from an organization's own documents and 6 for assistants that can take actions. The library grows as new risks are published; new tests are drafts that no scan runs until an analyst approves them.
The OWASP Top 10 for LLM Applications
OWASP is a non-profit whose lists are widely used in security questionnaires. Some risks cannot be seen from outside an assistant, such as how its underlying model was trained. For those, CimAssure provides questions to put to the vendor instead of claiming coverage it does not have. Each client report counts only the tests actually run in that period.
| Risk | Coverage | What CimAssure looks at |
|---|---|---|
| LLM01 Prompt injection | Tested | Jailbreak-style reframing, commands planted in documents, fake claims of authority |
| LLM02 Sensitive information disclosure | Tested | Personal data, other members' details, internal documents |
| LLM03 Excessive agency | Tested | Action tests, run only with the client's authorization |
| LLM04 Supply chain | Vendor questions | Not visible from outside the assistant |
| LLM05 Data and model poisoning | Partly testable | Does it trust planted or false information? Training data is covered by vendor questions |
| LLM06 Unbounded consumption | Partly testable | A single, polite over-long request, never a flood. Rate limits and cost caps are covered by vendor questions |
| LLM07 Misinformation | Tested | Invented facts, sources, citations and abilities |
| LLM08 Hidden context exposure | Tested | Hidden instructions, internal tools and settings, other people's conversations |
| LLM09 Vector and embedding weaknesses | Partly testable | Whether its document search surfaces restricted or other members' content |
| LLM10 Improper output handling | Tested | Hidden-image data leaks, live web code, planted payment links |
Assistants that can act
Some assistants can do things for members: issue refunds, change account details, cancel registrations. CimAssure tests whether they can be talked into actions they should not take, and tags those tests against the OWASP Top 10 for Agentic Applications. Because these tests could trigger real actions, they run only after a Cimbiotic analyst confirms the client has authorized action testing on a test account. That confirmation is recorded on every scan.
The Assurance Statement
The answer for the board
Numbers and evidence matter, but a board needs a judgment. The Assurance Statement is a short, plain-language document that sits on top of the evidence report.
The evidence sets the limits
An assistant with results still awaiting review can only be Not rated. A confirmed high-severity failure rules out Green. The system enforces this rather than leaving it to judgment.
AI drafts, people decide
A first draft is written from that client's evidence only. Every finding it mentions must cite real evidence, and any number not found in the evidence is flagged. A person checks it and a second person approves it.
Nothing leaves by accident
Release to the client is a separate, deliberate step after approval. Until then every copy is watermarked as a draft, and corrections become a new version with the full history kept.
Plans and pricing
Fixed prices, published
You pay for the assessment, never for an outcome. Cimbiotic takes no commissions, referral fees, equity or revenue share from any vendor whose product it tests, no fee depends on the finding, and it can give a Red rating.
Founding-cohort pilot. CimAssure is being offered to a small number of associations while the hosted service is completed. Cimbiotic analysts run each engagement. Nothing here describes a self-serve product. The prices below are the founding-cohort prices and may change when general availability opens.
Point-in-time assurance
A launch pilot or pre-go-live assessment.
For an organization preparing to launch a member-facing assistant, changing platform, or wanting an annual check.
- The full 34-test library, run once
- Grounding, hallucination and document-leakage tests for assistants that answer from your documents
- Prompt-injection and jailbreak-resistance tests
- OWASP Top 10 for LLM Applications coverage report
- Questionnaire on the vendor's privacy and architecture
- One Board Assurance Statement, written and approved by two people
Standard continuous assurance
For associations running an active member-facing assistant.
Or $1,250 per month, plus $1,500 for onboarding and policy ingestion.
- One registered AI assistant, monitored
- Weekly scans, including regression checks
- Quarterly Board Assurance Statements with trend analysis
- Email alerts when a critical failure is confirmed
- Read-only portal for staff and executives
- Test library updated as new risks are published
Enterprise and agentic assurance
For larger societies with several assistants, or assistants that can act.
Or $2,450 per month, plus $2,500 for onboarding and system integration.
- Up to three registered AI assistants, monitored
- Weekly scans, including authorized action tests mapped to the OWASP Top 10 for Agentic Applications
- Monthly executive summaries alongside quarterly Board Assurance Statements
- Priority re-testing after a fix
- An annual AI governance briefing for leadership and the board
Compare the plans
| Capability | Point-in-time | Standard continuous | Enterprise and agentic |
|---|---|---|---|
| Monitored assistants | 1, single scan | 1, ongoing | Up to 3, ongoing |
| Scan frequency | One comprehensive scan | Weekly | Weekly |
| OWASP benchmark | Top 10 for LLM Applications | Top 10 for LLM Applications | LLM and Agentic Top 10 |
| Action and transactional testing | Excluded | Basic boundary checks | Full, with client authorization |
| Board Assurance Statements | 1 initial statement | Quarterly | Monthly summaries and quarterly statements |
| Analyst review | Single cycle | Every result, plus alerts | Every result, with priority review |
| Client portal | Report download | Read-only portal | Multi-user, role-based portal |
| Alerts | Briefing after the assessment | Email alerts on confirmed critical failures | Email alerts and priority support |
Add-ons
Additional assistant
Extend ongoing monitoring to a second member-facing or internal assistant.
Action and agentic testing
Add authorized transactional, tool-use and multi-step action tests to a Standard plan.
Interim Board Assurance Statement
An off-cycle statement ahead of an unscheduled board meeting or after a major model update.
Why the results can be relied on
Evidence, not summaries
Findings quote the assistant's exact words
That is what makes a finding defensible months later.
Failures are recorded honestly
If an assistant times out, rejects the key or returns nothing, the result says so and can never be marked Pass.
People make the judgment
By default an analyst confirms every result. Anything accepted automatically is labelled as such, including in client reports, and stays subject to sampling. Fails are never accepted automatically.
Strict client separation
Each organization's data is walled off at the database level. A client never sees another client's results, or any statement before it is released.
Traceable tests
Each scan records the exact version of every test it ran, and any wording tailored for that client.
A lasting record
An activity log records every sign-in, change, view and download. Staff sign in with two-step verification and role-based access.
What CimAssure does not claim
Assurance, not a guarantee
- It is not a certification, an audit or an attestation. An Assurance Statement is operational evidence about how an assistant behaved when tested. It does not replace a SOC 2 report or any CPA-issued control attestation.
- It is a view from the outside, at a point in time. Results describe the tests run in that period. They cannot show how a model was trained or what a vendor does internally; for those, CimAssure supplies questions to put to the vendor.
- AI assists, people decide. With AI-assisted review and drafting switched on, test evidence and client reference documents are sent to an AI provider for assessment. Client agreements need to allow this.
- Prior relationships are disclosed. Cimbiotic's founder, Rick Bawcum, led Cimatri and held advisory roles across the Blue Cypress group of association technology companies, and exited both in September 2026. He retains no ownership, advisory position or financial interest in either. Betty is a Blue Cypress product. If it is tested, or if any assistant built or sold by a Blue Cypress company is tested, the report says so on its first page, and the same limits apply as for any other vendor.
- Advised organizations are not given a statement. Cimbiotic does not issue an Assurance Statement for an organization it currently advises, or has advised in the preceding twelve months.
- Cimbiotic is aligning to ISO/IEC 17065 and is not currently accredited.
Questions
Frequently asked
Why test from the outside instead of trusting vendor claims?
Vendor guardrails address platform safety in general, not your policies, your documents or the way your assistant is configured. Testing from the outside evaluates the assistant the way a member meets it, and shows whether its model, instructions and document search respect your boundaries in practice.
Does CimAssure touch live member data?
No. Tests are scripted and synthetic, and tests that could trigger real actions run only on a test account the client has authorized. If an assistant does expose something it should not, that is recorded as a finding and handled under the engagement's confidentiality terms.
Does this replace a SOC 2 or other formal audit?
No. CimAssure tests how an AI assistant behaves. A Board Assurance Statement is evidence for a board, a risk committee or an insurer. It is not a certification or a CPA-issued attestation.
What happens if our assistant is rated Red?
A Red rating means a serious failure, such as leaked confidential documents or a planted instruction being followed. Once an analyst confirms the failure, the report gives the exact input, what the assistant said and a recommended fix. On continuing plans, we re-test after your team or vendor deploys a change.
What do you need from us to start?
Access to the assistant's public or staging interface, and the organization's key policies and documents. There is no software to install and no change to your infrastructure.
Which assistants can you test?
Assistants reachable through the same interface the vendor's own website uses, including OpenAI-style and custom APIs, streaming replies and assistants that answer later. Before any scan, a connection check looks for common setup mistakes and explains any problem in plain English.
Give your board an answer it can check
Thirty minutes, no obligation and no pitch deck. Sometimes the answer is that your assistant is in reasonable shape and the money is better spent elsewhere.