Skip to content
North Valley AI Security AI Security Consulting
Open navigation menu

FAQ

Questions small businesses often ask before starting

Clear answers about local service area, remote consulting, AI policy, custom tools, security boundaries, pricing, and website privacy.

Do you work only in Chico? +

No. The business is Chico-based and works with organizations in Paradise, Oroville, Durham, Gridley, Orland, Corning, Red Bluff, and surrounding areas, while also supporting remote clients when the work can be handled effectively online.

Do you offer remote consulting? +

Yes. Many AI security, policy, vendor review, documentation, and roadmap engagements can be handled remotely with clear scope and secure handoff materials.

Do you perform penetration testing? +

Not as a default service. Work is focused on practical cybersecurity, secure AI adoption, documentation, and limited lawful open-source exposure review. Any testing must be explicitly scoped, authorized in writing, and limited to systems the client has authority to assess.

Can you help us create an AI policy? +

Yes. AI acceptable-use policies can be created as a standalone engagement or as part of an AI assessment, adoption roadmap, or staff training package.

Can you build custom AI tools? +

Yes, when the scope is appropriate for a lightweight, maintainable business tool. Projects can include secure workflow prototypes, internal assistants, report generators, dashboards, and automations.

Do you store information submitted through the website? +

The launch site is designed not to collect or store visitor-submitted data. Contact uses email and phone links. If a protected form is added later, messages should be sent by email and not stored in a website database.

Can you help with Microsoft Copilot, ChatGPT, Gemini, Claude, or other AI tools? +

Yes. Tool reviews can look at intended use, data handling, account settings, vendor terms, staff guidance, and practical controls for common AI tools.

What does a starter engagement include? +

A starter engagement usually includes a discovery call, a focused review of the agreed area, a plain-English risk summary, and a prioritized action plan.

How long does an assessment take? +

Small starter reviews may take one to two weeks after scheduling and access to needed information. Larger roadmaps, policy packages, or tool reviews depend on scope and responsiveness.

Do you work with very small businesses? +

Yes. The services are designed for small businesses, solo founders, nonprofits, professional services firms, and local organizations that need practical help without enterprise overhead.

Can you help with email/domain security? +

Yes. Work can include MFA, registrar security, DNS hygiene, SPF/DKIM/DMARC guidance, website security headers, and admin access review.

What should we not send through the contact form? +

Do not send passwords, secrets, credentials, regulated data, emergency requests, or sensitive internal details through the website. Use email or phone first to establish an appropriate channel.

Are prices fixed? +

No. Published pricing is a planning guide. Final quotes depend on scope, urgency, systems involved, documentation needs, implementation depth, and authorization requirements.

Do you offer monthly support? +

Yes. Monthly advisory retainers can provide recurring guidance, vendor/tool review, policy updates, roadmap tracking, and limited async support.

Not sure where to start?

Still deciding where to begin?

A starter conversation can separate policy needs, tool questions, account basics, and custom build ideas into a useful next step.

Request a Consultation