This is a guided tour of the sample Shadow AI Audit report: what each section shows, how to read it and what to do with it. The PDF itself is open to anyone, no signup.
The sample uses clearly labeled example data. Everything else about it is exactly what a paying customer receives.
Each page of the PDF answers for a different reader. Leadership stops at page one; auditors read to the end.
Scope line, summary tiles and the policy profile split.
Reader: the executive who has 90 seconds. The five tiles are the whole story at a glance.
Findings at a glance, tools by category and the full tool table.
Reader: the IT or security lead who has to triage every row into sanction, control or block.
The per-user breakdown and the control evidence statement.
Reader: the compliance officer filing this for an audit period, and HR when a name needs a conversation.
Follow along with the PDF open in another tab. Each stop shows the section and what to do with it.
The first paragraph states whose export was read, the format, the line count and the register size it was matched against.
Shadow AI Audit: evidence pack
Scope: Example Industries (sample data). AI tools observed in the supplied network export, matched against our live register of 20,399 classified AI tool domains. Export format: csv. Lines read: 4,400.
Five numbers, colored by severity. This row is what gets screenshotted into slide decks.
Three tiles sort every tool into block, allow with controls, or allow, under a named policy profile. The sample applies the General business profile.
Profile: General business. A starting point to review before deployment.
A ten-row table that decomposes the headline numbers, each with a one-line meaning.
The 37 sample tools fall into 11 of the register's 18 categories. Text tools lead, image and code follow.
The heart of the report: every matched tool with category, risk, training verdict, policy verdict, sanctioned flag, hits and user count.
Page 3 lists each identity that reached AI tools, with tool counts, hits and the most-used domains.
This table only appears when your export carries an identity column, and only in the full report. The how-it-works page shows where that column lives per log source.
Control evidence statement
"This report is generated from the organisation's own DNS, proxy or firewall export... Each matched domain carries its category, risk rating... with the date the vendor terms were last checked."
A closing paragraph written for auditors: what the report is, where the data came from and how it can be filed.
The export behind any report is read once and discarded. Reports stay in the account for 90 days and can be deleted earlier. Nothing else is retained.
The sample shows the full report. The free preview is the same engine with most names withheld.
| Section | Free preview | Full report (the sample) |
|---|---|---|
| Summary tiles | Included, full totals | Included, full totals |
| Tools by category | Included | Included |
| Tool table | A fifth of tools named, at least five; the rest as withheld rows | Every tool named |
| Per-user breakdown | Not included | Included when identities exist |
| Sanctioned split | Counts only | Full split against your approved list |
| CSV export | No | Yes |
| Shareable PDF | Yes, preview pack | Yes, evidence pack |
The withheld rows are drawn in the preview one per hidden tool, so you can count exactly what you are not seeing. Details on the free audit page.
Three pages, sample data, no signup. If the format works for your board or your client, the same document is one log export away.
The sample took a 4,400-line CSV. Yours will take whatever your console exports this afternoon.
30 days of DNS, proxy or firewall logs, with the identity column if you have one. The four-step walkthrough covers every console.
Totals and the top tools, free, in minutes. Enough to know whether the full report is worth $99 to you.
One-time purchase, no subscription. Packs of 3 and 5 drop the per-report price, see pricing.
The report uses a fixed vocabulary. Here is what each label commits to, and what it does not.
| Label | It means | It does not mean |
|---|---|---|
| Trains by default | The vendor's consumer terms state or imply training on user content unless a higher tier changes it. | That your specific plan trains. Enterprise tiers often carve it out. |
| Trains unless opted out | A switch exists and defaults to on. Past prompts may already be in a training set. | That anyone in your org has flipped the switch. |
| Does not train | The vendor states it does not train on customer data, as of the checked date. | That the terms cannot change next quarter. The date matters. |
| Not stated | The public terms do not answer the training question at all. | That the tool is safe. Silence is the most common finding, at 85.5% in our analysis. |
| Block | Under the applied policy profile, this tool would be denied. | That anything has been blocked. The report is read-only evidence. |
| Allow with controls | Acceptable on an enterprise tier with SSO, no-training terms and logging. | That the free tier your staff currently use qualifies. |
The fastest way to waste a good report is sending all three pages to everyone. Split it by reader.
Page 1 only, plus one sentence of context. The tiles and the profile split carry the message alone. The CISO page covers the board framing.
Page 2 and the CSV. They own the row-by-row triage into sanction, control and block.
Page 3 and the scope line. The evidence statement is written to be filed, not summarized.
Their category rows only. Marketing gets the image tools, engineering gets the code assistants.
MSPs and consultants use the sample to sell the assessment before running one. It answers the "what do I get" question without a meeting.
The deliverable stops being abstract. The client sees the exact document their engagement produces, with sample data.
Five tiles, three verdicts, ninety seconds. Then ask what they think their own tile row looks like. Nobody knows, and that is the engagement.
At the 5-pack rate a report costs $60. The MSP page and consultant page cover the per-engagement economics.
MSP plan reports carry the client name you enter, so each deliverable reads as the client's own document, not a shared template.
The sample's verdicts are drawn from the same research layer as every customer report.
All four are avoidable once you know they exist.
No. It is sample data for a fictional company, labeled as such on every page. The document structure and rendering engine are the real product.
Same sections, same order. Row counts differ, and the per-user table only appears if your export carries identities.
Yes, the PDF is public and needs no account. Most teams circulate it before the first run to agree on who reads which page.
Yes, a CSV of the tool table ships with every full report, for your risk register or spreadsheet work.
Each verdict carries the date the vendor's terms were last checked. The register behind it is maintained daily.
$99 one time for one report, $199 for three, $299 for five. No subscription, and several plans include monthly audits, see pricing.
Run the free preview first. If the numbers surprise you, the full evidence pack is one click and $99 away.
Start the free audit