AI is already inside your case management system, your email, and your documents. The AI Exposure Review shows you where that information goes, and what to put in place before you rely on it.
The AI did not ask permission.
Most of the AI now touching your data arrived quietly. A feature switched on inside a platform you already pay for. A tool a staff member started using on their own. None of it announced that it would read your clients’ records, send them to an outside company, or keep them for a while.
97% of organizations that experienced AI-related security incidents lacked proper AI access controls.
IBM Cost of a Data Breach Report, 2025
Among organizations that experienced a breach, 63 percent had no AI governance policy or were still developing one. Staff are already using tools on their own. The question is not whether AI is in your organization. It is whether anyone is paying attention to what it is doing there.
For an organization serving survivors, children, families, or anyone whose safety depends on confidentiality, that quiet shift is the whole problem. The information you are trusted to protect can leave the building without anyone deciding it should.
Turning off training is not the same as keeping data private.
One question: will the company train its AI on your information? You can usually turn that off. The other: who can hold, read, or be compelled to produce your information, and for how long? That is controlled by the kind of account and the contract behind it. That is not one setting. For privileged records, the second question is the one almost no one is asking.
RAISE Tech builds AI tools for vulnerable populations. The person reviewing your exposure is the same person who builds these systems and knows what they actually do with data. Behind that sits two decades inside the work itself: direct service to survivors, a decade on a family drug treatment court team, and co-authorship of reference material on child protection law. It is someone who understands your populations, your obligations, and your systems at the same time.
The review makes your lawyer, your IT, and your vendor conversations sharp and informed. The decisions, and the legal calls, stay with you and your counsel. That is exactly what protects you.
Some organizations want help acting on the findings. Remediation support is available as a separate engagement, scoped after your review.
A 90-minute briefing for your board, your leadership team, or your new AI committee. One question drives the session: what is your AI actually doing with your clients’ information?
Most rooms find they do not know. That is not a failure, and it is more common than not. The AI arrived without anyone deciding to let it in. What happens after this session is an actual decision.
The three doorways. Where AI is already touching your data: the tools staff open and type into, the assistant sitting inside your email and documents, and the one built into your case management system that can read real records.
Why your obligations raise the stakes. Advocate privilege over survivor communications. Duty of care and FERPA for records about minors. Your exposure is not the same as a company protecting sales data.
Your own map. A short exercise where the room lists where client information actually lives and which of those places now has AI in it. Most rooms surprise themselves.
Three or four questions to put to your vendors and your counsel right away. A one-page reference sheet that stays with you after I leave. And a clear picture of what you know and what you have been assuming.
Not alarmist, and not legal advice. I raise the questions and name the standard. Your counsel makes the call. That separation is what makes it safe to have your attorney in the room.
No commitment to a full review required.
Full reviews start at $10,000, scoped to your size and the number of systems involved. Systems means your case management platform, the everyday software your team already pays for, and any AI tools staff have adopted on their own. A limited sliding scale is available for grassroots organizations, with two engagements reserved each year. Qualification is based on budget size, staff size, the population you serve, community-led leadership, and funding history. Reach out and we will scope it together.
Sessions are virtual. In person is available in Austin by arrangement.
Start with a briefing. $1,500 flat, 90 minutes, no commitment to a full review required.
Book a briefingor reach out directly at hello@raisetech.org
RAISE Tech builds AI tools for vulnerable populations and advises organizations on AI data exposure. This service identifies exposure and frames the questions your counsel and IT should resolve. It is not legal advice.