Articles and Research

Check out some of our valuable content
September 2, 2025
Hitl-sop

Human-in-the-Loop & Escalation SOP Mercury Security | 2025 Introduction Human oversight is a cornerstone of responsible AI deployment. No AI system should operate without defined escalation pathways that allow humans to intervene in real time. This Standard Operating Procedure (SOP) describes how human-in-the-loop (HITL) oversight is designed, tested, and maintained for AI agents. The EU […]

Read More
September 2, 2025
Logging-Retention

Logging & Retention Policy Mercury Security | 2025 Introduction Effective logging and retention practices are critical for ensuring AI systems are transparent, auditable, and compliant with regulatory expectations. Logs provide the evidence needed to demonstrate accountability, while retention policies ensure that data is stored only as long as necessary and deleted when no longer required. […]

Read More
September 2, 2025
Model Card template

Model Card & Change Log Template Mercury Security | 2025 Introduction Model cards and change logs provide transparency into how AI systems are designed, deployed, and updated. A model card describes the system’s purpose, data, and performance, while the change log tracks updates over time. Together, these artifacts demonstrate lifecycle accountability, which is emphasized in […]

Read More
September 2, 2025
Evidence Journal Template

Evidence Journal Template Mercury Security | 2025 Introduction An evidence journal provides a structured way to record findings during AI audits. It captures what was tested, what evidence was observed, and whether the result met expectations. Maintaining such a journal demonstrates defensible governance and supports repeatable audit cycles (NIST, 2023; ISO, 2023). How to Use […]

Read More
September 2, 2025
Advisory & Enablement Services - Menu

Mercury Security Advisory & Enablement Services — Menu(v1.0, 2025) Mercury provides targeted advisory support to organizations needing governance help beyond the fixed-scope Audit Sprint and Oversight Pack. Services are offered on a time-and-materials or package basis. 1. Procurement & Vendor Assurance Supplier Security Pack Review — $5,000 (flat fee) Review of vendor DPA, SOC 2, […]

Read More
September 2, 2025
AI Agent Oversight Pack - SLA & Scope

Mercury Security AI Agent Oversight Pack — SLA & Scope(v1.0, 2025) The AI Agent Oversight Pack provides annual governance assurance for customer-facing and internal AI agents. This document defines the service scope, monitoring cadence, and client responsibilities. 1. Service Scope Covered Agent Types Reception & call answering agents Customer support & FAQ agents Knowledge retrieval […]

Read More
September 2, 2025
Add-On Catalog - Audit & Oversight

Mercury Security Add-On Catalog — Audit & Oversight(v1.0, 2025) The following add-ons expand the scope of Mercury’s fixed deliverables. Each add-on is pre-priced, documented, and can be added via change request or included in initial contracting. 1. Additional Production Agent Description: Expands the Sprint or Oversight Pack to cover an additional live AI agent (beyond […]

Read More
September 2, 2025
SOW

Mercury Security Sample Statement of Work (SOW)4-Week Audit → Governance Sprint(Illustrative Template, 2025) 1. Overview This Statement of Work (“SOW”) describes the scope, deliverables, timelines, roles, and terms of engagement for the Mercury Security 4-Week Audit → Governance Sprint (“Sprint”). This is a fixed-scope engagement with defined outputs and timelines. 2. Objectives Assess [Client AI […]

Read More
September 1, 2025
Bias & Safety Testing Method-Client Handout

Bias & Safety Testing Method Mercury Security | 2025 Introduction Bias and safety testing ensures that AI systems perform consistently across diverse user groups and avoid harmful or misleading outputs. The EU AI Act, GDPR, and NIST AI RMF all stress the importance of testing for fairness, safety, and accountability in AI systems (European Union, […]

Read More
September 1, 2025
Hosting and Assurance

Hosting & Assurance Overview Mercury Security | 2025 Introduction Assurance is not only about controls inside an AI system but also about where and how the system is hosted. This document outlines Mercury Security’s approach to hosting assurance, explaining the safeguards applied to third-party providers, the data protection commitments in place, and what clients can […]

Read More
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram