{
  "schema": "ecowealth-ai-operational-safety-offer-v1",
  "seller": {
    "legal_name": "EcoWealth Corporation",
    "brand": "EcoWealth Safety",
    "email": "brandon@ecowealthsafety.com",
    "fulfillment_system": "Vealth"
  },
  "offer": {
    "name": "AI / Agent Operational Safety Review",
    "status": "ready_to_quote_not_binding",
    "summary": "A bounded review of one AI-enabled workflow, agent, MCP/tool surface, or automation path: identify concrete operational failure modes, tighten authority boundaries, and return testable fixes and receipts.",
    "buyer_fit": [
      "company shipping internal or customer-facing AI agents",
      "operator exposing MCP or tool-calling surfaces",
      "team automating money, publishing, infrastructure, or external actions with AI",
      "business adding AI to an existing operational workflow"
    ],
    "included": [
      "one named AI-enabled workflow or agent surface",
      "threat and failure-mode map grounded in the actual tool and authority path",
      "prompt-injection and untrusted-input boundary review",
      "secret, permission, approval, and least-authority review",
      "tool-call and external-action fail-closed review",
      "receipt, auditability, stale-truth, and rollback/kill-switch review",
      "prioritized corrective actions with paste-ready policy/code/config artifacts where feasible",
      "verification plan naming the deterministic checks that prove each admitted repair"
    ],
    "not_included": [
      "frontier-model alignment research",
      "claims that a model is generally safe",
      "formal legal, regulatory, privacy, or compliance certification",
      "active penetration testing, exploit development, or credential attacks",
      "production access or custody of client secrets by default",
      "guaranteed prevention of incidents",
      "model benchmark certification unless separately scoped with an accepted methodology"
    ],
    "price": "scoped quote; no standing public price",
    "commercial_expansion": "Review -> remediation -> re-test/closeout -> evidence pack where needed -> recurring change review by separate agreement."
  },
  "quote_request": {
    "method": "email",
    "to": "brandon@ecowealthsafety.com",
    "subject_template": "AI operational safety review — {system}",
    "required": [
      "principal_name",
      "company",
      "reply_email",
      "system_or_workflow",
      "models_or_providers_if_known",
      "tools_and_external_actions",
      "highest_authority_action",
      "untrusted_inputs",
      "known_failure_or_concern",
      "desired_review_window"
    ],
    "safe_intake": "Do not send passwords, private keys, tokens, production secrets, or sensitive personal data in the quote request."
  },
  "evidence_basis": [
    "Vealth AI-Era Threat Model covering prompt injection, leaked secrets, fake receipts, stale proof, malicious dependencies, wallet-draining automation, over-permissioned keys, AI-generated-code failure, PR/comment injection, authority smuggling, public/internal boundary drift, queue flooding, and coordination-state spoofing.",
    "Vealth security red-team review pattern with named severity, blockers, deterministic checks, and deferred high-authority actions.",
    "Existing agent/product quality parity guards that fail when machine-readable public status drifts across canonical surfaces."
  ],
  "authority": "This service is operational safety engineering for deployed AI-enabled systems. It is not a general certification that an AI model is safe.",
  "service_family": "https://ecowealthsafety.com/ai-safety-services.json"
}
