Who is Periscope a fit for?
Any team that has to get AI into production, from a fifty-person company automating its back office to an enterprise standing up an AI lab. What they share: real systems, security obligations, and no appetite for a two-year program. Software companies and traditional businesses alike, across healthcare, financial services, manufacturing and automotive, retail, energy and professional services. If you need one freelancer or a body shop by the hour, we are the wrong shape, and we will say so.
We just raised. Why bring in Periscope instead of hiring?
Because the two quarters after a raise usually go to hiring the senior AI, platform and security team the plan assumes, and the plan slips while that happens. We are the team funded companies, Seed to Series D, bring in instead: senior, fixed-scope, milestone-priced, reporting to the board monthly, with most of our work in healthcare, fintech and insurance. It starts with a free 45-minute post-raise planning session for CEOs, CTOs and boards: what the round has to fund, what a specialized team costs against hiring, and what to sequence first. For VC and PE investors, the same model runs per portfolio company from a fixed-fee Value-Creation Diagnostic, typically two weeks, on one rate card across the portfolio, with, where it fits, a portion of fees tied to agreed outcomes.
Do you do technology due diligence, exit readiness or carve-outs?
Yes. Technology Due Diligence is a fixed fee per target, typically two to three weeks, buy-side or investor-side: architecture, code and pipeline quality, security posture, data estate and run-rate, ending in a report a deal team and a board can act on. Exit & Carve-out Readiness works the other direction: we fix what an acquirer's diligence will find before they find it, security and compliance evidence, platform run-rate, documentation, and for spin-offs we plan which systems, data, licenses and pipelines leave with the entity, what must be rebuilt, and the transition-service window that protects both sides.
How do you price work?
Every engagement starts fixed-scope, priced before it begins. The starting prices on this page cover typical scope; we confirm a fixed quote after a short scoping call, usually within two business days. Phased builds are quoted phase by phase, with a go / no-go decision at each boundary, so you are never committed further than the phase you are in.
Who actually does the work?
A senior engineer based in the US leads every engagement and stays on it through production. Delivery is shared with our Mumbai team, full-time Periscope employees on the same tooling, standards and security controls, not contractors found for the project. You always know who is on your team, and the people who scoped the work are the people who build it.
How do you handle security and compliance?
Periscope operates under SOC 2 Type II controls, audited annually, and our teams have delivered under HIPAA for years. Client data stays inside agreed boundaries. For sensitive workloads we design private deployments, VPC or on-premises, including NVIDIA DGX systems, so data never leaves your environment, and every agent we ship carries approval gates and an audit log by default.
Can you run AI on-prem, in a private cloud, or hybrid?
Yes, that is the point of the infrastructure specialization. We design and operate AI stacks on NVIDIA DGX-class systems on-premises, in private clouds, on Azure, Google Cloud and AWS, and in hybrid arrangements where training, inference and data each live where they should. Sovereignty is a routing decision on one platform, not a separate project, and the same eval, monitoring and cost controls apply wherever the model runs.
Our data isn't ready. Is that a blocker?
Almost never, it is the normal starting condition. We scope readiness to the workload in front of us: which sources it needs, how clean and how current they must be, who may access them and how the results are retained. That pass is the first week of every Sprint Zero, and the pipelines, retrieval stores and evaluation sets we build for the first workload are designed to be reused by the next ones. You do not need a data lake, a catalogue program or a new platform before the first agent ships; you need the data for one workload to be trustworthy, and a plan for the rest that grows with demand.
Do you train our teams as well as build?
Yes. DevSecOps Enablement and AI enablement engagements pair implementation with hands-on training, so the pipelines, controls and agent tooling we put in place are run by your engineers afterwards. The goal is capability that stays, not a dependency.
Can you get our pipelines and cloud ready for agents?
Yes, it is one of the most common asks now. Agents multiply the number of things that ship code and call APIs: internal teams, agent runtimes, third-party systems, SaaS tools, open-source components and whatever shadow IT has adopted. We review and audit the code (human- and agent-written), build pipelines that both humans and agents move through across every environment, size the cloud workloads for the traffic that creates, and put an inventory and a policy around the endpoints so growth is governed rather than discovered. It is scoped per environment, in fixed-fee phases, and it is the same work we run for platforms we operate.
How do you protect API keys, tokens and agent credentials at scale?
Treat them as what they are: non-human identities, and soon the majority of identities you have. An enterprise running thousands of agents across hundreds of models holds far more tokens, keys, service accounts and agent credentials than people, many long-lived, over-scoped and never rotated. We start with a read-only exposure scan across repos, CI, cloud and SaaS (age, scope, last use, where each leaks), then rotate and scope down, move workloads to short-lived credentials and workload identity federation, put secret scanning and supply-chain controls, signed commits, protected branches, artifact attestation, into the pipelines, and add detection for abused tokens. We have run this after a live GitHub supply-chain attack, not only as a checklist.
Do you offer managed security monitoring?
Yes. As a WatchGuard Gold Partner we run 24×7 security monitoring, threat detection and response, and compliance reporting for SOC 2, HIPAA and PCI, either as a standalone managed service or as part of operating the platforms and agents we build. It starts with a free, read-only security posture review of your environment; the service is then priced per environment and reported monthly, alongside the same evidence report our operated systems carry.
Which clouds and AI models do you work with?
Azure, Google Cloud, AWS, private cloud and on-prem. On models we are deliberately agnostic: OpenAI, Anthropic, Google and open-weight models on private infrastructure, routed per workload for accuracy, cost and data-boundary requirements, never for a partner rebate. Token spend is measured and managed from day one, and we will tell you when a simpler, non-AI fix is the better answer.
How quickly can we start?
Free reviews and audits are usually scheduled within a week. Sprint Zero typically starts within two weeks of a signed scope, depending on team availability. We run a small number of sprints and pilots at a time and will confirm the next available start when we send the quote.