Zachary Longo

Zachary Longo

Principal Consultant @ Mantleline · AI Security Officer @ SNHU (150,000+ student system)

Deploy AI without landing in a Mobley v. Workday headline. I run the vendor audits, build the governance, and brief the board — one operator for every AI risk conversation on your desk.

0+

AI vendors assessed

0

regulatory frameworks in scope

0

business days to a Snapshot

I'm Zach. I'm the AI Security Officer at Southern New Hampshire University — a 150,000+ student system with a live AI vendor queue — where I built the vendor-evaluation methodology and have run it against 400+ AI vendors under active procurement. I'm the operator leadership calls when a board, GC, or CISO needs a defensible answer on an AI risk — before the regulator, the plaintiff, or the press does.

I don't just run the process. I designed it, and I built the tooling that makes it happen.

Vendor audits. Deployment security reviews. Compliance mapping (NIST AI RMF, EU AI Act, ISO 42001, HIPAA, and the HR-AI statutes). Governance program buildouts. Board briefings. Training your team so they catch the next one themselves. Incident response when something has already gone sideways. And AI research advisory — the build-vs-buy call before you spend the budget.

Mantleline is a small practice on purpose: your engagement gets me, not a rotating bench of juniors. For continuity, all engagements are documented against the same Mantleline methodology (yours to keep), and Advisory Retainers include a 48-hour incident-response SLA plus named subcontractor coverage for anything I can't take that week.

Everything AI-implementation, in one operator. Fixed-price on entry. Retainer on the way out.

Most AI-governance consultants read one NIST doc and started a firm. I run the AI security function for a 150,000+ student university and have graded 400+ vendors under active procurement. That's the methodology you're hiring.

Where I help

Vendor Risk

You're about to sign an AI vendor. I grade them against bias, safety, compliance, and supply chain — before the contract clears procurement.

Deployment Security

You're building or launching AI internally. I review the model, data flow, and controls before the feature ships — not after Legal escalates.

Compliance Programs

You need to align with NIST AI RMF, EU AI Act, ISO 42001, NYC AEDT (Local Law 144), or CO AI Act (SB24-205). I map your stack, name the gaps, and hand you the close plan.

Governance Buildout

You have no AI policy — or one that hasn't survived contact with a real deployment. I write it, stand up the review board, install procurement gates, and train the operators.

Training + Enablement

You want your team to catch AI risk themselves. I run the workshops. The internal doc and playbooks stay with you.

Incident Response

Your AI made a bad call and now someone senior wants answers. I run the retro, fix the process, and brief the board.

AI Research Advisory

You're deciding build-vs-buy on a specific AI capability. I scope the technical bet, evaluate vendors against custom builds, and structure the internal R&D so the budget doesn't evaporate.

Who I work with

CISO / CIO

vendor audits, deployment security reviews, incident response support

General Counsel / CLO

compliance mapping, governance policy, regulatory defensibility on the record

CHRO / VP People

HR-AI risk (Mobley v. Workday, NYC AEDT, CO AI Act), hiring-tool audits

CFO

AI procurement gates, contract-side risk review, spend defensibility

CEO / Board

strategic AI risk briefings, board-level advisory on the AI footprint

AI & Security Engineering Teams

use-case assessment, secure implementation, lifecycle management

Proven against

  • NIST AI RMF
  • EU AI Act
  • ISO 42001
  • Mobley v. Workday (precedent)
  • NYC AEDT (Local Law 144)
  • Colorado AI Act (SB24-205)
  • SOC 2 (Type II)
  • GDPR
  • HIPAA (subprocessor 164.308/.314)

400+ vendor evaluations across a 150,000+ student university system. Same methodology available to you.

Engagements

The Snapshot

Start here

$2,997 flat10 business days

Money-back guarantee

If the Snapshot doesn't surface at least one material risk you didn't already know about, full refund. No fine print. 400+ vendors in, that's never happened.

Pick your entry point:

  • Vendor Snapshot Five to eight AI vendors graded against bias, safety, compliance, and supply chain. Delivered with a risk-tier recommendation for each.
  • Deployment Snapshot One AI system you're building or launching. Security and compliance review of the model, data flow, and controls before it ships.
  • Program Health Check Your existing AI governance posture assessed end-to-end. Where it holds; where it wouldn't survive an audit.
  • Branded report per artifact — yours to keep
  • 60-minute executive readout
  • 30-day Q&A window
  • Can be run under outside-counsel direction (privileged work product) on request

Deep Engagement

From $12,50030 days

Pick the scope:

  • Deep Vendor Audit Twenty-plus vendors assessed comprehensively, plus a 90-day risk monitor on anything that shifted.
  • AI Governance Program Buildout Policy, review board, procurement gates, and training docs — built with your team so it stays alive after the engagement ends.
  • AI Compliance Alignment Full mapping of your AI stack to the frameworks that apply (NIST, EU AI Act, ISO 42001, statutes) plus a gap-close plan.
  • Executive briefing pack
  • Board-ready deck
  • 90 days of email support included
  • All documentation owned by you

Advisory Retainer

From $5,000/momonth-to-month

  • Quarterly vendor re-assessments
  • Policy updates as regulations shift
  • Incident-response support (48-hr SLA on urgent)
  • Monthly executive briefings
  • Direct operator access on anything AI-related

Not a fit if…

  • You have 0–2 AI tools in production. Too early — spend on the deployment first, come back when there's something to govern.
  • You want a one-and-done checkbox report. I do the work; you have to act on it.
  • You're shopping for the cheapest option. I'm not that.
  • You want vague risk language you can hand off. I name vendors, cite frameworks, and quote the statute.

How it works

  1. 1

    Discovery call

    Thirty minutes, no charge. We scope the actual ask and confirm fit.

  2. 2

    The work runs

    Snapshot in ten business days, Deep Engagement in thirty. I run it — not a junior team.

  3. 3

    Report + readout

    Branded deliverables (yours to keep) plus a 60-minute executive readout.

  4. 4

    Support window

    Thirty to ninety days of Q&A included, or flip straight to Advisory Retainer.

Recent work

Client details anonymized under NDA. Outcomes and dollar figures are real.

Higher-Ed · 150k+ students · Vendor Snapshot · 2026

Paused a $200k AI grading contract in six days.

The vendor's bias documentation didn't survive the audit. Contract paused, vendor rewrote their posture disclosures, Mobley v. Workday-style exposure avoided before signature.

EdTech SaaS · Deployment Snapshot · 2026

Caught two data-residency blockers before launch.

A new AI feature would have been undeployable in roughly half the customer's US buyer states. Mapped the full subprocessor chain and surfaced both issues pre-contract — fixed before the launch date.

Mid-market SaaS · 12-tool Deep Vendor Audit · 2026

Dropped 2 vendors, renegotiated 3, saved ~$180k/yr.

Twelve AI tools, no unified risk view. Tiered every one, flagged three that violated their own DPA language, and handed the CISO the report that walked the renewal negotiations.

Mid-market · Governance Program Buildout · 2026

Stood up an AI review board from scratch, gated 8 vendors in Q1.

Policy written, review board seated, procurement gates installed. Q1 results: eight vendors gated, two rejected, six approved with conditions. Legal, IT, and procurement all trained on the framework and running it without me.

Whatever AI question is on your desk this quarter — start here.

Thirty minutes. No slide deck. We'll scope the actual ask and tell you whether it's a fit before either of us commits to anything.

zach@mantleline.com·LinkedIn