
Zachary Longo
Principal Consultant @ Mantleline · AI Security Officer @ SNHU (150,000+ student system)
Deploy AI without landing in a Mobley v. Workday headline. I run the vendor audits, build the governance, and brief the board — one operator for every AI risk conversation on your desk.
0+
AI vendors assessed
0
regulatory frameworks in scope
0
business days to a Snapshot
I'm Zach. I'm the AI Security Officer at Southern New Hampshire University — a 150,000+ student system with a live AI vendor queue — where I built the vendor-evaluation methodology and have run it against 400+ AI vendors under active procurement. I'm the operator leadership calls when a board, GC, or CISO needs a defensible answer on an AI risk — before the regulator, the plaintiff, or the press does.
I don't just run the process. I designed it, and I built the tooling that makes it happen.
Vendor audits. Deployment security reviews. Compliance mapping (NIST AI RMF, EU AI Act, ISO 42001, HIPAA, and the HR-AI statutes). Governance program buildouts. Board briefings. Training your team so they catch the next one themselves. Incident response when something has already gone sideways. And AI research advisory — the build-vs-buy call before you spend the budget.
Mantleline is a small practice on purpose: your engagement gets me, not a rotating bench of juniors. For continuity, all engagements are documented against the same Mantleline methodology (yours to keep), and Advisory Retainers include a 48-hour incident-response SLA plus named subcontractor coverage for anything I can't take that week.
Everything AI-implementation, in one operator. Fixed-price on entry. Retainer on the way out.
Most AI-governance consultants read one NIST doc and started a firm. I run the AI security function for a 150,000+ student university and have graded 400+ vendors under active procurement. That's the methodology you're hiring.
Where I help
Vendor Risk
You're about to sign an AI vendor. I grade them against bias, safety, compliance, and supply chain — before the contract clears procurement.
Deployment Security
You're building or launching AI internally. I review the model, data flow, and controls before the feature ships — not after Legal escalates.
Compliance Programs
You need to align with NIST AI RMF, EU AI Act, ISO 42001, NYC AEDT (Local Law 144), or CO AI Act (SB24-205). I map your stack, name the gaps, and hand you the close plan.
Governance Buildout
You have no AI policy — or one that hasn't survived contact with a real deployment. I write it, stand up the review board, install procurement gates, and train the operators.
Training + Enablement
You want your team to catch AI risk themselves. I run the workshops. The internal doc and playbooks stay with you.
Incident Response
Your AI made a bad call and now someone senior wants answers. I run the retro, fix the process, and brief the board.
AI Research Advisory
You're deciding build-vs-buy on a specific AI capability. I scope the technical bet, evaluate vendors against custom builds, and structure the internal R&D so the budget doesn't evaporate.
Who I work with
CISO / CIO
vendor audits, deployment security reviews, incident response support
General Counsel / CLO
compliance mapping, governance policy, regulatory defensibility on the record
CHRO / VP People
HR-AI risk (Mobley v. Workday, NYC AEDT, CO AI Act), hiring-tool audits
CFO
AI procurement gates, contract-side risk review, spend defensibility
CEO / Board
strategic AI risk briefings, board-level advisory on the AI footprint
AI & Security Engineering Teams
use-case assessment, secure implementation, lifecycle management
Proven against
- NIST AI RMF
- EU AI Act
- ISO 42001
- Mobley v. Workday (precedent)
- NYC AEDT (Local Law 144)
- Colorado AI Act (SB24-205)
- SOC 2 (Type II)
- GDPR
- HIPAA (subprocessor 164.308/.314)
400+ vendor evaluations across a 150,000+ student university system. Same methodology available to you.
Engagements
The Snapshot
Start here$2,997 flat10 business days
If the Snapshot doesn't surface at least one material risk you didn't already know about, full refund. No fine print. 400+ vendors in, that's never happened.
Pick your entry point:
- Vendor Snapshot — Five to eight AI vendors graded against bias, safety, compliance, and supply chain. Delivered with a risk-tier recommendation for each.
- Deployment Snapshot — One AI system you're building or launching. Security and compliance review of the model, data flow, and controls before it ships.
- Program Health Check — Your existing AI governance posture assessed end-to-end. Where it holds; where it wouldn't survive an audit.
- Branded report per artifact — yours to keep
- 60-minute executive readout
- 30-day Q&A window
- Can be run under outside-counsel direction (privileged work product) on request
Deep Engagement
From $12,50030 days
Pick the scope:
- Deep Vendor Audit — Twenty-plus vendors assessed comprehensively, plus a 90-day risk monitor on anything that shifted.
- AI Governance Program Buildout — Policy, review board, procurement gates, and training docs — built with your team so it stays alive after the engagement ends.
- AI Compliance Alignment — Full mapping of your AI stack to the frameworks that apply (NIST, EU AI Act, ISO 42001, statutes) plus a gap-close plan.
- Executive briefing pack
- Board-ready deck
- 90 days of email support included
- All documentation owned by you
Advisory Retainer
From $5,000/momonth-to-month
- Quarterly vendor re-assessments
- Policy updates as regulations shift
- Incident-response support (48-hr SLA on urgent)
- Monthly executive briefings
- Direct operator access on anything AI-related
Not a fit if…
- You have 0–2 AI tools in production. Too early — spend on the deployment first, come back when there's something to govern.
- You want a one-and-done checkbox report. I do the work; you have to act on it.
- You're shopping for the cheapest option. I'm not that.
- You want vague risk language you can hand off. I name vendors, cite frameworks, and quote the statute.
How it works
- 1
Discovery call
Thirty minutes, no charge. We scope the actual ask and confirm fit.
- 2
The work runs
Snapshot in ten business days, Deep Engagement in thirty. I run it — not a junior team.
- 3
Report + readout
Branded deliverables (yours to keep) plus a 60-minute executive readout.
- 4
Support window
Thirty to ninety days of Q&A included, or flip straight to Advisory Retainer.
Recent work
Client details anonymized under NDA. Outcomes and dollar figures are real.
Higher-Ed · 150k+ students · Vendor Snapshot · 2026
Paused a $200k AI grading contract in six days.
The vendor's bias documentation didn't survive the audit. Contract paused, vendor rewrote their posture disclosures, Mobley v. Workday-style exposure avoided before signature.
EdTech SaaS · Deployment Snapshot · 2026
Caught two data-residency blockers before launch.
A new AI feature would have been undeployable in roughly half the customer's US buyer states. Mapped the full subprocessor chain and surfaced both issues pre-contract — fixed before the launch date.
Mid-market SaaS · 12-tool Deep Vendor Audit · 2026
Dropped 2 vendors, renegotiated 3, saved ~$180k/yr.
Twelve AI tools, no unified risk view. Tiered every one, flagged three that violated their own DPA language, and handed the CISO the report that walked the renewal negotiations.
Mid-market · Governance Program Buildout · 2026
Stood up an AI review board from scratch, gated 8 vendors in Q1.
Policy written, review board seated, procurement gates installed. Q1 results: eight vendors gated, two rejected, six approved with conditions. Legal, IT, and procurement all trained on the framework and running it without me.
Whatever AI question is on your desk this quarter — start here.
Thirty minutes. No slide deck. We'll scope the actual ask and tell you whether it's a fit before either of us commits to anything.