COMMERCIAL SERVICE 03 · AVAILABLE NOW · FIXED QUOTE BEFORE START

AI & Automation
Security Check

A calm, bounded check of the access, credentials, AI tools and automations running inside your business. Practical owner clarity. No scare stories.

✓ No passwords requested ✓ Fixed quote before start ✓ Response within 24 hours
SYSTEM ACCESS & BOUNDARY SCAN BOUNDED AUDIT
Account Ownership & Admin Rights Google, Meta, LINE & POS primary owners
SAFE
Staff & Former Staff Access Ex-staff logins and active session tokens
FIX
AI Data & Guest Exposure Guest records or TM30-related information
FIX
Automation & Trigger Authority Unapproved webhooks & outbound actions
CAN’T CONFIRM

Who it is for

For small businesses, bars, hotels, restaurants and independent operators in Pattaya and beyond who have adopted modern tools over time. You use Google Workspace, Meta Business Suite, LINE Official, cloud POS systems and new AI tools like ChatGPT or automated webhooks—but nobody has done a dedicated check on who still has access or what is happening automatically.

What we check: 4 inspection pillars

A structured, non-intrusive examination focused on practical owner risk, access paths and automation authority.

01 / Account Ownership & Admin Rights

Who actually owns your primary business logins, domains and digital channels?

  • Primary owner vs. delegated manager status
  • Multi-factor authentication (MFA) status on core logins
  • Active admin accounts and emergency account recovery paths
  • Google, Meta Business, LINE Official & POS ownership

02 / Staff & Former Staff Offboarding

Do former employees, contractors or past agencies still have active access?

  • Ex-employee accounts and active sessions
  • Shared terminal and counter login practices
  • Delegated manager permissions on social and booking pages
  • Audit of who can modify settings or export customer records

03 / AI Usage & Customer Data Exposure

How are staff using tools like ChatGPT, Claude or Copilot in day-to-day work?

  • Entering guest passport details, booking records or TM30-related information into external AI tools without data controls
  • Third-party AI plugins connected to company inboxes or cloud drives
  • Unnecessary disclosure of business takings, customer lists or private correspondence
  • Review of third-party processing, retention settings and output boundaries

04 / Automation Authority & Stored Secrets

What can your automations, scripts and connected apps do on their own?

  • Automations able to send messages, issue refunds or alter data autonomously
  • Approval gates ensuring an owner or manager approves before dispatch
  • API keys or webhooks stored in shared chats or plain-text spreadsheets
  • Audit trails and logging for automated operations

How it works

A clear, transparent process from initial intake to agreed scope. No surprise charges and no automatic execution.

01

Tell us about your setup

You complete a short intake. Never send passwords, secret keys or customer datasets.

02

Acorn reviews it

Your intake is securely received and reviewed by Chris.

03

You get a fixed quote

Within 24 hours Chris confirms whether the Security Check fits and gives you the price before anything starts.

04

You decide

Nothing is charged and no review starts until you agree.

How the access review works

You stay signed in.

We review the relevant settings with you by screen share or guided walkthrough. You make account changes yourself unless you explicitly ask Acorn to help. Acorn never needs your password.

You keep complete control of every login. No remote control software, no admin delegation and no shared credentials.

Practical small-business scenarios

Common access and automation risks in small-business setups. (Illustrative examples, not claims regarding specific Acorn customers).

SCENARIO A · ACCESS

Ex-manager controls Meta Business

A former manager created the Facebook page 3 years ago under their personal profile. The current owner is only an editor and cannot remove them.

SCENARIO B · LOGINS

Shared Gmail with no MFA

The main reception or booking email is logged in across 5 phones and till tablets. Password hasn’t been changed in 18 months; no two-factor check.

SCENARIO C · AI DATA

Guest records entered into an external AI service

Staff pasted guest details into an AI tool without first checking the business's data-handling settings, retention terms or whether that information needed to be shared at all.

SCENARIO D · AUTOMATION

Bot messaging with no review

A Zapier or n8n workflow was set up to confirm bookings automatically. A bad input sent incorrect pricing to 40 guests without human approval.

SCENARIO E · CREDENTIALS

API key stored in LINE chat

An OpenAI key with unrestricted card billing was pasted into a staff group chat so a freelancer could test a feature.

SCENARIO F · RECOVERY

No emergency recovery path

The primary domain and email registrar are tied to a former contractor’s personal phone. If the owner loses access, the business is locked out.

The Customer Deliverable: The Owner’s Report

You receive a calm, evidence-led report written in straightforward business English—not 80 pages of vulnerability scanner output.

[ SAFE ]

System checked and confirmed with appropriate ownership, strong access boundaries and proper human controls.

[ FIX ]

Specific access hazard or data exposure observed. Concrete remediation required.

[ CAN’T CONFIRM ]

System records are inaccessible, missing or unverified. Kept visible so nothing is assumed.

What every finding includes:

  • What Acorn observed: The specific configuration or record found.
  • Why it matters: Real business risk in plain owner terms.
  • Evidence: Direct reference, timestamp or screenshot.
  • Recommended action: Exact, bounded fix step.
  • Priority: High, Normal or Low impact.
  • Fixable by Acorn: Clear note whether Acorn can resolve it in a Fix Sprint.

The Security Product Ladder

Start with an objective assessment. Remediate what needs fixing. Keep Ongoing Guard for the future.

STAGE 01

Security Check

AVAILABLE NOW · FIXED QUOTE BEFORE START

A bounded, one-off inspection of your accounts, staff access, AI usage, credentials and automations. Delivered as a prioritized Owner’s Report with a fixed quote agreed before we start.

STAGE 02

Security Fix Sprint

AVAILABLE FOR QUOTE

Once you review the report findings, you can hire Acorn for a bounded fix sprint: reclaim accounts, lock down MFA, rotate exposed keys and install approval gates.

STAGE 03

Ongoing Guard

FUTURE CAPABILITY

Continuous monitoring and periodic re-verification of access paths and automations. (In development — not advertised as operational today).

What Acorn does NOT claim to provide

We believe in complete truth about capability. To avoid any confusion:

  • We are not a Security Operations Center (SOC) or MDR provider.
  • We do not conduct technical penetration testing, port probing or ethical hacking.
  • We do not provide emergency incident response or forensic ransomware recovery.
  • We are not a law firm or regulatory compliance certifier (ISO 27001, SOC 2, PDPA legal advice).
  • We are not an enterprise cybersecurity consultancy selling expensive corporate retainers.
  • Acorn provides practical, bounded, owner-level access, AI boundary and automation governance.

Strict Privacy & Credential Prohibition

Acorn never asks for, receives or stores your passwords, credit cards or master encryption keys. System inspections happen collaboratively on screen with the owner present. Your findings remain strictly private.

Start Security Check →