Flagship practice

AI that acts needs security that thinks ahead.

We help organizations adopt generative AI, LLM applications and AI agents with eyes open: testing how they fail, designing how they are controlled, and governing how they are used.

AI is moving from answering to acting.

Language models are now connected to email, documents, code repositories, ticketing systems and production APIs. Once a model can call tools, an untrusted sentence can turn into a business action.

Traditional application testing does not examine model behavior, and most governance programs were written before agents existed. The result is a new attack surface that sits between people, data and automation, often owned by no one.

AI security closes that gap. It makes AI adoption faster, because the risks are understood, bounded and monitored.

Where AI systems are attacked

Risk point

  1. People & inputsUsers, documents, email, web pages
    • Direct prompt injection
    • Indirect prompt injection
  2. ApplicationAssistants, copilots, orchestration
    • Improper output handling
    • System prompt leakage
  3. ModelHosted, fine-tuned or open models
    • Jailbreaks
    • Sensitive data disclosure
    • Unbounded consumption
  4. Tools & agentsMCP servers, plugins, APIs, other agents
    • Excessive agency
    • Tool misuse
    • Agent goal hijack
  5. Data & memoryRAG, vector stores, agent memory
    • Poisoned retrieval
    • Memory poisoning
    • Over-permissioned data

Across every layer: identity & privilege abuse · AI supply chain · logging and monitoring gaps

A typical AI application stack. Each layer adds risk points; the most serious incidents chain several of them, for example an injected document that convinces an agent to misuse an over-privileged tool.

What we do

AI Security Assessment
A structured review of an AI application or platform: architecture, data flows, identities, guardrails and abuse cases, with prioritized findings.
AI & LLM Red Teaming
Adversarial testing of model behavior and the surrounding application: prompt injection, data exfiltration, jailbreaks, tool abuse and harmful outputs.
Agentic AI & MCP Security
Review of agents, tool permissions, Model Context Protocol (MCP) servers, memory and inter-agent trust, so autonomy has clear limits.
Secure AI Architecture & Threat Modeling
Security design for RAG pipelines, vector stores, model gateways and AI APIs before they reach production.
AI Governance & Risk
Policies, inventories, risk assessment and controls that let leadership approve AI use with confidence, mapped to recognized frameworks.
AI Monitoring & Incident Readiness
Logging, detection and response playbooks for AI-specific incidents, connected to your existing SOC and incident response plan.

How an engagement runs

  1. Scope

    Inventory AI use cases, models, data sources, tools and the people who own them.

  2. Model the threats

    Map trust boundaries and abuse scenarios for each use case, ranked by business impact.

  3. Test

    Manual and tool-assisted adversarial testing against agreed rules of engagement.

  4. Harden & govern

    Prioritized remediation, architecture guidance, governance controls and retesting.

What leadership gains

  • Faster, safer adoption
  • Bounded autonomy
  • Defensible decisions

Technical depth

For practitioners

For security architects and engineering teams: the threat landscape, our methodology and what we assess.

Threat scenarios we test
  • Direct & indirect prompt injectionInstructions smuggled through user input or through content the model reads, such as documents, web pages, emails and tool responses.
  • Agent goal hijackRedirecting what an agent is trying to achieve so that it carries out actions its owner never intended.
  • Excessive agency & tool misuseAgents holding broader permissions, functions or autonomy than the task requires, and tools invoked with attacker-controlled parameters.
  • Sensitive information disclosureLeakage of personal data, secrets, system prompts or proprietary content through model output or logs.
  • RAG & vector store weaknessesPoisoned or over-permissioned retrieval, embedding inversion and cross-tenant data exposure.
  • Improper output handlingModel output passed unchecked into browsers, shells, SQL or downstream systems.
  • Memory & context poisoningPersistent manipulation of agent memory or shared context that influences future decisions.
  • AI supply chainUntrusted models, datasets, plugins, packages and MCP servers entering the environment.
  • Identity & privilege abuseAgents and AI services using inherited, shared or long-lived credentials.
  • Unbounded consumptionAbuse that drives runaway cost, denial of service or model extraction.
What we assess
  • Architecture & data flowTrust boundaries between users, orchestrators, models, tools and data stores.
  • Identity & authorizationHow agents authenticate, which scopes they hold, and whether user context is enforced end to end.
  • GuardrailsInput and output filtering, policy enforcement, human approval points and their bypass resistance.
  • MCP & tool layerServer provenance, tool descriptions, parameter validation, sandboxing and least privilege.
  • Secrets & keysAPI key storage, rotation and exposure in prompts, logs and client code.
  • MonitoringPrompt and tool-call logging, anomaly detection and incident handoff to the SOC.
Typical deliverables
  • AI threat modelUse-case level trust boundaries and abuse scenarios.
  • Findings reportReproducible findings rated by business impact, with remediation guidance.
  • Executive summaryRisk posture in business terms, with decisions required from leadership.
  • Control roadmapPrioritized technical and governance controls, with a retest plan.
Frameworks we align with

We use these frameworks to structure our work. Alignment does not imply certification.

  • OWASP Top 10 for LLM Applications (2025)
  • OWASP Top 10 for Agentic Applications (2026)
  • NIST AI Risk Management Framework (AI RMF 1.0) and Generative AI Profile (NIST AI 600-1)
  • MITRE ATLAS
  • ISO/IEC 42001 (AI management systems), as a governance reference

Questions leaders ask

We only use a commercial AI assistant. Do we need AI security?

Yes, but scaled to the risk. The questions become which data employees can share, which integrations are enabled, how access is governed and what is logged. A focused governance and configuration review is usually enough.

How is AI red teaming different from a penetration test?

A penetration test looks for technical vulnerabilities in applications and infrastructure. AI red teaming also tests model behavior: whether the system can be manipulated into leaking data, taking unintended actions or bypassing its own policies. We usually combine both.

Can prompt injection be fixed completely?

Not with current technology. It is managed through design: limiting what the model can reach, separating trusted and untrusted content, requiring approval for sensitive actions, and monitoring tool use.

What is MCP and why does it matter?

The Model Context Protocol is a widely adopted standard for connecting AI assistants and agents to tools and data. Every MCP server is effectively a new integration with its own permissions and supply chain, and it should be reviewed like one.

Discuss your AI program with us.

Tell us what you are building or deploying. We will suggest the shortest route to a defensible risk position.

Discuss AI security