CATALOGUE

The work.

AI-native offence and defence first. Then the estate: cloud, people, certificates. One firm. No slideware.

AI red team

We attack models, agents, and the tools they can touch. Prompt injection, jailbreaks, RAG exfil, poisoned context, shadow AI. You get the path an operator would use — and the control that closes it.

Agent defence

Tool firewalls, retrieval scope, human-in-command, anomaly on the tool-call stream. Incident response that treats a model as both weapon and sensor.

Compliance for AI you actually run

Audit trails for agent actions and approvals. ISO 27001, GDPR, PCI DSS, HIPAA, CCPA/CPRA — mapped to production, not a binder.

Risk and architecture

Assessments across infra, process, and people. AWS Well-Architected. Ranked findings, not a shelf ornament.

Incident response

Contain, investigate, recover. BCDR written so the next incident is a drill.

Awareness and phishing

Campaigns that land on staff who already ignore the obvious invoice mail. Including AI-authored lures.

Secure software

SSDLC aligned to OWASP and NIST SSDF. Injection, XSS, CSRF — and the new class that rides on the LLM.

ISO 27001 / CSA STAR

ISMS through certification. STAR for SaaS that has to prove the cloud service is controlled.

Open a channel →