Service / 09
AI Security
AI systems add attack surface that classical security programs do not cover: prompt injection, data exfiltration through model outputs, poisoned inputs. We threat-model, harden, and test AI systems before they ship — and keep testing after.
When you need this
The situations we are called into.
You are shipping an LLM feature that reads untrusted content — documents, email, the open web.
Your security team's threat models predate language models, and nobody has updated them.
An AI system needs security sign-off before go-live, and generalist firms lack the expertise to give it.
Approach
How the engagement runs.
Threat modelling
Attack surface mapped for each AI system: inputs, tools, outputs, and the data each can reach.
Architecture review
Trust boundaries, privilege separation, and output handling reviewed against the threat model.
Adversarial testing
Injection, exfiltration, and abuse scenarios executed against the real system, with reproducible findings.
Hardening
Fixes implemented and verified — input mediation, output constraints, privilege reduction — not just listed.
Monitoring design
Detection rules and response procedures for the attacks that will arrive after launch.
Deliverables
What you hold at the end.
AI threat model
Adversarial test report
Implemented hardening measures
Detection rules and response procedures
Secure-deployment checklist
Related research
The evidence behind this practice.
Technical report · 2026
Evaluating large language models for regulated enterprise workflows
A practical evaluation framework for LLM systems in banking, insurance, and government contexts — metrics, test harnesses, and a taxonomy of failure modes.
In preparation
White paper · 2026
Multi-agent systems in production: reliability patterns
Failure modes observed when orchestrating multiple LLM agents on business-critical tasks, and the containment patterns that keep them recoverable.
In preparation
Contact
Talk to our engineers.
Describe the situation you are in. The person who replies is the person who would do the work.