ServicesAI security and governance

Security and governance for AI you actually run.

Permission scoping, audit trails, guardrails, red-teaming and compliance mapping for agents and generative systems, so that security and legal sign off and the system still ships.

Who it is forCISOs and risk teams asked to approve an AI system, product teams blocked on that approval, and regulated organisations that need to show a supervisor how an agent is controlled.

The problem

An agent that can act in your ERP is a new kind of user, and most security programmes have no category for it. The result is either a blanket no, or an approval based on a demo that nobody can audit later.

We make agents governable: every tool call under an explicit permission, every action attributed to an identity, every run traced and retained, and a written mapping from those controls to the frameworks you answer to. Then we attack the system before anyone else does.

What we deliver

  • AI system threat model and control design
  • Permission scoping per tool, human approval gates for consequential actions
  • Guardrails for inputs, outputs and data exfiltration
  • Red-teaming: prompt injection, tool abuse, data leakage, with a written report
  • Audit trail design and retention aligned to your record-keeping rules
  • Compliance mapping: LFPDPPP, GDPR, NIST AI RMF, ISO 42001 and sector supervisors
  • AI use policy and review process for your organisation

How we work

Map

Systems, data, actions the AI can take, and the frameworks that apply. Written threat model.

Control

Permissions, identity, guardrails, logging. Implemented in your tenancy with your security team.

Test

Red-team against the threat model. Findings fixed or formally accepted, in writing.

Evidence

The control mapping and audit design packaged for your auditor or supervisor, plus a review cadence.

What backs it

The commitments on our home page apply here in full: work inside your tenancy, evidence for every recommendation, complete handover. Our PKI practice provides the identity layer when agents need credentials.

Common questions

We already have a security team. What do you add?

Specific experience with how agents and language models fail: prompt injection through retrieved documents, tool chaining, data leakage through outputs. Your team keeps ownership; we bring the attack patterns and the control designs.

Can you review a system someone else built?

Yes. A review and red-team of an existing system is a common starting point, and it does not require you to change vendors.

Do you certify systems?

No. We produce the control design and evidence; certification bodies and auditors certify. We will work alongside yours.

Talk to an engineer about this

Thirty minutes, no slides. Bring the workload and we will tell you what we would do and what it would cost.

Talk to us[email protected]