Series 02 · AI Security

Proactive and reactive. Before something gets through, and after.

An agent with tool access is a new attack surface, and the interesting failures are not the ones the frameworks warn about. Prompt injection arrives inside data you trusted. Credentials end up in a context window. An agent takes an action nobody authorised because nobody wrote down what it was allowed to do. The proactive half is finding those before someone else does. The reactive half is what happens the week after something got through — containment, then repair, then the change that stops the repeat.

What this looks like

Real problems, real shapes.

A few scenarios that sit squarely in the AI Security practice. Your problem probably rhymes with one of them.

01

You shipped an agent with tool access

It can read, write, and act. Nobody has written down what it is not allowed to do.

02

Something already got through

Contain it, repair it, and change the thing that let it happen. In that order.

03

A client is asking questions you cannot answer

Procurement wants to know how the agent is bounded. You need a real answer, not a policy document.

How we engage

Choose the shape that fits.

Three engagement models per practice. Every one of them is outcome-focused and written into a one-page agreement before work starts.

01 · Model

Security Audit

A review of what you have running, with findings ranked by what an attacker would reach first.

Pricing

$2,500

Best for

Something is live and you have not looked at it this way yet.

Inquire

02 · Model

Remediation

Fixing what the audit found. Deliberately not fixed-price — remediation cannot be scoped before the audit, and a number quoted blind is a guess.

Pricing

From $7,500, scoped from audit

Best for

The audit found things and you want them closed.

Inquire

03 · Model

Monitoring

Ongoing watch with findings surfaced when they matter, not a dashboard nobody opens.

Pricing

$750/mo

Best for

The surface keeps changing because you keep shipping.

Inquire

Recent work

Scrlpets is the worked example.

A marketplace built, launched, and still being iterated in-house — which means the pipeline underneath it has been run against real users rather than described in a deck. The portfolio carries everything else, each entry with its actual state.

See the portfolio
Scrlpets — liven8n SEO Tool — live

Start a project

Ready for AI Security?

Tell us what you're trying to build. We'll tell you what it'll take — or point you somewhere better if we're not the fit.