Security and governance for AI you actually run.
Permission scoping, audit trails, guardrails, red-teaming and compliance mapping for agents and generative systems, so that security and legal sign off and the system still ships.
The problem
An agent that can act in your ERP is a new kind of user, and most security programmes have no category for it. The result is either a blanket no, or an approval based on a demo that nobody can audit later.
We make agents governable: every tool call under an explicit permission, every action attributed to an identity, every run traced and retained, and a written mapping from those controls to the frameworks you answer to. Then we attack the system before anyone else does.
What we deliver
- AI system threat model and control design
- Permission scoping per tool, human approval gates for consequential actions
- Guardrails for inputs, outputs and data exfiltration
- Red-teaming: prompt injection, tool abuse, data leakage, with a written report
- Audit trail design and retention aligned to your record-keeping rules
- Compliance mapping: LFPDPPP, GDPR, NIST AI RMF, ISO 42001 and sector supervisors
- AI use policy and review process for your organisation
How we work
Map
Systems, data, actions the AI can take, and the frameworks that apply. Written threat model.
Control
Permissions, identity, guardrails, logging. Implemented in your tenancy with your security team.
Test
Red-team against the threat model. Findings fixed or formally accepted, in writing.
Evidence
The control mapping and audit design packaged for your auditor or supervisor, plus a review cadence.
What backs it
Common questions
We already have a security team. What do you add?
Specific experience with how agents and language models fail: prompt injection through retrieved documents, tool chaining, data leakage through outputs. Your team keeps ownership; we bring the attack patterns and the control designs.
Can you review a system someone else built?
Yes. A review and red-team of an existing system is a common starting point, and it does not require you to change vendors.
Do you certify systems?
No. We produce the control design and evidence; certification bodies and auditors certify. We will work alongside yours.
Related services
Talk to an engineer about this
Thirty minutes, no slides. Bring the workload and we will tell you what we would do and what it would cost.