AI Threat Model
A written threat model — prompt injection, data leakage, abuse, the risks the AI faces.
AI Consulting & Governance
AI security and guardrails for the AI that ships to a customer — prompt injection defence, data leakage prevention, the eval suite, the red team, the audit log, the model swap path, the deployment on the infrastructure the security review requires, owned by you.
AI Threat Model
Guardrails & Filters
Red Team & Eval
Data Leakage Prevention
Audit Log & Compliance
Deployment on Your Infra
Overview
AI security is the work of making the AI safe to ship — prompt injection defence, data leakage prevention, the eval suite, the red team, the audit log, the model swap path, the deployment on the infrastructure the security review requires. The work is the safety net, the deployment is the constraint, the eval is the test.
We do AI security as engineering work, with the threat model, the guardrails, the eval suite, the red team, the audit log and the deployment as part of the architecture from sprint one. The output is an AI the security review can pass, not a wrapper that adds friction without safety.
This is the wrong engagement if the AI is not yet ready to ship. The right answer there is an AI development engagement, with the security as part of the build, not a separate wrapper.
What we deliver
A written threat model — prompt injection, data leakage, abuse, the risks the AI faces.
Input filters, output filters, the safety filters the AI needs in production.
A red team exercise, the eval suite, the regression tests the AI needs to stay safe.
PII detection, data masking, the controls the data privacy review needs.
The audit log, the compliance report and the controls the security review needs.
On your VPC, on your hardware, with the deployment model the security review requires.
Our process
01
Discover
We audit the AI, the threats, the deployment and the security posture.
02
Plan & Design
We design the guardrails, the eval, the red team and the deployment.
03
Develop
We build the guardrails, the eval and the audit log in sprints.
04
Deploy
We ship to production on your infrastructure, with the eval and the audit log live.
05
Optimize & Grow
We read the eval, the red team and the team feedback, and ship the next iteration.
Technology
What you can expect
Industries we serve
Prompt injection, data leakage, PII exposure, model abuse, jailbreaks, hallucination in irreversible actions, model theft. The threat model is the list of risks the AI faces, with the mitigations scoped and the residual risk named. The work is engineering, not a wrapper.
Input filters, output filters, context isolation, tool permissions, structured output validation, the eval suite that catches the regressions. The guardrails are part of the architecture, not a wrapper, and the eval suite runs on every change.
PII detection, data masking, encryption at rest and in transit, access control, the audit log. The privacy posture is part of the architecture, with the deployment model that fits the data posture (cloud, on-prem, hybrid). The DPDP Act 2023 sets the rules for Indian companies, and the deployment is built to comply.
Yes. The model, the guardrails and the storage can all run on your infrastructure — your VPC, your hardware, your data centre. The deployment model is part of the discovery, and the security review is part of the engagement. The AI is yours, on your infrastructure, with the audit that proves it.
Related services
Business software
Tell us the outcome you need. We’ll come back with an approach, a timeline and a written estimate.