Home / What We Do / AI Security Review

Independent AI security review, before the auditor asks.

We red-team production and pre-launch AI systems against OWASP LLM Top 10, NIST AI RMF, MITRE ATLAS, and curated prompt-injection corpora. Framework alignment delivered in writing: EU AI Act, ISO 42001, HIPAA, DORA, and sector-specific. For BFSI, healthcare, and public sector enterprises whose AI has gone live or is about to.

See the threat surface
Reproducible findings · Framework alignment scorecards · NDA before scoping · ISO 27001 certified
What is an AI security review?

A structured assessment of an AI system's model, retrieval, data, access, prompt, tool-use, and deployment risks, producing reproducible findings and a remediation plan before launch or audit. It covers the AI-specific attack surface, prompt injection, data exfiltration, model supply chain, retrieval poisoning, that conventional appsec was never designed to find.

The threat surface

Seven surfaces, one reproducible findings backlog.

S1

Model

Provider, fine-tune, supply chain.

S2

Retrieval

RAG poisoning, index leakage.

S3

Data

PII flow, training data, exfiltration.

S4

Access

User population, trust boundaries.

S5

Prompt

Injection, jailbreak corpora.

S6

Tool-use

Agentic actions, over-privilege.

S7

Deployment

Cloud, on-prem, air-gapped.

Output

Reproducible findings, CVSS-aligned severity, remediation backlog.

Scorecards:OWASP LLM Top 10NIST AI RMFMITRE ATLASEU AI ActISO 42001HIPAADORASEBI
Investment

Ranges before you spend a meeting on us.

AI Security Review

From $60K
6 to 10 weeks

Pre-Deadline Remediation

Scoped to severity
4 to 8 weeks · fixed fee

AI Threat Model

From $25K
3 to 4 weeks

NDAs are executed before any scoping discussion. Exact figures are named on the scoping call and written into the SOW.

Where you are today

Assess it, or fix it against a deadline.

Assess

AI live, or about to launch.

The system is approaching launch, audit, or board review, and the risk position has to be written down.

AI Security Review (6–10 wks, from $60K)
You get
Threat model
Red-team vs OWASP LLM Top 10, NIST AI RMF, MITRE ATLAS, curated corpora
Findings report with severity and reproduction steps
Framework alignment scorecard (EU AI Act, NIST AI RMF, ISO 42001, HIPAA, DORA, SEBI)
Remediation roadmap
Board-ready executive summary
Remediate

A deadline, and the system isn't ready.

An audit date, regulator question, or board review is fixed, and known gaps have to close first.

Pre-Deadline Remediation (4–8 wks, fixed-fee scoped to severity and deadline)
You get
Targeted threat assessment on the specific gap
Critical findings remediated in-engagement
Documentation for audit or regulator
SOW commitment to the deadline
Coverage phases

Threat model, red team, framework alignment.

Phase 01

The Threat Model

Weeks 1–2

Architecture and boundaries, PII and sensitive data flow, access and trust, attack-surface enumeration.

Phase 02

The Red Team

Weeks 3–6

OWASP LLM Top 10, NIST AI RMF, MITRE ATLAS, adversarial corpora, prompt-injection, jailbreak, exfiltration, supply-chain scenarios, and CVSS-aligned vulnerability scoring.

Phase 03

Framework Alignment

Weeks 7–10

EU AI Act, NIST AI RMF and ISO 42001, HIPAA / DORA / SEBI / BFSI regimes, internal governance policies, and a board-ready summary.

From $60K, 6 to 10 weeks end to end.

The pod

Who does the work.

Lead Practitioner, AI Security (12+ yrs, 4+ in AI)
Senior Engineer, Adversarial Testing
Senior Engineer, Framework & Compliance
Delivery Lead
Principles

How we review it.

AI security is not appsec with AI bolted on

The attack surface, prompts, retrieval, tool-use, model supply chain, needs its own discipline.

Findings are reproducible, not theoretical

Every finding ships with reproduction steps your team can run.

Framework alignment is delivered as scorecards

Gap positions in writing, per framework, not a slide of green ticks.

The executive summary is written for the board

Risk in business language, with the technical annex behind it.

Review posture

Independent practitioner review, we do not sell the AI system we audit.

Model providers reviewed

AnthropicOpenAIAzure OpenAIAmazon BedrockGoogle Vertex AIHugging Face open-weight

Architectures

RAGAgenticFine-tunedEmbedded AI

Deployment reviewed

AWSAzureGCPOn-premiseAir-gapped / sovereignThird-party SaaS AI
Expected outcomes (ranges)
3–8
critical or high-severity findings per production-grade system
5–15
framework alignment gaps per relevant framework
< 2 weeks
from report delivery to board briefing
FAQ

What CISOs and risk teams ask

Anything else, email the practice. NDAs executed before scoping.

It complements it, we cover AI-specific risks traditional pen testing was never designed to find.

Yes, if you want, hand the report to your team, or we implement guardrails and re-test.

Whichever your risk posture allows; commonly a staging mirror with scoped production validation.

Independent AI red-teaming and framework alignment, before the auditor asks.

Bring the system approaching launch, audit, or board review. NDAs are executed before the scoping discussion.

Email the Practice