Tell us what you have. We reply with a scope and a price.
Three sentences about the product and what worries you is enough to start.
For teams that ship without anyone whose job is security. We look at your product, your cloud and your AI features the way an attacker would, then write it up the way a colleague would.
Authentication, sessions, access between tenants, the endpoints your front end never calls but an attacker will.
Prompt injection, data leaving through the model, tools the model can call that it should not. We red-team the feature, not just the model.
What is reachable from the internet, what is public that should not be, and who holds the keys.
Dependencies, container images, the pipeline that builds them and the secrets it needs to do so.
Backups you have restored from, logs you can read, and a one-page plan for the incident you would rather rehearse than meet.
A read-only account, the repository, and an hour on a call about what the product does and what would hurt most. We sign whatever you need first.
Manual review first, tooling second. Anything serious is reported the day it is found, not at the end.
Findings ranked by real impact, a fix order, and a walkthrough call. Written for the person who has to fix it, not for a compliance folder.
The lab’s own systems run on GitOps with default-deny networking, supply-chain gates in CI, secrets that never sit in plain text, and a written incident plan. Every one of those choices was made after something broke, and every one is written up in the field notes.
We also build AI red-teaming tooling, so the AI part of your review is not a checklist copied from a vendor blog.
Read the Security Without a Security Team seriesThree sentences about the product and what worries you is enough to start.