MANNATAI LABS
Services · 02 · Security consultation

A security review in plain language, ranked by what would actually hurt.

For teams that ship without anyone whose job is security. We look at your product, your cloud and your AI features the way an attacker would, then write it up the way a colleague would.

Ask for a scope and a priceQuote only. No packages, no retainers you did not ask for.
Fits when
You have a product in front of users, or about to be.
An investor, a customer or a partner has started asking about security.
You added an AI feature and nobody has tried to break it yet.
What it covers

Five places things go wrong, in the order they usually do.

01

The product itself

Authentication, sessions, access between tenants, the endpoints your front end never calls but an attacker will.

02

The AI features

Prompt injection, data leaving through the model, tools the model can call that it should not. We red-team the feature, not just the model.

03

The cloud around it

What is reachable from the internet, what is public that should not be, and who holds the keys.

04

The path to production

Dependencies, container images, the pipeline that builds them and the secrets it needs to do so.

05

The day it goes wrong

Backups you have restored from, logs you can read, and a one-page plan for the incident you would rather rehearse than meet.

How it runs

Three steps. You are in the room for the first and the last.

Week 0

You send access and context

A read-only account, the repository, and an hour on a call about what the product does and what would hurt most. We sign whatever you need first.

Weeks 1 to 2

We review and try to break it

Manual review first, tooling second. Anything serious is reported the day it is found, not at the end.

Week 2

You get a report you can act on

Findings ranked by real impact, a fix order, and a walkthrough call. Written for the person who has to fix it, not for a compliance folder.

Why us

We run the platform we would tell you to build.

The lab’s own systems run on GitOps with default-deny networking, supply-chain gates in CI, secrets that never sit in plain text, and a written incident plan. Every one of those choices was made after something broke, and every one is written up in the field notes.

We also build AI red-teaming tooling, so the AI part of your review is not a checklist copied from a vendor blog.

Read the Security Without a Security Team series

Tell us what you have. We reply with a scope and a price.

Three sentences about the product and what worries you is enough to start.