The scarcest skill in AI security is not offensive security — it is understanding how production agent systems actually fail: tool schemas, memory persistence, retrieval scoping, MCP wiring, orchestration loops. Most AI red teamers came from application security and have never shipped an agent. We ship them weekly, which is why our findings come back as pull requests rather than screenshots.
Why teams choose us.
Built By People Who Build Agents
We run a production agentic practice. The review is done by engineers who have debugged tool-permission bugs at 2am, not by testers reading an architecture diagram.
Fixes, Not Findings
Remediation arrives as pull requests against your repository, with a regression eval harness wired into your CI so the same class of failure cannot come back.
The Evidence Pack
The 2026 SIG added an expanded AI governance section and CAIQ now names ISO 42001 and NIST AI RMF. You get answers to those questions, grounded in your actual system.
Independent Of Your Build Team
We do not review agents withRemote built. Independence from the builder is explicit in 2026 practice and sophisticated buyers check for it.
The full menu.
Threat Model & Blast Radius
- Tool surface and permission mapping
- What the agent can reach on its worst day
- Excessive-agency and privilege paths
- Human-in-the-loop gate placement
Adversarial Testing
- Direct and indirect prompt injection
- Tool abuse and unauthorised action chains
- Memory and conversation-state leakage
- Retrieval and vector-store permission leakage
MCP & Tool-Schema Review
- Server trust boundaries
- Tool-description poisoning surface
- Supply chain of connected servers
- Schema validation and output handling
AI Governance Evidence Pack
- SIG and CAIQ AI-section answers
- Model provenance and subprocessor map
- Data flow and training-data position
- Mapped to ISO/IEC 42001 and NIST AI RMF
Remediation & Regression
- Fixes shipped as pull requests
- Guardrail and output-handling layer
- Eval harness running in your CI
- Optional continuous re-test retainer
Our process.
Scope & Authorisation
We agree the systems in scope and sign Rules of Engagement plus a countersigned authorisation letter from a verified asset owner. Default scope is staging and non-destructive.
Model & Map
Architecture review, tool inventory, permission mapping and blast-radius analysis. Most of the serious findings surface here, before a single payload is sent.
Adversarial Pass
Prompt injection, tool abuse, memory and retrieval leakage, MCP trust boundaries — run against the real system, with every attempt logged.
Fix & Evidence
Remediation as pull requests, a regression eval suite in your CI, and the governance evidence pack your buyer's questionnaire is asking for.
What we build with.
Where this review is worth buying
Default scope is staging and non-destructive. The constraint here is authorisation, not residency.
Full scope. The trigger is procurement: the 2026 SIG update added an expanded AI governance section and CAIQ now names ISO 42001 and NIST AI RMF outright.
No production testing without signed Rules of Engagement and a countersigned authorisation letter from a verified asset owner, plus third-party authorisation where the systems sit on AWS or Azure.
Full scope for private-sector clients. A useful secondary trigger: the April 2026 Cyber Essentials Danzell question set brought AI and LLM tools formally into scope as cloud services, so anyone who deployed an agent since their last renewal now has a certification problem they did not have before.
We hold no CREST or CHECK accreditation and will not imply otherwise. UK public sector is closed.
Deliverable, but do not buy it as regulatory readiness. The high-risk obligations are deferred to December 2027 and August 2028; only Article 50 transparency and Article 4 AI literacy are live.
We will say so instead of selling against a deadline that has moved. If you ship a product with digital elements into the EU, the Cyber Resilience Act reporting clock from 11 September 2026 is the real and nearer obligation.
The DIFC's June 2026 consultation proposes embedding AI safety into processing systems, certification obligations, and an Autonomous Systems Officer role. No other regulator has gone that far yet.
We do not certify ISO 42001 and cannot; only an accredited certification body can. Our output is an evidence pack that answers procurement questions, not a certificate.
Every market position we hold, with the legal reason and the transfer mechanism, is on where we work.
Choose this if...
Honest about who this is for.
This will be a fit.
- You have a production agent with real tool access and real data behind it
- Your enterprise deal is blocked on an AI governance section you cannot answer
- You want remediation as pull requests against your codebase
- You want a regression suite so the finding does not come back next quarter
Honestly — not our zone.
- —You want an independent audit, attestation or certification — this is an engineering review and we certify nothing
- —You want ISO 42001 certified or an EU AI Act conformity assessment. Only an accredited body can do the first; we do neither
- —withRemote built the agent. We do not review our own work — our build clients get the Secure Build tier instead
- —You want production testing without signed Rules of Engagement and an authorisation letter. We will not proceed without them
Common questions, straight answers.
One contract covers any of these.
Everything below runs on the same agreement, the same invoice and the same account team as Agent Security & AI Governance Review.
Compliance Readiness Assessment
A fixed-fee assessment of where you actually stand against SOC 2 or ISO 27001:2022, ending in a costed, sequenced remediation plan and a warm introduction to an auditor. We are not your auditor and legally cannot be — which is exactly why we can do this work.
Compliance Remediation Pod
Your platform lists eighty failing controls and your auditor is legally not allowed to close any of them. We put a security pod on the backlog — IAM, logging, encryption, cloud configuration, CI/CD hardening — and hand your auditor working evidence in the format they ask for.
Agentic AI Development
Custom AI agents, LLM integrations, RAG pipelines, and intelligent automation built into your product. On the Secure Build tier, every agent ships with a threat model, tool-permission scoping, guardrails, and an adversarial eval suite running in your CI.
Direct Hire
We source, vet, and shortlist senior engineers from a 100,000+ pool. You interview, offer, and own the employment.
Managed Growth
The whole digital operation for a business people physically visit — website built and maintained, SEO, AEO, GEO, Google Ads, email, campaigns, lead gen, and the automations behind them. One team, one fee, and ad spend passed through to the platforms at cost.
Graphic & Design Services
Brand systems, marketing collateral, and design-on-demand for product, social, and sales.































