AI security consulting

# Security for AI agents with real access.

Mostly Harmless is a specialist AI security consultancy. We review, test and design agentic systems: the agents, the tools and credentials they use, and the infrastructure they run on.

[See our services](https://mhl42.ai/services) [Get in touch](https://mhl42.ai/#contact)

![An untrusted email reaches an AI agent with access to a database, email and payments. A security consultant maps the paths and places an approval control before the payment step.](https://mhl42.ai/assets/agent-attack-path.jpg)

*Untrusted input · Agent with access · Control before the action*

01 · Services

## What we do

Five services, from a first review of one system to ongoing support. Each one ends with findings you can act on.

[All services in detail](https://mhl42.ai/services)

- [**Agentic system review**](https://mhl42.ai/services#agentic-review): A security assessment of an agent or agentic workflow: what it can reach, what an attacker can make it do, and how to close the gap.
- [**AI infrastructure review**](https://mhl42.ai/services#infrastructure-review): The platform the agents run on: cloud accounts, model gateways, MCP servers, identity, secrets and runtime isolation.
- [**Architecture and threat modelling**](https://mhl42.ai/services#architecture): Design work before or during the build. A threat model of the system and the security decisions that follow from it.
- [**Operational security**](https://mhl42.ai/services#operations): Support for companies running agents day to day: access policies, vendor and tool onboarding, monitoring, incident preparation.
- [**Training**](https://mhl42.ai/services#training): Workshops and briefings for engineering, security and leadership teams, built on our twelve-module agentic AI security course.

02 · Research and development

## What we build

Alongside consulting, we build methods, tests and tooling for the problems that come up in agent security again and again. Some of it is open, some of it is a product.

[About our research](https://mhl42.ai/research)

[**Agent Auth for x402**](https://mhl42.ai/research#apf): Technical preview · Open-source authorization middleware for agents that pay through x402. Before the wallet signs, it checks the payment against a task grant, resource scope, policy and budget, alongside the wallet’s own rules.

[**TRACE for agentic AI**](https://mhl42.ai/research#trace): Open methodology · Threat modelling for systems that act through a model. Designed by Dr. Stefan Beyer as an extension of his TRACE methodology, with MITRE ATLAS and NIST AI RMF crosswalks.

[**Security evaluations for agents**](https://mhl42.ai/research#evaluations): Ongoing · Turning the findings from a review into repeatable tests that run again when the model, the prompts or the tools change.

03 · How an engagement works

## Three steps, no mystery

1. **Scope**
  We agree on the system, the decision you need to make, and what must not happen. This is usually one call.
2. **Assess**
  We map the system, follow the authority the agent holds, and test the paths that matter. Findings come with evidence, not speculation.
3. **Hand over**
  You get a report, prioritised fixes and, where useful, tests that keep the fixes in place. We stay available for questions afterwards.

04 · About

## A small, specialist practice

- **Focus**: Security of agentic AI systems
- **Led by**: Dr. Stefan Beyer · [LinkedIn](https://www.linkedin.com/in/st-beyer)
- **Working with**: Teams worldwide, remote and on site

Mostly Harmless is the AI security practice of Dr. Stefan Beyer. We work with product, engineering and security teams that are shipping agents with access to data, tools and money, and with companies adopting agents in their own operations.

The work connects three things that are usually done separately: threat modelling and architecture, adversarial testing, and the operational controls that keep a system defensible after launch. We also teach, and we publish the methods we use.

The name is a Hitchhiker's Guide reference. The aim is a system that stays mostly harmless when one of its assumptions fails.

05 · Contact

## Get in touch

Tell us what you are building and what you need to decide. We will suggest the smallest engagement that answers the question.

[info@mhl42.ai](mailto:info@mhl42.ai)

---
Source: https://mhl42.ai/
Site guide for agents: https://mhl42.ai/llms.txt · Whole site as Markdown: https://mhl42.ai/llms-full.txt
