Services
Security services for agentic systems.
Five services. Most engagements start with a review of one system and grow from there. If you are not sure which one fits, start with the first.
Agentic system review
We assess the complete workflow, not the model in isolation: instructions and context, memory and retrieval, the identities and credentials the agent holds, the tools it can call, approval steps, interaction with other agents, and what happens downstream. Where it matters, we demonstrate the attack rather than describe it.
The result is a clear picture of the system's real attack surface and a prioritised plan for closing it.
AI infrastructure review
We review the platform for the case where a model, tool, integration or operator is compromised, and ask how much authority it inherits. That covers identity and access, secrets, isolation, network paths, logging, cost controls and incident response.
The review is useful on its own and pairs well with an agentic system review when the agents and the platform are owned by different teams.
Architecture and threat modelling
We work alongside your team to define agent identities, trust boundaries, capability limits, approval paths, isolation and recovery. The threat model uses TRACE for agentic AI, our specialisation of the TRACE methodology for systems that act through a model.
The output is written for the people who will build the system, and it doubles as the test plan for a later review.
Operational security
Support covering access to models and data, onboarding of vendors and tools, release controls for prompts and policies, detection of agent-specific failures, and incident preparation. Available as a one-off assessment or as an ongoing arrangement.
Training
Workshops built on our twelve-module agentic AI security course: the new attack surface, zero trust for agents, prompt injection, least privilege, harness and runtime security, secret management, model and supply-chain security, multi-agent systems, and a hardened reference setup. We adapt the material to your systems and your audience.
How we work
Assume the model is compromised. Then look at what it can reach.
-
01
Start from the consequence
We begin with what must not happen, then trace which identities, credentials and tools would let an agent make it happen.
-
02
Model the system with TRACE
Threat actors, roles, assets, critical invariants and edges give your team and ours one shared picture of the system.
-
03
Test to the effect
A model saying something odd is not a finding. A boundary being crossed is. We follow attacks through to an observable result.
-
04
Keep the evidence
The findings that matter become tests that run again when the model, the prompts or the tools change.
Where it helps your security and governance teams, we map findings to OWASP Agentic AI, MITRE ATLAS and the NIST AI Risk Management Framework.
Engagement formats
How the work is packaged
- Design workshop
Threat model and architecture decisions, worked through with the team.
- Point-in-time review
Assessment of an agent, a product, a platform or a defined boundary.
- Review plus test suite
The review, with the most important findings retained as regression tests.
- Ongoing advisory
Regular time with your team as the system and the threat landscape change.
Something else?
Describe the system. We will suggest the smallest engagement that answers your question.
We also take on commissioned research: a focused investigation into an attack class, a protocol or a control pattern. See the research page for how that works.