Security by default
Built into every AI engagement.
Security is not a menu item. We design it in from the first architecture sketch, not audit it in at the end. Every AI build we deliver includes the baseline controls below, whether or not they were in the brief. This page is our public methodology.
Baseline controls
12 controls in every build
- 01Data classification and data-flow mapping first
- 02Model and vendor terms reviewed for retention
- 03Least-privilege access for tools and agents
- 04Identity-aware access for staff, customers, admins
- 05Secrets managed — never in code or prompts
- 06Separate dev, test, and production
- 07Human approval for consequential actions
- 08Prompt-injection and tool-misuse threat model
- 09Audit trails, monitoring, and rate limits
- 10Evaluation tests to prevent regressions
- 11Secure SDLC with scanning and code review
- 12A named owner after launch
Agent control model
Agents draft. People approve. Everything is logged.
Every agent we ship follows the same four-stage loop. The approval gate, the audit log, and the off-switch are part of the build, not follow-up work.
01
Draft
The agent retrieves only what the requesting user may see, then drafts the reply, summary, or change with its sources cited.
02· human gate
Approve
A named person reviews anything consequential: payments, deletions, external messages, privileged access. Nothing ships on the agent's say-so.
03
Act
Approved actions run through scoped tools with least-privilege credentials held in a secrets vault, behind rate limits.
04
Log
Sources, identity, approver, action, and outcome go to an audit log. Monitoring and evaluation tests catch drift before users do.
Framework
Mapped to NIST AI RMF
We use the four functions of the NIST AI Risk Management Framework to structure every engagement, and the principles of CISA Secure by Design to own the security outcome. We reference both; we are not certified against either.
NIST AI RMF
Govern
We set ownership, policies, and controls before the first build: who approves what, which vendors and models are allowed, and who owns the system after launch. Architecture decisions and the 12 baseline controls live here.
NIST AI RMF
Map
Discovery maps each workflow, the data it touches, and the people it affects. We classify data and trace data flows so risks are known before implementation starts.
NIST AI RMF
Measure
We build evaluation sets for reliability, grounding, safety, and policy compliance, and threat-model agents for prompt injection and tool misuse. Tests run in CI so quality is measured, not assumed.
NIST AI RMF
Manage
In operation we monitor quality, cost, and incidents, keep evaluation sets current, and act on what we find. Runbooks define who responds and how.
Precision
What we don't claim
We don't claim certifications we don't hold, sell compliance guarantees, or give legal advice. Where needed, we partner with specialist firms.
- No regulatory or framework certifications. We reference the NIST AI RMF and CISA Secure by Design; we are not certified against them.
- No penetration-testing services or claims of penetration-testing expertise.
- No compliance guarantees.
- No legal advice.
- No 24/7 SOC or managed detection and response.
Next step
Book an AI Systems Readiness Call
Bring one workflow and the systems it touches. We will walk through which controls it needs and what a safe first build looks like.