Security by default

Built into every AI engagement.

Security is not a menu item. We design it in from the first architecture sketch, not audit it in at the end. Every AI build we deliver includes the baseline controls below, whether or not they were in the brief. This page is our public methodology.

Baseline controls

12 controls in every build

  1. 01Data classification and data-flow mapping first
  2. 02Model and vendor terms reviewed for retention
  3. 03Least-privilege access for tools and agents
  4. 04Identity-aware access for staff, customers, admins
  5. 05Secrets managed — never in code or prompts
  6. 06Separate dev, test, and production
  7. 07Human approval for consequential actions
  8. 08Prompt-injection and tool-misuse threat model
  9. 09Audit trails, monitoring, and rate limits
  10. 10Evaluation tests to prevent regressions
  11. 11Secure SDLC with scanning and code review
  12. 12A named owner after launch

Agent control model

Agents draft. People approve. Everything is logged.

Every agent we ship follows the same four-stage loop. The approval gate, the audit log, and the off-switch are part of the build, not follow-up work.

  1. 01

    Draft

    The agent retrieves only what the requesting user may see, then drafts the reply, summary, or change with its sources cited.

  2. 02· human gate

    Approve

    A named person reviews anything consequential: payments, deletions, external messages, privileged access. Nothing ships on the agent's say-so.

  3. 03

    Act

    Approved actions run through scoped tools with least-privilege credentials held in a secrets vault, behind rate limits.

  4. 04

    Log

    Sources, identity, approver, action, and outcome go to an audit log. Monitoring and evaluation tests catch drift before users do.

Framework

Mapped to NIST AI RMF

We use the four functions of the NIST AI Risk Management Framework to structure every engagement, and the principles of CISA Secure by Design to own the security outcome. We reference both; we are not certified against either.

NIST AI RMF

Govern

We set ownership, policies, and controls before the first build: who approves what, which vendors and models are allowed, and who owns the system after launch. Architecture decisions and the 12 baseline controls live here.

NIST AI RMF

Map

Discovery maps each workflow, the data it touches, and the people it affects. We classify data and trace data flows so risks are known before implementation starts.

NIST AI RMF

Measure

We build evaluation sets for reliability, grounding, safety, and policy compliance, and threat-model agents for prompt injection and tool misuse. Tests run in CI so quality is measured, not assumed.

NIST AI RMF

Manage

In operation we monitor quality, cost, and incidents, keep evaluation sets current, and act on what we find. Runbooks define who responds and how.

Precision

What we don't claim

We don't claim certifications we don't hold, sell compliance guarantees, or give legal advice. Where needed, we partner with specialist firms.

  • No regulatory or framework certifications. We reference the NIST AI RMF and CISA Secure by Design; we are not certified against them.
  • No penetration-testing services or claims of penetration-testing expertise.
  • No compliance guarantees.
  • No legal advice.
  • No 24/7 SOC or managed detection and response.

Next step

Book an AI Systems Readiness Call

Bring one workflow and the systems it touches. We will walk through which controls it needs and what a safe first build looks like.

Book an AI Systems Readiness Call30 min · with the engineer who builds it · no slide deck