What we deliver

Scope of work

Every engagement is scoped in writing before it starts. A typical engagement includes:

  • Pre go-live red-team assessment of LLM applications, RAG pipelines and agentic platforms
  • Indirect prompt injection and data exfiltration testing, including zero-click attack classes
  • Model Context Protocol (MCP) and agent-to-agent (A2A) security: tool poisoning, rug-pulls, confused deputy and session smuggling
  • Adversarial machine learning: poisoning, evasion and membership inference testing
  • Agent boundary design: least agency, human-in-the-loop gates and kill switches
  • Findings mapped to OWASP LLM Top 10, OWASP Agentic Top 10, MITRE ATLAS and CSA MAESTRO
  • A reproducible evidence record and remediation plan

What you get

Outcomes

  • Known, measured risk before an AI system reaches customers
  • Agents that can only do what they were meant to do
  • Evidence that supports EU AI Act Article 15 robustness and cybersecurity duties

Track record

Experience behind it

  • Cybersecurity evaluation engineering for a frontier AI lab's benchmark: sandboxed, machine-graded offensive and defensive tasks
  • Architect of Cyron AI Security, air-gapped agent boundary protection for MCP and A2A with 15 detectors
  • Reproduced the EchoLeak zero-click prompt injection (CVE-2025-32711)
  • Eight public, runnable AI security proof-of-concept labs covering RAG injection, MCP security, adversarial ML and AI governance

Technologies and frameworks

  • OWASP LLM Top 10
  • OWASP Agentic Top 10
  • MITRE ATLAS
  • MCP
  • A2A
  • garak
  • LangGraph
  • Docker
  • Python

FAQ

Common questions

Something else on your mind? Ask us directly.

What is LLM red teaming?

LLM red teaming is adversarial testing of an AI application: attempting prompt injection, jailbreaks, data exfiltration and tool misuse the way a real attacker would, then documenting what succeeded, why, and how to fix it.

Why do AI agents need separate security controls?

Agents act through tools. Over MCP and A2A, a poisoned tool description or a malicious tool response can redirect an agent without any attack on the network or API layer, so the boundary where agents call tools needs its own inspection and policy.

Which standards are findings mapped to?

The OWASP Top 10 for LLM Applications (2025), the OWASP Top 10 for Agentic Applications (2026), MITRE ATLAS and CSA MAESTRO, with links to EU AI Act and ISO/IEC 42001 duties where relevant.

Related services

Often combined with

Have a system to build, modernise or secure?

Tell us where things stand today. The first conversation is free, and you will leave it with an honest view of the work involved.