Services

AI security, scoped to where you actually are

Every engagement starts the same way: we profile the target — what the AI system is, what data it touches, what authority its outputs carry, what trust boundaries it crosses. That intake decides which of the framework's twelve domains apply, so the work is scoped to your context, not a generic checklist.

ORG whole-of-organisation posture  ·  PROJECT a single system, agent, or deployment
Assess

AI Security Snapshot

Org

Rapid posture read across the 12 domains. Prioritised findings, quick wins, where the real risk sits. The entry point.

AASF

AI Security Assessment

Org

Full controls-based assessment. Maturity-rated findings, gap register, remediation roadmap.

AASF · ISO 42001

ISO 42001 Readiness / Gap

Org

Where you stand against the AI management system standard, what certification will demand, the path to close.

ISO 42001

AI Risk Assessment

Project

Threat-modelled risk register for a specific system: what can go wrong, how likely, how to treat it.

NIST AI RMF · ATLAS

Privacy / DPIA for AI

Project

Data-protection impact assessment built for AI: training data, inference exposure, retention, cross-border flow.

EU AI Act · VAISS

Vendor AI Risk Review

Project

A third-party AI or agent product assessed before you buy or renew. An evidence-based verdict, not a questionnaire taken on faith.

AASF · VAISS
Build

Secure AI Architecture & Design Review

Project

Your design stress-tested against the architect's question. Trust-boundary analysis, failure containment, fixes before build.

AASF · OWASP

SecAI / DevSecOps Pipeline Security

Project

Security built into the AI delivery pipeline: model supply chain, CI/CD, deployment gates.

AASF · NIST AI RMF
Run

Managed AI Security

Org

Ongoing retainer: continuous posture monitoring, new-system reviews, advisory on tap. Security that keeps pace with deployment.

AASF

AI Security Advisory / vCISO

Org

Fractional senior AI-security leadership. Strategy, board reporting, programme ownership.

AASF · ISO 42001
Not sure where to start?
The Snapshot tells you in a fortnight. Everything else builds from there.
Book a scoping call
Palette
Navy Brass