AI Safety & Security Audit

    The audit we run
    before anything ships.

    An operator reviewing an AI system's safety checks before launch
    Why we lead with the audit

    The message came in on a live chatbot — a working site, real customer data behind it. Someone was probing it with injection attempts, trying to make it execute code and leak what it knew.

    It refused, logged the attempt, and flagged it. Every check it hit was designed months earlier, before launch, when the system was still a diagram.

    We didn't get lucky. We'd assumed someone would try — that assumption is what we sell.

    system: monitored
    [14:02:11] inbound message flagged: injection pattern detected
    [14:02:11] tool execution request → DENIED (policy: no_exec)
    [14:02:12] session isolated · data scope: none exposed
    [14:02:12] alert sent → human review queue
    Regulation

    The rules landed on 2 August 2026.

    The EU AI Act's high-risk obligations are in force: risk management, data governance, logging, human oversight, post-deployment monitoring.

    Most small B2B teams aren't high-risk. Proving which side you're on takes thirty minutes, and it's the first thing we do.

    What we check.

    • Data exposure

      What it sees that you didn't intend.

    • Prompt injection

      Can it be talked into ignoring you.

    • Human oversight gaps

      Decisions with nobody's name on them.

    • Failure modes

      What it does on its worst day.

    • Logging and audit trail

      Can you reconstruct what happened.

    • Data consent

      Are you allowed to feed it that.

    • Compliance

      Can you prove it to an auditor.

    • Model selection

      Is your model defensible.

    A demo and a production system are not the same thing.

    A demo

    In production

    Works on the path someone planned.

    Handles the inputs nobody thought of.

    Fails quietly.

    Fails loudly, with an alert attached.

    Impressive in a meeting.

    Boring on purpose.

    What you get.

    01

    Risk assessment report

    02

    Remediation roadmap

    03

    Governance framework

    Two weeks, fixed scope, priced as a project.

    Principles

    How we build everything.

    01

    Data flows are mapped before anything is connected.

    02

    Sign-off on anything high-stakes stays with your team.

    03

    If we find something uncomfortable, it goes in the report anyway.

    Questions we get.

    Find out what your AI is actually doing.