PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

AI SECURITY SERVICES

Security engineering for the AI system you actually ship.

Use focused reviews, deeper assessments, adversarial testing, hardening, and evidence work to answer a defined security or business decision. Each engagement uses the AI Security Workbench where it adds value, but the deliverable is the outcome and evidence—not access to an undifferentiated tool catalog.

Buyer situations

Start with the decision, not a pillar or tool.

LAUNCH

AI Launch Security Review

Know what must be fixed, accepted, or evidenced before launch.

Decision answered

What must be fixed, accepted, or evidenced before this AI feature ships?

Typical duration

5–10 business days; first findings targeted within 5 business days.

Primary output

AI Launch Risk Memo and release-condition checklist

Best for

Teams preparing a selected AI feature, system, workflow, or release boundary for launch.

ASSESS

AI Product Security Assessment

Map the AI product as a connected system, test material failure and abuse flows, qualify consequential paths, and turn the result into remediation and evidence.

Decision answered

What are the material security paths, control gaps, and remediation priorities across this AI product?

Typical duration

2–4 weeks, depending on scope.

Primary output

AI Product Security Assessment Report and prioritized remediation backlog

Best for

Teams that need a deeper product-security view than a bounded launch review.

ATTACK

AI Red Team & Adversarial Testing

Reproduce realistic adversarial behavior against the authorized AI system and preserve the evidence needed to understand, remediate, and retest what actually failed.

Decision answered

Which realistic abuse and adversarial behaviors can be reproduced, and what controls break them?

Typical duration

2–5 weeks, depending on scope.

Primary output

AI Red-Team Findings Register with reproduction and retest conditions

Best for

Teams that need authorized, realistic adversarial testing against a defined AI system boundary.

HARDEN

Agentic Workflow Security & Hardening

Map what the agent can actually cause to happen, reduce unnecessary authority, strengthen approvals and rollback, and verify the changed boundary.

Decision answered

Where can delegated authority, tool use, identities, permissions, approvals, or side effects exceed the intended boundary?

Typical duration

2–5 weeks, depending on scope.

Primary output

Agent Authority and Hardening Plan with verified boundary changes

Best for

Teams operating agents or AI workflows that can call tools, use credentials, or create consequential side effects.

VALIDATE

AI Guardrails & Evals Review

Determine what your guardrails and evals actually cover — and what still gets through.

Decision answered

What do the current guardrails and evals actually cover, and what failure cases still pass?

Typical duration

2–5 weeks, depending on scope.

Primary output

Guardrails and Evals Coverage Review with regression and release criteria

Best for

Teams with guardrails or evals already in place that need a coverage review before release.

RETRIEVAL

RAG Security Testing

Test whether retrieval authorization, tenant boundaries, provenance, context integrity, and indirect-injection controls hold within the authorized system boundary.

Decision answered

Are retrieval authorization, tenant boundaries, provenance, context integrity, and indirect-injection controls holding?

Typical duration

2–4 weeks, depending on scope.

Primary output

RAG Security Findings and Retest Record

Best for

Teams shipping a RAG application, knowledge assistant, or retrieval-backed agent.

SELL

AI Security Sales Enablement

Turn existing security architecture, controls, testing, remediation, and evidence into defensible answers for customer and procurement review.

Decision answered

What AI security claims can the company safely make, and what evidence can support buyer review?

Typical duration

1–4 weeks, depending on scope.

Primary output

Approved buyer security narrative, answer bank, and evidence index

Best for

B2B AI companies and product teams repeatedly answering enterprise security and procurement questions.

BUILD

AI Governance & Security Program Build

Define AI security ownership, intake, control expectations, release conditions, evidence requirements, exception handling, and an owned implementation backlog.

Decision answered

What ownership, controls, workflows, evidence, and backlog are required to operate AI security coherently?

Typical duration

4–10 weeks or retainer, depending on scope.

Primary output

AI Security Operating Model and owned implementation backlog

Best for

Organizations that need to turn fragmented AI policy and risk work into a security-operational program.

BASELINE

Expert-Led AI Security Program Baseline

Establish a directional, analyst-reviewed baseline of AI security ownership, control coverage, evidence gaps, and priority work.

Decision answered

Where should the AI security program start, and which ownership, control, and evidence gaps need priority work?

Typical duration

1–3 weeks, depending on scope.

Primary output

Analyst-reviewed AI Security Program Scorecard baseline and prioritized roadmap

Best for

Leaders who need a bounded starting point before funding a larger assessment or program build.

Operating method

M.A.D.E.

Map · Attack · Defend · Evidence

M.A.D.E. is the operating method across engagements, not the service taxonomy. The work maps the authorized system, tests material hypotheses, strengthens the boundary, and preserves the evidence needed for decisions and retest.

Map the system and decision boundary.
Attack realistic, authorized failure paths.
Defend with owned controls and remediation.
Preserve findings, decisions, retest state, and evidence.

Scope boundary

A service answers a bounded decision.

Actual testing follows the authorized scope. Observations and retest results apply to the tested condition and boundary. An engagement does not establish certification, universal coverage, framework compliance, or the absence of vulnerabilities unless a separately defined and supportable determination explicitly says so.