AI security · Cloud security · DevSecOps

Practical cybersecurity for cloud-native, AI-enabled organisations

We are an independent security consultancy for teams building on the cloud and shipping AI. We secure what you already run — AWS, Google Cloud, Kubernetes, CI/CD and the applications on top — and put the governance around it that your customers and auditors expect.

  • 13+ years SRE, DevOps, cloud and security engineering
  • CISSP · CCSP · CISM Certified security leadership
  • 50+ Application security assessments delivered
  • AWS + Google Cloud Hands-on production experience

What we do

Four practices, one security programme

Most security problems cross boundaries. We work across all four areas so the controls you get in one are consistent with the others — not four vendors' worth of contradictory advice.

AI Security

Secure adoption of generative AI and machine learning, with the governance to keep it accountable.

1 service

DevSecOps & AppSec

Security engineered into how software is designed, built, tested and shipped.

2 services

Cloud Security

Architecture, identity, detection and posture management across AWS, Google Cloud and Kubernetes.

3 services

Advisory & Compliance

Strategy, risk, compliance and incident readiness for organisations building a security programme.

2 services

Focus areas

AI security & governance

Ship AI features without shipping new attack surface

Generative AI changes what an application can be talked into doing. We threat model the architecture you have actually built — prompts, retrieval, tool calls, agent autonomy — and put controls where they hold: authorisation at the data layer, least privilege for tools, human approval on irreversible actions.

  • AI threat modelling for LLM, RAG and agentic systems
  • Prompt injection and AI abuse prevention
  • Model, prompt and training-data protection
  • AI governance aligned to NIST AI RMF and ISO/IEC 42001
Explore AI security services

Cloud & cloud-native security

Guardrails that hold as the estate grows

A one-off cloud clean-up decays within two quarters. We fix the current findings and then encode the baseline — organisation policy, service control policies, Terraform modules, admission control — so every new account, project and cluster inherits it.

  • AWS and Google Cloud security architecture and assessment
  • Least-privilege IAM and keyless workload identity
  • Detection with GuardDuty, Security Hub and Security Command Center
  • Kubernetes hardening and container supply-chain integrity

Services

Security consulting across the stack

From a single threat model to a full security programme. Each engagement is scoped to a defined problem, with deliverables agreed before we start.

AI Security

AI Security & Governance

Adopt generative AI and machine learning without opening a new class of exposure — from model and data protection to prompt injection defence and an AI governance framework your auditors and customers can follow.

DevSecOps & AppSec

DevSecOps

Build security into the delivery pipeline instead of bolting it on at the end — secure SDLC, CI/CD hardening, IaC scanning, supply-chain controls and guardrails engineers will actually keep.

DevSecOps & AppSec

Application Security

Threat modelling, secure design review, application security testing and a vulnerability management process that closes findings instead of collecting them.

Cloud Security

AWS Security

Secure AWS architecture, least-privilege IAM, detection with GuardDuty and Security Hub, and posture management that keeps multi-account estates defensible as they grow.

Cloud Security

GCP Security

Google Cloud security architecture, IAM and organisation policy, VPC design, Security Command Center, Workload Identity and GKE hardening — built and maintained as code.

Advisory & Compliance

Cybersecurity Advisory

Security strategy, architecture review, maturity assessment, vulnerability management and incident readiness — built into a programme with owners, metrics and a roadmap leadership can fund.

Who you work with

Senior consultants, on your engagement

You work directly with the people who do the work. No pyramid staffing, no handover to a junior team after the pitch.

Devashish Kureel

Principal Consultant — DevSecOps, Cloud & AI Security

Noida, Uttar Pradesh, India

Engineering leader with 13+ years across Site Reliability Engineering, DevOps, cloud infrastructure and security operations, focused on embedding security into how platforms are built, delivered and run.

  • Red Hat Certified Specialist in OpenShift Administration
  • HashiCorp Certified Terraform Associate
  • Securing the Use of Generative AI in Your Organization

Dilpreet Singh

Principal Consultant — Application Security, GRC & Security Operations

Toronto, Ontario, Canada

CISSP, CCSP and CISM-certified security engineer whose work spans application security and penetration testing through to running a full cybersecurity programme — risk, compliance, vulnerability management and incident response.

  • Certified Information Systems Security Professional (CISSP)
  • Certified Cloud Security Professional (CCSP)
  • Certified Information Security Manager (CISM)
  • Cisco Certified Network Associate (CCNA)

Who we support

Organisations we work with

We support organisations across these sectors. Sector context shapes the risk model and the compliance obligations, but the underlying engineering discipline is consistent.

How we work

A predictable engagement

Security work goes wrong when scope is vague and findings arrive without a plan. Every engagement follows the same shape, so you know what you are getting and when.

Start with a discovery call
  1. Discovery call

    A short, no-obligation conversation about your environment, what is driving the work, and the outcome you need. If we are not the right fit, we will say so.

  2. Scoping and proposal

    A written proposal with defined scope, approach, deliverables, timeline and commercials. Any testing is explicitly authorised in writing before it begins.

  3. Assessment

    Hands-on review of the environment, architecture, pipeline or application in scope, using recognised frameworks and methodologies rather than a generic checklist.

  4. Findings and prioritisation

    Findings ranked by real exploitability and business impact, with a technical report and an executive summary written for the people who fund the fix.

  5. Remediation support

    We work alongside your engineers — reference architectures, policy as code, pipeline changes, Terraform modules — rather than handing over a PDF and leaving.

  6. Validation and enablement

    Retesting to confirm the fix, plus the standards, runbooks and training that keep the improvement in place after the engagement closes.

Why work with us

Security advice you can actually implement

Plenty of firms will tell you what is wrong. The value is in the part that comes next.

Engineers, not just assessors

Our consultants have built and operated the systems they review — cloud platforms, CI/CD pipelines, Kubernetes, security operations. Recommendations come with implementation detail, and often with the code.

Prioritised by real risk

We rank findings by exploitability, reachability and blast radius rather than by scanner severity, so your team spends its limited time on what actually reduces exposure.

Genuine AI security depth

AI security is a core practice, not a keyword. We threat model LLM, RAG and agentic architectures and align governance to NIST AI RMF and ISO/IEC 42001 rather than repackaging generic advice.

Both halves of the problem

Offensive testing and security engineering on one side, governance, risk and compliance on the other. You get a fix for today and a programme that stops the issue recurring.

Insights

Notes from the work

Practical writing on AI security, cloud security and DevSecOps — the things we find ourselves explaining most often.

Discuss your security challenges

Tell us what you are trying to secure and where it hurts. We will tell you what we would do first, whether or not you engage us.