Security for the AI stack.
We build and teach AI application security: threat modeling, red teaming, and guardrails for LLM apps, RAG systems, and AI agents.
Four areas. One attack surface.
Prompts are an attack surface.
Treat them like one.
The Evolution
Traditional AppSec
Focuses on code vulnerabilities and standard network defenses.
AI Features Bolted On
Adding wrappers around APIs without securing the underlying model interactions.
Security by Design
Security designed around the model, retrieval, and tools.
Understand Context
Evaluate the whole system, not just the model in isolation.
Test Adversarially
Simulate real-world attacks to find prompt injections.
Constrain Tool Use
Apply least privilege to agents and external integrations.
Keep Humans in Control
Ensure transparency and oversight for automated actions.
Projects in progress.
Prompt Injection Test Harness
An automated testing framework that probes LLM applications for direct and indirect prompt injection vulnerabilities using structured attack patterns.
Agent Permission Analyzer
A static analysis tool that maps agent tool-call permissions, identifies over-privileged configurations, and suggests least-privilege boundaries.
RAG Poisoning Checker
A validation layer for RAG pipelines that detects poisoned documents, manipulated embeddings, and suspicious retrieval patterns before they reach the model.
AI security is a shared problem.
We learn in the open — sharing techniques, building exercises, and breaking things together so everyone ships safer AI.
Built with security as a foundation.
Least privilege by default
Components operate with minimal necessary access rights.
Human oversight at every boundary
Critical decisions always involve human confirmation.
Evaluation before claims
Rigorous testing validates security assertions before use.
Explainable findings
Security events are documented clearly and concisely.
Responsible disclosure
Vulnerabilities are handled ethically and transparently.