Practice 02 ยท Cybersecurity

Security work for products, companies and AI systems.

Audits, penetration testing and hardening. We also secure the AI systems other teams are deploying.

What we do

In this practice.

  • Security audits for products and infrastructure
  • Penetration testing: web, applications and networks
  • AI security: prompt injection, data exposure, access control
  • Secure development practices and code review
  • Hardening and monitoring setup
  • Incident readiness and repair of compromised systems
  • Automated and continuous security testing
  • Compliance frameworks and readiness

This list is a sample, not a limit. If your task lives in security, we scope it.

How we approach it

Working principles.

01

Evidence over fear

Findings come with severity, reproduction steps and a fix. No vague warnings.

02

Fix first

Every report ends with a remediation plan, not just a list of problems.

03

Confidentiality by default

Your data and findings stay private, under contract.

Typical engagements

Ways this usually starts.

Audit and report

A structured review of a product or infrastructure, one to three weeks.

Penetration test

Offensive testing with a prioritized remediation report, two to four weeks.

Secure the AI stack

Review of an AI system: access, data flows, prompt-injection exposure and guardrails.

Deliverables

What you get.

  • Findings with severity, reproduction steps and a clear fix.
  • A remediation plan ordered by business impact.
  • Executive summary and technical report.
  • A walkthrough session with your engineers.
  • Verification of fixes as agreed in the statement of work.
Inputs

What we need from you.

  • A defined scope: assets, environments and rules of engagement.
  • Written authorization to test.
  • Test accounts or credentials where the scope requires them.
  • A technical contact and an escalation channel.
Process

How it runs.

01

Scoping and rules

We agree in writing what is tested, how far we can go and how findings are escalated.

02

Reconnaissance

We map the attack surface the way an attacker would.

03

Testing

Manual exploitation, with tooling where it helps and every finding reproduced.

04

Reporting

Severity, evidence and remediation, in business and technical language.

05

Verification

We re-test the fixes agreed in the statement of work.

Tell us what you need.

Every engagement starts with a conversation and a written quote.

Let's talk