What we do
Three practices, one team
Each is scoped and priced on its own. They are staffed by the same small group of people, which is why findings from one routinely change the recommendation in another.
Break it
AI Security
Adversarial assessment of language models and the agentic systems built on them — prompt injection, tool-use abuse, data exfiltration, alignment failure under pressure.
from £14,000Explore AI Security →Run it
Cloud Engineering
DevOps and FinOps for teams whose infrastructure bill grew faster than their traffic. Cost attribution, performance engineering, and platform reliability with measurable outcomes.
from £12,000Explore Cloud Engineering →Build it
AI Engineering
Inference infrastructure, retrieval pipelines, agent orchestration, and the evaluation harnesses that tell you whether any of it actually works.
from £16,000Explore AI Engineering →Start small
Exposure Review
A fixed-scope first look, sized so it can be approved without a procurement cycle. We map the input surface, the tool permissions, and the cost concentrations, then hand you a prioritised list of what we would fix and what it would take.
It exists because the first conversation is usually the expensive one. Nobody wants to commit to a six-week engagement to find out whether there is a problem worth six weeks. This is sized to be approved on a corporate card rather than through procurement, and it either produces a shortlist worth acting on or it tells you your exposure is smaller than you feared.
If it turns into a larger engagement, the fee comes off the first invoice. If it does not, you still keep the findings.
How we engage
Fixed-fee and fixed-window. Every engagement has a written deliverable and an end date agreed before it starts. We do not hold findings back to seed a follow-on sale, we do not take a percentage of savings, and we hold no reseller margin on any platform we might recommend.
We are a small team by choice. That means we occasionally turn work down or schedule it out — we would rather tell you that than staff an engagement thin.
Save yourself a call
When we are not the right people.
We would rather you worked this out here than three weeks into a procurement process. If you recognise your situation below, we are probably not your best option — and where we can, we will point you at someone who is.
You need a compliance checkbox, not an assessment
If the goal is a certificate for a customer questionnaire and nobody intends to act on the findings, a larger firm with an audit practice will serve you better and cost less.
You want staff augmentation
We do fixed-scope engagements with an end date. If what you actually need is two engineers embedded for six months, that is a hire, and we will say so.
The system is not built yet
Adversarial testing needs something to test. If you are at the whiteboard, the useful conversation is an architecture review — that is AI Engineering, not AI Security.
You need someone on call
We are not an incident-response retainer and we do not carry a pager. If you are mid-incident right now, you need an IR firm today and us afterwards.