AI security assessment & LLM penetration testing

Secure AI.
Built to ship.

A Vancouver consultancy that tests AI-heavy software the way an adversary meets it — probed first on an isolated rig, every claim carrying its evidence. Findings arrive severity-ranked with proof attached; retests close them. Every engagement is principal-led.

01 Services

Four practices.
One register.

Assessments find what is broken. Reviews cover the AI surfaces generic audits skip. Readiness turns findings into controls. Tooling keeps the findings register honest at corpus scale.

Assessment

Web app & API penetration testing.

Dynamic testing of web apps and APIs on an isolated rig: seeded accounts, composed attack chains, findings severity-ranked with the probe transcript beside every claim. Fixes close by retest, not by promise.

AI systems

LLM & agent penetration testing.

Full-spectrum penetration testing of agent platforms: tool and runner boundaries, MCP surfaces, injection and egress paths, secrets handling, redaction that holds under adversarial input. Built for current agent stacks.

Compliance

SOC 2 readiness.

Security + Confidentiality controls mapped to the Trust Services Criteria, scoped to what an engineering team owns. Gap analysis from controls already verified, remediation sequenced against the register, evidence automation on a client-owned comp instance. The examination stays with the client's CPA.

Tooling

Finding triage & tooling.

Offline-first pipelines that scan, classify and roll up findings across repositories. Dispositions are explicit: triaged findings are deduplicated and mapped to the controls they affect, untriaged candidates are queued — a findings register an auditor can follow.

02 Method

Rig first.
Evidence always.

The method behind every number on this page. It runs the same way every time, and the reports say where it did not run.

03 Record

Nineteen findings.
Eight controls verified.

Counts from a live client program, anonymized by contract. Two engagements, five systems, one register.

5

Client systems reviewed

Across two authorized engagements.

19

Findings on the register

2 critical / 9 high / 8 medium.

8

Control sets verified

Retested on the same rig; evidence retained.

41

SOC 2 requirements scoped

Security + Confidentiality of the 74 TSC; the common SaaS start.

Confidential by default

Client identities stay out of case studies. Detailed evidence packages are shared under NDA on request.

04 Limits

What the work
does not claim.

Claims here carry the same caveats the reports do. These are the standing ones.

Start an engagement

Put a system
on the rig.

Scoping starts with one call and a system boundary. Built for engineering teams shipping AI features that touch customer data. The call is followed by the engagement plan: scope, rig design, evidence rules, report gate, dates.

Abdullah Siddique, principal. The person who scopes the engagement runs the rig and signs the report. Vancouver, BC.

Verified credentials