Security & Privacy practice
It's the question every board eventually asks about AI — and for a consulting or accounting firm, the data in question is privileged client work and regulated personal information (PIPEDA, client confidentiality, professional privilege), so “what stops it leaking” is the adoption decision. We answer it from both sides of the table: by day the principal designs and defends these exact controls as a presales security expert; by night he builds systems to them.
Runtime security
Conventional network and web inspection never parses the thing that actually carries the risk: the natural-language interaction itself. AI runtime security reads both the prompt going in and the response coming out — which is where prompt injection, jailbreaks, model poisoning and extraction, and runaway consumption actually live.
Detect attempts to override instructions, exfiltrate system context, or coerce the model past its guardrails — before they reach the model.
Controls against training/data poisoning and model-extraction probing, plus excessive-consumption limits that are named, not silent.
Inspect what comes back for leaked secrets, regulated data and unsafe content — the egress channel traditional DLP can't read.
Data loss prevention
Context-aware DLP sits in the critical path of AI traffic, inspecting inbound and outbound prompts for PII and regulated data. This is classic egress DLP extended into a channel traditional content inspection doesn't parse — and for regulated clients it's usually the control that decides whether AI adoption is approved at all.
Paired with shadow-AI discovery and risk-based access over unsanctioned AI use, plus per-prompt and per-response audit logging and token/compute cost attribution — so security, compliance and finance get the same visibility over AI they already expect from every other sanctioned service.
pii.sin · user · timestamp · redacted preview.Illustrative. Identifiers fabricated; no real client data.
OWASP Top 10 for LLM applications
Input guardrails + bounded tool preconditions, so a crafted prompt can't force a privileged action.
Responses treated as untrusted: verified in code, never executed or rendered on trust.
DLP on prompt and response traffic; fail-closed per-client visibility on every query.
Agents act only within bounded tool loops with preconditions and live re-authorization.
Figures computed deterministically; citations verified; the system refuses rather than guesses.
Self-hosted weights, network isolation and extraction-probing controls — nothing to exfiltrate off-box.
0 bytes leave
no external API · self-hosted weights
Fail-closed access
one table · re-checked at execute time
mTLS + PKI
service-to-service identity
Serve from a mirror
never mount the live client tree
Audit everything
per-prompt log · cost attribution
Privacy posture of the production platform.
Privacy by architecture
Everything we build runs with no external API dependency. Client data is served from read-only mirrors, never the live ingestion tree; service-to-service traffic is mutually authenticated; and the “no company_id = public” assumption — the one that quietly leaks data in most builds — is replaced with an explicit fail-closed check.
Security maturity isn't the absence of incidents — it's catching the near-miss and closing the class.
A one-time internal citation backfill once nearly exposed dozens of personal attachments because “no owner recorded” was treated as “safe to show.” It was caught in pre-ship verification — nothing reached a client or left the building — the staged exposure reverted, and the root cause fixed with a fail-closed database check so the whole class of assumption can't recur. That discipline — caught before harm, reverted, class closed — is what we bring to an audit.
Credentials
These certifications are depth, not a sales channel. Everything we build runs on open, self-hosted components you own — there is no product to resell here, and the security opinion you get is independent of any vendor's line card.
A readiness review maps your intended architecture against the failure modes and the OWASP LLM Top 10, with a written finding and remediation order.