Security & Privacy practice

“What stops this thing leaking our data?”

It's the question every board eventually asks about AI — and for a consulting or accounting firm, the data in question is privileged client work and regulated personal information (PIPEDA, client confidentiality, professional privilege), so “what stops it leaking” is the adoption decision. We answer it from both sides of the table: by day the principal designs and defends these exact controls as a presales security expert; by night he builds systems to them.

Prompt-injection & jailbreakDLP over prompt traffic Shadow-AI governanceOWASP Top 10 for LLMs On-prem · zero egress

Runtime security

Guardrails on both sides of the model.

Conventional network and web inspection never parses the thing that actually carries the risk: the natural-language interaction itself. AI runtime security reads both the prompt going in and the response coming out — which is where prompt injection, jailbreaks, model poisoning and extraction, and runaway consumption actually live.

Input

Prompt-injection & jailbreak

Detect attempts to override instructions, exfiltrate system context, or coerce the model past its guardrails — before they reach the model.

Model

Poisoning & extraction

Controls against training/data poisoning and model-extraction probing, plus excessive-consumption limits that are named, not silent.

Output

Response inspection

Inspect what comes back for leaked secrets, regulated data and unsafe content — the egress channel traditional DLP can't read.

Data loss prevention

Sensitive data can't leave through a chat box.

Context-aware DLP sits in the critical path of AI traffic, inspecting inbound and outbound prompts for PII and regulated data. This is classic egress DLP extended into a channel traditional content inspection doesn't parse — and for regulated clients it's usually the control that decides whether AI adoption is approved at all.

Paired with shadow-AI discovery and risk-based access over unsanctioned AI use, plus per-prompt and per-response audit logging and token/compute cost attribution — so security, compliance and finance get the same visibility over AI they already expect from every other sanctioned service.

DLP · prompt egress inspection
Summarise this and email it to the vendor: “Client SIN 123‑456‑789, balance …”
⟂ blocked · DLP  Outbound prompt contains a government identifier (SIN) and a client financial record. Egress to an external model/provider denied. Logged: rule pii.sin · user · timestamp · redacted preview.
Draft the same note with identifiers removed.
✓ allowed  No regulated data detected. Proceeding — on-prem model, nothing leaves the building.

Illustrative. Identifiers fabricated; no real client data.

OWASP Top 10 for LLM applications

We design to the standard the industry is converging on.

LLM01 · Prompt injection

Input guardrails + bounded tool preconditions, so a crafted prompt can't force a privileged action.

LLM02 · Insecure output

Responses treated as untrusted: verified in code, never executed or rendered on trust.

LLM06 · Sensitive disclosure

DLP on prompt and response traffic; fail-closed per-client visibility on every query.

LLM08 · Excessive agency

Agents act only within bounded tool loops with preconditions and live re-authorization.

LLM09 · Overreliance

Figures computed deterministically; citations verified; the system refuses rather than guesses.

LLM10 · Model theft

Self-hosted weights, network isolation and extraction-probing controls — nothing to exfiltrate off-box.

privacy by architecture

0 bytes leave

no external API · self-hosted weights

Fail-closed access

one table · re-checked at execute time

mTLS + PKI

service-to-service identity

Serve from a mirror

never mount the live client tree

Audit everything

per-prompt log · cost attribution

Privacy posture of the production platform.

Privacy by architecture

The strongest DLP control is the data never leaving.

Everything we build runs with no external API dependency. Client data is served from read-only mirrors, never the live ingestion tree; service-to-service traffic is mutually authenticated; and the “no company_id = public” assumption — the one that quietly leaks data in most builds — is replaced with an explicit fail-closed check.

Security maturity isn't the absence of incidents — it's catching the near-miss and closing the class.

A one-time internal citation backfill once nearly exposed dozens of personal attachments because “no owner recorded” was treated as “safe to show.” It was caught in pre-ship verification — nothing reached a client or left the building — the staged exposure reverted, and the root cause fixed with a fail-closed database check so the whole class of assumption can't recur. That discipline — caught before harm, reverted, class closed — is what we bring to an audit.

Credentials

Two decades of security architecture behind the AI.

9× Fortinet — incl. Certified Solution Specialist, SASE Cisco CCNP Enterprise + Security specialist track Palo Alto PCNSE Delivery to PCI & HIPAA

These certifications are depth, not a sales channel. Everything we build runs on open, self-hosted components you own — there is no product to resell here, and the security opinion you get is independent of any vendor's line card.

Reviewing an AI deployment? Start with the controls.

A readiness review maps your intended architecture against the failure modes and the OWASP LLM Top 10, with a written finding and remediation order.