AI & AGENT SECURITY
Give AI systems useful authority without giving them unchecked access.
Review LLM applications, AI agents, RAG workflows, MCP and tool integrations, memory, identity, data access, approval gates, monitoring, and high-impact actions.
Review surface
What we review
-
01 Instructions & prompts System instructions, prompt boundaries, injection paths, and control assumptions. -
02 Retrieval & data Sources, access, poisoning, sensitive data, provenance, and isolation. -
03 Memory & state Persistence, cross-user leakage, manipulation, retention, and deletion. -
04 Tools & permissions APIs, MCP servers, credentials, scope, delegation, and dangerous actions. -
05 Identity & approval User, agent, service, and human-in-the-loop authorization. -
06 Monitoring & response Logs, anomaly signals, rollback, containment, and investigation.
Timing
Best used when
Sensitive access
An agent can read sensitive data or call business-critical tools.
High-impact action
Automation can change records, move value, deploy code, or trigger workflows.
New trust model
RAG, memory, MCP, or multi-agent architecture changes authority boundaries.
Before expansion
Leadership needs a bounded view of AI risk before launch or expansion.
Process
From authority mapping to contained agent behavior.
- 01
Map agent authority
Document models, prompts, retrieval, memory, identities, data sources, tools, approvals, and high-impact actions.
- 02
Trace control boundaries
Follow untrusted input through reasoning, data access, tool calls, human approval, monitoring, and recovery.
- 03
Test abuse and failure
Challenge prompt boundaries, permissions, data handling, tool use, and autonomous behavior with realistic scenarios.
- 04
Contain and verify
Prioritize permission, approval, monitoring, and recovery changes, then verify agreed controls.
Outputs / What you receive
Clear findings, practical fixes, and a report your team can use.
Authority map
AI system, identity, data, tool, and approval boundaries.
Prioritized findings
Technical and workflow findings with abuse and failure scenarios.
Control recommendations
Permission, approval, monitoring, containment, and recovery improvements.
Typical engagement team
Who typically leads this work
The exact team depends on the scope. Every engagement has a principal who owns it from scoping through delivery, joined by the specialists the system calls for, and whoever is assigned is named in your proposal.

José C. Ramírez
Specialist Advisor
Security engineer and trainer with around 10 years across application and protocol security. At ZKsync, reviewed Solidity, account abstraction, and Rust, then built AI-assisted vulnerability-analysis workflows.

Michal Bajor
Specialist Advisor
Secured funding, custody, APIs, and on-chain systems at Kraken. Has reviewed 60+ Web3 projects across DeFi, L1s, bridges, oracles, and other critical infrastructure.

Timur Güvenkaya
Founder & Partner
Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.
Related services
Next step
Map the authority before the agent uses it.
Share the architecture, models, data sources, tools, identities, and high-impact actions. We will define the right review or design scope.
Discuss your scope