AI Act applicability & role determination
Per AI system, establish whether you are provider, deployer, importer or distributor, classify risk, and produce an attested applicability determination with its basis recorded. The question every other obligation hangs from.
AI governance readiness assessment
Assess your AI management system against ISO/IEC 42001 and the applicable AI Act duty elements. The gap report names, for each unmet duty, whose condition prevents it, so remediation has an owner rather than a colour.
Evidence & technical documentation build
Build the Annex IV technical documentation and the ISO/IEC 42001 Statement of Applicability, with every claim traced to its source evidence rather than to a paragraph someone wrote.
Adversarial testing & AI red-teaming
Contained adversarial testing of deployed AI systems with a reproducible evidence record, addressing the Article 15 robustness and cybersecurity duties, which apply from 2 December 2027. Prompt injection, tool poisoning, excessive agency and egress abuse, proven rather than asserted.
Security posture assessment & threat modelling
We map your real attack surface across applications, APIs, cloud and identity, then model it with STRIDE and, for AI systems, agentic frameworks. Findings ranked by exploitability and impact, not raw CVSS.
Continuous advisory
A standing relationship for teams without a full security function. We review designs, triage risk and keep your posture current as you ship, including as your AI footprint grows.