Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
AI Security · New

AI / LLM Security Assessments

From $4,000CAD · scoped to what you built · hands-on, with our testing partnerSee full pricing →

Every startup is shipping AI features. Almost none have tested them for prompt injection, data leakage, or agent abuse. We do. Strategy comes from traztech. Adversarial testing comes from our offensive-security partner.

Book a scoping call
Adversarial, not theoretical. five published CVEs, with hands-on testing run with our testing partner.

Real attacks, not regex scans

We treat your AI feature like an attacker would. Hand-crafted prompt corpora, multi-turn jailbreaks, and live agent abuse. Not a wrapper over an open-source scanner.

01

Prompt injection & jailbreak testing

Direct and indirect prompt injection. Role override and system-prompt extraction. Multi-turn jailbreaks that defeat naive guardrails. Tested across the OWASP LLM Top 10 plus our own corpus from real engagements.

02

Data leakage & PII exposure

RAG poisoning, context-window leakage, training-data exfiltration, cross-tenant context bleed. We try to make your model surface another customer's data. If it can be done, we will find the path.

03

Agent abuse & tool misuse

Autonomous agents acting on attacker-controlled inputs are the new SSRF. We test for tool-call injection, side-effect chains, privilege confusion across tools, and unbounded action loops. Critical for any agent that touches a database, an API, or a billing system. If you have not shipped the agent yet, testing it before launch is the cheapest time to find these.

04

Model integrity & supply chain

Base-model provenance, fine-tune dataset audit, third-party API trust surface, and model serialization risks. Most teams forget that a hosted model is a third-party dependency with a privileged seat in their stack.

What an engagement covers

The testing window is agreed at scoping. Below is what we hand back.

StandardOWASP LLM Top 10
FormatExecutive + technical reports
FindingsRanked by exploitability
Re-testIncluded on remediation
DeliveryWindow agreed at scoping
ConfidentialityNo prompts shared with vendors

Why this team, why now

AI security is a new label on an old discipline. The teams that win at it are the ones that have already done AppSec the hard way.

·

Offensive testing partnership

Adversarial testing is delivered with our testing partners, who run penetration testing, red team, and AI agent assessments. We work with both Canadian and global firms and put the one that gives you the best value on your engagement, and we bundle their hands-on testing with our remediation strategy in one engagement.

·

Published CVEs and AppSec lineage

Our principal has published CVEs and led application-security programs for years before LLMs were called LLMs. Prompt injection is a parsing problem; data leakage is an authorization problem. We have been doing the underlying work for a decade.

·

Strategy that survives the report

Most pentest reports get filed and forgotten. Ours come with a remediation plan, a re-test, and an optional retainer to keep your AI surface tested as it changes. The report is a starting point, not a deliverable.

How we work

Three phases. No surprises on scope or invoice.

01

Threat-model the surface

Map the AI feature: model, prompts, retrieval sources, tool calls, downstream effects. Identify trust boundaries and the failure modes that actually matter for your business.

02

Adversarial testing

Our partner runs the assessment against the threat model with both black-box and grey-box methods, covering prompts plus tooling. We sit in the loop to flag findings against your actual architecture, not generic boilerplate.

03

Remediate & re-test

Findings ranked by exploitability with concrete fixes. We help your engineers ship the patches, then re-test the high-severity items before sign-off.

Works well with

Fixed-scope AI security offers

Ship AI features without shipping a breach

Tell us what you are building. We will scope an assessment in one call.

Book a Call

Frequently asked questions

What does an AI/LLM security assessment cover?

We assess the risks specific to systems that use large language models: prompt injection, insecure output handling, data leakage through prompts and context, model and supply-chain risks, excessive agency in tool-using agents, and access control around model endpoints. The work is mapped to the OWASP Top 10 for LLM applications.

How is this different from a normal pen test?

A traditional pen test targets your network, infrastructure, and application logic. An AI assessment targets the model layer: how prompts, context, tools, and outputs can be abused. The threat model is different. We often run both, since an LLM feature still sits on top of conventional infrastructure that needs testing too.

Do you test agents and tool-using systems?

Yes. Agentic systems that call tools, browse, or take actions carry extra risk because a successful injection can trigger real-world effects. We review tool permissions, sandboxing, human-in-the-loop checkpoints, and how untrusted content flows into the agent.

Will this help with enterprise AI security reviews?

Yes. Buyers increasingly ask how you secure AI features before they sign. A documented assessment with prioritized findings and remediation gives you evidence to answer those questions and shortens the review. It also feeds directly into SOC 2 and broader security questionnaires.

Who runs the assessment?

It is led by our principal, a published security researcher with 5 CVEs. Deeper application and infrastructure penetration testing is delivered with our offensive-security partner when scope calls for it.

Free PDFs, no card

Get the AI governance checklists

The template set as PDFs, including the vendor security questionnaire that most AI vendor reviews start from. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Track record

Who is actually doing the work

We would rather show you the work than a wall of logos. Here is what is behind the advice.

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.

The platform stayed in production throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.