AI infrastructure operations
Active abuse, leaked credentials, inference theft and token-jacking, cloud and identity attack chains, attack-surface and shadow-AI discovery, model extraction, and hands-on remediation with your engineers.
Production AI systems carry identities, credentials, memory, tools, MCP servers, network and filesystem access, cloud permissions, inference budgets, and the authority to take actions. The prompt is one input. The execution path is the security boundary. We work where incident response, cloud, offensive security, abuse prevention, agent runtime, and AI infrastructure overlap.
Inquiries marked as an active incident are read first and answered the same business day, US Pacific. Everything else within two business days. Describe the situation
Four capabilities answer it. Which methods apply is decided after discovery and written into scope.
Active abuse, leaked credentials, inference theft and token-jacking, cloud and identity attack chains, attack-surface and shadow-AI discovery, model extraction, and hands-on remediation with your engineers.
Agents, MCP, delegated authority, memory and retrieval poisoning, indirect prompt injection, cross-agent trust, credential reachability, egress, runtime isolation, and detection and response built around agent behavior.
Models, serialized artifacts, datasets, skills, plugins, coding extensions, and MCP servers treated as executable components: provenance, integrity, an AI bill of materials, and validation of confidential and sovereign boundaries.
A customer-specific adversarial corpus and release gates so every material model, prompt, retrieval, tool, MCP, permission, or architecture change is compared against the prior security baseline.
Fixed scope, fixed fee, principal-led. Fees are in US dollars and exclude taxes. When a budget is below an offer, we reduce scope before we reduce quality. Every offer starts with a forty-five-minute conversation and a written scope; nothing starts until it is signed.
$75,000 fixed
“Tell us what is actually happening and what matters.”
$150,000 fixed
“Help us fix this and get ahead of it.”
$275,000 fixed
“Help us build the capability internally.”
$50,000 per month, reference
“Keep testing, tuning, and reviewing as we ship.”
Weekly principal rate with a minimum commitment; quoted in the emergency letter
“It is happening now.”
The three-week threat picture is weeks one and two plus a plan. The twelve-week buildout adds telemetry, release validation, SOC workflow, and transition after week six.
| Week | Operating objective | Proof at the end of the week |
|---|---|---|
| 1 | Ground truth and immediate stabilization | Architecture, identities, evidence, current abuse, preservation, containment. |
| 2 | Attack reconstruction and adaptation watch | Full chains, workload attribution, model, region, origin, and cost behavior. |
| 3 | Next-path adversarial cycle | Controlled tests of equivalent trust boundaries under the rules of engagement. |
| 4 | Control and detection engineering | Production analytics, quotas, identity, routing, policy, containment. |
| 5 | Remediation validation | Same-path replay and weakness-class tests. |
| 6 | Transfer and executive closure | Runbooks, SOC handoff, architecture decisions, residual risk. |
A finding is closed only when the same outcome no longer occurs and something would notice if it came back. Where the scope is an assessment, the deliverable is a decision-grade readout and a prioritized backlog your team or ours can act on.
Another senior operator should be able to reconstruct the chain, reproduce the analytic, understand the uncertainty, and take a defensible containment decision.
A day-one charter names the incident commander, decision rights, evidence owner, workstream boundaries, shared identifiers, escalation routes, and report separation.
First fifteen minutes, first hour, evidence, containment, durable controls, closure. Use them without talking to us. They are how we work when we do.
If two or more are missing, the smallest offer is probably the wrong purchase, and we will say so on the call.
Derek Hinch and Joey Victorino lead every engagement personally. Both delivered this kind of work before founding Qompute AI: inside a global security consultancy and for cryptocurrency protocol teams, on incident response, adversarial testing, and cryptographic review. Their backgrounds are on the team page.
We will say what the shortest path to a decision-grade threat picture is, and whether we are the right people for it. Inquiries marked as an active incident are read first and answered the same business day, US Pacific. Everything else within two business days.
Put no credentials, prompts, or customer data in this form. Detail moves under a signed agreement.