Services · AI security engineering

Security for AI systems that can act.

Production AI systems carry identities, credentials, memory, tools, MCP servers, network and filesystem access, cloud permissions, inference budgets, and the authority to take actions. The prompt is one input. The execution path is the security boundary. We work where incident response, cloud, offensive security, abuse prevention, agent runtime, and AI infrastructure overlap.

Fixed offers from $75,000 (USD), fees stated belowWritten rules of engagement; template public10 free incident runbooksWorks on any stack; no qore license
What we get called for

Start from the outcome an attacker is getting.

“Our AI bill jumped and nobody can say why.”
Rapid threat picture. Compromise versus abuse classification first, then attribution by workload and spend ceilings that hold. Smallest offer: Rapid threat picture. If it is happening now, start with the free runbook: Inference Cost Spike or Token-Jacking.
“A provider key leaked. We rotated it. The abuse came back.”
Embedded adversarial operations. Credential lineage, adaptation watch after rotation, and workload identities in place of shared keys. Smallest offer: Embedded adversarial operations. If it is happening now, start with the free runbook: Leaked AI or Model API Credential.
“We are about to ship an agent or MCP server that can take real actions.”
Agentic systems and MCP red team inside a rapid threat picture: authority map, tool-integrity baseline, validated attack paths, and a regression suite before launch. Smallest offer: Rapid threat picture. If it is happening now, start with the free runbook: MCP Tool Poisoning, Impersonation, or Rug Pull.
“An agent did something nobody asked it to do.”
Active incident support and forensic trajectory reconstruction: what it saw, decided, invoked, changed, and disclosed, with explicit uncertainty. Smallest offer: Active incident support. If it is happening now, start with the free runbook: Unauthorized Agent Action or Data Exfiltration.
“A customer wants proof that our private or sovereign AI claim holds.”
Confidential and sovereign AI validation: a claim-to-control matrix, key and attestation path review, adversarial boundary tests, and a customer-facing assurance report. Smallest offer: Security capability buildout. If it is happening now, start with the free runbook: Confidential or Sovereign AI Boundary Failure.
“Security cannot see the AI estate engineering has built.”
AI attack surface and shadow infrastructure discovery: internal and external inventory, exposure validation, owners, and a repeatable discovery pipeline. Smallest offer: Rapid threat picture. If it is happening now, start with the free runbook: Shadow or Exposed AI Infrastructure.
“We pull models, plugins, and MCP servers from public hubs.”
AI supply chain and artifact assurance: an AI bill of materials, provenance and integrity controls, and CI gates that catch a test artifact. Smallest offer: Embedded adversarial operations. If it is happening now, start with the free runbook: Malicious Model, Artifact, Skill, Plugin, or Extension.
“The board asked what happens when an AI incident hits us.”
AI incident readiness and executive exercise: response plan, decision rights, telemetry readiness, a tabletop, and a ninety-day closure plan. Smallest offer: Rapid threat picture. If it is happening now, start with the free runbook: AI Provider or Model Gateway Third-Party Incident.

Inquiries marked as an active incident are read first and answered the same business day, US Pacific. Everything else within two business days. Describe the situation

The question

What authority does the AI system actually have, how can that authority be abused, and would you know when it happened?

Four capabilities answer it. Which methods apply is decided after discovery and written into scope.

AI infrastructure operations

Active abuse, leaked credentials, inference theft and token-jacking, cloud and identity attack chains, attack-surface and shadow-AI discovery, model extraction, and hands-on remediation with your engineers.

Agentic security

Agents, MCP, delegated authority, memory and retrieval poisoning, indirect prompt injection, cross-agent trust, credential reachability, egress, runtime isolation, and detection and response built around agent behavior.

AI supply chain assurance

Models, serialized artifacts, datasets, skills, plugins, coding extensions, and MCP servers treated as executable components: provenance, integrity, an AI bill of materials, and validation of confidential and sovereign boundaries.

Continuous adversarial validation

A customer-specific adversarial corpus and release gates so every material model, prompt, retrieval, tool, MCP, permission, or architecture change is compared against the prior security baseline.

Offers and fees

Five ways in, each with a fixed shape and a stated fee.

Fixed scope, fixed fee, principal-led. Fees are in US dollars and exclude taxes. When a budget is below an offer, we reduce scope before we reduce quality. Every offer starts with a forty-five-minute conversation and a written scope; nothing starts until it is signed.

Three weeks, fixed scope

Rapid threat picture

$75,000 fixed

“Tell us what is actually happening and what matters.”

Discuss this offer

Scope
  • Architecture and AI-asset map
  • Telemetry and evidence-readiness review
  • Compromise versus abuse classification
  • Up to three priority attack-path reconstructions
  • Targeted validation of the highest-risk assumptions
  • Immediate containment recommendations and a thirty-day plan
You receive
Executive threat picture, technical attack-path graph, evidence and telemetry gap register, prioritized control backlog, two production-ready hunt queries where data permits, and a closeout briefing.
Six weeks, fixed scope

Embedded adversarial operations

$150,000 fixed

“Help us fix this and get ahead of it.”

Discuss this offer

Scope
  • Everything in the rapid threat picture
  • Direct work with your security and platform engineers
  • Adversarial testing of likely next paths
  • Remediation design, detection and containment engineering
  • Validation that the same path no longer works
  • Runbooks and live knowledge transfer
You receive
Production controls and detections, validated remediation, runbooks, and a trained internal owner.
Twelve weeks, fixed scope

Security capability buildout

$275,000 fixed

“Help us build the capability internally.”

Discuss this offer

Scope
  • Everything above
  • Normalized agent and inference telemetry
  • Recurring attack-surface discovery
  • Continuous release validation
  • SOC workflows, AI bill-of-materials controls, tabletop exercises, training
  • Transition to named owners on your team
You receive
An operating capability your team runs, with the evidence to show a board or a customer.
Monthly, limited seats

Ongoing adversarial coverage

$50,000 per month, reference

“Keep testing, tuning, and reviewing as we ship.”

Discuss this offer

Scope
  • Monthly adversarial cycle
  • Detection tuning and threat review
  • Validation of material releases
  • Quarterly architecture review
  • A defined critical escalation window
You receive
Principal-led continuity after a buildout.
Weekly, from a signed emergency letter

Active incident support

Weekly principal rate with a minimum commitment; quoted in the emergency letter

“It is happening now.”

Discuss this offer

Scope
  • Evidence preservation and immediate stabilization
  • Attack reconstruction and adaptation watch
  • Coordination with your counsel and primary incident-response provider under a day-one charter
You receive
Priced weekly with a minimum commitment. No fixed total is promised before evidence volume and access are known.
What six weeks look like

Embedded adversarial operations, week by week.

The three-week threat picture is weeks one and two plus a plan. The twelve-week buildout adds telemetry, release validation, SOC workflow, and transition after week six.

WeekOperating objectiveProof at the end of the week
1Ground truth and immediate stabilizationArchitecture, identities, evidence, current abuse, preservation, containment.
2Attack reconstruction and adaptation watchFull chains, workload attribution, model, region, origin, and cost behavior.
3Next-path adversarial cycleControlled tests of equivalent trust boundaries under the rules of engagement.
4Control and detection engineeringProduction analytics, quotas, identity, routing, policy, containment.
5Remediation validationSame-path replay and weakness-class tests.
6Transfer and executive closureRunbooks, SOC handoff, architecture decisions, residual risk.
How we work

Every engagement ends with controls, not only a document.

A finding is closed only when the same outcome no longer occurs and something would notice if it came back. Where the scope is an assessment, the deliverable is a decision-grade readout and a prioritized backlog your team or ours can act on.

  1. ObserveEstablish what exists, what is happening, and which evidence is trustworthy: assets, identities, gateways, agents, tool definitions, memory, telemetry.
  2. ReconstructFollow the complete path from the initiating identity through model, agent, tool, credential, and effect. The output is an execution-path graph with confidence and alternate explanations, not a timeline of screenshots.
  3. BreakTest the next likely trust boundaries, not only the path already observed, under written rules of engagement with named systems, approved test identities, and stop conditions.
  4. InstrumentTurn each validated weakness into a control, a telemetry requirement, a hunt query, a containment action, an owner, and a regression test. No finding closes without proof of a changed outcome.
  5. TransferLeave your team able to operate without us: runbooks, queries, policy, parsers, CI tests, architecture decisions, and training delivered through the live work.
The finding standard

What every finding contains.

Another senior operator should be able to reconstruct the chain, reproduce the analytic, understand the uncertainty, and take a defensible containment decision.

  1. Claim: one sentence stating the failed boundary
  2. Authority at risk: what the system can read, change, execute, spend, or disclose
  3. Reachability: exact preconditions and attacker path
  4. Proof: reproducible evidence against a safe impact target
  5. Detection state: visible, alerted, blocked, or silent
  6. Root cause: the design or control failure, not the payload string
  7. Fix: a specific control change and a named owner
  8. Validation: evidence that the same outcome no longer occurs
  9. Recurrence analytic: the query, rule, or test that detects reintroduction
  10. Residual risk: what remains possible and why it is accepted
Rules of engagement
All work is authorized defensive work. Adversarial modules run only under written scope with named systems, approved test identities, stop conditions, and evidence-handling rules. We do not test systems we are not contracted to test. Read the template we sign.
Frameworks we map to
OWASP Agentic AI Top 10 (2026); OWASP AI Security Verification Standard; OWASP Agent Observability and Agent Control standards; MITRE ATLAS; NIST IR 8596 preliminary Cyber AI profile; OpenTelemetry GenAI semantic conventions. Mapping is a crosswalk for your reviewers, not a certification.
Alongside your existing providers

You do not have to replace a major incident-response provider or testing firm to work with us.

Your incident-response or testing firm keeps

  • Counsel and insurer coordination
  • Broad enterprise investigation and endpoint forensics
  • Crisis management at scale
  • Scheduled application, network, and cloud testing
  • Independent assurance and regulatory support

We take the embedded gap

  • An embedded principal operator
  • AI execution-path reconstruction
  • Active inference abuse and agent-specific investigation
  • Rapid hypothesis testing between formal testing cycles
  • Direct work with platform and product engineering
  • Agent, MCP, and runtime telemetry and detection
  • Remediation validation and continuous regression tests

A day-one charter names the incident commander, decision rights, evidence owner, workstream boundaries, shared identifiers, escalation routes, and report separation.

Is this for you?

Five things a good engagement has.

If two or more are missing, the smallest offer is probably the wrong purchase, and we will say so on the call.

  1. An executive sponsor who can accept risk decisions
  2. A senior engineering owner available to us daily
  3. Access that can begin within five business days of signature
  4. A budget at or above the smallest fixed offer
  5. A preference for owning the capability afterwards rather than renting it from us
Questions buyers ask first

Straight answers.

Do we have to replace our incident-response or penetration-testing firm?
No. They keep counsel and insurer coordination, broad investigation, endpoint forensics, scheduled testing, and independent assurance. We take the embedded gap: AI execution-path reconstruction, agent and inference-specific investigation, rapid hypothesis testing between formal cycles, and direct engineering work. A day-one charter sets the boundaries.
What access do you need?
Only what the rules of engagement list. Work starts passive: architecture, configuration, logs, and telemetry. Adversarial modules use named test identities against named systems inside an authorization window with stop conditions. Anything not listed is out of scope.
What happens to our prompts, data, and secrets?
Minimum proof only. Secrets are shown as an identifier or last four characters. Evidence goes to storage you approve, with a classification, encryption method, and retention period written into the rules of engagement. No third-party AI service receives your data unless you approve it in writing.
How fast can you start?
We are two principals, so it depends on what is already under way. We tell you within one business day whether we can mobilize and when. Fixed offers assume access begins within five business days of signature.
What does it cost?
The rapid threat picture is $75,000 fixed, embedded adversarial operations $150,000 fixed, the security capability buildout $275,000 fixed, and ongoing coverage a reference $50,000 per month. Active incident support is a weekly principal rate with a minimum commitment. When a budget is below an offer we reduce scope, not quality.
Is this a product or a service?
This engagement is a professional service: people, methods, and deliverables you keep. Tools we use are recorded with their version, license, and data-handling behavior, and you keep the queries, tests, runbooks, and parsers we build. Qompute AI also makes qore, a separate product in private preview; it is not part of this engagement and is not required for it.
Do we need qore, or need to replace what we already use?
No to both. This work covers the AI systems you already run on any stack, with the providers you already have. If a governed local deployment turns out to be the right control for you, that is a separate deployment engagement, scoped and priced on its own.
Which SIEM and cloud do you work in?
Hunt content is written first as KQL for Microsoft Sentinel and Defender with Splunk and Sigma translations. Other platforms are handled per engagement. Cloud, Kubernetes, inference, gateway, agent, and model providers are scoped at discovery.
Who does the work

Two principals. On every engagement.

Derek Hinch and Joey Victorino lead every engagement personally. Both delivered this kind of work before founding Qompute AI: inside a global security consultancy and for cryptocurrency protocol teams, on incident response, adversarial testing, and cryptographic review. Their backgrounds are on the team page.

Joey Victorino
  • More than a decade of incident response on nation-state intrusions, ransomware, and advanced persistent threats, inside a global cloud provider's response practice, an endpoint-security firm, and a Fortune 100 technology consultancy
  • M.S. Cybersecurity; CISSP; eleven GIAC certifications in forensics, malware analysis, and detection engineering
  • Builds and runs Qompute AI's own infrastructure and licensing hosts
Derek Hinch
  • Nearly three decades across U.S. Air Force electronic-warfare research and test, hyperscale cloud security, and Fortune 500 enterprise defense
  • Architect and principal author of qore: inference runtime, agent engine, and cryptographic subsystems
  • Author of the 2024 quaternion neural-network paper recorded in Labs
  • Client names, outcomes, and case studies are not published. References are offered under mutual agreement during scoping.
  • Fees for the fixed offers are stated on this page; active-incident work is quoted in the emergency letter.
  • Two principals lead every engagement. Capacity is limited and is confirmed before signing.
Discuss a project

Tell us the outcome an attacker is getting, or the authority you are about to give an agent.

We will say what the shortest path to a decision-grade threat picture is, and whether we are the right people for it. Inquiries marked as an active incident are read first and answered the same business day, US Pacific. Everything else within two business days.

Put no credentials, prompts, or customer data in this form. Detail moves under a signed agreement.

One or two sentences is enough. No credentials, secrets, prompts, or customer data here; detail moves under a signed agreement.
More detail (optional)
Inquiries marked as an active incident are read first and answered the same business day, US Pacific.

Derek Hinch or Joey Victorino reads it and replies personally, usually within two business days, with whether we fit and a proposed call time. Nothing is scheduled or committed by sending this form. Privacy notice.