Not a security company that learned AI
We are engineers who built large-scale ML, personalisation and identity systems, kept hitting the gaps security tools do not cover, and eventually went and did something about it. That order matters. It is why we read your architecture before we attack it.
A blade is only useful if you can hold it
AI is a blade. It is genuinely sharp, which is the entire point, and the companies winning with it are the ones swinging hardest. Nobody sensible responds to a sharp tool by refusing to pick it up.
The hilt is the part that lets you hold it. The crossguard is what stops your hand sliding onto the edge while you are busy doing the thing you picked the blade up to do. It does not make the blade less sharp. It makes it yours to use.
That is the job. We are not here to slow your AI programme down or to tell you the risk means you should not ship. We are here so you can move fast without cutting yourself, accidentally or because somebody else made you.
Ember always marks the part we contribute. Same rule in the wordmark, where it sits on Lock.
We ask a different question
Most of the industry asks whether a prompt is safe. That is a content question, and it is the one automation is already good at answering.
We ask whether this action, by this identity, on this data, right now should be allowed. That is an authorisation question, and nearly every serious finding we have published came from asking it.
The 95 customer reports a free-trial account walked away with was not a prompt problem. Nothing was phrased cleverly. There was no jailbreak. The system simply never checked who was asking.
What we hold to when it costs us something
Anyone can list values. These are the ones that have actually cost us revenue, which is the only test that means anything.
Evidence over assertion
Every finding ships with reproduction steps. If you cannot reproduce it without us in the room, we have not finished writing it. Severity we assert is worth nothing; severity you can verify is worth acting on.
We say where automation stops
Our automated pass is genuinely useful and genuinely limited, and we publish both halves of that. A vendor who will not tell you the ceiling of their own tool is selling you the ceiling as the whole building.
Right-sell, not upsell
You will hear us decline revenue. If the cheap automated pass covers your situation, we say so and take the smaller number. If neither product suits you, we say that too.
Depth over breadth, on purpose
No traditional VAPT, no security operations, no certification. A specialist who will do anything is not a specialist, and the moment we take on commodity work is the moment we stop being worth calling for this.
Retest, never take the ticket's word
"Fixed" is a claim until it is re-run against the live system. We re-attack with the same model and record what actually closed. Sometimes the answer is that it did not.
The findings are yours
Written so your engineers can act without us, and so your buyers and auditors can read them without translation. No portal you have to keep paying for to see your own results.
"You are a small team. What if you disappear?"
Usually the third question we get, and a fair one. Headcount is not the reassurance you actually want, so here is what protects you instead.
The methodology is written down
The attack library and testing sequence are documented artifacts, not knowledge living in one head. That is also what makes the automated pass possible at all: you cannot automate a method nobody wrote down.
Named primary and named backup
You get both on the first call, and both are briefed on the engagement throughout. Not a support queue, and not one person holding the whole relationship.
Findings outlive the engagement
Reproduction steps, affected components, fix path. If we disappeared mid-engagement you would still be holding something your team could act on tomorrow.
Escalation in writing
Response times and the escalation route sit in the engagement terms rather than being implied. Anything found that cannot wait for the report reaches you the same day.
We would rather you asked than assumed. A large firm with a rotating bench and a junior on your account is a continuity risk too. It is just a better-dressed one.
Where the instincts come from
Twelve years each building large-scale ML, personalisation, growth, identity and data-governance systems. The authorisation instinct behind most of our findings comes from having built the systems that get this wrong.
Where the team built, not who we have sold to. We do not put customer logos on this site without permission, and most of our clients prefer not to advertise that they needed us.
HiltLock is operated by CalmSparks Tech Pvt. Ltd. We were previously in market as HiltLock. Same people, same methodology, sharper focus.
Judge us on the findings, not this page
Everything above is a claim. The evidence page is not.