For consultancies, SIs and MSSPs

AI security specialists for your engagements

Your client is asking about AI risk. You have the relationship and the contract. You need someone who has broken a production GenAI system before. We're flexible on brand and how we engage, that's yours to set. We never approach your client on our own.

01  /  The problem we solve for you

You cannot hire this fast enough

AI security specialists are scarce, expensive, and mostly not looking. Meanwhile the AI section of every enterprise security questionnaire got longer this year, and your clients are asking you about it now rather than next budget cycle.

Option A

Hire a team

Nine to twelve months to recruit, a senior salary each, and utilisation risk while your pipeline is still forming.

Option B

Stretch your pentest team

They are good, and this is not their discipline. A report that misses the AI-shaped hole is worse than no report, because it tells your client they are covered.

Option C

Subcontract the specialism

Keep the relationship and the margin. Bring in depth for the part that needs it, on the engagements where it matters.

02  /  How it works

Terms, stated plainly

Partner arrangements usually fall apart over the things nobody wrote down, so here they are.

Question Our answer
Whose brand is on the report? Yours, ours, or co-branded, decided per engagement.
Will you contact our client? Never on our own. We join a call as your specialist only if you ask.
Will you go around us later? No. Contractual non-solicit on any client you introduce, for the life of the relationship plus a tail.
How do we price it? You buy at a partner rate and set your own client price. We do not publish your margin and we do not quote your client directly.
How fast can you start? The automated pass can run inside 24 hours of getting access. Human-led assessments book one to two weeks out, sooner if the scope is tight.
What if our client wants everything? We only take the AI scope. Traditional VAPT, SOC and compliance work stay yours, which is usually the larger half.
03  /  What you can resell

Two things, at two speeds

24 hours or less AWS Marketplace

Automated assessment

The easiest thing to attach to an engagement you already have. Cheap enough to include in a discovery phase, fast enough not to move your timeline, and it frequently surfaces something that justifies a larger piece of work.

  • Bundle it into an assessment you are already scoping
  • Run it per sprint as a managed service under your brand
  • Available through AWS Marketplace if your client prefers to transact there
1 to 2 weeks Human-led

Human-led assessment

For the engagements where the finding has to stand up to scrutiny. Architecture-aware testing, exploit chains with reproduction steps, and a named practitioner who will defend the work on a call with your client's engineering team.

  • Delivered to your template and your timeline
  • We join client calls as your specialist when you want us to
  • Findings written to survive a hostile technical review
  • Includes voice agents, attacked over live telephony or WebRTC, for clients whose voice agents nobody on your bench can test
04  /  Being straight with you

We are taking very few of these

There is no partner portal, no tier structure and no channel team. We are working with a small number of partners properly rather than signing a page of logos, because delivery quality is the only thing we have that a client cannot get elsewhere.

If you are looking for a vendor to list on a slide, we are the wrong call. If you have a live client conversation about AI risk and no one to hand it to, that is exactly the call to make.

Findings report / partner edition Your brand here

3.1 Cross-tenant retrieval boundary bypass

Severity: Critical. Reproduced in 3 of 3 attempts. The retrieval scope was enforced by instruction rather than by policy, allowing a caller authenticated as one tenant to read documents belonging to four others.


Your brand or ours, your call.