For consultancies, SIs and MSSPs

The AI red team you white-label

Your client is asking about AI risk. You have the relationship, the scope and the contract. What you do not have is someone who has broken a production GenAI system before. We work behind your brand.

01  /  The problem we solve for you

You cannot hire this fast enough

AI security specialists are scarce, expensive, and mostly not looking. Meanwhile the AI section of every enterprise security questionnaire got longer this year, and your clients are asking you about it now rather than next budget cycle.

Option A

Hire a team

Nine to twelve months to recruit, a senior salary each, and utilisation risk while your pipeline is still forming.

Option B

Stretch your pentest team

They are good, and this is not their discipline. A report that misses the AI-shaped hole is worse than no report, because it tells your client they are covered.

Option C

Subcontract the specialism

Keep the relationship and the margin. Bring in depth for the part that needs it, on the engagements where it matters.

02  /  How it works

Terms, stated plainly

Partner arrangements usually fall apart over the things nobody wrote down, so here they are.

Question Our answer
Whose brand is on the report? Yours. We deliver an unbranded findings report you re-badge, or we work inside your template. Your call.
Will you contact our client? Not unless you put us in the room. We are happy to join a technical call as your specialist, introduced however you prefer.
Will you go around us later? No. Contractual non-solicit on any client you introduce, for the life of the relationship plus a tail.
How do we price it? You buy at a partner rate and set your own client price. We do not publish your margin and we do not quote your client directly.
How fast can you start? The automated pass can run inside 24 hours of getting access. Human-led assessments book one to two weeks out, sooner if the scope is tight.
What if our client wants everything? We only take the AI scope. Traditional VAPT, SOC and compliance work stay yours, which is usually the larger half.
03  /  What you can resell

Two things, at two speeds

24 hours or less AWS Marketplace

Automated assessment

The easiest thing to attach to an engagement you already have. Cheap enough to include in a discovery phase, fast enough not to move your timeline, and it frequently surfaces something that justifies a larger piece of work.

  • Bundle it into an assessment you are already scoping
  • Run it per sprint as a managed service under your brand
  • Available through AWS Marketplace if your client prefers to transact there
1 to 2 weeks Human-led

Human-led assessment

For the engagements where the finding has to stand up to scrutiny. Architecture-aware testing, exploit chains with reproduction steps, and a named practitioner who will defend the work on a call with your client's engineering team.

  • Delivered to your template and your timeline
  • We join client calls as your specialist when you want us to
  • Findings written to survive a hostile technical review
04  /  Being straight with you

We are taking very few of these

There is no partner portal, no tier structure and no channel team. We are working with a small number of partners properly rather than signing a page of logos, because delivery quality is the only thing we have that a client cannot get elsewhere.

If you are looking for a vendor to list on a slide, we are the wrong call. If you have a live client conversation about AI risk and no one to hand it to, that is exactly the call to make.

Findings report / partner edition Your brand here

3.1 Cross-tenant retrieval boundary bypass

Severity: Critical. Reproduced in 3 of 3 attempts. The retrieval scope was enforced by instruction rather than by policy, allowing a caller authenticated as one tenant to read documents belonging to four others.


Delivered unbranded. Your cover, your template, your client relationship.