Skip to content
AI Security Services · 2026

AI security testing that produces evidence, not just findings.

We discover the shadow AI in your environment, red-team the AI systems you ship, and produce the audit evidence regulators now require — delivered with tooling we build and publish openly.

Auditable sensor · Fixed-fee engagements · 30-day re-test · Framework-mapped output
The forcing function

AI security just became a legal obligation.

The EU AI Act adversarial-testing obligations are operative — GPAI systemic-risk red-teaming since Aug 2025 (Art. 55), high-risk risk-management from 2 Aug 2026 (Art. 9). Penalties reach €35M or 7% of global turnover.

A scanner gives you

A findings list

Raw output, no methodology, no framework tags, no verified fix — stale the moment the model changes. Not something an auditor can use.

An engagement gives you

Defensible evidence

Documented method, mapped findings, verified remediation, re-tested, structured the way regulators are asking for it. That gap is the business.

Six ways to work together

Fixed-fee engagements, defined scope.

Every engagement is fixed-fee against a scope agreed before work begins — and every assessment includes a re-test after fixes ship.

Flagship

EU AI Act Readiness

2–3 weeks · fixed fee

Where you stand against Article 9 & 55 — plus the evidence structure you will be assessed on, built to be maintained.

  • High-risk classification review
  • Gap analysis vs. Art. 9 risk-management
  • Safety & Security Model Report — populated
  • Incident-reporting runbook + remediation roadmap
Best forOrgs with AI systems in EU markets, or facing a customer security review that now asks about AI governance.
Focused testing

AI Security Assessment

2 weeks · + 30-day re-test

Adversarial testing of one LLM application or agent, mapped to OWASP LLM Top 10 and MITRE ATLAS.

  • Prompt injection, jailbreak, instruction-override
  • Excessive agency & tool-access review
  • Conventional AppSec of the API surface
  • Severity-classified findings + verified re-test
Best forTeams with one production AI app who need defensible evidence before launch, or after a customer asks.
Deep engagement

Full AI Red Team

4 weeks · + 30-day re-test

End-to-end adversarial testing across the app, its retrieval layer, and its agent layer — including chained attack paths.

  • RAG: indirect injection, retrieval poisoning, tenant isolation
  • Agent/MCP: tool-call auth, confused-deputy
  • Chained privilege escalation, multi-turn attacks
  • Board-level executive summary + full technical findings
Best forOrgs running agentic systems with tool access, RAG over sensitive data, or multi-agent workflows.
Discovery

Araghatta

1–2 weeks · fixed fee

What unapproved AI is actually running in your environment right now — the inventory a governance programme starts from.

  • Endpoint sensor across Windows, Linux, macOS
  • Eleven signal classes — network, MCP & tool scope, keys, IDE assistants, skills, agents, mobile & more
  • Full inventory with attribution — machine, user
  • Risk-ranked, sanctioned vs. unsanctioned
Best forSecurity teams beginning an AI governance programme who need a real inventory first.
Recurring

Continuous AI Testing

Rolling · 3-mo minimum

Point-in-time testing goes stale the moment a model changes. This keeps the harness running as your systems evolve.

  • Automated adversarial testing on a schedule
  • Regression suite — every finding becomes a test
  • Monthly framework-mapped report
  • Alerting on new AI systems & failure modes
Best forTeams shipping AI changes continuously, where an annual assessment cannot keep pace.
Advisory

Embedded AI Programme

Ongoing · 6-mo minimum

Ongoing ownership of your AI risk programme without a full-time hire.

  • Ownership of the AI risk register & red-team harness
  • AI security policy & standards
  • Board and audit-committee reporting
  • Direct support during audits & customer reviews
Best forOrgs adopting AI faster than their security function can govern it, without headcount to hire.
The tooling behind every engagement

Eighteen testing capabilities, one platform.

Every assessment is powered by our own testing platform — real scanners and adversarial probes across code, cloud, models and agents, each finding scored deterministically with AI reasoning applied to the ambiguous cases, and delivered as framework-mapped evidence.

Code, supply chain & secrets
  • Source Code Analysis
  • Live Application Scan
  • Dependency & Supply-Chain Risk
  • Secret & Credential Scan
  • License & Provenance
  • Container Posture
  • Infrastructure Exposure
AI / LLM red-team
  • Prompt Injection Probe
  • Jailbreak & Multi-turn Attack
  • Injection Surface Mapping
  • Data Leakage & Safety
  • Agent Interface Scan
  • Agent Capability Map
Model, guardrails & inventory
  • Model Artifact Integrity
  • Guardrail Effectiveness
  • AI Threat Model
  • AI-BOM Generator
  • Vulnerability Triage
New this quarter Secret & Credential Scan, AI-BOM Generator, and License & Provenance — full AI supply-chain coverage.
Delivered where you work Findings sync to Jira & Slack; critical & high risks alert in real time and close automatically when you resolve them.
Always current A threat-intel feed keeps discovery signatures fresh, and a compliance-evidence agent generates audit-ready packs mapped to NIST AI RMF, OWASP LLM Top 10, ISO 42001 & the EU AI Act.
Evidence your auditor reads

Every finding maps to a framework.

Findings without framework tags are findings an auditor cannot use. Mapping is part of every engagement — never an add-on.

EU AI Act — Art. 9 & 55OWASP LLM Top 10MITRE ATLASNIST AI RMFISO/IEC 42001ISO/IEC 27001OWASP Top 10
How it runs

Scoping to evidence in four steps.

01
Scoping call
Free, 30 minutes. If it is not the right fit, we say so — and tell you what would be.
02
Fixed proposal
Defined scope, fixed fee, fixed timeline. No hourly billing on defined work.
03
Testing
Weekly progress. Critical findings reported immediately, not held for the report.
04
Report & re-test
Findings, evidence, roadmap — then a 30-day re-test to verify and document the fixes.
Why this practice

What is different here.

Auditable by design

Before the sensor is ever deployed, we walk you through exactly what it collects — and what it never touches. You review the agent's behaviour and data flow up front; few vendors let you look under the hood at all.

Fixed fee, not hourly

Scope and price agreed before work starts. No hourly billing on defined work, no scope-creep invoices, a written rate card at the scoping call.

Evidence is the deliverable

Most engagements end with a findings list. These end with framework-mapped evidence, verified remediation, and an auditor-ready report.

Built, not resold

Sensors and adversarial orchestration are purpose-built, not licensed from a scanner vendor — faster coverage per dollar, findings tuned to you.

Start here

Start with a scoping call.

Thirty minutes, no cost, no obligation. If what you need is smaller or different than what is listed here, we tell you — including if the honest answer is that you do not need an engagement yet.

Book a scoping call
shadowaidiscovery.com · discovery.test().prove()