Generic controls fail. Tuning is the real work.

Off-the-shelf security controls keep failing because they try to be generic. The real work is tuning them to your use cases and your organization: software that integrates into your environment and stays under your ownership.

Tuned software

We deliver software and modules tuned to your use cases, integrated into your environment.

Your IP, your ownership

What we build with you is yours: the code, the controls, and the knowledge to run them.

Optional shared delivery

Either we build it or your team does, with us working as the architects and AI security experts behind the solution.

SafeDescent Modules

The pieces we bring into your environment.

Organization mapping, governance, security controls, supervision and testing: five modules that grew out of engagements, not out of a roadmap. Each one is small enough to understand and built to sit next to what you already run.

We use them to speed up our own work on your systems, and we leave them with your team when they are useful on their own. None of them asks you to move your stack.

Governance module: registry, the AI estate at a glance with lifecycle pipeline
01 / 06

Early Risk Awareness

Self assessments that read the AI risk of a system in minutes.

Written by practitioners from the questions we ask in engagements. Each assessment asks the minimum number of questions and still leaves you with a risk classification and specific risks to check.

Runs in your browser; your answers stay there unless you choose to share them with us as a conversation starter.

Open ERA
ERA: answering an AI reliance assessment question
01 / 07

Security Testing Toolbox

Prompt injection and agentic attack techniques, organised so you can test with them.

An interactive map of prompt injection and jailbreak techniques, how they relate, and what defends against them. Grown from our prompt injection taxonomy into a toolbox you can run test cases from.

Built for teams that need to test their own LLM and agent systems without assembling a red team first.

Taxonomy: cognitive trap and model confusion techniques
01 / 09

Hush

Personal data masked before it leaves your machine.

A browser extension that masks personal data in ChatGPT, Claude, Gemini and Grok prompts before they are sent. English, Polish and Japanese, with an optional local detection engine.

A seatbelt, not a wall: it catches what people paste in a hurry, and it is honest about its limits.

Learn more
Hush desktop: engine running, protecting prompts locally
01 / 02
Behind the software
The same practice that builds these can assess and fix your AI systems.
See our services