Security & Compliance

Answer the AI questionnaire.
Then fix what it exposes.

A fixed-scope review of a production agent or RAG system: what it can reach, how it gets abused, and how to rebuild it so the finding stops recurring. It ends with the AI-governance evidence pack your enterprise buyer is asking for, and the remediation shipped as pull requests.

40+
MCP CVEs disclosed Jan–Apr 2026
~40%
Of enterprise apps run agents by end-2026
~6%
Report an advanced AI security strategy
Trusted by 32+ teams shipping remote engineering, today
Razorpay
Naamly
Tekdoors
SimAgro
Enzen Technologies
Greenlink Health
R360
SharafDG
Concourse Solutions
YOptima
ReMarketplace
Desisiv
Dealflow
LIAISON
Stealth Connect
Car Concierge Pro
Dinner Daddy
Heal Me Fit
Heather Hakes
Kegelbell
Laina
MogiFit
Visag
YouthRenewal
OC Weight Loss
USPTO Lawmatics
Delegata
AZCap
Mindbase
WeBuyUglyBuildings
One Collab Space
Epifinder
Razorpay
Naamly
Tekdoors
SimAgro
Enzen Technologies
Greenlink Health
R360
SharafDG
Concourse Solutions
YOptima
ReMarketplace
Desisiv
Dealflow
LIAISON
Stealth Connect
Car Concierge Pro
Dinner Daddy
Heal Me Fit
Heather Hakes
Kegelbell
Laina
MogiFit
Visag
YouthRenewal
OC Weight Loss
USPTO Lawmatics
Delegata
AZCap
Mindbase
WeBuyUglyBuildings
One Collab Space
Epifinder
Why it matters

The scarcest skill in AI security is not offensive security — it is understanding how production agent systems actually fail: tool schemas, memory persistence, retrieval scoping, MCP wiring, orchestration loops. Most AI red teamers came from application security and have never shipped an agent. We ship them weekly, which is why our findings come back as pull requests rather than screenshots.

Benefits

Why teams choose us.

Built By People Who Build Agents

We run a production agentic practice. The review is done by engineers who have debugged tool-permission bugs at 2am, not by testers reading an architecture diagram.

Fixes, Not Findings

Remediation arrives as pull requests against your repository, with a regression eval harness wired into your CI so the same class of failure cannot come back.

The Evidence Pack

The 2026 SIG added an expanded AI governance section and CAIQ now names ISO 42001 and NIST AI RMF. You get answers to those questions, grounded in your actual system.

Independent Of Your Build Team

We do not review agents withRemote built. Independence from the builder is explicit in 2026 practice and sophisticated buyers check for it.

What we offer

The full menu.

Threat Model & Blast Radius

  • Tool surface and permission mapping
  • What the agent can reach on its worst day
  • Excessive-agency and privilege paths
  • Human-in-the-loop gate placement

Adversarial Testing

  • Direct and indirect prompt injection
  • Tool abuse and unauthorised action chains
  • Memory and conversation-state leakage
  • Retrieval and vector-store permission leakage

MCP & Tool-Schema Review

  • Server trust boundaries
  • Tool-description poisoning surface
  • Supply chain of connected servers
  • Schema validation and output handling

AI Governance Evidence Pack

  • SIG and CAIQ AI-section answers
  • Model provenance and subprocessor map
  • Data flow and training-data position
  • Mapped to ISO/IEC 42001 and NIST AI RMF

Remediation & Regression

  • Fixes shipped as pull requests
  • Guardrail and output-handling layer
  • Eval harness running in your CI
  • Optional continuous re-test retainer
How it works

Our process.

01

Scope & Authorisation

We agree the systems in scope and sign Rules of Engagement plus a countersigned authorisation letter from a verified asset owner. Default scope is staging and non-destructive.

02

Model & Map

Architecture review, tool inventory, permission mapping and blast-radius analysis. Most of the serious findings surface here, before a single payload is sent.

03

Adversarial Pass

Prompt injection, tool abuse, memory and retrieval leakage, MCP trust boundaries — run against the real system, with every attempt logged.

04

Fix & Evidence

Remediation as pull requests, a regression eval suite in your CI, and the governance evidence pack your buyer's questionnaire is asking for.

Tech stack

What we build with.

Frameworks
OWASP Top 10 for Agentic ApplicationsOWASP LLM Top 10 2026MITRE ATLASNIST AI RMFISO/IEC 42001 Annex A
Tooling
PromptFooGarakDeepTeamBurp Suite Pro
Surfaces
MCP serversLangGraphRAG pipelinesVector storesTool/function calling
Week 0
Scope, ROE and authorisation signed
Week 1
Threat model and permission map
Week 2
Adversarial pass
Week 3
Pull requests, eval harness, evidence pack
By jurisdiction

Where this review is worth buying

Default scope is staging and non-destructive, which makes this the most portable security service we offer — the constraint is authorisation, not residency.

United StatesDeliverable

Full scope. The buying trigger is procurement: the 2026 SIG update added an expanded AI governance section and CAIQ now names ISO 42001 and NIST AI RMF outright.

No production testing without signed Rules of Engagement and a countersigned authorisation letter from a verified asset owner, plus third-party authorisation where the systems sit on AWS or Azure.

United KingdomDeliverable

Full scope for private-sector clients. A useful secondary trigger: the April 2026 Cyber Essentials Danzell question set brought AI and LLM tools formally into scope as cloud services, so anyone who deployed an agent since their last renewal now has a certification problem they did not have before.

We hold no CREST or CHECK accreditation and will not imply otherwise. UK public sector is closed.

European UnionConstrained

Deliverable, but do not buy it as regulatory readiness. The Digital Omnibus, in force 27 July 2026, deferred Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028. Only Article 50 transparency and Article 4 AI literacy are live.

We will tell you that rather than sell against a deadline that has moved. If you ship a product with digital elements into the EU, the Cyber Resilience Act reporting clock from 11 September 2026 is the real and nearer obligation.

UAE & GCCDeliverable

The sharpest regulatory hook for this service anywhere in the world. The DIFC's June 2026 consultation proposes embedding AI safety into processing systems, certification obligations, and an Autonomous Systems Officer role — nobody else is being asked this yet.

We do not certify ISO 42001 and cannot; only an accredited certification body can. Our output is an evidence pack that answers procurement questions, not a certificate.

Every market position we hold, with the legal reason and the transfer mechanism, is on where we work.

Right fit?

Choose this if...

You shipped an agent or RAG system and an enterprise buyer has sent an AI questionnaire
The agent was built by someone other than withRemote
You can name an asset owner with authority to authorise testing
You want the fixes shipped, not just enumerated
Right fit?

Honest about who this is for.

Pick us if

This will be a fit.

  • You have a production agent with real tool access and real data behind it
  • Your enterprise deal is blocked on an AI governance section you cannot answer
  • You want remediation as pull requests against your codebase
  • You want a regression suite so the finding does not come back next quarter
Skip us if

Honestly — not our zone.

  • You want an independent audit, attestation or certification — this is an engineering review and we certify nothing
  • You want ISO 42001 certified or an EU AI Act conformity assessment. Only an accredited body can do the first; we do neither
  • withRemote built the agent. We do not review our own work — our build clients get the Secure Build tier instead
  • You want production testing without signed Rules of Engagement and an authorisation letter. We will not proceed without them
FAQ

Common questions, straight answers.

When can we start?

Scoping calls are open now. Adversarial testing engagements begin once our specific insurance endorsement covering security testing and adversarial evaluation is bound — we will tell you the date on the call rather than book you against a maybe. Threat-modelling and governance-evidence work is unaffected and can start immediately.

Do you review agents you built yourselves?

No. Independence from the build team is explicit in current practice and sophisticated buyers check for it. If we built your agent, you get the Secure Build tier — the same hardening delivered as engineering, with independent review commissioned from a third party we will help you scope.

Is this an audit or a certification?

Neither. It is an architecture and remediation review. We do not issue an independent audit, attestation or certificate, and we do not certify any system as secure. We do not certify ISO 42001 — only an accredited certification body can — and we do not perform EU AI Act conformity assessment.

Should we be buying EU AI Act readiness?

Not right now, and we would rather say so. The Digital Omnibus that entered into force on 27 July 2026 deferred the Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028. Only the Article 50 transparency duties are live. Anyone selling you a programme against an August 2026 deadline is working from stale material.

What actually drives this budget then?

Procurement, and incidents. The 2026 SIG update added an expanded AI governance section, CAIQ now names ISO 42001 and NIST AI RMF, and the July 2026 agent sandbox escape and Hugging Face breach put agent security in front of boards. Your buyer's questionnaire is the compelling event, not a regulator.

Do you test against production?

Only with signed Rules of Engagement and a countersigned authorisation letter from a verified asset owner, plus third-party authorisation where the systems sit on AWS or Azure. Default scope is staging and non-destructive. Without that paperwork, testing is an offence regardless of intent, and we will not do it.

From $18,000· Answer the AI questionnaire, fix what it exposes

Ready to start?

Book a free 30-minute call. We'll scope the work, share examples, and send a plan within a week.

Related

More from this category

Compliance Readiness Assessment
The honest gap list, costed in engineer-days
Compliance Remediation Pod
Keep your Vanta. Keep your auditor. We ship the fixes.
Cyber Essentials Readiness (UK)
Pass Danzell first time, or find out why now