Independent security engineeringEurope based · US LLC

Security at the
point of action.

An AI agent can read, decide and act.
We help you define where its authority ends, test the boundary and build the controls.

Discuss your system ↗
AI applications, agent workflows, APIs and cloud infrastructure.
Explore an execution boundary

Allowed. The request stays within its declared permissions.

Interactive illustration. No live agent or tool execution.
01 / Assess the exposure02 / Implement the controls03 / Verify the result
01 / Engagements

A defined problem.
A practical deliverable.

Assessment / AI

AI application & agent security

For teams connecting models to business data, APIs and tools. Review trust boundaries and test prompt injection, data access, tool permissions and approval behaviour within an agreed scope.

You receiveReproducible findings, a prioritised remediation plan, an engineering walkthrough and an agreed retest.

Explore the engagement

Example assessment scope

One AI application, its retrieval sources and connected tools. Agree the test environment, accounts and permitted actions before testing.

Illustrative starting point

A support agent that retrieves customer records and can update tickets.

Find your starting point ↗
Implementation / AI

Secure AI adoption

Take one useful workflow from idea to a bounded pilot. Define the data access, tool permissions, human approvals and evaluation criteria, then implement and test the integration.

You receiveA scoped pilot, security and reliability evaluations, documented limitations and an operating handover.

Explore the engagement

Example pilot scope

One workflow with explicit data sources, tool permissions, approval points and success criteria. Start in a controlled environment before expanding access.

Illustrative starting point

An internal assistant that prepares a draft report and waits for approval before publishing.

Find your starting point ↗
Engineering / AppSec

API & cloud security

Review API authorization, Azure infrastructure and delivery controls. Work with your engineers to investigate findings, implement fixes and add checks to the release process.

You receiveValidated findings, practical control changes and verification evidence. Project work or an agreed ongoing allocation.

Explore the engagement

Example engineering scope

One API or cloud workload. Review authorization, identities, deployment configuration and the controls protecting its data and operations.

Illustrative starting point

A multi-tenant API where each customer must only access its own records.

Find your starting point ↗
02 / A boundary, made concrete

The model asks.
The control decides.

A convincing instruction is not permission. Choose a request to see how this simplified illustration checks a tool call against a declared file-access grant.

Illustrative interaction only. No agent runs and no files are accessed.

CALL RECORD / ILLUSTRATION
REQUESTED ACTION
files.read → notes/project.md
DECLARED GRANT
files.read → notes/**
CONTROL CHECK
The resource is inside the permitted scope.
ALLOWED / proceed to tool
03 / Independent engineering

Inspect the thinking.
Read the code.

Python / Alpha

Legion

An execution-control runtime for agent tool calls. Scoped grants, call-bound approvals, narrowing delegation and recovery designed around uncertain effects.

Explore the repository ↗
Go / Agent security

NIA

Credential-bound agent identity, authorization, runtime monitoring and revocation. REST and MCP requests pass through a shared enforcement path.

Explore the repository ↗
Python + C# / Early development

Witness

Evidence-based triage of scanner findings in supported C#/.NET vulnerability classes. Deterministic checks preserve uncertainty when the evidence is insufficient.

Explore the repository ↗

Independent open-source projects. They demonstrate engineering work and are not presented as client deployments.

04 / Find a starting point

What are you
building?

Suggested first conversation

AI application & agent assessment

Start with the data and tools your system can reach. Review permissions, prompt injection exposure and actions that require human approval.

A defined test scope, reproducible findings and prioritised remediation.

Discuss this scope ↗This is a starting point. Final scope follows a conversation about your system.
05 / Start with the system

What are you
giving AI access to?

Tell us what you are building, what it can access and what you need to establish. We will discuss whether a scoped assessment or implementation engagement fits.

Founded by Bogdan Ticu, a security engineer working across AI, application and cloud security.

Remote delivery from Europe.
B2B contracting through Bitwise Defence LLC, New Mexico.