[~] products

Test before launch.
Enforce at runtime.
Control AI at work.

Three modules that cover the AI security lifecycle. All are in early development. Design partners shape what ships first.

mod_01 guardrails in design
appguardllm
in  redact   2 secrets
ctx strip    1 injected instruction
out deny     send_email() — out of scope
log decision 7f3a written

Guardrails

A policy layer between your application and any LLM. It inspects prompts, retrieved content, tool calls, and responses before they reach users or systems.

  • Prompt-injection & jailbreak detection
  • PII and secret redaction, both directions
  • Tool-call allowlists and output policy
  • Audit log for every decision
mod_02 workplace-shield researching
endpoint · fin-laptop-07           policy
───────────────────────────────────────────
chrome      chat.ai-tool       coach
coding-agent  llm api          redact ×2
desktop-ai  personal acct      block
python3     llm api (new)      block
ide-copilot company tenant     allow
browser + endpoint · one policy, every process

Workplace AI Shield

Visibility and control over every way AI is used at work: a browser extension for AI chat tools, plus a lightweight agent on managed endpoints that sees any process talking to an LLM, from desktop AI apps and coding agents to CLI harnesses and local scripts.

  • Endpoint agent: per-process LLM traffic inspection
  • Browser extension for paste, upload, and chat
  • Secrets, source, and PII redacted before they leave
  • Shadow AI discovery and central policy
mod_03 redteam-lab planned
$ redteam run --target staging --suite owasp
PASS llm01/direct-basic        24/24
FAIL llm01/indirect-email-html 21/24
PASS llm07/prompt-extraction  16/16
WARN llm06/tool-abuse         11/12
──────────────────────────────────
score 94.7%  Δ +3.1 vs v1.8

Red Team Lab

Adversarial testing for LLM apps and agents, for authorised use in controlled environments. Repeatable attack suites, mapped to OWASP, run on every release.

  • Injection & jailbreak suites
  • Agent and tool-abuse scenarios
  • Mapped to OWASP LLM Top 10
  • Regression tracking across releases

[~] coverage map

Mapped to the OWASP LLM Top 10.

LLM01 Prompt Injection GSR
LLM02 Sensitive Info Disclosure GSR
LLM03 Supply Chain GSR
LLM04 Data & Model Poisoning GSR
LLM05 Improper Output Handling GSR
LLM06 Excessive Agency GSR
LLM07 System Prompt Leakage GSR
LLM08 Vector & Embedding Weaknesses GSR
LLM09 Misinformation GSR
LLM10 Unbounded Consumption GSR

Planned coverage, based on the OWASP Top 10 for LLM Applications 2025.

> design_partner.apply()

Shape what we build.

We work with security and platform teams who run LLM features in production.