Proof of work

What we were brought in to test.

What we found, and what changed afterwards. Published by sector, never by name.

  1. Regulated consumer lending · AI voice assistant

    Confirmed

    The guardrail held. The name field didn't.

    Asked directly, the agent refused to reveal its instructions — correctly, every time. The same request placed in the caller's name field got the system prompt, the tool inventory and the model identity read aloud. No credentials, any origin, an ordinary browser.

    CVSS 8.1 0 credentials 4 med-high+ Voice · tokens · LLM

    Read the case study →

  2. B2B sales-intelligence SaaS · multi-tenant

    Confirmed

    They had been pentested. The AI had not.

    RAG pipelines, a multi-agent orchestrator and sequential-ID data APIs. Conventional pentests had already been run. Nothing had treated the AI itself as the attack surface — and six criticals were reachable from a free trial seat.

    6 criticals 18 confirmed 95 reports reachable RAG · agents · AWS

    Read the case study →

  3. AI-native LMS platform · SaaS

    Confirmed

    Tested, documented, still stuck.

    The GRC programme was active and an established vendor had already run the security testing. The deals were still stalling — because nothing anyone had tested went near the MCP server.

    28 findings 3 critical Two months Azure · MCP · LLMs

    Read the case study →

Watch it happen

One request. Then ninety-five customers.

DATA-01 replayed at the speed it actually ran — request, fan-out, and what survived the revoke. Every frame is a request we made and recorded.

22 seconds

Client feedback

  • Then Manish and his team started working with us. Within weeks, the picture changed completely.

    CEO · AI-native LMS SaaS platform
  • The team went beyond surface-level scans and uncovered vulnerabilities that had been sitting in our system for months.

    CEO · AI-native LMS SaaS platform
  • First-principles thinking — not just throwing an LLM over the requirement.

    Head of Security · AI-native LMS SaaS platform
  • Every finding came with clear proof, severity mapping to OWASP and LLM-specific threat models, and actionable fixes prioritised by impact.

    Head of Security · AI-native LMS SaaS platform

Six engagements completed. Every finding above was reproduced on a second run before it was written down.

Two people, one engagement · read the case study Reference available on request.

Every case study here is published under written authorization and anonymised to sector and system type. No client is named. No client data is redistributed. References available on request.