AI

Your team is already using AI. The question is what it can reach.

Adoption is happening whether or not anyone approved it — and every tool your people paste work into is a decision about where your data goes. We inventory it, govern it, secure it, and keep it inside the boundary you already defend, including running the assistants, models, and agents you choose inside your own accredited environment.

Our AI never touches your CUI. When we enable AI, it runs in your environment under your controls — we build and govern it, you run it.

The problem

There are two ways to get this wrong.

The first is letting it run unmanaged — nobody approved it, everybody’s using it, and no one can say what it touched. The second is over-correcting: a policy so restrictive that your team either works around it or stops using AI altogether. One creates exposure. The other creates cost with nothing to show for it.

You can’t see it

Work gets pasted into whatever tab is open. Without an inventory, you don’t know which tools are in use, what they retain, or who agreed to their terms.

Locked down until useless

The overcorrection is just as costly. Block everything and your people use their phones instead, or they stop — and you’re paying for a tool nobody opens while competitors move faster. A control nobody can work with isn’t a control.

It’s a new attack surface

Assistants and agents hold credentials, read your files, and act on instructions. Prompt injection and over-scoped agents are software vulnerabilities — they just don’t look like the ones you’re used to.

Customers have started asking

Security questionnaires now ask how you use AI, whether their data trains a model, and what controls you have. “We’re not sure” is an answer with commercial consequences.

The target isn’t maximum restriction. It’s a sanctioned path that’s better than the unsanctioned one — fast enough that people prefer it, controlled enough that you can prove what happened.

How we approach it

Govern it. Secure it. Keep it worth using.

Three pieces of work that are usually sold separately and fail separately. A policy nobody enforces is theatre; controls nobody documented won’t survive a questionnaire. And a program your team routes around has failed no matter how tight it looks on paper — so we measure it by whether people are still using it in month six.

AI governance

Knowing what’s in use, deciding what’s allowed, and having a path to approve the rest.

Tool inventory Acceptable use Approval path Human oversight

AI security

Treating models, assistants, and agents as software with permissions — because that’s what they are.

OWASP LLM Top 10 MITRE ATLAS Agent and tool scoping Data boundary controls

AI compliance

Being able to show a customer, a prime, or an insurer how your AI use is controlled.

NIST AI RMF ISO/IEC 42001 Audit logging Questionnaire responses

Two things we’re precise about. NIST AI RMF and ISO/IEC 42001 are voluntary frameworks, not law — we align you to them because buyers increasingly expect it, and we don’t certify against either. And our own AI never touches your CUI: when we enable AI it runs inside your accredited environment, under your controls, not on Greypike systems.

What we run

From “what are people using?” to agents you can defend.

Most clients start with the inventory, because you can’t govern what you can’t see. Where you go after that depends on how much you want AI actually doing.

AI inventory and governance program

We find what’s actually in use, review the terms behind each tool, and write the policy, acceptable-use rules, and approval path that follow. An inventory first, a policy second — the other order produces a document nobody follows.

Per engagement, then ongoing

AI risk and threat assessment

We assess your AI use the way we’d assess any other system — prompt injection, over-scoped agents, data leakage, supply chain — against the OWASP LLM Top 10 and MITRE ATLAS, and tell you what’s worth fixing first.

Per engagement

The right AI, inside your boundary

We’re not tied to one vendor. Microsoft Copilot, Google Gemini, Claude, ChatGPT Enterprise, Azure OpenAI, Amazon Bedrock, or open-weight models running on your own infrastructure — we help you pick what actually fits the work, then deploy it in your tenant with the data boundary, retention, and access controls set.

Project, then ongoing

Data boundary and DLP controls

Classification, labelling, and loss-prevention rules that decide what AI can see in the first place. The most reliable AI control is the data it was never given access to.

Ongoing

Rollout, training, and adoption

A deployment nobody uses is a failed deployment. We train your people on what’s allowed and what it’s actually good at, then watch usage and loosen or tighten based on what we see — not on what felt safest on day one.

Ongoing

Custom agents for your workflows

When off-the-shelf assistants aren’t enough, we build agents scoped to a specific job — least-privilege access, logging, and a human in the loop where the decision matters.

Per project

NIST AI RMF and ISO 42001 alignment

The documentation, logging, and oversight evidence that lets you answer an AI question on a customer questionnaire with something other than a shrug.

Per engagement

Start here

Find out what your AI can actually reach.

Start with a scoping session. We’ll walk through what your team is already using, where that data is going, and what a sanctioned version would look like in your environment. No obligation.

Veteran-founded · Cyber AB RPA-led · Government contractors only