Focus
App + process
Product features and how engineers use AI
AI security · LLM apps · Data governance
I review how your product and engineering workflows use AI — prompts, data flows, API keys, RAG pipelines, and user-facing features — so you ship innovation without preventable leaks or compliance surprises.

AI features introduce new attack surfaces: prompt injection, over-permissive tool use, training data in logs, customer PII in embeddings, and API keys in repos or browser bundles.
I audit AI projects with a builder’s mindset — I run production AI monitoring (Observinio) and ship LLM-integrated products — so findings are specific and fixable, not generic security theater.
Coverage includes application architecture, third-party model usage, vibe coding risks in your repo, and policies your team can actually follow.
Focus
App + process
Product features and how engineers use AI
Standards
OWASP LLM
Mapped to practical mitigations
Output
Risk register
Severity, owner, and remediation steps
User inputs, tool calling, file uploads, and admin surfaces that can be abused.
What leaves your boundary, what providers log, and minimization opportunities.
API keys, MCP servers, dependencies, and CI/CD exposure from AI tooling.
Policies, logging, red-team scenarios, and incident response hooks.
Relative frequency in audits of early-to-mid-stage AI products.
It is a focused AI security assessment, not a full pentest certification. I can partner with specialized firms if you need formal compliance attestation.
OpenAI, Anthropic, OpenRouter, RAG with vector DBs, agent frameworks, and custom MCP integrations — plus how your team uses Cursor or Claude Code on the codebase.
Yes. Implementation support for guardrails, logging, and secure architecture is available after the audit.
Pre-launch is often the cheapest time to fix data handling and permission models before real customer data flows through the system.
Describe your AI product, data sensitivity, and launch timeline. I will outline audit scope and deliverables.