Service ยท AI security
Secure AI Enablement
We design and deploy AI tools, agents and integrations with the security controls already in place. Identity, data boundaries, tool permissions, logging and DLP specified before rollout, not retrofitted after an assessment finds them missing.
Who it is for
Adoption is easy. Safe adoption is not.
Most organisations now have access to enterprise AI tooling. Few have configured it for their actual risk profile. Default admin settings retain too much, log too little, share too widely, and leave DLP disconnected.
This is for organisations about to deploy, or already deployed on defaults and wanting it done properly. We build the controls in during deployment, which is roughly an order of magnitude cheaper than adding them to a system already in production.
If the system is already live and you need to know whether it can be broken, that is the AI Offensive Security Review.
What we build in
Six control layers, specified before the tool is enabled at scale.
These are the controls that are cheap during deployment and expensive afterwards. Each one is defined as an objective first and configured second.
Identity and access for agents
Every agent gets its own identity, never a borrowed human account. Short-lived, least-privilege credentials, so an agent action is attributable and its blast radius is bounded.
Data boundaries
What the system may retrieve, for whom, and under what tenancy rules. Enforced at retrieval rather than at presentation, because presentation-layer filtering is not a control.
Tool permissions
Each tool exposed to a model is an API an attacker may reach through it. Scoped narrowly, with consequential actions behind human approval.
Logging and audit
Prompt, retrieval, tool call and output logged as privileged activity, exported where your detection can see it. Without this you cannot answer what an agent did.
DLP and classification
Sensitivity labels and data loss prevention wired into AI inputs and outputs, so the AI inherits controls the rest of the estate already has.
Vendor and model selection
Data residency, retention, training-use terms and contractual position assessed before deployment, not after an incident.
What changed in 2026
Two regulatory events moved AI from policy to proof.
Boards used to ask whether there was an AI policy. They now ask who has tested the AI and who is watching it.
Letter to industry on artificial intelligence
AI is not a separate regime. AI-enabled services must be managed under CPS 230 and CPS 234, and APRA expects continuous monitoring rather than a point-in-time audit.
Read the source ›Careful adoption of agentic AI services
Least privilege, a distinct identity per agent, continuous logging, red teaming through the lifecycle, and human approval for irreversible actions.
Read the source ›What we deploy
Tooling we configure to enterprise control standards.
Microsoft 365 Copilot
Tenant-level rollout, sensitivity label integration, Purview DLP scoping, audit log export to SIEM, restricted SharePoint indexing, retention configuration.
ChatGPT Enterprise and Team
Workspace setup, SSO and SCIM provisioning, retention policy, audit export, custom GPT governance, data residency confirmation, member role design.
Claude Enterprise and Team
Workspace configuration, SSO setup, project-level access controls, audit log integration, content filter calibration, role assignment.
GitHub Copilot Enterprise
Organisation-level policy, repository scope rules, public code filter, audit logs, content exclusion configuration, Copilot Workspace governance.
Google Workspace Gemini
Admin console hardening, data region controls, retention configuration, audit log surface, Vault integration where applicable.
Custom agents and workflows
Internal agent build using Claude, OpenAI or open-weight models. Prompt safety, output filtering, audit trail, human-in-the-loop checkpoints, and an evaluation harness.
Method
Controls first. Adoption second.
Every engagement defines the control objectives before the tool is enabled at scale. We do not enable, then assess. We assess, then enable.
01
Use case definition
Defined business outcomes per tool. We do not deploy AI for its own sake.
02
Control objectives
Per use case: data classification posture, retention, audit, identity, monitoring, exit conditions.
03
Configuration
Tenant or workspace configured to the control objectives. SSO, SCIM, DLP, retention, audit export.
04
Pilot
Bounded user group, monitored adoption, control evidence captured before scale.
05
Rollout and handover
Phased rollout with documented runbooks. Operational ownership transferred to internal teams.
What you get
Deliverables and investment.
- Configured tenant or workspace, hardened to agreed control objectives
- Agent identities with scoped, short-lived credentials
- Audit logging wired into your existing SIEM or log platform
- DLP and sensitivity labelling applied to AI inputs and outputs
- Acceptable use, prompt hygiene and training collateral
- Evaluation harness for custom agents, so behaviour is measurable
- Documented runbooks and handover to named internal owners
Investment
From AUD 8,000
Per tool. Admin hardening, DLP wiring, audit export, runbook documentation.
From AUD 15,000
Per custom agent. Production-ready with identity, control hooks, audit trail and evaluation harness.
Multi-tool rollouts with policy, training and pilot management are quoted per engagement, typically AUD 30,000 to 75,000.
Independence
We do not test what we built.
Build and review stay separate
If we deploy your AI system, we do not then review it and call that assurance. Where a client wants both, the review is run by an independent tester we bring in, or the build goes to a partner. Regulated buyers need that separation for the report to mean anything.
No reseller arrangements
We take no commissions on the tools we recommend. Vendor and model selection is tied to your control objectives and data position, not to a partner margin.
Handover is the deliverable
The engagement ends with your team owning the system, with documented runbooks. If you would rather keep the accountability external, that is the Fractional AI and Information Risk Officer role.
Get started
Deploy AI safely. Once.
A discovery call clarifies your tooling, your control posture, and the realistic shape of an enablement engagement.