Service Line A · AI Build

AI products and agents, built with security in from the start.

We design and build custom AI capabilities that you run in your own environment. Every build is threat-modelled before we start and security-tested before we hand it over.

What we build

AI that does a defined job, within agreed boundaries.

01

Agents

Agents for defined organisational workflows, with the tools, permissions and controls agreed for the use case.

02

Assistants

Assistants for your teams or your customers, with guardrails on what goes in and what comes out.

03

Retrieval systems

AI that answers from your own documents and data, with access control respected in what it retrieves.

04

Workflow automation

Multi-step work such as document processing, automated with clear points for human review.

Who it is for

For organisations with a use case, but not the team to build it safely.

And for vendors who need a build partner that treats security as part of delivery, not an extra.

A working product
Deployed in your environment and accepted against criteria agreed at the start.
Documentation and a system card
A plain statement of what the system does, what it cannot do, and its known limits.
An internal QA security report
Our pre-delivery security test, included in every build and clearly labelled as internal QA. It is never presented as independent assurance.
Optional support
Maintenance and periodic re-testing under a support agreement, so the system stays sound as models and usage change.

How a build runs

Nine steps. Security is a gate, not an afterthought.

You see the design, the model choice and the running costs before you commit. Three steps cannot be passed without a signature.

Gate requires a signature to proceed.

  1. Shape01
    DiscoveryYour problem, environment, data and users. An honest decision on whether we can do it well.
  2. 02
    Solution designArchitecture, model choice, a realistic usage and running-cost estimate, and a data-handling plan, shown to you before you commit.
  3. 03
    Proposal and SOWScope, deliverables, timeline, price and acceptance criteria, with a shared-responsibility matrix.
    GateSigned SOW
  4. Build04
    PrototypeSomething early, so you can redirect us before we build deep.
  5. 05
    Build in sprintsSecure by design, from a threat model, with regular demos.
  6. Assure06
    Security testOur internal quality gate before handover. Labelled internal QA, never independent assurance.
    GateInternal QA report
  7. Deliver07
    AcceptanceYou test against the agreed criteria and sign off.
    GateClient sign-off
  8. 08
    HandoverDeployed in your environment, with documentation and a system card stating known limits.
  9. 09
    SupportOptional maintenance and periodic re-testing under a support agreement.

What we need from you

A short list, agreed up front.

An environment
A development or staging environment, or scoped access to one.
Data
Sample or anonymised data that represents the real thing.
Context
The business problem, the users, and what success looks like.
Named contacts
People who can make decisions and sign off at each gate.

What we will say plainly

AI outputs are probabilistic. No build is immune to every jailbreak, prompt injection or hallucination. Human oversight of outputs stays with you. We document these limits in the system card rather than leaving them unsaid.

Who owns what

We own the design we build: agent logic, guardrails and the controls we implement. You own your environment: connected data, access, configuration and monitoring. It is all written into a shared-responsibility matrix before work starts.

See the matrix

Want independent sign-off on something we built?

We will not give it ourselves. Independent assurance on our own work goes to another firm. That is the rule that keeps our testing honest.

Why we work this way

Ways to start

Start small, with a clear outcome.

Every engagement starts with a conversation about your needs and a scope agreed in writing. Each of these is a natural first step: narrow, concrete, and easy to approve.

Before a full build

Discovery and prototype

Your use case, data and users; a solution design with model choice and running-cost estimate; and an early prototype you can react to.

Time
A short, defined phase, so you can decide on the full build with evidence, not promises.
You receive
Design note with a running-cost estimate for the system, and a working prototype.
Ask about this

After the first engagement

Ongoing assurance and support

Periodic re-testing as your system or its model changes, and maintenance for systems we built.

Time
Ongoing, on a schedule that matches how often your system changes.
You receive
Retest letters and an up-to-date view of residual risk.
Ask about this

FAQ

Questions we are often asked.

Something else on your mind? Ask us directly.

How soon will we see something working?

Early. A prototype comes before the deep build, so you can redirect us while changes are still cheap, and you see regular demos throughout.

Will you certify the system you build for us as secure?

No. We security-test everything we build before handover, and that report is clearly labelled internal QA. Independent sign-off on our own work has to come from another firm, and we will help you arrange it.

Where does our data go during the build?

The data-handling plan is part of the solution design you see before you commit. We work with sample or anonymised data where possible, act as a data processor, and sign a data-processing agreement in line with the UAE PDPL.

Can you work with our cloud and model provider?

Yes. The system runs in your environment, and model choice is part of the design stage, where we explain the trade-offs and realistic running costs before you commit.

What happens after handover?

You receive documentation and a system card that states the known limits. Optional support covers maintenance and periodic re-testing. If something breaks, the signed shared-responsibility matrix decides who fixes which layer.

Is any AI system immune to prompt injection or jailbreaks?

No, and we will not claim otherwise. AI outputs are probabilistic. We design and test to reduce the risk, document what remains, and keep human oversight with you.

Next step

Have a use case in mind?

Tell us the problem, the users and the data involved. We will tell you honestly whether we can build it well, and what it would take.

Talk to us

A scoping conversation first. Nothing starts until scope and limits are agreed in writing.