
FAQ
Clear answers before the work starts.
The practical details: how we work, what we cover, and what to expect.
01
About & how we work
Who we are, who you'll work with, and how we run an engagement.

Red Vault is a UK cybersecurity consultancy with a dedicated AI-security specialism - REDVAULT LTD, Company No. 17184267, incorporated 27 April 2026 and registered at 23 Limeharbour, London E14 9TS. The company is new; the people are not. We started it because client teams are wiring LLMs and agents into production far faster than their controls can follow, and we wanted to do that work without the overheads of a large firm. We pair hands-on security engineering with offensive testing, and we are small enough that the person who scopes your engagement is the person who does it.
Operators, not a sales bench that hands you to juniors. Engagements are led by the senior practitioners who do the work - the people who threat-model your systems, red-team your AI, and break into your applications. You get engineering-grade findings with fixes your team can land this sprint, not a slide deck and a severity label.
Both. We're a remote-first UK team and most assessment, testing, and response work is delivered remotely with scoped, secure access to the systems in question. Where an engagement genuinely needs people in the room - a workshop, a sensitive incident, an on-prem deployment - we travel. Engagement data stays in the UK by default, with the EU available on request.
With a scoping conversation - no NDA required to talk, and no discovery fee. We map what you're trying to protect, agree the outcomes, and come back with a scope and timeline. If you are unsure where to start, a cybersecurity assessment reviews your current policies, systems and controls, then sets out practical next steps. Its scope, timing and price are agreed before work begins. Start at contact@redvault.co.uk or via the contact page.
02
Services & AgentShield
What we do across cyber and AI security - and where AgentShield fits.

Six, delivered by the same operators end to end: cybersecurity assessment; penetration testing across web, API, network, cloud, and mobile; incident response; compliance & regulations (GDPR, DORA, NIS2, PCI-DSS, ISO 27001, SOC 2); AI security mapped to the OWASP LLM Top 10; and identity & access security covering IAM, PAM, MFA, and ITDR. If you are unsure where to start, our assessment reviews your current security and sets out a prioritised plan. You can act on it with your own team or chosen provider, or discuss separately scoped and priced follow-up work with Red Vault.
It's the architecture your AI actually runs inside. We inventory every model, agent, and copilot in use - sanctioned and shadow - and what each can reach, write each agent's job contract, and design the guardrails around it: an enforcement point on every tool call, least-privilege tool scopes, and a human in the loop for the actions that matter. Then we build it with your engineers on the platform you already run, and red-team it to prove it holds.
You own the architecture when it is done, plus an EU AI Act and ISO/IEC 42001 evidence map that it produces as it runs, so governance is a by-product of the work rather than a second project.
AgentShield is our AI-agent visibility product in development. It connects known-tool identification, observed behaviour and network evidence to help your team understand AI adoption and investigate changes. Core analysis runs locally. Optional remote model-assisted analysis is off by default and has separate data-handling considerations.
AgentShield is coming soon: macOS is the first platform, Linux is the next priority and Windows is also planned. The current engine does not block actions; policy-based endpoint controls remain in development. Register your interest on the product page for availability announcements and future evaluation discussions.
No. Our AI & LLM Security service is vendor-neutral. We design and build guardrails with your engineers on the platform you already run. AgentShield is a separate product in development; a future evaluation is optional and would be considered only where endpoint visibility of AI agents fits your needs.
Availability, response targets and the activation route are agreed in writing. Existing clients should use the route in their response agreement. New enquiries are subject to confirmed availability and scope; a website form or email does not activate incident response. If you need immediate assistance without an agreement, use your appointed responder or insurer’s incident channel.
03
Security & compliance
How we handle your data, where we stand on our own certifications, and the frameworks we map you to.

None yet, and we would rather say so than imply otherwise. Red Vault Ltd was incorporated in April 2026; ISO/IEC 27001 and Cyber Essentials are certifications we intend to hold, not ones we can show you a certificate for today.
What we can evidence now is how we work: engagement data stays in the UK by default, access is least-privilege and time-boxed, and we work to your data-handling rules under an NDA and a DPA. If your procurement process needs a supplier with a current certificate, tell us early and we'll tell you straight whether we clear your bar.
On a need-to-know basis, least privilege, and time-boxed access. Engagement data is stored in the UK by default - EU on request - and we don't move it outside the agreed jurisdiction without written consent. We work to your data-handling rules, sign your DPA where reasonable, and return or securely delete the data on completion. Data-protection queries go to contact@redvault.co.uk.
GDPR, DORA, NIS2, PCI-DSS, ISO 27001, and SOC 2 on the cyber side, plus the EU AI Act and ISO/IEC 42001 for AI governance. We map your controls to the obligations that actually apply, pre-stage the evidence auditors expect, and tell you where you're in scope - and where you're not - before you spend on compliance you don't need.
Yes. For DORA we work the ICT risk-management, incident-reporting, and resilience-testing requirements that reach UK firms serving EU financial entities; for NIS2 we help in-scope operators meet the tightened risk-management and reporting duties. Both lean on the same foundations - asset inventory, tested response, and evidence that the controls work - which is exactly where our testing and assessment work line up.
Yes. We factor crypto-agility and post-quantum readiness into assessments where it matters - inventorying where you rely on at-risk public-key cryptography and planning migration to the new NIST post-quantum standards - so long-lived data and certificates don't become a problem you discover too late. Paired with ITDR, it's part of keeping identity and encryption resilient over the next few years.
04
Commercials & contracts
How we price, contract, and start - and how we treat your data.

Two models. Fixed-scope projects - assessments, penetration tests, incident-response readiness - are quoted as a fixed fee against an agreed scope and timeline, so there are no surprises. Ongoing service work, such as compliance support or identity programmes, is scoped and priced for your environment. AgentShield is in development; product availability and commercial terms will be announced separately. Get in touch for a tailored service quote.
We work under a master services agreement with a statement of work per engagement, and we're happy to operate on your paper or ours. Where personal or regulated data is involved we put a data-processing agreement in place - we'll sign yours where reasonable - alongside an NDA before anything sensitive changes hands.
Fixed-scope projects are exactly that - no ongoing tie-in once the work is delivered. Retainers are typically agreed on a rolling term so you can scale cover up or down as your risk changes. We'd rather earn the renewal than lock you in, so terms stay deliberately straightforward.
Email contact@redvault.co.uk or use the contact page and we'll set up a scoping call - no NDA to talk, no discovery fee. Tell us what you're trying to protect, or what's gone wrong, and we'll come back with a scope, a timeline, and a fixed price. For anything urgent or already live, flag it as such and we'll fast-track the response.
still have a question
Ask us the one that isn't here.
Tell us what you would like to know about our services, your project or AgentShield.
contact@redvault.co.uk