
Enable
AI & LLM Security.
Put AI into production without losing control of it.
Use AI with a clear view of the risks.
Red Vault is an AI security consultancy that helps protect the data, systems and decisions connected to your AI. We help your team understand what an assistant can access, what it can do and where a person needs to stay in control.
This can include reviewing an existing setup, designing security controls and helping integrate them with your engineers. We focus on the AI workflows and connections agreed in your proposal.
LLM security assessment
Review an agreed LLM application, its data flows, identities, tools and approval boundaries before access expands.
MCP security review
Examine the agreed Model Context Protocol servers, credentials, tool permissions and trust boundaries around connected data and actions.
AI agent security
Define the tasks, access and human approvals for the agents in scope, then help your engineers implement and validate the agreed controls.
Prompt injection testing
Test agreed misuse scenarios, including untrusted instructions in messages and retrieved content, and record the remaining risks and fixes.
How we help in real business situations.
Choose a scenario to explore the work and an example access boundary. These are illustrative scopes, not client case studies.
Choose your AI use case
An assistant that helps customers without overstepping.
Your assistant answers questions using account information and may raise requests or take actions in connected business systems.
How we help
- Review customer identity checks, account separation and connected tools.
- Test how untrusted messages could influence responses or actions.
- Help configure limited permissions and approval for sensitive actions.
An example access boundary
- Within scope
- Read the signed-in customer’s permitted records.
- Needs approval
- Issue a refund or change an account.
- Outside scope
- Retrieve another customer’s information.
What this gives your team
A documented boundary between answering a question and taking a business action, with checks your engineers can maintain.
Useful answers from the right company information.
Your employees use retrieval-augmented generation (RAG) to search documents and get answers. The assistant needs to respect the permissions behind those sources.
How we help
- Map document sources, access rules and the retrieval process.
- Review how confidential content reaches prompts and model providers.
- Test cross-user data exposure and instructions hidden in retrieved content.
An example access boundary
- Within scope
- Search documents the employee is allowed to read.
- Needs approval
- Connect a new repository of sensitive records.
- Outside scope
- Use the assistant to bypass document permissions.
What this gives your team
A clearer design for access-aware retrieval and handling sensitive information, with evidence of the checks performed.
Productive agents with deliberate access to tools.
Your engineers connect coding agents to repositories, local files, command tools or MCP servers. Those connections can give an agent more access than its task requires.
How we help
- Inventory the agreed agents, MCP servers, credentials and tool connections.
- Review file, repository and execution permissions against each agent’s task.
- Help implement approval points and validate tool-misuse scenarios.
An example access boundary
- Within scope
- Read and edit files in the approved project.
- Needs approval
- Run a deployment or a sensitive command.
- Outside scope
- Read private credentials or unrelated business files.
What this gives your team
An agreed tool and access policy, practical integration guidance and test findings for the agent workflows in scope.
Know what has changed. Know what comes next.
A useful engagement connects the security recommendations to the AI your business actually uses. Your team receives the agreed design, implementation records and test evidence.
- An AI access and risk map
- The systems in scope, their owners, connected data and tools, and the ways misuse could affect your business.
- A control design and implementation record
- Agreed permissions, approval boundaries and data-handling controls, with the configuration or integration work included in your scope.
- Security test findings
- Reproducible examples where available, observed impact, recommended fixes and the status of any agreed rechecks. Test coverage and limitations stay explicit.
- An operating handover
- Control ownership, useful logs, change-review triggers and a prioritised list of remaining work for your team.
From your use case to tested controls.
Start with a defined workflow and the people responsible for it. We agree the depth of review, implementation support and validation before work begins.
Understand and define
Map the agreed AI systems, data flows, identities and tools. Agree the intended tasks, permitted access and actions that need human approval.
Design and integrate
Translate those boundaries into practical application, identity and platform controls. Work with your engineers on the agreed changes and document how they operate.
Test and hand over
Exercise the agreed abuse scenarios, record findings and review fixes. Walk your team through the controls, remaining risks and checks to repeat as the system changes.
Grounded in established guidance.
We use relevant OWASP and NCSC guidance to shape the review and test cases around your systems.
Before you book.
Can you help if we are only starting to use AI?
Yes. Start with the intended tasks, the information involved and the systems you want to connect. We can help define a sensible initial scope and access boundaries before implementation. If you need a wider review of your organisation’s security first, a Cybersecurity Assessment may be the better starting point.
Do you review chatbots, RAG applications and autonomous agents?
We scope work around the application and its connections. This can include customer chatbots, assistants that retrieve company documents, and agents that call APIs or use tools. We agree the models, integrations, user roles and environments covered; a review of one workflow is not a review of every AI system in the business.
What does MCP security cover?
MCP, the Model Context Protocol, connects AI applications to tools and data. We review the agreed servers, tool permissions, credentials and trust boundaries, including how untrusted tool descriptions or results are handled. We help design access restrictions and approval checks using controls supported by your platform.
Can you guarantee that prompt injection or data leakage will be stopped?
No. We reduce exposure through restricted access, appropriate data handling, approval boundaries and testing. A prompt filter alone is not a complete control. The review records what was tested, remaining risks and changes that should trigger another check.
Do you build the controls or only provide a report?
We can review the design and help integrate agreed controls with your engineers on the platform you operate. The proposal distinguishes review, design, implementation and validation so it is clear what is included. Your team approves changes and remains responsible for operating the system.
Do you provide ongoing monitoring or a managed AI-security service?
This is project work: we design, help integrate and validate controls with your team, then hand them over. Day-to-day monitoring and operation need an owner in your organisation or a separately appointed provider. We help document those responsibilities.
Do we need AgentShield for the engagement?
No. We design and build guardrails with your engineers using your existing environment. AgentShield is a separate AI-agent visibility product in development, coming soon. Its current engine does not block actions; policy enforcement remains in development. Any future evaluation would be optional and agreed separately, based on the capabilities and platform support available at that time.
Can you help with AI governance and regulatory requirements?
We can prepare technical evidence about AI systems, risks, responsibilities, data handling and human oversight. The applicable legal obligations and certification scope should be confirmed with your legal or compliance advisers. This engagement does not certify compliance with the EU AI Act or ISO/IEC 42001; wider policy or audit-readiness work can be scoped separately.
How do you handle access, confidentiality and test data?
We agree access, confidentiality, storage location, retention and testing permissions before the review. Where practical, testing uses an isolated environment and synthetic or redacted data. Share a system outline and your main concerns first; credentials and sensitive records should use the agreed secure channel.
How long does it take, and how is it priced?
Scope depends on the workflows, user roles, data sources, tool connections and implementation work involved. We agree the deliverables, responsibilities, schedule and fee in a proposal. A focused review of one assistant is different from designing and integrating controls across several business systems.
Let’s look at the AI you want to secure.
Tell us what your assistant or agent does, what it can access and where you need help. We’ll define a practical starting point with you.
contact@redvault.co.uk