Building or shipping

Build security into your product and AI features before they ship

Product & AI Security reviews your architecture, data flows, access model and AI use, so you find and fix the risks that matter while they’re still cheap to fix, not after launch.

See review packages ➜
Product & AI Security Service Detail

WHEN YOU NEED THIS

Is Product & AI Security right for you?

If one or more of these apply to your situation, our Product & AI Security service is worth a closer look:

  • You're about to launch a new product, major feature, or AI capability and want it reviewed before it ships
  • You're adding AI or agent-based functionality and aren't sure what could go wrong
  • An enterprise customer or investor has asked about your architecture, data handling or AI security
  • You're preparing for a penetration test and want to fix the obvious issues first
  • Your product has grown quickly and nobody has stepped back to look at the security architecture as a whole

HOW IT WORKS

From scoping call to delivered roadmap

1

Scoping call

We learn about your product, architecture and AI use, and agree the right level of review.

2

Review

We assess architecture, data flows, access model, and AI/agent security where relevant.

3

Threat modelling

We identify the risks that actually matter for your product and users.

4

Roadmap & handover

You get a prioritised remediation roadmap and a walkthrough of the findings with your team.

TYPICAL OUTCOMES

What you walk away with

  • A clear picture of your product's real security risks, not a generic checklist
  • A prioritised roadmap your engineering team can actually act on
  • Documented AI/agent security considerations you can show customers and investors
  • Readiness for a penetration test or wider security assurance process

SERVICE PACKAGES & PRICING

Product & AI Security Packages

Focused Review

£5,000-£7,500
2-3 weeks
Best for

Early-stage startups launching a product, adding a major feature or introducing AI.

For a single product, feature, architecture change or defined AI use case.
What you get
  • Architecture, data-flow and access-model review
  • Targeted threat modelling
  • Secure-by-design recommendations
  • Review of key third-party integrations
  • Prioritised remediation roadmap

Advanced Product & AI Review

£12,000-£20,000+
4-6 weeks
Best for

AI-native, regulated or higher-risk digital products.

For complex, regulated, multi-product or agentic AI environments.
What you get
  • Everything in Product & AI Review
  • Agent permissions, tools and autonomous-action controls
  • RAG, knowledge-source and sensitive-data security
  • AI and software supply-chain risks
  • Cross-product trust boundaries and architecture
  • Abuse-case and adversarial threat modelling
  • Regulatory and customer security considerations
  • Workshops with engineering, product and leadership teams

SCOPE

What's not included

  • Hands-on engineering or remediation — We identify and prioritise the fixes; your team implements them.
  • Penetration testing or vulnerability scanning — These can be commissioned separately, and this review sets you up to get more value from one.
  • Source-code security review — This is an architecture and design-level review, not a line-by-line code audit.
  • Ongoing ownership of the security programme — For ongoing oversight beyond this engagement, see Security Leadership.

FOUNDERS ASK US

Product & AI Security FAQs

Can you help us understand whether the EU AI Act, EU Cyber Resilience Act or NIS-2 apply to us?

Yes. Most founders do not know these apply to them until an investor or customer raises it. If you have EU customers or EU users, the EU AI Act and Cyber Resilience Act can apply regardless of Brexit, with fines up to €35M or 7% of global turnover for the EU AI Act. NIS-2 mainly affects essential and important-sector operators and their suppliers, so it is less common at early stage but worth checking if you sell into those supply chains. Commercial Readiness includes a plain-English regulatory map specific to your product and market.


Do you test the AI models themselves, or just how we use them?

We review how AI and agents are integrated into your product, permissions, data flows, prompts, third-party AI services, and where things could go wrong, rather than testing the underlying model itself, which is usually the responsibility of the model provider.


We're not using AI yet. Is this still relevant?

Yes. The Focused Review works just as well for a standard SaaS product, covering architecture, data flows and access model. AI-specific review is only included where it's relevant to what you're building.


How is this different from a penetration test?

A penetration test tries to break what you've built. This review happens earlier, at the architecture and design level, so you fix structural issues before they become expensive, and arrive at a penetration test with fewer, cheaper findings.


Book a Discovery Call.

30 minutes, no obligation. We will talk through where you are, what is coming up, and what would actually help at your stage.

Book a discovery call