Security assurance · AI risk · Compliance

Security assurance for teams shipping AI in regulated industries.

AI red teaming, penetration testing, risk management and compliance — delivered by a practitioner who has spent fourteen years on both sides of the audit. Every finding is mapped to ISO 27001, ISO 27701, ISO 42001, NIST AI RMF, Malaysia’s PDPA and, for financial institutions, BNM RMiT, so it holds up when the regulator asks.

14+ yearsIndustry expertise
OSCP · CISA · CISMOffense + governance
ISO 42001AIMS Lead Auditor
MITRE ATLASAI threat coverage
Flagship · AI red teaming

We attack your AI the way adversaries will — then prove it's fixed.

Manual, adversarial testing of LLM features, agents with tool access and RAG pipelines. Not a script firing a thousand jailbreak prompts — targeted abuse cases built from how your product actually works.

01
Prompt injection & jailbreaksDirect, indirect and multi-turn — through user input, documents, email and web content the model reads.
02
Agent & tool misuseCan the agent be talked into a refund, an export or an email it was never authorised to make?
03
Data exfiltration & RAG poisoningCross-tenant leakage, embedding attacks and poisoned knowledge bases that persist for every user.
04
Mapped, fixed, retestedFindings tied to OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF and ISO 42001 — with one retest included.
airexguard — ai-redteam.log
Regulations, frameworks & standards we map findings to
0+
Years of industry expertise in security & compliance
0
Specialised service lines
0+
Industry certifications held
0
Frameworks & standards mapped
What we do

Nine specialised services. One accountable expert.

Scoped, fixed-fee engagements delivered by the same practitioner you speak to on the first call. Click any service to expand what's included.

Who we work with

From the first signal to a record you can defend.

Every engagement starts with a trigger inside your business. Select a service to see who typically calls, why, and what they walk away with.

Why AIRexGuard

Built by someone who has been on both sides of the audit.

Most firms either know the regulation or know how to break the system. AIRexGuard was built on doing both — inside a national digital identity provider, a high-volume payments platform, and the AI systems now embedded in them.

Regulator-facing, not just audit-ready

Direct experience answering central-bank, data-protection and enterprise-bank assurance questions — the ones that come after the certificate.

Offense and governance in one engagement

OSCP-level testing paired with CISA / CISM / CRISC depth — findings arrive with the fix, the risk rating and the control mapping.

AI security that is actually operational

ISO 42001 Lead Auditor plus hands-on GenAI guardrail engineering and MITRE ATLAS-aligned red teaming — a rare combination in the region.

Fixed scope, fixed fee, no retainers to start

Small engagements first. You know the deliverable and the price before we begin, and you can walk away afterwards.

How it works

From first call to signed-off report.

A structured engagement designed to fit around your release schedule, not stall it.

01

Scoping call

30 minutes to define assets, regulator and what "done" looks like.

02

Rules of engagement

Written scope, timelines and safe-testing boundaries agreed upfront.

03

Assessment

Manual testing, red teaming or gap analysis against the agreed scope.

04

Report & mapping

Findings ranked by business impact and mapped to your framework.

05

Walkthrough & retest

Live debrief with your team, then one included retest after fixes.

Credentials

Certified across offense, governance, cloud and AI.

Track record

Fourteen years inside regulated, fast-moving companies.

Digital identity

National Certification Authority & eKYC provider

End-to-end security and compliance for a licensed digital identity operator: central-bank technology risk requirements, ISO 27001, data protection, AWS security architecture, and the deepfake / presentation-attack defenses behind a bank-grade eKYC pipeline.

Payments

High-volume Southeast Asian payments platform

Built and scaled product and information security across three countries; owned security and compliance across card processing, merchant APIs and settlement infrastructure.

Enterprise

Global consulting & enterprise software

Secure SDLC, code review and penetration testing for telecom and enterprise software clients across the UK, India and Southeast Asia.

Sectors

Where a finding actually matters.

Fintech & PaymentsBNM RMiT for financial institutions, PDPA
Digital Identity & eKYCLiveness, PAD, deepfake defence
AI & GenAI ProductsISO 42001, NIST AI RMF, LLM red teaming
SaaS & PlatformsISO 27001, ISO 27701, PDPA, enterprise assurance
Government-linked & RegulatedAssurance reviews, policy, risk registers
Healthtech & InsurtechSensitive data, AI decisioning
Enquiry

Tell us what you're shipping.

Fill in the form, use the chat assistant in the corner, or message us directly on WhatsApp. Every enquiry is answered by the practitioner who will do the work — within one business day.

Get started

Tell us what you're shipping. We'll tell you what actually needs testing.

A 30-minute scoping call — no proposal decks, no sales cycle. If an engagement doesn't make sense yet, you'll hear that too.