Our own AI cyber security agents

Built in-house. Bounded by design. Signed by a person.

Consistency at speed comes from handing the repetitive work to agents we control. Ours are narrow on purpose: each one has a job, a boundary and a human gate. None of them can exploit a system, publish a finding, change a production control or attest to anything.

Scout

PILOT

External exposure reconnaissance

Runs the bounded External Exposure Snapshot: certificate and TLS posture, security headers, cookie flags, exposed services and version disclosure — read-only, rate-limited, only after the requester attests authorization. Produces a plain-language draft with confidence labels.

Human gate. A practitioner reviews every snapshot before it is sent and decides what, if anything, is a finding. Scout never exploits, never submits forms and never scans a target without attested authorization.

Triage

PILOT

Finding clustering and validation support

Normalizes and de-duplicates scanner and proxy output, clusters related observations, drafts reproduction steps and proposes CVSS vectors so the practitioner spends time validating rather than sorting.

Human gate. The practitioner validates exploitability, sets the final severity and decides what is reported. Triage proposes; it never publishes.

Warden

PILOT

WAF tuning assistant

Groups blocked and flagged requests by rule, host, route and matched field; drafts narrowly scoped exceptions with rationale, expiry and rollback; measures noise before and after a change; keeps the decision record.

Human gate. Every exception is approved by the practitioner and applied by the client through its own change process. Warden never touches a production control.

Scribe

LIVE

Report and attestation drafting

Turns validated evidence into finding sections, executive summaries, the fix-sprint record and the attestation letter from approved templates, with framework references and evidence hashes.

Human gate. The practitioner signs every report and letter. Scribe drafts from validated evidence only and cannot invent a finding.

Ledger

PLANNED

Compliance evidence mapper

Maps evidence to SOC 2, ISO 27001, CyberSecure Canada, O. Reg. 51/26 and Law 25 controls with framework version and gap flags; keeps the evidence register current between engagements.

Human gate. Interpretation, applicability and the final recommendation are the practitioner's. Ledger never attests.

Concierge

PILOT

Intake and scheduling

Answers from the public service information, qualifies fit, runs the conflict screen and offers tentative discovery slots. It does not accept evidence, credentials or incident details.

Human gate. A person confirms every booking and every commitment. Concierge cannot promise dates, prices or availability.

Statement of practice on AI

We use our own agents and, where it helps, commercial language models to draft, cluster, map and summarize. We publish which parts of an engagement they touch, and we keep them out of the parts that require judgment or accountability.

  • Validation is human. Exploitability, severity and what appears in a report are decided by the practitioner who signs it.
  • Production is yours. Agents draft changes; your team applies them through your change process, with a rollback recorded for every WAF exception.
  • Evidence stays in scope. Client evidence is not used to train any model. Snapshot and intake data are retained only as long as the engagement record needs them.
  • Every letter is signed. Attestation letters, engagement letters and reports carry a practitioner's signature and the evidence hashes the letter refers to.
  • We say when it is an agent. Drafts are labelled as drafts. Concierge identifies itself as an assistant and hands off to a person for any commitment.