AI Security · Cybersecurity · Information Security · AI Governance

Security and governance
for the AI era.

An AI security lab building grounded, verifiable tooling - threat models, risk analysis, and governance that run where your data lives.

$
scroll ↓
STRIDE threat modellingMITRE ATT&CK mappingOWASP LLM Top 10prompt-injection defenceagentic & MCP securityadversarial testinglocal-first inference · zero egressEU AI Act governance STRIDE threat modellingMITRE ATT&CK mappingOWASP LLM Top 10prompt-injection defenceagentic & MCP securityadversarial testinglocal-first inference · zero egressEU AI Act governance
01 - What the lab does

AI, pointed at the hard parts of security.

Not chatbots bolted onto dashboards. Purpose-built agents that reason about threats, ground every finding in real frameworks, and refuse to invent what they can't verify.

[ TM ]

Threat Modelling

Describe a system in plain English; get a STRIDE data-flow diagram, findings mapped to ATT&CK / CWE / OWASP, and residual risk scored against the controls actually in place.

[ AI ]

AI / LLM Security

Adversarial testing, prompt-injection defence, and agentic / MCP threat assessment - the attack surface that appears the moment a model gets tools.

[ CR ]

Cyber Risk

Risk analysis grounded in regulated-finance reality, where a control failure is measured in findings, not just tickets.

[ GV ]

AI Governance

EU AI Act classification, ISO 42001, NIST AI RMF - turning framework text into decisions an organisation can actually act on.

[ TI ]

Threat Intelligence

CTI agents that pull, verify, and reason over advisory feeds - with the indirect-injection paths that come with them already closed.

[ LC ]

Local-First

The map of an organisation's weaknesses never leaves its machine. Runs on local inference - offline, air-gappable, defensible.

02 - Selected work

Shipped, not slideware.

Public repositories and demonstrations - real agents, security-assessed and CI-gated.

03 - The stack

Frameworks in, grounded findings out.

Every agent is built on the same discipline: deterministic rules decide the security logic, the model only writes the prose, and a verification pass checks nothing was invented.

STRIDEMITRE ATT&CKMITRE ATLASCWEOWASP Top 10OWASP LLM Top 10NIST AI RMFISO/IEC 42001EU AI ActOllama · local LLMPythonverification pipeline
04 - Who's behind it

Built by a practitioner.

~/whoami

Narendra Karki - 25+ years on the defending side of security in regulated financial services across the GCC and UK. Security architecture, cyber risk, and the governance that keeps both accountable.

The lab is where that experience meets AI: tooling held to the same standard as the environments it came from - grounded, verifiable, and honest about its limits.

CISSPCISMCISACAISPCMCPSE