Global platforms
AI governance and security programs for products serving 100M+ users
Canadian AI governance + security
Evidence-led AI governance for organizations that need their systems to stand up to scrutiny, incident pressure, and board-level questions.
Paris 2024 Olympics & Paralympics security
iPhone launch security architecture
Microsoft Trustworthy Computing
What we look for
Generic AI sites sell certainty. Real AI governance has to expose the awkward parts: unclear ownership, brittle vendors, missing logs, untested controls, and promises no one can prove.
Surface claim
A tool inventory
Evidence needed
Which workflows depend on AI, who owns them, where data moves, and what evidence proves the control works.
Surface claim
A policy PDF
Evidence needed
Decision rights, escalation paths, exception handling, vendor obligations, and board-ready reporting cadence.
Surface claim
A model assessment
Evidence needed
Threat paths across prompts, retrieval, agents, identity, monitoring, logging, and operational recovery.
Signal is what the system says. Soil is the operating reality beneath it. We work where the two disagree.
Track record
The useful part of experience is pattern recognition: knowing which risks are real, which controls are performative, and what proof survives operational pressure.
Global platforms
AI governance and security programs for products serving 100M+ users
Telecom + mobile
Security design and implementation for the iPhone launch at AT&T
Microsoft
Trustworthy Computing, open source security assessment, and customer-facing security
Major events
Cybersecurity for the Paris 2024 Olympics & Paralympics
Critical systems
E-voting, anonymization, internet backbone, and cloud infrastructure security
Standards used as tools, not wallpaper
Engagements
The site should feel different because the work is different: fewer decorative frameworks, more decision-grade artifacts your operators, auditors, and executives can use.
01
A fast, evidence-based read on where AI is already operating, what could fail, and what proof is missing.
Typical outputs
02
Turn policy into roles, rituals, decisions, exception handling, and reporting that can survive audit and change.
Typical outputs
03
Assess prompts, retrieval, agents, identity, monitoring, and data flows before attackers or auditors do.
Typical outputs
04
Connect AI risk to business impact, resilience planning, budget decisions, and the controls leaders already understand.
Typical outputs
Method
Governance fails when it starts as a slide deck. We start with the operating environment, then turn findings into repeatable controls.
01
Locate the AI systems, vendors, data paths, owners, and unspoken dependencies.
02
Test assumptions against security threats, failure modes, regulatory duties, and recovery pressure.
03
Define decisions, controls, monitoring, exceptions, and evidence that people can actually maintain.
04
Leave teams with artifacts, operating rhythms, and reporting they can run after the engagement.
Trust signals
AWS
Cloud control design
GCP
Data and platform risk
Azure
Enterprise identity and governance
Where this matters
AI governance gets real when a missed control affects citizens, patients, customers, infrastructure, or the board packet due next week.
01
Citizen-facing AI, public safety workflows, procurement scrutiny, and audit-ready accountability.
02
Model governance, third-party concentration, fraud systems, operational resilience, and regulator evidence.
03
Clinical decision support, privacy, safety review, incident response, and patient-impact escalation.
04
Critical infrastructure, predictive maintenance, OT/IT security boundaries, and continuity planning.
05
LLM features, agentic workflows, customer trust, platform security, and security review at product speed.
06
Knowledge automation, client confidentiality, workflow redesign, and defensible AI use policies.
Field notes
Practical notes on AI governance, security, incidents, and the parts of implementation that rarely fit into vendor diagrams.
The May 2026 Canvas breach exposed 275 million users across 8,800+ institutions. Here's what happened, immediate steps to take, and how to build long-term resilience.
Most organizations rush to deploy AI capabilities without governance frameworks. Here's why that's a costly mistake and how ISO 42001 provides a structured path forward.
A hands-on guide to the OWASP Top 10 risks for LLM applications, with real-world examples and mitigation strategies for each vulnerability category.
Start here
A useful first conversation starts with what is already in motion: the tools, vendors, pressure, incidents, audit asks, and executive questions that do not fit neatly in a slide deck.