AI Agent Security & Governance
Independent audits, red-teaming and EU AI Act readiness for AI agents running on ServiceNow. Building agents is becoming easy; proving they are safe is not.
What we do
Agent reach audit
What an agent can actually see, which tables and records it can reach, and where that exceeds what anyone intended.
Red-teaming
Prompt injection, data exfiltration through tool calls, and privilege escalation. We test the agent the way somebody hostile would.
Privacy leakage
What a sequence of ordinary-looking queries can reconstruct. Agents leak through what they are willing to answer, not only through what they store.
AI Control Tower
Deciding which services an agent may touch, and keeping an audit trail that survives a question from your DPO.
MCP Registry
Governing which MCP servers are trusted and what each may do — and building the servers on the other side of that registry.
EU AI Act readiness
Risk classification, technical documentation and monitoring for Annex III systems, due 2 December 2027.
An audit you buy from the vendor is not an audit
The platform shipping your agents cannot also be the party certifying them safe. We are independent of ServiceNow, and the person who scopes the work is the person who does it — which is why a question gets an answer the same day, and why we will tell you when the thing you asked for is not the thing you need.
Ten years inside enterprise ServiceNow instances, and now inside the agents being deployed into them. We also build the MCP servers on the other side of the registry, which is why we know where they leak.
- Independent of the platform vendor
- Tested against a live instance, not a slide deck
- Findings you can hand to an auditor
- The engineer who scoped it is the one who did it
- We say so when the work you asked for is not the work you need
EU AI Act readiness
Obligations for high-risk systems under Annex III fall due on 2 December 2027, after the deferral from May 2026. Harmonised standards are running late, so the practical work — classifying risk, producing technical documentation, proving monitoring — lands on you before the guidance does. It is worth doing whether or not that date moves again.
Risk classification
Establishing which of your agents are high-risk under Annex III, and which are genuinely out of scope.
Technical documentation
The evidence pack the Act expects: purpose, data, limitations, and the testing behind each claim.
Monitoring
Logging and review that demonstrates ongoing oversight rather than a one-off assessment.
The platforms these agents run on
The integration work that put us inside these systems in the first place
ServiceNow Development
Scoped apps, IntegrationHub spokes, SAP and Workday connectors, multi-instance synchronisation.
Enterprise Integration
Connecting the systems either side of an agent, so what it reaches is deliberate rather than incidental.
AI & Automation
The broader machine-learning and process-automation work, separate from the security practice.