Focused research sprint
For a narrow security question, feature, attack hypothesis, or early design decision that needs concentrated investigation.
Engagements
Different systems and stages require different forms of assurance. H-One defines the scope, depth, and outputs around the security question—not a generic package.
Engagement planner
Choose the system and project stage. This is guidance only; the final engagement is scoped through a technical conversation.
A scoped adversarial evaluation covering model behavior, tools, data flows, and application controls.
Final scope is defined after an initial technical conversation.Discuss this engagement ↗Engagement models
For a narrow security question, feature, attack hypothesis, or early design decision that needs concentrated investigation.
For a defined application, API surface, AI-enabled workflow, or infrastructure boundary that needs broader adversarial review.
For teams exploring a shared technical question, developing evaluation methods, or investigating a vulnerability class.
What gets defined
The decision, risk, or security claim the work should examine.
In-scope applications, models, APIs, environments, identities, and integrations.
Allowed testing techniques, constraints, data-handling rules, and escalation paths.
Expected evidence, reporting format, readout, and remediation support.
Points of contact, testing windows, incident procedures, and disclosure expectations.
Engagement FAQ
Pricing depends on the scope, depth, access model, environment, and reporting needs. H-One first clarifies the technical objective, then proposes a bounded engagement.
Start a conversation
Tell us what you are building, the question you need answered, and where an independent security perspective could help.
Contact H-One