Engagements

Security work shaped around the decision you need to make.

Different systems and stages require different forms of assurance. H-One defines the scope, depth, and outputs around the security question—not a generic package.

Engagement planner

Find a sensible starting point.

Choose the system and project stage. This is guidance only; the final engagement is scoped through a technical conversation.

1. What needs attention?
2. Where is the project?
Suggested starting point

AI security evaluation

A scoped adversarial evaluation covering model behavior, tools, data flows, and application controls.

Final scope is defined after an initial technical conversation.Discuss this engagement

Engagement models

Three ways to structure the work.

01

Focused research sprint

For a narrow security question, feature, attack hypothesis, or early design decision that needs concentrated investigation.

Best suited toPre-release features, new agent capabilities, suspected weakness classes, evaluation prototypes
02

Scoped security assessment

For a defined application, API surface, AI-enabled workflow, or infrastructure boundary that needs broader adversarial review.

Best suited toProduct releases, high-value workflows, authorization models, exposed service boundaries
03

Research collaboration

For teams exploring a shared technical question, developing evaluation methods, or investigating a vulnerability class.

Best suited toAI labs, security teams, developer platforms, and academic research groups

What gets defined

A clear engagement boundary.

Objective

The decision, risk, or security claim the work should examine.

Systems

In-scope applications, models, APIs, environments, identities, and integrations.

Methods

Allowed testing techniques, constraints, data-handling rules, and escalation paths.

Outputs

Expected evidence, reporting format, readout, and remediation support.

Coordination

Points of contact, testing windows, incident procedures, and disclosure expectations.

Engagement FAQ

Practical questions.

Pricing depends on the scope, depth, access model, environment, and reporting needs. H-One first clarifies the technical objective, then proposes a bounded engagement.

Start a conversation

Have a system or research question worth testing?

Tell us what you are building, the question you need answered, and where an independent security perspective could help.

Contact H-One