Expertise

Deep technical research, applied to real systems.

We focus on security questions that require careful manual investigation, practical validation, and direct communication with the teams responsible for the technology.

Selected focus

Evaluate the behavior and boundaries of AI-enabled products.

Testing considers the model, application logic, tools, data flows, and user trust assumptions as one connected system.

Questions we test

Can untrusted content redirect the system?

Can tools be used outside intended authority?

What sensitive context can be exposed?

Typical outputs

Threat model and test plan

Reproducible findings

Mitigation priorities

01

AI security evaluation

Adversarial evaluation of AI models and agentic systems, from model behavior to tools and surrounding application controls.

Areas of inquiry

Model red teaming

Prompt injection

Agent and tool security

Data exposure

Evaluation design

02

Application security research

Manual analysis of web applications and APIs with an emphasis on business logic, authorization, and practical impact.

Areas of inquiry

Web applications

API security

Access control

Business logic

Product security

03

Cloud and infrastructure

Assessment of trust boundaries across cloud services, identity systems, exposed infrastructure, and security-sensitive configurations.

Areas of inquiry

Cloud services

Identity and access

Attack surface

Trust boundaries

Configuration review

Engagement principle

H-One performs testing only with explicit authorization, an agreed scope, and clear rules of engagement.

Common questions

Before an evaluation begins.

Automation can support coverage and repeatable checks, but the core of the work is manual investigation of security assumptions, system behavior, and practical attack paths.

Start a conversation

Need an independent evaluation of a model, application, or platform?

Tell us what you are building, the question you need answered, and where an independent security perspective could help.

Contact H-One