01The gap 02Services 03What each engagement covers 04Who does the work 05FAQ 06AI Operations 07AI Agents 08Pricing 09AI Assessment Manual 10Home
Book a free 15-minute security call Get the free AI Field Manual

Service 02 · The security practice

Secure AI

Know what your AI did, who told it to, and what it touched.

Prompt-injection testing, shadow-AI discovery, guardrails, and a fractional CISO who signs off on the controls. Built for the people who have to answer for what the agents do.

20+ years in cybersecurity U.S. Army Special Forces veteran Cyber Electronic Warfare Warrant Officer RSA Conference speaker
Agent activity · todayExample record
Tool Agent requested a full customer export Blocked · outside approved scope · owner notified 09:14
Inject Instruction hidden in an inbound email Quarantined · escalated to a human reviewer 09:41
Shadow Unsanctioned AI tool found on a finance laptop Added to inventory · data reach recorded 10:02

Illustrative interface with fictional data. Not live customer activity, and not a performance claim.

The gap

The agents are already running. The record of what they did is not.

Close to three-quarters of companies plan to deploy agentic AI within two years. Only 21% report a mature model for agent governance (Deloitte, 2026 State of AI).

The risk is not using AI badly. It is running it without a record.

Problem 01

Shadow AI

Staff paste customer data into whatever assistant is open, and vendors add models to products you already bought. Nobody knows which tools hold your data.

Problem 02

Prompt injection

An agent that reads email, tickets, or web pages will eventually read instructions written by someone else. If it holds tools, those instructions become actions.

Problem 03

Ungoverned agents

Access is granted broadly to make the pilot work, then never revisited. The pilot becomes production and the blast radius grows quietly.

Problem 04

No audit trail

Something goes wrong and nobody can reconstruct it: who authorised the action, what data it read, which model ran.

Services

Four pieces of work. Each one ends in something written down.

Scope is agreed before anything starts. Every engagement hands over documents your team can operate without us.

Service 01

Prompt-injection testing

We test the agents you already run against the content they actually process. The question is what the model can reach once it is tricked.

Deliverables

  • A test plan mapped to each agent’s tools and permissions
  • A findings register with severity, reproduction steps, and a fix owner
  • A retest after remediation, with the deltas recorded
Service 02

Shadow-AI discovery

We start from where your data moves, not from what the policy says: extensions, bundled assistants, personal accounts, vendors who added a model.

Deliverables

  • An inventory of AI tools in use, with owner and data reach
  • A sanction, replace, or block decision on every tool found
  • An AI use policy people will actually follow
Service 03

Guardrails and audit trail

What the agent may do alone, what needs a human, what it never touches, and what gets written down every time it acts.

Deliverables

  • A guardrail policy: allowed actions, escalation triggers, hard stops
  • A least-privilege pass across every integration
  • A logging specification and an access inventory
Service 04

Fractional CISO and AI governance

Security leadership for companies that need a named owner without a full-time executive. Strategy, policy, and board-ready reporting.

Deliverables

  • A risk register with owners and review dates
  • AI controls mapped to your compliance framework
  • Vendor and model review before anything reaches production

Security & governance coverage

What each engagement covers.

The monthly retainer, priced here once. Anything not listed is scoped and quoted before the work starts, never after.

Scroll the table sideways to compare engagements.

Security and governance coverage by monthly engagement
Coverage Reconnaissance $2,600starting / month Operations $5,525starting / month Command $14,625starting / month
Workflow build capacity One workflow at a time, automated then maintained Several workflows built and optimised in parallel Dedicated build-and-governance capacity
Tooling integration & documentation Scoped on the call Included Included, as full AI workspace architecture
AI security audit Scoped separately Scoped separately Included
Security leadership & governance Scoped separately Scoped separately Included
Hosting, monitoring & patching $325 / month $325 / month Included
Individual cybersecurity assessment Available à la carte at any tier, scoped and priced on what is needed
Strategy cadence Bi-weekly strategy calls Weekly strategy calls Dedicated lead on an embedded weekly cadence
Reporting & support Monthly reporting, email support Priority response Dedicated lead

Prompt-injection testing, shadow-AI discovery, and guardrail authoring are scoped against your stack on the call, because the work depends on how many agents you run and what those agents can reach. The AI security audit sits inside Command. All prices in USD, billed monthly.

Who does the work

One operator, and a background you can check.

You work with the person doing the work. That is the whole staffing model, and it is why engagement volume is deliberately limited.

Jaclyn "Jax" Scott, Founder and Principal of TheZaraAI

Jaclyn “Jax” Scott

Founder & Principal

Cybersecurity and AI executive with more than 20 years across military cyber operations and enterprise security. A U.S. Army Cyber and Electronic Warfare Special Operations Warrant Officer, she supported SOCOM, SOCEUR, the Department of State, and NATO, and still serves as a Chief Warrant Officer in the 75th Innovation Command, delivering AI innovation to the warfighter.

Former Deputy CISO and VP of Cybersecurity at Pearson. Co-author of Cybersecurity Career Master Plan, co-host of the award-winning 2 Cyber Chicks, and a board member of the Special Operations Association of America, where she authored the Jax Act. Master’s in Cybersecurity Risk Management, Georgetown University.

Security is the practice here, not an add-on sold back to you after the build. The access inventory, the least-privilege pass, and the audit trail are stages of the engagement, and you get the documentation to prove it.

Special OperationsCyber & EW Warrant OfficerFormer Deputy CISOGeorgetown MSRSA SpeakerPublished Author

Questions

What security buyers ask first.

A network penetration test looks for a way in. Prompt-injection testing looks at what happens after a model reads text it was never meant to obey: a support ticket, a resume, a web page, a calendar invite. The attack path is the content the agent processes and the tools the agent holds, so it does not appear in a scope built around hosts and ports. If your agent can send mail, read a drive, or call an internal API, that reach is the thing to test.

Usually, yes. Shadow AI is rarely a policy violation on purpose. It is a browser extension, an assistant bundled into a tool you already pay for, a personal account used on a work laptop at 6pm, or a vendor who quietly added a model to their product. Discovery starts from where data actually moves rather than from what the policy says, and it ends with an inventory naming each tool, its owner, and the data it can reach.

Testing runs against a scope agreed in writing before anything starts, with a named contact, a stated window, and a stop condition. Where an agent takes real-world actions (sending, paying, deleting), we test in a mirrored environment or with the destructive tools disconnected. You are told what was attempted, what succeeded, and what was left alone.

Yes. Controls are mapped to the framework you are already measured against rather than to a new one invented for AI. TheZaraAI is an advisory practice, not an auditor or a certification body: we do not issue attestations or certify you against any standard. We write the controls, the evidence, and the reporting that your assessor and your board are going to ask for.

Documents. An inventory of AI in use and the data each tool can reach. A findings register with severity, reproduction steps, and a fix owner. A written guardrail policy. A logging specification saying what an audit entry records. An access inventory showing which system can reach which data under whose credentials. Every engagement ends in artefacts your team can operate without us.

You work with the person doing the work. TheZaraAI is led by Jax Scott: a U.S. Army Cyber and Electronic Warfare Special Operations Warrant Officer with more than 20 years across military cyber operations and enterprise security, former Deputy CISO and VP of Cybersecurity at Pearson, and an RSA Conference speaker. Nothing is subcontracted.

Monthly retainers start at $2,600 for Reconnaissance, $5,525 for Operations, and $14,625 for Command, which includes an AI security audit and governance. Hosting and security is $325 per month on the first two tiers. An individual cybersecurity assessment is also available à la carte, scoped and priced on what is needed. See all pricing.

15-minute security call

Book fifteen minutes.

A short working call, not a sales sequence. We walk what you have deployed and name where the exposure sits. Free, and it books straight into the calendar.

  • Which AI is running in your company, including the parts nobody filed
  • What your agents can currently reach, and what that costs you if one is tricked
  • Whether you could reconstruct an incident today from what is being logged
  • A recommended engagement shape, or an honest “you do not need us yet”

The AI Agent Field Manual.

The practical guide we wrote for people who want to build and secure their own agents. Answer two questions and it downloads straight away, with a copy to your inbox. If it saves you hiring us, that is a perfectly good outcome.

Delivered instantly · No spam · Unsubscribe anytime

Book 15-min call Get the manual