Shadow AI
Staff paste customer data into whatever assistant is open. Vendors add a model to a product you already bought. Nobody filed a ticket, so nobody knows which tools hold your data or under whose account.
Secure AI · The security practice
Prompt-injection testing, shadow-AI discovery, guardrails, and a fractional CISO who signs off on the controls, not just the slide. Built for CTOs, CISOs, and compliance leaders who have to answer for what the agents do.
Illustrative interface with fictional data. Not live customer activity, and not a performance claim.
The gap
Close to three-quarters of companies plan to deploy agentic AI within two years, but only 21% report a mature model for agent governance, and 37% still use AI only at a surface level, with little or no change to underlying processes (Deloitte, 2026 State of AI). Only 9% of organizations have fully deployed an AI use case (Accenture).
The risk is not using AI badly. It is running it without a record.
Staff paste customer data into whatever assistant is open. Vendors add a model to a product you already bought. Nobody filed a ticket, so nobody knows which tools hold your data or under whose account.
An agent that reads email, tickets, resumes, or web pages will eventually read instructions written by someone else. If it holds tools, those instructions become actions. Network scanners do not look here.
Access is granted broadly to make the pilot work, then never revisited. The agent keeps the keys, the pilot becomes production, and the blast radius grows quietly for a year.
Something goes wrong and the honest answer is that nobody can reconstruct it. Who authorised the action, what data it read, which model version ran, and whether it has happened before.
Services
Scope is agreed before anything starts, and every engagement hands over documents your team can operate without us. Dependence is not a business model we are interested in.
We test the agents you already run, against the content they actually process — inbound mail, tickets, documents, calendar invites, retrieved web pages. The question is not whether the model can be tricked. It is what the model can reach once it is.
We start from where your data moves rather than from what the policy says. Browser extensions, assistants bundled into tools you already pay for, personal accounts on work machines, and vendors who quietly added a model to their product.
Controls that survive contact with real users. What the agent may do on its own, what needs a human, what it is never permitted to touch, and what gets written down every time it acts.
Security leadership for companies that need a named owner without hiring a full-time executive. Strategy, policy, and board-ready reporting from someone who has operated in genuinely adversarial environments.
Security & governance coverage
The rows below describe what is published today. Anything not listed is scoped and quoted before the work starts, never after.
Scroll the table sideways to compare engagements.
| Coverage | Reconnaissance $1,424starting / month | Operations $3,026starting / month | Command $8,010starting / month |
|---|---|---|---|
| Workflow build capacity | One workflow at a time, automated then maintained | Several workflows built and optimised in parallel | Dedicated build-and-governance capacity |
| Tooling integration & documentation | Scoped on the call | Included | Included, as full AI workspace architecture |
| AI security audit | Scoped separately | Scoped separately | Included |
| Security leadership & governance | Scoped separately | Scoped separately | Included |
| Hosting, monitoring & patching | $325 / month | $325 / month | Included |
| Strategy cadence | Bi-weekly strategy calls | Weekly strategy calls | Dedicated lead on an embedded weekly cadence |
| Reporting & support | Monthly reporting, email support | Priority response | Dedicated lead |
Prompt-injection testing, shadow-AI discovery, and guardrail authoring are scoped against your stack on the call, because the work depends on how many agents you run and what those agents can reach. The AI security audit sits inside Command. All prices in USD, billed monthly.
Who does the work
You work with the person doing the work. That is the whole staffing model, and it is why engagement volume is deliberately limited.
Founder & Principal
Ten-plus years in U.S. Army Special Forces as a Cyber Electronic Warfare Warrant Officer. Nineteen years in cybersecurity. RSA Conference speaker, Substack publisher, and an active practitioner rather than a commentator.
The through-line is unglamorous: systems fail at the boundaries, under pressure, when nobody is watching. Adversary work teaches you to look at what a system can be made to do, not at what it was designed to do. Applied to AI, that is the whole job — the tools an agent holds, the content it will obey, and the record it leaves behind.
Security is the practice here, not an add-on sold back to you after the build. The access inventory, the least-privilege pass, and the audit trail are stages of the engagement, and you get the documentation to prove it.
Prices
Security work is not a one-off document. Agents change, vendors ship new models, and staff find new tools, so the retainer is what keeps the inventory, the guardrails, and the audit trail true. Published rates below — the call confirms which engagement you need, it is not where the number appears for the first time.
Get one workflow off your plate at a time, done properly. The usual entry point.
Ship new automations while what is already live keeps getting tuned.
Run AI operations with an embedded partner. Security leadership included, hosting covered.
All prices in USD. Reconnaissance and Operations add $325/month for hosting & security — managed hosting, uptime monitoring, updates, and patching. That is already inside Command. If you want proof before a retainer, one-time builds start at $325 for the Starter Agent and $789 for the Integrated Agent, with a $197/month care plan after handoff. See the full pricing table on the homepage, or read how the build side works in AI Operations.
Questions
A network penetration test looks for a way in. Prompt-injection testing looks at what happens after a model reads text it was never meant to obey — a support ticket, a resume, a web page, a calendar invite. The attack path is the content the agent processes and the tools the agent holds, so it does not appear in a scope built around hosts and ports. If your agent can send mail, read a drive, or call an internal API, that reach is the thing to test.
Usually, yes. Shadow AI is rarely a policy violation on purpose. It is a browser extension, an assistant bundled into a tool you already pay for, a personal account used on a work laptop at 6pm, or a vendor who quietly added a model to their product. Discovery starts from where data actually moves rather than from what the policy says, and it ends with an inventory naming each tool, its owner, and the data it can reach.
Testing runs against a scope agreed in writing before anything starts, with a named contact, a stated window, and a stop condition. Where an agent takes real-world actions — sending, paying, deleting — we test in a mirrored environment or with the destructive tools disconnected. You are told what was attempted, what succeeded, and what was left alone.
Yes. Controls are mapped to the framework you are already measured against rather than to a new one invented for AI. TheZaraAI is an advisory practice, not an auditor or a certification body: we do not issue attestations or certify you against any standard. We write the controls, the evidence, and the reporting that your assessor and your board are going to ask for.
Documents. An inventory of AI in use and the data each tool can reach. A findings register with severity, reproduction steps, and a fix owner. A written guardrail policy. A logging specification saying what an audit entry records. An access inventory showing which system can reach which data under whose credentials. Every engagement ends in artefacts your team can operate without us.
You work with the person doing the work. TheZaraAI is led by Jax Scott — ten-plus years in U.S. Army Special Forces as a Cyber Electronic Warfare Warrant Officer, 19 years in cybersecurity, and an RSA Conference speaker. That is the staffing model, and it is why engagement volume is deliberately limited.
Monthly engagements start at $1,424 for Reconnaissance, $3,026 for Operations, and $8,010 for Command, which includes an AI security audit and governance. Hosting and security is $325/month on Reconnaissance and Operations and is already inside Command. The 15-minute call confirms which engagement fits; it is not where the number appears for the first time.
15-minute security call
A short working call, not a sales sequence. We walk what you have deployed and name where the exposure sits. Free, and it books straight into the calendar.
The practical guide we wrote for people who want to build and secure their own agents. Answer two questions and it downloads straight away, with a copy to your inbox. If it saves you hiring us, that is a perfectly good outcome.