01The gap 02Services 03Capability matrix 04Who does the work 05Prices 06FAQ 07AI Operations 08Home
Book a free 15-minute security call Get the free AI Field Manual

Secure AI · The security practice

Know what your AI did, who told it to, and what it touched.

Prompt-injection testing, shadow-AI discovery, guardrails, and a fractional CISO who signs off on the controls, not just the slide. Built for CTOs, CISOs, and compliance leaders who have to answer for what the agents do.

19 years in cybersecurity U.S. Army Special Forces veteran Cyber Electronic Warfare Warrant Officer RSA Conference speaker
Agent activity · todayExample record
Tool Agent requested a full customer export Blocked · outside approved scope · owner notified 09:14
Inject Instruction hidden in an inbound email Quarantined · escalated to a human reviewer 09:41
Shadow Unsanctioned AI tool found on a finance laptop Added to inventory · data reach recorded 10:02

Illustrative interface with fictional data. Not live customer activity, and not a performance claim.

The gap

The agents are already running. The record of what they did is not.

Close to three-quarters of companies plan to deploy agentic AI within two years, but only 21% report a mature model for agent governance, and 37% still use AI only at a surface level, with little or no change to underlying processes (Deloitte, 2026 State of AI). Only 9% of organizations have fully deployed an AI use case (Accenture).

The risk is not using AI badly. It is running it without a record.

Problem 01

Shadow AI

Staff paste customer data into whatever assistant is open. Vendors add a model to a product you already bought. Nobody filed a ticket, so nobody knows which tools hold your data or under whose account.

Problem 02

Prompt injection

An agent that reads email, tickets, resumes, or web pages will eventually read instructions written by someone else. If it holds tools, those instructions become actions. Network scanners do not look here.

Problem 03

Ungoverned agents

Access is granted broadly to make the pilot work, then never revisited. The agent keeps the keys, the pilot becomes production, and the blast radius grows quietly for a year.

Problem 04

No audit trail

Something goes wrong and the honest answer is that nobody can reconstruct it. Who authorised the action, what data it read, which model version ran, and whether it has happened before.

Services

Four pieces of work. Each one ends in something written down.

Scope is agreed before anything starts, and every engagement hands over documents your team can operate without us. Dependence is not a business model we are interested in.

Service 01

Prompt-injection testing

We test the agents you already run, against the content they actually process — inbound mail, tickets, documents, calendar invites, retrieved web pages. The question is not whether the model can be tricked. It is what the model can reach once it is.

Deliverables

  • A written test plan mapped to each agent's tools, data, and permissions
  • A findings register with severity, reproduction steps, and a named fix owner
  • Recommended guardrails and tool-scoping changes, ranked by blast radius
  • A retest after remediation, with the deltas recorded
Service 02

Shadow-AI discovery

We start from where your data moves rather than from what the policy says. Browser extensions, assistants bundled into tools you already pay for, personal accounts on work machines, and vendors who quietly added a model to their product.

Deliverables

  • An inventory of AI tools in use, with the owner and the data each one can reach
  • A sanction, replace, or block decision recorded against every tool found
  • An AI use policy written in language a 40-person company will actually follow
  • A refresh cadence, so the inventory does not go stale the week after we leave
Service 03

Guardrails and audit trail

Controls that survive contact with real users. What the agent may do on its own, what needs a human, what it is never permitted to touch, and what gets written down every time it acts.

Deliverables

  • A guardrail policy naming allowed actions, escalation triggers, and hard stops
  • A least-privilege pass across every integration, with the gaps named rather than hidden
  • A logging specification: what an audit entry records, and how long it is kept
  • An access inventory showing which system reaches which data, under whose credentials
Service 04

Fractional CISO and AI governance

Security leadership for companies that need a named owner without hiring a full-time executive. Strategy, policy, and board-ready reporting from someone who has operated in genuinely adversarial environments.

Deliverables

  • A risk register your leadership team can read, with owners and review dates
  • AI controls mapped to the compliance framework you are already measured against
  • Board-ready reporting on AI risk, written for directors rather than engineers
  • Vendor and model review before a new tool reaches production

Security & governance coverage

What each engagement covers.

The rows below describe what is published today. Anything not listed is scoped and quoted before the work starts, never after.

Scroll the table sideways to compare engagements.

Security and governance coverage by monthly engagement
Coverage Reconnaissance $1,424starting / month Operations $3,026starting / month Command $8,010starting / month
Workflow build capacity One workflow at a time, automated then maintained Several workflows built and optimised in parallel Dedicated build-and-governance capacity
Tooling integration & documentation Scoped on the call Included Included, as full AI workspace architecture
AI security audit Scoped separately Scoped separately Included
Security leadership & governance Scoped separately Scoped separately Included
Hosting, monitoring & patching $325 / month $325 / month Included
Strategy cadence Bi-weekly strategy calls Weekly strategy calls Dedicated lead on an embedded weekly cadence
Reporting & support Monthly reporting, email support Priority response Dedicated lead

Prompt-injection testing, shadow-AI discovery, and guardrail authoring are scoped against your stack on the call, because the work depends on how many agents you run and what those agents can reach. The AI security audit sits inside Command. All prices in USD, billed monthly.

Who does the work

One operator, and a background you can check.

You work with the person doing the work. That is the whole staffing model, and it is why engagement volume is deliberately limited.

Jaclyn "Jax" Scott, Founder and Principal of TheZaraAI

Jaclyn “Jax” Scott

Founder & Principal

Ten-plus years in U.S. Army Special Forces as a Cyber Electronic Warfare Warrant Officer. Nineteen years in cybersecurity. RSA Conference speaker, Substack publisher, and an active practitioner rather than a commentator.

The through-line is unglamorous: systems fail at the boundaries, under pressure, when nobody is watching. Adversary work teaches you to look at what a system can be made to do, not at what it was designed to do. Applied to AI, that is the whole job — the tools an agent holds, the content it will obey, and the record it leaves behind.

Security is the practice here, not an add-on sold back to you after the build. The access inventory, the least-privilege pass, and the audit trail are stages of the engagement, and you get the documentation to prove it.

Special ForcesCyber EW Warrant OfficerRSA Conference speaker19-year cybersecurity veteranvCISO

Prices

Here are the prices. Retainers are the main path.

Security work is not a one-off document. Agents change, vendors ship new models, and staff find new tools, so the retainer is what keeps the inventory, the guardrails, and the audit trail true. Published rates below — the call confirms which engagement you need, it is not where the number appears for the first time.

Monthly

Reconnaissance

$1,424 starting / month

Get one workflow off your plate at a time, done properly. The usual entry point.

  • One workflow at a time — automated, then maintained
  • Bi-weekly strategy calls
  • Monthly reporting · email support
  • Hosting & security at $325/month
Monthly · most common

Operations

$3,026 starting / month

Ship new automations while what is already live keeps getting tuned.

  • Several workflows built and optimised in parallel
  • Tooling integration & documentation
  • Weekly strategy calls · priority response
  • Hosting & security at $325/month
Monthly

Command

$8,010 starting / month

Run AI operations with an embedded partner. Security leadership included, hosting covered.

  • Dedicated build-and-governance capacity
  • Full AI workspace architecture
  • AI security audit included
  • Dedicated lead · embedded weekly cadence
  • Hosting, monitoring & governance included

All prices in USD. Reconnaissance and Operations add $325/month for hosting & security — managed hosting, uptime monitoring, updates, and patching. That is already inside Command. If you want proof before a retainer, one-time builds start at $325 for the Starter Agent and $789 for the Integrated Agent, with a $197/month care plan after handoff. See the full pricing table on the homepage, or read how the build side works in AI Operations.

Questions

What security buyers ask first.

A network penetration test looks for a way in. Prompt-injection testing looks at what happens after a model reads text it was never meant to obey — a support ticket, a resume, a web page, a calendar invite. The attack path is the content the agent processes and the tools the agent holds, so it does not appear in a scope built around hosts and ports. If your agent can send mail, read a drive, or call an internal API, that reach is the thing to test.

Usually, yes. Shadow AI is rarely a policy violation on purpose. It is a browser extension, an assistant bundled into a tool you already pay for, a personal account used on a work laptop at 6pm, or a vendor who quietly added a model to their product. Discovery starts from where data actually moves rather than from what the policy says, and it ends with an inventory naming each tool, its owner, and the data it can reach.

Testing runs against a scope agreed in writing before anything starts, with a named contact, a stated window, and a stop condition. Where an agent takes real-world actions — sending, paying, deleting — we test in a mirrored environment or with the destructive tools disconnected. You are told what was attempted, what succeeded, and what was left alone.

Yes. Controls are mapped to the framework you are already measured against rather than to a new one invented for AI. TheZaraAI is an advisory practice, not an auditor or a certification body: we do not issue attestations or certify you against any standard. We write the controls, the evidence, and the reporting that your assessor and your board are going to ask for.

Documents. An inventory of AI in use and the data each tool can reach. A findings register with severity, reproduction steps, and a fix owner. A written guardrail policy. A logging specification saying what an audit entry records. An access inventory showing which system can reach which data under whose credentials. Every engagement ends in artefacts your team can operate without us.

You work with the person doing the work. TheZaraAI is led by Jax Scott — ten-plus years in U.S. Army Special Forces as a Cyber Electronic Warfare Warrant Officer, 19 years in cybersecurity, and an RSA Conference speaker. That is the staffing model, and it is why engagement volume is deliberately limited.

Monthly engagements start at $1,424 for Reconnaissance, $3,026 for Operations, and $8,010 for Command, which includes an AI security audit and governance. Hosting and security is $325/month on Reconnaissance and Operations and is already inside Command. The 15-minute call confirms which engagement fits; it is not where the number appears for the first time.

15-minute security call

Book fifteen minutes.

A short working call, not a sales sequence. We walk what you have deployed and name where the exposure sits. Free, and it books straight into the calendar.

  • Which AI is running in your company, including the parts nobody filed
  • What your agents can currently reach, and what that costs you if one is tricked
  • Whether you could reconstruct an incident today from what is being logged
  • A recommended engagement shape, or an honest “you do not need us yet”

The AI Agent Field Manual.

The practical guide we wrote for people who want to build and secure their own agents. Answer two questions and it downloads straight away, with a copy to your inbox. If it saves you hiring us, that is a perfectly good outcome.

Delivered instantly · No spam · Unsubscribe anytime

Book 15-min call Get the manual