Enterprise AI security, at startup scale
You are shipping AI faster than any security team could keep up with — and you do not have a security team. This is the page for that.
The first enterprise prospect who takes you seriously will send a security questionnaire. The first regulator who notices you will ask what models you run and who is accountable for them. Both arrive earlier than anyone plans for, and both are answered from an inventory you do not have yet.
Apply to the programme
Tell us what you are building and roughly where you are. Fields marked with an asterisk are required; the rest help us come back with something useful rather than generic.

Questions founders actually ask
Who is it for?
Early-stage companies that are building or shipping something with AI in it and do not yet have a dedicated security team. We scope fit per company rather than against a funding number — what matters is whether the platform genuinely helps at the stage you are at. If you are a scaleup, a spinout or a non-profit, tell us anyway and we will give you an honest answer.
What does it cost?
Terms are scoped per company on a call. What you are running, how much of it there is and what your buyers are asking you for all change the answer, so we would rather work it out with you than publish a number that would be wrong for most of the people reading this. There is no obligation, and nothing to sign before you have seen the platform run against your own environment.
How do we start?
Send us a note through the contact form saying what you are building and roughly where you are. What comes back is a scoping call rather than a form to fill in.
Is it the full product?
Yes. The same platform an enterprise gets — the same modules, the same scanners, the same risk engine and the same evidence model. Nothing is held back for a larger logo, and nothing is stripped out to make a starter tier.
What do you need from us to get going?
Read-only roles on the cloud accounts, SaaS tenants and repositories you want covered, and someone who can create them. There is no agent to deploy, nothing to embed in a workload, and no change to how your application is built or shipped.
What happens to our data?
Read-only access, per-tenant encrypted credentials and row-level isolation at the database. If your customers or your regulator require it, the same platform runs self-hosted in your own account, or fully air-gapped.