Skip to content
PhiloCyber logo
AI Security / Independent practice

Security for LLMs, agents and MCP integrations

I help engineering teams find and fix the security problems in what they are shipping with AI, before somebody else finds them first.

One practice, one subject: systems built on LLMs and agents. If what you need is general infrastructure security, a compliance audit or a SOC, I am not the right call.

See the five engagementsAn independent practice run by Ricardo N. Prieto under PhiloCyber.

Five ways to work together, from a single decision to a full adversarial assessment.

Where to start

Not sure which one fits?

Most engagements begin with a single advisory session. One focused conversation about the decision in front of you, and a straight answer on whether anything else on this list is even necessary.

Book an advisory session

Before you write

The questions people ask first

Do you need access to our production environment?
Usually not. Threat modeling runs entirely on design documents and sessions with your team. Penetration testing runs against non-production environments unless you explicitly authorize otherwise, in writing.
How does an engagement start?
With a written scope: what is in, what is out, what you hand over and when. For testing work that same document carries the authorization. Nothing begins before both sides have signed off on it.
Can you sign an NDA?
Yes. I sign your NDA before receiving any architecture, code or design material, and I work under it for the whole engagement.
Is a retest included?
Yes, on penetration testing engagements. Once your fixes are ready I re-run the relevant findings and hand back closure evidence you can put in front of a customer or an auditor.
What language do you work in, and from where?
Reports and sessions in English or Spanish, whichever your team works in. Remote, on Argentina time, which overlaps with both European and North American hours.

Next engagement

Something already in production you are not sure about?

Tell me what you are building and what worries you about it. If it is not something I can help with, I will tell you that too.

Tell me what you are building
Security for LLMs, agents and MCP integrations | Ricardo N. Prieto | PhiloCyber