Security for LLMs, agents and MCP integrations
I help engineering teams find and fix the security problems in what they are shipping with AI, before somebody else finds them first.
One practice, one subject: systems built on LLMs and agents. If what you need is general infrastructure security, a compliance audit or a SOC, I am not the right call.
Five ways to work together, from a single decision to a full adversarial assessment.
Where to start
Not sure which one fits?
Most engagements begin with a single advisory session. One focused conversation about the decision in front of you, and a straight answer on whether anything else on this list is even necessary.
- S/01
Threat Modeling for AI Systems
See what is involvedA structured security review of how your agents, LLM features and MCP integrations could be misused, delivered one week after a single session with the people who built it.
One week from the session with your team
- S/02
Penetration Testing for Agents, LLMs and MCPs
See what is involvedAuthorized adversarial testing of your deployed AI application, from prompt injection and tool abuse to complete data-exfiltration chains. Retest included.
One to two weeks by scope and complexity, plus a week of retesting
- S/03
AI Security Policy and Governance
See what is involvedPractical rules, review paths and evidence requirements for using and shipping AI without turning governance into a bottleneck.
Five to six weeks
- S/04
Advisory and Consultations
See what is involvedIndependent judgment for one concrete AI security decision, without committing to a full assessment.
One session, plus async follow-up
- S/05
AI Security Enablement
See what is involvedHands-on workshops that give engineering, product and security a repeatable way to review AI systems before release.
One intensive session of one to four hours, or weekly sessions of one to two
Before you write
The questions people ask first
- Do you need access to our production environment?
- Usually not. Threat modeling runs entirely on design documents and sessions with your team. Penetration testing runs against non-production environments unless you explicitly authorize otherwise, in writing.
- How does an engagement start?
- With a written scope: what is in, what is out, what you hand over and when. For testing work that same document carries the authorization. Nothing begins before both sides have signed off on it.
- Can you sign an NDA?
- Yes. I sign your NDA before receiving any architecture, code or design material, and I work under it for the whole engagement.
- Is a retest included?
- Yes, on penetration testing engagements. Once your fixes are ready I re-run the relevant findings and hand back closure evidence you can put in front of a customer or an auditor.
- What language do you work in, and from where?
- Reports and sessions in English or Spanish, whichever your team works in. Remote, on Argentina time, which overlaps with both European and North American hours.
Next engagement
Something already in production you are not sure about?
Tell me what you are building and what worries you about it. If it is not something I can help with, I will tell you that too.

