Sorami / AI security

Most production AI failures are access failures, not model failures.

Your agent calls tools and touches data. AI security is the review layer around it.

Our position

The model is not the attack surface. The permissions are.

Models invent. That is a property of the technology and no control removes it. The damage happens when invented output reaches a tool holding a real credential, so nothing writes to production without a human sign-off the downstream service enforces.

Start with what happened

Six events, six starting points.

A capability list makes you translate your problem into our vocabulary. This table does it the other way round.

Route on the event, not on the capability.
What happenedWhere to start
The agent got write access to something realAgent security review
A customer sent AI questions with the security questionnaireBuyer due diligence pack
The coding assistant rolled out faster than the controlsCoding agent control baseline
The AI feature itself needs adversarial testingAI application security testing
The model and its data sit in a cloud account nobody has reviewedCloud security review
An auditor wants the whole control set evidencedSOC 2 readiness
What you keep

Every AI engagement ends in something you can re-run.

  • Agent Blast Radius Map: the worst call and the worst chain.
  • Tool Permission Ledger: scope held against scope needed.
  • AI Architecture Summary a buyer security team reads alone.
  • Control baseline committed as policy in your own repository.

Each one is a document or a file in your repository, not a slide. The agent security review produces the first two.

The lists we test against

Named, versioned and dated.

A framework without a version is decoration. These are the editions findings are mapped to, read on the date below.

Framework and advisory versions above were read from the primary source on 17 September 2026.

Limits matter

What we do not do

  • No guardrail product, and no blocking proxy we operate.
  • No monitoring service. Every review is dated.
  • No model training, fine-tuning or adversarial model work.
  • No certification. We hold no ISO/IEC 42001:2023 certificate.
  • No multimodal work across image, audio or video.

Sorami is not a certification body and issues no attestation of your controls. Readiness against an external standard is separate work, and security testing and readiness covers it.

Who this is for

Australian teams of ten to three hundred people shipping AI.

The buyer is usually a platform lead or a head of engineering who has been asked to approve something. It is a poor fit for a team that wants a certificate without changing a permission. Work happens in your repositories and your cloud accounts, on the same terms as a cloud security review.

Instant quote

Get an instant quote in 2 minutes

Answer four questions. The indicative price updates as you go. Prices are ex GST.

Indicative until we confirm scope in writing, within one business day. We use your details only to reply. See our Privacy notice.

Questions before you book

Practical answers.

Do you build AI features, or only review them?

Both, but they are scoped separately. The reviews on this page are fixed-scope assessments of something you already run. Engineering work is quoted after the review, because a review that also sells the remediation stops being independent.

Do you need production access?

No. The agent review runs on read-only cloud access, tool manifests and a non-production environment that matches production. Anything touching production needs written authorisation and a rollback plan first.

Can you make the model stop inventing things?

No, and nobody can. Models invent. The design position is that invented output cannot reach a tool with real permissions without a human sign-off enforced by the downstream service.

Are you certified against ISO/IEC 42001:2023?

No. Sorami is not a certification body and holds no AI management system certificate. A register with a named owner per entry is the prerequisite for that work, and it is useful on its own.

Let’s scope it

Not sure which one you need?

Tell us what happened and who asked. We will name the right starting point, or say plainly that we are not the right firm.

Request a quote

Last reviewed: