The projects below are real work in progress, not completed engagements. This page exists so that intent is documented honestly, separate from the verified case studies above it — each of which links to a real, inspectable codebase or a documented client delivery. Nothing here carries a client name, a metric, or a screenshot, because none of that exists yet for these five.
AI Security Framework
A structured methodology and toolset for assessing AI-powered products end-to-end — model access control, prompt-injection surface, data leakage through AI features, and vendor/API key exposure — complementing the AI Security Kenya service.
Secure AI Agents
Reference architecture and tooling for autonomous AI agents with bounded tool-call permissions, human-approval gates on consequential actions, and trajectory auditing — the practical build-out behind the AI Agent Security service.
RAG Security Architecture
Hardened retrieval-augmented generation reference design — vector database access control, source-freshness and provenance checks, and defenses against indirect prompt injection via retrieved documents — underpinning the RAG Security service.
Security Audit Framework
A repeatable audit methodology and checklist tooling covering infrastructure/cloud configuration, security architecture reviews, and process/policy audits, distinct from the app/API-specific testing already delivered under Web & API Security Assessment.
Data Protection Assessments
A standardized KDPA/GDPR gap-assessment package — data processing register, DPIA templates, breach-response planning — building out the Data Protection Consulting service into a repeatable delivery product.