Governed AI Engineering
Our own AI governance framework drives the work, run by professionals with experience in offensive security and in governance. Accelerated quality, driven by the framework.
How We Work
TALUS is our AI governance framework. You never have to interact with it, but you will notice what it does to the turnaround and to the consistency of what comes back.
One standard
Every person on an engagement works inside TALUS, so the standard does not change with who is holding the work.
Efficiency from governance
TALUS is how we keep a small firm fast. It sets the sequence of the work and keeps the record of it, so nothing is redone and nothing is lost.
Assisted, never automated
We use AI internally where it improves our own output. A person owns every word that reaches you.
What We Do
Every engagement is scoped to an outcome and a date before it starts.
Secure code review
A senior read of your codebase against a threat model, ranked by what each finding actually breaks.
CybersecurityPassword assessment
Active Directory password testing driven by Ashfall, with a published method and a reproducible benchmark.
CybersecurityInternal PCI compliance scanning
Scheduled scanning that feeds your own compliance programme, written up in plain terms.
CybersecurityPenetration testing
Senior led and manual, run through our own TALUS driven process rather than a scan and a template.
CybersecurityFeature additions
A new module or a new function in something you already run, delivered against a fixed date.
Software deliveryOne Number, Checkable
A wordlist only finds passwords somebody already leaked. Ashfall statistically prioritizes which candidates to try first, tailored to your organization and its users, rather than working through generic wordlists and password rulesets. Ashfall then uses OMEN, trained on the passwords already cracked in the engagement, to supercharge password recovery - at the same guess budget, that stage recovers roughly four times what the strongest wordlist configuration reaches. This allows your organization to identify potentially vulnerable passwords before malicious actors can exploit them.
The OMEN method is published and the benchmark reproduces in one command. We put it here because it is the part of our work you can verify without hiring us.
Password assessmentWordlist replay sits at zero because replaying training words recovers nothing on a disjoint test set. That is the control confirming no leakage, so every recovery above it is genuine. This chart reflects the OMEN stage only - Ashfall's own organization-tailored prioritization sits upstream of this stage and isn't part of a published benchmark yet.
One Process, Every Review
Every secure code review runs through our TALUS-governed process: a threat model built for the codebase, findings ranked by what they actually break, and a re-check that closes them. Request a sample and we'll walk you through one.
Request a walkthrough