Secure session File — Organisations
For organisations

You're deploying AI. You hold sensitive data. You have a decade of cryptography to age correctly

For SMEs, mid-sized organisations and regulated entities that take risks seriously while most still ignore them. We work where expertise is scarce and where mistakes are costly.

Specialty in development

AI security

An AI system in production is not an application like any other. Its attack surface includes its natural-language inputs, its tools, its memory and its model supply chain. We evaluate it the way an adversary would.

See the AI security service

In development

A specialty under construction. Our methods draw on the state of the art (OWASP LLM Top 10, MITRE ATLAS); we scope every engagement precisely and say so clearly when a test falls outside our current perimeter.

Attack surfaceAI · LLM / AGENT

Where an AI system is attacked

Five surfaces, evaluated the way an adversary would — not just the model, but everything around it.

AI system LLM · agent Natural-language inputsprompt injection Tools & actionsmisuse · escalation Memory & contextexfiltration Model supply chainpoisoning Guardrailsbypass
01

LLM application security audit

Direct and indirect prompt injection, data exfiltration, guardrail bypass, context leakage. Architecture review and concrete adversarial testing.

Prompt injectionExfiltrationGuardrails
02

AI agent security assessment

Agents with tools, access and autonomy. We assess tool misuse, privilege escalation, unintended actions and the blast radius of a hijack.

Tool useEscalationBlast radius
03

AI red teaming

A structured offensive campaign against your AI system and its environment, up to realistic business scenarios — not just lab cases.

Business scenariosRealistic adversaryActionable report
04

EU AI Act security reading

Mapping your systems to the AI Act's risk levels, identifying applicable obligations and a compliance plan — the security angle, not just the legal one.

Risk classificationObligationsCompliance plan
05

AI supply-chain security

Third-party models, datasets, dependencies, downloaded weights. We assess poisoning, backdoor and unverified-provenance risks.

Model provenancePoisoningDependencies
Specialty in development

Cryptographic resilience

Encrypted data captured today can be decrypted tomorrow. Post-quantum migration is not a "later" project: for long-life secrets, the clock is already ticking.

See the Cryptographic resilience service

In development

A specialty backed by a published method (see Research) and NIST standards (ML-KEM, ML-DSA, SLH-DSA).

Mosca's theoremX + Y > Z

Why the clock is already ticking

Migration time (Y) plus required secrecy (X), beyond the quantum horizon (Z), opens an exposure window.

Z · relevant quantum computer Y · migration · 4 yrs X · required secrecy · 10 yrs exposure window today +4 +8 +12 yrs

Reading: migration (4 yrs) + required secrecy (10 yrs) = 14 years, 2 years beyond the quantum horizon (12). Those 2 years are already exposed to "harvest now, decrypt later". A cryptographic inventory is how you measure X, Y and Z on your own systems.

01

"Harvest now, decrypt later" threat modelling

Which data will still matter in ten years? Which data travels today under cryptography that won't hold? We establish your real exposure to the quantum risk.

Secret lifetimeMosca's theoremPrioritisation
02

Cryptographic inventory

You can't migrate what you don't know you have. A four-pass mapping of the algorithms, keys, protocols and certificates in use across your organisation.

DiscoveryInventoryCrypto-agility

Read our full methodology

03

Post-quantum roadmap

A migration plan toward standardised algorithms (ML-KEM, ML-DSA), sequenced by risk priority, compatible with your operational constraints and built for crypto-agility.

NIST standardsMilestonesProgressive migration
Investigation & audit

Digital investigation and cryptographic quality

See the Investigation & OSINT service

01

Corporate investigation & OSINT

Open-source research within a legal, documented framework: due diligence, information leaks, brand abuse, incident investigation, building admissible evidence files.

Due diligenceData leaksEvidence file
02

Entropy & RNG quality audit

For sectors where randomness is critical — gaming, lottery, finance, cryptographic applications. Statistical evaluation of random-number generators and their resistance to bias.

Statistical testsBiasCompliance

Let's scope your need

contact@adinavprotection.fr Working languages: English · French · Reply within 48 business hours
Contact us