We test what's exposed, close it, and prove it.
Pyralink is a UK-based cybersecurity firm. We assess, harden, and red-team your infrastructure — then map findings to the frameworks your regulator expects. Senior practitioners with CISM, CISSP, CISA, CRISC, CCISO, CEH, CC credentials. £5M professional indemnity cover.
CloudAuditX
Cloud compliance scanning platform. Read-only scans of your AWS estate with findings fused across six frameworks simultaneously. No agent, no stored credentials, no customer data leaving your account.
- Agentless, read-only scanning of IAM, S3, EC2, VPC, CloudTrail, KMS, RDS and the rest of your AWS estate.
- One scan, six framework views — every finding mapped to ISO 27001:2022, NIST CSF 2.0, SOC 2, CIS, MITRE ATT&CK and STRIDE at once, so a single piece of remediation closes controls in all of them.
- Each finding carries the affected resource, severity, exploit context, remediation steps and the mapped control references.
- Evidence packs formatted for auditors — export and hand straight over at certification or renewal.
Built for regulated SMEs on AWS that need audit-grade evidence without hiring a security team.
LLM Red Team & Audit Implementation
Offensive security assessment for organisations deploying AI agents, RAG pipelines and LLM-integrated systems. We attack your deployed AI the way an adversary would — then help you implement the audit controls your regulator expects.
What we test:
- Direct and indirect prompt injection against your deployed agents and assistants.
- Tool-access abuse and privilege escalation through the agent orchestration layer — what your agent can do that it should not.
- RAG data leakage and retrieval poisoning across your knowledge base.
- System-prompt extraction and guardrail bypass.
- Excessive agency: destructive or irreversible actions reachable without human sign-off.
Every finding is mapped to the AI control set — OWASP LLM Top 10, OWASP Agentic Top 10, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001 and the EU AI Act — in a board-grade evidence pack with prioritised remediation. After you fix, we re-test the exact exploits and issue closure evidence. Our published methodology is documented in RES-05, a controlled red-team of an MCP-connected AI agent.
Airgap AI
Secure AI deployment for sensitive workloads. We stand up LLM capability entirely inside your boundary — on-premises, private cloud or fully air-gapped — so your data never touches a third-party API.
What a deployment includes:
- Model selection and hardware sizing matched to your workload and budget.
- Deployment inside your network boundary — no telemetry, no external API calls, no data leaving your estate.
- Hardened configuration, access control and audit logging from day one, mapped to your existing ISO 27001 or SOC 2 control set.
- Runbooks, staff handover and an agreed support arrangement — your team runs it, we stay reachable.
For firms that want AI capability but cannot send client data, case files or patient records to a public model endpoint.
Scope. Test. Report. Prove.
A free 30-minute review. We agree what gets tested, where the boundary sits, and what evidence you need at the end — for your board, your auditor or your regulator.
Senior practitioners run the assessment directly. Evidence is captured as the work happens, not reconstructed afterwards.
Findings with severity, exploit path and concrete remediation steps — each one mapped to the framework controls it affects, so fixes count towards certification.
After you remediate, we re-test the exact findings and issue closure evidence you can hand to an auditor. Fixed means proven fixed.
vCISO retainer — from £497/month
A senior practitioner owns your security programme: board reporting, risk register ownership, policy and audit preparation, supplier reviews and incident readiness — without the cost of a full-time hire.
Managed Security — priced per environment
Ongoing managed operations: continuous scanning, vulnerability triage, patching cadence and monthly evidence reporting. One contract, one invoice, practitioner-led.
RES-05 — Red-Teaming an MCP-Connected AI Support Agent: A Proof Piece — five vulnerability classes in agentic AI, each proven by re-test.
Credentials and evidence
Every engagement is carried out by senior practitioners with verifiable qualifications and recognised professional standards.
- Credentials
MBA · DBA · PMP · CISA · CRISC · CIA · CISM · CISSP · CCISO · CEH · CC · MSc Data Science - Professional indemnity
£5,000,000 - IP
Multi-framework finding fusion across six standards · UK-built, UK-supported - Registration
ICO Reg. ZB516923 - Incorporation
Company No. 14512137 · Est. 2022
Sectors served
Insights and research
View all insights →Book a free 30-minute security review.
No pitch. One specific recommendation you can action immediately — mapped to your actual cloud environment and compliance obligations.