Skip to content

We test what's exposed, close it, and prove it.

Pyralink is a UK-based cybersecurity firm. We assess, harden, and red-team your infrastructure — then map findings to the frameworks your regulator expects. Senior practitioners with CISM, CISSP, CISA, CRISC, CCISO, CEH, CC credentials. £5M professional indemnity cover.

Book a security review
Product

CloudAuditX

Cloud compliance scanning platform. Read-only scans of your AWS estate with findings fused across six frameworks simultaneously. No agent, no stored credentials, no customer data leaving your account.

  • Agentless, read-only scanning of IAM, S3, EC2, VPC, CloudTrail, KMS, RDS and the rest of your AWS estate.
  • One scan, six framework views — every finding mapped to ISO 27001:2022, NIST CSF 2.0, SOC 2, CIS, MITRE ATT&CK and STRIDE at once, so a single piece of remediation closes controls in all of them.
  • Each finding carries the affected resource, severity, exploit context, remediation steps and the mapped control references.
  • Evidence packs formatted for auditors — export and hand straight over at certification or renewal.

Built for regulated SMEs on AWS that need audit-grade evidence without hiring a security team.

ISO 27001:2022NIST CSF 2.0SOC 2MITRE ATT&CKSTRIDECIS
Product

LLM Red Team & Audit Implementation

Offensive security assessment for organisations deploying AI agents, RAG pipelines and LLM-integrated systems. We attack your deployed AI the way an adversary would — then help you implement the audit controls your regulator expects.

What we test:

  • Direct and indirect prompt injection against your deployed agents and assistants.
  • Tool-access abuse and privilege escalation through the agent orchestration layer — what your agent can do that it should not.
  • RAG data leakage and retrieval poisoning across your knowledge base.
  • System-prompt extraction and guardrail bypass.
  • Excessive agency: destructive or irreversible actions reachable without human sign-off.

Every finding is mapped to the AI control set — OWASP LLM Top 10, OWASP Agentic Top 10, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001 and the EU AI Act — in a board-grade evidence pack with prioritised remediation. After you fix, we re-test the exact exploits and issue closure evidence. Our published methodology is documented in RES-05, a controlled red-team of an MCP-connected AI agent.

OWASP Top 10 for LLMs OWASP Agentic Top 10 MITRE ATLAS NIST AI RMF ISO/IEC 42001 EU AI Act
Product

Airgap AI

Secure AI deployment for sensitive workloads. We stand up LLM capability entirely inside your boundary — on-premises, private cloud or fully air-gapped — so your data never touches a third-party API.

What a deployment includes:

  • Model selection and hardware sizing matched to your workload and budget.
  • Deployment inside your network boundary — no telemetry, no external API calls, no data leaving your estate.
  • Hardened configuration, access control and audit logging from day one, mapped to your existing ISO 27001 or SOC 2 control set.
  • Runbooks, staff handover and an agreed support arrangement — your team runs it, we stay reachable.

For firms that want AI capability but cannot send client data, case files or patient records to a public model endpoint.

On-premises Air-gapped Private cloud Zero-exfiltration Priced per deployment
How we work

Scope. Test. Report. Prove.

01 — Scope

A free 30-minute review. We agree what gets tested, where the boundary sits, and what evidence you need at the end — for your board, your auditor or your regulator.

02 — Test

Senior practitioners run the assessment directly. Evidence is captured as the work happens, not reconstructed afterwards.

03 — Report

Findings with severity, exploit path and concrete remediation steps — each one mapped to the framework controls it affects, so fixes count towards certification.

04 — Prove

After you remediate, we re-test the exact findings and issue closure evidence you can hand to an auditor. Fixed means proven fixed.

Ongoing delivery

vCISO retainer — from £497/month

A senior practitioner owns your security programme: board reporting, risk register ownership, policy and audit preparation, supplier reviews and incident readiness — without the cost of a full-time hire.

Managed Security — priced per environment

Ongoing managed operations: continuous scanning, vulnerability triage, patching cadence and monthly evidence reporting. One contract, one invoice, practitioner-led.

Research

RES-05 — Red-Teaming an MCP-Connected AI Support Agent: A Proof Piece — five vulnerability classes in agentic AI, each proven by re-test.

Credentials and evidence

Every engagement is carried out by senior practitioners with verifiable qualifications and recognised professional standards.

  • Credentials
    MBA · DBA · PMP · CISA · CRISC · CIA · CISM · CISSP · CCISO · CEH · CC · MSc Data Science
  • Professional indemnity
    £5,000,000
  • IP
    Multi-framework finding fusion across six standards · UK-built, UK-supported
  • Registration
    ICO Reg. ZB516923
  • Incorporation
    Company No. 14512137 · Est. 2022
Standards mapped across engagements
ISO 27001:2022NIST CSF 2.0SOC 2MITRE ATT&CKSTRIDECIS

Sectors served
Financial Services Healthcare SaaS & Technology Legal & Professional Education

Insights and research

View all insights →

Book a free 30-minute security review.

No pitch. One specific recommendation you can action immediately — mapped to your actual cloud environment and compliance obligations.

Book a security review