Somebody in your organization is pasting documents into a chatbot. Somebody built a form with AI-written code. Somebody connected an assistant to the shared drive. None of that is wrong — but no one has written down which tools exist, what data they can touch, or whether the vendor trains on what you send. We do that, and then we fix what it turns up.
Read-only assessment · Fixed scope · Call or text (940) 281-6672
A July 2026 study scanned 549 public repositories that identified themselves as AI- or "vibe"-coded. Among the 467 substantial ones: 48.8% had injection-category flaws, 30.2% had a critical or high-severity finding, and 23.3% exposed a secret. The most common single issue was unescaped HTML rendering, in 43%.
Two caveats we will give you before you ask, because we would rather you trusted the rest: the study capped findings at 300 per repository, so the worst offenders are under-counted; and the sample includes small demo projects, which flatter the average. The authors' own reading is that real applications score worse. We cite it because it is measured, not because it is scary.
.env files, hardcoded credentialsWe run an AI system against other people's email every day. That means we have had to answer, for ourselves and in writing, the exact questions we will ask you: which model provider, does it train on inputs, what does the model see, what does it never see, who approves an action before a human is contacted, and what happens when it is wrong.
Our own answers are on our Trust page and our Privacy policy. We think an AI security assessment from someone who has not had to answer those questions about their own product is worth very little.
The large agent-governance platforms now being funded are real and good — and they are built for enterprises with a SecOps team, an IAM team and a platform team. If you have those, buy one of those. If you do not, the useful thing is a person who inventories what you have, tells you what to turn off, and writes it down. That is this.
Thirty minutes, free. We ask what your staff are using and what it can reach, and tell you honestly which of these is worth doing — or that you are already fine.
Schedule a scoping sessionOr call the Security Architect directly — (940) 281-6672