When it fits
For an AI product, agentic workflow, model integration, or AI-enabled service approaching launch, material change, scrutiny, or high-consequence use.
Foldspan
Foldspan examines models, agents, tools, data, identities, providers, infrastructure, and human control as one system, then prioritizes the controls and decisions that reduce material exposure.
When it fits
For an AI product, agentic workflow, model integration, or AI-enabled service approaching launch, material change, scrutiny, or high-consequence use.
What leadership can act on
Decide what must be redesigned, constrained, tested, monitored, or explicitly accepted before launch or material change.
How Foldspan engages
The work follows the architecture and the threat, separating observed facts, test results, assertions, inferences, and unknowns before recommending action.
What happens next
Findings can move into Secure Design Review, Targeted Security Validation, Ongoing Security Change Review, or Security Strategy & Decision Support.
What you receive
A versioned view of the agreed system, authority, dependencies, owners, unknowns, and material paths.
Makes the system and the evidence behind its security decisions visible.Credible attack, misuse, and failure scenarios tied to actor capability, evidence maturity, consequence, controls, and owners.
Prioritizes the paths that require design, mitigation, validation, or monitoring.Immediate action, longer-term changes, owners, dependencies, proof criteria, exceptions, and residual-risk decisions.
Turns the assessment into an owned technical and leadership path.Scope
Models, agents, tools, prompts, retrieval, training or reference data, APIs, identities, permissions, human approval, external providers, and supporting infrastructure.
Prompt injection, tool misuse, excessive agency, data exposure, tenant crossing, model and supply-chain compromise, insecure fallbacks, and recovery.
The controls and operating assumptions intended to prevent, detect, contain, and recover from material attack, misuse, and failure paths.
Approach
Reconstruct the agreed AI system, its data flows, trust boundaries, identities, permissions, tools, providers, and required human control.
Threat-model credible adversary, misuse, failure, and unsafe-automation paths against the actual architecture.
Assess the controls and assumptions intended to prevent, detect, contain, and recover from those paths.
Define focused validation where direct technical evidence could change the decision.
Convert the findings into priorities, design requirements, owners, evidence criteria, and operating conditions.
Working model