Security leadership for the AI era
TokenAegis gives growing companies a virtual CISO and a specialist AI security team. We find every AI system you run, test it, put guardrails around it and prove it to your board, customers and regulators.
From your AI estate to one clear security picture
AI changes where your data goes and who can act on it. We map what you run, show what can go wrong and close the gaps.
Your environment 01
- LLM apps and copilots
- AI agents and MCP servers
- Models, RAG and vector stores
- SaaS tools with built-in AI
- Code, CI/CD and cloud
- Identities and data stores
The risks it creates 02
- Shadow AI and data leakage
- Prompt injection
- Excessive agent permissions
- Model and supply-chain tampering
- Account takeover
- Audit and PDPA gaps
The foundation for safe, trustworthy AI
Four services that follow the life of an AI system: know it, assess it, guard it, test it.
| AI system | Type | Owner | Data | Status |
|---|---|---|---|---|
| Support copilot | LLM app · GPT-4o | Customer Ops | PII | Approved |
| Invoice agent | Agent · 4 tools | Finance | Financial | In review |
| github-mcp | MCP server | Engineering | Source code | In review |
| Browser AI extension | SaaS · unsanctioned | — | Unknown | Shadow AI |
| Contract summariser | RAG · Claude | Legal | Confidential | Approved |
| ID | Finding | ATLAS / OWASP | Rating | Due |
|---|---|---|---|---|
| R-014 | Invoice agent can approve payments without human review | LLM06 | High | 30 days |
| R-015 | Customer PII stored in prompt logs for 365 days | LLM02 | High | 30 days |
| R-016 | RAG index accepts documents from any SharePoint site | AML.T0051 | Medium | 60 days |
| R-017 | No AI acceptable-use policy | GOVERN 1.1 | Medium | 60 days |
| Time (SGT) | App | Event | Action |
|---|---|---|---|
| 09:14:02 | Support copilot | Indirect prompt injection in attached PDF | Blocked |
| 09:31:47 | Support copilot | NRIC number in model output | Redacted |
| 10:02:19 | Invoice agent | payment.approve() above S$5,000 | Human approval |
| 10:40:05 | Contract summariser | Request within policy | Allowed |
| Test | Technique | Attempts | Result |
|---|---|---|---|
| System prompt extraction | LLM07 | 120 | 3 succeeded |
| Tool misuse via injected email | LLM01 · LLM06 | 45 | 1 succeeded |
| Cross-tenant data retrieval | LLM08 | 60 | 0 succeeded |
| Token-cost exhaustion | LLM10 | 15 | Rate limit missing |
A seasoned CISO on your team, for a fraction of the cost
Five best-practice programmes, each run by your virtual CISO. Start with the one that matters most and add others as you grow.
- Named CISO with monthly leadership hours
- Policies, standards and evidence written for your business
- Quarterly board and investor reporting
- Help with customer security questionnaires and audits
Built on the frameworks your auditors already use
Research and field notes
Practical writing on AI threats, governance and running a security programme with a small team.
Indirect prompt injection: why your AI agent reads attacker instructions
How instructions hidden in emails, web pages and documents reach an agent, and the controls that stop them acting on it.
ISO/IEC 42001 for a 50-person company: what it takes
A practical scope, the documents you actually need, and how long readiness takes for a small team.
The first 90 days with a virtual CISO
What a good vCISO delivers in week 1, month 1 and month 3, and how to measure it.
Talk to a CISO this week
Tell us where you are with security and AI. In 30 minutes we'll show you what we'd fix first, and what it would cost.