SECURITY ASSESSMENT

Security for the
AI and cloud era —
from assessment to remediation.

AI agents, web apps, APIs, cloud, and GitHub — we review the risks in the environment you already run, prioritize them, and support remediation without slowing development down.

Aligned with OWASP Top 10 /OWASP LLM Top 10 /CIS Benchmark
CHALLENGES

Do any of these sound familiar?

We support the full path from assessment to remediation.

We want AI at work, but worry about data leaks

Moving forward without checking AI-specific risks such as prompt injection and data exfiltration paths feels unsafe.

Our PoC cannot move to production

The prototype works, but unresolved security concerns keep the production decision on hold.

Unsure about cloud and GitHub permissions

IAM and repository permissions have never been reviewed systematically, and it is unclear whether they are safe as they are.

FOR — A good fit if you are
  • A company about to move AI into production work that needs a security review first
  • A company with 10–100 people and no dedicated security role
  • A SaaS company or startup running public web services or APIs
  • An agency or AI consultancy whose client projects require security compliance
SCOPE

What we assess

From AI agents to the cloud, Kubernetes, and GitHub foundations beneath them. Assess only the areas you need.

01 FEATURED

AI security assessment

We review AI agents, RAG, MCP, and internal AI chat against the OWASP Top 10 for Agentic Applications / OWASP LLM Top 10.

  • Prompt injection and data exfiltration paths
  • Over-privileged agents (excessive tool access, authorization design)
  • Supply chain risks in MCP and external tool integrations
  • Missing logs and audit trails
02

Web / API security assessment

We review web apps, admin consoles, and public APIs against the OWASP Top 10 / OWASP API Security Top 10.

  • Authentication, authorization, and session management
  • Input validation and injection defenses
  • Rate limiting and API key management
03

Cloud security assessment

We review AWS, Google Cloud, and Alibaba Cloud configurations based on the CIS Benchmarks.

  • IAM (permission inventory, least privilege)
  • Network and storage exposure settings
  • Logging, encryption, and audit settings
04

Kubernetes / container assessment

We review cluster and container runtime settings for permissions, isolation, and exposure.

  • RBAC, secret management, NetworkPolicy
  • Container images, Ingress, Pod Security
05

GitHub / DevSecOps assessment

We review the development flow from repositories through CI/CD and deployment, focusing on permissions and supply chain.

  • Repository permissions and branch protection
  • GitHub Actions workflow permissions and secrets management
  • CI/CD deploy permissions and supply chain defenses

This assessment is centered on reviewing configuration, permissions, and design.It is not an offensive test against live environments (penetration testing). We combine reviews of architecture, settings, and code with tool-based scans where useful, so it can run against services in development or in production without impact.

PROCESS

How the assessment works

The initial consultation is free. We review your current situation and propose the right scope and approach.

01
Free

Consultation

We review your system architecture, cloud usage, AI usage, and development structure.

02

Scope definition

We propose which areas to assess: AI, web/API, cloud, Kubernetes, or GitHub.

03

Security assessment

We review settings, permissions, logs, authentication, and development flow.

04

Report and debrief

We deliver a risk list ranked by impact and priority, and walk you through it.

05
Optional

Remediation support

We support configuration changes, code fixes, CI/CD improvements, and AI usage guidelines.

DELIVERABLES

We do not stop at
pointing out problems.

Beyond flagging issues, we organize where to start and how to fix each one before handing over.

  • Security assessment report (risk list with impact and priority)
  • Remediation checklist and roadmap
  • Debrief session with Q&A
  • Configuration and implementation support where needed
TRUSTRAY — Security Assessment Report
FINDINGS — by priority
HIGH Agent tool permissions are too broad AI-04
HIGH Storage is publicly accessible CLD-02
MED Branch protection is not configured GH-01
LOW Audit log retention is too short CLD-07
Every finding comes with how-to-fix steps
PLAN

Assessment plans

We review how you use AI, web, cloud, and GitHub / CI/CD today, then propose the scope that fits best.

LIGHT

Light assessment

Focus on a single area and review its main risks.

Scope
A focused review of one area
Best for
Companies that want to start by checking part of their risks
Deliverables
  • Summary assessment report
  • Key risk list
  • Remediation checklist
Ask about the Light plan
STANDARD Recommended

Standard assessment

Combine multiple areas such as web / API, cloud, and GitHub.

Scope
A standard review combining 2–3 areas
Best for
Companies ready to review their development and cloud environments properly
Deliverables
  • Assessment report
  • Prioritized remediation list
  • Recommended response policy
Ask about the Standard plan
FULL

Full assessment

A cross-cutting review of AI, web, API, cloud, Kubernetes, and DevSecOps.

Scope
A comprehensive review across the whole stack
Best for
Companies reviewing AI adoption, cloud operations, and the dev platform together
Deliverables
  • Detailed assessment report
  • Remediation roadmap
  • Implementation support where needed
Ask about the Full plan

We start by reviewing your current situation and propose the right scope and approach.

WHY TRUSTRAY

What makes Trustray different

Few assessment services can cover both AI security and cloud security in one engagement.

01

AI and cloud, assessed together

We review AI-agent-specific risks and the cloud, Kubernetes, and CI/CD foundations beneath them in a single engagement.

02

Alibaba Cloud support

We also assess Alibaba Cloud configurations — still rare in Japan. Ask us about services for the Chinese market as well.

03

We do not slow development down

Instead of ideal-but-impractical controls, we propose prioritized improvements your current team can realistically adopt.

04

Beyond the assessment

We do not stop at the report. We stay with you through configuration changes, implementation, and operational guidelines as needed.

Standards and reference frameworks OWASP Top 10OWASP API Security Top 10OWASP LLM Top 10OWASP Top 10 for Agentic ApplicationsCIS Benchmark

Start by understanding where you are.

If you have concerns about the security of your AI, web apps, APIs, cloud, or GitHub environment, get in touch. The initial consultation is free — we review your situation and propose the right scope and approach.