The free CBOM scanners read Java, Python, Go and npm — not C#. So a .NET estate cannot self-serve an answer to the only question that matters: where does quantum-vulnerable cryptography actually live in our code? We answer it with Roslyn-based semantic analysis of your C#, then design the migration.
The engagements: a free scan of one .NET repository · Cryptographic Discovery, one application in 3 days · the Cryptographic Baseline Audit, your full estate in 4 weeks · the Cryptographic Assurance License, keeping new quantum-vulnerable crypto out of your pipeline after the audit.
Two questions, two engagements. Where is our IP leaking into AI tools? is a diagnosis. What can our AI systems actually be made to do? is assurance, and it needs hands-on testing.
The AI Sovereignty Diagnostic — 2 weeks. Shadow AI footprint, prompt-layer exfiltration paths, and GDPR and EU AI Act gaps, plus the Zero-Knowledge architecture blueprint: local LLM orchestration, private GraphRAG indexing, and prompt-level redaction that keeps corporate IP inside your perimeter.
The AI Security Baseline Audit — hands-on adversarial red-teaming of your live deployment under a signed authorization-to-test, with control testing evidenced against NIST AI RMF, the EU AI Act and ISO 42001. Two fixed-fee tiers, scoped by what your system can access, call and trigger.
Secondary to the two practice lines above, and deliberately so. Four courses — AI Security, AI Ethics & Privacy, AI Governance, and Post-Quantum Cryptography — taught by the architect who audits these systems, most often bought by a team that has just seen its own gaps in an audit report.
How it is bought: as a private cohort for your engineers, or as a line item on a Baseline Audit. Fixed fee per seat, no hourly billing.
Apply for a strict 15-minute qualification call to discuss your architectural intervention.