A boutique AI-security studio

AI security, measured.

Your AI can be talked out of its rules, tricked into leaking data, or driven to act without permission. We measure exactly how — built by people who work both sides of the threat surface — and tell you plainly what we found. Deep security expertise, not a checklist.

Capabilities

What we do.

Secursion is a security studio first. We go past the checklist, verify the claims other people take on faith, and report what we find plainly — across AI systems and the environments they live in.

01 · AI-Augmented Analysis

AI Security Review

Automated threat modeling, architecture analysis, and code-level vulnerability discovery. We train on attack patterns, not compliance checklists — and we surface what automated scanners miss.

02 · Federal-Grade

Compliance Automation

Federal framework alignment — NIST 800-53, FedRAMP, CMMC 2.0, plus OWASP LLM Top 10 and the EU AI Act — through policy engines that understand context, not just controls. Fewer gaps. Faster authorization.

03 · Adversarial

Penetration Testing & Reporting

Adversarial testing with attacker mindset and auditor discipline. Red-team depth, federal-grade documentation. We find the vectors before your adversaries do.

Selected Work

Field Notes.

A sample of the work our principals have led — anonymized to protect client confidentiality. The pattern is consistent: we go past the checklist, verify the claims others take on faith, and report what we find plainly.

Vendor Evaluation · Enterprise Security

Debunking an "AI-powered" security appliance

A client was weeks from a six-figure purchase of a network-defense appliance marketed as an AI-driven intrusion-detection and honeypot system. We ran an independent black-box evaluation: hardware teardown, live traffic capture, and claim-by-claim verification. The device was a repurposed embedded PC running an operating system that had reached end-of-life years earlier — we bypassed its proprietary lockout to gain administrative access, and showed its "threat detections" were ordinary internet background noise.

Outcome: the client walked away from a costly purchase built on security-through-obscurity.

Red Team · Defense & Engineering

Full-scope red team against a defense contractor

Reconnaissance mapped an attack surface far larger than the client realized — including a forgotten subdomain vulnerable to takeover and a typo-squatted look-alike domain already serving malware to employees. A tailored spear-phishing campaign, built entirely from open-source intelligence, tested the human layer. Every finding was disclosed responsibly, with remediation guidance.

Outcome: live external exposures identified and closed before an adversary reached them.

Federal · Connected-Vehicle Security

Data-at-rest risk in a federal vehicle fleet

Modern vehicles are data-generation machines on wheels — retaining location history, paired-phone contacts, and cached credentials long after a driver walks away. For a federal fleet program, we assessed whether existing "wipe" and "factory reset" tools actually removed that data. They didn't. We delivered an operational-impact analysis and a phased data-sanitization roadmap.

Outcome: a previously unaddressed data-exposure gap closed across a 20,000+ vehicle fleet.

Internal Assessment · Operating Company

The network defended only by factory defaults

An on-site assessment of a regional operating company found its entire network fronted by ISP gateways still using published factory-default administrator credentials — the only thing standing between the open internet and a flat internal network of workstations, cameras, and access-control systems. We inventoried the environment and delivered a segmentation, firewall, and hardening plan.

Outcome: a trivially-breachable perimeter replaced with a defensible, segmented architecture.

Experience we bring

Secursion is boutique, but its principals didn't start yesterday. Between them, our team's prior security, research, and compliance work spans federal agencies, national laboratories, and Fortune 500 enterprises. These reflect the individual track records our founders bring — not client endorsements.

Oak Ridge National Laboratory PwC KBR Ford U.S. Dept. of Homeland Security
Why Secursion

Credibility you can't fake, velocity you can't hire.

The name is a portmanteau of security and recursion — signal intelligence that thinks in layers.

Named operators, not a logo

You work with the principals directly — an ex-Fortune 500 CISO with top-secret clearance serving federal contractors, and the engineer who builds the tooling. No account layer, no handoff to juniors.

Practitioners, not presenters

Behind the method is a boutique team of federally-cleared researchers — including patent-holders in security architecture. This isn't a consultancy that added an AI layer, or an AI company that discovered security. It's the real thing, combined.

Honest findings, on principle

We strip false positives before you ever see them. A page full of red is a sales tactic; an accurate picture of your risk is an asset. We give you the accurate one.

Framework-mapped by default

Every finding maps to OWASP LLM Top 10, the EU AI Act, SOC 2, and NIST AI RMF — so what we hand you is also compliance evidence.

Full-spectrum capability

Offensive red-team and pen testing, defensive detection and malware analysis, hardware / RF / embedded research, and federal compliance — under one roof, from the same principals.

Boutique by design

We don't scale by diluting expertise. Every engagement involves principals — the people who built the capabilities, not a team trained to present them.

The Founders

Who you'll be working with.

Secursion is boutique on purpose — you work with the people who built it, not a team trained to present them.

Noah Schiffman

Founder · Chief Security Officer

A former Fortune 500 CISO and security consultant holding top-secret clearance in service of federal contractors. Decades on both the offensive and defensive sides of enterprise and federal security — red teaming, malware analysis, hardware and RF research — and the standards Secursion's assessment work is built on.

noah@secursion.ai

Jimmy Ardis

Founder · Product & Engineering

The builder behind Secursion — a federal compliance consultant who turns security methodology into shipping software: the adversarial attack harness, the reporting engine, and the tooling our assessments run on. Deep security domain expertise, paired with someone who actually ships.

jimmy@secursion.ai
Engage

Serious work
starts here.

Tell us what you're building and what you're worried about, and we'll tell you straight whether it's something we should look at. We work with federal contractors, security teams, and technology leaders navigating the new attack surface AI introduces.