SBA Certified SDVOSB | FL Certified Business Enterprise | SAM.gov Registered | MFMP Vendor
Flagship Practice

AI Security and Assurance for the Systems You Are
Trusting With the Mission

Organizations are shipping large language models and AI agents into production faster than they can secure or govern them. Waypoint does both. We prove your AI is safe enough to defend in front of a regulator or a board, and we attack it the way an adversary would, before an adversary does.

Two Questions Every Organization Deploying AI Now Has to Answer

Can you prove it is safe enough? And do you actually know whether it can be broken?

Most vendors answer one. Waypoint answers both, because they are the same problem seen from two sides. The governance program that satisfies your auditor is only as honest as the red team that tested what it claims. We run both sides in-house, and we build the tooling that keeps them true after we leave.

Two Tracks, Run In-House

Engage either side on its own, or both together where the assurance argument has to survive the attack.

Track 1: AI Governance and Assurance

For regulated organizations adopting AI. Prove your AI is safe enough, in the language your auditor, your customers, and your board already speak. We assess the risk, build the program, and produce the evidence.

  • AI risk assessments aligned to the NIST AI Risk Management Framework and its Generative AI Profile
  • Governance programs, acceptable use policy, and control frameworks
  • ISO/IEC 42001 readiness, the first certifiable AI management system standard
  • EU AI Act readiness for organizations in scope
  • Assurance cases: a defensible argument that a system is safe enough for its use, not a checklist
  • Evidence automation, so compliance is sustainable instead of a one-time scramble

Track 2: AI Red Team and Evaluation

For security teams and the people shipping AI. Find out how it breaks on your terms, before an attacker finds out on theirs. Hands-on offensive testing of your LLM and agent systems, mapped to the frameworks the field actually uses.

  • LLM and agent red teaming: direct and indirect prompt injection, jailbreaks, guardrail evasion
  • Data exfiltration and unauthorized action through tool-using agents
  • Tool and agent containment and least-privilege testing for autonomous systems
  • Evaluation harness builds: evaluation as a security control, not an accuracy metric
  • Mapped to the OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications, and MITRE ATLAS
  • Findings delivered as a defensible report your team can act on and reproduce

Train Your Team to Red-Team Their Own AI

We deliver private, hands-on AI security workshops for security teams and AI builders. The same methodology we use on engagements, taught against realistic targets in a controlled environment, so the capability stays in-house after we leave.

Half-day to multi-day, scoped to your stack and your team's level. Your people leave able to threat-model, red-team, and evaluate the LLM and agent systems you are already running.

Ask About a Workshop

We Did Not Add AI to a Compliance Shop.
We Built the Field's Body of Knowledge.

AI security is not a bullet we appended to a services list. Waypoint's founder authored a full doctoral-level curriculum for applied AI security and assurance, with the security discipline as its spine rather than an afterthought, grounded in the same frameworks we bring to your engagement.

Pillar

Applied AI Security and Assurance: the full curriculum

A doctoral-level curriculum authored by Cameron Hopkin, CISSP. Seven cores spanning mathematical foundations through adversarial machine learning, LLM and agent red teaming, secure AI engineering, and AI governance. Published as a reference, with the verified market gap and citations.

Core 5: LLM and Agent Security, the full syllabus

The deepest artifact in the set. Fourteen weeks of prompt injection, jailbreaks, guardrail evasion, agent containment, and evaluation harnesses that function as security controls, with outcomes, assessment weighting, capstone rubric, and ethics policy published in full.

The hands-on companion. Before either of those, there is a free one. The AI Security Lab is a 36-week open-source path for practitioners moving into this field, MIT licensed and open to pull requests. It is the on-ramp; the curriculum above is the same ground at depth.

Credentials that back it

CISSP, CEH, CHFI, with 21 plus years across federal, defense, healthcare, and commercial security

U.S. Navy veteran. SBA Certified Service-Disabled Veteran-Owned Small Business

Selected to speak on AI security at ISC2 Security Congress 2026

Builder, not just auditor: we ship the automation and the tooling ourselves, so what we build for you keeps working after the engagement ends

What You Can Engage Us For

AI Risk Assessment

Aligned to NIST AI RMF and ISO/IEC 42001.

LLM and Agent Red Team Engagement

Structured offensive testing against your live systems.

Evaluation Harness Build

Evaluation that operates as a security control.

AI Governance Program and Acceptable Use Policy

The program and the policy, built to be defended.

Private AI Security Workshop

Hands-on training scoped to your team and stack.

Fractional AI Security Leadership

Folded into a vCISO retainer.

Deploying AI Into a Controlled Environment?
Let's Make Sure It Holds.

Schedule a free 30-minute consultation. We will talk through what you are shipping, where the risk actually sits, and whether you need the governance side, the offensive side, or both.

or email directly at [email protected]