QDOT / cloud consulting
Multi-cloud security architecture
Fixed scope · Two weeks · Fixed fee in 48 hours

Your AI can already reach more than you think.

A two-week assessment of what your AI systems can actually retrieve, call and change — and what stops them if one account is compromised. Mapped to OWASP LLM Top 10 and MITRE ATLAS, and run by the same architect who designs the network underneath it.

what you scoped what it can also reach Your AI Your documents The wiki Support tickets Email threads Shared drives Calendar invites Vendor portals
One identity. Everything that identity can open.
5 documents planted in a knowledge base can steer a RAG system to attacker-chosen answers roughly 90% of the time

The attacker never touches your AI interface. They leave instructions inside a PDF, a web page, a calendar invite — something your pipeline retrieves on its own, later, and hands to the model as trusted context.

Your retrieval database became a trust boundary the day you turned it on. Most teams are still treating it as a filing cabinet.

This is not a new class of problem. It is least privilege, applied one layer earlier than anyone has applied it yet.

The path a poisoned document takes

trust boundary Sources you do not control A PDF A web page A calendar invite Retrieval index fetches on its own Model context trusted by default Answer or an action taken the payload is only content nothing here can tell
The attacker never touches your AI interface. Every arrow above is your own pipeline working exactly as designed. The only place to stop it is the dashed line, and most teams have nothing standing on it.
What happens

Ten working days, in four stages.

The engagement

One scope, one fixed fee, quoted in 48 hours. No discovery call required.

  • A written assessment, 20 to 30 pages, with the reasoning shown rather than a scored checklist
  • An inventory of every AI surface and what each one can reach
  • Permission-aware retrieval recommendations, specific to your stack
  • Findings ranked by what it costs to fix, not by CVSS
  • A ninety-minute walkthrough with whoever needs to sign off
  • Thirty days of follow-up questions, included
What this is not. It is not a penetration test, it is not a compliance certification, and it will not tell you your AI is safe. It tells you what it can reach and what that would cost you.
The three questions buyers actually ask
How many hours per system?
Sixteen for the first AI surface, eight for each additional one. Counted in the proposal, not discovered later.
Which attack categories?
Direct and indirect prompt injection, retrieval poisoning, excessive agency and tool misuse, and identity escalation through the agent's own credentials. OWASP LLM Top 10 and MITRE ATLAS as the reference frames.
What severity classification?
Ranked by remediation cost and blast radius, not CVSS. A finding that costs an afternoon outranks one that needs a re-architecture, and the document says which is which.
The packages

Four engagements. Each one earns the next, and you can stop after any of them.

A

The shared network

The foundation everything else sits on. Most teams never built this on purpose, which is why the AI project turns into an argument later.

  • Hub-and-spoke or transit network in one cloud, built as code so it can be rebuilt
  • Private DNS resolution, tiered — local zones, enterprise forwarding, inspected egress
  • Egress firewall with traffic inspection, sized so it does not become the bottleneck
  • RBAC and workload identity, so nothing runs on a static key

You end up with one place traffic is inspected, one place names resolve, one place permissions are decided.

What that looks like

Production Non-production AI workloads Hub transit network Egress firewall traffic inspected Internet Private DNS tiered resolution nothing leaves uninspected
Built as code, so it can be rebuilt. The point is not the diagram, it is that there is only one of each box.
B

The AI build

The workflow itself, connected to your real data and your real tools. Scoped to one job that a person is currently doing by hand.

  • Retrieval pipeline over your own documents and systems
  • The agent or workflow, with the tools it is allowed to call defined up front
  • Integration into where the work already happens, not a separate app nobody opens
  • A written handover so your team can change it without us

You end up with a task that used to take hours happening without anyone doing it.

C

The boundary

The assessment above, or the same work applied to a build you already have. This is the package for anyone whose AI is already live.

  • Every AI surface mapped, and what each one can actually reach
  • Permission-aware retrieval, so a document you cannot open never enters the prompt
  • Prompt injection tested against your own corpus, in an agreed scope
  • A written verdict, ranked by what it costs to fix

You end up with a document you can hand to whoever asks whether this is safe.

D

Ongoing

Monthly, for teams who have the first three and need someone to keep it honest as it changes.

  • Architecture review before anything significant ships
  • Changes to the network, identity or retrieval layer as the estate grows
  • A named person to argue with, rather than a ticket queue

You end up with decisions that get made once, and stay made.

Every package is fixed scope and fixed fee, written down before anything starts. Tell us which one you are looking at and you get the number within two business days.

Who does the work

An architect who also signs the invoices.

Eight years designing and securing enterprise multi-cloud infrastructure across Azure, GCP and AWS — network architecture, Zero Trust, identity federation, and the governance that keeps it from drifting.

And separately, an e-commerce business built from nothing to over $1M since 2024, with a real P&L.

That second part is the reason the verdict is written the way it is. When you own the outcome, a control nobody can follow is not a finding, it is a cost. Most engineers have never had to feel the price of their own architecture. Most owners have never been able to read one.

  • SC-100 — Microsoft Cybersecurity Architect Expert The architect-level certification, not the entry one.
  • OWASP Agentic AI — threat model in active use The public catalogue of what goes wrong with AI agents. Not a private methodology you have to take on faith.
  • Workload Identity Federation — static credentials eliminated No passwords or keys left sitting in code, where they get copied and never expire.
  • Zero Trust — hub-and-spoke, transit, inspected egress Nothing is trusted for being inside the network. Every request proves who it is.
  • Terraform · GitHub Actions — governed provisioning at scale The environment is written down as code, so it can be reviewed, repeated and rebuilt.
  • FinOps — governance across 188+ subscriptions Cloud spend kept accountable when it is spread across hundreds of accounts.
  • BGP · DNS · Palo Alto — routing and resolution design The plumbing that decides how traffic leaves your network and how names get resolved.
Start here

Four questions. If it is not a fit, the form will say so.

1 — Is AI reaching internal data today?
2 — Which clouds are in scope?
3 — Who signs off on security spend?
4 — Where to reach you

You will get a written reply within one business day, either with next steps or with an honest reason this is not the right time.