AI security consulting

Security for AI agents with real access.

Mostly Harmless is a specialist AI security consultancy. We review, test and design agentic systems: the agents, the tools and credentials they use, and the infrastructure they run on.

An untrusted email reaches an AI agent with access to a database, email and payments. A security consultant maps the paths and places an approval control before the payment step.
Untrusted input Agent with access Control before the action

03 · How an engagement works

Three steps, no mystery

  1. Scope

    We agree on the system, the decision you need to make, and what must not happen. This is usually one call.

  2. Assess

    We map the system, follow the authority the agent holds, and test the paths that matter. Findings come with evidence, not speculation.

  3. Hand over

    You get a report, prioritised fixes and, where useful, tests that keep the fixes in place. We stay available for questions afterwards.

04 · About

A small, specialist practice

Focus
Security of agentic AI systems
Led by
Dr. Stefan Beyer · LinkedIn
Working with
Teams worldwide, remote and on site

Mostly Harmless is the AI security practice of Dr. Stefan Beyer. We work with product, engineering and security teams that are shipping agents with access to data, tools and money, and with companies adopting agents in their own operations.

The work connects three things that are usually done separately: threat modelling and architecture, adversarial testing, and the operational controls that keep a system defensible after launch. We also teach, and we publish the methods we use.

The name is a Hitchhiker's Guide reference. The aim is a system that stays mostly harmless when one of its assumptions fails.

05 · Contact

Get in touch

Tell us what you are building and what you need to decide. We will suggest the smallest engagement that answers the question.

info@mhl42.ai

By sending this message you agree to our privacy policy. Messages are delivered to our inbox via Resend.