AI SECURITY PARTNER
Enable safe AI development,
with client trust intact
Your team already uses AI every day. Stihia adds what is missing: training that changes habits, rules people follow, and a named owner for AI security and compliance. More AI, safely.
- Training, policy, and ownership
- EU AI Act, NIS2, DORA, ISO 27001, ISO 42001
- Offensive and defensive security
AI adoption ran ahead of the rules
Three things we keep hearing from CEOs of software development companies.
AI use is scattered
Assistants, coding agents, personal accounts. Usage spread bottom-up, faster than any approval process, and nobody can say exactly where client data travels.
Clients ask for proof
Security questionnaires now ask how AI tools are governed. A confident answer takes training records, a written policy, and a named owner.
Regulation needs decoding
The EU AI Act, NIS2, and DORA carry real obligations for software companies. Decoding them is nobody's day job, and a full-time security hire rarely makes sense at SME scale.
None of this is a reason to slow AI down. It is a reason to give the adoption structure: rules people follow, evidence you can show, and someone accountable for both.
One path from AI confusion to AI control
Educate, govern, sustain. Three services that build on each other, from one partner, and the workshop is where most companies start.
AI Security Workshop
Your team watches real AI attacks live, then learns habits that keep client data safe.
AI Policy Consulting
Internal AI rules written for your tools and clients, then embedded into daily work.
Fractional Security & Compliance Officer
A named owner keeps the policy applied and answers security reviews for you.
Each step is scoped and priced on its own. Together they run as one engagement: Enable Safe AI Development.
Start in the workshop room
One session of the AI Security Workshop changes how your team treats AI tools, and it is the easiest way to see how we work.
Hands-on training for your whole team: engineers and everyone else. We show live attacks on the AI tools your people open every morning, then turn what the room just saw into daily habits: what never goes into a prompt, which tools to trust, and how to get more out of AI, not less.
- Real attacks on real tools, live in the room
- A hands-on stage where everyone attacks Stihia Zmey, our AI agent built to be broken safely
- Attendance evidence you can show in client security reviews
- Two hours to multi-day, on-site or remote, in English or Bulgarian
Theory, grounded
What an AI agent actually is, how agents fail, and what has already gone wrong in the real world. Documented incidents, not hypotheticals.
Demos on real tools
We hack current versions of popular AI tools live in the room, step by step, so the failure modes stop being abstract.
Practice on a live agent
Everyone gets a turn attacking Stihia Zmey, a real AI agent with real defenses. Whoever gets furthest takes home a medal.
Exceptionally useful knowledge shared by the Stihia team! Presentation was strict and covered AI dev practices + what devs should look for to detect AI vulnerabilities. What I truly loved about this workshop was not only the interesting content, but the interest of the dev team looking into trendy AI vulnerabilities and security approaches. Everybody's eyes were saying: Wow, I was thinking exactly "how actually this was made to happen" and the lectures clearly answered everything. After those 2 hours we got a networking session and many many people wanted to extend it more. Waiting for the next season after 3-4 months.
For the AI you ship, not just the AI you use
The journey covers how your team uses AI. If you also build AI into your own product, that product has its own attack surface, and its own path.
AI Red Teaming
Security experts attack your AI product by hand: prompt injection, jailbreaks, data leakage, agent abuse. You get reproducible findings with severity ratings, mapped to the OWASP Top 10 for Agentic Applications.
Stihia Sense
Real-time threat detection for the AI you run. Prompt injections, data leakage, and rogue agent behavior raised as alerts the moment they happen, with SIEM integration over OpenTelemetry.
The two combine into one engagement: AI Product Security & Compliance. And to feel the attacker's side yourself, play Stihia Zmey, our educational AI hacking game.
Questions we get asked
Where do we start?
Most companies start with the workshop: it needs little preparation, lands in a single session, and shows you exactly how we work. When AI use has already spread far, the policy audit can come first instead. A half-hour intro call settles it.
Do we have to buy the whole journey?
No. Each service is scoped and priced separately, and most clients start with one. The journey is the natural order, not a bundle you commit to upfront.
What does it cost?
The workshop and the policy work are fixed prices, scoped after the intro call. The fractional officer is a monthly retainer sized to your company. In every case you see the price before you commit to anything.
Will this slow our AI adoption down?
The opposite is the goal. Clear rules and an approved way to work remove the hesitation and the quiet workarounds. Teams end up using AI more, with client data protected and evidence to show for it.
Does this cover the EU AI Act and NIS2?
Yes. Policies are aligned with the EU AI Act, NIS2, DORA, GDPR, ISO 27001, SOC 2, and ISO 42001, and the workshop covers the AI-literacy obligation. Mapping which provisions apply to your company is part of the work, not your homework.
Where do you work?
We are based in Bulgaria (part of the European Union) and work with software companies across Europe. Workshops and consulting run on-site or fully remote, in English or Bulgarian. Meet the team.
Find out where you stand
Start with a half-hour intro call. Tell us how AI is used in your company today and what your clients are asking for, and we will tell you honestly what to do first. No obligation past that.