Scams that sound like you.
Cloned-voice calls asking for a wire, AI-written phishing and fake invoices, deepfake video calls, and takeovers of email, Instagram, and Google Business accounts.
Protection from the AI attacking your business and the AI your business uses. For small and mid-size companies without a security team.
A cloned voice asks for a wire. Staff paste client files into a free chatbot. A website bot gets tricked into leaking data or making promises you are on the hook for.
In 2024, a British Columbia tribunal ordered Air Canada to honor a bereavement refund its chatbot had made up. Moffatt v. Air Canada, 2024 BCCRT 149 (opens in a new tab).
Cloned-voice calls asking for a wire, AI-written phishing and fake invoices, deepfake video calls, and takeovers of email, Instagram, and Google Business accounts.
Records, contracts, and notes pasted into public AI tools, AI apps connected to your email and files, and no written rule about any of it.
Chatbots and agents tested for prompt injection, data leaks, jailbreaks, invented prices or refunds, and requests that stall them or run up the bill.
The basics these attacks go through are covered too: email spoofing protection (SPF, DKIM, DMARC), two-step login, social account lockdown, backups, and what is exposed online. A report says what was checked and what was found. It is not a guarantee and not a certification.
Reads only public information: email records, the website, public certificate logs, known breaches, and chat widgets. Takes about 15 seconds.
Only scan a domain you own or have permission to check. Results aren't stored. Source on GitHub (opens in a new tab).
Small and mid-size businesses using AI, or being targeted with it: dental and medical offices, law firms, real estate, insurance, e-commerce, studios and shops. The checkup needs no chatbot and no IT department.
Agencies, dev shops, and startups that build AI chatbots and agents for clients. You own the code, and a prompt or model change can ship the same day, so the bot needs a tester every release.
If your bot is a vendor's widget and you do not control the code, the offer is a lighter configuration and exposure review, not a full audit.
Firewalls, help desk, and device management stay with your IT provider. This work sits next to theirs.
Healthcare providers have AI disclosure duties under Texas law, and the offer here is technical readiness testing, not legal advice.
Every check and test runs under a signed written scope and your permission. Prices are not listed here.
The starting point. An interview and a scan cover all three areas: AI scams, staff AI use, and any AI you run, plus the basics they go through. You get one report graded red, yellow, or green per area, with a plain fix list.
Callback and code-word rules for money requests, email spoofing protection, two-step login on email, banking, and social accounts, and a short staff session with a live voice-clone demo, made only with consent.
A one-page AI policy, an approved tools list, business settings that keep your data out of model training, and a review of which AI apps are connected to your Google or Microsoft accounts.
Testing against the OWASP Top 10 for LLM Applications, using garak and promptfoo plus manual testing. The pass covers prompt injection, data leaks, jailbreaks, and system-prompt leaks. You get a written report of what was tried, what failed, and what held, and a retest after you fix it. For a vendor's widget, this becomes a lighter configuration and exposure review.
A model update, a prompt change, or a new connected app can reopen something the last check closed. Retests and scans repeat on a schedule, with the same kind of written record.
Setups that keep data on your own hardware, for offices that cannot send client data to a cloud AI. The model runs on machines you control, with the serving stack hardened and the configuration written down. This is the same kind of local deployment work published in the lab.
There is no client list yet. This page does not fill the gap with testimonials or statistics.
Raúl Wesche builds, quantizes, and benchmarks frontier open models on his own hardware: a 4× NVIDIA DGX Spark cluster and a Mac Studio. The runs are published so someone else can check them, including the ones that fail.
He is currently earning the Google Cybersecurity Certificate, then CompTIA Security+, the Practical Network Penetration Tester (PNPT), and CompTIA SecAI+. None of those are finished. The free checkup above runs on his open-source scanner (opens in a new tab). Tools for chatbot testing are next.
For businesses willing to be a case study. The work is the checkup or the red-team audit above. A public write-up happens only with your approval, and only after details that identify your customers or your systems are removed. You can take the audit and decline to be named.
Send a message on X or LinkedIn: what you do, which AI tools you or your staff use, and what worries you. That is enough to say whether a checkup is the right first step.
Security testing by Raúl Wesche, Houston. This page is not a law firm and not legal advice.