Overview

We are launching a Web application vulnerability assessment service and a forensic support service powered by SUGI, our own product that integrates a local LLM and our proprietary CLI AI agent into a single package. Everything runs entirely inside the customer’s environment, so data under analysis and any intermediate artifacts never leave your infrastructure to external clouds or frontier-model providers, making these services suitable even for environments handling confidential or regulated data.

  • Web application vulnerability assessment: For in-house systems under development, code assets that cannot be shared externally, and applications handling regulated data, we perform vulnerability assessments without sending data outside your environment.
  • Forensic support: We analyze and investigate incident-response evidence, logs, and malware samples on-site, with no need to take them outside.

Top screen of SUGI

Why Fully Local

Standard AI agents that call frontier models via external APIs offer high performance, but because inputs, outputs, code, and logs traverse the model provider’s infrastructure, using them in workflows that involve confidential information, personal data, regulated data, or unreleased code often runs into policy or contractual limits. In particular, vulnerability assessment and forensics work that handles customer code assets or raw incident data frequently cannot allow external data transmission at all.

SUGI runs entirely inside the customer’s environment. In the standard configuration, the host running SUGI has its network access fully cut off, and finer-grained customization is possible on request, such as allowing only search-engine access. It runs in air-gapped environments and inside networks where external communication must be strictly limited.

Typical Use Cases Where Fully Local Is Required

The services are designed for environments where the data itself is sensitive and sending it outside is not an acceptable option, such as:

  • Healthcare and pharmaceuticals: patient data, electronic health records, medical imaging, and clinical trial data governed by privacy laws and related guidelines that restrict external transmission
  • Financial institutions: account information, transaction histories, and internal audit data covered by industry regulations and supervisory guidance
  • Government, municipalities, and defense-related work: personal information, classified documents, and policy or national-security-related information subject to handling restrictions
  • Incident response and forensics: raw logs from compromised environments, malware samples, evidence of impact scope, and internal communication logs that cannot, in principle, leave the environment

What these cases share is that the data itself is sensitive and that the act of external transmission directly conflicts with regulations, contracts, or operational policy. The performance of frontier models is attractive, but adopting them in these environments is often not practical. SUGI provides an option for using AI agents in such settings without a significant drop in performance.

Performance Close to Frontier Models, Fully Local

SUGI integrates, into a single product, an LLM built on an open-weight model and tuned by us for the security domain, together with the CLI agent we have been developing for use with frontier models — harness and all. It can be used directly as a CLI, or embedded into your applications and existing workflows via an API. It embeds vulnerability-discovery and incident-analysis expertise built up through our vulnerability research, CTFs, and hands-on customer work.

Workflows that previously required a frontier-model AI agent can be reproduced end-to-end in a fully local environment. Our internal evaluations measure performance on Web application vulnerability assessment and forensics tasks close to that of frontier models, and as a concrete example, we have confirmed that SUGI can autonomously solve Pwn (binary exploitation) challenges from CTF competitions.

SUGI autonomously solving a CTF Pwn challenge

Delivery Options

The services can be delivered in either of the following forms.

  • Turnkey delivery with hardware: We build the execution platform including hardware and deliver it to the customer with SUGI pre-installed, ready to use on arrival.
  • Deployment on customer infrastructure: We install SUGI and the execution stack on servers or internal clouds prepared by the customer, fitting them into existing governance policies and network boundaries.

In either form, we design the network-access rules and their granularity, log handling, and update policy to match your requirements.

Additionally, for use cases where standard safety filters interfere with the work itself, such as offensive-perspective vulnerability research, red team exercises, and analysis of real malware samples, we may provide an Uncensored option in which the model’s safety filters are lifted. It is provided under an individual contract after we review the intended purpose, operational setup, and allocation of responsibilities.

Contact

If you are interested in using AI agents in environments handling confidential data, or in Web application vulnerability assessment and forensic support where data cannot leave your infrastructure, please contact us. We support the full path from requirements gathering to SUGI configuration design and proof-of-concept.