Skip to content
offbyquant_
independent security consultancy & research — est. 2026

AI Security.
Security through AI.

Securing AI systems and agents — and building agentic systems that do security work at scale.

drydock-cli  2.9.32  ·  PyPI  ·  new publication ■ flagged by pyDiffWatch
+ 7,000+ lines crammed into a single file
+ obfuscation · fetch + exec primitives
+ credential + network access at install time
  triage score 16,400 → local reviewer: malicious · 95%
  reported → removed from PyPI

Two mandates. Stated as two things.

Most firms do one or the other.

01

AI Security

Securing AI systems, agents, and the software teams are shipping with them — agent architectures, tool and MCP surfaces, prompt-injection and data-exfiltration paths, and the trust boundaries between a model and the systems it can act on.

02

Security through AI

Using AI and agentic systems to do security work that was previously too slow or too manual to do at scale — detection pipelines, static analysis, and review harnesses built for a specific codebase.

What we take on

Findings trace to code paths, with a reproduction and a patch — not a scanner export with severity labels attached.

ai-security-review

AI security review

Assessment of AI systems in production: agent architectures, tool and MCP surfaces, prompt-injection and data-exfiltration paths. For teams shipping agents, not for teams writing AI policy documents.

appsec-assessment

Application security assessment

Source-driven review of web applications and APIs. Findings trace to code paths, with a reproduction and a patch.

supply-chain

Supply chain & dependency security

Detection of malicious and compromised packages in PyPI and npm, informed by current research into how scanners are evaded — cross-file splitting, directory relocation, and related techniques.

vciso

vCISO & security risk management

Fractional security leadership: risk scoring models, lifecycle definition, gap analysis against existing policy, and the reporting that makes risk legible to a board. Delivered at enterprise scale for organisations with existing policy landscapes.

tooling

Security tooling & automation

Custom static analysis, detection pipelines, and agentic harnesses built for a specific codebase or workflow — where an off-the-shelf tool doesn't fit the shape of the problem.

secure-by-design

Secure by design programmes

Security built into how a team ships, not bolted on after: threat models and policies written with the developers, a suggested fix on every finding, the workflow living in the same board as the sprint. Proven over an 18-month enterprise engagement at zero commercial tooling cost. The heavy lifting that made it labour-intensive then — context-aware review, dependency mapping — is what we now automate with AI.

Registered 2026. A decade behind it.

OffByQuant was registered in July 2026, but the practice behind it is ten years of security consulting — leading engagements and consulting teams for enterprise clients. Based in India, working with clients and partners across EMEA & APAC.

10+
years consulting
2
public research tools
EMEA·APAC
client regions

fixes, not findings · policies written with, not for · findings live where the sprint lives

the thinking behind this → uncategorized.blog · On Consulting

Start a conversation

No forms. No newsletter. Just email.

contact@offbyquant.com