AI Security & Development

We build the AI systems we secure

Graystone is a team of senior security and AI practitioners. We harden the systems you already run and build the ones you don’t.

Most firms advise on AI security. We write the code as well, which means our advice has to survive contact with a real system.

PracticeAI Security & Development
Years Operational2013 — Present
Flagship PlatformIn Development
What we do

Three practices — for your organization, and inside ours

AI Security & Governance

Your board wants to know the exposure, your auditor wants policy, and your engineers have already shipped something.

  • Risk assessment for AI systems already in use
  • Governance policy and model-handling procedure
  • Data-flow review: what leaves your control, and to whom
  • Defense against AI-assisted attack

Assessment & Architecture

Two decades of building and defending regulated environments, applied to yours.

  • Security posture assessment, remediation in priority order
  • Vulnerability assessment and guidance
  • Architecture aligned to your compliance obligations
  • Incident response planning, written before you need it
  • Third-party and vendor risk review

Secure AI Development

For organizations whose data needs to stay in their own hands.

  • Self-hosted models on infrastructure you control
  • Architectures where you hold the keys and we hold nothing
  • Document handling and retrieval over your own store
  • On-device and on-premise processing where the workload allows
How we build

The architecture is the argument

These are design decisions, not aspirations. Each one has a cost, and we state the cost. What we build for you is your product, on your terms — we advise, and you decide.

01

You hold the keys

Content is encrypted on your device or your hardware, under keys generated there. We operate no key escrow and keep no copy, so there is nothing for anyone to compel us to produce. Keys are exportable: back them up, and moving to new hardware means importing them back.

02

You decide where your data goes, and you can see it

Our own systems run open-weight models on infrastructure we operate, and that is the default we build toward. If you want a commercial provider in the path, we will integrate it and document exactly what leaves your environment, who receives it, under whose terms, what they may retain, and how you revoke it. The choice is yours to make. What we will not do is make it quietly.

03

Processing where the data lives

Where the workload allows it, inference runs on your own hardware. Where it does not, it runs in our environment, on your explicit instruction, for the duration of that operation and no longer.

04

Nothing is trained on your content

Not by us, and not by anyone operating infrastructure for us. There is no opt-out to find, because there is nothing to opt out of.

Who you work with

The people who scope the work are the people who do it

Caleb Crable
Product Security Officer — Red Team

Offensive security and red team engineer with roughly fifteen years in the field, now a principal AI red team engineer. He has run red teams at BILL, Verisign, and Cylance, with a background in malware analysis and incident response.

Allen D. Duck
Chief Product Officer
PMPPMI-ACPCIPM (IAPP)

Technical product management leader with more than twenty years building secure SaaS products in data privacy and security. He has led product teams at Spirion and GFI, co-founded a startup, and served in the Army National Guard.

Brandon M. Hanes
Founder & Chief Information Security Officer
CISSPCBITOCBCSMCBISO

A decade as CISO of a regulated financial institution: board reporting, state and federal examinations, GLBA and GDPR alignment, vendor risk, disaster recovery. Before that, malware incident response and federal threat-intelligence platform engineering. Writes the code today.

Michael Sellers
Chief Mercenary Officer — Regenerative Operations
Dual KatanaHealing FactorFourth-Wall Clearance

Full-lifecycle mercenary with an accelerated healing factor and decades of survived field experience. Fluent in most languages and every firearm, he is aware he is a placeholder and would like his real bio sent in.

Dr. Amanda Walker-Hanes
EdD · Director of AI Ethos & Ethics

Two decades in education, curriculum design, and teacher preparation, now applied to how AI systems are trained and how they behave. Model conduct is a curriculum problem before it is an engineering problem, and it is treated here as a discipline rather than a policy page.

You will not be handed to a junior analyst working from a playbook.

Plainly

What we will not tell you

We will not tell you we can prevent a breach. No security professional can, and our Terms of Service say so in writing rather than in the small print.

Where we came from

Thirteen years, one deliberate turn

2013

Founded as a managed IT services firm, serving healthcare, small business, and regulated environments.

2026

Stopped managing infrastructure. Moved to securing and building AI systems.

The managed services years are why the security work lands. We know how business IT is actually assembled, including the parts nobody documented.

Talk to us

Tell us what you are running, and what is worrying you

If we are not the right people, we will say so and tell you who is.

Graystone Solutions — We build the AI systems we secure