Human factors consulting
Find the behaviours, incentives and decision points that make otherwise robust security controls fail.
SanRa helps organisations secure the human and artificial intelligence systems they depend on.
Talk to usTechnology succeeds only when people can use, challenge and govern it with confidence. Our work joins behavioural insight with technical cybersecurity.
Find the behaviours, incentives and decision points that make otherwise robust security controls fail.
Practical readiness for ISO/IEC 27001, ISO/IEC 42001 and related management-system programmes.
Probe AI systems and tooling for prompt injection, leakage, malicious models and rogue agent behaviour.
Security is not a feature you bolt on. It is a relationship between a system, its people and the decisions they make.
Three questions. A useful starting point. No data is retained unless you choose to contact us.
Your signal
Open the FIDO framework Open the ISO 27001 framework Open the ISO 42001 framework Discuss your result with a specialistThis indicative assessment is educational only. It is not an audit, certification or compliance determination.
FIDO
FIDO2, WebAuthn and passkeys — policy, recovery, IdP rollout and assurance evidence in one interactive framework.
Open the frameworkISO/IEC 27001
Interactive clause framework for information security management — scope, risk, SoA and operational evidence.
Open the frameworkISO/IEC 42001
Decisions, evidence and operating disciplines behind an AI management system — plus an interactive clause framework.
Open the framework Download readiness guide ↓WP-01
SanRa thought leadership on human factors and security in the age of AI-augmented systems.
Download whitepaperClosed-source safety library: jailbreak heuristics, ethics policy packs, and output gates. Pair with open-source Open Bastion.
Score bot risk from Cloudflare bot scores and request signals. Studio plus an open Worker starter.
Heuristic synthetic-media risk from EXIF gaps, artefacts, and claim conflicts. Honest limits, local studio.
ZTNA, SWG and CASB decisions in one studio — SanRa’s take on the converged edge category (inspired by platforms like Cato; not affiliated).
Brain-inspired spatial reasoning for robots: Somatic Place Graphs and hippocampal affordance replay, with a local Embodiment Bus so tools join as senses and effectors.
Model three minds: North Korean hacker, Russian hacker, and the usual consumer. Rank messaging that hits — and the breaches they’d sniff for, with or without AI.
Free WhiteHat desktop app for AI-era codebases. Visualise architecture as a 3D code metropolis and surface vulnerability signals — locally, on your machine. Not open source.
Collect discipline-scoped cybersecurity data and run local inference against Foundation-Sec, Antares, and other OpenAI-compatible endpoints. MIT licensed.
Open subset of SanRa’s AI-safety prompt gating. For the full ethics packs and studio, use closed-source Bastion.
Free, offline AI-security scanner: prompt injection, secrets leakage, malicious models, phishing lures, and rogue agent actions. MIT licensed. Your data never leaves your machine.
MIT Pages/Workers middleware patterns for basic bot friction. Pair with proprietary Botglass for full scoring.
SAN-101 builds judgement with AI in the loop. SAN-102 closes the data risks of using AI. Free online for now — not CPD or (ISC)² accredited.
CREST Certified in
Cybersecurity Training
EC-Council & Proofpoint certified
Guest lecture at SANS
Erasys Ltd.
TAAM Open Source
Anti-Body · Drillwright · Open Bastion
Read our privacy notice.