Security engineering for self-hosted AI
Clear the security review on the AI you run yourself.
A customer's security review, a compliance audit, or a new AI mandate can put the AI you self-host under a bar your team isn't staffed to clear. FEDLIN builds the controls it requires in your own environment, and the evidence comes from systems that are actually running. You clear the bar, and the deal moves forward.
Partnerships Vanta MSP · Google Cloud Partner · Red Hat Partner
Where engagements start
Start with the control that's blocking you.
Every engagement is a build, priced as a fixed-fee project. Start at the blocker in front of you and scale to the full program.
Pilot Build
Start with the requirement blocking the deal. We build the fix in your environment and hand you the evidence that closes it. Fixed fee, and it credits toward the full build.
Enterprise-Readiness Build
We measure your setup against what your buyer requires, then engineer the fixes: build the controls, close the quick wins, and hand you the evidence to clear the review.
Build & Run
We build the full control set your buyers and auditors require and keep it audit-ready, mapped to whatever framework the deal runs on. Run it yourself, or we operate it as your security function.
Mandate Engineering
For defense and critical-infrastructure mandates, we engineer the controls the flowdown requires on the contractor's side: CMMC, CNSA-PQC, NERC-CIP. Delivered through teaming.
The run scales with what's at stake: Enablement (controls kept running), Assurance (a security architect in every deal review), or Stewardship (full ownership of a regulated program). Scoped to your architecture, priced on the call.
What the Build leaves you holding
The Risk Register, yours to keep.
The Build's deliverable isn't a slide deck. It's a client-owned Risk Register: every finding ranked, costed, and mapped to the frameworks you answer to, the action plan you keep whether or not the work continues with us. And the evidence holds up because the controls are running: we build and operate them in your environment, so the register is produced by the systems doing the work.
Risk Register: what's in every row
Finding
What's exposed
Surface
Where it lives
Severity
How bad
Business impact
What it costs you
Frameworks satisfied
The standards the deal runs on
Remediation + effort
The fix, and the lift
Routes to
Which program clears it
Status
Open → closed, with evidence
One fix, every framework it satisfies
The Frameworks-satisfied column projects a single remediation into whichever standard the room names. Where cryptography is in scope, a generated CBOM artifact stands as the evidence. You engineer the control once; it clears the gate in each framework it maps to.
It scopes and prices what comes next
Each finding routes to the program that closes it, and the ongoing seat is priced off what the register actually measures: surfaces, findings, and severity, quoted once the environment has been looked at.
Who you're working with
Principal-led security engineering.
FEDLIN comes out of a decade inside regulated NIST 800-53 environments: HIPAA, PCI-DSS, SOX, NERC/FERC-CIP. That experience now backs the self-hosted AI, post-quantum, and control-engineering work. Engineering-led throughout.
More about FEDLIN →Let's build your security program.
It starts with a scoping call. We map the review in front of you and scope the build from there.
Book a Scoping CallAdvisor, MSP, or agency? You keep the client and the relationship. We're the engineering arm, findings to you first. See the partner program →
Don't take our word for it
Point it at your own domain.
Run it on your own site and see your TLS and post-quantum posture the way we see ours. No signup. The scanner is open source and runs as an agent-callable tool on our MCP server.
Unable to scan
Email these results to yourself
FEDLIN receives a copy and may follow up.
Check your inbox.
This scan covers your public TLS surface only. In-boundary endpoints, firmware, code dependencies, and your full cryptographic inventory require a dedicated assessment.
scan_post_quantum at https://mcp.fedlin.com/mcp From the Blog
Latest field notes
Before the Algorithm: Where a Post-Quantum Plan Really Starts
The deadline lands and the instinct is to pick an algorithm. The plan actually starts a few phases earlier, and the hard part is the calls you make in the middle.
SPIFFE/SPIRE on OpenShift: Building the Workload Identity Plane Your Zero-Trust Model Is Missing
After locking down human and device access, pod-to-pod communication was still trust-the-network. SPIFFE/SPIRE closes that gap. Short-lived cryptographic identities, attested per-workload, chained under your existing Root CA.
Taking Inventory: You Can't Migrate the Cryptography You Can't See
A federal mandate now requires agencies to inventory the cryptography they're running, with acquisition rules written to reach the contractors who serve them — and mandate or not, you can't migrate what you can't see. My FIPS 140-3 rebuild gave me a validated floor but didn't tell me what was standing on it, so I built the tool that takes the inventory — a secret-safe capture of a live system's cryptography with the CNSA 2.0 judgment on top — against my own cluster first, then for the estates that look nothing like it. It's the first deliverable of FEDLIN's Post-Quantum Readiness service.
Frequently Asked Questions
What does working with FEDLIN look like?
Engagements start with a scoping call about your architecture and the review in front of you: a SOC 2, a HIPAA audit, an enterprise security review, or investor diligence. From there the work is a build. We measure what your buyer requires, engineer the fixes, and hand you the evidence that clears it.
We don't have a security team. Can FEDLIN run the whole program?
That's a common place to be as you grow. FEDLIN embeds as your security function: it builds the controls, wires the evidence, stands up or works within your GRC platform, and runs the program that clears the review, then keeps it clear. You get a security architect without making the hire.
What's the difference between FEDLIN and a GRC platform like Vanta?
A GRC platform monitors and collects evidence from controls that already exist. FEDLIN builds those controls: IAM configurations, pipeline gates, secrets management, infrastructure hardening, and the NIST AI RMF layer for agentic systems. When a GRC platform is in the picture, FEDLIN wires the controls so it has something real to monitor. When there's no platform yet, FEDLIN can stand one up in your environment as part of the build.
Do you work with companies building with LLMs or agentic systems?
Yes, and it is a core capability. LLM integrations, MCP servers, and agentic pipelines introduce a security surface that standard assessments are not designed to reach. FEDLIN builds the controls NIST AI RMF calls for at the infrastructure layer: context boundaries, access scoping, prompt injection coverage, and agentic audit logging, mapped to the frameworks your build operates under.
What's the relationship between NIST CSF and NIST 800-53?
NIST CSF is the framework designed for communication. It gives founders, executives, and non-technical stakeholders a clear language for security posture across five functions: Identify, Protect, Detect, Respond, Recover. NIST 800-53 is the technical control catalog underneath it, the specific controls that implement what CSF describes. FEDLIN assesses and builds to both. Every major framework, from SOC 2 to HIPAA to PCI-DSS, maps back to this foundation.
What does principal-led mean in practice?
You work directly with the principal security architect, the person who owns the architecture, the engagement, and the build. Delivery draws on a vetted partner network where scope requires it: penetration testing, specialized infrastructure work, or govtech contracting.
How does FEDLIN approach AI-native and agentic architecture specifically?
FEDLIN builds the controls NIST AI RMF calls for at the infrastructure layer: context boundaries, MCP server access scope, agentic audit logging, and prompt injection coverage, built into the SDLC. If your team is shipping LLM or agentic features on infrastructure you run yourself, this is the security surface a standard review misses.
Do you work with fractional advisors, agencies, or MSPs?
Fractional advisors, MSPs, and agencies bring FEDLIN in for the specialist work their clients need and can't keep on staff: agentic and MCP server security, self-hosted AI hardening, post-quantum cryptography, and NIST 800-53 engineering. You keep the client, the relationship, and the advisory lead. FEDLIN does the engineering, findings to you first. See the partner program for how this works.