Applied AI — cyber security

Applied AI for cyber security — engineered, not improvised.

Claude-powered AI for security and risk teams, engineered and delivered on Google Cloud — built by a firm that runs a cyber risk practice, not adapted from a general one.

Agentic security workflows

Anthropic's Claude reading live security data and producing the artefact your team has to file — a vendor decision, a triage order, a board briefing — with the evidence trail attached.

Third-party risk at machine speed

Portfolio-wide vendor triage, CVE exposure sweeps and pre-contract due diligence built on Bitsight's measured data rather than on questionnaire answers.

Engineered on Google Cloud

Deployed in your own Google Cloud environment with enterprise controls — the same design-and-architecture rigor we bring to cyber risk.

Discuss an AI engagement See our open-source plugin
In short
BitScore's Applied AI practice builds Claude-powered systems for cyber security work — third-party risk, exposure triage, framework evidence and board reporting — deployed inside the client's own Google Cloud environment under their existing enterprise controls. BitScoreCoWork, our MIT-licensed Claude plugin for the Bitsight API, is that practice published in full.

Security work is a better candidate for AI than most of what is currently being automated, for an unglamorous reason: the inputs are already machine-readable. Ratings, findings, advisories, asset inventories and control frameworks are structured data, and a great deal of skilled analyst time goes into assembling and cross-checking them rather than into judgement. The judgement still belongs to the analyst. The assembly does not have to.

What that demands in return is an evidence trail. A security answer is used to sign off a vendor, brief a board or satisfy an auditor, so it has to be checkable rather than trusted — which rules out most of what is currently sold as enterprise AI, and is the constraint everything below is designed around.

BitScoreCoWork — the practice, in public

Most AI consultancies ask you to take the engineering on trust. Ours is on GitHub. BitScoreCoWork is an MIT-licensed Claude plugin we built and published: a zero-dependency MCP server wrapping the Bitsight REST API, plus sixteen skills that turn ratings data into vendor decisions, exposure sweeps, board packs, framework evidence, regulatory incident notifications and scoped security-testing plans. Install it, point it at your own Bitsight tenancy, and it runs — it is not a demo we drive.

What we build

Third-party and supply-chain risk

Vendor portfolios triaged continuously rather than annually: measured posture read from Bitsight and your own sources, assembled into pre-contract due-diligence briefs and renewal reviews that end in a recommendation and the clauses worth negotiating. This is where the hours are, and where a questionnaire is least informative.

Exposure and vulnerability triage

When an advisory lands, the question is which of your entities and vendors is observably exposed, and in what order to call them. Agents sweep the estate, attach the evidence, and produce a triage order — a job that is mechanical, urgent, and consistently done late because it is done by hand.

Framework and regulatory evidence

Findings mapped to NIST CSF 2.0, ISO/IEC 27001:2022 and Indian obligation areas — RBI, SEBI, IRDAI, IFSCA, CERT-In and DPDP — with each row marked by where its evidence came from. An outside-in view evidences the external surface and no more, so the honest output is an evidence pack the compliance team works from, not a verdict.

Board and executive reporting

The recurring translation problem: posture into a page a board can act on, and, where it is wanted, into an indicative financial exposure range with every assumption on show. Assembled in minutes, in your house style, from data that is current on the day of the meeting rather than the day the deck was started.

Deployment and controls

Identity, access control, retention, logging and evaluation, deployed into your own Google Cloud tenancy. Your data stays in your environment. This is the part that determines whether a pilot becomes production in a regulated organisation, and it is routinely the part left until last.

How engagements start

With one security workflow, not a platform decision. We look for something expensive, repetitive and evidence-heavy — vendor due diligence, exposure triage, framework evidence, board reporting — build it properly end to end, and establish whether the accuracy, the controls and the economics actually work for your organisation. That produces something your team keeps using and a real basis for the next decision, which a proof of concept generally does not.

  • Scope. One workflow, its data sources, its accuracy bar, and what “wrong” would cost.
  • Build. Grounded, evaluated, and deployed in your environment.
  • Govern. Access, retention, logging and audit trail agreed before go-live rather than retrofitted after it.
  • Extend. Additional workflows on infrastructure that already has sign-off.

Judging AI defenders at SANS

Nimitt Jhaveri, BitScore's Managing Partner, is a judge for FIND EVIL!, the SANS Institute hackathon on autonomous AI agents for incident response, which ran from April to June 2026. Entrants built agents that detect and triage a live intrusion in seconds rather than hours, and judging meant assessing dozens of them against the question this whole practice turns on: can you tell what the agent actually saw, and would you let it act on that alone?

It is a useful vantage point. Seeing where a hundred serious attempts at agentic defence succeed and where they quietly break is a faster education in the failure modes than building alone, and the answers feed straight back into what we are willing to put in front of a client.

Partnerships

BitScore is an authorised partner for Bitsight, a solutions partner for Anthropic's Claude frontier AI, and a cloud partner for Google Cloud, which is the deployment platform for the AI work.

Questions people actually ask about AI in security.

/01

What does the BitScore AI practice actually build?

AI systems for security and risk work: agents that read live security data and produce the artefact a team has to file — a vendor decision, an exposure triage, a framework evidence pack, a board briefing — plus the deployment work around them, meaning identity, access control, retention, logging and evaluation. BitScoreCoWork, our open-source Claude plugin for the Bitsight API, is the same pattern published in full.

/02

Why cyber security rather than AI consulting in general?

Because it is the domain we already answer for. BitScore runs a cyber risk practice as an authorised Bitsight partner, so the data, the failure modes and the standard of evidence are familiar rather than researched. Security work is also unusually well suited to AI: the inputs are machine-readable, the analyst hours go into assembling and cross-checking rather than judgement, and every output has to survive an auditor.

/03

Where does the AI run, and who holds the data?

In your own Google Cloud environment, under your enterprise controls and your existing identity model. BitScore builds and deploys into your tenancy rather than hosting your data in a BitScore product — which matters when the material is your own attack surface, vendor assessments and audit evidence.

/04

Will an AI agent be allowed to touch production security systems?

Only where you decide it should, and our default is narrower than most buyers expect. The systems we build read, correlate and draft; actions with consequences stay behind human approval. The security-testing skills in our own plugin illustrate the principle — they produce a scoped engagement plan for licensed testers to run, and never execute anything.

/05

How do engagements typically start?

With one security workflow that is expensive, repetitive and evidence-heavy — vendor due diligence, exposure triage, framework evidence or board reporting — rather than with a platform decision. A single well-chosen workflow establishes whether the accuracy, the controls and the economics work for your organisation, and produces something your team keeps using.

Tell us the workflow.

The fastest way into a useful conversation is one concrete security process that costs your team real hours — vendor reviews, exposure triage, evidence packs. We will tell you honestly whether it is a good candidate; several are not.

Discuss an AI engagement About BitScore