# Secure AI applications

Adrien Murillo — Murillo Consulting

Define what an assistant may read, transmit and execute. Test these boundaries before giving it more autonomy.

You are integrating an assistant, RAG system or agents with your tools. I help map data flows, limit access and build security tests for your use case.

Gate and the agent projects are public demonstrators. They let you inspect my technical work. No client AI engagement is claimed here.

## Map the use case
Identify users, data, providers and possible actions. Describe the consequences of disclosure, incorrect output or unauthorized action.

## Design controls
Define minimum permissions, approval for sensitive actions, spending limits and logging rules. Separate reference data from trusted instructions.

## Test and hand over
Build tests for injection, access across users and tool calls. Report gaps, verified controls and remaining risks.

## Deliverables
- Data and permission map
- Abuse scenarios and repeatable tests
- Control prototype within an agreed scope
- Risk register and implementation plan

## Boundaries
- Regulatory or legal certification of your AI.
- A guarantee to block every injection or hallucination.
- Custom model training without dedicated scoping.



## Navigation
- [Independent engineer and trainer.](/en/profil)
- [Engineering services.](/en/services)
- [Selected work.](/en/realisations)
- [Open-source projects.](/en/projets)
- [Guides to put into practice.](/en/ressources)
- [Let’s discuss your project.](/en/contact)
- [From scope to handover.](/en/approche)
- [Real contexts. Real constraints.](/en/secteurs)
- [Learn by making decisions.](/en/lab)
- [Legal notice](/en/mentions-legales)
- [Privacy](/en/confidentialite)
- [Train your teams. Through practice.](/en/formation)

[Contact](mailto:contact@adrien-murillo.com)
