HIJ4CKinfo@hij4ck.com

We secure your systems.We ship production AI.

The engineer who scopes the work does the work: security reviews, threat models, agent security, production LLM systems. Founder-led, New York. No handoffs, no juniors.

Past engagements.

Not a complete list, just a sense of the work.

01Frontier AI labsSecurity reviews and AI systems engineering
02U.S. government programSecurity engineering
03Defense & aerospaceThreat modeling and hardening
04Robotics companyVision models, product research, robot action simulation
05Biotech companyModels in weeks, not months
06Scientific simulation groupSystems engineering
07StartupsAI engineering and production LLM builds
08Professional services firmSOC 2 readiness

What we do.

Offensive-minded security engineering

We review code and architecture the way an attacker reads them, then fix what we find. Findings ranked by risk, each with a working fix, and a report written for the security team that asked for it.

  • code and architecture security review
  • penetration test, with a report you can hand to the customer who asked for it
  • threat model of your system and its trust boundaries
  • risk-ranked findings, each with a fix and reproduction steps
  • hardening plan your team can execute

AI and LLM systems engineering

Agents, retrieval pipelines, and self-hosted model serving, built to run in production. We design, build, instrument, and hand over systems your engineers can operate without us.

  • production agent and tool-use architecture
  • RAG and retrieval pipelines
  • self-hosted model serving on your infrastructure
  • LLM API integrations built for production
  • handover documentation your engineers own

AI security

Securing LLM applications and agent systems is work we learned inside frontier AI labs. We map how your agents can be steered, what they can reach, and what leaves the building, then close those paths.

  • threat model of your agent's tool surface
  • prompt injection and data exfiltration review
  • red-team exercise against your LLM application
  • eval suite that catches security regressions

Custom model development

When an off-the-shelf model can't do the job, we build one that can. We've trained custom models for biology, robotics, physical simulation, and language, including abliterated variants of open-weight LLMs, and we hand them over running on your infrastructure.

  • custom models for bio, robotics, simulation, and language
  • fine-tuning and post-training of open-weight LLMs
  • abliterated and uncensored model variants, self-hosted
  • eval suites that prove the model does the job
  • training and serving on infrastructure you control

SOC 2 and ISO 27001 readiness

Engineering-led compliance. We build the controls (access, logging, change management) so the audit measures something real. Paperwork follows from working systems, not the other way around.

  • gap assessment against SOC 2 or ISO 27001
  • implemented controls: access, logging, change management
  • policies mapped to how your team actually works
  • audit-ready evidence trail

How engagements run.

Every engagement starts with a short scoping conversation. We agree on a fixed scope, a deliverable, and a date before anything is signed. If the problem isn't ours to solve, we say so and point you somewhere better.

Work runs async-first: a shared channel, written updates you can forward to your customer's security team, and working sessions when a decision needs one. Every engagement ends with a walkthrough and a handoff: findings with fixes, systems your team can operate, controls that keep running after we leave.

Fixed-scope sprints
A defined deliverable and an end date, agreed before anything is signed.
Advisory retainers
Fractional, ongoing security and AI work when a sprint isn't the right shape.
Remote, US-wide
Async-friendly. On-site in the NYC metro.
Senior only
The engineer who scopes the work does the work.

About the firm.

HIJ4CK is a founder-led security and AI engineering consultancy in New York City. Most consultancies run on leverage: a senior person scopes the work, junior people deliver it. HIJ4CK doesn't have that layer: the engineer you scope with is the engineer in your codebase, and we take on a few engagements at a time so that stays true. Past engagements span frontier AI labs, U.S. government programs, defense and aerospace, robotics, biotech, scientific simulation, and early-stage startups.

When to email us

An enterprise customer made a pentest a condition of the contract. Another just asked for your SOC 2. Your agent has tool access nobody threat-modeled. You're shipping AI features faster than you can review them. Write a few lines about the situation. The reply comes from the engineer who would do the work, usually with a first read on scope, and an honest no if it isn't a fit. No forms, no calendar links, no sales call.

Accepting engagements · Remote US · NYC on-site

info@hij4ck.com