SERVICES
Two halves of the same job.
We build AI systems that do real work inside enterprises, and we run the security layer that keeps them from becoming the incident. Most firms do one or the other. Doing both is why our security is designed by people who have had to ship the thing it protects.
01
AI Security
AI-Sentinel for deterministic runtime protection, AI-Armory for continuous adversarial validation, plus the assessments and compliance evidence that turn both into something you can put in front of a board or an auditor.
Jump to AI Security ›
02
AI Build
Custom agents, workflow automation and analytics, delivered in weeks. This is the original business and it still runs. Every system we build now ships behind AI-Sentinel by default, which is a change we made after we saw what was getting through.
Jump to AI Build ›
01 · AI SECURITY
Protection and proof - sold together - because either one alone is useless.
THE SHIELD
AI-Sentinel
A high-performance security sidecar that sits between your applications and your models, inspects every request and every response, and enforces with math.
On the way in
- Prompt injection and jailbreak signature matching against a live threat libraryIncluded
- Indirect injection: retrieved documents run the same pipeline, because your own store is not a trust boundaryIncluded
- PII and credential detection before anything reaches a third-party modelIncluded
- Entropy analysis and exponential moving average drift for patterns no signature would catchIncluded
- A hard daily spend ceiling that stops cost-amplification attacks in progressIncluded
On the way out
- System prompt and model extraction attemptsIncluded
- Data exfiltration and PII leakage in generated outputIncluded
- Output redaction against your own sector rulesIncluded
- Agent tool-call and action gating before the agent gets to actIncluded
- A tamper-evident SHA-256 record of every decision, allowed or blocked, with the rule IDIncluded
THE PROOF
AI-Armory
The adversarial engine. Roughly 20,000 tests mapped to MITRE ATLAS, fired at your live deployment every 30 days, with the findings written up as evidence rather than a dashboard.
It runs on a schedule
Not once at procurement. Attack techniques change monthly, so validation happens monthly.
It runs against production
Against the deployment you actually have, with the models, prompts and tools you actually use, not a reference architecture.
Findings become candidate rules
Which still have to clear the deterministic validator and a human before they enforce anything. The loop closes without an AI ever writing its own policy.
THE ENTRY POINT
Assessments and compliance evidence
Monitor-mode reveal report
A non-blocking deployment against your live traffic, mapped against every applicable MITRE ATLAS technique. This is the strongest thing we have and we give it away, because the gap sells better than we do.
AI security readiness and maturity assessment
Where your AI actually is, who deployed it, what governs it, and what would happen if an auditor asked tomorrow. Start free with the readiness scorecard.
Compliance documentation suite
Included with every deployment: 13 documents for ISO/IEC 42001 and 8 for the EU AI Act, plus the tamper-evident audit chain that feeds them. Months of consultant work, bundled.
Sector rule modules
Pre-configured profiles for healthcare (HIPAA), financial services (PCI DSS), legal, government and defense, and K-12 education. Hours instead of months of configuration.
02 · AI BUILD
We ship AI into businesses. That is how we found the gap.
Onnex Global started by building custom AI agents, workflow automation and analytics for companies that wanted months of work compressed into minutes. We still do it. What changed is that we no longer hand anything over without a shield in front of it.
Custom AI agents
Agents that handle customer service, qualify leads and make routine operational decisions without a person in the loop for every step. Scoped, permissioned and gated, because an agent with tool access is a new class of privileged user.
Workflow automation
We spend time inside the business first, map the real data flows and the real bottlenecks, then automate the parts that actually cost you. Implementation in weeks.
Traceable analytics
Turning raw operational data into decisions people will act on, with the lineage intact so you can explain where an answer came from.
Why this matters to a security buyer
Everything in AI-Sentinel exists because we hit it while building. The spend ceiling exists because we watched a token budget get away from a client. The tool-call gating exists because we shipped an agent with more reach than it needed and caught it in review. This is not a security product designed from a threat report.
DEPLOYMENT
In minutes, non-blocking, with no code change.
| Mode | What it is | Who it fits | Time to value |
|---|---|---|---|
| Monitor mode | Non-blocking sidecar observing live traffic. Nothing is stopped, everything is recorded. | Every new engagement, without exception | Minutes to deploy, days to the first report |
| Transparent proxy | Inline enforcement with no application code change. Requests route through, decisions happen, developers do not feel it. | Teams that cannot touch the application | Same day |
| Managed gateway | Cloud-hosted, traffic routed through managed infrastructure. | SMBs and startups with no infrastructure team | Same day |
| Sidecar, co-located | Deployed next to the application to keep the hop short and the latency down. | SaaS vendors shipping AI features to their own customers | Days |
The appliance stack is seven containers: core, WAF, PII engine, Postgres, Redis, Prometheus and Grafana.
Only SaaS deployment is currently available - Kubernetes and edge deployment modes are on the roadmap.
PRICING
This normally sells for +$250,000 a year. We charge $48,000.
Not because it is worth less. Because a principle of the company is that every organization should be able to afford to prove their AI is safe, and that only works if the price is not a luxury. We would rather define this part of the market than protect a margin.
Entry
$100 per user – makes sense up to 35 users then Enterprise plan
Low-friction entry for individual teams and software vendors. Runtime protection, policy management, logging.
Enterprise, up to 100 employees
$4,000 per month
$3,500 for AI-Sentinel plus $500 for AI-Armory. $48,000 a year for protection and continuous proof, with the compliance documentation suite and sector modules included.
Above 100 employees
Custom
Scaled on deployment size, environments, throughput and sovereignty requirements. Custom SLA terms are available at the OEM and partner tier.
What we are anchoring against, since you will ask
Not a competitor's license; possibly piece of mind knowing you are protected and compliant.
The average breach now costs $4.99 million globally and $11.5 million in the United States, and an AI-enabled breach averages around $6 million (IBM, Cost of a Data Breach 2026). EU AI Act penalties for prohibited practices reach 35 million euros or 7% of worldwide annual turnover.
Against those numbers, $48,000 is a rounding error, and we would rather you spent the difference on the rest of your business.
No money-back guarantee, deliberately. Refund promises are a tactic for crowded markets where nobody can demonstrate anything. Why would you need a money back guarantee when AI-Sentinel actually saves you money. You will get your money back, added to the best AI protection on the market.
Our risk reversal is that you run the thing against your own production traffic before you pay us a dollar, and that the enforcement engine is provably byte-identical with every AI feature switched off. Proof beats a promise.
Do not take our word for it. Run it against your own traffic.
Monitor mode goes in non-blocking, in minutes, with zero risk to live workflows. Within days you get a written audit of the prompt injections, extraction attempts and data leaks your current stack is not catching. Then you decide.
The audit is free. The blind spot is not.