Boutique consultancy · AI · Cloud · Security
We build AI systems, break them, and run the cloud they live on.
Most firms do one of those three. The interesting failures happen where they meet — a retrieval pipeline that leaks across tenants, an agent whose tool permissions outrun its guardrails, an inference bill that scales with abuse instead of usage. PinkCloud works the seams.
The call usually starts one of six ways
You are probably here because one of these just happened.
An enterprise prospect sent a security questionnaire about your AI feature, and nobody on your side can answer section four with a straight face.
AI Security →You are weeks from shipping an agent that can move money, change records, or email customers — and the guardrail is a paragraph in the system prompt.
AI Engineering →Your inference bill grew faster than your usage, and the delta has no owner.
Cloud →Someone published a prompt injection against a product shaped like yours, and your board has now read about it.
AI Security →Your evaluation set was written by the same team that built the feature, and it has never once failed.
AI Engineering →You are paying for accelerators that idle between batches, and nobody can tell you the utilization number.
Cloud →
Three practices, one team
Engagements are scoped independently, but they are staffed by people who have worked the other two sides. That is the whole point.
Break it
AI Security
Adversarial assessment of language models and the agentic systems built on them — prompt injection, tool-use abuse, data exfiltration, alignment failure under pressure.
Explore AI Security →Run it
Cloud Engineering
DevOps and FinOps for teams whose infrastructure bill grew faster than their traffic. Cost attribution, performance engineering, and platform reliability with measurable outcomes.
Explore Cloud Engineering →Build it
AI Engineering
Inference infrastructure, retrieval pipelines, agent orchestration, and the evaluation harnesses that tell you whether any of it actually works.
Explore AI Engineering →Who is in the room
Small, senior, and specifically credentialled.
We present as a collective — the capabilities are public, the roster is disclosed under NDA before you sign anything.
- Signals intelligence
A Unit 8200 alumnus
Nation-state tradecraft, pointed at commercial systems.
- Adversarial
Offensive AI red-teamers
People who break model guardrails as a full-time job.
- Economics
FinOps specialists
Unit cost per tenant, per request, per thousand tokens.
- Measurement
Model-evaluation authorities
Harnesses that make capability claims checkable.
Why the intersection
An AI system is not a model. It is infrastructure with a model inside it.
Assessments that stop at the model miss most of the attack surface. The prompt is one input; so are the documents in the index, the tools on the loop, the service account the agent inherited, and the queue that retries a poisoned job forty times.
Reviewing that honestly means reading Terraform as fluently as transcripts. It is why the security practice and the cloud practice sit in the same room, and why the engineering practice exists at all — we take the systems apart more convincingly because we have shipped them.
Retrieval that crosses tenants
Embedding stores inherit the access model you gave them, which is usually none.
Agents with inherited privilege
The guardrail reviews the text. The IAM role is what actually executes.
Cost as a denial-of-service surface
Token-metered endpoints turn an abuse problem into a billing problem, and then into an availability one.
How engagements work
Fixed fee, fixed window, written deliverable.
- Two to ten weeks
Most engagements are scoped between a two-week targeted review and a ten-week build. The window is agreed before we start.
- No percentage of savings
There is no upside for us in recommending a three-year commitment you should not sign.
- No reseller margin
We hold no partner margin on any platform we might recommend, so the recommendation is just a recommendation.
- You keep the harness
Test cases, code, and reasoning are delivered to you. If you never call us again, everything still works.
Bring us the system you are least comfortable defending.
Engagements usually start with a short scoping call — what you are running, what you are worried about, and whether we are the right people for it. If we are not, we will say so.