Home / Services

Services and software development

Audit, testing and hardening of AI systems. All work is delivered under a contract with a fixed scope, timeline and set of deliverables.

Service catalogue

Pricing is scoped individually: there is no single price list, because the price depends on the task. The factors behind the calculation are published openly and listed for every service. We send the indicative range and the stage breakdown on request — within one business day, without registration on this site.

ServiceScopeDeliverableTimelineWhat drives the price
AI Red Teaming as a Service Testing a multi-agent system: cross-agent prompt injection, privilege escalation through call chains, infection through shared memory files Report with reproducible attack scenarios and a remediation plan 3–8 weeks Number of agents and test scenarios, environment availability, access mode, requirements for a reproducible report
Behavioural Audit of AI Ecosystems Behavioural assessment: delusional gradient, self-preservation attempts, covert communication Analytical report and immunisation recommendations 3–6 weeks Number of agents, telemetry volume, depth and duration of observation
AI Supply Chain Security Assessment Supply chain review: open-source components, datasets, LoRA adapters, hidden triggers Report, software bill of materials profile, recommendations 4–6 weeks Number of components and datasets, depth of review, required standard of evidence
AI compliance audit Assessment against Russian regulation and the EU AI Act: transparency, documentation, human oversight Compliance map and gap remediation plan 4–10 weeks Number of systems, applicable jurisdictions, availability of internal documentation
OSINT research and due diligence Counterparty integrity assessment, information-leak risk analysis, digital footprint review Findings report with risk assessment and annexes 2–5 weeks Depth of review, number of subjects, required standard of evidence
Guardrails implementation Inter-agent authentication, memory isolation, oversight loops, hardware kill switch Working protection layer and operating procedures 2–4 months Number of agents and tools, access mode, production requirements
Corporate training Programme for executives and engineers: risks of agentic systems, defensive practice Trained team and teaching materials 16–40 hours Format (webinar or workshop), number of participants, volume of teaching materials
How we work: request → free scoping call (30–60 minutes) → proposal with a fixed price → contract and NDA → work with interim demonstrations → final report and results review.

More on selected services

Four areas that generate most enquiries. For each we set out what the work includes, what the client receives and where our limits are.

Guardrails: oversight loops instead of a single filter

Guardrails are not one input filter and not a list of banned words. They are several independent loops, each aimed at its own class of failure: input and output filtering, intent checks before a tool call, mutual authentication between agents, memory isolation and emergency shutdown. We design them for a specific architecture rather than selling a ready-made box.

  • Input and output filtering and classification, including indirect injections in documents and on web pages
  • Intent checks before tool calls and before requests to external services
  • Mutual authentication of models and agents: an instruction from another agent is rejected unless its source is verified
  • Memory and log isolation: a shared memory file is the most common infection channel in multi-agent systems
  • An oversight loop: an independent observer that can see the decision chain and stop it
  • Emergency shutdown — software and hardware, tested against a real scenario rather than on paper

Timeline 2–4 months. Price is scoped individually; factors — number of agents and tools, access mode, production requirements.

A limitation we state before work begins: guardrails reduce likelihood and impact but do not guarantee safety. A system with access to tools remains a system with residual risk; the report names the risk that remains and why.

Compliance audit: Russian regulation and the EU AI Act

We assess a system against requirements already in force and against those about to take effect. The Russian track: Federal Law No. 243-FZ of 26 July 2026, requirements for large foundation models, and notification of rights in generated content. The European track: Regulation (EU) 2024/1689 and its application timetable by risk level. For organisations operating in both markets the two tracks are separated within a single compliance map.

  • Inventory of AI systems and classification of each by risk category
  • A requirements map: what is mandatory now, what is coming and by when
  • Model documentation: purpose, data, limitations, known failures
  • Human oversight: where it is mandatory and how its presence is evidenced
  • Transparency and marking of generated content
  • A gap remediation plan with an effort estimate for every item

Timeline 4–10 weeks. Price is scoped individually; factors — number of systems, jurisdictions, availability of internal documentation.

We do not issue a “fully compliant” conclusion: compliance is confirmed as of a date and within the scope examined, and the report says so plainly. Legal decisions and their consequences remain with the client.

OSINT and digital footprint

Open sources give more than is commonly assumed: team composition, technology stack, contractors, leak history and traces of automation can be collected without touching closed systems. We do this for two purposes — assessing a counterparty before a transaction and assessing a client’s own risk surface.

  • Organisation profile: affiliations, officers, participation in procurement, litigation
  • Technical footprint: domains and subdomains, certificates, exposed services, infrastructure traces
  • Leaks and mentions: breach datasets, forums, repositories, openly accessible storage
  • Public digital footprint of employees that is relevant to social engineering
  • Risk assessment and remediation priorities — from the cheapest to the most expensive

Timeline 2–5 weeks. Price is scoped individually; factors — depth of review, number of subjects, required standard of evidence.

We work only from lawful open sources and within the scope agreed in writing with the client. Information about individuals is not collected beyond what is necessary.

Bug bounty automation: continuous discovery instead of a one-off review

A one-off review records the state of a system on a given date. A bounty programme turns vulnerability discovery into a continuous process: external researchers work to published rules, findings arrive in a stream, and the Institute handles intake, verification and prioritisation.

  • Programme design: permitted scope, reward levels, disclosure rules
  • A responsible disclosure policy: timelines and exceptions for critical infrastructure
  • A report intake platform and verification that findings are reproducible
  • Filtering out false and duplicate reports and rating severity
  • Handing findings to engineering and tracking remediation
  • A public report at the end of the programme — without exploitation details

Launch 2–6 months. Price on request: it depends on the scope of the programme and the reward pool.

A bounty programme does not replace penetration testing: it draws on a broad community of researchers and finds the unexpected, but it does not give systematic coverage. We say this before work starts, not afterwards.

AI adoption concepts for an industry, with an effect estimate

We set out where AI actually delivers a result in a given industry and estimate the effect before development starts. The client receives not a story about what technology can do, but an examination of its own processes: which tasks are already solvable, which need data that does not exist yet, and which of them pay back.

  • Process review stage by stage: where a person decides and where the decision can go to a model
  • A data map: what exists, what is missing, what it costs to collect the missing part
  • Use scenarios with an estimate of effect and cost of implementation
  • Requirements for models and agents: class, mode of operation, deployment perimeter
  • Risks: model error, leakage, vendor dependency, regulatory requirements
  • A roadmap and a division of work: what the Institute does and what the technology partner takes on

Timeline 4–8 weeks. Price on request: it depends on the industry and the depth of the study.

The Institute produces the concept and the effect estimate; industrial implementation is carried out by a technology partner. That separation keeps the research side independent of contracting interests: we have no stake in proving that implementation is needed — we assess whether it pays back.

What we do not do

  • We do not test systems without the written consent of their owner
  • We do not sell or transfer attack tools or attack methodology
  • We do not publish vulnerability information before the agreed deadline expires
  • We do not take on work whose result cannot be verified by measurement

Software development and IT activity

This section is published in accordance with the requirements applicable to the official website of an organisation operating in the field of information technology in the Russian Federation. The mandatory information in Russian is available on the contacts page.

Fields of IT activity

  • Software development for analysis and monitoring of multi-agent AI systems (OKVED 62.01)
  • Consulting and computer technology services: AI system audit, guardrails implementation (62.02)
  • Testing of AI systems, red teaming, security assessment (62.09)
  • Data processing, hosting and monitoring services (63.11)
  • Publishing of other software products (58.29)
  • Research and development in natural, technical and social sciences (72.19, 72.20)
  • Additional education and professional retraining in AI (85.41, 85.42 — subject to a licence)

Codes of IT activity

The list of activity codes in the field of information technology is determined in accordance with order No. 449 of the Ministry of Digital Development of 11 May 2023 and is submitted with an application for state accreditation. The current list of codes is published in the legal information section.

Programming languages and development tools

Python, TypeScript/JavaScript, SQL; frameworks for large language models and multi-agent systems; containerisation (Docker), version control (Git), automated testing, monitoring and logging systems; data analysis and machine learning libraries.

Software rights and licensing

Exclusive rights to software and databases developed by the Institute belong to the Institute or to the rights holder named in the contract. Licensing terms are described on the products page. The Russian-language statement of exclusive rights and licensing is provided in the mandatory Russian section.

Need an assessment of your system?

Send a short description of your architecture — we will propose a scope, timeline and indicative price.

Page updated 29 September 2026 · site build 2026.10.01 · ANO «ISAI»