Boutique consultancy · AI · Cloud · Security

We build AI systems, break them, and run the cloud they live on.

Most firms do one of those three. The interesting failures happen where they meet — a retrieval pipeline that leaks across tenants, an agent whose tool permissions outrun its guardrails, an inference bill that scales with abuse instead of usage. PinkCloud works the seams.

Who is in the room

Small, senior, and specifically credentialled.

We present as a collective — the capabilities are public, the roster is disclosed under NDA before you sign anything.

  • Signals intelligence

    A Unit 8200 alumnus

    Nation-state tradecraft, pointed at commercial systems.

  • Adversarial

    Offensive AI red-teamers

    People who break model guardrails as a full-time job.

  • Economics

    FinOps specialists

    Unit cost per tenant, per request, per thousand tokens.

  • Measurement

    Model-evaluation authorities

    Harnesses that make capability claims checkable.

Why we publish capabilities and not headshots →

Why the intersection

An AI system is not a model. It is infrastructure with a model inside it.

Assessments that stop at the model miss most of the attack surface. The prompt is one input; so are the documents in the index, the tools on the loop, the service account the agent inherited, and the queue that retries a poisoned job forty times.

Reviewing that honestly means reading Terraform as fluently as transcripts. It is why the security practice and the cloud practice sit in the same room, and why the engineering practice exists at all — we take the systems apart more convincingly because we have shipped them.

  • Retrieval that crosses tenants

    Embedding stores inherit the access model you gave them, which is usually none.

  • Agents with inherited privilege

    The guardrail reviews the text. The IAM role is what actually executes.

  • Cost as a denial-of-service surface

    Token-metered endpoints turn an abuse problem into a billing problem, and then into an availability one.

How engagements work

Fixed fee, fixed window, written deliverable.

  • Two to ten weeks

    Most engagements are scoped between a two-week targeted review and a ten-week build. The window is agreed before we start.

  • No percentage of savings

    There is no upside for us in recommending a three-year commitment you should not sign.

  • No reseller margin

    We hold no partner margin on any platform we might recommend, so the recommendation is just a recommendation.

  • You keep the harness

    Test cases, code, and reasoning are delivered to you. If you never call us again, everything still works.

Bring us the system you are least comfortable defending.

Engagements usually start with a short scoping call — what you are running, what you are worried about, and whether we are the right people for it. If we are not, we will say so.

Start a conversation