UK cyber security consultancy / EPIC28 Ltd

AI agent security you can prove.

Banks, hospitals, retailers, factories, defence programmes and government departments are putting AI agents to work. EPIC28 builds the security architecture that makes an agent's authority enforceable, and the evidence that proves what it did. Our first product, Raucle, delivers both.

Work with us Explore Raucle
01 / Why EPIC28

A bank answers to the FCA. A hospital answers to its board. A retailer answers to the card schemes. A manufacturer answers to its customers. In every regulated sector the question is the same: when an AI agent takes an action, who authorised it, and can you prove it? Most security work stops at policy. Ours ends in evidence.

The practice

Advisory
01

Security architecture

SABSA-driven target architecture for organisations modernising under pressure. Design reviews, control mapping and delivery roadmaps that stand up in the architecture review board and in operation. From zero-trust patterns to the operating model that makes them stick.

02

AI security advisory

Guidance on deploying AI agents safely: how safeguards, sandboxing and active oversight become controls you can enforce, and where an agent's authority should stop. Aligned to the Code of Practice for the Security of AI, ETSI EN 304 223 and EU AI Act Article 12 logging duties.

03

Assurance and audit readiness

Assurance for organisations under audit everywhere: evidence that controls operate, not claims that they exist. We design the evidence trail an auditor, regulator, customer or supervisory review can verify independently.

Products

01 / Raucle

Raucle. Every agent action, on the record.

Every regulated sector has the same audit problem. A bank must show the FCA what its agents did and under what authority. A hospital trust answers to its board, a defence programme to its accreditors, a government department to the National Audit Office. A retailer answers to the card schemes, a manufacturer to the customers who audit their supply chain. Raucle gates every tool call an agent makes against a signed, least-privilege capability, and produces a cryptographic receipt of what was authorised and what ran. Receipts are content-addressed, immutable and verifiable offline by any auditor, regulator or partner organisation, with no vendor contact required.

raucle.com github.com/epic28-ltd/raucle
100%
block rate on attacker-controlled tool calls, AgentDojo banking suite
69 µs
median gate decision per call, no attenuation chain
4+
framework adapters: Microsoft Agent Framework, LangChain, AutoGen, MCP gateway
Apache-2.0
open source; Lean proofs, benchmark harness and paper draft published with the code

About

EPIC28 Ltd is a cyber security consultancy built around one idea: security you can prove.

Our consultants have spent twenty-five years inside banking and capital markets, central government and defence, manufacturing, retail, telecoms and software security. The work has always been the same: architecture that survives contact with regulators, auditors and attackers.

We advise on security architecture for the age of AI, and we build what we recommend. Raucle, our first product, came out of that advisory work. Regulated organisations need proof of what an agent was allowed to do and what it actually did, and that proof has to survive outside a vendor's log file. So Raucle is open source, cryptographic and independent.

Contact

Start a conversation.

Engagements across finance, healthcare, manufacturing, retail, defence and the public sector, Raucle deployments and press enquiries.

Engagements and Raucle[email protected]