Back to the registry
Agent passport

Security Review for AI Applications & Services

Deloitte · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach3 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownProfessional service
ProvenanceUnknown33% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

At Deloitte Cyber Security, we offer unique services designed to help enterprise clients assess the security of their AI applications and foster the development of inherently secure AI services. In an era where security threats are continuously evolving, Deloitte stands at the forefront, equipped with the tools, expertise, and strategic thinking necessary to address these challenges head-on.

AI applications, services, and models present their own exclusive set of security threats that require intimate understanding and specialized skills to mitigate. We are well-versed in diverse security threats that AI systems can be prone to, including model inversion attacks, prompt injections, adversarial attacks, poisoning attacks, and extraction attacks. Our services cover generative AI models such as Large Language Models (LLM) or image models where the potential misuse can be significantly high.

Show the rest of the publisher’s description (10 more lines)

Our approach to addressing these issues is systematic and well-structured. It begins with onboarding, during which we familiarize ourselves with our client's specific circumstances and needs. This leads into the information-gathering stage that involves a comprehensive overview of the client's architectural, software, cloud and process infrastructure.

We follow a standardized approach that includes scoping, information gathering, threat analysis, recommending mitigating measures, and reporting. This approach provides you with a comprehensive overview of the overall security aspects of your applications and services.

Following this, we perform an in-depth system architecture review that concentrates on uncovering potential risks. Our specialized security architects have a deep understanding of the interplay between AI and underlying technologies which assists in thorough evaluations.

Our services also include comprehensive threat analysis for recognizing and mitigating potential risks. We help businesses identify vulnerabilities and work together to formulate and implement measures that make their AI portfolio secure, efficient, and resilient to attacks.

Our report consists of a management summary, a system description, data flow diagrams, a list of vulnerabilities along with their severity ratings, a list of countermeasures, and the overall risk level. This will equip you with the necessary information to make informed decisions and implement necessary controls to ensure the security of your AI applications and services.

Creating a safe environment for AI systems is not just about threat mitigation but also involves upholding data privacy and enforcing AI compliance. Our expertise extends to an in-depth understanding of the data privacy aspects of AI applications and associated compliance requirements in cloud environments.

In compliance with national and international standards, we help our clients establish AI compliance in their cloud environment, navigating complexities and ensuring that their AI applications are developed and deployed safely and efficiently.

We embody the principle of 'security by design'. This involves helping our clients develop a robust security concept from the conception of an AI application. We work alongside you from development through to deployment, ensuring that security measures are properly implemented and maintained.

Our service portfolio culminates with a comprehensive report that delivers insights on all aspects of security, from threat analyses and infrastructure vulnerabilities to data privacy considerations and effective mitigation steps.

  • S Size (Effort = 10 PDs): Scope  well-documented, 3-tier application with minimal complexity and that supports only a single business use case.

Highlights

Highlighted by the publisher on AWS Marketplace.

Our standardized service provides you with rapid, holistic transparency into all security aspects of your AI applications & services, as well as their underlying cloud environments, using a white box approach. This service leverages AI and automation to ensure prompt and efficient delivery. It helps you identify and mitigate potential vulnerabilities swiftly and effectively.

We have hands-on AI security experience working with a range of German companies, from DAX-listed enterprises to medium and small-sized businesses. Our familiarity with local use cases and the specific regulatory requirements of Germany and the EU positions us advantageously to support your needs.

We are equipped to offer a holistic range of services, all from a single source. This includes tool selection, use case development, security governance, cloud compliance automation, penetration test and consultancy services with an emphasis on generative AI.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource

Publisher resources

1 link
Cyber Cloud – Die sichere Grundlage einer kosteneffizienten, skalierbaren und flexiblen ITwww.deloitte.comSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Unknown
Not stated
Delivery
Professional service
Contact us to learn how we can help you: Ellen Schäfer eschaefer@deloitte.de, Xin Jin xijin@deloitte.de, Jana Holstein jholstein@deloitte.de
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.