Agentic systems security
Threat modelling and controls for systems that combine models, data, tools, memory, and autonomous action.
- Trust boundaries
- Identity and permissions
- Data and prompt controls
- Evaluation and guardrails
AI security / cloud defence
Security architecture for LLM agents and the cloud systems around them—grounded in software engineering, identity, detection, and operational reality.
The useful unit of security is the whole system: model, identity, data, tools, infrastructure, and the people operating it.
Threat modelling and controls for systems that combine models, data, tools, memory, and autonomous action.
Cloud foundations for training, fine-tuning, and serving models with governance built into the platform.
Security operations that connect useful telemetry to detections, triage, and repeatable response.
Representative architecture and engineering engagements. Client identities remain private; sectors and scope are shown as they appear in the underlying experience.
Energy sector
Architecture for securely training, fine-tuning, and serving open-source LLMs, with identity controls across model APIs, data stores, and compute. Security telemetry feeds an AI-assisted threat-detection system.
Azure · Entra ID · Sentinel · Defender XDR · MLOps
IP management
Target architecture for central log ingestion and threat detection, including custom rules, parsing, response playbooks, triage workflows, and onboarding runbooks for new sources.
Google SecOps · Entra ID · Defender · Meraki · MongoDB Atlas
Energy sector
Security frameworks for endpoints and digital identities, core SIEM infrastructure, Azure Active Directory assessments, and policies for interconnected cloud platforms.
AWS · Azure · IAM · SIEM · Endpoint security
A compact method for moving from a diagram to controls that can be operated, observed, and improved.
Trace trust boundaries, data flows, identities, tool access, operators, and the assumptions between them.
surface.map()Use scoped identity, policy, isolation, approvals, and bounded tool interfaces to limit what failure can reach.
access.bound()Capture the signals needed to explain a decision, investigate an event, and improve detections over time.
trace.observe()Exercise misuse, prompt injection, excessive agency, data leakage, and operational recovery before production does.
failure.test()newman.ai draws on 16 years across software engineering, platform reliability, cloud architecture, and defence operations.
Company foundation
The company perspective is deliberately end-to-end: how software is built, how cloud platforms are operated, and how defenders see and contain failure. That is the same perspective applied to agentic systems.
Microservices, web platforms, and technical team leadership.
Container infrastructure, CI/CD, staging, and runtime architecture.
AWS, Azure, and GCP platforms, networking, automation, and governance.
SOC, SIEM, identity, endpoints, governance, and security at scale.
Secure LLM platforms, AI-assisted detection, SecOps, and AI governance.
Start with context
A useful first note includes what the system can access, what it can change, and what failure would matter most.