Introducing Ryvane, and What We're Building Next

Why we started Ryvane, what our AI security research and audits cover, and how Ryvane Academy will help security professionals get AI-ready.

I have spent years breaking systems for a living. Network perimeters, Active Directory forests, cloud environments. Offensive security has been my craft, and it still is. But over the past year something shifted that I could not ignore.

AI is moving into production at a speed that genuinely surprised most of us in security. Not as a demo. Not as a side feature. As the core product. Agents making decisions, retrieval pipelines feeding context to language models, tool integrations that can reach your filesystem, your APIs, your users. The attack surface is real, it is growing, and the field has barely started naming it properly, let alone defending it.

That tension, between how fast AI is shipping and how slowly security is catching up, is why I built Ryvane.

What Ryvane Is#

Ryvane is an AI security company. Small and early, deliberately so. The work falls into three areas.

Research. We study how AI systems break in production. Agents, retrieval architectures, the Model Context Protocol, the operator workflows wrapped around all of it. What we find, we share openly. The community deserves working knowledge, not vendor whitepapers.

Audits. We take on a select number of hands-on engagements with teams who are actually shipping AI. The goal is not a compliance checkbox. It is findings backed by working proof-of-concept exploits and documentation that engineers can act on.

Training. This is where Ryvane Academy comes in.

Ryvane Academy: Built for the Gap#

There is a real gap right now between security professionals who know how to break traditional systems and security professionals who understand how AI systems fail. OWASP LLM Top 10 exists. MITRE ATLAS exists. But reading a framework is not the same as understanding, at a technical level, how prompt injection propagates through an agent chain, how a poisoned document reaches a retrieval pipeline, or how MCP attack surfaces open up new lateral movement paths in agentic environments.

Ryvane Academy is being built to close that gap. Self-paced courses. Hands-on labs. No fluff. The curriculum is written by people who do this work, not people who write about people who do this work. It is early and in beta, and we are building it in the open precisely because the field needs it now, not after it is perfect.

The first track is focused on AI security fundamentals for security practitioners. If you already understand how attacks work at a systems level, this is the translation layer that helps you apply that instinct to AI.

Why Now#

AI is being adopted faster than it is being secured. That is not a hot take; it is the current state. Organizations are deploying LLM-powered products without threat models for their AI components. Security teams are being asked to review systems they have never been trained to evaluate. Red teamers are running traditional assessments against targets that have grown an entirely new class of attack surface.

The community that built offensive security from the ground up, wrote the tools, ran the engagements, gave the conference talks, that community is exactly who needs to lead on AI security. Not because AI security is a new field that replaces the old one. Because the instincts developed over years of breaking systems are precisely what this moment needs, translated into new territory.

Ryvane exists to help with that translation.

What's Next#

The website is live at ryvane.ai. The Academy is in early access. Research will be published through our journal. If you are a security professional trying to get up to speed on AI attack surfaces, or an organization shipping AI and wondering whether it has been thought through properly, we would like to talk.

The frontier is moving. We are working to secure it.

Arun

Founder, Ryvane Security Private Limited

Arun Nair

Arun Nair

Where AI security gets practiced.

Audits, research, and training from the team building the field's working toolchain.

LEARN MORE