A Security Practice · Charleston, SC

Federal-grade security,
shipped at AI speed.

Two decades of CISO leadership and Top Secret-cleared work, paired with the velocity of a modern AI shop. For federal contractors, regulated enterprise, and the mission systems they're racing to bring online.

Brief Us On Your Problem
Scroll
§ 01 — Practice

Most security firms either understand the regulatory perimeter or they can actually build software. Few do both.

Secursion closes that gap — pairing twenty-five years of CISO leadership and Top Secret-cleared federal work with the engineering velocity of a modern AI practice. We work on what the threat models actually call for, in formats the auditors can sign.

I.

Credibility that travels.

Our security lead holds DoD and FBI Top Secret clearances and has served as CISO and Chief Technology Advisor inside Fortune 500 defense contracting and intelligence-community workloads. The threat models we build are the ones we have actually defended against.

II.

Velocity that ships.

Our managing partner is a working AI builder — Carolina Redesign, SCAIO, the Palmetto Budgeting Suite, the Babcock re-platform — shipping production deployments where larger consultancies are still scoping. AI exposure moves faster than most security shops can respond.

§ 02 — Capabilities

Four practice areas, all assembled around what the AI-era federal supply chain actually needs.

01
LLM & Agent Key Governance
Secrets management, access control, and audit infrastructure for LLM and agent systems under CMMC, NIST 800-171, and FedRAMP. Most enterprise AI today runs on developer API keys with no auditable access trail. We build the layer a CISO can sign.
02
CMMC & Federal Compliance
Pre-assessment readiness, gap analysis, and program build-out for the Defense Industrial Base. CMMC Level 2 and 3, NIST 800-171, DFARS, and FedRAMP advisory — delivered by practitioners who have lived inside the programs, not consultants who have only read the standards.
03
AI Red-Teaming & Model Security
Adversarial testing of AI deployments, prompt-injection assessments, model inversion, and threat-modeling for AI-integrated workflows. Run by a CISO who has built red-team programs at Fortune 500 scale and presented original research at DEF CON, SOURCE Boston, and IEEE.
04
Secure AI Infrastructure Builds
Custom secure deployments — voice agents, intake systems, document workflows, internal LLM portals — for organizations whose compliance posture rules out off-the-shelf SaaS. When the data cannot leave, we build the version that can.
§ 03 — In Development

Products in flight — built from the patterns we keep encountering inside federal and regulated engagements.

Product · ResponseOS Live Prototype

Security Questionnaire Intelligence

Most security teams lose dozens of hours per deal answering vendor questionnaires, DDQs, and RFP security sections — by hand, from the same recycled answers. ResponseOS turns your existing corpus into an auditable answer engine. Drafts in minutes, evidence linked inline, signed by the humans who own each control.

Open Prototype →
Platform · Spec v0.1 CMMC-driven

LLM Key Governance Platform

A secrets-management and access-control layer for LLM and agent systems under CMMC and NIST 800-171. Per-tenant key vaulting, model-level access policy, full audit trail of every prompt and tool call, and the evidence pack auditors actually ask for. In spec; design partners welcome.

Inquire About Design Partnership →
§ 04 — Principals

Two principals. Both names on every engagement.

Principal · I

Noah Schiffman

Co-Founder & Chief Security Officer

Noah has spent the last twenty-five years building security programs for organizations that cannot afford to get it wrong — Fortune 500 defense contractors, intelligence-community workloads, NAVSEA-supporting programs. Most recently he was Chief Technology Advisor at KBR, where his red-team and vulnerability program cut measured exposure by 95% across one of the largest federal contractor portfolios in the country. Before that he ran the CISO function at Wave Sciences and Orbis, securing classified workloads and shipping patented biometric authentication systems.

He holds DoD and FBI Top Secret clearances, is the inventor on six U.S. patents in security and communications, and has presented original threat research at DEF CON, SOURCE Boston, and IEEE. He is an M.D. by training — Medical University of South Carolina — with prior degrees from Rutgers in mechanical engineering and cognitive psychology.

Principal · II

Jimmy Ardis

Co-Founder & Managing Partner

Jimmy is the build side. Through his AI studio Carolina Redesign, he has shipped production AI systems across legal intake, healthcare triage, state government budgeting, and cybersecurity compliance — including the Palmetto Zero-Based Budgeting Suite for South Carolina legislators and a HIPAA-compliant AI receptionist running across multiple medical practices. Larger consultancies were still scoping.

Before AI he spent fifteen years inside federal environmental compliance — 120+ NEPA reviews with zero findings overturned, a HUD Addendum to a FEMA Programmatic Agreement for South Carolina disaster recovery, a designated Subject Matter Expert seat on the HUD Exchange. The same regulatory machinery that drives CMMC and FISMA today. He is a six-year Air Force veteran (A-10 aviation, Incirlik AB), co-founder of the South Carolina Artificial Intelligence Observatory, and holds an MPA from the College of Charleston.

§ 05 — How We Work

Four operating principles, borrowed from the disciplines that actually have to hold.

i.

Both names on every engagement.

We do not subcontract. Both principals work on every engagement directly. If it needs a larger team, we say so before we sign.

ii.

Written for the auditor.

Deliverables are written for the assessor, regulator, or board member who will eventually have to act on them — not the marketing deck. Evidence linked, citations precise, rationale on the page.

iii.

Federal-grade controls when required.

Active DoD and FBI Top Secret clearances. We operate under appropriate handling controls for sensitive engagements — including those where the existence of the engagement is itself the sensitive fact.

iv.

First conversation costs nothing.

Engagements begin with a one-hour scoping call. No NDA required to describe the problem. If we are not the right team, we will tell you — and where we can, point you to one who is.

§ 06 — Engage

Serious work starts here.

Tell us what you are defending, your regulatory framework, and what is blocking you. Response within one business day.

For sensitive inquiries, use the direct mailbox; we will respond with secure channel options.

General Inquiries
Direct Mailbox

For new engagements & press

contact@secursion.ai
Principal · I
Noah Schiffman

Chief Security Officer

noah@secursion.ai
Principal · II
Jimmy Ardis

Managing Partner

jimmy@secursion.ai