Your AI & cybersecurity partner
Move faster with security and AI that stays ahead by design
AI Governance, Security & Automation
Stand up AI governance with policies and guardrails, assess your AI systems, then build guarded automation for your existing tooling with security in mind.
AI & Security Training
AI-first training through a self-serve portal and in-person workshops: AI literacy, prompt injection, and AI-era social engineering alongside core security fundamentals.
Fractional SecOps
Senior security operations expertise on a flexible basis or retainer: tooling, triage, hardening, and architecture without the full-time headcount.
About Fletch Labs
A Canadian software development and security firm based in Cambridge, Ontario. We bring over a decade of software development and computer security experience and more than 3 years of hands-on AI work to every engagement.
We operate as a strategic partner, not a vendor. Our small, agile team combines secure engineering discipline with practical AI adoption, building and implementing AI solutions that do not compromise security, privacy, or compliance.
- Security and privacy built in from day one
- Real-world AI experience, not just experiments
- Scoped, retainer, or hourly. We fit how you work.
Which service should you start with?
Short scenarios that point to a typical starting place. Full detail on each service page.
Our teams are already using AI tools and we have no policy for what data can go into them. We need governance before it becomes an incident.
Start with AI governance, security & automation: a governance framework with acceptable use standards, data handling guidelines, and vendor assessment criteria, backed by a security assessment aligned to OWASP LLM Top 10 and NIST AI RMF.
We need fractional security help for incidents, configuration work, and ongoing security engineering, but we are not hiring a full-time security team.
Start with fractional SecOps: ongoing retainer or project-based support for incidents, hardening, and security engineering, with hourly options when you need ad hoc capacity.
We want to use AI (copilots, assistants, or internal models) and need to secure it before we scale, then put AI to work on security operations.
Start with AI governance, security & automation: stand up governance and assess prompt injection, data leakage, and tool permissions against OWASP LLM Top 10 and NIST AI RMF, then build guarded automation for triage, enrichment, and reporting.
We need to build security automation or tooling, with guardrails baked in so the tools we ship do not recreate the risks we are fixing.
Start with AI governance, security & automation: scoped assessment plus guarded automation development that integrates with your existing tooling with security in mind and reduces analyst workload.
We need a penetration test, security assessment, or code review for a launch, customer, or audit.
Start with fractional SecOps for a one-off engagement (a launch, customer, or audit), including vulnerability assessments and penetration-testing support.
We need hands-on training: AI workshops for our team, phishing simulations, or broader security awareness, not just a policy deck.
Start with AI & security training for what we offer (self-serve portal content and in-person workshops), then contact us to scope simulations and programs tailored to your organization.
None of these match, or you are not sure where to begin.
Contact us and we will help you narrow it down.