Cybersecurity, AI Security & Governance

Nineharbor - Cybersecurity, AI Security and Governance for Regulated Institutions

A harbor is judged by one measure: what holds when the weather arrives.

Why the name · nine lights, one standard

Nineharbor is an independent practice for the security and governance of intelligent systems.

--:-- Manama · Kingdom of Bahrain

We test AI the way adversaries approach it, and govern it the way regulators read it.

--:-- London · United Kingdom

Every finding evidenced. Every control demonstrated. Every claim one an auditor can stand behind.

--:-- Manama · Kingdom of Bahrain

Built inside regulated financial services and now serving institutions that must answer for the AI they deploy - to boards, to auditors, and to the regulators of the UK, EU and GCC.

What we do

Four disciplines, one standard: evidence over opinion.

Assess

AI security assessment

Hands-on adversarial testing of AI systems: prompt injection and agentic attack paths, model and pipeline hardening, LLM application review, and secure-build verification. Findings arrive reproduced, evidenced, and mapped to the frameworks your auditors use.

Govern

AI governance & compliance

Classification and conformance against the EU AI Act, ISO/IEC 42001 and NIST AI RMF, with privacy obligations mapped across UK and EU GDPR, the Bahrain, Saudi and UAE PDPLs, India DPDP and Singapore PDPA. Governance written for the regulator who will actually read it.

Attest

Attestation & assurance

Verifiable proof that controls hold: boundary and egress enforcement, grounded outputs, audit-ready evidence trails. Not a statement that a control exists, but a demonstration that it held when tested.

Build

Secure agentic systems

Design and review of AI agent architectures that run locally with zero data egress, keeping models, prompts and records inside your estate. Built for institutions where data sovereignty is a requirement, not a preference.

25+
years in regulated financial services, GCC and UK
5
professional certifications held by the principal*
16
security, privacy and AI frameworks mapped in delivery
0
client data leaving the client estate - local-first by design
* CISSP, CISM, CISA, CAISP, CMCPSE. Nineharbor Ltd is registered in England and Wales.
Frameworks & jurisdictions

Mapped to the rules your regulator tests.

Every engagement is delivered against named provisions of the applicable frameworks, across the UK, EU, GCC and Asia, so findings translate directly into your compliance position.

EU AI Act ISO/IEC 42001 NIST AI RMF UK GDPR EU GDPR DORA Bahrain PDPL Saudi PDPL UAE PDPL India DPDP Singapore PDPA CBB Rulebook SAMA CSF FCA OWASP LLM Top 10 MITRE ATLAS
I spent twenty-five years on the institution's side of the audit table. Nineharbor exists so that when an institution says its AI is secure and governed, the statement is not a hope - it is a demonstrated, evidenced fact.
Narendra Karki Founder · CISSP, CISM, CISA, CAISP, CMCPSE
How we work

Institutional in standard, independent by design.

Independent by design

No vendor alliances, no resold tooling, no incentive to find what a partner sells. Assessment and attestation only mean something when the assessor has nothing else to gain.

Local-first, zero egress

Our tooling runs inside the boundary. Client data, prompts and findings never transit a third-party cloud, which is precisely what we would tell you to demand of anyone else.

Evidence, not opinion

Every finding is reproduced, sourced to a primary text or a demonstrated exploit, and verified before it reaches you. If we cannot ground it, we do not report it.

Built in regulated finance

We have sat on the institution's side of the audit table across the GCC and UK, and we write findings for the people who will sit across it from you.

Contact

Bring us the system you are least sure about.

A first conversation is free, confidential, and usually tells you within an hour whether the risk you suspect is real.