Security · Data · AI
Engineering Security
for an Autonomous World.
We design, build and secure cybersecurity, data and AI systems for modern organizations — across security operations, data platforms, agentic AI and cloud infrastructure.
Engineering first
KOR IT is an engineering company. We design, build and integrate systems — we do not deliver slide decks and leave.
Evidence, not assertion
Architectures are validated in our own lab before they are recommended. Every measurement we publish carries the configuration it came from.
Nothing invented
No customer logos, no benchmark claims, no invented metrics. Where something is experimental, the page says so.
Services
Engineering. Integration. Protection.
Four pillars. Hover one to see where it sits in the architecture.
Solutions
How the capabilities combine.
Services describe what we can do. Solutions describe the architecture you actually end up with.
AI-Ready SOC
SOC + Security Data + AI + Automation
A security operations architecture where AI assists triage and enrichment, high-risk actions stop at a human, and every step is auditable.
Security Data Platform
Telemetry + Pipelines + Governance + Analytics
A designed security data estate: sources, pipelines, schema, lineage and quality — the foundation every detection and AI capability inherits.
Secure Agentic AI
Agents + Memory + Tools + Identity + Policy + Observability
A control plane around autonomous agents: identity, memory governance, tool policy gates and telemetry a SOC can actually use.
AI Governance & Observability
Models + Data + Agents + Telemetry + Governance
Making AI systems accountable: what runs, on what data, under whose authority — and what the organisation can prove afterwards.
Sovereign AI Infrastructure
Local AI + Secure Infrastructure + Observability + Governance
AI capability that runs inside your boundary: local inference, open models, and the infrastructure and telemetry to operate them.
KOR IT LAB
Build. Measure. Break. Improve.
Controlled environments for testing emerging security, data and AI architectures before they become real-world systems.
AI Lab
Local inference, open models, agent architectures, memory and the performance characteristics of running all of it on owned hardware.
- Local inference
- Open models
- Agent architectures
- Memory
- +2
Security Lab
Agent security, memory provenance, runtime policy, tool boundaries and what any of it looks like from a SOC.
- Agent security
- Memory security
- Runtime policy
- Tool security
- +2
Data Lab
Security data architecture, governance, metadata, lineage and data quality — modelled and tested before it reaches an estate.
- Data architecture
- Security data
- Governance
- Metadata
- +2
Observability Lab
Infrastructure, AI, agent, network and security telemetry — designed together, because the questions cross all five.
- Infrastructure telemetry
- AI telemetry
- Agent telemetry
- Network telemetry
- +1
Products
Ideas that survived the lab.
Research validates an idea. The lab builds it. A small number become products — and we say plainly which is which.
Cryptagion
Crypto-Agility & Post-Quantum Readiness
Discover cryptographic exposure. Build your CBOM. Prepare for post-quantum migration.
cryptagion.io
Agent Security
Security and observability for AI agents, their memory, tools and actions
An emerging direction: a control plane that gives agents an identity, governs their memory, mediates their tools and makes all of it visible to a SOC.
Selected projects
What we have actually built.
Every entry carries its maturity status. Nothing here is presented as more finished than it is.
Agent Security Control Plane
Prototype control plane for governing how agents reach memory, tools, identities and data, with policy and telemetry as first-class layers.
AI Security · Agent Security
Memory Contract Specification
An experimental specification for runtime contracts that decide when a memory record is allowed to influence an agent. Principle: Trust Before Recall.
Agent Memory Security · Agent Security
Sovereign Agentic AI Lab
A self-hosted agentic AI environment on owned hardware, used to study inference, retrieval and agent security without external model dependencies.
AI Infrastructure · AI Security
AI-Native SOC Lab
Active research into AI-assisted triage, agent-assisted investigation and human-in-the-loop automation inside a working security operations lab.
Security Operations · Security Operations
Cryptagion
A KOR IT venture for cryptographic discovery, inventory and post-quantum migration planning. Full detail lives on the venture page and at cryptagion.io.
Cryptographic Security · Cryptographic Security
Insights & publications
Work published outside KOR IT.
Memory Poisoning: when the AI agent becomes the SOC's blind spot
Memory Poisoning : quand l'agent IA devient l'angle mort du SOC
Ali Korsi · KOR IT · September / October 2026
Memory Poisoning: When AI Agent Memory Becomes a Security Boundary
Persistent agent memory is an attack surface. We examine provenance, recall policy, and why memory operations remain largely invisible to the SOC.
Agent Security · September 2026
Agent Security: Identity, Tools, Memory and Runtime Policy
An active research programme on agent security: identity and authorisation, tool and MCP inventory, memory, runtime policy, and telemetry.
AI Security · April 2026
About KOR IT
An engineering company with a laboratory attached.
KOR IT designs, builds, integrates and secures modern systems across cybersecurity, security operations, data engineering, AI, agentic systems, cloud infrastructure and observability.
Research exists here to strengthen the engineering, not to replace it. The LAB validates ideas in a controlled environment; a small number of those ideas become products. That pipeline — engineering, experimentation, products — is the whole of the company, and it is why we can say what we know and where our knowledge stops.
Engineering
Services, integration and build
Experimentation
The LAB — measured, limited, published
Research
Published work supporting the engineering
Products
Cryptagion, and what comes after it
Ali Korsi is the founder of KOR IT, a cybersecurity engineering and research organisation. His work sits at the intersection of security operations, security architecture, security data engineering, data, AI security and agent security — a combination that reflects how he arrived at the subject rather than a set of interests assembled after the fact.
- Security engineering
- SOC / SIEM
- Security data
- Data
- AI
- AI security
- Agent security
Contact
Tell us what you are building, and what worries you about it.
Security operations, security data, AI and agent security, or cloud and platform engineering — we will tell you honestly whether it is work we should be doing.