Skip to content
phaiAI.tech
About

PhaiAI Tech builds the unglamorous parts that make agents trustworthy.

PhaiAI Tech is an AI-native software development practice. We are engineers, not a reseller — we work on ASDLC design, domain-focused agents, agentic engineering platforms and agentic security, and we publish what we build on so our work can be checked against it.

PhaiAI TechASDLCAgentic platformsAgentic security
What we believe

Four positions, stated plainly enough to be argued with.

These are not values on a wall. They determine what we propose, what we refuse, and when we tell a client the answer is to fix something else first.

01

The platform decides the outcome, not the model

A faster model makes one agent quicker. Many agents running governed paths in parallel is throughput, and throughput is a property of identity, sandboxes, gates and observability. The competitive dynamic is a platform race wearing a model race's clothes.

02

Domain context is the difference between useful and plausible

A general agent knows how software is usually written. Yours needs one that knows how your software is written — its patterns, its regulations, its awkward decisions and the reasons behind them. That is an engineering problem with a real answer, not a prompt to tune.

03

Governance earns speed rather than costing it

Teams accept controls that let work continue. A policy that rewrites an unbounded query is adopted; one that blocks it with an apology gets routed around by Friday. We design controls that survive contact with delivery pressure.

04

We would rather tell you not to buy this

If your instinct is that a three-layer reference architecture feels like overkill for your estate, you are probably right. If your IDP is not solid, an AEP is the wrong project. We say so during the assessment, before there is anything to defend.

How we engage

Four shapes of work, all of them bounded.

Every engagement produces artefacts you own and can read without us in the room. We do not open with a transformation programme, and we do not leave behind a platform only we can operate.

ASDLC assessment

2 weeks

One real value stream traced end to end and located on the four-level model. Every path classified. Every unwritten definition of done named. You keep the findings regardless of what happens next.

Level assessmentPath inventoryGap registerRecommended first loop

Domain agent build

6–10 weeks

Our agent packages forked against your bounded context, a Domain Context Engine standing behind them, your rules encoded as rules, and one hybrid path running end to end with real gates.

Agent packagesDomain Context EnginePath definitionsEval suite

Agentic security review

3–4 weeks

Threat modelling against the OWASP agentic guidance, red teaming of the live deployment, an AgBOM inventory of the estate, and an ACS Guardian in front of the riskiest agent before we leave.

Findings registerAgBOMPolicy bundlesGuardian deployment

Platform engineering partnership

quarterly

Ongoing work as your AEP moves from minimum viable platform to something several domains run on. Agent Infrastructure as Code, eval infrastructure, and the unglamorous work of keeping context true.

AIaC repositoryDomain onboardingEval platformCost governance
How we participate

Standards, not proprietary lock-in.

We publish our agents into an open package format, govern them with an open standard, and expose our context engines over an open protocol. If a client wants to leave, they should be able to — that constraint keeps us honest about where our value actually is.

Agent packages on APM

Our agents ship in the Agent Package Manager format so they install on any harness a team already uses, with the lockfile and policy behaviour provided by the open project rather than by us.

reference ↗

Governed by the Agent Control Standard

We implement against ACS, track its milestones, and report where our conformance is partial. Self-declared conformance is not verified by anyone in v0.1.0, and we would rather name that than lean on it.

reference ↗

Developed to OWASP GenAI guidance

The OWASP GenAI Security Project's agentic developer guidelines are the checklist our design reviews and gates encode, with section numbers cited so a reviewer can check our work against the source.

reference ↗

Context over MCP

Domain Context Engines and tool gateways are exposed over the Model Context Protocol, so a client's future harness choice is not a migration project.

reference ↗

Book a working session.

Not a discovery call. Ninety minutes with your platform and delivery leads, on one real value stream, ending with a written view of which level you are at and what the next level would actually require.

Research & correctionsresearch@phaiai.tech
Security disclosuresecurity@phaiai.tech

PhaiAI Tech · phaiai.tech

Bring these to the session

  • One value stream you would call representative
  • Whatever passes for your definition of done today
  • The list of AI tools already in use, sanctioned or otherwise
  • Your honest answer on whether the IDP underneath is solid

Prefer to start with the material? The ASDLC page covers the lifecycle model, and the agent catalogue shows exactly what ships in a package.