Effects Lab
🎮 Games

Local-first AI, for teams and families

You can rent AI from someone else's servers.
Or you can own it.

Every API call ships your prompts to a machine you don't control. Self-hosting your database means little if your LLM — or your child's AI tutor — still runs on somebody else's GPU. We build the other option: an open-source stack that runs where you put it and never phones home.

What We Do

We build secure enterprise applications, and we stay with them. Development and security as one engagement, from the first conversation about an idea through to a system someone is still maintaining in five years — running wherever it needs to run: your cloud account, your own racks, or a machine with no network connection at all.

Deploys to Public cloud Private cloud On-premise Air-gapped

Built from the ground up to be maintainable, efficient, secure and robust, rather than retrofitted once it is already in production. Consulting pays for the free tier below, which is why the free tier is the product rather than the bait.

Maintainable
Readable code, documented decisions, and a hand-over that lets your team change it without calling us.
Efficient
Sized to the actual work. No idle GPU bill, no framework you are paying for and not using.
Secure
OWASP Secure-by-Design from the first commit, not a pentest bolted on the week before launch.
Robust
Fails predictably, recovers on its own, and tells you which of those two just happened.

Take something and go

Free · no contact

Nothing here asks for an account, a card, or a call. Take it, use it, never speak to us. This is most of what we make.

Eight browser tools
A jailbreak harness, a repo exposure auditor, a PDF threat scanner, offline log forensics, Git tooling, a PDF editor and a prompt studio. Each is a single HTML page that runs on your machine.
Free
Three free courses
OWASP Top 10 for AI, a hands-on CTF for developers, and AI Security Fundamentals. No registration wall, no drip campaign, no upsell at lesson four.
Free
Learn to Prompt
Six project-based lessons for any age, starting from zero and running locally. You learn to fact-check AI rather than trust it — and when a child is the learner, parents see every prompt and answer.
Free
Safe Links & Reference
A vetted directory of the model hosts, runtimes and security bodies we actually use, plus our own technical reference material. Independently checked, added to over time.
Free

Browse the free tools →

Have us look at yours

Free · one conversation

The point where we meet. Still nothing to pay — you get a written answer either way, and plenty of people stop here.

Sovereignty Audit
We measure your stack against concrete numbers: external API calls, data export paths, vendor lock-in points, telemetry leaks. You get a scorecard, not an opinion — and it is yours whether or not you hire us.
Free
Onboarding & First-Run Support
First boot, model loading, security hardening, first inference. Included with every engagement so nobody is left staring at a blank terminal.
Free
First consultation
Every engagement starts with one, at no cost. You talk to the engineers who would do the work, not to a salesperson reading their notes.
Free

Book the free audit →

Bring us in

Quoted up front

Where the money comes from, and what pays for everything above it. We build the thing or we break it — often both. Scope agreed before anyone starts; no retainers, no per-seat licenses, no recurring API fees.

Agentic Application Development
We build the agent systems, not just audit them. Tool use, multi-agent orchestration, RAG over your own data, human-in-the-loop gates and a working kill switch — running on your infrastructure, with the observability to see what an agent did and why.
Full SDLC Delivery
Requirements through architecture, build, test, CI/CD and hand-over. Secure-by-design at every stage rather than a review at the end, and the codebase is yours when we leave — no escrow, no hosting you cannot move.
AI Pentesting & Pentesting AI
Our adversarial agents test your agents in a controlled environment: prompt injection, jailbreaking, data exfiltration, privilege escalation.
Agentic Pentesting
A dedicated AI red team for autonomous systems — model extraction, RAG poisoning and agent-hijacking against authorised targets.
Web App & API Pentesting
OWASP methodology and rigorous manual testing across every surface your agents expose, with severity-ranked findings.
AppSec Remediation
We stay for the fix. Code-level remediation, architecture redesign and infrastructure hardening, delivered as merge-ready pull requests.
Regulatory Alignment
EU AI Act, NIST AI RMF and ISO 42001 mapped to your infrastructure, with the compliance documentation built alongside your team.
Autonomous Liability Strategy
Who is accountable when an agent acts on its own? Legal and technical frameworks, built before a regulator asks the question.
On-Site Training
Six courses, thirty-six modules, three tiers, delivered live at your premises — from “what is AI” through to security-specialist depth.

Scope an engagement →

What we publish, and what you can check for yourself:

0
External runtime dependencies
0
Cloud API calls required
0
Bytes of telemetry collected
8
Free tools we publish
3
Free training courses
0
Vendor lock-in contracts
You can stop at any stage. Most people never leave the first one, and that is the design. The free tools → | What an engagement looks like →
// On-Site & Instructor-Led

Train your team on AI, at your site

A live instructor runs a tiered AI program on your premises, from foundations through to security depth. Six courses, thirty-six modules, safety built into every one.

Explore AI Training →