New: Compliance toolkits for the EU AI Act and NIS2 (cybersäkerhetslagen) — templates your auditor will actually accept. Browse toolkits →

About

I'm Amine.
I help teams build AI systems that don't become security incidents.

Contributor, OWASP Top 10 for Agentic Applications 2026 · CISSP · PhD · 15+ years enterprise security

Amine Raji, founder of Molntek

For fifteen years I secured things where the consequences were physical. Grid operators, hospital systems, payment infrastructure. You learn to think in blast radius rather than vulnerability counts, because the question anyone senior asks is never "how many findings" but "what happens if this one goes wrong at 3am".

Then I started running AI agents with real credentials across multi-cluster Kubernetes estates, and found the same question had no good answer. An agent reads a document, decides something, and calls a tool holding permissions nobody threat-modelled. None of the scanners I had trusted for a decade looked at that path.

I kept meeting the same standoff. Engineering teams shipping capable AI systems with no security expertise in the room, and security teams asked to sign off on systems they had no way to reason about. Both were right, and neither could close it alone. I do both jobs, so I sit in the middle.

I contribute to the OWASP Top 10 for Agentic Applications 2026 and speak on agent security. The most useful thing I have published recently is the OWASP Stockholm debrief on a year of hands-on MCP work: which attacks kept recurring, and which defences held.

The short version of what I have learned: prompt-level controls fail and infrastructure controls hold. The attacks are genuinely new. The defences that survive contact are scoping, identity and segmentation, which your team already knows how to enforce.

What makes this different

I ship these systems as well as break them

My working knowledge of prompt injection and agentic privilege escalation comes from operating agents in production, not from reading the standard I help write.

Findings your engineers can act on

Every issue arrives with a reproduction and a specific remediation, sequenced by how much risk it removes per unit of effort. Your team should be able to start on Monday.

One subject, done properly

AI security is all I sell. If your problem is network segmentation or SOC 2, I will tell you on the first call and point you somewhere better.

How I work

You talk to me directly. No account managers, no junior staff doing the work while a senior signs off. If you engage with Molntek, you engage with me.

I'll tell you if it's not the right fit. A bad engagement helps no one. If what you need isn't what I do, I'll say so on the first call.

The goal is a safer system, not a finished report. I care whether your team understands the risks and knows what to do about them, not whether the PDF is thorough enough to file away.

Want to know if I can help?

30 minutes. I'll ask about your system and tell you honestly what I think.