Three Backticks Consulting: Security for Software That Acts on Its Own
Three Backticks Consulting GmbH is the security consultancy I founded for teams shipping LLM agents, automation, and the infrastructure underneath them.
What we do
- Agent security: prompt injection, tool abuse, privilege boundaries, and the blast radius of an agent that gets something wrong
- Threat modelling: what an attacker wants, where your trust boundaries sit, and which mitigations are worth building
- Code audits: targeted review of authentication, tool execution, sandboxing, and secrets handling, with findings ranked by exploitability
Engagements run one to four weeks and end in a technical report you can hand to your board, your auditors, or your customers: findings, reproductions, and the fixes we would make first.
Alongside client work we build our own software: the Expected Loss Calculator, which puts a number on cyber risk; Sampo, which runs agents for weeks at a time on a Nextcloud; hardened Nextcloud hosting; and CruxHub.











