About GovernGuard
GovernGuard is an independent AI security and governance practice for CISOs and security leaders at regulated enterprises and defense organizations. Its discipline is AI governance engineering: turning AI governance frameworks into guardrails that actually run in production. The practice exists because the field has plenty of policy advisors and plenty of security tooling, but very little help from the place where they meet.
The gap
Most AI-governance advisors come from policy. Most AI-security engineers never read the framework. This practice operates in the gap between them, running the governance program and engineering its controls with the same hands. Frameworks like NIST AI RMF, the EU AI Act, and ISO/IEC 42001 only matter when someone translates them into controls that engineers can implement and auditors can verify. Hence the name: AI governance, and the guardrails that enforce it.
Who’s behind it
I’m Vasan Kidambi, VK for short. I’ve spent 25+ years in security across financial services, technology, healthcare, and defense. Today I’m the AI security architect on a U.S. Department of Defense program, working on security architecture and governance for agentic AI in cyber operations. Before that I worked on cloud security and DevSecOps for U.S. Air Force Cloud One through SAIC, and, contracting independently, for BESPIN, the U.S. Air Force software factory. Earlier, my security work spanned Microsoft, State Street, American Express, and JPMorgan Chase, alongside roles at KPMG, Merck, ADP, Lenovo, and 3M.
I hold AAISM — ISACA’s Advanced in AI Security Management credential, the certification closest to what this practice does — alongside CISSP, ISSAP, CCSP, CISM, CISA, and CRISC. I earned an M.S. in Cybersecurity Analytics and Operations from Penn State and a B.S. in Information Systems from BITS Pilani.
The approach is public: soc-triage-agent, published under Apache-2.0, is a defensive AI agent paired with the governance layer that controls it. The same dual mandate, in running code.
Start an inquiry
If you’re weighing an AI governance program, an audit-ready control set, or guardrails around a production AI system, see how I work, then use the contact form or find me on LinkedIn.