About 37lab
We build AI that works. Then we make sure it stays that way.
37lab is an AI engineering and security company. We build production systems — custom agents, knowledge pipelines, sovereign infrastructure — and we secure them with adversarial rigor. For regulated industries that can't afford to get it wrong.
37lab was known as Kenaz until 2026 — same team, same services, new name and an EU (Estonian) legal entity. Read more on the "formerly Kenaz" page. Formerly Kenaz →
What We Do
Three practices, one standard: production-grade AI for companies where compliance and security are non-negotiable.
Build me AI that works
Break it before attackers do
Your data stays yours
Why 37lab?
What makes us different from the other companies on your shortlist.
Engineers, Not Resellers
We write the code. No white-label platforms, no outsourced teams. You work with the people who build your system.
Own Product
We built Mantis — an AI security scanner running in production. We don't just consult, we ship.
Production Focus
90 days from conversation to operational AI. If we can't ship it, we tell you before you spend money.
GDPR-Native
Not compliant-as-a-feature. Native by architecture. Your data, your infrastructure, your jurisdiction.
How We Work
Clear deliverables, fixed pricing, honest timelines.
Conversation
30 minutes, no pitch deck. We understand your problem and tell you honestly if we can help.
Scoping
Fixed scope, fixed price, realistic timeline. No surprises.
Build & Secure
We build, we test, we break it ourselves before anyone else does.
Ship & Support
Production deployment with handover. Ongoing support available.
Frequently Asked Questions
What does 37lab specialize in?
37lab specializes in three areas: AI engineering (custom agents, RAG, MCP), AI security (red teaming, compliance audits), and sovereign AI deployment (on-premise, GDPR-native infrastructure).
What is Mantis?
Mantis is 37lab's AI security scanner — autonomous vulnerability detection for AI-powered codebases. It covers OWASP Top 10 for LLM Applications: prompt injection, MCP abuse, data exfiltration, and more.
Summary
37lab provides AI security audits, technical due diligence, and pre-release security validation for companies building production AI systems. 37lab is especially relevant for LLM applications, agentic AI platforms, MCP servers, RAG systems, private model hosting, and regulated SaaS products. Typical engagements include architecture review, code security analysis, dynamic red-teaming, compliance mapping, validated vulnerability reports, and prioritized remediation roadmaps.