Bring AI into your work safely — without putting your data at risk.

I help Iranian businesses and organisations start AI where their data stays safe — and finish with an acceptance criterion that holds up in front of a board and an auditor.

13+ years in information security, networking, IoT and ERP · ISO/IEC 42001 · NIST AI RMF · OWASP LLM Top 10

Positioning

I start from where your data goes — not from the tool

Most people who consult on AI start from the tool. I start from where your data goes and what happens if it leaks.

The reason is simple: before moving into this field, I spent over a decade working in information security, networking, IoT and ERP. In those years I saw enough careless technical decisions turn into serious problems months later.

In practice this means the order of work matters more than the choice of tool. If you pick a tool first and then discover your data is not allowed into it, you have lost both the money and the organisation’s trust in the whole idea.


About

Who you would be working with

I did not arrive at AI from the tool side. I arrived from the side that has to keep the data safe.

I am Sheida Bohlouly — an AI and IT consultant based in Tehran. Before this field, I spent over a decade in information security, networking, IoT and ERP, and that order is the reason this site talks about data before it talks about models.

What I do now is the secure implementation of existing models inside real workflows: choosing what may be automated, deciding what must never leave your network, and writing down the number that says whether it worked.

  • Information security & networkingDesigning and implementing access controls, network segmentation, and incident response.
  • Internet of ThingsSystems that move data from the edge to the centre, where every connection point is an attack surface.
  • ERPClose experience with how an organisation’s real processes work — and why solutions that ignore the process fail.
  • AI & Persian language processingSecure implementation of language models on real work, focused on the Persian-specific problems generic tools do not solve.

Frameworks I work against: ISO/IEC 42001 · NIST AI RMF · OWASP LLM Top 10

The answer to those questions

The three-step path to secure AI

  1. 01

    Data map

    We establish what data you hold and which of it must never leave your internal network.

  2. 02

    First task

    One specific, repeatable task is automated first — a tangible output, not a strategy deck.

  3. 03

    Acceptance criterion

    The number that tells you it worked, signed before we start.

Engagement

Four engagement packages

No package starts without a signed acceptance criterion, and each one ends with a system card — not a slide deck.

Package 0

AI Working Session

A working session on your actual work — not a generic example. We identify which of your daily tasks can be automated today, with which tool, and which of your data must never enter an external tool.

Duration:
Half-day or full-day

Acceptance criterion

At least one of the three identified tasks is running by the end of that same week.

Package 1

Readiness & Governance Assessment

Process mapping, data sensitivity classification, gap analysis against ISO/IEC 42001 and NIST AI RMF, and prioritisation of the first three processes.

Duration:
2–4 weeks

Acceptance criterion

A prioritised list of at least three processes, each with a time and risk estimate, signed off by the client.

Package 2

Secure Implementation (Pilot)

Tool selection and configuration matched to your data sensitivity level, deployment architecture, OWASP LLM Top 10 controls, an evaluation set, guardrails, logging and monitoring.

Duration:
8–12 weeks

Acceptance criterion

A specific number on the evaluation set — minimum agreed accuracy on samples held out from development data — plus an access test report showing no cross-unit leakage.

Package 3

Adoption & Retention

Team training, human-in-the-loop procedures, quarterly review of the evaluation set and regulatory status, and knowledge transfer.

Duration:
Monthly or quarterly

Acceptance criterion

At least two people in the organisation can run and interpret the evaluation set without me.

Pricing is not published. Without knowing your work, any number I write would be meaningless — and the brand’s claim discipline does not allow a number without its conditions.

Why ShidHoosh can be trusted

  • Explicit criteriaWe do not start without a signed, numeric acceptance criterion.
  • Isolated environmentWe do not work on sensitive data without a written agreement and independent infrastructure.
  • Complete honestyEach solution’s limitations and technical risks are written down next to its benefits.
  • Human authorityOn high-risk decisions the final call stays with you.

Boundaries

What I don’t do

Stating the boundaries up front means neither of us wastes the other’s time.

  • I do not train foundation models — my work is the secure implementation of existing models in your workflow.
  • I do not promise headcount replacement — on high-risk decisions, authority stays with a human.
  • I do not work on sensitive data without a written agreement and an isolated environment.
  • I do not accept work that has no numeric acceptance criterion.
  • I do not build clinical or diagnostic applications — that field needs separate regulatory validation.
  • I do not give legal advice — final mapping to legal requirements belongs with your compliance team.

You will also not find client testimonials, client logos, or unsourced numbers on this site. Until I have a published measured result, that space is filled with real, working tools instead — six of them in the Lab, all running entirely in your own browser.

Next step

Get in touch

A 30-minute call, free and with no commitment. If your problem isn’t something I can help with, I’ll say so in that call.

  • No cost, no commitment
  • A straight answer in that same call

ShidHoosh — Founder: Sheida Bohlouly

AI & IT Consultant · Security · Governance · Automation · NLP

Tehran, Iran

نسخه‌ی کامل فارسی · Privacy