AI and LLM penetration testing
AI features accept a new kind of input: text that can override the model’s instructions.
- Reply within one business day
- NDA on request
We test chatbots, copilots, retrieval-augmented generation (RAG) pipelines, and tool-using agents for prompt injection, data leakage between users, and actions taken on an attacker’s behalf.
What we test
- Direct and indirect prompt injection
- System prompt and sensitive data disclosure
- Cross-user and cross-tenant data exposure through RAG
- Excessive agency: unsafe tool, plugin, and function calling
- Output handling: XSS, SSRF, and code execution through model output
- Jailbreaks and guardrail bypass
- Cost exhaustion and abuse of model APIs
- Supply chain review: models, datasets, and third-party AI services
Why it matters
-
IBM (2026): 21% of breached organizations reported an AI model or application incident, up from 13%; 92% of those lacked proper AI access controls.Source: IBM and Ponemon Institute, Cost of a Data Breach Report 2026 (2026) (PDF)
The 21% is a share of the breached organizations IBM studied, not of all organizations.
How we approach it
We test the whole application around the model. That means planting instructions in content your RAG pipeline retrieves, abusing the tools your agent can call, and checking that the rest of the application treats model output as untrusted input.
Standards and references: OWASP Top 10 for LLM Applications (2025), MITRE ATLAS, NIST AI RMF
Included in every penetration test
- Manual testing by our own US-based testers, backed by tooling.
- Critical findings are reported within 24 hours of confirmation, not held for the report.
- Executive summary and technical findings with severity ratings, evidence, and reproduction steps.
- Final report delivered within 5 business days after testing ends.
- A walkthrough call with your team after the report.
- An attestation letter you can share with customers, auditors, and insurers.
- One retest of reported findings within 90 days of the final report, included in the price.
- Every engagement is a fixed fee after a free scoping call.
Engagement commitments apply to work under a signed HackNow proposal.
When to use it
- Launching a customer-facing assistant or agent
- LLM features with access to internal data or tools
- Customers asking how your AI features are secured
- AI governance and risk management programs
Can support:
What we’ll need from you
- Access to the AI feature, with test accounts for each user role
- The system prompt and tool or function definitions, if you can share them
- What the model can reach: documents, databases, APIs, or other tools
- Any usage or cost limits we should stay within
- Which model providers and third-party AI services are involved
Questions about AI and LLM testing
How much does it cost?
Prices start at $5,000 for the smallest scope. Your price depends on the number of AI features, the tools the model can use, and the data it can retrieve, and it’s a fixed fee set after a free scoping call.
Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call.
How long does it take, and when do we get results?
Testing can usually start within 5 business days of signing. Testing typically takes one to two weeks. Critical findings are reported within 24 hours of confirmation, not held for the report. Final report delivered within 5 business days after testing ends.
Will testing disrupt our systems?
Testing is planned to avoid disruption. We agree on testing windows, source IP addresses, and emergency contacts before we start. Denial-of-service and destructive testing are never performed without written approval, and you can pause testing at any time with one message.
Is a retest included?
Yes. One retest of reported findings within 90 days of the final report is included in the price. We verify each fix and issue an updated report and attestation letter.
Do you test the model or the application around it?
The application around it: the data the model can retrieve, the tools it can call, and how your app handles its output. Those are the paths an attacker uses to turn a prompt into a data leak or an unwanted action.
Last reviewed October 2026
Often paired with
- Web application penetration testing Authenticated, manual testing of your web apps, from the login page to business logic.
- API penetration testing REST, GraphQL, gRPC, and WebSocket APIs tested for authorization flaws and data exposure.
- Secure code review and threat modeling Design reviews and manual source code review that find security flaws before they ship.
Ready to test your AI features?
We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.