AI and LLM penetration testing

AI features accept a new kind of input: text that can override the model’s instructions.

We test chatbots, copilots, retrieval-augmented generation (RAG) pipelines, and tool-using agents for prompt injection, data leakage between users, and actions taken on an attacker’s behalf.

What we test

  • Direct and indirect prompt injection
  • System prompt and sensitive data disclosure
  • Cross-user and cross-tenant data exposure through RAG
  • Excessive agency: unsafe tool, plugin, and function calling
  • Output handling: XSS, SSRF, and code execution through model output
  • Jailbreaks and guardrail bypass
  • Cost exhaustion and abuse of model APIs
  • Supply chain review: models, datasets, and third-party AI services

Why it matters

How we approach it

We test the whole application around the model. That means planting instructions in content your RAG pipeline retrieves, abusing the tools your agent can call, and checking that the rest of the application treats model output as untrusted input.

Standards and references: OWASP Top 10 for LLM Applications (2025), MITRE ATLAS, NIST AI RMF

Included in every penetration test

  • Manual testing by our own US-based testers, backed by tooling.
  • Critical findings are reported within 24 hours of confirmation, not held for the report.
  • Executive summary and technical findings with severity ratings, evidence, and reproduction steps.
  • Final report delivered within 5 business days after testing ends.
  • A walkthrough call with your team after the report.
  • An attestation letter you can share with customers, auditors, and insurers.
  • One retest of reported findings within 90 days of the final report, included in the price.
  • Every engagement is a fixed fee after a free scoping call.

Engagement commitments apply to work under a signed HackNow proposal.

When to use it

  • Launching a customer-facing assistant or agent
  • LLM features with access to internal data or tools
  • Customers asking how your AI features are secured
  • AI governance and risk management programs

What we’ll need from you

  • Access to the AI feature, with test accounts for each user role
  • The system prompt and tool or function definitions, if you can share them
  • What the model can reach: documents, databases, APIs, or other tools
  • Any usage or cost limits we should stay within
  • Which model providers and third-party AI services are involved

See the full scoping checklist

Questions about AI and LLM testing

How much does it cost?

Prices start at $5,000 for the smallest scope. Your price depends on the number of AI features, the tools the model can use, and the data it can retrieve, and it’s a fixed fee set after a free scoping call.

Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call.

How long does it take, and when do we get results?

Testing can usually start within 5 business days of signing. Testing typically takes one to two weeks. Critical findings are reported within 24 hours of confirmation, not held for the report. Final report delivered within 5 business days after testing ends.

Will testing disrupt our systems?

Testing is planned to avoid disruption. We agree on testing windows, source IP addresses, and emergency contacts before we start. Denial-of-service and destructive testing are never performed without written approval, and you can pause testing at any time with one message.

Is a retest included?

Yes. One retest of reported findings within 90 days of the final report is included in the price. We verify each fix and issue an updated report and attestation letter.

Do you test the model or the application around it?

The application around it: the data the model can retrieve, the tools it can call, and how your app handles its output. Those are the paths an attacker uses to turn a prompt into a data leak or an unwanted action.

Last reviewed October 2026

Ready to test your AI features?

We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.