1. Home
  2. Services
  3. Penetration testing

AI and LLM security testing

AI features accept a new kind of input: text that can override the model's instructions. We test chatbots, copilots, retrieval-augmented generation (RAG) pipelines, and tool-using agents for prompt injection, data leakage between users, and actions taken on an attacker's behalf.

What we test

  • Direct and indirect prompt injection
  • System prompt and sensitive data disclosure
  • Cross-user and cross-tenant data exposure through RAG
  • Excessive agency: unsafe tool, plugin, and function calling
  • Output handling: XSS, SSRF, and code execution through model output
  • Jailbreaks and guardrail bypass
  • Cost exhaustion and abuse of model APIs
  • Supply chain: models, datasets, and third-party AI services

How we approach it

We test the whole application around the model, not just the model. That means poisoning the documents your RAG pipeline retrieves, abusing the tools your agent can call, and checking that the rest of the application treats model output as untrusted input.

What you get

  • Executive summary written for leadership and customers
  • Technical findings with CVSS scores, evidence, and reproduction steps
  • Specific remediation guidance for each finding
  • One retest of reported findings within 90 days, with an updated report
  • Attestation letter you can share with customers and auditors

Typical use cases

  • Launching a customer-facing assistant or agent
  • LLM features with access to internal data or tools
  • Customers asking how your AI features are secured
  • AI governance and risk management programs

Tell us what you need tested.

Send a few details and we'll set up a short scoping call, then follow up with a fixed-fee proposal.

Request a quote