1. Home
  2. Services
  3. AI security testing
AI & LLM

Your AI features shipped faster than their threat model

Prompt injection, data leakage, tool and agent abuse, and model supply chain risk — tested against your real deployment, with your real guardrails in place, rather than a demo notebook.

What this covers

  • Direct prompt injection and jailbreak attempts
  • Indirect injection through documents, web pages and retrieved content
  • Data leakage via retrieval, context windows, logs and error messages
  • Guardrail and content-filter bypass testing
  • Tool, plugin and agent permission abuse
  • Excessive agency and unsafe autonomous actions
  • Training and fine-tuning data exposure review
  • Model, dependency and supply chain assessment
  • Output handling — XSS, SSRF and code execution via model output

The new attack surface is language

Indirect injection is the one that hurts

Agents change the blast radius

Treat model output as untrusted inputAnything a model produces should be validated, encoded and authorised exactly as if it came from an anonymous internet user — because after an indirect injection, that is precisely what it is.

How we approach an AI assessment

Questions

Questions about ai security testing

Almost never. The vulnerabilities we care about live in the application around the model — the prompts, the retrieval pipeline, the tools and the output handling. We test through the same interface your users and attackers would use, which is the more realistic assessment anyway.

That is where most of our AI work happens. Retrieval-augmented systems introduce two specific risks: poisoned content entering the context window, and cross-user data leakage through poorly scoped retrieval. Both are testable, and both are common.

Sometimes, and we will tell you honestly which ones held up. Guardrails raise the cost of a successful attack, but no filter reliably distinguishes instruction from data. The durable mitigations are architectural: least-privilege tools, strict output handling, and never letting retrieved content carry authority.

Ready to look at this properly?

A 30-minute call, no pitch deck. We will tell you whether we are the right fit — and if we are not, we will point you somewhere better.

Book a security review