AI Security / CORE SERVICE

AI Security Testing

AI security testing for LLM applications, agents, MCP servers, and RAG pipelines, with manual attack validation, clear fixes, and retest evidence.

THE WORK, IN CONTEXT

AI Security Testing, with a clear purpose.

AI Security Testing covers the AI systems you already run: the model, the application built around it, and every tool, data source, and identity the model can reach. Five focused services sit under this core. The application penetration test probes the model-facing layer and the interfaces, sessions, and access controls around it. The agentic assessment examines how an autonomous system plans, remembers, and acts on your behalf, and what it can do without a human in the loop. The connector assessment tests the components that hand the model new tools and the credentials behind them. The data boundary test checks whether retrieval ever returns information a user is not entitled to see. The red team exercise runs objective-driven campaigns against your guardrails. Every engagement follows one rhythm: scope in writing, test by hand under agreed spend and rate caps with a pause contact, report with reproduction steps and fixes, then retest with evidence.

A GOOD FIT WHEN

For CTOs, CISOs, and product owners who have shipped, or are about to ship, an assistant, copilot, agent, or retrieval feature, whether it runs on a hosted model service or a model you operate yourself. Engage before launch, before a customer security review, or after a change widens what the model is allowed to reach.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Map the model, tools, and data

We start from a walkthrough with the people who built the system: the model behind it, the application around it, the tools and data it can reach, and the identities it acts with. We agree which focused services apply, the roles to test as, staging or production, the spend and rate limits, and a named contact who can pause the work.

Test by hand against real attacks

The same principal who scoped the work runs it. We attempt the attacks that matter by hand: overriding the model's instructions with hidden input, tricking it into misusing its tools, pulling data a user should not see, and abusing the access controls around it. Because model output varies, every attempt is logged and successes are counted. Scanners support the work but are never the deliverable.

Report, fix, and retest with evidence

You receive findings with reproduction transcripts, a severity rating based on impact and how easily each issue is exploited, and a fix aimed at the layer that actually closes it. An executive summary is written for leadership and customer reviews. After you remediate, we retest each finding and package the evidence for customers, insurers, and auditors.

FIND YOUR FOCUS

Specific services.
Substantive answers.

01 / AI Security Testing

LLM Application Penetration Test

LLM penetration testing for prompt injection, data disclosure, unsafe outputs, and application access controls, with reproducible findings and fixes.

  • Overriding the model's instructions through the chat box, uploads, form fields, and the interface
  • Slipping instructions into documents, fetched pages, and other content the model reads later
  • Drawing out the model's hidden instructions, policy text, and tool definitions

From $6,000

Scope, pricing & FAQs
02 / AI Security Testing

Agentic AI Security Assessment

Agentic AI security assessments test tool access, memory, approval controls, and autonomous actions to identify misuse and limit potential damage.

  • Redirecting the agent's goal through documents, tickets, web pages, or messages from other agents
  • A per-tool inventory of identity, access, reversibility, and paths from reading to writing
  • Poisoned memory that carries planted instructions into later runs or other users' sessions

From $8,400

Scope, pricing & FAQs
03 / AI Security Testing

MCP Server Security Assessment

MCP server security testing for tool misuse, excessive permissions, and credential handling across the AI connectors you build, host, or approve.

  • Sign-in conformance: proving identity, accepting only tokens meant for the server, and validating them
  • Mistaken-authority flaws in servers that sit in front of other services
  • Hidden malicious tools introduced through tool descriptions, inputs, or returned results

From $3,600

Scope, pricing & FAQs
04 / AI Security Testing

RAG Pipeline & Data Boundary Testing

RAG security testing checks document access, retrieval poisoning, and permission changes, with evidence of where an AI assistant can expose data.

  • Entitlement checks per group and tenant using plain, paraphrased, and closely related queries
  • Where each user's permissions are enforced: the search service, or filters built in code
  • Shared indexes and caches, and steps that run over everything before the permission filter

From $6,000

Scope, pricing & FAQs
05 / AI Security Testing

AI Red Team Exercise

AI red teaming tests prompt injection, guardrail bypasses, and multi-turn manipulation against agreed objectives, with documented results and fixes.

  • Written objectives such as revealing another customer's record or triggering an unapproved payment
  • Rules of engagement: channels, off-limits content, spending limits, real-data handling, and stop conditions
  • Single- and multi-turn attempts to talk the model past its guardrails

From $9,000

Scope, pricing & FAQs
WHAT YOU TAKE FORWARD

Built to support the next decision.

  • Attack-surface map of the prompts, tools, data sources, and identities the model can reach
  • Findings with reproduction transcripts, attempt counts, severity, and a fix written for the implementer
  • Each finding tied to a recognized category of AI and application risk, in plain language
  • Executive summary written for leadership and customer security reviews
  • Retest report with evidence that remediated findings are closed

The selected services, deliverables, access requirements, and any follow-up validation are agreed in your engagement scope.

INFORMED BY RECOGNIZED GUIDANCE
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security