Overview
Generative AI features change your threat model. An attacker no longer needs a code bug if they can persuade your model to ignore its instructions, reveal another user's documents, or call a tool on their behalf.
Our AI security assessments focus on your application — prompts, retrieval, tools, permissions and output handling — rather than the underlying foundation model. We test direct and indirect prompt injection, data leakage across users and tenants, excessive agency in agents, and unsafe handling of model output in downstream systems.
Because AI features usually sit on top of ordinary APIs, we typically combine AI-specific testing with a web and API assessment of the same application.
What's included
Our approach
- Architecture reviewModel provider, orchestration, retrieval, tools and data flows.
- Threat modellingMapping abuse cases to the OWASP LLM Top 10 and MITRE ATLAS.
- Adversarial testingManual and assisted prompt attacks across direct and indirect channels.
- Integration testingWeb/API testing of the surrounding application and tool endpoints.
- Report & guardrail designPrioritised fixes and secure-design recommendations.
What you receive
- Findings mapped to OWASP LLM Top 10 (2025)
- Prompt injection test corpus results
- Data isolation verification
- Agent permission review
- Secure AI design recommendations
Standards & frameworks
- OWASP Top 10 for LLM Applications 2025
- MITRE ATLAS
- NIST AI RMF
- ISO/IEC 42001
- EU AI Act
Frequently asked questions
Can prompt injection be fully prevented?
Not reliably with current models. The practical goal is to limit impact: treat model input as untrusted, restrict tool permissions and enforce authorization outside the model.
Do you test the AI model provider?
No. We test your application's use of the model. Model providers operate their own security programs under their terms.
Is this a separate engagement from a web app test?
It can be, but we usually combine them because most AI features are delivered through ordinary web and API endpoints.