Service

AI, LLM and Agentic Security Assessment

When the attack surface reads English and calls tools.

Assessment of the AI features you have shipped — the prompts, the retrieval layer, the tool boundary, the agent loop, the supplier chain and the human in the loop. Aligned to the OWASP Top 10 for LLM Applications and for Agentic Applications.

What it is

Your feature reads tickets. It calls tools. It writes to a database. The question is what a careful attacker can make it do with nothing but input.

Five layers get tested, because a defect in any one of them is reachable from the others.

  1. Model and prompt

    Direct and indirect prompt injection, document and image injection, jailbreaks, system-prompt extraction, improper output handling, sensitive information disclosure, guardrail bypass.

  2. Agentic

    Tool misuse, excessive agency, agent identity and delegated authorization, inter-agent message spoofing, memory and context poisoning, human-in-the-loop bypass.

  3. Retrieval and data

    RAG poisoning, vector-store access control, cross-tenant leakage.

  4. Supply chain

    Model provenance, third-party tool and MCP server trust, plugin and connector surface.

  5. Infrastructure

    Inference endpoint exposure, key handling, missing rate and spend limits, SSRF via model-controlled requests.

What you get

  • Findings with the reproducible prompt or chain
  • Mapping to the OWASP Top 10 for LLM Applications and for Agentic Applications
  • Mitigations across prompt design, tool boundaries, retrieval and infrastructure
  • Retest by agreement — these defects regress easily

Ready to scope this engagement?

One email is enough to start. Tell us roughly what you want tested and we'll come back with a scoping call slot inside one business day.