Skip to content
← All insights
Company news1 min read

We now test AI and LLM applications

A dedicated engagement for applications built on large language models — the interface, the retrieval pipeline, and the tools the model is permitted to call.

We have added AI and LLM application security assessment to the services we offer. It covers what you would expect of a testing engagement, applied to a system whose attack surface does not behave like a conventional application.

What it covers

  • Prompt injection, direct and indirect — including payloads arriving through retrieved documents, uploaded files, and third-party content the model ingests.
  • System prompt extraction, and what an attacker learns from it.
  • Excessive agency: what the model may do through its tools, and what happens when an attacker steers those calls.
  • RAG pipeline security — corpus poisoning, vector store weaknesses, and retrieval-boundary bypass between tenants.
  • The conventional application underneath, tested to the same standard as any other engagement.

Findings map to the OWASP Top 10 for LLM Applications and to MITRE ATLAS techniques, with risk framed against the NIST AI Risk Management Framework — so the output is usable by a governance team as well as an engineering one.

Full scope and pricing are on the services page.

  • Company news
  • AI security