AI application security
A classic penetration test does not find what breaks AI products. Prompt injection has topped the OWASP LLM list for three years running, and excessive agency climbed to third place: an agent with access to email and payments is not a chat, it is executable code with a user's rights.
What's included
- Testing for direct and indirect prompt injection, including via documents and the web
- Audit of agent permissions and tool access against least privilege
- Hunting for leaks of hidden context, system instructions and other users' data
- Regular adversarial testing and a prioritised report
Technologies
Platforms
How we work
- 01
Brief and estimate
We look at the task, your current system and constraints, then name the timeline and budget and suggest how to work together.
- 02
Specification
We capture requirements and acceptance criteria in a specification — it is what we build against and how the result is accepted.
- 03
Iterative development
You see the result after every iteration; we test and fix before anything goes into a release.
- 04
Launch and support
We ship with no downtime, monitor the product after launch and stay on for support if you need it.
Cost and timeline
Hourly Rates: from 1 800 ₽ to 3 500 ₽ / hour — depending on specialist qualification.
We give an exact timeline and budget after a brief: we break down the task, fix the scope and suggest a format — a fixed plan or hourly work.
See plansFAQ
How is this different from a regular penetration test?
A classic pentest covers infrastructure and the web application, but not what the model does with untrusted input. We test direct and indirect prompt injection through documents, web pages and emails the agent reads, leaks of system instructions and context, and what the agent can actually do with its tools. For a full picture it is worth combining this with a regular security audit.
What do you need from us, and do you test in production?
We need a test environment as close to production as possible, test accounts and a description of the tools and data the agent can access. We test in production only when agreed and within agreed limits. Real user data is not needed for the assessment.
What do we get at the end of the assessment?
A report with the vulnerabilities found, risk-based priorities, reproduction steps and fix recommendations. We can apply the fixes ourselves or together with your team and then retest. Models and prompts keep changing, so adversarial testing works best on a regular basis, hourly or on a fixed monthly plan.
AI application security
We test LLM products for prompt injection, context leaks and excessive agent permissions.