Opulence.
Cybersecurity

AI/LLM Security Assessment

Prompt injection, data leakage and model abuse testing for AI features, assistants and agents.

AI features add attack surface that traditional testing doesn't cover. A chatbot can be talked into revealing data it should hold back. An agent with tool access can be steered into taking actions nobody intended. Retrieval pipelines can be poisoned. We test for all of it, using the methods attackers already use.

The assessment produces a threat model for your AI system, findings with proof, and guardrail recommendations that your developers can implement.

How we're different
  • Testers work with our AI engineering practice, so findings come with fixes that fit how the system is built.
  • We test the whole chain, including retrieval, tools and integrations, not only the model prompt.
  • Findings are rated by business impact, so a jailbreak that reveals nothing sensitive isn't treated as critical.
Who this is for
  • A bank or insurer that has put an assistant in front of customers and must answer the regulator's questions about it.
  • An airline or retailer whose support agent can issue refunds, rebook or change orders.
  • A group whose staff use a vendor copilot connected to internal documents.
Signals you need this now
  • The assistant has tool access and there is no approval step for consequential actions.
  • Nobody has tried to make it reveal its instructions or another customer's data.
  • Retrieval indexes documents without enforcing the permissions that apply to them.
  • The model vendor has been assessed but your integration has not.
Scope of work

What is included.

  1. 01

    Threat modelling

    Data flows, trust boundaries, tool access and abuse cases for the AI system mapped.

  2. 02

    Prompt injection testing

    Direct and indirect injection through user input, documents, web content and tool outputs.

  3. 03

    Data leakage testing

    System prompt extraction, cross-tenant leakage and sensitive data exposure through retrieval.

  4. 04

    Agent and tool abuse

    Attempts to escalate actions, bypass approvals and misuse connected systems.

  5. 05

    Guardrail review

    Existing filters, evaluations and monitoring assessed and improved.

Method

Four steps, no surprises.

  1. 01

    Model the threat

    Understand the system, its data, its tools and who could abuse it.

  2. 02

    Attack

    Manual and automated adversarial testing across the identified paths.

  3. 03

    Report

    Findings with reproduction, impact and guardrail recommendations.

  4. 04

    Retest

    Verification after fixes, with an evaluation set you can keep running.

How the engagement runs

From first meeting to steady state.

  1. 01Week 1

    Threat model

    Data flows, trust boundaries, tool access and abuse cases mapped with your engineers.

  2. 02Weeks 2 to 3

    Attack

    Manual and automated adversarial testing across the identified paths in a controlled environment.

  3. 03Weeks 4 to 5

    Report and retest

    Findings with reproduction, guardrail recommendations, a reusable evaluation set and verification after fixes.

What we measure
  • Findings by severity from prompt injection, data leakage and tool abuse, tracked to closure.
  • Pass rate on the adversarial evaluation set in your release pipeline.
  • Share of consequential actions gated by approval or policy.
  • Time from a new attack technique being published to it being covered in the evaluation set.
Who is on the engagement
  • AI security lead
  • Penetration tester
  • AI engineer
  • Engagement manager
Deliverables
  • AI threat model.
  • Findings report with reproduction steps.
  • Guardrail and architecture recommendations.
  • Reusable adversarial evaluation set.
  • Retest confirmation.
Engagement terms

AI security assessments are fixed scope, agreed after a scoping call about the system and its integrations. A single assistant or agent typically takes one to two weeks of testing plus reporting. Organisations shipping AI features regularly can add this to an annual testing retainer.

FAQ

AI/LLM Security Assessment, in plain terms.

The OWASP Top 10 for LLM applications and the MITRE ATLAS knowledge base, adapted to your specific architecture.

We test your configuration and integration of them and the data you expose. Testing the vendor's model itself depends on their terms.

In a staging environment with sandboxed tool access wherever possible, with agreed limits on any live actions.

Yes. Our AI engineers can implement the recommended controls and the evaluation set becomes part of your release pipeline.

Next step

Ready to talk about ai/llm security assessment?