CLOUDPANICCLOUDPANIC

AI and LLM security testing

The risk isn't the model talking. It's the model acting, on attacker-controlled input, with your tools and your data behind it.

We test LLM applications and agents as an adversary who treats every input channel as injectable: user prompts, retrieved documents, tool output and upstream data. The question is what the system can be made to do, not just what it can be made to say.

Test scope

The full attack surface — not just what's visible from the outside.

Prompt injection

Retrieved content becomes instructions

Direct and, more importantly, indirect injection through retrieved content, documents and tool output that the model treats as instructions.

Agency & tool abuse

The model is not an authorization boundary

What an agent with function-calling, API access or code execution can be steered into doing, and whether authorization is enforced outside the model.

RAG & data poisoning

A poisoned knowledge base

Manipulating the knowledge base and upstream sources to bias, mislead or exfiltrate through the model.

Data leakage

Theft of prompts and training data

System-prompt and instruction disclosure, training-data and cross-tenant leakage, and sensitive output through legitimate queries.

Guardrail bypass

Breaking soft guardrails

Defeating content and safety filters via encoding, role-play and multi-step framing.

Surrounding application

Model secure, application not

The backend, APIs, auth and integrations around the model, tested conventionally, where the real breach usually lands.

Built on recognised standards

Established industry frameworks — not proprietary checklists.

methodology.sh
OWASP LLM Top 10

The risk model for LLM applications, applied as adversarial testing rather than a questionnaire.

Agent threat modeling

Mapping the tools, data and privileges the model can reach, then attacking those paths.

Conventional app testing

Because an AI feature is still an application, and the surrounding code is still the softest target.

From scope to retest

A structured process from scope to retest — no surprises at delivery.

Diagram of the penetration testing cycle: scope and reconnaissance, testing, reporting
Common questions

The questions we hear most often before a contract is signed.

Both, but the application and its integrations are where breaches actually happen. We attack the model (injection, leakage, jailbreaks) and the system around it (auth, tools, data access) as one surface.

The attack surface is the integration, not the weights. We test self-hosted models, hosted APIs and agent frameworks; the tools and data a model can reach define the risk.

It adds the AI-specific layer a standard pentest skips — indirect injection, tool abuse, RAG poisoning — on top of the conventional application testing we always run.

Contact us

For any matter, you can reach us using the contact details below or via the contact form.

Calendar icon for scheduling meetings

If you would like to speak with us in person, we invite you to book a meeting using the Microsoft Bookings platform.

Book a meeting in Microsoft Bookings
E-mail:
Send us an email and our team will get back to you within 1–2 business days.
Phone:
We also offer phone contact from Monday to Friday, 9:00 AM – 5:00 PM.
0 / 5000
The personal data provided will be used solely for the purpose of handling your inquiry or contact request. The data controller is CLOUDPANIC Sp. z o.o. You can find detailed information in our privacy policy.