AI and LLM security testing
We test LLM applications and agents as an adversary who treats every input channel as injectable: user prompts, retrieved documents, tool output and upstream data. The question is what the system can be made to do, not just what it can be made to say.
The full attack surface — not just what's visible from the outside.
Prompt injection
Retrieved content becomes instructions
Direct and, more importantly, indirect injection through retrieved content, documents and tool output that the model treats as instructions.
Agency & tool abuse
The model is not an authorization boundary
What an agent with function-calling, API access or code execution can be steered into doing, and whether authorization is enforced outside the model.
RAG & data poisoning
A poisoned knowledge base
Manipulating the knowledge base and upstream sources to bias, mislead or exfiltrate through the model.
Data leakage
Theft of prompts and training data
System-prompt and instruction disclosure, training-data and cross-tenant leakage, and sensitive output through legitimate queries.
Guardrail bypass
Breaking soft guardrails
Defeating content and safety filters via encoding, role-play and multi-step framing.
Surrounding application
Model secure, application not
The backend, APIs, auth and integrations around the model, tested conventionally, where the real breach usually lands.
Established industry frameworks — not proprietary checklists.
The risk model for LLM applications, applied as adversarial testing rather than a questionnaire.
Mapping the tools, data and privileges the model can reach, then attacking those paths.
Because an AI feature is still an application, and the surrounding code is still the softest target.
A structured process from scope to retest — no surprises at delivery.

The questions we hear most often before a contract is signed.
Both, but the application and its integrations are where breaches actually happen. We attack the model (injection, leakage, jailbreaks) and the system around it (auth, tools, data access) as one surface.
The attack surface is the integration, not the weights. We test self-hosted models, hosted APIs and agent frameworks; the tools and data a model can reach define the risk.
It adds the AI-specific layer a standard pentest skips — indirect injection, tool abuse, RAG poisoning — on top of the conventional application testing we always run.
Contact us
For any matter, you can reach us using the contact details below or via the contact form.
If you would like to speak with us in person, we invite you to book a meeting using the Microsoft Bookings platform.
Book a meeting in Microsoft Bookings