AI & LLM
Penetration Testing
Test the security of your AI features and agents. We check prompt injection, data exposure, and what connected tools are allowed to do.
Overview
New capabilities, new attack surface.
We test your LLM applications, RAG pipelines, and AI agents against the OWASP Top 10 for LLM Applications — attempting prompt injection and exfiltration, probing guardrails, and assessing the tools your agents can reach. We test the surrounding app and APIs too.
Coverage
What we test.
The model, the pipeline, the agent, and the application around it.
- Direct & indirect prompt injection
- Jailbreaks & guardrail bypass
- Sensitive data & context leakage
- Insecure output handling
- Excessive agency & tool abuse
- RAG & data-source poisoning
- Authentication & rate limiting
- Surrounding web & API security
FAQ
AI penetration testing FAQ
Scope, cost, and what happens next.
How much does AI or LLM penetration testing cost?
AI/LLM penetration testing typically starts around €4,000 and depends on the AI features, integrations, and agent tooling in scope, plus any testing of the surrounding application. Use our estimator for a tailored figure.
What does AI penetration testing cover?
The OWASP Top 10 for LLM Applications — prompt injection, jailbreaks, sensitive-data leakage, insecure output handling, excessive agency, and RAG poisoning — plus the app and APIs around the model.
Do you test AI agents and RAG pipelines?
Yes — we assess what tools and data your agents can reach, whether they can be coerced into unsafe actions, and how your retrieval pipeline handles untrusted content.
Is this different from a normal application penetration test?
It adds AI-specific attack classes on top of standard application testing. Because LLM features sit inside web and API stacks, we usually test both together.
What do we receive?
A CVSS-scored report with reproduction steps and practical mitigations, an executive summary, and a free retest within 60 days.
What do you need to scope an AI test?
Access to the AI feature or app, a description of the model(s), tools/agents it can call, data sources, and user roles.
More questions about this service
Do you test the model or the application?
Both — model-level attacks like prompt injection and jailbreaks, plus the surrounding application, APIs, and agent tooling.
Can you test third-party LLMs we use via API?
Yes — we test how your application uses the model, its guardrails, and what an attacker can make it do, regardless of provider.
Do you align to a recognised standard?
Yes — testing maps to the OWASP Top 10 for LLM Applications and MITRE ATLAS.
How does AI testing fit with regular app testing?
It adds AI-specific attack classes on top of standard web/API testing; we usually run them together.
Related services
Explore more.
Ready to secure your AI features?
A 30-minute scoping call costs nothing. An AI data leak costs considerably more.
Book a short call Send an email