Can this AI feature be turned against the business?
AI and LLM application test
An AI and LLM application test is a manual security assessment of the language model features in your product: chat interfaces, copilots, agents, and retrieval pipelines. It shows whether an attacker can manipulate the model to leak data, abuse connected tools, or act outside its intended purpose.
What you get
- Proven prompt injection paths, direct and through your data
- Data and system prompt leakage you can reproduce
- Tool and agent misuse with real business impact
Overview
Large language model features add a new attack surface: prompts, tools, retrieval pipelines, and the data they can reach. We test how your AI features can be manipulated, what they can leak, and what actions an attacker can make them take, aligned to the OWASP Top 10 for LLM Applications.
Scope
What is typically in scope. The final list is agreed with you before testing starts.
- Chat and copilot features exposed to users or the public
- System prompts, guardrails, and content filters
- Retrieval augmented generation pipelines and the documents they index
- Tools, functions, and agents the model can invoke
- Data flows between the model, your backend, and third-party providers
- Cost and availability controls
- Supporting web application and API surface where relevant
Methodology
Phases run in this order. Each one produces evidence that feeds the next.
Architecture review
We map the model, prompts, tools, data sources, and trust boundaries so testing targets the paths with real consequences.
Direct prompt injection and jailbreaks
Guardrails and system prompts are tested for bypass, extraction, and instruction override.
Indirect injection
Malicious content is planted in documents, web pages, or messages the model reads, to see whether it changes model behaviour.
Tool and agent abuse
We test whether the model can be driven to call tools with attacker-chosen parameters, escalate privileges, or act on other users' data.
Output handling and leakage
Model output is traced into your application for injection, and retrieval scopes are tested for cross-user and cross-tenant leakage.
Reporting
Findings are mapped to the OWASP Top 10 for LLM Applications with reproducible prompts and fixes at the application layer.
Deliverables
- Threat model of the AI feature and its integrations
- Findings with reproducible prompts, inputs, and observed outputs
- OWASP Top 10 for LLM Applications coverage matrix
- Guardrail and system prompt assessment
- Remediation guidance for prompts, tools, and application controls
- Executive summary and attestation letter
- One retest of remediated findings
Sample report excerpt
One finding, in the structure every finding follows. The content is illustrative.
Indirect prompt injection through indexed support tickets
- Severity
- High
- Status
- Open, retest pending
- Affected assets
- Listed in appendix A
Impact
A customer could submit a support ticket containing hidden instructions that the internal support copilot later followed, causing it to disclose another customer's account details to the agent viewing the ticket.
Evidence
Test ticket containing embedded instructions was indexed; a subsequent copilot query returned fields from a second test tenant's record.
Remediation
Treat retrieved content as untrusted data rather than instructions, enforce tenant scoping at the retrieval layer rather than in the prompt, and strip or neutralize instruction-like content before indexing.
Verification
Retested after remediation. Result and date are recorded here and reflected in the attestation letter.
Timeline
Typical duration
Typically 1 to 2 weeks per AI feature set
What affects it
Simple chat features take about a week. Agents with many tools, or products with several AI features, take longer. Access to a non-production environment with representative data is strongly recommended.
Compliance drivers
Need this for an audit or renewal? This test provides accepted evidence for HIPAA, SOC 2, ISO 27001.
See the full requirement mappingFrequently asked questions
How long does an AI application test take?
Typically one to two weeks per feature set. Agentic features with many tools take longer than a single chat interface.
Do you test the model itself or our application?
Both, but the focus is your application: how prompts, retrieval, tools, and data flows can be abused. Model-level weaknesses matter only where your application lets them cause harm.
Which standard do you follow?
Coverage is mapped to the OWASP Top 10 for LLM Applications, and the supporting web and API surface follows the OWASP Web Security Testing Guide.
Is a retest included?
Yes. One retest of remediated findings is included.
How is this different from a web application test?
A web application test covers authentication, authorization, and input handling for the application. An AI test adds the model, its prompts, its data sources, and the tools it can call, which have their own failure modes and attack techniques.
Related
Often paired with
Web application test
Can this application be turned against its users?
Deep, manual testing of one application and its APIs.
Learn moreCloud penetration test
Is our cloud configured the way we think it is?
AWS, Azure, and GCP environments assessed for the mistakes attackers look for.
Learn moreContinuous Threat Exposure Management
What is exposed right now, and does it matter?
A year-round testing program instead of an annual snapshot.
Learn moreReady to scope a ai and llm application test?
Tell us about your environment and timelines. You will talk to the people who run the engagement and hear back within one business day.