API security testing
Testing of REST, GraphQL, gRPC and WebSocket interfaces for broken authorisation, data exposure and abuse of business flows.
Application security
Adversarial testing of LLM applications, agents and MCP integrations: prompt injection, data leakage, tool abuse and escape from the intended task.
AI, Web3 and cryptography
An application built on a language model takes instructions from everything it reads: the user, a retrieved document, the content of a web page, the output of a tool. It cannot reliably tell an instruction from data. Once the model can call tools, send messages or write to a database, a sentence hidden in a document becomes an action in your systems.
We test the whole application and not only the model: the prompts, the retrieval pipeline, the tools and their permissions, the agents and the protocols that connect them. The question is what an attacker can make the system do, read or disclose, and whether the controls around the model hold when the model itself does not.
01Scope
02Approach
We map what the model reads, what it can call and with whose permissions. Most critical findings are visible at this stage as a trust boundary that is missing.
Inputs are crafted by hand and generated at scale against every channel into the model. A successful attack is reduced to the smallest input that reproduces it.
We use injected instructions to drive tools and agents: to read what should be unreadable, to act in the name of another user, to move from one system to the next.
Filters, guardrails and approval steps are tested on their own. The report states which control stopped which attack and which stopped none.
03
04
05Standards
The most critical risks of applications built on language models.
OWASP Gen AI Security Project
The most critical risks of autonomous agents and their tools.
OWASP Gen AI Security Project
Catalogue of adversary techniques against AI systems.
The MITRE Corporation
Vocabulary for reporting AI risks to management.
NIST
Severity score and vector of every finding.
FIRST
06Questions
The application. The safety of the base model is the responsibility of its provider. What you control, and what attackers exploit, is how the model is connected to your data and your tools.
The point is to know what follows from it. If injection leads to a wrong answer, that is a quality issue. If it leads to an email sent in the name of the user, that is a vulnerability in the permissions around the model, and it can be fixed.
No. Client data, prompts and findings are not submitted to public AI services and are not used for training. Tooling that relies on language models runs in environments we control.
Adversarial testing is one of the measures the Act refers to for certain systems and models. The report documents method, scope and results in a form suitable as evidence. Whether and how the Act applies to your system is a legal question that we do not answer.
08Request
Reference
Keep the reference: we name it in all further communication with you.
We never ask for payment, passwords or remote access in the first reply.