Service · AI security and assurance
You are shipping AI features faster than anyone can say whether they are safe.
Is this you?
Your team has put a language model in front of customers or connected an agent to internal systems. Security reviews built for web apps do not cover prompt injection, data leakage through retrieval, poisoned training data or an agent doing more than it should. You need someone who has studied how these systems fail to test yours properly, and to tell you plainly what to fix first.
Scope and methods
What we do.
- Threat modelling of AI and LLM applications, agents and retrieval pipelines
- Hands-on testing: prompt injection, insecure output handling, data and model leakage, excessive agency
- Red-team exercises against agreed objectives
- Model and data supply-chain review: where weights, datasets and third-party models come from
- AI governance set-up: policy, risk register, roles and evidence for audit
Standards we use
Measured against recognised frameworks.
OWASP Top 10 for LLM Applications 2025
Test coverage and findings are mapped to it.
UK AI Cyber Security Code of Practice (Jan 2025)
The basis for ETSI TS 104 223; we show where you stand against each principle.
ISO/IEC 42001
For organisations setting up an AI management system.
Deliverables
What you receive.
- D1Threat model with data flows and trust boundaries
- D2Findings report ranked by likelihood and impact, with reproduction steps
- D3Remediation guidance and a retest of fixed issues
- D4Executive summary written for non-technical readers
FAQ
Questions
Do you need access to our model weights?
Usually not. Most testing works against the application as users and attackers see it. Supply-chain review looks at where models come from, not inside them.
Can you test a third-party model we only call through an API?
Yes. We test your application and how it uses the model, which is where most exploitable risk sits.
Will this help with customer security questionnaires?
Yes. Reports map findings to recognised frameworks, so you can answer questions with evidence.
Next step
Talk to us about AI security and assurance.
Tell us about the system and your deadline. We reply within two working days.