01 — AssessmentModel & LLM security assessment
Direct and indirect prompt injection, multi-turn and encoded jailbreaks, system-prompt extraction, guardrail bypass, PII and tenant regurgitation, model extraction, and denial-of-wallet. Typical duration: 2–3 weeks for a single production assistant.
02 — AssessmentAgentic systems & tool-use
Function-calling, MCP servers, plugins, multi-agent orchestration, goal hijacking, and excessive agency. Aligned to the OWASP Top 10 for Agentic Applications.
03 — AssessmentRAG & data-pipeline security
Indirect injection via documents, email and tickets; corpus and embedding poisoning; connector over-permission; cross-tenant retrieval.
04 — AssessmentHybrid application penetration testing
The surrounding web and API estate: authentication, object-level authorisation, business logic, and output handling where model text is executed or stored.
05 — AssessmentCloud & inference infrastructure
GPU clusters, model registries, vector databases, inference gateways, secrets, isolation patterns, and trust boundaries.
06 — AssessmentModel lifecycle & supply chain
Fine-tune and training-data poisoning, CI/CD gate tampering, model provenance, dependency risk, secrets in notebooks and weights.
07 — OperationsAI-focused red team & readiness
Multistep adversary emulation against the model pipeline. Purple-team variants work live with your detection staff. Tabletop drills for AI incidents.
08 — ReviewGenAI architecture & governance review
Model and tool deployment, data flows, human-in-the-loop, vendor risk, and control coverage against NIST AI RMF, ISO/IEC 42001, and EU AI Act evidence.
09 — RetainerContinuous intrusion programme
A named operator retains scope over your models and agents, retesting after releases, keeping an attack library current.
10 — ReviewSecure code & prompt review
System prompts, tool schemas, retrieval filters, output parsers, and the glue that turns a completion into an action.