Threat model
How your AI system could be attacked, by whom, and what is at stake.
Service 06
Adversarial testing of your chatbots, copilots and AI agents for prompt injection, data leakage and excessive permissions, before attackers or customers find the gaps.
Why it matters
Once an AI system can read your data and call your tools, a single malicious instruction hidden in an email, document or web page can make it act against you. Traditional penetration tests rarely cover this.
What we test
How your AI system could be attacked, by whom, and what is at stake.
Direct and indirect attacks through chat, documents, email and web content.
Exposure of personal information, secrets and system instructions.
Tool permissions, approvals and what an agent can really do on its own.
Poisoned content, cross-tenant access and permission bypass in search.
Prioritised fixes, help implementing them, and a retest to confirm.
Engagement
Two to three weeks. Threat model, hands-on testing, an executive summary for the board and a technical report your engineers can act on.
from A$12,000
An attack where instructions hidden in user input, documents, web pages or emails steer an AI system into doing something it should not, such as revealing data or misusing a connected tool. Read our guide for leaders.
We agree scope, rules of engagement and test environments in writing first. Most testing runs against staging, and anything touching production is coordinated with your team.
Yes. Every finding comes with a practical fix, and we can implement the remediation and retest to confirm it worked.
Before launch, after significant changes to models, prompts, tools or data sources, and at least annually for systems in production.
Related