AI & LLM
Penetration Testing

Security testing for AI-powered features and LLM applications — prompt injection, jailbreaks, training-data and context leakage, and insecure agent tooling — aligned to the OWASP Top 10 for LLM Applications.

Overview

New capabilities, new attack surface.

Shipping AI features introduces risks traditional testing was never designed to catch — prompt injection, jailbreaks, sensitive-data leakage through context, and over-privileged agents that can take real actions.

We test your LLM applications, RAG pipelines, and AI agents against the OWASP Top 10 for LLM Applications — attempting prompt injection and exfiltration, probing guardrails, and assessing the tools your agents can reach. We test the surrounding app and APIs too.


Coverage

What we test.

The model, the pipeline, the agent, and the application around it.

Methodologies: OWASP Top 10 for LLM MITRE ATLAS CVSS v3.1 Agent tooling review

FAQ

AI penetration testing FAQ

The questions we're asked most about scope, cost, and timing.

How much does AI or LLM penetration testing cost?
AI/LLM penetration testing typically starts around €4,000 and depends on the AI features, integrations, and agent tooling in scope, plus any testing of the surrounding application. Use our estimator for a tailored figure.
What does AI penetration testing cover?
The OWASP Top 10 for LLM Applications — prompt injection, jailbreaks, sensitive-data leakage, insecure output handling, excessive agency, and RAG poisoning — plus the app and APIs around the model.
Do you test AI agents and RAG pipelines?
Yes — we assess what tools and data your agents can reach, whether they can be coerced into unsafe actions, and how your retrieval pipeline handles untrusted content.
Is this different from a normal application penetration test?
It adds AI-specific attack classes on top of standard application testing. Because LLM features sit inside web and API stacks, we usually test both together.
What do we receive?
A CVSS-scored report with reproduction steps and practical mitigations, an executive summary, and a free retest within 60 days.
What do you need to scope an AI test?
Access to the AI feature or app, a description of the model(s), tools/agents it can call, data sources, and user roles.
Do you test the model or the application?
Both — model-level attacks like prompt injection and jailbreaks, plus the surrounding application, APIs, and agent tooling.
Can you test third-party LLMs we use via API?
Yes — we test how your application uses the model, its guardrails, and what an attacker can make it do, regardless of provider.
Do you align to a recognised standard?
Yes — testing maps to the OWASP Top 10 for LLM Applications and MITRE ATLAS.
How does AI testing fit with regular app testing?
It adds AI-specific attack classes on top of standard web/API testing; we usually run them together.

Related services

Explore more.

Ready to secure your AI features?

A 30-minute scoping call costs nothing. An AI data leak costs considerably more.

Book a meeting Send an email