Prompt injection
Direct and indirect instructions through user input and retrieved documents.
Testing for AI applications, retrieval systems and agents, focused on data boundaries.
Human-led testing.
Manually verified findings.
Direct and indirect instructions through user input and retrieved documents.
Cross-user retrieval and the authorisation checks around data sources.
Tool permissions, approval boundaries and unsafe handling of generated output.
Reporting and retest terms are agreed in writing. The record separates verified fixes from outstanding work.
No. A prompt matters when it crosses an application boundary, reveals restricted data or causes an unauthorised action. We examine the identity, retrieval and tool controls around the model.
From A$7,500 ex GST for one web application with its API and two user roles. That covers five testing days, the report and a retest of critical and high findings. More applications, endpoints or cloud accounts give an indicative range. The price is fixed once scope is agreed, in writing, before work starts.
Testing effort and elapsed delivery time are different. We agree both after reviewing the scope, access readiness and your deadline. Leave time for remediation and a focused retest.
An AI feature still sits on ordinary infrastructure. The interface is web application penetration testing, the service behind it is API penetration testing, and the account holding the model and its data is cloud penetration testing. We will not claim a model has been made safe, and what a penetration test report should contain sets the standard we report against.
Share the assets and your reason for testing. We will confirm the approach, fee and schedule.
Last reviewed: