Technical Security
AI security
Models, prompts, and the data around them — reviewed for failure modes that don't show up in a traditional security scan.
Who this is for
- Companies that have integrated LLMs or other AI models into their product
- Teams handling sensitive data in AI training, fine-tuning, or retrieval pipelines
- Organizations fielding new security questionnaire sections specifically about AI usage
What this addresses
- An AI feature was shipped without a security review of how it handles prompts, data, and outputs
- It's unclear what happens if a user tries to manipulate the model into leaking data or bypassing intended behavior
- Enterprise security questionnaires now include AI-specific questions with no clear internal answer
Our approach
Review covers the failure modes specific to AI-integrated systems: prompt injection, data leakage through model outputs, unsafe tool/function-calling permissions, and how training or retrieval data is handled and secured.
We assess the system around the model as much as the model itself — how inputs reach it, what access it has, and what happens with what it returns.
This is a genuinely developing area of security practice; findings are grounded in current, well-understood failure modes rather than speculative or overstated risk.
Every engagement follows the same six-step methodology — see our approach.
What to expect
Scope depends heavily on how AI is integrated — a simple API call to a hosted model looks very different from a custom fine-tuned model with tool access to internal systems.
Frequently asked
Do you review both first-party and third-party AI models?
Yes — the review focuses on how the model is integrated and what access and data it touches, whether it's a hosted third-party API or a model trained or fine-tuned in-house.
Is this a mature, standardized field yet?
Not to the extent traditional application or network security is — practices are still evolving. We ground assessments in current, well-documented failure modes rather than overstating certainty in a fast-moving area.
Shipped an AI feature without a security review?
Tell us how it's built and what it touches, and we'll scope a review around the real risk.