All services
AI Security & Red-Team Audit
Phase 03 — Enterprise AI Solutions

Find the holes in your AI before someone else does

We test your AI systems the way an attacker would: prompt injection, data leakage, agent abuse, MCP server hardening — and deliver a prioritised remediation report your engineering team can actually ship.

Features

What we test

Prompt injection & jailbreak testing

We try to make your AI assistant say what it shouldn't, leak what it shouldn't, and do what it shouldn't. We document every successful attack.

Agent and tool-call abuse

If your AI can call tools — send emails, write to databases, execute code — we test what happens when an attacker controls the prompt. Most teams underestimate this.

MCP server hardening

MCP servers expose tools to AI agents. We audit yours for authentication gaps, over-permissive scopes, and tool descriptions that leak sensitive context.

Process

From kickoff to remediation report

1

Scoping & threat model (week 1)

We map your AI surface area: assistants, agents, MCP servers, tool integrations, data flows. We agree on the rules of engagement.

2

Active testing (weeks 2–3)

Prompt injection, jailbreak, data exfiltration, tool abuse, MCP hardening tests. Every finding gets a reproducer.

3

Remediation report (week 4)

Findings prioritised by impact and effort, with concrete code-level fix recommendations. Walk-through with your engineering team.

4

Optional re-test

Six weeks later we re-run the failed tests against your fixes. You get a clean bill of health to share with your security team or board.

Prompt injection is real — and your security audits don't cover it

Classic pen-tests probe web apps, APIs and networks. AI systems break differently: a carefully crafted input in a customer ticket gets your support bot to quote internal documents. A link in an email makes your agent ship data to an external server. We bring the threat model, the test methodology and the reproducers — and hand you a report your engineering team can translate into pull requests.

4 weeks
from kickoff to report
100 %
findings come with a reproducer
Re-test
after 6 weeks optional
Use Cases

Who needs an AI security audit

Three situations where we typically get called in.

💬
B2B SaaS · 70 employees

Customer-support bot with access to customer tickets. CTO wants to know whether prompt injection is a real problem before SOC-2 audit.

12 findings (3 critical, 5 high). Three days of engineering work to fix, clean re-test certificate for SOC-2.
🛡️
Insurer · 280 employees

Internal agent with email-send permission. Board asks what happens if an employee uploads a malicious PDF.

Two critical tool-call abuse findings, one data-exfiltration path discovered. Guardrails redesigned, re-test passed.
🔒
FinTech · 25 employees

MCP server with access to the production database. Lead investor wants security evidence before the funding round.

MCP hardening with scope reduction, per-tool authentication. Investor-ready documentation delivered in 4 weeks.
Technology

Four layers of our AI security audit

We test what classical pen-tests miss — and hand off every finding with a concrete fix.

threatModel

Threat modeling — the map

We map your AI attack surface: assistants, agents, MCP servers, tool integrations, data flows. Before we test, we know where it can hurt.

redTeam

Red-team probes — the real attack

Prompt injection, jailbreak, indirect injection via documents and websites, tool-call abuse. We use techniques that actually work in the wild.

guardrails

Guardrail tests — the protection layer

If you already use guardrails, we check whether they hold. If not, we design the missing ones — system prompts, Bedrock Guardrails, output filters.

report

Remediation report — the roadmap

Findings prioritised by impact and effort, each with a concrete code-level fix. Walk-through with your engineering team. Optional re-test after 6 weeks.

Pricing
On request Individual quote

scoped to complexity

  • Prompt injection & data leakage tests
  • MCP server and agent hardening
  • Prioritised remediation report
Same phase

Related services

Enterprise
Pricing
On request
scoped to complexity

AI Foundation on AWS

A governed AI environment on your own AWS account: Bedrock with access to Claude and OpenAI (ChatGPT) models, Guardrails, audit logs and cost controls — set up in 4 weeks.

  • AWS Bedrock + Guardrails in Frankfurt
  • Access to Claude and OpenAI models
  • Cost controls and full audit trail
Learn more
Pricing
On request
scoped to complexity

AI Assistant for Your Business

A digital team member that knows all your company documents and gives your staff the right answers instantly — around the clock.

  • Knows your entire company knowledge
  • Built into your daily tools
  • Gets smarter over time
Learn more
Enterprise
Pricing
On request
scoped to complexity

Agent Factory

A management platform for AI agents: deploy new agents independently, assign tasks, monitor results — no external vendor required.

  • Deploy new agents at the push of a button
  • Assign tasks & monitor results
  • Own AWS account, enterprise-grade security
Learn more
Governance
Pricing
On request
scoped to complexity

EU AI Act Compliance Package

Risk classification, AI register, DPIAs and governance committee setup — your documentation and processes ready for the regulator.

  • Risk classification per EU AI Act
  • AI register and DPIA templates
  • Vendor risk assessment for AI tools
Learn more
Regulated industries
Pricing
On request
scoped to complexity

Sovereign LLM Deployment

AI inside your own AWS environment — your keys, your data, no traffic to the public internet. For finance, healthcare and the public sector.

  • Data never leaves your AWS network
  • Encrypted with your own keys
  • Zero data retention with the model provider
Learn more
Pricing
On request
scoped to complexity

AI Cost & FinOps

Stop paying for what you don't need. Audit your AI spend, implement caching, set budgets, and assign costs back to teams.

  • Audit existing Bedrock & API spend
  • Prompt caching and model right-sizing
  • Per-team chargeback dashboards
Learn more
No sales pitch. No pressure. Just a conversation.

Let's talk.

30 minutes, no obligation, no cost. We'll honestly tell you if and how we can help.