Security
AI systems introduce failure modes most security programmes have never assessed: prompt injection, training-data leakage, tool misuse and over-permissioned agents. We test for both the classic and the new.
What this includes
Application security review
Code review, dependency auditing and penetration testing.
Prompt injection testing
Adversarial testing of AI features against instruction-hijacking attacks.
Data leakage assessment
Whether your system can be induced to reveal data it should not.
Agent permission audit
Review of what tools and actions an agent can reach, and what that allows.
Threat modelling
Structured analysis of attack surface before a feature ships.
Incident response planning
Playbooks for when something does go wrong.
What you end up with
- Vulnerabilities found before attackers find them
- AI-specific risks assessed explicitly
- Least-privilege agent design
- A tested incident response plan
Tools we reach for
Frequently asked
What is prompt injection?
Malicious instructions hidden in content the model reads — a document, a web page, an email — that attempt to override its actual instructions. It is the most common AI-specific vulnerability we find.
Do you provide a report we can show clients?
Yes. Findings come with severity ratings, reproduction steps and remediation guidance.
Other work in this practice
PRIDE — AI Search Visibility
Buyers now ask AI assistants for recommendations. PRIDE measures whether your brand is in those answers — and works to get it there.
Read moreStrategy & Consulting
Decide what is worth building — and what should be bought, delayed or abandoned.
Read moreProduct Development
Take a product from idea to live users, with AI capability built in rather than bolted on.
Read moreLet's talk about what you're building
Tell us the problem. We'll tell you honestly whether AI is the right tool, and what it would take.