AI security audit

AI security, code, and cost audits for LLM systems

If you already run chatbots, AI agents, or LLM features in production — or you're about to launch one — the AI security audit tells you how they fail. We review the code, attack the system the way an adversary would, build the evaluation harness you need to catch regressions, and review what you're spending on model APIs and why.

Why AI systems need their own audit

A conventional penetration test checks your network, authentication, and web application. LLM systems add new ways to fail: instructions hidden in a document or email that the model obeys, an agent tricked into calling a tool it shouldn't, sensitive data surfacing in a response, answers that drift after a quiet model update, and API bills that grow faster than usage. These risks sit in prompts, retrieval pipelines, and tool permissions — places a traditional security review rarely looks.

Our audit is scoped to those risks, using the OWASP Top 10 for LLM Applications as a baseline checklist and adapting it to how your system is actually built. We test against a staging environment wherever possible, and agree rules of engagement in writing — scope, timing, and what's off-limits — before any testing starts.

What we test

The audit combines hands-on adversarial testing with a review of the code and architecture behind it, so every finding comes with a root cause rather than just a symptom.

LLM red teaming

Structured adversarial testing of your chatbot or agent: jailbreaks, attempts to extract the system prompt or other users' data, harmful or off-brand output, and social-engineering the model into skipping a business rule.

Prompt-injection testing

Direct injection through the chat box and indirect injection through anything the model reads — uploaded files, web pages, emails, tickets, and retrieved documents. For agents, we test whether injected instructions can trigger tool calls, data exfiltration, or actions outside the intended scope.

Code and architecture review

How prompts are built, how user input and retrieved content are separated, where secrets live, how tool permissions are enforced, how model output is validated before other systems act on it, and what gets logged.

Evaluation harnesses

Many teams have no automated way to know whether their AI system got better or worse after a change. As part of the audit we build or extend an evaluation harness: a versioned set of test cases drawn from real usage and from the attacks we found, automated scoring for accuracy, groundedness, refusal behavior, and injection resistance, and a script your CI pipeline can run on every prompt, model, or retrieval change. It stays with you after the audit, so every fix we recommend comes with a test that proves it holds.

API cost review

Model API spend can become one of the fastest-growing lines in an AI budget, and much of it is often avoidable. We trace where tokens go and look for the usual causes: oversized prompts and context windows, missing prompt caching, a large model doing work a smaller one handles equally well, retries and agent loops without limits, and repeated retrieval of the same content. Every recommendation is checked against the evaluation harness so cost savings don't quietly cost accuracy.

  • Token usage breakdown by feature and prompt
  • Model right-sizing and routing recommendations
  • Prompt caching and context-trimming opportunities
  • Loop, retry, and rate-limit controls
  • Spend alerts and per-feature budgets

Deliverables and next steps

You receive a written report with every finding rated by severity and likelihood, reproduction steps, and a specific fix — plus an executive summary for non-technical stakeholders, the evaluation harness, and the cost review with an estimated saving for each change. We walk your engineers through the findings and retest the fixes once they're in. If you'd rather we implement them, we can, and managed AI services can keep running the evaluations and cost monitoring on an ongoing basis. Building a new agent? See how we design guardrails into AI agent development from the start. Every engagement starts with a free discovery call, where we learn your goals, systems, and constraints before proposing a scope.

Frequently asked questions

Structured adversarial testing of an AI system — trying to make a chatbot or agent leak data, ignore its rules, produce harmful output, or take actions it shouldn't — so weaknesses are found and fixed before real attackers or users find them.