AI/ML Security
Adversarial testing for LLM applications and AI products.
For teams shipping customer-facing AI, preparing for enterprise security reviews, or putting agents into production. Methodology built on promptfoo, Garak, and manual operator testing. Findings mapped to OWASP LLM Top 10.
AI‑T0
AI Exposure Recon
2–3 business days
Public-facing AI surface check. Exposed model endpoints (Ollama, vLLM, LangServe), unprotected vector databases, leaked LLM provider keys, Gradio and Streamlit deployments without auth. Snapshot report with each finding mapped to remediation.
AI‑T1
LLM Red-Team Assessment
2 weeks
Adversarial testing against a target LLM application. Prompt injection, jailbreak resistance, system prompt extraction, output handling abuse, and RAG poisoning where applicable. Combines promptfoo, Garak, and manual operator testing. Full report with reproduction steps and severity ranking.
AI‑T2
AI Security Audit
3–4 weeks
Architecture-level review of an AI product or feature. Data flow, prompt construction, tool and function-call boundaries, agent abuse paths, RAG retrieval handling, output sanitization, and IAM around model serving. Includes AI-T1 testing of the live endpoint.
AI‑T3
GCP + AI Workload Security Review
2–3 weeks
Combined cloud and AI focus. Vertex AI deployments, model-serving IAM, training-data exposure, pipeline security, service account scope, and audit-log gaps. Built for teams running AI workloads on GCP.
AI‑TR
AI/ML Security Retainer
Monthly engagement, quarterly milestones
Continuous LLM red-team coverage for AI systems that ship changes regularly. Monthly: targeted testing of new model integrations, RAG modifications, prompt revisions, and agent capability additions as they ship. Quarterly: full architecture audit of the system in its current state. The retainer covers ongoing oversight of an AI product you've already had assessed. Net-new full-scope assessments of unscoped systems, formal compliance audits, or pre-launch certifications are separate engagements at standard rates. Retainer clients receive priority scheduling and a multi-engagement discount.
Pricing: Fixed-fee AI security engagements, $16k–$50k depending on scope. Retainer engagements starting at $8,500/month. Reach out to discuss.
Contact
Test your AI before someone else does.
Tell me what you've shipped, what you're about to ship, or what you're worried about. 15 minutes is enough to figure out if there's an engagement here.
Get in touch