SVC—09 · ASSESSMENT

AI and LLM system penetration testing

System-level testing of how AI components interact with identities, tools, data, and business authority.

Start scoping
OWASP LLM guidanceOWASP API Security Top 10 2023NIST SP 800-115Threat-model-specific tests

TEST BOUNDARY

What sits inside the boundary

Models, prompts, system instructions, tools, agents, and retrieval sources
Authorization, prompt injection, data exposure, and output handling
MLOps pipelines, model supply chain, and monitoring

ACCESS MODES

Knowledge level is scoped

Application black box
Architecture-assisted
Pipeline white box

DELIVERY—LEDGER

Deliverables you can inspect.

OUTPUT

Authority and data-boundary map

Reproducible abuse cases with model variability noted

Guardrail, architecture, and monitoring improvements

EFFORT—DRIVER

Models, tools, agents, and data sources

Authorization and business consequence

Evaluation stability and pipeline access

EXPLICIT—LIMIT

Probabilistic behavior and model updates limit repeatability

Model-provider systems require separate authorization

POINT—IN—TIME

Precision includes what we do not claim.

A penetration test provides evidence about named assets, versions, access, and time. It does not guarantee the absence of vulnerabilities, replace internal vulnerability management, or constitute compliance certification.

Method and limitations

SCOPE—NEXT

Define the boundary before the fee.

Build a scope draft