Prompt injection
Direct and indirect instructions through user input and retrieved documents.
Testing for AI applications, retrieval systems and agents, focused on data boundaries.
From A$7,500 ex GST for one AI application feature.
This is a penetration test of one AI feature. The AI Production Readiness Review is a design and controls review before launch.
Manually verified findings.
Direct and indirect instructions through user input and retrieved documents.
Cross-user retrieval and the authorisation checks around data sources.
Tool permissions, approval boundaries and unsafe handling of generated output.
Reporting and retest terms are agreed in writing. The record separates verified fixes from outstanding work.
A 19-page illustrative report built from synthetic findings, not a client report. It shows scope, evidence, severity rationale and the retest record.
No. A prompt matters when it crosses an application boundary, reveals restricted data or causes an unauthorised action. We examine the identity, retrieval and tool controls around the model.
From A$7,500 ex GST for one web application with its API and two user roles. That covers five testing days, the report and a retest of critical and high findings. More applications, endpoints or cloud accounts give an indicative range. The price is fixed once scope is agreed, in writing, before work starts.
Testing effort and elapsed delivery time are different. We agree both after reviewing the scope, access readiness and your deadline. Leave time for remediation and a focused retest.
The sample report is illustrative, built from synthetic findings. It is not a client report.
Last reviewed: