Manual, not automated.
A senior AI pentester walks every chain by hand against your models, prompts, RAG and tools. No scanner noise.
Your copilots, RAG pipelines and agents already see customer data, source code and internal policies. We prove how an attacker (or an over-trusting employee) turns that access into a breach, before it ends up in a regulator’s inbox.
How an AI pentest worksProtected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
We’ll be in touch within one business day with next steps.
No se ha podido enviar. Inténtalo otra vez o escríbenos.















The AI running inside your systems is only as good as the data it is fed, and only as secure as the access around it. We test from an attacker’s point of view: what data they can manipulate to fool the model, what access it has to the AI server, what secrets sit in its container, and how it talks to the systems around it. The whole chain.
An AI pentest is normally booked because a release-velocity question, an enterprise customer ask, a regulator deadline, a near-miss in production or an M&A due diligence has forced it.
When the ask is for assurance about AI exposure, you need an external, expert-led AI pentest and a deliverable that maps to business impact in language a non-technical stakeholder can read.
With the OWASP Top 10 for LLM Apps, ISO/IEC 42001 or EU AI Act conformity work on the line, the report has to survive scrutiny: traceable scope, a methodology mapped to recognised standards and signed retest evidence.
The question is not ‘do we have findings’ but ‘are there other paths’. We focus the engagement on the suspected exposure, confirm it is closed, and surface every adjacent path an attacker could pivot to.
The cheapest moment to validate is at the change, while your team still holds the context. We test the new surface, prove which paths exist, and retest the difference after the fix to confirm the boundary held.
A copilot, an agent with write actions and a public chatbot each fail differently. We scope to yours and prove the path from what any user can already send to the data that should have been out of reach.
Seven phases, in order. Each one ends with something proven, not something assumed.
Strengthen your AI posture with manual, expert-led assessments, not box-ticking jailbreak demos.
A senior AI pentester walks every chain by hand against your models, prompts, RAG and tools. No scanner noise.
We prove or disprove the path from a public chat to a tool we should not be able to fire, to data we should not see.
Every finding mapped to the OWASP Top 10 for LLM Apps (2025): the artefact your auditor and procurement teams read.
After a fix or a model or prompt change we retest the diff against the same version, RAG index and tool config.
We at Etnia highly value our collaboration with Asperis Security.
Reports your ML engineers actually read and your enterprise customers’ procurement teams actually accept. Real names, real roles, real clients.
We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
An experienced consultant will reply.
A web or API pentest treats the AI as one endpoint behind your stack. An AI pentest treats the model plus prompts plus RAG plus tools plus permissions as the product: instructions, context, retrieval, agent orchestration, model providers and the supply chain are all in scope. It is not a subset, it is a different surface. The same product can ship a clean web and API pentest and still have an indirect prompt injection in an uploaded PDF that fires a refund tool, or a RAG index that returns another tenant’s documents to a single natural-language question. Most regulated companies that ship an LLM-backed product run both: a web or API pentest tied to the front-end and gateway release train, and an AI pentest tied to model versions, prompts, tools and RAG sources.
An AI pentest covers the model plus its prompts, its context, its RAG sources, its agents and its tools, not just the endpoint your web team ships. We audit direct prompt injection, indirect prompt injection through documents your agents read, system prompt and policy extraction, RAG index integrity and cross-tenant retrieval, tool-calling permissions and excessive agency, vector store and embedding weaknesses, connector and MCP server supply-chain risks, and cost or token consumption abuse. Every finding is chained to business impact and mapped to the OWASP Top 10 for LLM Apps (2025).
An AI pentest is priced by scope, complexity and test type. We deliver a fixed-price proposal within 48 hours of our first call, with no hidden fees and no commitment to renew. A focused audit of a single chatbot with a documented RAG index sits at the bottom of the range. Multi-agent platforms, multi-tenant RAG rollouts or engagements requiring specialised harness setup for a proprietary model scale from there. The free retest is always included, against the same model version and prompt configuration.
Not without your consent. Every AI pentest ships with documented Rules of Engagement, safe-attack criteria and a critical-finding protocol: which surfaces are in scope (staging or a controlled production tenant), which tools may be fired live, and what triggers an immediate stop. On managed model providers we default to a sandboxed API key with a rate ceiling and a token budget you agree in advance, so cost-abuse testing is measured, not open-ended. Any exploitation on production requires explicit written approval and your team on standby.
Black box mirrors what a customer or a curious researcher would have: the public chat, an uploaded document and a polite question. Grey box adds your system prompts, your tool list, your RAG source inventory, a test tenant and one technical contact for questions, so we spend more of the engagement chaining and less on discovery. White box adds architecture diagrams, model configuration, prompt libraries and connector or MCP server design documents. We usually recommend grey box for the first engagement and repeat cycles as your AI product matures, and black box for a customer-audit signal or a public-facing chatbot re-baseline.
Experienced senior offensive security specialists with hands-on AI pentesting experience. Our team holds OSCP, OSCE³, OSWE, OSEP, CRTO and CRTP credentials, and our AI practice adds LLM-specific expertise (OWASP Top 10 for LLM Apps 2025, MITRE ATLAS, OWASP AI Testing Guide) plus practical familiarity with GPT, Claude, Llama and Mistral models and the common orchestration frameworks (LangChain, LlamaIndex, MCP servers). We are NASA Bug Bounty verified contributors, and our team has published research against widely deployed AI toolchains. Every engagement is scoped, executed and retested by the same specialist you spoke to on the first call. You keep talking to that same person throughout.
We will review your AI stack (channels, models, prompts, RAG, agents, tools, permissions) and help you define the right AI pentest before the project begins.
Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Got it.
The AI pentester who’d run your project will email you within one business day.
No se ha podido enviar. Inténtalo otra vez o escríbenos.
Or email [email protected] directly.
OUR CLIENTS HAVE ALREADY DONE IT
We at Etnia highly value our collaboration with Asperis Security.
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives.
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive.
With Asperis you don’t hire a service. You hire a partner.
Pick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.