SECURITY AUDIT · PENETRATION TESTING · AI ENGINEERING
Security audits and AI engineering, with evidence you can verify.
We test your applications, APIs, servers and AI systems to find the holes before an attacker does — then hand you a report with proof, risk level, and the fix for each issue. We also build custom AI systems for daily operations, including deployments that stay on your own servers.
Services
2 service lines
Security audit and AI engineering on your own infrastructure.
Introductory program
Free audit
Delivered to the same standard as a paid engagement. In return: recognition — permission to reference the work in our portfolio.
Response
45 minutes
Email replies during Western Indonesian business hours (WIB, UTC+7).
SERVICES
Website, API and AI security auditing
Audits follow standards used across the industry, so results can be compared between reviews and reused as internal compliance evidence. For AI work we map the requirements first, test on real data, then move to production with access control and human escalation.
Second service line
Custom AI Engineering: customer-service assistants, sales and lead handling, voice and chat agents, an internal assistant that answers from your own documents, back-office automation, and AI models that run on your own infrastructure.
See AI Engineering →
01 // AUDIT
Web & API Security Audit
We test login flows, permissions, input handling, business logic, sessions and third-party integrations — without damaging your data. Findings are mapped to the OWASP Top 10, the industry list of the ten most common web security risks.

02 // AUDIT
Source Code Review
We read the code you hand over line by line: how login works, how input is validated, where secrets are stored, and where one system trusts another too much. Every finding points to the exact file and line.

03 // AUDIT
Server & Cloud Audit
We map what is exposed to the internet — open services, TLS certificates, response headers, undocumented entry points — then review access policies, stored credentials and the misconfigurations that keep coming back.

04 // AUDIT
AI System Audit
If you use a chatbot or any AI feature, we check whether it can be talked into breaking its own rules, leaking internal data, or reaching information it should not see. This is the OWASP guidance for AI systems, applied to your actual deployment.
HOW WE WORK
Every finding is proven, not just claimed
cyberagent.id is a security audit and AI engineering firm. We test systems up to their limits and build AI that is actually used in production, not demos. Reports are written so your engineers can act on them and your management can understand the risk.
Two rules apply to every engagement: each finding comes with the steps to reproduce it, and we are honest about limits — including what we did not test. Anything we cannot reproduce does not go into the report.
DEPLOYMENT
Your data stays on your infrastructure
For AI work, systems can run on your own side: in-country cloud, your office servers, or with no internet connection at all. Customer data, transcripts and documents are never used to train third-party models.
01 // OPTION
In-country cloud
Runs on infrastructure inside your jurisdiction, with no copy of the data sent to other regions.
02 // OPTION
Your own servers
Installed in your data centre and reached by your internal systems over your internal network.
03 // OPTION
Fully offline
No outbound internet connection at all, for environments where that is a legal requirement.
04 // OPTION
Fixed scope, your code
Work runs as a fixed-scope project or a retainer, and the code and configuration we build are yours.
STANDARDS
Mapped to standards the industry already recognises
Every audit is mapped to international standards, so results can be compared between reviews and reused as internal compliance evidence.
01 // STANDARD
OWASP Top 10
The industry list of the ten most common web application risks — weak login, broken access control, injection, and similar — used as the baseline for every web and API audit.
02 // STANDARD
AI system testing guidance
OWASP reference for AI systems: prompt injection, data leaking through AI answers, and agents abusing the tools they are given.
03 // STANDARD
MITRE ATT&CK & NIST CSF
A map of how attackers actually operate, placed inside an organisation-level risk framework your management already understands.
04 // STANDARD
PTES, ISO 27001 & CVSS
Testing phases, the link back to ISO information-security controls, and CVSS — the standard score that says how severe a finding is.
COMMON QUESTIONS
Questions buyers ask before the first call
Short answers to the things people search for before they hire anyone for security testing or AI work.
What is a security audit, and why does my business need one?
A security audit is a structured attempt to break into your own application, API or server — with your permission — so you learn about the holes before an attacker does. If you store customer data, take payments or run logins, the audit tells you exactly what is exposed today and what to fix first.
How much does a penetration test cost?
Price follows scope: how many applications are involved, whether source-code review is included, and how deep the testing goes. You get a fixed per-project quote after a short scoping call — no open-ended retainer, and the number is agreed before any work starts.
What does a web application and API security audit include?
Web application testing against the OWASP Top 10, API testing against the OWASP API Security Top 10, source-code review, external infrastructure and cloud configuration review, and AI system review. Every finding includes reproduction steps, a CVSS 3.1 score and a concrete remediation.
Do you need production access or real customer data?
No. Testing runs against a staging copy wherever one exists. If production is the only option we restrict ourselves to non-destructive checks, and we never exfiltrate real customer data.
How long does an assessment take?
From about two days for a single small application up to four weeks for an engagement covering several systems. The report is handed over after a debrief walkthrough with your engineers, so the fixes are clear to the people who implement them.
Can chatbots and AI systems be security tested too?
Yes. If you run a chatbot, an AI agent or an LLM feature, we test whether it can be pushed outside its instructions (prompt injection), leak internal data through its answers, or reach tools and data it should not. We also build and operate those systems, including private deployments that run on your own servers.
GET STARTED
Start with one email
Send a short brief: what you are protecting, which systems are involved, and what you expect to get out of it. You receive scoping questions, then a proposal with scope, timeline and price. No long procurement process — one email, one 30-minute call, one proposal.
Request a Scoping CallDocumentation & Links
Replies within 45 minutes during Indonesian business hours (WIB). The dashboard and public API are still in development — every service is currently handled by email.