AI audit
AI System Security Audit
If you run a chatbot, an internal assistant or any AI feature, one question needs an answer before your customers find it: can the model be pushed outside its instructions?
Introductory program
Free security audit
One full engagement at no fee, delivered to the same standard and depth as a paid one. In return we ask for one thing: recognition — permission to reference this engagement in the cyberagent.id portfolio. You may remain anonymous.
What we test
- Prompt injection: whether a user can make the model ignore instructions, adopt another role, or leak its system prompt.
- Data leakage: whether answers can surface internal documents or other customers' data with the right phrasing.
- Tool access: whether limits can be bypassed to read data or change systems when the model can call functions.
- Conversation resilience: whether a staged dialogue can lead the system to a conclusion or action it should refuse.
- Escalation path: whether risky conditions actually reach a human, and whether that is recorded.
Reference guidance
We use the OWASP guidance for language-model applications, combined with conventional application testing: access control on the data the system reads, interface security, and how uploads and integrations feed the model.
No AI system can be made attack-proof. What is achievable: explicit limits, bounded damage, and monitoring that makes abuse visible sooner.
Frequently asked questions
Does our chatbot need an audit?
If it answers customers, reads internal documents, or can trigger actions such as changing data, testing is worth it. A system answering only from a public FAQ carries much lower risk.
What is prompt injection in plain terms?
An attempt to make the AI ignore its instructions — for example asking it to print its internal rules, or hiding a command inside a document it reads.
How long does it take?
Usually two to five working days for one system, depending on channels, callable tools and the breadth of source data.
Can it be combined with an application audit?
Yes, and it is usually more efficient, since the AI interface normally sits inside the same application.
Related services
Start with one email to founder@cyberagent.id listing the assets you want tested. You get scoping questions and a written quote back.