cyberagent.id

AI audit

AI System Security Audit

If you run a chatbot, an internal assistant or any AI feature, one question needs an answer before your customers find it: can the model be pushed outside its instructions?

Introductory program

Free security audit

One full engagement at no fee, delivered to the same standard and depth as a paid one. In return we ask for one thing: recognition — permission to reference this engagement in the cyberagent.id portfolio. You may remain anonymous.

Request a scoping call Read the documentation

What we test

Reference guidance

We use the OWASP guidance for language-model applications, combined with conventional application testing: access control on the data the system reads, interface security, and how uploads and integrations feed the model.

No AI system can be made attack-proof. What is achievable: explicit limits, bounded damage, and monitoring that makes abuse visible sooner.

Frequently asked questions

Does our chatbot need an audit?

If it answers customers, reads internal documents, or can trigger actions such as changing data, testing is worth it. A system answering only from a public FAQ carries much lower risk.

What is prompt injection in plain terms?

An attempt to make the AI ignore its instructions — for example asking it to print its internal rules, or hiding a command inside a document it reads.

How long does it take?

Usually two to five working days for one system, depending on channels, callable tools and the breadth of source data.

Can it be combined with an application audit?

Yes, and it is usually more efficient, since the AI interface normally sits inside the same application.

Related services

Start with one email to founder@cyberagent.id listing the assets you want tested. You get scoping questions and a written quote back.