Red teaming & pentest

We attack the systems you ship, the way an adversary would.

AI red teaming and adversarial testing across your models, agents, and pipelines, with penetration testing of the surrounding applications, APIs, and infrastructure included.

// what it is

AI red teaming, with the infrastructure in scope.

We attack models, agents, pipelines, applications, APIs, and the infrastructure they run on, the way an adversary would. The target is the authority-boundary and integration failures that standard evals miss: instructions that arrive inside content you already trust, an agent persuaded into unsafe tool use, one component acting with the privileges of another. The AI is the sharp end. The rest of the software stack around it is in scope in the same engagement.

A jailbreak is not the finding. The finding is what the model was allowed to do next. We test the authority a compromised path actually holds, not whether a filter can be talked past.

// specimen

A finding, redacted.

Real shape, sealed client, no fabrication. An indirect injection reaches an agent holding finance authority; the high-impact step is stopped at the human gate.

Specimen · redacted
class LLM01, AG1    High    client sealed
POST /tools/invoice.export
Authorization: Bearer [redacted]
{"scope":"all","dest":"https://[redacted]"}

# source: vendor statement (indirect)
# authz: finance.write
# gate: human    result: held
// the engagement

Six phases, agreed in writing before anything is touched.

Most first engagements are a fixed-scope adversarial test, typically two to six weeks. You name the systems, the boundaries, and the questions worth answering. The full six-phase model, with the rules of engagement and the stop conditions, lives on the method page.

Scope

We map the real attack surface with you: which systems, which authority boundaries, and what a breach would cost. Rules of engagement, test windows, and data handling are agreed and signed.

Attack

Senior operators attack the agreed targets the way an adversary would, across AI systems, applications, and the rest of the software stack. Every high-impact step passes a human gate.

Findings

Reproducible attack paths, each with proof, demonstrated impact, and the steps to replay it. Severity is rated against a published rubric, not assigned by feel.

Harden

Findings become concrete design and control changes your engineers can ship, prioritized by real risk rather than by count.

Retest

We re-run the affected attacks against the fixes and record what moved. A finding is closed when it is proven closed.

Retainer

Optional. Systems change and so does the attack surface, so coverage re-runs on a cadence as you ship.

// coverage

Coverage is a number you can audit.

Every test declares the attack classes it exercises, and every finding records the class it demonstrates. Coverage maps to named external frameworks, so it is countable rather than asserted. The deeper framework mapping, from the EU AI Act and NIST AI RMF to IMDA framework and AI Verify, and MAS guidance, lives on the assurance page; how coverage is counted is on the method page, and the class catalog itself is the threat register.

// deliverables

What you receive.

Proof

Reproducible findings

Each finding is an attack path with proof, demonstrated impact, and the exact steps to replay it. Nothing is claimed that we cannot reproduce, and there are no scanner dumps.

Evidence

A bundle you can replay

An evidence bundle your team runs independently, pinned to the run that produced each finding. The operator run is logged append-only. The workbench stays with us.

Severity

Rated by real blast radius

Impact and exploitability scored like everyone else, then the authority and blast radius the compromised path actually holds. Authority is the third axis, so an injection reaching a tool that moves money is not scored like one reaching a benign tool.

Hardening

Fixes your engineers can ship

Concrete design and control changes, made by the people who broke the system and verified by re-test. The hardening of what we tested, not a general modernization program.

Scope an engagement.

Tell us what you run and what worries you. We will tell you how we would break it, and how we would help you hold.

Scope an engagement