AI security testing
AI and LLM penetration testing, priced per system
Your chatbot, copilot or LLM-powered app is an attack surface, and a new kind of one. We test it the way an adversary would: prompt injection, jailbreaks, data extraction and tool abuse, mapped to the OWASP LLM Top 10, at a fixed published price per system with a free retest.
What this is
Security testing of your AI systems, not AI doing your pentest
Two very different services share this search term. Plenty of vendors now sell tools where AI performs penetration testing of ordinary networks. This page is the other thing: human specialists attacking the AI systems you have built or bought, because those systems fail in ways traditional testing never looks for.
We treat AI and LLM penetration testing as one service, since a production AI system is almost always an LLM plus the prompts, retrieval and integrations around it. The whole stack is the target, not the model in isolation.
One boundary worth stating: conventional web application and infrastructure penetration testing is delivered by CyPro directly. This site tests the AI layer.
The attack surface
What gets tested, mapped to the OWASP LLM Top 10
Six classes of weakness account for most real-world AI compromises. Each finding in your report cites the OWASP category it belongs to.
Prompt injection and jailbreaks
OWASP LLM01: Prompt Injection
Direct and indirect injection through every channel your system reads: user input, retrieved documents, web content, email. Can attacker text override your instructions, and what happens when it does?
Data leakage
OWASP LLM02: Sensitive Information Disclosure
System prompts, other users' conversations, training data and connected records coaxed out of the model. Includes LLM07, System Prompt Leakage, because your prompt usually contains more than you think.
Insecure output handling
OWASP LLM05: Improper Output Handling
Where model output flows into browsers, databases or downstream code without treatment. A chatbot that can be made to emit live script or SQL is a classic web vulnerability wearing a new interface.
RAG and retrieval poisoning
OWASP LLM08: Vector and Embedding Weaknesses
The knowledge base behind your assistant is an attack surface. We test whether planted or manipulated content can steer answers, exfiltrate data or reach documents the user should never see.
Excessive agency
OWASP LLM06: Excessive Agency
Tools, plugins and API calls the model can trigger. We probe whether the system can be talked into actions its designers never intended, and whether anything meaningful stands in the way.
Unbounded consumption
OWASP LLM10: Unbounded Consumption
Resource exhaustion and runaway spend: inputs crafted to inflate token usage, loop the system or degrade service for everyone else, tested within limits you agree.
How the test runs
A CREST-aligned methodology, four stages
Structured like the penetration testing your security team already trusts, adapted for systems whose behaviour is probabilistic rather than fixed.
Scoping, by system complexity
A scoping call maps the architecture: model, prompts, retrieval, integrations and tools. That determines the price band and the test plan, both confirmed in writing before anything starts.
Testing, in a controlled harness
Attacks run against an agreed environment under agreed constraints, so findings are real but production users, live data and your bill are protected throughout.
Reporting, built for fixing
Every finding carries severity, evidence, exact reproduction steps and a specific fix, mapped to the OWASP LLM Top 10. The report reads for engineers and summarises for the board and for procurement.
Retesting, free
Once the fixes land, we re-run every finding and issue an updated report showing what closed. The retest is included in the fixed price, not an upsell.
You receive the full technical report, a summary written for non-specialists, the reproduction evidence for every finding and the post-fix retest report: the pack a security questionnaire or audit actually asks for.
Published pricing
A fixed price per AI system, banded by complexity
Almost nobody in this market publishes a number. We band by what actually drives testing effort, the architecture, and confirm your band on the scoping call before you commit.
Single chatbot or LLM app
£5,600
One model, one prompt layer, no retrieval or tool calls. The typical customer-facing assistant.
App with RAG or integrations
£7,900
Retrieval over your documents, API connections or both. The knowledge base and the joins join the scope.
Agentic or multi-model estate
From £13,500
Agents with tools and permissions, or several models working together. Scoped per estate on the call.
Every band includes the free retest. Full details, and how testing combines with the governance services, on the pricing page.
The three triggers
When an AI penetration test earns its keep
Procurement is asking
A customer's security questionnaire wants evidence your AI feature has been tested. A dated report against a named methodology answers the question the way reviewers expect.
You are about to launch
The AI feature works and the demo lands. Pre-launch testing is the cheapest it will ever be: no incident response, no disclosure, no retrofit under pressure.
Something already happened
A user found a jailbreak, an odd output reached a customer, or the assistant said something it knew but should not have shared. Testing establishes how deep the problem goes before you rebuild.
Quick answers
AI penetration testing questions, answered
How do you test an LLM application?
By attacking it the way a motivated adversary would, inside a controlled harness: injection through every input the system reads, extraction attempts against its prompts and data, abuse of its outputs and any tools it can call. Findings map to the OWASP LLM Top 10 and arrive with reproduction steps, so your team can verify and fix each one.
What is prompt injection?
Prompt injection is an attack where instructions hidden in content an AI system reads, a web page, an email, a document, override the instructions its builders gave it. The model cannot reliably tell data from commands, so attacker text can redirect its behaviour, extract information or trigger unintended actions.
Do you test AI agents too?
Yes. Agents sit in the top complexity band here, and because they hold permissions and take actions, they also warrant their own assessment of what they are allowed to do in the first place. The agentic AI security page covers that in full.
How is this different from AI red teaming?
A penetration test hunts exploitable technical weaknesses in a defined system and ends in a findings-and-fixes report. Red teaming is scenario-driven: it explores harms, misuse and model behaviour under adversarial pressure, including failures no vulnerability scanner would flag. Many organisations need the pentest first and red teaming as their AI estate matures.
Scope it in one call
Get your AI system tested
A free scoping call maps your architecture, confirms the price band and books the test. You know the number before you commit, and the retest is already included.