AI Security
AI security & LLM penetration testing
AI applications introduce a new attack surface: prompt injection, data leakage, unsafe tool use, and model abuse. Clear Infosec tests AI and LLM systems against recognized references including the OWASP LLM Top 10, MITRE ATLAS, the NIST AI RMF, and ISO 42001.
AI risk areas we assess
Prompt injection
Untrusted input that overrides an application's intended instructions to a model. Tracked as OWASP LLM01.
Indirect prompt injection
Malicious instructions hidden in content the model later retrieves (web pages, documents, emails), rather than typed by the user.
RAG security
Risks in retrieval-augmented generation: poisoned or over-permissive knowledge sources, and data leakage across tenants or users.
AI agent security
Autonomous agents that plan and act. Risks include unsafe tool use, goal manipulation, and excessive agency (OWASP LLM06/LLM08).
Tool and function abuse
Coercing a model to call connected tools or functions in unintended ways, turning a model flaw into a real-world action.
MCP (Model Context Protocol) security
Securing the connectors and servers that expose tools and data to models: authentication, scoping, and trust of MCP servers.
Sensitive information disclosure
Models revealing secrets, training data, or other users' data through their outputs (OWASP LLM02).
AI supply chain security
Risks from third-party models, datasets, and plugins, including tampering and provenance (OWASP LLM03/LLM05).
AI red teaming
Adversarial testing of an AI system end to end, combining the techniques above to find exploitable weaknesses.
AI security guides
AI Security Testing Methodology: OWASP LLM Top 10 and MITRE ATLAS
AI security testing evaluates LLM-backed applications against the OWASP Top 10 for LLM Applications and adversarial techniques catalogued in MITRE ATLAS, treating the model, its data, its integrations, and its output handling as distinct attack surfaces.
Prompt Injection Testing Guide: Direct, Indirect, and Mitigations
Prompt injection testing verifies whether untrusted input can override an LLM application's instructions, covering direct injection in user input and indirect injection through content the model retrieves, mapped to OWASP LLM01 and mitigated by treating all model input and output as untrusted.
AI governance & testing frameworks
ISO 42001
ISO/IEC 42001 is the first international standard for an Artificial Intelligence Management System (AIMS), providing a governance framework for developing and using AI responsibly.
NIST AI RMF
The NIST AI Risk Management Framework (AI RMF) 1.0 is a voluntary framework for managing risks in the design, development, and use of AI systems, organized around four functions: Govern, Map, Measure, and Manage.
MITRE ATLAS
MITRE ATLAS is a knowledge base of adversary tactics and techniques against AI and machine-learning systems, modeled after MITRE ATT&CK.
OWASP
OWASP is a nonprofit community that produces free application security resources, including the widely used Top 10 lists for web, API, and LLM security risks.
Securing an AI or LLM application?
Clear Infosec tests AI systems against real adversarial techniques and maps findings to recognized frameworks.
Contact us