Skip to content
Clear Infosec

AI Security

AI security & LLM penetration testing

AI applications introduce a new attack surface: prompt injection, data leakage, unsafe tool use, and model abuse. Clear Infosec tests AI and LLM systems against recognized references including the OWASP LLM Top 10, MITRE ATLAS, the NIST AI RMF, and ISO 42001.

AI risk areas we assess

Prompt injection

Untrusted input that overrides an application's intended instructions to a model. Tracked as OWASP LLM01.

Indirect prompt injection

Malicious instructions hidden in content the model later retrieves (web pages, documents, emails), rather than typed by the user.

RAG security

Risks in retrieval-augmented generation: poisoned or over-permissive knowledge sources, and data leakage across tenants or users.

AI agent security

Autonomous agents that plan and act. Risks include unsafe tool use, goal manipulation, and excessive agency (OWASP LLM06/LLM08).

Tool and function abuse

Coercing a model to call connected tools or functions in unintended ways, turning a model flaw into a real-world action.

MCP (Model Context Protocol) security

Securing the connectors and servers that expose tools and data to models: authentication, scoping, and trust of MCP servers.

Sensitive information disclosure

Models revealing secrets, training data, or other users' data through their outputs (OWASP LLM02).

AI supply chain security

Risks from third-party models, datasets, and plugins, including tampering and provenance (OWASP LLM03/LLM05).

AI red teaming

Adversarial testing of an AI system end to end, combining the techniques above to find exploitable weaknesses.

AI security guides

AI governance & testing frameworks

Securing an AI or LLM application?

Clear Infosec tests AI systems against real adversarial techniques and maps findings to recognized frameworks.

Contact us