Service
Scope

What we test, review, and validate.

Outcome of this engagement

AI risk often sits in the prompts, retrieval layer, connected tools, permissions, workflows, and data the model can reach. AI & LLM Penetration Testing helps your team validate whether AI-enabled features behave safely under adversarial use and whether the surrounding application, data, and integration layers create exploitable risk.

Prompt & instruction security
  • Direct and indirect prompt injection
  • System prompt extraction, override, and instruction bypass
  • Output validation and guardrail bypass
Data & retrieval risk
  • Sensitive data leakage from training, prompts, or retrieval
  • Cross-tenant, cross-user, or unauthorized retrieval issues
  • RAG source manipulation, poisoning, and source-of-truth abuse
Authorization & access
  • Tool / function-calling abuse and over-privilege
  • SSRF, exfiltration, and integration pivoting
  • Cost, rate-limit, and cost and resource-consumption attacks
What You Receive

AI security findings your team can act on.

  • Executive summary for non-technical stakeholders
  • Prioritized findings with business and security impact
  • OWASP Top 10 for LLM Applications alignment where applicable
  • Reproducible adversarial test cases
  • Evidence-backed vulnerability detail
  • Prompt, retrieval, agent, and integration-layer findings
  • Practical remediation guidance for engineering and security teams
  • Risk context to guide prioritization
  • Findings review meeting
  • Retesting of remediated findings within the defined engagement window
  • Letter of Attestation, where applicable
Beyond THE REPORT

AI security should be validated before trust is assumed.

Methodology Preview

A transparent process from scope to retesting.

01
Define
02
Uncover
03
Report
04
Remediate
05
Retest
See Full Methodology
Why Canary Trap

The proof behind this engagement.

Senior-led testing

Testing is led by experienced offensive security professionals, not handed off to junior scanner operators.

Application-aware AI testing

We test the AI feature in the context of the application, including roles, workflows, integrations, data access, retrieval behaviour, and connected tools.

Human-led validation

Tools support the process. They do not replace judgment. Our testers validate exploitability, investigate context, and look for realistic attack paths.

Practical reporting

Findings include the technical detail needed for remediation and the business context needed for leadership, compliance, and customer conversations.

Project management

Every engagement includes clear communication, defined expectations, and project management throughout the testing lifecycle.

Retesting and validation

Retesting helps confirm that remediated findings have actually been addressed, not just marked complete.

Related Services

AI risk rarely exists in isolation

Application Penetration Testing
Secure Code Review
API Penetration Testing
FAQ

AI & LLM penetration testing questions, answered plainly.

Next Step

Ready to scope your AI & LLM Penetration Testing?

Book a Scoping CallGet a Complimentary External Exposure Assessment