AI security & adversarial testing. With evidence.

LLMs open new attack surfaces: prompt injection, data exfiltration, jailbreaking. Traditional security tools don't cover AI-specific threats. We test your AI systems systematically against real-world attack vectors.

Security Products

Assurance Basic
Automated Security Scan
Automated assessment of the most common AI attack vectors.
  • Prompt injection: direct and indirect
  • Data leakage: system prompt extraction, training data leaks
  • Jailbreak resistance: 50+ known bypass techniques
from CHF 5,000 1 week
Next: AI Penetration Testing
Assurance Komplett
Full Red Team Exercise
Coming Q4 2026
Comprehensive red team exercise for business-critical AI systems.
  • Everything from the Assurance Plus Penetration Test
  • CALDERA adversary emulation for AI infrastructure
  • Autonomous attack agents: automated exploit chains
  • Purple team assessment with evidence-based remediation prescriptions
Pricing on request 3–4 weeks

Why AI security?

LLMs have fundamentally new attack surfaces: prompt injection enables unauthorised access to system prompts and data. Jailbreaking bypasses safety guardrails. Data exfiltration extracts sensitive information through seemingly harmless queries. Traditional security tools -- firewalls, WAFs, SAST -- don't cover these AI-specific threats.

Our evaluations follow MITRE ATLAS and the OWASP Top 10 for LLM Applications. Systematic, reproducible, evidence-based.

What you get

  • Vulnerability report with criticality ratings (CVSS-aligned)
  • Pass/fail per attack vector with reproduction steps
  • MITRE ATT&CK for AI (ATLAS) mapping
  • Detection coverage analysis: what your existing tools detect and what they miss
  • Prioritised remediation roadmap
  • Documented methodology for independent verification of results
Is your AI also compliant, performant, and reliable? Security is one of four dimensions of our AI evaluation.

Schedule a scoping call

Start with an Automated Security Scan or go directly to an AI Penetration Test. The first step is always a scoping call. No preparation needed.