Skip to content
SenthexBook a scope call (opens in a new tab)

AI Security Sprint

We attack your AI system before attackers do.

A fixed-scope, fixed-price adversarial assessment of one AI application. 5 business days. €2,500.

20 minutes. You get a fixed proposal the same day.

The problem

Your LLM app reads untrusted input, holds sensitive context and can call tools. That is an attack surface most traditional pentests only touch lightly.

Customers and auditors are starting to ask what you have done about it.

Attack surface of an LLM applicationUntrusted inputs (user prompt, documents, web pages, emails) cross trust boundary A into the LLM or agent. The agent's output crosses trust boundary B to reach tools and APIs, the knowledge base and other users' data. An example attack path runs from a document, through the agent, to a tool call.Untrusted inputsTrust boundary AUser promptDocumentsWeb pagesEmailsLLM / agentinstructions + contextTrust boundary BTools &APIsKnowledgebaseOther users’data

Boundary A. Untrusted content enters the model's context, where it can be read as instructions.

Boundary B. Model output becomes tool calls and data access.

Example attack path: a document steers the agent into a tool call.

What we test

Direct prompt injection
Can a user override your instructions or leak your system prompt?
Indirect prompt injection
Can a document, web page or email hijack your assistant?
Data extraction
Can one user reach another user's data or your secrets?
Agent and tool abuse
Can your agent be pushed into actions nobody approved?
RAG attacks
Can poisoned or cross-tenant content reach an answer?
Architecture review
Where do trust boundaries fail between model, tools and data?

At least 15 attack scenarios executed and documented, including the ones your system resisted. Mapped to the OWASP Top 10 for LLM Applications.

What you get

  • Technical report: every finding with severity, evidence, reproduction steps and fix
  • Reproducible proof-of-concept for every critical and high finding
  • Executive summary for leadership
  • Remediation roadmap: fix now, fix next, hardening
  • 60-minute debrief with your engineers
  • One-page Customer Security Summary you can share with your own customers

How it works

  1. Scope call, 20 min

    We confirm the fit and send a fixed proposal the same day.

  2. Access

    You provide a test environment, test accounts and architecture notes.

  3. Sprint

    5 business days from complete access to delivered report.

  4. Debrief

    We walk your team through findings and priorities.

Why Senthex

Senthex publishes research on attacks against AI systems, including RELAY, a study of how multi-agent LLM CI/CD pipelines can be compromised. Our methodology is informed by that research and by real-world attack observations.

Read RELAY on arXiv

Pricing

AI Security Sprint

List price €3,500, founding-customer price €2,500 excl. VAT, fixed.

Founding-customer price for our first 5 Sprints.

Scope: one application — one entry point, one agent with up to 5 tools, one knowledge base, two user roles, one test environment.

  • Technical report: severity, evidence, reproduction steps and fix
  • Proof-of-concept for every critical and high finding
  • Executive summary
  • Remediation roadmap
  • 60-minute debrief
  • Customer Security Summary

Larger or multi-agent system? Ask about our AI Red Team engagement.

FAQ

We already have a pentest.

Good, we do not redo it. We test the AI-specific layer: indirect injection, tool abuse, cross-user leakage. If your last report covers those, you may not need us.

Why not an automated scanner?

Use one; we do too. Scanners replay known prompt attacks. Serious findings come from chaining attacks through your specific tools and data, which is manual work.

Can you guarantee we are secure?

No, and nobody honestly can. We guarantee a scope, a method and documented coverage. An assessment is not a certification.

What do you need from us?

A test environment, test accounts, your system prompts and tool list, and a technical contact. The 5-day clock starts when access is complete.

Do you test in production?

We test staging or pre-production. We do not test against real personal data.

What happens to our data?

Evidence is stored encrypted and deleted 90 days after delivery. Nothing is reused without your written consent.

Your AI system has an attack surface.

Know what it looks like before someone else does.