AI Security Sprint
We attack your AI system before attackers do.
A fixed-scope, fixed-price adversarial assessment of one AI application. 5 business days. €2,500.
20 minutes. You get a fixed proposal the same day.
The problem
Your LLM app reads untrusted input, holds sensitive context and can call tools. That is an attack surface most traditional pentests only touch lightly.
Customers and auditors are starting to ask what you have done about it.
Boundary A. Untrusted content enters the model's context, where it can be read as instructions.
Boundary B. Model output becomes tool calls and data access.
Example attack path: a document steers the agent into a tool call.
What we test
- Direct prompt injection
- Can a user override your instructions or leak your system prompt?
- Indirect prompt injection
- Can a document, web page or email hijack your assistant?
- Data extraction
- Can one user reach another user's data or your secrets?
- Agent and tool abuse
- Can your agent be pushed into actions nobody approved?
- RAG attacks
- Can poisoned or cross-tenant content reach an answer?
- Architecture review
- Where do trust boundaries fail between model, tools and data?
At least 15 attack scenarios executed and documented, including the ones your system resisted. Mapped to the OWASP Top 10 for LLM Applications.
What you get
- Technical report: every finding with severity, evidence, reproduction steps and fix
- Reproducible proof-of-concept for every critical and high finding
- Executive summary for leadership
- Remediation roadmap: fix now, fix next, hardening
- 60-minute debrief with your engineers
- One-page Customer Security Summary you can share with your own customers
How it works
Scope call, 20 min
We confirm the fit and send a fixed proposal the same day.
Access
You provide a test environment, test accounts and architecture notes.
Sprint
5 business days from complete access to delivered report.
Debrief
We walk your team through findings and priorities.
Why Senthex
Senthex publishes research on attacks against AI systems, including RELAY, a study of how multi-agent LLM CI/CD pipelines can be compromised. Our methodology is informed by that research and by real-world attack observations.
Pricing
AI Security Sprint
List price €3,500, founding-customer price €2,500 excl. VAT, fixed.
Founding-customer price for our first 5 Sprints.
Scope: one application — one entry point, one agent with up to 5 tools, one knowledge base, two user roles, one test environment.
- Technical report: severity, evidence, reproduction steps and fix
- Proof-of-concept for every critical and high finding
- Executive summary
- Remediation roadmap
- 60-minute debrief
- Customer Security Summary
Larger or multi-agent system? Ask about our AI Red Team engagement.
FAQ
We already have a pentest.
Good, we do not redo it. We test the AI-specific layer: indirect injection, tool abuse, cross-user leakage. If your last report covers those, you may not need us.
Why not an automated scanner?
Use one; we do too. Scanners replay known prompt attacks. Serious findings come from chaining attacks through your specific tools and data, which is manual work.
Can you guarantee we are secure?
No, and nobody honestly can. We guarantee a scope, a method and documented coverage. An assessment is not a certification.
What do you need from us?
A test environment, test accounts, your system prompts and tool list, and a technical contact. The 5-day clock starts when access is complete.
Do you test in production?
We test staging or pre-production. We do not test against real personal data.
What happens to our data?
Evidence is stored encrypted and deleted 90 days after delivery. Nothing is reused without your written consent.
Your AI system has an attack surface.
Know what it looks like before someone else does.