AI Surfaces in the real world

An AI surface can appear helpful while the application behind it exposes data or takes actions its user was never allowed to perform.

Test the whole application—not only the model.

The problem

The model is only one part of the application.

Your AI-enabled application may be able to expose sensitive data or take actions its user is not allowed to perform.

The real boundary is formed by identity, data, permissions, and tools. A polite refusal or detector warning does not tell you what the application attempted—or what happened downstream.

What can someone persuade your AI surface to see, call, change, or disclose?

The solution

AI Application Security Assessment

Test one authorized AI surface as an application—not just as a model.

The fixed-scope assessment follows meaningful attempts through identities, tools, services, and downstream effects. It identifies the owning control, helps the team correct the gap, and repeats the same meaningful test.

See how the assessment works

Case study

One HR chatbot. Four different security outcomes.

A synthetic HR chatbot used a service identity with more authority than its user. The test separated what the model said from what the application attempted, enforced, and changed downstream.

  1. Vulnerable baselineAn unsafe email side effect was visible.
  2. Detected without preventionA warning appeared, but the effect remained possible.
  3. Optionally blockedOne pinned attempt was stopped by an added control.
  4. RetestedThe authoritative readback showed no unsafe email side effect.

This bounded synthetic example does not prove that every prompt injection is blocked or establish universal safety.

Read the evidence and limitations

How engagements run

Assess. Plan. Execute.

One pillar at a time, in three shapes. Examples below; the full matrix lives on the Work page.

  1. Assess

    Healthcheck — fixed fee, 1 week

    OWASP LLM Top 10 audit against your stack.

  2. Plan

    Roadmap — fixed fee, 2–3 weeks

    Threat model and remediation roadmap.

  3. Execute

    Project — day rate, 4–12 weeks

    Deploy guardrails, instrument apps, train the team.

See the full 12-cell service matrix →

Start with one AI feature.

Tell us what the surface can see or do. We’ll identify a bounded first assessment.

Discuss one AI feature

Need the wider picture?

Assessment is one part of the practice. See the full Assess, Plan, Execute matrix across Security, Finance, Development, and Operations.

Explore the work