Skip to content
All services

Estma service / AI security

AI application security

Assess and improve the security of AI-enabled applications across prompts, data, APIs, identities, tools and cloud infrastructure—not only the model endpoint.

Where this starts

A good fit when…

  • An AI feature is approaching customer or internal release
  • Sensitive data enters retrieval, prompts or model tools
  • An agent can call APIs or take consequential actions
  • A customer, investor or security team needs credible assurance

The operating problem

The difficult part is rarely the headline technology.

The engagement focuses on the surrounding system: boundaries, evidence, permissions, exceptions, people and the decisions the implementation must support.

  1. 01

    Prompt injection and jailbreak paths are tested without application context

  2. 02

    Model tools inherit more access than the user should have

  3. 03

    Sensitive data can leak through retrieval, logs or provider configuration

  4. 04

    Findings describe theoretical risk without a reproducible path or fix

What leaves the engagement

Concrete output, not advisory residue.

  1. 01Authorised scope, system map and threat model
  2. 02Testing across prompt attacks, data exposure, APIs, identity and cloud controls
  3. 03Evidence-backed findings ranked by impact and exploitability
  4. 04Remediation guidance designed for the actual architecture
  5. 05Readout, retest plan and residual-risk record

Ways to start

Choose the smallest engagement that resolves the next decision.

AI security assessment

2–4 weeks

Test one defined application boundary and deliver evidence, findings and a remediation plan.

Release review

1–2 weeks

Review architecture and controls before a production or customer-facing release.

Remediation support

As scoped

Work with the engineering team to fix, verify and document prioritised findings.

What Estma needs from your team.

  • Written authorisation and agreed test boundaries
  • A test account and representative environment
  • Architecture and data-flow context
  • An engineering owner available for triage

Service questions

What teams usually ask.

Is this a penetration test?

It can include adversarial testing, but the scope is broader than prompts alone. We look at the AI application as a system: data, identity, tools, APIs, model behaviour and cloud controls.

Will testing affect production?

The rules of engagement define environments, limits, test data and stop conditions before any active testing begins. Production testing only happens when explicitly authorised.

Start with context

Is this the work you need?

Describe the current system, the decision ahead and the constraint that is making progress difficult.

Required fields help us assess fit before the first call.

Next serviceGovernance support