AI security assessment
2–4 weeks
Test one defined application boundary and deliver evidence, findings and a remediation plan.
Estma service / AI security
Assess and improve the security of AI-enabled applications across prompts, data, APIs, identities, tools and cloud infrastructure—not only the model endpoint.
Where this starts
The operating problem
The engagement focuses on the surrounding system: boundaries, evidence, permissions, exceptions, people and the decisions the implementation must support.
Prompt injection and jailbreak paths are tested without application context
Model tools inherit more access than the user should have
Sensitive data can leak through retrieval, logs or provider configuration
Findings describe theoretical risk without a reproducible path or fix
What leaves the engagement
Ways to start
2–4 weeks
Test one defined application boundary and deliver evidence, findings and a remediation plan.
1–2 weeks
Review architecture and controls before a production or customer-facing release.
As scoped
Work with the engineering team to fix, verify and document prioritised findings.
Service questions
It can include adversarial testing, but the scope is broader than prompts alone. We look at the AI application as a system: data, identity, tools, APIs, model behaviour and cloud controls.
The rules of engagement define environments, limits, test data and stop conditions before any active testing begins. Production testing only happens when explicitly authorised.
Start with context
Describe the current system, the decision ahead and the constraint that is making progress difficult.