Skip to content
Penetration testing
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • AI penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • AI security and governance assessment
  • Remediation support and retesting
Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
All services on one page
Industries How we work About Blog
1300 AURIAN Contact
Menu
Penetration testing
  • Penetration testing services
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • AI penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Security assurance and compliance services
  • Essential Eight assessment
  • Configuration review and benchmarking
  • AI security and governance assessment
  • Remediation support and retesting
Managed security
  • Managed security services
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
  • All services
  • Industries
  • How we work
  • About
  • Blog
Call 1300 AURIAN Contact
  1. Services
  2. Penetration testing
  3. AI penetration testing

Penetration testing

AI penetration testing

We test the assistants, copilots and agents you build or buy the way an attacker would, from the prompt to the data and tools behind it.

Scope a test Call 1300 AURIAN

Who this is for

  • You have put an assistant, copilot or agent in your product

    A chat interface over your data, an agent that acts for a customer or an AI feature in the next release all open paths that a web or API test was never designed to find.

  • Staff use an AI assistant over your documents and systems

    An assistant that retrieves from file shares, mailboxes and ticket queues reaches whatever the retrieval layer allows, and that is rarely the same as what the user is entitled to see.

  • A customer, board or insurer has asked whether the AI has been tested

    Due-diligence questionnaires and board papers now ask the question directly. An independent test answers it with evidence rather than a vendor's assurance.

What our AI penetration test covers

Internet Web application API Perimeter Cloud tenancy Email Office network Workstation Identity Wireless Crown jewels Servers Artificial intelligence INTERNET: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. WEB APPLICATION: CHECKS INCLUDE The assistant's interface and session handling Model output rendered as HTML or markdown Access control on every endpoint the assistant uses API: CHECKS INCLUDE Model endpoints, tool calls and rate limiting Authorisation on retrieval and tool back-ends Vendor keys and integration secrets PERIMETER: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. CLOUD TENANCY: CHECKS INCLUDE The AI platform tenancy and the model's own identity What the vendor retains and trains on Logging of prompts and tool calls EMAIL: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. OFFICE NETWORK: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. WORKSTATION: NOT IN SCOPE HERE Covered by essential Eight assessment. Click to open that service. IDENTITY: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. WIRELESS: NOT IN SCOPE HERE Covered by wireless penetration testing. Click to open that service. CROWN JEWELS: CHECKS INCLUDE Customer records reachable through retrieval Bulk exposure through prompts and enumeration Data held in prompts, embeddings and conversation history SERVERS: NOT IN SCOPE HERE Covered by configuration review and benchmarking. Click to open that service. ARTIFICIAL INTELLIGENCE: CHECKS INCLUDE Prompt injection, direct and indirect System prompt and tool schema leakage Retrieval authorisation and tool abuse Output handling and unbounded consumption Internet Web application Perimeter API Email Cloud tenancy Office network Workstation Wireless Identity Crown jewels Servers Artificial intelligence INTERNET: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. WEB APPLICATION: CHECKS INCLUDE The assistant's interface and session handling Model output rendered as HTML or markdown Access control on every endpoint the assistant uses PERIMETER: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. API: CHECKS INCLUDE Model endpoints, tool calls and rate limiting Authorisation on retrieval and tool back-ends Vendor keys and integration secrets EMAIL: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. CLOUD TENANCY: CHECKS INCLUDE The AI platform tenancy and the model's own identity What the vendor retains and trains on Logging of prompts and tool calls OFFICE NETWORK: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. WORKSTATION: NOT IN SCOPE HERE Covered by essential Eight assessment. Click to open that service. WIRELESS: NOT IN SCOPE HERE Covered by wireless penetration testing. Click to open that service. IDENTITY: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. CROWN JEWELS: CHECKS INCLUDE Customer records reachable through retrieval Bulk exposure through prompts and enumeration Data held in prompts, embeddings and conversation history SERVERS: NOT IN SCOPE HERE Covered by configuration review and benchmarking. Click to open that service. ARTIFICIAL INTELLIGENCE: CHECKS INCLUDE Prompt injection, direct and indirect System prompt and tool schema leakage Retrieval authorisation and tool abuse Output handling and unbounded consumption

We test the whole system against the OWASP Top 10 for LLM Applications, in each role you provide, from the prompt to the model's retrieval, tools and outputs and the application around them.

  • Prompt injection, direct and indirect, through the documents, web pages, emails and tickets the model reads
  • System prompt leakage and jailbreaks that remove the guardrails the application depends on
  • Retrieval authorisation, whether the data the model can reach is filtered by the user's rights or only by the prompt
  • Tool and agent abuse, covering what the model can be made to do with the functions and credentials it holds
  • Output handling, where model output is rendered as HTML, executed as code or passed to another system unchecked
  • Sensitive information disclosure, including other users' conversations, secrets in prompts and data the vendor retains
  • Rate limiting and unbounded consumption, from cost abuse to using your model as a free proxy
  • The conventional surface around the model, covering authentication, session handling, access control and the integration with the AI vendor

How we test it

An assistant built on a language model fails in two places at once. The application around it is a web application and an API, with the same authentication, session and access-control flaws as any other, and the model layer adds flaws of its own: the model follows instructions wherever they come from, reaches whatever its retrieval and tools can reach, and produces output the application tends to trust. An Aurian AI penetration test covers both, because the worst findings sit where they meet, as when a prompt hidden in a document makes a tool call that the application never checked.

We start with a threat model of the system as deployed: the model, the prompts, the retrieval sources, the tools and the credentials each one holds, and who can talk to it. A senior consultant then works through the OWASP Top 10 for LLM Applications by hand, in each role, with the techniques catalogued in MITRE ATLAS: direct and indirect injection, leakage of the system prompt and tool schema, retrieval that answers from data the user should not see, tools that do more than the user could, output that lands in a browser or a database unescaped, and endpoints with no limit on what they will spend. Automated prompt sets widen coverage. The judgement about what a given assistant should refuse, and what it should be able to reach, is the consultant’s.

Findings come with the exact conversation or request that reproduces them, the data or action reached, and the layer where the fix belongs, which is usually the tool or the retrieval boundary rather than the prompt. We retest the findings rated high or above once you have remediated. Where the question is how the whole organisation adopts and governs AI rather than how one assistant can be broken, our AI security and governance assessment answers it.

Standards OWASP Top 10 for LLM Applications, OWASP API Security Top 10, OWASP ASVS, MITRE ATLAS

  1. 01 Threat model

    We map the system first, including the model, the prompts, what it retrieves, which tools it can call and with whose credentials, and who can talk to it, so the test targets the paths that matter.

  2. 02 The application around the model

    An AI feature is still a web application and an API. We test authentication, session handling and access control on every endpoint the assistant uses, because a flaw there needs no clever prompt at all.

  3. 03 Prompt, retrieval and tools

    A consultant works through injection, leakage, retrieval authorisation and tool abuse by hand, in each role, chaining what the model will do with what the application lets it reach.

  4. 04 Reporting and retest

    You receive findings ranked by severity with the exact conversation or request that reproduces each one. Once you have remediated, a retest of the findings rated high or above confirms what is closed and the report is updated. Retesting is quoted with the test or booked afterwards.

What you receive

Every finding in an Aurian report looks like this: what we found, the evidence, what it means for you, and what to change.

High AUR-2026-014 Sample finding, fictional environment

Support assistant discloses other customers' orders through its ticket tool

Affected asset
Customer support assistant on portal.example.com.au, search_tickets tool
Rating
High Likely 4 × High 4 = 16

Description

The assistant answers questions about orders by calling a search_tickets tool with an order number the model takes from the conversation. The tool searches the whole ticket store, and the only thing keeping a customer to their own orders is an instruction in the system prompt. Asking about someone else's order number returns that customer's name, delivery address and phone number, and order numbers are sequential.

Evidence

user      > My order 7731-5520 hasn't arrived. Which address is it going to?
assistant > [tool call] search_tickets(order="7731-5520")  # no customer filter
tool      > ticket 88412, customer 1187   (the session is customer 2041)
            J. Moreau, 14 Example St, Parramatta NSW 2150, 04xx xxx xxx
assistant > Order 7731-5520 is on its way to J. Moreau at 14 Example St,
            Parramatta NSW 2150. The courier has the number ending in xxx.

A customer asked about an order number that was not theirs. The tool searched every ticket, and the model relayed another customer's name, address and phone number.

Impact

Any customer can read any other customer's delivery details by asking about an order number, and the numbers are sequential, so a script would retrieve the whole customer base through the assistant. The system prompt told the model to answer only about the user's own orders, and a model following instructions is not an access control. Exposure on this scale is what the Notifiable Data Breaches scheme exists for.

Remediation

Enforce authorisation in the tool, not the prompt: scope every search_tickets call to the customer ID of the authenticated session on the server side, and never accept identity as an argument the model fills in. Give each tool the least access its job needs, treat the model's output as untrusted input to every system downstream, and log tool calls with the session that made them so misuse can be seen.

References

  • OWASP Top 10 for LLM Applications, excessive agency
  • OWASP API Security Top 10, broken object level authorisation
  • Executive summary written for the board and the insurer, in plain language
  • Technical findings ranked by severity, each with the conversation or request that reproduces it
  • A map of the system as tested, covering the model, prompts, retrieval sources, tools and the credentials each holds
  • Remediation guidance your developers can act on without calling us

Common findings

What this kind of engagement typically surfaces, so you can recognise your own environment.

  • Authorisation left to the model

    Retrieval and tools that search everything, with an instruction in the system prompt as the only thing keeping users to their own data.

  • Indirect prompt injection

    Instructions hidden in a document, web page, email or ticket the assistant reads, which it then follows as if the user had typed them.

  • System prompt and tool schema disclosure

    The prompt, the list of tools and their parameters recovered in a few turns, which hands an attacker the map of what the assistant can be made to do.

  • Excessive agency

    Tools and agents holding broader permissions than the user in front of them, so a successful injection sends email, changes records or spends money.

  • Unsafe output handling

    Model output rendered as HTML or markdown, executed as a query or passed to another system unchecked, turning an injection into cross-site scripting or worse.

  • Unbounded consumption

    No rate limit or spend cap on the model endpoint, and vendor keys exposed in the client, so anyone can run up your bill or use your model as their own.

Frequently asked questions

What counts as an AI-powered service?

Anything where a model takes input from people or systems and produces output your application acts on or shows: customer chatbots, copilots over internal documents, agents that call tools and APIs, AI features inside your product, and assistants you have bought and connected to your data. Built or bought, hosted by you or by a vendor, we test the system as deployed.

How is this different from a web application or API test?

It includes one. The assistant's endpoints, sessions and access controls are tested as they would be in any application test, and then we test the layer those tests never reach: what the model will do when its instructions, its retrieval sources and its tools are turned against it.

Do you test the model itself or our use of it?

Your use of it. We do not evaluate the vendor's model for accuracy or bias. We test what an attacker can reach through your deployment: the prompts you wrote, the data you connected, the tools you gave it and the application around it. That is where the findings are, whichever model sits underneath.

What do you need from us?

Accounts in each role, including at least two customers or tenants where the assistant serves more than one; the system prompts and the list of tools, which we hold under our standard confidentiality terms; and a sketch of what the model can retrieve and call. We can test without the prompts and recover them ourselves, but the test is faster and more complete with them.

Will testing run up our model bill or affect production?

We agree spend limits and a testing window before we start, and test in a non-production environment where you have one. Consumption and rate-limiting tests run with your agreement and stop at the limit we set together.

How long does it take?

It depends on the number of assistants, roles, retrieval sources and tools in scope: typically three to ten days of testing, with the report following. We confirm the timeframe after scoping.

Related services

Web application penetration testing

Web application penetration testing against the OWASP Testing Guide: authentication, access control, injection and business logic, tested by hand.

API penetration testing

API penetration testing for REST, GraphQL and SOAP against the OWASP API Security Top 10: authorisation, rate limiting and undocumented endpoints.

AI security and governance assessment

AI security and governance assessment of how your organisation adopts, governs and secures AI, measured against ISO/IEC 42001, NIST and Australian guidance.

Penetration testing services

Scope a test with a senior consultant

Tell us what you need to know about your environment. We reply within one business day.

Scope a test Call 1300 AURIAN

Aurian Security is an Australian penetration testing and security assurance firm. Senior consultants perform every engagement, for clients across the country.

Penetration testing

  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • AI penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation

Assurance and managed

  • Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • AI security and governance assessment
  • Remediation support and retesting
  • Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring

Company

  • About Aurian
  • How we work
  • Industries
  • Blog
  • Contact
  • Privacy policy
526/368 Sussex St, Sydney NSW 2000 1300 AURIAN (1300 287 426) sales@aurian.com.au

© 2026 Aurian Security Pty Ltd. ACN 639 930 528.

This site is static, loads no third-party trackers, and publishes a security.txt.