I will do ai and llm security testing and prompt injection pentest
Security and Development
About this Gig
Does your AI feature open a security hole?
If your product uses an LLM chatbot, copilot, RAG assistant, or AI agent, attackers can manipulate it with a single crafted message.
Prompt injection is the #1 risk on the OWASP Top 10 for LLM Applications, and traditional testing misses it completely.
I am a security specialist focused on AI and LLM application security. I attack your AI the way a real adversary would, then show you exactly how to fix it before someone malicious does or an auditor asks for proof.
What I test for:
- Prompt injection (direct and indirect/stored)
- Jailbreaks and guardrail bypass
- System-prompt and sensitive-data leakage
- RAG poisoning and data-source manipulation
- Agent and tool-abuse / unsafe actions
- The underlying API layer (auth, access, rate limits)
- Mapped to OWASP LLM Top 10 + MITRE ATLAS
You get a clear, executive-readable report: each finding with proof-of-concept, risk rating, and developer-ready fixes plus a walkthrough call and a free retest.
Ideal if you are launching an AI feature or facing a security / EU AI Act / SOC 2 review.
Message me before ordering so I can scope your system. Let us make your AI safe to ship.
My Portfolio
FAQ
Is this legal? Do you need authorization?
Yes. I only test systems you own or are authorized to test, and I ask you to confirm authorization in writing before I begin. This keeps the engagement legal and clean for both of us.
Will you break my app or touch real data?
No. I test carefully, prefer a staging environment, avoid destructive actions, and never exfiltrate real data. If only production is available, we agree on safe limits first.
Do I need to give you source code?
Not required. I can test black-box with just access, or grey-box if you share the system prompt/architecture for deeper coverage. More context means better, more accurate findings.
What do I actually receive?
A professional PDF report: every finding with a proof-of-concept, severity rating, business impact, and clear developer-ready remediation steps, written so both developers and executives understand it.
Can you sign an NDA?
Absolutely. I am happy to sign your NDA before any access or testing begins. Confidentiality is standard on every engagement.
